PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / trunk
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More vtrunk
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmAntiSpam.php +55 -23 6.25 → trunk View file →
@@ -12,8 +12,20 @@
12 12 */
13 13 class FrmAntiSpam extends FrmValidate {
14 14
15 15 /**
16 + * Track when the token filters have been added so they are only added once.
17 + * The callback checks the Anti-Spam setting of the form being rendered, so
18 + * a single callback covers every form on the page. Adding one callback for
19 + * each form would print duplicate data-token attributes.
20 + *
21 + * @since 6.34
22 + *
23 + * @var bool
24 + */
25 + private static $filters_added = false;
26 +
27 + /**
16 28 * @return string
17 29 */
18 30 protected function get_option_key() {
19 31 return 'antispam';
@@ -25,8 +37,9 @@
25 37 * @return void
26 38 */
27 39 public static function maybe_init( $form_id ) {
28 40 $antispam = new self( $form_id );
41 +
29 42 if ( $antispam->run_antispam() ) {
30 43 $antispam->init();
31 44 }
32 45 }
@@ -38,10 +51,16 @@
38 51 *
39 52 * @return void
40 53 */
41 54 public function init() {
42 - add_filter( 'frm_form_attributes', array( $this, 'add_token_to_form' ), 10, 1 );
43 - add_filter( 'frm_form_div_attributes', array( $this, 'add_token_to_form' ), 10, 1 );
55 + if ( self::$filters_added ) {
56 + return;
57 + }
58 +
59 + self::$filters_added = true;
60 +
61 + add_filter( 'frm_form_attributes', array( $this, 'add_token_to_form' ), 10, 2 );
62 + add_filter( 'frm_form_div_attributes', array( $this, 'add_token_to_form' ), 10, 2 );
44 63 }
45 64
46 65 /**
47 66 * Return a valid token.
@@ -54,13 +73,9 @@
54 73 */
55 74 private function get( $current = true ) {
56 75 // If $current was not passed, or it is true, we use the current timestamp.
57 76 // If $current was passed in as a string, we'll use that passed in timestamp.
58 - if ( $current !== true ) {
59 - $time = $current;
60 - } else {
61 - $time = time();
62 - }
77 + $time = $current === true ? time() : $current;
63 78
64 79 // Format the timestamp to be less exact, as we want to deal in days.
65 80 // June 19th, 2020 would get formatted as: 1906202017125.
66 81 // Day of the month, month number, year, day number of the year, week number of the year.
@@ -66,13 +81,14 @@
66 81 // Day of the month, month number, year, day number of the year, week number of the year.
67 82 $token_date = gmdate( 'dmYzW', $time );
68 83
69 84 // Combine our token date and our token salt, and md5 it.
70 - $form_token_string = md5( $token_date . $this->get_antispam_secret_key() );
71 -
72 - return $form_token_string;
85 + return md5( $token_date . $this->get_antispam_secret_key() );
73 86 }
74 87
88 + /**
89 + * @return string
90 + */
75 91 private function get_antispam_secret_key() {
76 92 $secret_key = get_option( 'frm_antispam_secret_key' );
77 93
78 94 // If we already have the secret, send it back.
@@ -102,9 +118,9 @@
102 118 private function get_valid_tokens() {
103 119 $current_date = time();
104 120
105 121 // Create our array of times to check before today. A user with a longer
106 - // cache time can extend this. A user with a shorter cache time can remove times.
122 + // Cache time can extend this. A user with a shorter cache time can remove times.
107 123 $valid_token_times_before = apply_filters(
108 124 'frm_form_token_check_before_today',
109 125 array(
110 126 // Two days ago.
@@ -109,9 +125,9 @@
109 125 array(
110 126 // Two days ago.
111 127 2 * DAY_IN_SECONDS,
112 128 // One day ago.
113 - 1 * DAY_IN_SECONDS,
129 + DAY_IN_SECONDS,
114 130 )
115 131 );
116 132
117 133 // Mostly to catch edge cases like the form page loading and submitting on two different days.
@@ -161,19 +177,31 @@
161 177 return in_array( $token, $this->get_valid_tokens(), true );
162 178 }
163 179
164 180 /**
165 - * Add the token field to the form.
181 + * Add the token field to the form if the form has Anti-Spam enabled.
166 182 *
167 183 * @since 4.11
184 + * @since 6.34 The $form param was added, and forms without Anti-Spam enabled are now skipped.
168 185 *
169 - * @param string $attributes
186 + * @param string $attributes
187 + * @param object|null $form The form being rendered.
170 188 *
171 189 * @return string
172 190 */
173 - public function add_token_to_form( $attributes ) {
174 - $attributes .= ' data-token="' . esc_attr( $this->get() ) . '"';
175 - return $attributes;
191 + public function add_token_to_form( $attributes, $form = null ) {
192 + $antispam = $this;
193 +
194 + if ( $form ) {
195 + $antispam = new self( (int) $form->id );
196 + $antispam->form = $form;
197 + }
198 +
199 + if ( ! $antispam->run_antispam() ) {
200 + return $attributes;
201 + }
202 +
203 + return $attributes . ( ' data-token="' . esc_attr( $antispam->get() ) . '"' );
176 204 }
177 205
178 206 /**
179 207 * @param int $form_id
@@ -181,8 +209,9 @@
181 209 * @return void
182 210 */
183 211 public static function maybe_echo_token( $form_id ) {
184 212 $antispam = new self( $form_id );
213 +
185 214 if ( $antispam->run_antispam() ) {
186 215 echo 'data-token="' . esc_attr( $antispam->get() ) . '"';
187 216 }
188 217 }
@@ -210,11 +239,12 @@
210 239
211 240 // If the antispam setting is enabled and we don't have a token, bail.
212 241 if ( ! $token ) {
213 242 if ( FrmAppHelper::is_admin_page( 'formidable-entries' ) ) {
214 - // add an exception for the entries page.
243 + // Add an exception for the entries page.
215 244 return true;
216 245 }
246 +
217 247 return $this->process_antispam_filter( $this->get_missing_token_message() );
218 248 }
219 249
220 250 // Verify the token.
@@ -274,13 +304,13 @@
274 304 }
275 305
276 306 // If the user is an admin, return text with a link to support.
277 307 // We add a space here to separate the sentences, but outside of the localized
278 - // text to avoid it being removed.
308 + // Text to avoid it being removed.
279 309 return ' ' . sprintf(
280 310 // translators: %1$s start link, %2$s end link.
281 311 esc_html__( 'Please check out our %1$stroubleshooting guide%2$s for details on resolving this issue.', 'formidable' ),
282 - '<a href="https://formidableforms.com/knowledgebase/add-spam-protection/">',
312 + '<a href="https://formidableforms.com/knowledgebase/add-spam-protection/" target="_blank" rel="noopener">',
283 313 '</a>'
284 314 );
285 315 }
286 316
@@ -315,12 +345,14 @@
315 345 /**
316 346 * @return void
317 347 */
318 348 private static function clear_wp_super_cache() {
319 - if ( function_exists( 'wp_cache_clean_cache' ) ) {
320 - global $file_prefix;
321 - wp_cache_clean_cache( $file_prefix, true );
349 + if ( ! function_exists( 'wp_cache_clean_cache' ) ) {
350 + return;
322 351 }
352 +
353 + global $file_prefix;
354 + wp_cache_clean_cache( $file_prefix, true );
323 355 }
324 356
325 357 /**
326 358 * @return void