← All changes
|
includes/widgets/Form_Builder/helpers/Upload_Email_File.php
+5
-30
51.1.77
→
51.1.87
View file →
| @@ -256,8 +256,12 @@ | ||
| 256 | 256 | |
| 257 | 257 | /** |
| 258 | 258 | * AJAX handler for generating a fresh form nonce. |
| 259 | 259 | * |
| 260 | + * This nonce is a CSRF token for Form Builder AJAX. It is not authorization | |
| 261 | + * to read or change a submission: payment reuse requires the per-submission | |
| 262 | + * access secret issued when that submission was created. | |
| 263 | + * | |
| 260 | 264 | * Requires a published page that actually contains the Form Builder widget. |
| 261 | 265 | * A bare form_public flag is not accepted. |
| 262 | 266 | * |
| 263 | 267 | * @return void |
| @@ -265,9 +269,9 @@ | ||
| 265 | 269 | public function get_fresh_nonce() |
| 266 | 270 | { |
| 267 | 271 | $page_id = absint($_POST['page_id'] ?? 0); |
| 268 | 272 | |
| 269 | - if (!$this->page_has_form_builder($page_id)) { | |
| 273 | + if (!Form_Builder_Security::page_has_form_builder($page_id)) { | |
| 270 | 274 | wp_send_json_error([ |
| 271 | 275 | 'message' => esc_html__('Insufficient permissions.', 'king-addons'), |
| 272 | 276 | ]); |
| 273 | 277 | } |
| @@ -277,36 +281,7 @@ | ||
| 277 | 281 | 'timestamp' => time(), |
| 278 | 282 | ]); |
| 279 | 283 | } |
| 280 | 284 | |
| 281 | - /** | |
| 282 | - * Checks whether a published page contains the Form Builder widget. | |
| 283 | - * | |
| 284 | - * @param int $page_id Page or post ID. | |
| 285 | - * @return bool True when the page is published and includes Form Builder. | |
| 286 | - */ | |
| 287 | - public function page_has_form_builder($page_id) | |
| 288 | - { | |
| 289 | - $page_id = absint($page_id); | |
| 290 | - if ($page_id <= 0) { | |
| 291 | - return false; | |
| 292 | - } | |
| 293 | - | |
| 294 | - $post = get_post($page_id); | |
| 295 | - if (!$post || 'publish' !== $post->post_status) { | |
| 296 | - return false; | |
| 297 | - } | |
| 298 | - | |
| 299 | - $elementor_data = get_post_meta($page_id, '_elementor_data', true); | |
| 300 | - if (empty($elementor_data)) { | |
| 301 | - return false; | |
| 302 | - } | |
| 303 | - | |
| 304 | - if (!is_string($elementor_data)) { | |
| 305 | - $elementor_data = wp_json_encode($elementor_data); | |
| 306 | - } | |
| 307 | - | |
| 308 | - return false !== strpos($elementor_data, 'king-addons-form-builder'); | |
| 309 | - } | |
| 310 | 285 | } |
| 311 | 286 | |
| 312 | 287 | new Upload_Email_File(); |