PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / 6.8.2
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More v6.8.2
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
formidable / classes / controllers / FrmXMLController.php

FrmXMLController.php in Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More 6.8.2, at classes/controllers/FrmXMLController.php

734 lines 20.0 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 if ( ! defined( 'ABSPATH' ) ) {
3 die( 'You are not allowed to call this page directly.' );
4 }
5
6 class FrmXMLController {
7
8 /**
9 * @return void
10 */
11 public static function menu() {
12 add_submenu_page( 'formidable', 'Formidable | ' . __( 'Import/Export', 'formidable' ), __( 'Import/Export', 'formidable' ), 'frm_edit_forms', 'formidable-import', 'FrmXMLController::route' );
13 }
14
15 /**
16 * @return void
17 */
18 public static function add_default_templates() {
19 if ( FrmXMLHelper::check_if_libxml_disable_entity_loader_exists() ) {
20 // XML import is not enabled on your server.
21 return;
22 }
23
24 $set_err = libxml_use_internal_errors( true );
25 $loader = FrmXMLHelper::maybe_libxml_disable_entity_loader( true );
26
27 $files = apply_filters( 'frm_default_templates_files', array() );
28
29 foreach ( (array) $files as $file ) {
30 FrmXMLHelper::import_xml( $file );
31 unset( $file );
32 }
33
34 unset( $files );
35
36 libxml_use_internal_errors( $set_err );
37 FrmXMLHelper::maybe_libxml_disable_entity_loader( $loader );
38 }
39
40 /**
41 * Use the template link to install the XML template
42 *
43 * @since 3.06
44 * @return void
45 */
46 public static function install_template() {
47 FrmAppHelper::permission_check( 'frm_edit_forms' );
48 check_ajax_referer( 'frm_ajax', 'nonce' );
49
50 if ( ! function_exists( 'simplexml_load_string' ) ) {
51 $response = array(
52 'message' => __( 'Your server is missing the Simple XML extension. This is required to install a template.', 'formidable' ),
53 );
54 echo wp_json_encode( $response );
55 wp_die();
56 }
57
58 $form = self::get_posted_form();
59 $url = FrmAppHelper::get_param( 'xml', '', 'post', 'esc_url_raw' );
60 self::override_url( $form, $url );
61
62 if ( ! self::validate_xml_url( $url ) ) {
63 $response = array(
64 'message' => __( 'The template you are trying to install could not be validated.', 'formidable' ),
65 );
66 echo wp_json_encode( $response );
67 wp_die();
68 }
69
70 $response = wp_remote_get( $url );
71 $body = wp_remote_retrieve_body( $response );
72 $xml = simplexml_load_string( $body );
73
74 if ( ! $xml ) {
75 $response = array(
76 'message' => __( 'There was an error reading the form template.', 'formidable' ),
77 );
78 echo wp_json_encode( $response );
79 wp_die();
80 }
81
82 self::set_new_form_name( $xml );
83
84 $imported = FrmXMLHelper::import_xml_now( $xml, true );
85 if ( ! empty( $imported['form_status'] ) ) {
86 // Get the last form id in case there are child forms.
87 end( $imported['form_status'] );
88 $form_id = key( $imported['form_status'] );
89 $response = array(
90 'id' => $form_id,
91 'redirect' => FrmForm::get_edit_link( $form_id ) . '&new_template=true',
92 'success' => 1,
93 );
94 if ( ! empty( $imported['imported']['posts'] ) ) {
95 // Return the link to the last page created.
96 $pages = $imported['posts'];
97 }
98
99 if ( ! empty( $form ) ) {
100 // Create selected pages with the correct shortcodes.
101 $pages = self::create_pages_for_import( $form );
102 }
103
104 if ( isset( $pages ) && ! empty( $pages ) ) {
105 $post_id = end( $pages );
106 $response['redirect'] = get_permalink( $post_id );
107 }
108 } else {
109 if ( isset( $imported['error'] ) ) {
110 $message = $imported['error'];
111 } else {
112 $message = __( 'There was an error importing form', 'formidable' );
113 }
114 $response = array(
115 'message' => $message,
116 );
117
118 }//end if
119
120 $response = apply_filters( 'frm_xml_response', $response, compact( 'form', 'imported' ) );
121
122 echo wp_json_encode( $response );
123 wp_die();
124 }
125
126 /**
127 * Make sure that the XML file we're trying to load is in fact an XML file, and that it's coming from our S3 bucket.
