PluginProbe ʕ •ᴥ•ʔ
JetFormBuilder — Dynamic Blocks Form Builder / 3.6.5.2
JetFormBuilder — Dynamic Blocks Form Builder v3.6.5.2
3.6.5.2 3.6.5.1 3.6.5 3.6.4.2 3.6.4.1 3.6.4 3.6.3.1 3.6.3 3.6.2.2 3.6.2.1 3.6.2 3.6.1.1 3.6.1 3.6.0.1 trunk 1.0.0 1.0.1 1.0.2 1.0.3 1.1.0 1.1.1 1.1.2 1.1.3 1.1.4 1.1.5 1.1.6 1.1.7 1.2.0 1.2.1 1.2.2 1.2.3 1.2.4 1.2.5 1.2.6 1.2.7 1.3.0 1.3.1 1.3.2 1.3.3 1.4.0 1.4.1 1.4.2 1.4.3 1.5.0 1.5.1 1.5.2 1.5.3 1.5.4 1.5.5 2.0.0 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 2.1.0 2.1.1 2.1.10 2.1.11 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 3.0.0 3.0.0.1 3.0.0.2 3.0.0.3 3.0.1 3.0.1.1 3.0.2 3.0.3 3.0.4 3.0.5 3.0.6 3.0.7 3.0.8 3.0.9 3.1.0 3.1.0.1 3.1.1 3.1.2 3.1.3 3.1.4 3.1.5 3.1.6 3.1.7 3.1.8 3.1.9 3.2.0 3.2.1 3.2.2 3.2.3 3.3.0 3.3.1 3.3.2 3.3.3 3.3.3.1 3.3.4 3.3.4.1 3.3.4.2 3.4.0 3.4.1 3.4.2 3.4.3 3.4.4 3.4.5 3.4.5.1 3.4.5.2 3.4.6 3.4.7 3.4.7.1 3.5.0 3.5.1 3.5.1.1 3.5.1.2 3.5.2 3.5.2.1 3.5.3 3.5.4 3.5.5 3.5.6 3.5.6.1 3.5.6.2 3.5.6.3 3.6.0
jetformbuilder / includes / presets / sources / preset-source-query-var.php
jetformbuilder / includes / presets / sources Last commit date
base-source.php 5 days ago preset-source-post.php 2 months ago preset-source-query-var.php 5 days ago preset-source-term.php 1 year ago preset-source-user.php 2 years ago
preset-source-query-var.php
66 lines
1 <?php
2
3
4 namespace Jet_Form_Builder\Presets\Sources;
5
6 // If this file is called directly, abort.
7 use Jet_Form_Builder\Exceptions\Preset_Exception;
8
9 if ( ! defined( 'WPINC' ) ) {
10 die;
11 }
12
13 class Preset_Source_Query_Var extends Base_Source {
14
15 public function get_id() {
16 return 'query_var';
17 }
18
19 public function query_source() {
20 // phpcs:ignore WordPress.Security.NonceVerification.Recommended
21 return $_GET;
22 }
23
24 public function get_prop() {
25 if ( ! empty( $this->field_data['other']['query_var'] ) ) {
26 return $this->field_data['other']['query_var'];
27 }
28
29 return ! empty( $this->field_data['key'] ) ? $this->field_data['key'] : '';
30 }
31
32 public function get_result_on_prop() {
33 if ( isset( $this->src()[ $this->prop ] ) ) {
34 return $this->src()[ $this->prop ];
35 }
36
37 throw new Preset_Exception(
38 '$_GET does not have ' . esc_attr( $this->prop ) . ' field'
39 );
40 }
41
42 /**
43 * This source only ever reads $_GET of the current request - data the
44 * requester already controls and can see - so there is nothing to
45 * protect and no ownership to verify. The #20359 report lists this
46 * source as a third bypass route, but reading back the caller's own
47 * query string discloses nothing they don't already have.
48 *
49 * Returned explicitly rather than deferring to Base_Source, whose
50 * default is `! empty( $this->src() )`: that would make an empty $_GET
51 * fail the *permission* check and throw, when the correct outcome is
52 * simply "no such query var" - which get_result_on_prop() already
53 * reports on its own.
54 *
55 * The array check is not about permission: get_result_on_prop() indexes
56 * src() directly, so a non-array source (only reachable if a subclass
57 * overrides query_source()) must fail here as a catchable
58 * Preset_Exception rather than a fatal further down.
59 *
60 * @return bool
61 */
62 protected function can_get_preset() {
63 return is_array( $this->src() );
64 }
65 }
66