PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / trunk
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More vtrunk
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmEntry.php +44 -3 6.34 → trunk View file →
@@ -865,9 +865,9 @@
865 865 'description' => self::get_entry_description( $values ),
866 866 'user_id' => self::get_entry_user_id( $values, $type ),
867 867 );
868 868
869 - $new_values['updated_by'] = $values['updated_by'] ?? $new_values['user_id'];
869 + $new_values['updated_by'] = self::get_updated_by( $values, $type, $new_values['user_id'] );
870 870
871 871 return $new_values;
872 872 }
873 873
@@ -882,8 +882,33 @@
882 882 return $values[ $name ] ?? $default;
883 883 }
884 884
885 885 /**
886 + * Get the updated_by value for an entry.
887 + *
888 + * The submitted value is only used during a trusted import, which restores the user who last
889 + * edited each entry. Every other save is being made by the current user, so a submitted
890 + * updated_by is ignored and cannot be pointed at another account. This matters because
891 + * updated_by is treated as a privilege signal when deciding how much HTML to strip from entry
892 + * values in FrmFieldType::should_strip_most_html().
893 + *
894 + * @since 6.35
895 + *
896 + * @param array $values
897 + * @param string $type The create/update type. 'xml' for an import.
898 + * @param int|string $default The value to use when an import doesn't include updated_by.
899 + *
900 + * @return int
901 + */
902 + private static function get_updated_by( $values, $type, $default ) {
903 + if ( self::is_trusted_import( $type ) ) {
904 + return absint( self::get_entry_value( $values, 'updated_by', $default ) );
905 + }
906 +
907 + return get_current_user_id();
908 + }
909 +
910 + /**
886 911 * Get the ip for a new entry.
887 912 * Allow the import to override the value.
888 913 *
889 914 * @since 2.03.10
@@ -1004,9 +1029,9 @@
1004 1029 *
1005 1030 * @return bool
1006 1031 */
1007 1032 private static function can_set_entry_user_id_from_values( $type = 'standard' ) {
1008 - if ( 'xml' === $type || ( defined( 'WP_IMPORTING' ) && WP_IMPORTING ) ) {
1033 + if ( self::is_trusted_import( $type ) ) {
1009 1034 return true;
1010 1035 }
1011 1036
1012 1037 return current_user_can( 'frm_edit_entries' ) || current_user_can( 'administrator' );
@@ -1012,8 +1037,24 @@
1012 1037 return current_user_can( 'frm_edit_entries' ) || current_user_can( 'administrator' );
1013 1038 }
1014 1039
1015 1040 /**
1041 + * Whether an entry is being saved by an import rather than by a normal request.
1042 + *
1043 + * An import is trusted to restore the values stored on each entry, including the columns that
1044 + * are otherwise taken from the current request.
1045 + *
1046 + * @since 6.35
1047 + *
1048 + * @param string $type The create/update type. 'xml' for an import.
1049 + *
1050 + * @return bool
1051 + */
1052 + private static function is_trusted_import( $type = 'standard' ) {
1053 + return 'xml' === $type || ( defined( 'WP_IMPORTING' ) && WP_IMPORTING );
1054 + }
1055 +
1056 + /**
1016 1057 * Insert new entry into the database
1017 1058 *
1018 1059 * @since 2.0.16
1019 1060 *
@@ -1206,9 +1247,9 @@
1206 1247 'name' => FrmAppHelper::truncate( self::get_new_entry_name( $values ), 255, 1, '', true ),
1207 1248 'form_id' => (int) self::get_entry_value( $values, 'form_id', null ),
1208 1249 'is_draft' => self::get_is_draft_value( $values ),
1209 1250 'updated_at' => current_time( 'mysql', 1 ),
1210 - 'updated_by' => $values['updated_by'] ?? get_current_user_id(),
1251 + 'updated_by' => self::get_updated_by( $values, $update_type, get_current_user_id() ),
1211 1252 );
1212 1253
1213 1254 if ( isset( $values['post_id'] ) ) {
1214 1255 $new_values['post_id'] = (int) $values['post_id'];