PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / 6.18
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More v6.18
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmEntryValidate.php +51 -195 6.25.1 → 6.18 View file →
@@ -129,9 +129,9 @@
129 129 );
130 130 $args = wp_parse_args( $args, $defaults );
131 131
132 132 if ( empty( $args['parent_field_id'] ) ) {
133 - $value = $values['item_meta'][ $args['id'] ] ?? '';
133 + $value = isset( $values['item_meta'][ $args['id'] ] ) ? $values['item_meta'][ $args['id'] ] : '';
134 134 } else {
135 135 // value is from a nested form
136 136 $value = $values;
137 137 }
@@ -157,9 +157,8 @@
157 157 }
158 158
159 159 FrmEntriesHelper::set_posted_value( $posted_field, $value, $args );
160 160
161 - self::validate_options( $errors, $posted_field, $value, $args );
162 161 self::validate_field_types( $errors, $posted_field, $value, $args );
163 162
164 163 // Field might want to modify value before other parts of the system
165 164 // e.g. trim off excess values like in the case of fields with limit.
@@ -177,175 +176,8 @@
177 176 }
178 177 }
179 178
180 179 /**
181 - * @since 6.21
182 - *
183 - * @param array $errors
184 - * @param object $posted_field
185 - * @param array|string $value
186 - * @param array $args
187 - *
188 - * @return void
189 - */
190 - private static function validate_options( &$errors, $posted_field, $value, $args ) {
191 - if ( empty( $posted_field->options ) ) {
192 - return;
193 - }
194 -
195 - $option_is_valid = self::option_is_valid( $posted_field, $value, $posted_field->options );
196 -
197 - /**
198 - * @since 6.21
199 - *
200 - * @param bool $option_is_valid
201 - * @param array|string $value
202 - * @param object $field
203 - */
204 - $option_is_valid = (bool) apply_filters( 'frm_option_is_valid', $option_is_valid, $value, $posted_field );
205 -
206 - if ( ! $option_is_valid ) {
207 - $errors[ 'field' . $args['id'] ] = FrmFieldsHelper::get_error_msg( $posted_field, 'invalid' );
208 - }
209 - }
210 -
211 - /**
212 - * Validate that value matches one of the options for the field.
213 - *
214 - * @since 6.21
215 - *
216 - * @param stdClass $field
217 - * @param array|string $value
218 - * @param array $options
219 - * @return bool
220 - */
221 - private static function option_is_valid( $field, $value, $options ) {
222 - if ( '' === $value ) {
223 - return true;
224 - }
225 -
226 - $field_object = FrmFieldFactory::get_field_type( $field->type, $field );
227 - if ( ! $field_object->field_type_has_options_settings() ) {
228 - return true;
229 - }
230 -
231 - if ( in_array( $field->type, array( 'likert', 'ranking' ), true ) ) {
232 - // Ignore these field types automatically.
233 - return true;
234 - }
235 -
236 - if ( 'product' === $field->type && 'user_def' === FrmField::get_option( $field, 'data_type' ) ) {
237 - return true;
238 - }
239 -
240 - if ( ! empty( $field->field_options['post_field'] ) ) {
241 - return true;
242 - }
243 -
244 - $value = (array) $value;
245 -
246 - foreach ( $value as $current_value ) {
247 - $match = false;
248 -
249 - foreach ( $options as $key => $option ) {
250 - if ( strpos( $key, 'other_' ) === 0 ) {
251 - // Always return true if an other option is found.
252 - return true;
253 - }
254 -
255 - if ( is_array( $option ) ) {
256 - $separate_value = FrmField::get_option( $field, 'separate_value' );
257 - $option_value = $separate_value ? $option['value'] : $option['label'];
258 - } else {
259 - $option_value = $option;
260 - }
261 -
262 - $match = trim( $current_value ) === trim( $option_value );
263 - if ( $match ) {
264 - break;
265 - }
266 -
267 - $match = trim( $current_value ) === trim( do_shortcode( $option_value ) );
268 - if ( $match ) {
269 - break;
270 - }
271 -
272 - $match = self::is_filtered_match( $current_value, $option_value );
273 - if ( $match ) {
274 - break;
275 - }
276 -
277 - if ( is_numeric( $current_value ) ) {
278 - $match = (int) $current_value === (int) $option_value;
279 - if ( $match ) {
280 - break;
281 - }
282 - }
283 - }//end foreach
284 -
285 - if ( ! $match ) {
286 - return self::options_are_dynamic_based_on_hook( $field, $value );
287 - }
288 - }//end foreach
289 -
290 - return true;
291 - }
292 -
293 - /**
294 - * Make an extra check after passing $option_value through the_content filter.
