PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / trunk
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More vtrunk
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/models/FrmSettings.php +347 -80 6.5 → trunk View file →
@@ -4,61 +4,254 @@
4 4 }
5 5
6 6 #[\AllowDynamicProperties]
7 7 class FrmSettings {
8 +
9 + /**
10 + * @var string
11 + */
8 12 public $option_name = 'frm_options';
13 +
14 + /**
15 + * @var int
16 + */
9 17 public $menu;
18 +
19 + /**
20 + * @var int
21 + */
10 22 public $mu_menu;
11 - public $use_html;
12 - public $jquery_css;
13 - public $accordion_js;
23 +
24 + /**
25 + * @var int
26 + */
14 27 public $fade_form;
15 - public $old_css;
28 +
29 + /**
30 + * @var bool
31 + */
16 32 public $admin_bar;
17 33
34 + /**
35 + * @var string
36 + */
18 37 public $success_msg;
38 +
39 + /**
40 + * @var string
41 + */
19 42 public $blank_msg;
43 +
44 + /**
45 + * @var string
46 + */
20 47 public $unique_msg;
48 +
49 + /**
50 + * @var string
51 + */
21 52 public $invalid_msg;
53 +
54 + /**
55 + * @var string
56 + */
22 57 public $failed_msg;
58 +
59 + /**
60 + * @var string
61 + */
23 62 public $submit_value;
63 +
64 + /**
65 + * @var string
66 + */
24 67 public $login_msg;
68 +
69 + /**
70 + * @var string
71 + */
25 72 public $admin_permission;
26 73
74 + /**
75 + * @var string
76 + */
27 77 public $email_to;
78 +
79 + /**
80 + * @var string|null
81 + */
28 82 public $load_style;
83 +
84 + /**
85 + * @var bool|int|null
86 + */
29 87 public $custom_style;
30 88
89 + /**
90 + * @var string|null
91 + */
31 92 public $active_captcha;
32 - public $hcaptcha_pubkey;
33 - public $hcaptcha_privkey;
93 +
94 + /**
95 + * Settings for reCAPTCHA.
96 + */
97 +
98 + /**
99 + * @var string|null
100 + */
34 101 public $pubkey;
102 +
103 + /**
104 + * @var string|null
105 + */
35 106 public $privkey;
107 +
108 + /**
109 + * @var string|null
110 + */
36 111 public $re_lang;
112 +
113 + /**
114 + * @var string|null
115 + */
37 116 public $re_type;
117 +
118 + /**
119 + * @var string
120 + */
38 121 public $re_msg;
122 +
123 + /**
124 + * @var bool
125 + */
39 126 public $re_multi;
40 127
128 + /**
129 + * @var float|string|null
130 + */
131 + public $re_threshold;
132 +
133 + /**
134 + * Settings for hCaptcha.
135 + */
136 +
137 + /**
138 + * @var string
139 + */
140 + public $hcaptcha_pubkey;
141 +
142 + /**
143 + * @var string|null
144 + */
145 + public $hcaptcha_privkey;
146 +
147 + /**
148 + * Settings for Turnstile.
149 + */
150 +
151 + /**
152 + * @var string
153 + */
154 + public $turnstile_pubkey;
155 +
156 + /**
157 + * @var string|null
158 + */
159 + public $turnstile_privkey;
160 +
161 + /**
162 + * @var bool
163 + */
41 164 public $no_ips;
165 +
166 + /**
167 + * @var string
168 + */
42 169 public $custom_header_ip;
170 +
171 + /**
172 + * @var int
173 + */
43 174 public $current_form = 0;
175 +
176 + /**
177 + * @var bool|int
178 + */
44 179 public $tracking;
45 180
181 + /**
182 + * @var bool
183 + */
184 + public $summary_emails;
185 +
186 + /**
187 + * @var string
188 + */
189 + public $summary_emails_recipients;
190 +
191 + /**
192 + * @var string|null
193 + */
194 + public $default_email;
195 +
196 + /**
197 + * @var string
198 + */
199 + public $from_email;
200 +
201 + /**
202 + * @var string|null
203 + */
46 204 public $currency;
47 205
48 206 /**
49 207 * @since 6.0
50 208 *
51 - * @var string|false|null
209 + * @var false|string|null
52 210 */
53 211 public $custom_css;
54 212
213 + /**
214 + * @var int
215 + */
216 + public $honeypot;
217 +
218 + /**
219 + * @var bool
220 + */
221 + public $wp_spam_check;
222 +
223 + /**
224 + * @var bool
225 + */
226 + public $denylist_check;
227 +
228 + /**
229 + * @since 6.25.1
230 + *
231 + * @var int|null 1 if installed after welcome tour update, null otherwise.