128 * This is to make sure that the URL can't be exploited for a SSRF attack.
129 *
130 * @since 5.5.5
131 * @param string $url
132 *
133 * @return bool True on success, False on error.
134 */
135 private static function validate_xml_url( $url ) {
136 return FrmAppHelper::validate_url_is_in_s3_bucket( $url, 'xml' );
137 }
138
139 /**
140 * @since 4.06.02
141 *
142 * @return mixed
143 */
144 private static function get_posted_form() {
145 $form = FrmAppHelper::get_param( 'form', '', 'post', 'wp_unslash' );
146 if ( empty( $form ) ) {
147 return $form;
148 }
149 $form = json_decode( $form, true );
150 return $form;
151 }
152
153 /**
154 * Get a different URL depending on the selection in the form.
155 *
156 * @since 4.06.02
157 *
158 * @return void
159 */
160 private static function override_url( $form, &$url ) {
161 $selected_form = self::get_selected_in_form( $form, 'form' );
162 if ( empty( $selected_form ) ) {
163 return;
164 }
165
166 $selected_xml = isset( $form['xml'] ) && isset( $form['xml'][ $selected_form ] ) ? $form['xml'][ $selected_form ] : '';
167 if ( empty( $selected_xml ) || strpos( $selected_xml, 'http' ) !== 0 ) {
168 return;
169 }
170
171 $url = $selected_xml;
172 }
173
174 /**
175 * @since 4.06.02
176 *
177 * @param array $form
178 * @param string $value
179 */
180 private static function get_selected_in_form( $form, $value = 'form' ) {
181 if ( ! empty( $form ) && isset( $form[ $value ] ) && ! empty( $form[ $value ] ) ) {
182 return $form[ $value ];
183 }
184
185 return '';
186 }
187
188 /**
189 * @since 4.06.02
190 *
191 * @param array $form The posted form values.
192 *
193 * @return array The array of created pages.
194 */
195 private static function create_pages_for_import( $form ) {
196 if ( ! isset( $form['pages'] ) || empty( $form['pages'] ) ) {
197 return;
198 }
199
200 $form_key = self::get_selected_in_form( $form, 'form' );
201 $view_keys = self::get_selected_in_form( $form, 'view' );
202
203 $page_ids = array();
204 foreach ( (array) $form['pages'] as $for => $name ) {
205 if ( empty( $name ) ) {
206 // Don't create a page if no title is given.
207 continue;
208 }
209
210 if ( $for === 'view' ) {
211 $item_key = is_array( $view_keys ) ? $view_keys[ $form_key ] : $view_keys;
212 $shortcode = '[display-frm-data id=%1$s filter=limited]';
213 } elseif ( $for === 'form' ) {
214 $item_key = $form_key;
215 $shortcode = '[formidable id=%1$s]';
216 } else {
217 $item_key = self::get_selected_in_form( $form, 'form' );
218 $shortcode = '[' . esc_html( $for ) . ' id=%1$s]';
219 }
220
221 if ( empty( $item_key ) ) {
222 // Don't create it if the shortcode won't show anything.
223 continue;
224 }
225
226 $page_ids[ $for ] = wp_insert_post(
227 array(
228 'post_title' => $name,
229 'post_type' => 'page',
230 'post_content' => sprintf( $shortcode, $item_key ),
231 )
232 );
233 }//end foreach
234
235 return $page_ids;
236 }
237
238 /**
239 * Change the name of the last form that is not a child.
240 * This will allow for lookup fields and embedded forms
241 * since we redirect to the last form.
242 *
243 * @since 3.06
244 *
245 * @param object $xml The values included in the XML.
246 * @return void
247 */
248 private static function set_new_form_name( &$xml ) {
249 if ( ! isset( $xml->form ) ) {
250 return;
251 }
252
253 $name = FrmAppHelper::get_param( 'name', '', 'post', 'sanitize_text_field' );
254 $description = FrmAppHelper::get_param( 'desc', '', 'post', 'sanitize_textarea_field' );
255 if ( ! $name && ! $description ) {
256 return;
257 }
258
259 // Get the main form ID.