295 - * This is to help catch cases where the option's formatting has been modified using
296 - * the_content filter.
297 - *
298 - * @since 6.22
299 - *
300 - * @param string $value
301 - * @param string $option_value
302 - * @return bool
303 - */
304 - private static function is_filtered_match( $value, $option_value ) {
305 - // First remove the wpautop filter so it doesn't add extra tags to $option_value.
306 - $filter_priority = has_filter( 'the_content', 'wpautop' );
307 - if ( is_numeric( $filter_priority ) ) {
308 - remove_filter( 'the_content', 'wpautop', $filter_priority );
309 - }
310 - $filtered_option = apply_filters( 'the_content', $option_value );
311 - if ( is_numeric( $filter_priority ) ) {
312 - add_filter( 'the_content', 'wpautop', $filter_priority );
313 - }
314 - return trim( $value ) === trim( $filtered_option );
315 - }
316 -
317 - /**
318 - * Do not validate options if they have been modified with a hook.
319 - * This is to help avoid issues where the options could be based on a URL param for example.
320 - *
321 - * @since 6.21
322 - *
323 - * @return bool
324 - */
325 - private static function options_are_dynamic_based_on_hook( $field_object, $value ) {
326 - $values = (array) $field_object;
327 - $values['value'] = $value;
328 - FrmFieldsHelper::prepare_new_front_field( $values, $field_object );
329 -
330 - $separate_value = FrmField::get_option( $field_object, 'separate_value' );
331 - $map_callback = function ( $option ) use ( $separate_value ) {
332 - if ( is_array( $option ) ) {
333 - $option_value = $separate_value ? $option['value'] : $option['label'];
334 - } else {
335 - $option_value = $option;
336 - }
337 - $option_value = do_shortcode( $option_value );
338 - return $option_value;
339 - };
340 -
341 - $values_options = array_map( $map_callback, $values['options'] );
342 - $field_object_options = array_map( $map_callback, $field_object->options );
343 -
344 - return $values_options !== $field_object_options;
345 - }
346 -
347 - /**
348 180 * Maybe add item_name to $_POST to save it in items table.
349 181 *
350 182 * @since 5.2.02
351 183 *
@@ -474,9 +306,9 @@
474 306 return $pattern;
475 307 }
476 308
477 309 /**
478 - * Check for spam.
310 + * Check for spam
479 311 *
480 312 * @param bool $exclude
481 313 * @param array $values
482 314 * @param array $errors By reference.
@@ -481,13 +313,8 @@
481 313 * @param array $values
482 314 * @param array $errors By reference.
483 315 */
484 316 public static function spam_check( $exclude, $values, &$errors ) {
485 - if ( defined( 'WP_IMPORTING' ) && WP_IMPORTING ) {
486 - // Do not check spam on importing.
487 - return;
488 - }
489 -
490 317 if ( ! empty( $exclude ) || empty( $values['item_meta'] ) || ! empty( $errors ) ) {
491 318 // only check spam if there are no other errors
492 319 return;
493 320 }
@@ -492,18 +319,14 @@
492 319 return;
493 320 }
494 321
495 322 $antispam_check = self::is_antispam_check( $values['form_id'] );
496 - $spam_msg = FrmAntiSpamController::get_default_spam_message();
497 323 if ( is_string( $antispam_check ) ) {
498 324 $errors['spam'] = $antispam_check;
499 325 } elseif ( self::is_honeypot_spam( $values ) || self::is_spam_bot() ) {
500 - $errors['spam'] = $spam_msg;
501 - } else {
502 - $is_spam = FrmAntiSpamController::is_spam( $values );
503 - if ( $is_spam ) {
504 - $errors['spam'] = $is_spam;
505 - }
326 + $errors['spam'] = __( 'Your entry appears to be spam!', 'formidable' );
327 + } elseif ( self::blacklist_check( $values ) ) {
328 + $errors['spam'] = __( 'Your entry appears to be blocked spam!', 'formidable' );
506 329 }
507 330
508 331 if ( isset( $errors['spam'] ) || self::form_is_in_progress( $values ) ) {
509 332 return;
@@ -575,17 +398,54 @@
575 398
576 399 return ( ! empty( $form->options['akismet'] ) && ( $form->options['akismet'] !== 'logged' || ! is_user_logged_in() ) );
577 400 }
578 401
402 + public static function blacklist_check( $values ) {
403 + if ( ! apply_filters( 'frm_check_blacklist', true, $values ) ) {
404 + return false;
405 + }
406 +
407 + $mod_keys = trim( self::get_disallowed_words() );
408 + if ( empty( $mod_keys ) ) {
409 + return false;
410 + }
411 +
412 + $content = FrmEntriesHelper::entry_array_to_string( $values );
413 +
414 + self::prepare_values_for_spam_check( $values );
415 + $ip = FrmAppHelper::get_ip_address();
416 + $user_agent = FrmAppHelper::get_server_value( 'HTTP_USER_AGENT' );
417 + $user_info = self::get_spam_check_user_info( $values );
418 +
419 + return self::check_disallowed_words( $user_info['comment_author'], $user_info['comment_author_email'], $user_info['comment_author_url'], $content, $ip, $user_agent );
420 + }
421 +
579 422 /**
580 - * Checks spam using WordPress disallowed words and Frm denylist.