232 + */
233 + public $installed_after_welcome_tour_update;
234 +
235 + /**
236 + * @var string
237 + */
238 + public $disallowed_words;
239 +
240 + /**
241 + * @var string
242 + */
243 + public $allowed_words;
244 +
245 + /**
246 + * @param array $args
247 + */
55 248 public function __construct( $args = array() ) {
56 249 if ( ! defined( 'ABSPATH' ) ) {
57 250 die( 'You are not allowed to call this page directly.' );
58 251 }
59 252
60 - $settings = get_transient( $this->option_name );
253 + $settings = get_option( $this->option_name );
61 254
62 255 if ( ! is_object( $settings ) ) {
63 256 $settings = $this->translate_settings( $settings );
64 257 }
@@ -72,30 +265,24 @@
72 265
73 266 $this->maybe_filter_for_form( $args );
74 267 }
75 268
269 + /**
270 + * @param false|object $settings
271 + *
272 + * @return object
273 + */
76 274 private function translate_settings( $settings ) {
77 - if ( $settings ) { //workaround for W3 total cache conflict
275 + if ( $settings ) {
276 + // Workaround for W3 total cache conflict.
78 277 return unserialize( serialize( $settings ) );
79 278 }
80 279
81 - $settings = get_option( $this->option_name );
82 - if ( is_object( $settings ) ) {
83 - set_transient( $this->option_name, $settings );
280 + // If unserializing didn't work.
281 + $settings = $this;
84 282
85 - return $settings;
86 - }
283 + update_option( $this->option_name, $settings, true );
87 284
88 - // If unserializing didn't work
89 - if ( $settings ) { //workaround for W3 total cache conflict
90 - $settings = unserialize( serialize( $settings ) );
91 - } else {
92 - $settings = $this;
93 - }
94 -
95 - update_option( $this->option_name, $settings );
96 - set_transient( $this->option_name, $settings );
97 -
98 285 return $settings;
99 286 }
100 287
101 288 /**
@@ -102,37 +289,46 @@
102 289 * @return array
103 290 */
104 291 public function default_options() {
105 292 return array(
106 - 'menu' => apply_filters( 'frm_default_menu', 'Formidable' ),
107 - 'mu_menu' => 0,
108 - 'use_html' => true,
109 - 'jquery_css' => false,
110 - 'accordion_js' => false,
111 - 'fade_form' => false,
112 - 'old_css' => false,
113 - 'admin_bar' => false,
293 + 'menu' => apply_filters( 'frm_default_menu', 'Formidable' ),
294 + 'mu_menu' => 0,
295 + 'fade_form' => false,
296 + 'admin_bar' => false,
114 297
115 - 're_multi' => 1,
298 + 're_multi' => 1,
116 299
117 - 'success_msg' => __( 'Your responses were successfully submitted. Thank you!', 'formidable' ),
118 - 'blank_msg' => __( 'This field cannot be blank.', 'formidable' ),
119 - 'unique_msg' => __( 'This value must be unique.', 'formidable' ),
120 - 'invalid_msg' => __( 'There was a problem with your submission. Errors are marked below.', 'formidable' ),
121 - 'failed_msg' => __( 'We\'re sorry. It looks like you\'ve already submitted that.', 'formidable' ),
122 - 'submit_value' => __( 'Submit', 'formidable' ),
123 - 'login_msg' => __( 'You do not have permission to view this form.', 'formidable' ),
124 - 'admin_permission' => __( 'You do not have permission to do that', 'formidable' ),
125 - 'new_tab_msg' => __( 'The page has been opened in a new tab.', 'formidable' ),
300 + 'success_msg' => __( 'Your responses were successfully submitted. Thank you!', 'formidable' ),
301 + // translators: %s: [field_name] shortcode.
302 + 'blank_msg' => sprintf( __( '%s cannot be blank.', 'formidable' ), '[field_name]' ),
303 + // translators: %s: [field_name] shortcode.
