PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / trunk
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More vtrunk
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmAntiSpam.php +50 -23 6.26 → trunk View file →
@@ -12,8 +12,20 @@
12 12 */
13 13 class FrmAntiSpam extends FrmValidate {
14 14
15 15 /**
16 + * Track when the token filters have been added so they are only added once.
17 + * The callback checks the Anti-Spam setting of the form being rendered, so
18 + * a single callback covers every form on the page. Adding one callback for
19 + * each form would print duplicate data-token attributes.
20 + *
21 + * @since 6.34
22 + *
23 + * @var bool
24 + */
25 + private static $filters_added = false;
26 +
27 + /**
16 28 * @return string
17 29 */
18 30 protected function get_option_key() {
19 31 return 'antispam';
@@ -39,10 +51,16 @@
39 51 *
40 52 * @return void
41 53 */
42 54 public function init() {
43 - add_filter( 'frm_form_attributes', array( $this, 'add_token_to_form' ), 10, 1 );
44 - add_filter( 'frm_form_div_attributes', array( $this, 'add_token_to_form' ), 10, 1 );
55 + if ( self::$filters_added ) {
56 + return;
57 + }
58 +
59 + self::$filters_added = true;
60 +
61 + add_filter( 'frm_form_attributes', array( $this, 'add_token_to_form' ), 10, 2 );
62 + add_filter( 'frm_form_div_attributes', array( $this, 'add_token_to_form' ), 10, 2 );
45 63 }
46 64
47 65 /**
48 66 * Return a valid token.
@@ -55,13 +73,9 @@
55 73 */
56 74 private function get( $current = true ) {
57 75 // If $current was not passed, or it is true, we use the current timestamp.
58 76 // If $current was passed in as a string, we'll use that passed in timestamp.
59 - if ( $current !== true ) {
60 - $time = $current;
61 - } else {
62 - $time = time();
63 - }
77 + $time = $current === true ? time() : $current;
64 78
65 79 // Format the timestamp to be less exact, as we want to deal in days.
66 80 // June 19th, 2020 would get formatted as: 1906202017125.
67 81 // Day of the month, month number, year, day number of the year, week number of the year.
@@ -67,11 +81,9 @@
67 81 // Day of the month, month number, year, day number of the year, week number of the year.
68 82 $token_date = gmdate( 'dmYzW', $time );
69 83
70 84 // Combine our token date and our token salt, and md5 it.
71 - $form_token_string = md5( $token_date . $this->get_antispam_secret_key() );
72 -
73 - return $form_token_string;
85 + return md5( $token_date . $this->get_antispam_secret_key() );
74 86 }
75 87
76 88 /**
77 89 * @return string
@@ -106,9 +118,9 @@
106 118 private function get_valid_tokens() {
107 119 $current_date = time();
108 120
109 121 // Create our array of times to check before today. A user with a longer
110 - // cache time can extend this. A user with a shorter cache time can remove times.
122 + // Cache time can extend this. A user with a shorter cache time can remove times.
111 123 $valid_token_times_before = apply_filters(
112 124 'frm_form_token_check_before_today',
113 125 array(
114 126 // Two days ago.
@@ -113,9 +125,9 @@
113 125 array(
114 126 // Two days ago.
115 127 2 * DAY_IN_SECONDS,
116 128 // One day ago.
117 - 1 * DAY_IN_SECONDS,
129 + DAY_IN_SECONDS,
118 130 )
119 131 );
120 132
121 133 // Mostly to catch edge cases like the form page loading and submitting on two different days.
@@ -165,19 +177,31 @@
165 177 return in_array( $token, $this->get_valid_tokens(), true );
166 178 }
167 179
168 180 /**
169 - * Add the token field to the form.
181 + * Add the token field to the form if the form has Anti-Spam enabled.
170 182 *
171 183 * @since 4.11
184 + * @since 6.34 The $form param was added, and forms without Anti-Spam enabled are now skipped.
172 185 *
173 - * @param string $attributes
186 + * @param string $attributes
187 + * @param object|null $form The form being rendered.
174 188 *
175 189 * @return string
176 190 */
177 - public function add_token_to_form( $attributes ) {
178 - $attributes .= ' data-token="' . esc_attr( $this->get() ) . '"';
179 - return $attributes;
191 + public function add_token_to_form( $attributes, $form = null ) {
192 + $antispam = $this;
193 +
194 + if ( $form ) {
195 + $antispam = new self( (int) $form->id );
196 + $antispam->form = $form;
197 + }
198 +
199 + if ( ! $antispam->run_antispam() ) {
200 + return $attributes;
201 + }
202 +
203 + return $attributes . ( ' data-token="' . esc_attr( $antispam->get() ) . '"' );
180 204 }
181 205
182 206 /**
183 207 * @param int $form_id
@@ -215,11 +239,12 @@
215 239
216 240 // If the antispam setting is enabled and we don't have a token, bail.
217 241 if ( ! $token ) {
218 242 if ( FrmAppHelper::is_admin_page( 'formidable-entries' ) ) {
219 - // add an exception for the entries page.
243 + // Add an exception for the entries page.
220 244 return true;
221 245 }
246 +
222 247 return $this->process_antispam_filter( $this->get_missing_token_message() );
223 248 }
224 249
225 250 // Verify the token.
@@ -279,13 +304,13 @@
279 304 }
280 305
281 306 // If the user is an admin, return text with a link to support.
282 307 // We add a space here to separate the sentences, but outside of the localized
283 - // text to avoid it being removed.
308 + // Text to avoid it being removed.
284 309 return ' ' . sprintf(
285 310 // translators: %1$s start link, %2$s end link.
286 311 esc_html__( 'Please check out our %1$stroubleshooting guide%2$s for details on resolving this issue.', 'formidable' ),
287 - '<a href="https://formidableforms.com/knowledgebase/add-spam-protection/">',
312 + '<a href="https://formidableforms.com/knowledgebase/add-spam-protection/" target="_blank" rel="noopener">',
288 313 '</a>'
289 314 );
290 315 }
291 316
@@ -320,12 +345,14 @@
320 345 /**
321 346 * @return void
322 347 */
323 348 private static function clear_wp_super_cache() {
324 - if ( function_exists( 'wp_cache_clean_cache' ) ) {
325 - global $file_prefix;
326 - wp_cache_clean_cache( $file_prefix, true );
349 + if ( ! function_exists( 'wp_cache_clean_cache' ) ) {
350 + return;
327 351 }
352 +
353 + global $file_prefix;
354 + wp_cache_clean_cache( $file_prefix, true );
328 355 }
329 356
330 357 /**
331 358 * @return void