PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / 5.5
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More v5.5
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmForm.php +21 -71 6.5.25.5 View file →
@@ -6,9 +6,9 @@
6 6 class FrmForm {
7 7
8 8 /**
9 9 * @param array $values
10 - * @return int|bool id on success or false on failure.
10 + * @return int|boolean id on success or false on failure
11 11 */
12 12 public static function create( $values ) {
13 13 global $wpdb;
14 14
@@ -284,8 +284,13 @@
284 284 $options['before_html'] = isset( $values['options']['before_html'] ) ? $values['options']['before_html'] : FrmFormsHelper::get_default_html( 'before' );
285 285 $options['after_html'] = isset( $values['options']['after_html'] ) ? $values['options']['after_html'] : FrmFormsHelper::get_default_html( 'after' );
286 286 $options['submit_html'] = ( isset( $values['options']['submit_html'] ) && '' !== $values['options']['submit_html'] ) ? $values['options']['submit_html'] : FrmFormsHelper::get_default_html( 'submit' );
287 287
288 + if ( ! empty( $options['success_url'] ) && ! empty( $args['form_id'] ) ) {
289 + $options['success_url'] = FrmFormsHelper::maybe_add_sanitize_url_attr( $options['success_url'], (int) $args['form_id'] );
290 + $values['options']['success_url'] = $options['success_url'];
291 + }
292 +
288 293 /**
289 294 * Allows modifying form options before updating or creating.
290 295 *
291 296 * @since 5.4 Added the third param.
@@ -365,18 +370,8 @@
365 370 'field_options' => $field->field_options,
366 371 'default_value' => isset( $values[ 'default_value_' . $field_id ] ) ? FrmAppHelper::maybe_json_encode( $values[ 'default_value_' . $field_id ] ) : '',
367 372 );
368 373
369 - if ( ! FrmAppHelper::allow_unfiltered_html() && isset( $values['field_options'][ 'options_' . $field_id ] ) && is_array( $values['field_options'][ 'options_' . $field_id ] ) ) {
370 - foreach ( $values['field_options'][ 'options_' . $field_id ] as $option_key => $option ) {
371 - if ( is_array( $option ) ) {
372 - foreach ( $option as $key => $item ) {
373 - $values['field_options'][ 'options_' . $field_id ][ $option_key ][ $key ] = FrmAppHelper::kses( $item, 'all' );
374 - }
375 - }
376 - }
377 - }
378 -
379 374 self::prepare_field_update_values( $field, $values, $new_field );
380 375
381 376 FrmField::update( $field_id, $new_field );
382 377
@@ -386,40 +381,17 @@
386 381
387 382 return $values;
388 383 }
389 384
390 - /**
391 - * @param string $opt
392 - * @param mixed $value
393 - * @return void
394 - */
395 385 private static function sanitize_field_opt( $opt, &$value ) {
396 - if ( ! is_string( $value ) ) {
397 - return;
386 + if ( is_string( $value ) ) {
387 + if ( $opt === 'calc' ) {
388 + $value = self::sanitize_calc( $value );
389 + } else {
390 + $value = FrmAppHelper::kses( $value, 'all' );
391 + }
392 + $value = trim( $value );
398 393 }
399 -
400 - /**
401 - * Allow the option to turn off sanitization for a field. This way a custom rule can be used instead.
402 - * Make sure to add custom sanitization using the frm_update_field_options filter as the data will no longer be sanitized.
403 - *
404 - * @since 6.0
405 - *
406 - * @param bool $should_sanitize
407 - * @param string $opt
408 - */
409 - $should_sanitize = apply_filters( 'frm_should_sanitize_field_opt_string', true, $opt );
410 -
411 - if ( ! $should_sanitize ) {
412 - return;
413 - }
414 -
415 - if ( $opt === 'calc' ) {
416 - $value = self::sanitize_calc( $value );
417 - } else {
418 - $value = FrmAppHelper::kses( $value, 'all' );
419 - }
420 -
421 - $value = trim( $value );
422 394 }
423 395
424 396 /**
425 397 * @param string $value
@@ -687,12 +659,10 @@
687 659 }
688 660
689 661 $query_key = is_numeric( $id ) ? 'id' : 'form_key';
690 662 $r = FrmDb::get_var( 'frm_forms', array( $query_key => $id ), 'name' );
663 + $r = stripslashes( $r );
691 664
692 - // An empty form name can result in a null value.
693 - $r = is_null( $r ) ? '' : stripslashes( $r );
694 -
695 665 return $r;
696 666 }
697 667
698 668 /**
@@ -756,9 +726,9 @@
756 726 if ( isset( $cache->options ) ) {
757 727 FrmAppHelper::unserialize_or_decode( $cache->options );
758 728 }
759 729
760 - return apply_filters( 'frm_form_object', wp_unslash( $cache ) );
730 + return wp_unslash( $cache );
761 731 }
762 732 }
763 733
764 734 if ( is_numeric( $id ) ) {
@@ -814,13 +784,9 @@
814 784 /**
815 785 * Get all published forms
816 786 *
817 787 * @since 2.0
818 - *
819 - * @param array $query
820 - * @param int $limit
821 - * @param string $inc_children
822 - * @return array|object of forms A single form object would be passed if $limit was set to 1.
788 + * @return array of forms
823 789 */
824 790 public static function get_published_forms( $query = array(), $limit = 999, $inc_children = 'exclude' ) {
825 791 $query['is_template'] = 0;
826 792 $query['status'] = array( null, '', 'published' );
@@ -1120,39 +1086,23 @@
1120 1086 return admin_url( 'admin.php?page=formidable&frm_action=edit&id=' . $form_id );
1121 1087 }
1122 1088
1123 1089 /**
1124 - * Check if the "Submit this form with AJAX" setting is toggled on.
1125 - *
1126 - * @since 6.2
1127 - *
1128 - * @param stdClass $form
1129 - * @return bool
1130 - */
1131 - public static function is_ajax_on( $form ) {
1132 - return ! empty( $form->options['ajax_submit'] );
1133 - }
1134 -
1135 - /**
1136 - * @deprecated 2.03.05 This is still referenced in a few add ons (API, locations).
1090 + * @deprecated 3.0
1137 1091 * @codeCoverageIgnore
1138 1092 *
1139 1093 * @param string $key
1094 + *
1140 1095 * @return int form id
1141 1096 */
1142 1097 public static function getIdByKey( $key ) {
1143 - _deprecated_function( __FUNCTION__, '2.03.05', 'FrmForm::get_id_by_key' );
1144 - return self::get_id_by_key( $key );
1098 + return FrmFormDeprecated::getIdByKey( $key );
1145 1099 }
1146 1100
1147 1101 /**
1148 - * @deprecated 2.03.05 This is still referenced in the API add on as of v1.13.
1102 + * @deprecated 3.0
1149 1103 * @codeCoverageIgnore
1150 - *
1151 - * @param string|int $id
1152 - * @return string
1153 1104 */
1154 1105 public static function getKeyById( $id ) {
1155 - _deprecated_function( __FUNCTION__, '2.03.05', 'FrmForm::get_key_by_id' );
1156 - return self::get_key_by_id( $id );
1106 + return FrmFormDeprecated::getKeyById( $id );
1157 1107 }
1158 1108 }