PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / trunk
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More vtrunk
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmEntry.php +101 -16 6.28 → trunk View file →
@@ -348,9 +348,9 @@
348 348 if ( ! $update ) {
349 349 return false;
350 350 }
351 351
352 - $new_values = self::package_entry_to_update( $id, $values );
352 + $new_values = self::package_entry_to_update( $id, $values, $update_type );
353 353 $query_results = $wpdb->update( $wpdb->prefix . 'frm_items', $new_values, compact( 'id' ) );
354 354
355 355 self::after_update_entry( $query_results, $id, $values, $new_values );
356 356
@@ -781,9 +781,9 @@
781 781 if ( $type !== 'xml' ) {
782 782 $values = apply_filters( 'frm_pre_create_entry', $values );
783 783 }
784 784
785 - return self::package_entry_data( $values );
785 + return self::package_entry_data( $values, $type );
786 786 }
787 787
788 788 /**
789 789 * Create an entry and perform after create actions
@@ -838,13 +838,14 @@
838 838 * Prepare the new values for inserting into the database
839 839 *
840 840 * @since 2.0.16
841 841 *
842 - * @param array $values
842 + * @param array $values
843 + * @param string $type The create type. 'xml' for an import.
843 844 *
844 845 * @return array New values.
845 846 */
846 - private static function package_entry_data( &$values ) {
847 + private static function package_entry_data( &$values, $type = 'standard' ) {
847 848 global $wpdb;
848 849
849 850 if ( ! isset( $values['item_key'] ) ) {
850 851 $values['item_key'] = '';
@@ -852,9 +853,9 @@
852 853
853 854 $item_name = self::get_new_entry_name( $values, $values['item_key'] );
854 855 $new_values = array(
855 856 'item_key' => FrmAppHelper::get_unique_key( $values['item_key'], $wpdb->prefix . 'frm_items', 'item_key' ),
856 - 'name' => FrmAppHelper::truncate( $item_name, 255, 1, '' ),
857 + 'name' => FrmAppHelper::truncate( $item_name, 255, 1, '', true ),
857 858 'ip' => self::get_ip( $values ),
858 859 'is_draft' => self::get_is_draft_value( $values ),
859 860 'form_id' => (int) self::get_entry_value( $values, 'form_id', null ),
860 861 'post_id' => (int) self::get_entry_value( $values, 'post_id', 0 ),
@@ -861,12 +862,12 @@
861 862 'parent_item_id' => (int) self::get_entry_value( $values, 'parent_item_id', 0 ),
862 863 'created_at' => self::get_created_at( $values ),
863 864 'updated_at' => self::get_updated_at( $values ),
864 865 'description' => self::get_entry_description( $values ),
865 - 'user_id' => self::get_entry_user_id( $values ),
866 + 'user_id' => self::get_entry_user_id( $values, $type ),
866 867 );
867 868
868 - $new_values['updated_by'] = $values['updated_by'] ?? $new_values['user_id'];
869 + $new_values['updated_by'] = self::get_updated_by( $values, $type, $new_values['user_id'] );
869 870
870 871 return $new_values;
871 872 }
872 873
@@ -881,8 +882,33 @@
881 882 return $values[ $name ] ?? $default;
882 883 }
883 884
884 885 /**
886 + * Get the updated_by value for an entry.
887 + *
888 + * The submitted value is only used during a trusted import, which restores the user who last
889 + * edited each entry. Every other save is being made by the current user, so a submitted
890 + * updated_by is ignored and cannot be pointed at another account. This matters because
891 + * updated_by is treated as a privilege signal when deciding how much HTML to strip from entry
892 + * values in FrmFieldType::should_strip_most_html().
893 + *
894 + * @since 6.35
895 + *
896 + * @param array $values
897 + * @param string $type The create/update type. 'xml' for an import.
898 + * @param int|string $default The value to use when an import doesn't include updated_by.
899 + *
900 + * @return int
901 + */
902 + private static function get_updated_by( $values, $type, $default ) {
903 + if ( self::is_trusted_import( $type ) ) {
904 + return absint( self::get_entry_value( $values, 'updated_by', $default ) );
905 + }
906 +
907 + return get_current_user_id();
908 + }
909 +
910 + /**
885 911 * Get the ip for a new entry.
886 912 * Allow the import to override the value.
887 913 *
888 914 * @since 2.03.10
@@ -974,14 +1000,15 @@
974 1000 * Get the user_id value for a new entry
975 1001 *
976 1002 * @since 2.0.16
977 1003 *
978 - * @param array $values
1004 + * @param array $values
1005 + * @param string $type The create type. 'xml' for an import.
979 1006 *
980 1007 * @return int
981 1008 */
982 - private static function get_entry_user_id( $values ) {
983 - if ( isset( $values['frm_user_id'] ) && ( is_numeric( $values['frm_user_id'] ) || FrmAppHelper::is_admin() ) ) {
1009 + private static function get_entry_user_id( $values, $type = 'standard' ) {
1010 + if ( isset( $values['frm_user_id'] ) && self::can_set_entry_user_id_from_values( $type ) ) {
984 1011 return $values['frm_user_id'];
985 1012 }
986 1013
987 1014 $current_user_id = get_current_user_id();
@@ -988,8 +1015,46 @@
988 1015 return $current_user_id ? $current_user_id : 0;
989 1016 }
990 1017
991 1018 /**
1019 + * Whether a submitted frm_user_id is allowed to set the entry owner.
