PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / trunk
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More vtrunk
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmAntiSpam.php +61 -42 6.3 → trunk View file →
@@ -12,8 +12,20 @@
12 12 */
13 13 class FrmAntiSpam extends FrmValidate {
14 14
15 15 /**
16 + * Track when the token filters have been added so they are only added once.
17 + * The callback checks the Anti-Spam setting of the form being rendered, so
18 + * a single callback covers every form on the page. Adding one callback for
19 + * each form would print duplicate data-token attributes.
20 + *
21 + * @since 6.34
22 + *
23 + * @var bool
24 + */
25 + private static $filters_added = false;
26 +
27 + /**
16 28 * @return string
17 29 */
18 30 protected function get_option_key() {
19 31 return 'antispam';
@@ -25,8 +37,9 @@
25 37 * @return void
26 38 */
27 39 public static function maybe_init( $form_id ) {
28 40 $antispam = new self( $form_id );
41 +
29 42 if ( $antispam->run_antispam() ) {
30 43 $antispam->init();
31 44 }
32 45 }
@@ -38,10 +51,16 @@
38 51 *
39 52 * @return void
40 53 */
41 54 public function init() {
42 - add_filter( 'frm_form_attributes', array( $this, 'add_token_to_form' ), 10, 1 );
43 - add_filter( 'frm_form_div_attributes', array( $this, 'add_token_to_form' ), 10, 1 );
55 + if ( self::$filters_added ) {
56 + return;
57 + }
58 +
59 + self::$filters_added = true;
60 +
61 + add_filter( 'frm_form_attributes', array( $this, 'add_token_to_form' ), 10, 2 );
62 + add_filter( 'frm_form_div_attributes', array( $this, 'add_token_to_form' ), 10, 2 );
44 63 }
45 64
46 65 /**
47 66 * Return a valid token.
@@ -54,13 +73,9 @@
54 73 */
55 74 private function get( $current = true ) {
56 75 // If $current was not passed, or it is true, we use the current timestamp.
57 76 // If $current was passed in as a string, we'll use that passed in timestamp.
58 - if ( $current !== true ) {
59 - $time = $current;
60 - } else {
61 - $time = time();
62 - }
77 + $time = $current === true ? time() : $current;
63 78
64 79 // Format the timestamp to be less exact, as we want to deal in days.
65 80 // June 19th, 2020 would get formatted as: 1906202017125.
66 81 // Day of the month, month number, year, day number of the year, week number of the year.
@@ -66,13 +81,14 @@
66 81 // Day of the month, month number, year, day number of the year, week number of the year.
67 82 $token_date = gmdate( 'dmYzW', $time );
68 83
69 84 // Combine our token date and our token salt, and md5 it.
70 - $form_token_string = md5( $token_date . $this->get_antispam_secret_key() );
71 -
72 - return $form_token_string;
85 + return md5( $token_date . $this->get_antispam_secret_key() );
73 86 }
74 87
88 + /**
89 + * @return string
90 + */
75 91 private function get_antispam_secret_key() {
76 92 $secret_key = get_option( 'frm_antispam_secret_key' );
77 93
78 94 // If we already have the secret, send it back.
@@ -102,14 +118,16 @@
102 118 private function get_valid_tokens() {
103 119 $current_date = time();
104 120
105 121 // Create our array of times to check before today. A user with a longer
106 - // cache time can extend this. A user with a shorter cache time can remove times.
122 + // Cache time can extend this. A user with a shorter cache time can remove times.
107 123 $valid_token_times_before = apply_filters(
108 124 'frm_form_token_check_before_today',
109 125 array(
110 - ( 2 * DAY_IN_SECONDS ), // Two days ago.
111 - ( 1 * DAY_IN_SECONDS ), // One day ago.
126 + // Two days ago.
127 + 2 * DAY_IN_SECONDS,
128 + // One day ago.
129 + DAY_IN_SECONDS,
112 130 )
113 131 );
114 132
115 133 // Mostly to catch edge cases like the form page loading and submitting on two different days.
@@ -116,9 +134,10 @@
116 134 // This probably won't be filtered by users too much, but they could extend it.
117 135 $valid_token_times_after = apply_filters(
118 136 'frm_form_token_check_after_today',
119 137 array(
120 - ( 45 * MINUTE_IN_SECONDS ), // Add in 45 minutes past today to catch some midnight edge cases.
138 + // Add in 45 minutes past today to catch some midnight edge cases.
139 + 45 * MINUTE_IN_SECONDS,
121 140 )
122 141 );
123 142
124 143 // Built up our valid tokens.