304 + 'unique_msg' => sprintf( __( '%s must be unique.', 'formidable' ), '[field_name]' ),
305 + 'invalid_msg' => __( 'There was a problem with your submission. Errors are marked below.', 'formidable' ),
306 + 'failed_msg' => __( 'We\'re sorry. It looks like you\'ve already submitted that.', 'formidable' ),
307 + 'submit_value' => __( 'Submit', 'formidable' ),
308 + 'login_msg' => __( 'You do not have permission to view this form.', 'formidable' ),
309 + 'admin_permission' => __( 'You do not have permission to do that', 'formidable' ),
310 + 'new_tab_msg' => __( 'The page has been opened in a new tab.', 'formidable' ),
126 311
127 - 'email_to' => '[admin_email]',
128 - 'no_ips' => 0,
129 - 'custom_header_ip' => false, // Use false by default. We show a warning when this is unset. Once global settings have been saved, this gets saved
130 - 'tracking' => FrmAppHelper::pro_is_installed(),
312 + 'email_to' => '[admin_email]',
313 + 'enable_gdpr' => 0,
314 + 'no_gdpr_cookies' => 0,
315 + 'no_ips' => 0,
316 + 'custom_header_ip' => 0,
317 + 'tracking' => FrmAppHelper::pro_is_installed(),
318 + // Only enable this by default for the main site.
319 + 'summary_emails' => get_current_blog_id() === get_main_site_id(),
320 + 'summary_emails_recipients' => '[admin_email]',
131 321
132 322 // Normally custom CSS is a string. A false value is used when nothing has been set.
133 323 // When it is false, we try to use the old custom_key value from the default style's post_content array.
134 - 'custom_css' => false,
324 + 'custom_css' => false,
325 + 'honeypot' => 1,
326 + 'wp_spam_check' => 0,
327 + 'denylist_check' => 0,
328 + 'disallowed_words' => '',
329 + 'allowed_words' => '',
330 + 'email_style' => 'classic',
135 331 );
136 332 }
137 333
138 334 /**
@@ -152,9 +348,10 @@
152 348 $this->fill_with_defaults();
153 349
154 350 if ( is_multisite() && is_admin() ) {
155 351 $mu_menu = get_site_option( 'frm_admin_menu_name' );
156 - if ( $mu_menu && ! empty( $mu_menu ) ) {
352 +
353 + if ( $mu_menu && $mu_menu ) {
157 354 $this->menu = $mu_menu;
158 355 $this->mu_menu = 1;
159 356 }
160 357 }
@@ -159,8 +356,9 @@
159 356 }
160 357 }
161 358
162 359 $frm_roles = FrmAppHelper::frm_capabilities( 'pro' );
360 +
163 361 foreach ( $frm_roles as $frm_role => $frm_role_description ) {
164 362 if ( ! isset( $this->$frm_role ) ) {
165 363 $this->$frm_role = 'administrator';
166 364 }
@@ -165,8 +363,12 @@
165 363 $this->$frm_role = 'administrator';
166 364 }
167 365 }
168 366
367 + if ( ! isset( $this->default_email ) ) {
368 + $this->default_email = get_option( 'admin_email' );
369 + }
370 +
169 371 if ( ! isset( $this->currency ) ) {
170 372 $this->currency = 'USD';
171 373 }
172 374 }
@@ -172,8 +374,9 @@
172 374 }
173 375
174 376 /**
175 377 * @param array $params
378 + *
176 379 * @return void
177 380 */
178 381 public function fill_with_defaults( $params = array() ) {
179 382 $settings = $this->default_options();
@@ -180,8 +383,9 @@
180 383 $filter_html = ! FrmAppHelper::allow_unfiltered_html();
181 384
182 385 if ( $filter_html ) {
183 386 $filter_keys = array( 'failed_msg', 'blank_msg', 'invalid_msg', 'admin_permission', 'unique_msg', 'success_msg', 'submit_value', 'login_msg', 'menu' );
387 +
184 388 if ( ! empty( $params['additional_filter_keys'] ) ) {
185 389 $filter_keys = array_merge( $filter_keys, $params['additional_filter_keys'] );
186 390 }
187 391 } else {
@@ -211,8 +415,9 @@
211 415 *
212 416 * @param mixed $value The unsanitized global setting value.
213 417 * @param string $key The key of the global setting being saved.
214 418 * @param array $filter_keys These keys that are filtered with kses.
419 + *
215 420 * @return mixed
216 421 */
217 422 private function maybe_sanitize_global_setting( $value, $key, $filter_keys ) {
218 423 if ( 'custom_css' === $key ) {
@@ -219,8 +424,9 @@
219 424 if ( false === $value ) {
220 425 // Avoid changing the false default value to an empty string.