260 $set_name = 0;
261 foreach ( $xml->form as $form ) {
262 if ( empty( $form->parent_form_id ) ) {
263 $set_name = (int) $form->id;
264 }
265 }
266
267 foreach ( $xml->form as $form ) {
268 // Maybe set the form name if this isn't a child form.
269 if ( $set_name === (int) $form->id ) {
270 $form->name = $name;
271 $form->description = $description;
272 }
273
274 // Use a unique key to prevent editing existing form.
275 $sanitized_form_name = sanitize_title( $form->name );
276 $form->form_key = FrmAppHelper::get_unique_key( $sanitized_form_name, 'frm_forms', 'form_key' );
277 }
278 }
279
280 /**
281 * @return void
282 */
283 public static function route() {
284 $action = isset( $_REQUEST['frm_action'] ) ? 'frm_action' : 'action';
285 $action = FrmAppHelper::get_param( $action, '', 'get', 'sanitize_title' );
286 FrmAppHelper::include_svg();
287
288 if ( 'import_xml' === $action ) {
289 self::import_xml();
290 } elseif ( 'export_xml' === $action ) {
291 self::export_xml();
292 } elseif ( apply_filters( 'frm_xml_route', true, $action ) ) {
293 self::form();
294 }
295 }
296
297 /**
298 * @param string[] $errors
299 * @param string $message
300 *
301 * @return void
302 */
303 public static function form( $errors = array(), $message = '' ) {
304 $where = array(
305 'status' => array( null, '', 'published' ),
306 );
307 $forms = FrmForm::getAll( $where, 'name' );
308
309 $export_types = array(
310 'forms' => __( 'Forms', 'formidable' ),
311 'items' => __( 'Entries', 'formidable' ),
312 );
313 $export_types = apply_filters( 'frm_xml_export_types', $export_types );
314
315 $export_format = array(
316 'xml' => array(
317 'name' => 'XML',
318 'support' => 'forms',
319 'count' => 'multiple',
320 ),
321 'csv' => array(
322 'name' => 'CSV',
323 'support' => 'items',
324 'count' => 'single',
325 ),
326 );
327 $export_format = apply_filters( 'frm_export_formats', $export_format );
328
329 include FrmAppHelper::plugin_path() . '/classes/views/xml/import_form.php';
330 }
331
332 /**
333 * @return void
334 */
335 public static function import_xml() {
336 $errors = array();
337 $message = '';
338
339 $permission_error = FrmAppHelper::permission_nonce_error( 'frm_edit_forms', 'import-xml', 'import-xml-nonce' );
340 if ( false !== $permission_error ) {
341 $errors[] = $permission_error;
342 self::form( $errors );
343
344 return;
345 }
346
347 $has_file = ! empty( $_FILES['frm_import_file'] ) && ! empty( $_FILES['frm_import_file']['name'] ) && ! empty( $_FILES['frm_import_file']['size'] ) && (int) $_FILES['frm_import_file']['size'] > 0;
348 if ( ! $has_file ) {
349 $errors[] = __( 'Oops, you didn\'t select a file.', 'formidable' );
350 self::form( $errors );
351
352 return;
353 }
354
355 // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.MissingUnslash
356 $file = isset( $_FILES['frm_import_file']['tmp_name'] ) ? sanitize_option( 'upload_path', $_FILES['frm_import_file']['tmp_name'] ) : '';
357
358 if ( ! is_uploaded_file( $file ) ) {
359 unset( $file );
360 $errors[] = __( 'The file does not exist, please try again.', 'formidable' );
361 self::form( $errors );
362
363 return;
364 }
365
366 $export_format = array(
367 'xml' => array(
368 'name' => 'XML',
369 'support' => 'forms',
370 'count' => 'multiple',
371 ),
372 );
373 $export_format = apply_filters( 'frm_export_formats', $export_format );
374
375 // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.MissingUnslash
376 $file_type = sanitize_option( 'upload_path', $_FILES['frm_import_file']['name'] );
377 $file_type = strtolower( pathinfo( $file_type, PATHINFO_EXTENSION ) );