@@ -158,19 +177,31 @@
158 177 return in_array( $token, $this->get_valid_tokens(), true );
159 178 }
160 179
161 180 /**
162 - * Add the token field to the form.
181 + * Add the token field to the form if the form has Anti-Spam enabled.
163 182 *
164 183 * @since 4.11
184 + * @since 6.34 The $form param was added, and forms without Anti-Spam enabled are now skipped.
165 185 *
166 - * @param string $attributes
186 + * @param string $attributes
187 + * @param object|null $form The form being rendered.
167 188 *
168 189 * @return string
169 190 */
170 - public function add_token_to_form( $attributes ) {
171 - $attributes .= ' data-token="' . esc_attr( $this->get() ) . '"';
172 - return $attributes;
191 + public function add_token_to_form( $attributes, $form = null ) {
192 + $antispam = $this;
193 +
194 + if ( $form ) {
195 + $antispam = new self( (int) $form->id );
196 + $antispam->form = $form;
197 + }
198 +
199 + if ( ! $antispam->run_antispam() ) {
200 + return $attributes;
201 + }
202 +
203 + return $attributes . ( ' data-token="' . esc_attr( $antispam->get() ) . '"' );
173 204 }
174 205
175 206 /**
176 207 * @param int $form_id
@@ -178,8 +209,9 @@
178 209 * @return void
179 210 */
180 211 public static function maybe_echo_token( $form_id ) {
181 212 $antispam = new self( $form_id );
213 +
182 214 if ( $antispam->run_antispam() ) {
183 215 echo 'data-token="' . esc_attr( $antispam->get() ) . '"';
184 216 }
185 217 }
@@ -207,11 +239,12 @@
207 239
208 240 // If the antispam setting is enabled and we don't have a token, bail.
209 241 if ( ! $token ) {
210 242 if ( FrmAppHelper::is_admin_page( 'formidable-entries' ) ) {
211 - // add an exception for the entries page.
243 + // Add an exception for the entries page.
212 244 return true;
213 245 }
246 +
214 247 return $this->process_antispam_filter( $this->get_missing_token_message() );
215 248 }
216 249
217 250 // Verify the token.
@@ -222,24 +255,8 @@
222 255 return $this->process_antispam_filter( true );
223 256 }
224 257
225 258 /**
226 - * @return bool True if saving a draft.
227 - */
228 - private function is_saving_a_draft() {
229 - global $frm_vars;
230 - if ( empty( $frm_vars['form_params'] ) ) {
231 - return false;
232 - }
233 - $form_params = $frm_vars['form_params'];
234 - if ( ! isset( $form_params[ $this->form_id ] ) ) {
235 - return false;
236 - }
237 - $this_form_params = $form_params[ $this->form_id ];
238 - return ! empty( $this_form_params['action'] ) && 'update' === $this_form_params['action'];
239 - }
240 -
241 - /**
242 259 * Helper to run our filter on all the responses for the antispam checks.
243 260 *
244 261 * @since 4.11
245 262 *
@@ -286,14 +303,14 @@
286 303 return '';
287 304 }
288 305
289 306 // If the user is an admin, return text with a link to support.
290 - // We add a space here to seperate the sentences, but outside of the localized
291 - // text to avoid it being removed.
307 + // We add a space here to separate the sentences, but outside of the localized
308 + // Text to avoid it being removed.
292 309 return ' ' . sprintf(
293 310 // translators: %1$s start link, %2$s end link.
294 311 esc_html__( 'Please check out our %1$stroubleshooting guide%2$s for details on resolving this issue.', 'formidable' ),
295 - '<a href="https://formidableforms.com/knowledgebase/add-spam-protection/">',
312 + '<a href="https://formidableforms.com/knowledgebase/add-spam-protection/" target="_blank" rel="noopener">',
296 313 '</a>'
297 314 );
298 315 }
299 316
@@ -328,12 +345,14 @@
328 345 /**
329 346 * @return void
330 347 */
331 348 private static function clear_wp_super_cache() {
332 - if ( function_exists( 'wp_cache_clean_cache' ) ) {
333 - global $file_prefix;
334 - wp_cache_clean_cache( $file_prefix, true );
349 + if ( ! function_exists( 'wp_cache_clean_cache' ) ) {
350 + return;
335 351 }
352 +
353 + global $file_prefix;
354 + wp_cache_clean_cache( $file_prefix, true );
336 355 }
337 356
338 357 /**
339 358 * @return void