PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / trunk
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More vtrunk
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmFormState.php +33 -11 6.25 → trunk View file →
@@ -13,9 +13,9 @@
13 13 */
14 14 class FrmFormState {
15 15
16 16 /**
17 - * @var FrmFormState
17 + * @var FrmFormState|null
18 18 */
19 19 private static $instance;
20 20
21 21 /**
@@ -29,8 +29,9 @@
29 29
30 30 /**
31 31 * @param string $key
32 32 * @param mixed $value
33 + *
33 34 * @return void
34 35 */
35 36 public static function set_initial_value( $key, $value ) {
36 37 if ( is_callable( 'FrmProFormState::set_initial_value' ) ) {
@@ -45,9 +46,9 @@
45 46 /**
46 47 * @return bool true if just initialized.
47 48 */
48 49 private static function maybe_initialize() {
49 - if ( empty( self::$instance ) ) {
50 + if ( ! self::$instance ) {
50 51 self::$instance = new self();
51 52 return true;
52 53 }
53 54 return false;
@@ -55,8 +56,9 @@
55 56
56 57 /**
57 58 * @param string $key
58 59 * @param mixed $value
60 + *
59 61 * @return void
60 62 */
61 63 public function set( $key, $value ) {
62 64 $this->state[ $key ] = $value;
@@ -64,8 +66,9 @@
64 66
65 67 /**
66 68 * @param string $key
67 69 * @param mixed $default
70 + *
68 71 * @return mixed
69 72 */
70 73 public static function get_from_request( $key, $default ) {
71 74 if ( self::maybe_initialize() ) {
@@ -73,8 +76,14 @@
73 76 }
74 77 return self::$instance->get( $key, $default );
75 78 }
76 79
80 + /**
81 + * @param string $key
82 + * @param mixed $default
83 + *
84 + * @return mixed
85 + */
77 86 public function get( $key, $default ) {
78 87 return $this->state[ $key ] ?? $default;
79 88 }
80 89
@@ -83,8 +92,9 @@
83 92 * This is required only when submitting with AJAX.
84 93 * It is used to track the value of a title=1|0 or description=1|0 option in a [formidable] shortcode.
85 94 *
86 95 * @param stdClass $form
96 + *
87 97 * @return void
88 98 */
89 99 public static function maybe_render_state_field( $form ) {
90 100 if ( is_callable( 'FrmProFormState::maybe_render_state_field' ) ) {
@@ -92,9 +102,9 @@
92 102 // This way we can also avoid duplicate state fields if Pro isn't up to date.
93 103 return;
94 104 }
95 105
96 - if ( empty( self::$instance ) && ! self::get_state_from_request() ) {
106 + if ( ! self::$instance && ! self::get_state_from_request() ) {
97 107 return;
98 108 }
99 109
100 110 $honeypot_field_id = self::$instance->get( 'honeypot_field_id', 0 );
@@ -121,23 +131,30 @@
121 131 * @return bool true if there is valid state data in the request.
122 132 */
123 133 private static function get_state_from_request() {
124 134 $encrypted_state = FrmAppHelper::get_post_param( 'frm_state', '', 'sanitize_text_field' );
135 +
125 136 if ( ! $encrypted_state ) {
126 137 return false;
127 138 }
139 +
128 140 $secret = self::get_encryption_secret();
129 141 $decrypted_state = openssl_decrypt( $encrypted_state, 'AES-128-ECB', $secret );
142 +
130 143 if ( false === $decrypted_state ) {
131 144 return false;
132 145 }
146 +
133 147 $decoded_state = json_decode( $decrypted_state, true );
148 +
134 149 if ( ! is_array( $decoded_state ) ) {
135 150 return false;
136 151 }
152 +
137 153 foreach ( $decoded_state as $key => $value ) {
138 154 self::set_initial_value( self::decompressed_key( $key ), $value );
139 155 }
156 +
140 157 return true;
141 158 }
142 159
143 160 /**
@@ -146,13 +163,14 @@
146 163 public function render_state_field() {
147 164 if ( ! self::open_ssl_is_installed() ) {
148 165 return;
149 166 }
167 +
150 168 if ( ! $this->state && ! self::get_state_from_request() ) {
151 169 return;
152 170 }
153 - $state_string = $this->get_state_string();
154 - echo '<input name="frm_state" type="hidden" value="' . esc_attr( $state_string ) . '" />';
171 +
172 + echo '<input name="frm_state" type="hidden" value="' . esc_attr( $this->get_state_string() ) . '" />';
155 173 }
156 174
157 175 /**
158 176 * @return string
@@ -160,13 +178,12 @@
160 178 private function get_state_string() {
161 179 if ( ! self::open_ssl_is_installed() ) {
162 180 return '';
163 181 }
164 - $secret = self::get_encryption_secret();
165 - $compressed_state = $this->compressed_state();
166 - $json_encoded = json_encode( $compressed_state );
167 - $encrypted = openssl_encrypt( $json_encoded, 'AES-128-ECB', $secret );
168 - return $encrypted;
182 +
183 + $secret = self::get_encryption_secret();
184 + $json_encoded = json_encode( $this->compressed_state() );
185 + return openssl_encrypt( $json_encoded, 'AES-128-ECB', $secret );
169 186 }
170 187
171 188 /**
172 189 * Returns true if open SSL is installed.
@@ -171,8 +188,9 @@
171 188 /**
172 189 * Returns true if open SSL is installed.
173 190 *
174 191 * @since 6.12
192 + *
175 193 * @return bool
176 194 */
177 195 private static function open_ssl_is_installed() {
178 196 return function_exists( 'openssl_encrypt' );
@@ -184,11 +202,13 @@
184 202 * @return array
185 203 */
186 204 private function compressed_state() {
187 205 $compressed = array();
206 +
188 207 foreach ( $this->state as $key => $value ) {
189 208 $compressed[ self::compressed_key( $key ) ] = $value;
190 209 }
210 +
191 211 return $compressed;
192 212 }
193 213
194 214 /**
@@ -196,8 +216,9 @@
196 216 * "title" => "t".
197 217 * "description" => "d".
198 218 *
199 219 * @param string $key
220 + *
200 221 * @return string
201 222 */
202 223 private static function compressed_key( $key ) {
203 224 return $key[0];
@@ -208,8 +229,9 @@
208 229 * Pro supports additional keys include "i" for include_fields and "g" for get params.
209 230 * To avoid conflicts, we should not add "i" or "g" in Lite for another state property.
210 231 *
211 232 * @param string $key
233 + *
212 234 * @return string The full key name if one is found. If nothing is found, the $key param is passed back.
213 235 */
214 236 private static function decompressed_key( $key ) {
215 237 switch ( $key ) {
@@ -235,9 +257,9 @@
235 257 }
236 258
237 259 // We don't have a secret, so let's generate one.
238 260 $secret_key = is_callable( 'sodium_crypto_secretbox_keygen' ) ? sodium_crypto_secretbox_keygen() : wp_generate_password( 32, true, true );
239 - update_option( 'frm_form_state_key', base64_encode( $secret_key ), 'no' ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_encode
261 + update_option( 'frm_form_state_key', base64_encode( $secret_key ), false ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_encode
240 262
241 263 return $secret_key;
242 264 }
243 265 }