221 426 return $value;
222 427 }
428 +
223 429 return sanitize_textarea_field( $value );
224 430 }
225 431
226 432 if ( in_array( $key, $filter_keys, true ) ) {
@@ -237,24 +443,28 @@
237 443 if ( ! isset( $this->active_captcha ) ) {
238 444 $this->active_captcha = 'recaptcha';
239 445 }
240 446
241 - $privkey = '';
242 - $re_lang = '';
447 + $privkey = '';
448 + $re_lang = '';
243 449
244 450 if ( ! isset( $this->hcaptcha_privkey ) ) {
245 451 $this->hcaptcha_privkey = '';
246 452 }
247 453
454 + if ( ! isset( $this->turnstile_privkey ) ) {
455 + $this->turnstile_privkey = '';
456 + }
457 +
248 458 if ( ! isset( $this->pubkey ) ) {
249 - // get the options from the database
459 + // Get the options from the database.
250 460 $recaptcha_opt = is_multisite() ? get_site_option( 'recaptcha' ) : get_option( 'recaptcha' );
251 - $this->pubkey = isset( $recaptcha_opt['pubkey'] ) ? $recaptcha_opt['pubkey'] : '';
252 - $privkey = isset( $recaptcha_opt['privkey'] ) ? $recaptcha_opt['privkey'] : $privkey;
253 - $re_lang = isset( $recaptcha_opt['re_lang'] ) ? $recaptcha_opt['re_lang'] : $re_lang;
461 + $this->pubkey = $recaptcha_opt['pubkey'] ?? '';
462 + $privkey = $recaptcha_opt['privkey'] ?? $privkey;
463 + $re_lang = $recaptcha_opt['re_lang'] ?? $re_lang;
254 464 }
255 465
256 - if ( ! isset( $this->re_msg ) || empty( $this->re_msg ) ) {
466 + if ( ! $this->re_msg ) {
257 467 $this->re_msg = __( 'The CAPTCHA was not entered correctly', 'formidable' );
258 468 }
259 469
260 470 if ( ! isset( $this->privkey ) ) {
@@ -294,23 +504,30 @@
294 504 * Allow strings to be filtered when a specific form may be displaying them.
295 505 *
296 506 * @since 3.06.01
297 507 *
508 + * @param array $args
509 + *
298 510 * @return void
299 511 */
300 512 public function maybe_filter_for_form( $args ) {
301 - if ( isset( $args['current_form'] ) && is_numeric( $args['current_form'] ) ) {
302 - $this->current_form = $args['current_form'];
303 - foreach ( $this->translatable_strings() as $string ) {
304 - $this->{$string} = apply_filters( 'frm_global_setting', $this->{$string}, $string, $this );
305 - $this->{$string} = apply_filters( 'frm_global_' . $string, $this->{$string}, $this );
306 - }
513 + if ( ! isset( $args['current_form'] ) || ! is_numeric( $args['current_form'] ) ) {
514 + return;
307 515 }
516 +
517 + $this->current_form = $args['current_form'];
518 +
519 + foreach ( $this->translatable_strings() as $string ) {
520 + $this->{$string} = apply_filters( 'frm_global_setting', $this->{$string}, $string, $this );
521 + $this->{$string} = apply_filters( 'frm_global_' . $string, $this->{$string}, $this );
522 + }
308 523 }
309 524
310 525 /**
311 526 * @param array $params
312 527 * @param array $errors
528 + *
529 + * @return array
313 530 */
314 531 public function validate( $params, $errors ) {
315 532 return apply_filters( 'frm_validate_settings', $errors, $params );
316 533 }
@@ -333,32 +550,55 @@
333 550 $this->update_roles( $params );
334 551
335 552 do_action( 'frm_update_settings', $params );
336 553
337 - if ( function_exists( 'get_filesystem_method' ) ) {
338 - // Save styling settings in case fallback setting changes.
339 - $frm_style = new FrmStyle();
340 - $frm_style->update( 'default' );
554 + if ( ! function_exists( 'get_filesystem_method' ) ) {
555 + return;
341 556 }
557 +
558 + // Save styling settings in case fallback setting changes.