423 + * For WP 5.5 compatibility.
581 424 *
582 - * @param array $values Entry values.
425 + * @since 4.06.02
426 + */
427 + private static function check_disallowed_words( $author, $email, $url, $content, $ip, $user_agent ) {
428 + if ( function_exists( 'wp_check_comment_disallowed_list' ) ) {
429 + return wp_check_comment_disallowed_list( $author, $email, $url, $content, $ip, $user_agent );
430 + }
431 + // phpcs:ignore WordPress.WP.DeprecatedFunctions.wp_blacklist_checkFound
432 + return wp_blacklist_check( $author, $email, $url, $content, $ip, $user_agent );
433 + }
434 +
435 + /**
436 + * For WP 5.5 compatibility.
583 437 *
584 - * @return bool
438 + * @since 4.06.02
585 439 */
586 - public static function blacklist_check( $values ) {
587 - return FrmAntiSpamController::contains_wp_disallowed_words( $values ) || FrmAntiSpamController::is_denylist_spam( $values );
440 + private static function get_disallowed_words() {
441 + $keys = get_option( 'disallowed_keys' );
442 + if ( false === $keys ) {
443 + // Fallback for WP < 5.5.
444 + // phpcs:ignore WordPress.WP.DeprecatedParameterValues.Found
445 + $keys = get_option( 'blacklist_keys' );
446 + }
447 + return $keys;
588 448 }
589 449
590 450 /**
591 451 * Check entries for Akismet spam
@@ -656,14 +516,13 @@
656 516 /**
657 517 * Gets user info for Akismet spam check.
658 518 *
659 519 * @since 5.0.13 Separate code for guest. Handle value of embedded|repeater.
660 - * @since 6.21 This changed from private to public.
661 520 *
662 521 * @param array $values Entry values after running through {@see FrmEntryValidate::prepare_values_for_spam_check()}.
663 522 * @return array
664 523 */
665 - public static function get_spam_check_user_info( $values ) {
524 + private static function get_spam_check_user_info( $values ) {
666 525 if ( ! is_user_logged_in() ) {
667 526 return self::get_spam_check_user_info_for_guest( $values );
668 527 }
669 528
@@ -915,9 +774,9 @@
915 774 }
916 775
917 776 // Check if submitted value is same as one of field option.
918 777 foreach ( $field_data->options as $option ) {
919 - $option_value = ! is_array( $option ) ? $option : ( $option['value'] ?? '' );
778 + $option_value = ! is_array( $option ) ? $option : ( isset( $option['value'] ) ? $option['value'] : '' );
920 779 if ( $values['item_meta']['other'][ $field_data->id ] === $option_value ) {
921 780 return true;
922 781 }
923 782 }
@@ -956,13 +815,12 @@
956 815 /**
957 816 * Prepares values array for spam check.
958 817 *
959 818 * @since 5.0.13
960 - * @since 6.21 This changed from private to public.
961 819 *
962 820 * @param array $values Entry values.
963 821 */
964 - public static function prepare_values_for_spam_check( &$values ) {
822 + private static function prepare_values_for_spam_check( &$values ) {
965 823 $form_ids = self::get_all_form_ids_and_flatten_meta( $values );
966 824 $values['form_ids'] = $form_ids;
967 825 }
968 826
@@ -1020,11 +878,9 @@
1020 878
1021 879 $values['name_field_ids'][] = $subsubindex;
1022 880 }
1023 881
1024 - if ( is_array( $values['item_meta'][ $subsubindex ] ) ) {
1025 - $values['item_meta'][ $subsubindex ][] = $subsubvalue;
1026 - }
882 + $values['item_meta'][ $subsubindex ][] = $subsubvalue;
1027 883 }
1028 884 }//end foreach
1029 885
1030 886 unset( $values['item_meta'][ $field_id ] );