378 if ( 'xml' !== $file_type && isset( $export_format[ $file_type ] ) ) {
379 // allow other file types to be imported
380 do_action( 'frm_before_import_' . $file_type );
381
382 return;
383 }
384 unset( $file_type );
385
386 if ( FrmXMLHelper::check_if_libxml_disable_entity_loader_exists() ) {
387 $errors[] = __( 'XML import is not enabled on your server with the libxml_disable_entity_loader function.', 'formidable' );
388 self::form( $errors );
389
390 return;
391 }
392
393 $set_err = libxml_use_internal_errors( true );
394 $loader = FrmXMLHelper::maybe_libxml_disable_entity_loader( true );
395
396 $result = FrmXMLHelper::import_xml( $file );
397 FrmXMLHelper::parse_message( $result, $message, $errors );
398
399 unset( $file );
400
401 libxml_use_internal_errors( $set_err );
402 FrmXMLHelper::maybe_libxml_disable_entity_loader( $loader );
403
404 self::form( $errors, $message );
405 }
406
407 /**
408 * @return void
409 */
410 public static function export_xml() {
411 $error = FrmAppHelper::permission_nonce_error( 'frm_edit_forms', 'export-xml', 'export-xml-nonce' );
412 if ( ! empty( $error ) ) {
413 wp_die( esc_html( $error ) );
414 }
415
416 $ids = FrmAppHelper::get_post_param( 'frm_export_forms', array(), 'sanitize_text_field' );
417 $type = FrmAppHelper::get_post_param( 'type', array(), 'sanitize_text_field' );
418 $format = FrmAppHelper::get_post_param( 'format', 'xml', 'sanitize_title' );
419
420 if ( ! headers_sent() && ! $type ) {
421 wp_redirect( esc_url_raw( admin_url( 'admin.php?page=formidable-import' ) ) );
422 die();
423 }
424
425 if ( 'xml' === $format ) {
426 self::generate_xml( $type, compact( 'ids' ) );
427 } elseif ( 'csv' === $format ) {
428 self::generate_csv( compact( 'ids' ) );
429 } else {
430 do_action( 'frm_export_format_' . $format, compact( 'ids' ) );
431 }
432
433 wp_die();
434 }
435
436 /**
437 * @param string[] $type
438 * @param array $args
439 *
440 * @psalm-param array{ids?: mixed} $args
441 *
442 * @return void
443 */
444 public static function generate_xml( $type, $args = array() ) {
445 global $wpdb;
446
447 self::prepare_types_array( $type );
448
449 $tables = array(
450 'items' => $wpdb->prefix . 'frm_items',
451 'forms' => $wpdb->prefix . 'frm_forms',
452 'posts' => $wpdb->posts,
453 'styles' => $wpdb->posts,
454 'actions' => $wpdb->posts,
455 );
456
457 $defaults = array(
458 'ids' => false,
459 );
460 $args = wp_parse_args( $args, $defaults );
461
462 // Make sure ids are numeric.
463 if ( is_array( $args['ids'] ) && ! empty( $args['ids'] ) ) {
464 $args['ids'] = array_filter( $args['ids'], 'is_numeric' );
465 }
466
467 $records = array();
468
469 foreach ( $type as $tb_type ) {
470 $where = array();
471 $join = '';
472 $table = $tables[ $tb_type ];
473
474 $select = $table . '.id';
475 $query_vars = array();
476
477 switch ( $tb_type ) {
478 case 'forms':
479 // Add forms.
480 if ( $args['ids'] ) {
481 $where[] = array(
482 'or' => 1,
483 $table . '.id' => $args['ids'],
484 $table . '.parent_form_id' => $args['ids'],
485 );
486 } else {
487 $where[ $table . '.status !' ] = 'draft';
488 }
489 break;
490 case 'actions':
491 $select = $table . '.ID';
492 $where['post_type'] = FrmFormActionsController::$action_post_type;
493 if ( ! empty( $args['ids'] ) ) {
494 $where['menu_order'] = $args['ids'];
495 }
496 break;
497 case 'items':
498 // $join = "INNER JOIN {$wpdb->prefix}frm_item_metas im ON ($table.id = im.item_id)";
499 if ( $args['ids'] ) {
500 $where[ $table . '.form_id' ] = $args['ids'];
501 }
502 break;
503 case 'styles':
504 // Loop through all exported forms and get their selected style IDs.