559 + $frm_style = new FrmStyle();
560 + $frm_style->update( 'default' );
342 561 }
343 562
344 563 /**
564 + * @param array $params
565 + *
345 566 * @return void
346 567 */
347 568 private function update_settings( $params ) {
348 - $this->active_captcha = $params['frm_active_captcha'];
349 - $this->hcaptcha_pubkey = trim( $params['frm_hcaptcha_pubkey'] );
350 - $this->hcaptcha_privkey = trim( $params['frm_hcaptcha_privkey'] );
351 - $this->pubkey = trim( $params['frm_pubkey'] );
352 - $this->privkey = trim( $params['frm_privkey'] );
353 - $this->re_type = $params['frm_re_type'];
354 - $this->re_lang = $params['frm_re_lang'];
355 - $this->re_threshold = floatval( $params['frm_re_threshold'] );
356 - $this->load_style = $params['frm_load_style'];
357 - $this->custom_css = $params['frm_custom_css'];
358 - $this->currency = $params['frm_currency'];
569 + $this->active_captcha = $params['frm_active_captcha'];
570 + $this->pubkey = trim( $params['frm_pubkey'] );
571 + $this->privkey = trim( $params['frm_privkey'] );
572 + $this->re_type = $params['frm_re_type'];
573 + $this->re_lang = $params['frm_re_lang'];
574 + $this->re_threshold = floatval( $params['frm_re_threshold'] );
575 + $this->hcaptcha_pubkey = trim( $params['frm_hcaptcha_pubkey'] );
576 + $this->hcaptcha_privkey = trim( $params['frm_hcaptcha_privkey'] );
577 + $this->turnstile_pubkey = trim( $params['frm_turnstile_pubkey'] );
578 + $this->turnstile_privkey = trim( $params['frm_turnstile_privkey'] );
579 + $this->load_style = $params['frm_load_style'];
580 + $this->custom_css = $params['frm_custom_css'];
581 + $this->default_email = $params['frm_default_email'];
582 + $this->from_email = $params['frm_from_email'];
583 + $this->currency = $params['frm_currency'];
359 584
360 - $checkboxes = array( 'mu_menu', 're_multi', 'use_html', 'jquery_css', 'accordion_js', 'fade_form', 'no_ips', 'custom_header_ip', 'tracking', 'admin_bar' );
585 + $checkboxes = array(
586 + 'mu_menu',
587 + 're_multi',
588 + 'fade_form',
589 + 'no_ips',
590 + 'no_gdpr_cookies',
591 + 'enable_gdpr',
592 + 'custom_header_ip',
593 + 'tracking',
594 + 'admin_bar',
595 + 'summary_emails',
596 + 'honeypot',
597 + 'wp_spam_check',
598 + 'denylist_check',
599 + );
600 +
361 601 foreach ( $checkboxes as $set ) {
362 602 $this->$set = isset( $params[ 'frm_' . $set ] ) ? absint( $params[ 'frm_' . $set ] ) : 0;
363 603 }
364 604 }
@@ -363,8 +603,10 @@
363 603 }
364 604 }
365 605
366 606 /**
607 + * @param array $params
608 + *
367 609 * @return void
368 610 */
369 611 private function update_roles( $params ) {
370 612 global $wp_roles;
@@ -370,18 +612,19 @@
370 612 global $wp_roles;
371 613
372 614 $frm_roles = FrmAppHelper::frm_capabilities();
373 615 $roles = get_editable_roles();
616 +
374 617 foreach ( $frm_roles as $frm_role => $frm_role_description ) {
375 - $this->$frm_role = (array) ( isset( $params[ $frm_role ] ) ? $params[ $frm_role ] : 'administrator' );
618 + $this->$frm_role = (array) ( $params[ $frm_role ] ?? 'administrator' );
376 619
377 620 // Make sure administrators always have permissions
378 - if ( ! in_array( 'administrator', $this->$frm_role ) ) {
621 + if ( ! in_array( 'administrator', $this->$frm_role, true ) ) {
379 622 array_push( $this->$frm_role, 'administrator' );
380 623 }
381 624
382 625 foreach ( $roles as $role => $details ) {
383 - if ( in_array( $role, $this->$frm_role ) ) {
626 + if ( in_array( $role, $this->$frm_role, true ) ) {
384 627 $wp_roles->add_cap( $role, $frm_role );
385 628 } else {
386 629 $wp_roles->remove_cap( $role, $frm_role );
387 630 }
@@ -386,8 +629,32 @@
386 629 $wp_roles->remove_cap( $role, $frm_role );
387 630 }
388 631 }
389 632 }
633 + }
634 +
635 + /**
636 + * Updates a single setting with specified sanitization.
637 + *
638 + * @since 6.9
639 + *
640 + * @param string $key The setting key to update.
641 + * @param mixed $value The new value for the setting.
642 + * @param string $sanitize The name of the sanitization function to apply to the new value.
643 + *
644 + * @return bool True on success, false on failure.
645 + */
646 + public function update_setting( $key, $value, $sanitize ) {
647 + if ( ! property_exists( $this, $key ) || ! is_callable( $sanitize ) ) {
648 + // Setting does not exist or sanitization function name is not callable.
649 + return false;
650 + }
651 +
652 + // Update the property value.
653 + FrmAppHelper::sanitize_value( $sanitize, $value );
654 + $this->{$key} = $value;
655 +
656 + return true;
390 657 }
391 658
392 659 /**
393 660 * @return void