1020 + *
1021 + * The owner is only taken from the submitted value when the current user is allowed to manage
1022 + * entries, or during a trusted import that restores each entry's original owner. On a public
1023 + * submission neither is true, so the owner falls back to the current user and cannot be set to
1024 + * another account.
1025 + *
1026 + * @since 6.34
1027 + *
1028 + * @param string $type The create/update type. 'xml' for an import.
1029 + *
1030 + * @return bool
1031 + */
1032 + private static function can_set_entry_user_id_from_values( $type = 'standard' ) {
1033 + if ( self::is_trusted_import( $type ) ) {
1034 + return true;
1035 + }
1036 +
1037 + return current_user_can( 'frm_edit_entries' ) || current_user_can( 'administrator' );
1038 + }
1039 +
1040 + /**
1041 + * Whether an entry is being saved by an import rather than by a normal request.
1042 + *
1043 + * An import is trusted to restore the values stored on each entry, including the columns that
1044 + * are otherwise taken from the current request.
1045 + *
1046 + * @since 6.35
1047 + *
1048 + * @param string $type The create/update type. 'xml' for an import.
1049 + *
1050 + * @return bool
1051 + */
1052 + private static function is_trusted_import( $type = 'standard' ) {
1053 + return 'xml' === $type || ( defined( 'WP_IMPORTING' ) && WP_IMPORTING );
1054 + }
1055 +
1056 + /**
992 1057 * Insert new entry into the database
993 1058 *
994 1059 * @since 2.0.16
995 1060 *
@@ -1102,8 +1167,18 @@
1102 1167 $is_child = isset( $values['parent_nonce'] ) && ! empty( $values['parent_form_id'] ) && wp_verify_nonce( $values['parent_nonce'], 'parent' );
1103 1168
1104 1169 do_action( 'frm_after_create_entry', $entry_id, $new_values['form_id'], compact( 'is_child' ) );
1105 1170 do_action( 'frm_after_create_entry_' . $new_values['form_id'], $entry_id, compact( 'is_child' ) );
1171 +
1172 + if ( ! empty( $values['form_key'] ) ) {
1173 + /**
1174 + * @since 6.30
1175 + *
1176 + * @param int $entry_id
1177 + * @param array $is_child
1178 + */
1179 + do_action( 'frm_after_create_entry_' . $values['form_key'], $entry_id, compact( 'is_child' ) );
1180 + }
1106 1181 }
1107 1182
1108 1183 /**
1109 1184 * Actions to perform immediately after an entry is inserted in the frm_items database
@@ -1158,22 +1233,23 @@
1158 1233 * Package the entry data for updating
1159 1234 *
1160 1235 * @since 2.0.16
1161 1236 *
1162 - * @param int $id
1163 - * @param array $values
1237 + * @param int $id
1238 + * @param array $values
1239 + * @param string $update_type The update type. 'xml' for an import.
1164 1240 *
1165 1241 * @return array New values.
1166 1242 */
1167 - private static function package_entry_to_update( $id, $values ) {
1243 + private static function package_entry_to_update( $id, $values, $update_type = 'standard' ) {
1168 1244 global $wpdb;
1169 1245
1170 1246 $new_values = array(
1171 - 'name' => self::get_new_entry_name( $values ),
1247 + 'name' => FrmAppHelper::truncate( self::get_new_entry_name( $values ), 255, 1, '', true ),
1172 1248 'form_id' => (int) self::get_entry_value( $values, 'form_id', null ),
1173 1249 'is_draft' => self::get_is_draft_value( $values ),
1174 1250 'updated_at' => current_time( 'mysql', 1 ),
1175 - 'updated_by' => $values['updated_by'] ?? get_current_user_id(),
1251 + 'updated_by' => self::get_updated_by( $values, $update_type, get_current_user_id() ),
1176 1252 );
1177 1253
1178 1254 if ( isset( $values['post_id'] ) ) {
1179 1255 $new_values['post_id'] = (int) $values['post_id'];
@@ -1186,9 +1262,9 @@
1186 1262 if ( isset( $values['parent_item_id'] ) ) {
1187 1263 $new_values['parent_item_id'] = (int) $values['parent_item_id'];
1188 1264 }
1189 1265
1190 - if ( isset( $values['frm_user_id'] ) && is_numeric( $values['frm_user_id'] ) ) {
1266 + if ( isset( $values['frm_user_id'] ) && is_numeric( $values['frm_user_id'] ) && self::can_set_entry_user_id_from_values( $update_type ) ) {
1191 1267 $new_values['user_id'] = $values['frm_user_id'];
1192 1268 }
1193 1269
1194 1270 return apply_filters( 'frm_update_entry', $new_values, $id );
@@ -1224,8 +1300,17 @@
1224 1300 }
1225 1301
1226 1302 do_action( 'frm_after_update_entry', $id, $new_values['form_id'] );
1227 1303 do_action( 'frm_after_update_entry_' . $new_values['form_id'], $id );
1304 +
1305 + if ( ! empty( $values['form_key'] ) ) {
1306 + /**
1307 + * @since 6.30
1308 + *
1309 + * @param int $entry_id
1310 + */
1311 + do_action( 'frm_after_update_entry_' . $values['form_key'], $id );
1312 + }
1228 1313 }
1229 1314
1230 1315 /**
1231 1316 * Create entry from an XML import