505 $frm_style = new FrmStyle();
506 $default_style = $frm_style->get_default_style();
507 $form_ids = $args['ids'];
508 $style_ids = array();
509 foreach ( $form_ids as $form_id ) {
510 $form_data = FrmForm::getOne( $form_id );
511 // For forms that have not been updated while running 2.0, check if custom_style is set.
512 if ( isset( $form_data->options['custom_style'] ) ) {
513 if ( 1 === absint( $form_data->options['custom_style'] ) ) {
514 $style_ids[] = $default_style->ID;
515 } else {
516 $style_ids[] = $form_data->options['custom_style'];
517 }
518 }
519 unset( $form_id, $form_data );
520 }
521 $select = $table . '.ID';
522 $where['post_type'] = 'frm_styles';
523
524 // Only export selected styles.
525 if ( ! empty( $style_ids ) ) {
526 $where['ID'] = $style_ids;
527 }
528 break;
529 default:
530 $select = $table . '.ID';
531 $join = ' INNER JOIN ' . $wpdb->postmeta . ' pm ON (pm.post_id=' . $table . '.ID)';
532 $where['pm.meta_key'] = 'frm_form_id';
533
534 if ( empty( $args['ids'] ) ) {
535 $where['pm.meta_value >'] = 1;
536 } else {
537 $where['pm.meta_value'] = $args['ids'];
538 }
539 }//end switch
540
541 $records[ $tb_type ] = FrmDb::get_col( $table . $join, $where, $select );
542 unset( $tb_type );
543 }//end foreach
544
545 $filename = self::get_file_name( $args, $type, $records );
546
547 header( 'Content-Description: File Transfer' );
548 header( 'Content-Disposition: attachment; filename=' . $filename );
549 header( 'Content-Type: text/xml; charset=' . get_option( 'blog_charset' ), true );
550
551 echo '<?xml version="1.0" encoding="' . esc_attr( get_bloginfo( 'charset' ) ) . "\" ?>\n";
552 include FrmAppHelper::plugin_path() . '/classes/views/xml/xml.php';
553 }
554
555 /**
556 * @return void
557 */
558 private static function prepare_types_array( &$type ) {
559 $type = (array) $type;
560 if ( ! in_array( 'forms', $type ) && ( in_array( 'items', $type ) || in_array( 'posts', $type ) ) ) {
561 // make sure the form is included if there are entries
562 $type[] = 'forms';
563 }
564
565 if ( in_array( 'forms', $type ) ) {
566 // include actions with forms
567 $type[] = 'actions';
568 }
569 }
570
571 /**
572 * Use a generic file name if multiple items are exported.
573 * Use the nme of the form if only one form is exported.
574 *
575 * @since 3.06
576 *
577 * @param array $args
578 * @param array $type
579 * @param array $records
580 *
581 * @return string
582 */
583 private static function get_file_name( $args, $type, $records ) {
584 $has_one_form = isset( $records['forms'] ) && ! empty( $records['forms'] ) && count( $args['ids'] ) === 1;
585 if ( $has_one_form ) {
586 // one form is being exported
587 $selected_form_id = reset( $args['ids'] );
588 $filename = 'form-' . $selected_form_id . '.xml';
589
590 foreach ( $records['forms'] as $form_id ) {
591 $filename = 'form-' . $form_id . '.xml';
592 if ( $selected_form_id === $form_id ) {
593 $form = FrmForm::getOne( $form_id );
594 $filename = $form->name !== '' ? $form->name : $form->form_key;
595 $filename = sanitize_title( $filename ) . '-form.xml';
596 break;
597 }
598 }
599 } else {
600 $sitename = sanitize_key( get_bloginfo( 'name' ) );
601
602 if ( ! empty( $sitename ) ) {
603 $sitename .= '.';
604 }
605 $filename = $sitename . 'formidable.' . gmdate( 'Y-m-d' ) . '.xml';
606 }//end if
607
608 /**
609 * @since 5.3
610 *
611 * @param string $filename
612 */
613 return apply_filters( 'frm_xml_filename', $filename );
614 }
615
616 /**
617 * @param array $atts
618 *
619 * @return void
620 */
621 public static function generate_csv( $atts ) {
622 $form_ids = $atts['ids'];
623 if ( empty( $form_ids ) ) {
624 wp_die( esc_html__( 'Please select a form', 'formidable' ) );
625 }
626 self::csv( reset( $form_ids ) );
627 }
628
629 /**
630 * Export to CSV
631 *
632 * @since 2.0.19
633 *
634 * @return void
635 */
636 public static function csv( $form_id = false, $search = '', $fid = '' ) {
637 FrmAppHelper::permission_check( 'frm_view_entries' );
638
639 if ( ! $form_id ) {
640 $form_id = FrmAppHelper::get_param( 'form', '', 'get', 'sanitize_text_field' );
641 $search = FrmAppHelper::get_param( ( isset( $_REQUEST['s'] ) ? 's' : 'search' ), '', 'get', 'sanitize_text_field' );
642 $fid = FrmAppHelper::get_param( 'fid', '', 'get', 'sanitize_text_field' );
643 }
644
645 // Remove time limit to execute this function.
646 set_time_limit( 0 );
647 $mem_limit = str_replace( 'M', '', ini_get( 'memory_limit' ) );
648 if ( (int) $mem_limit < 256 ) {
649 wp_raise_memory_limit();
650 }
651
652 global $wpdb;
653
654 $form = FrmForm::getOne( $form_id );
655
656 if ( ! $form ) {
657 esc_html_e( 'Form not found.', 'formidable' );
658 wp_die();
659 }
660
661 $form_id = $form->id;
662 $form_cols = self::get_fields_for_csv_export( $form_id, $form );
663
664 $item_id = FrmAppHelper::get_param( 'item_id', 0, 'get', 'sanitize_text_field' );
665 if ( ! empty( $item_id ) ) {
666 $item_id = explode( ',', $item_id );
667 }
668
669 $query = array(
670 'form_id' => $form_id,
671 );
672
673 if ( $item_id ) {
674 $query['id'] = $item_id;
675 }
676
677 /**
678 * Allows the query to be changed for fetching the entry ids to include in the export
679 *
680 * $query is the array of options to be filtered. It includes form_id, and maybe id (array of entry ids),
681 * and the search query. This should return an array, but it can be handled as a string as well.
682 */
683 $query = apply_filters( 'frm_csv_where', $query, compact( 'form_id', 'search', 'fid', 'item_id' ) );
684
685 $entry_ids = FrmDb::get_col( $wpdb->prefix . 'frm_items it', $query );
686 unset( $query );
687
688 if ( empty( $entry_ids ) ) {
689 esc_html_e( 'There are no entries for that form.', 'formidable' );
690 } else {
691 FrmCSVExportHelper::generate_csv( compact( 'form', 'entry_ids', 'form_cols' ) );
692 }
693
694 wp_die();
695 }
696
697 /**
698 * Get the fields that should be included in the CSV export
699 *
700 * @since 2.0.19
701 * @since 5.0.16 function went from private to public.
702 *
703 * @param int $form_id
704 * @param object $form
705 *
706 * @return array $csv_fields
707 */
708 public static function get_fields_for_csv_export( $form_id, $form ) {
709 $csv_fields = FrmField::get_all_for_form( $form_id, '', 'include', 'include' );
710 $no_export_fields = FrmField::no_save_fields();
711 foreach ( $csv_fields as $k => $f ) {
712 if ( in_array( $f->type, $no_export_fields, true ) ) {
713 unset( $csv_fields[ $k ] );
714 }
715 }
716
717 return apply_filters( 'frm_fields_for_csv_export', $csv_fields, compact( 'form' ) );
718 }
719
720 public static function allow_mime( $mimes ) {
721 if ( ! isset( $mimes['csv'] ) ) {
722 // allow csv files
723 $mimes['csv'] = 'text/csv';
724 }
725
726 if ( ! isset( $mimes['xml'] ) ) {
727 // allow xml
728 $mimes['xml'] = 'text/xml';
729 }
730
731 return $mimes;
732 }
733 }
734