PluginProbe
Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls / 6.5.1
Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls v6.5.1
6.5.1 6.5.0 6.4.9 6.4.8 6.4.7 6.4.6 6.4.5 6.4.4 6.4.3 6.4.2 6.4.1 6.4.0 6.3.9 6.3.8 6.3.7 6.3.6 6.3.5 6.3.4 6.3.3 5.6.0 5.6.1 5.6.2 5.6.3 5.6.4 5.6.5 All 154 releases
← All changes | public/class-poll-maker-ays-public.php +672 -134 5.6.3 → 6.5.1 View file →
@@ -79,8 +79,9 @@
79 79 $this->settings = new Poll_Maker_Settings_Actions($this->plugin_name);
80 80 add_shortcode('ays_poll_all', array($this, 'ays_poll_all_generate_shortcode'));
81 81 add_shortcode('ayspoll_results', array($this, 'ays_poll_results_generate_shortcode'));
82 82 add_shortcode('ays_display_polls', array($this, 'ays_generate_display_polls_method'));
83 + add_shortcode('ays_poll_cat', array($this, 'ays_poll_generate_categories_method'));
83 84 }
84 85
85 86 /**
86 87 * Get instance of this class. Singleton pattern.
@@ -113,9 +114,9 @@
113 114 * between the defined hooks and the functions defined in this
114 115 * class.
115 116 */
116 117
117 - wp_enqueue_style( 'ays_poll_font_awesome', POLL_MAKER_AYS_ADMIN_URL . '/css/poll-maker-ays-admin-fonts.css', array(), $this->version, 'all');
118 + wp_enqueue_style( 'ays_poll_font_awesome', esc_url(POLL_MAKER_AYS_ADMIN_URL) . '/css/poll-maker-ays-admin-fonts.css', array(), $this->version, 'all');
118 119
119 120 }
120 121
121 122 public function enqueue_styles_early(){
@@ -140,9 +141,9 @@
140 141 }
141 142
142 143 $ays_is_elementor = $this->ays_is_elementor();
143 144 if ( $ays_is_elementor ) {
144 - wp_enqueue_style( 'ays_poll_font_awesome', POLL_MAKER_AYS_ADMIN_URL . '/css/poll-maker-ays-admin-fonts.css', array(), $this->version, 'all');
145 + wp_enqueue_style( 'ays_poll_font_awesome', esc_url(POLL_MAKER_AYS_ADMIN_URL) . '/css/poll-maker-ays-admin-fonts.css', array(), $this->version, 'all');
145 146 }
146 147 }
147 148
148 149 public function ays_is_elementor(){
@@ -186,20 +187,21 @@
186 187 wp_enqueue_script($this->plugin_name.'-category', plugin_dir_url(__FILE__) . 'js/poll-maker-public-category.js', array('jquery'), $this->version, false);
187 188 wp_enqueue_script( $this->plugin_name . '-autosize', plugin_dir_url(__FILE__) . 'js/poll-maker-autosize.js', array( 'jquery' ), $this->version, false );
188 189 wp_localize_script($this->plugin_name . '-ajax-public', 'poll_maker_ajax_public',
189 190 array(
190 - 'ajax_url' => admin_url('admin-ajax.php'),
191 - 'alreadyVoted' => __( "You have already voted" , "poll-maker" ),
192 - 'day' => __( 'day', "poll-maker" ),
193 - 'days' => __( 'days', "poll-maker" ),
194 - 'hour' => __( 'hour', "poll-maker" ),
195 - 'hours' => __( 'hours', "poll-maker" ),
196 - 'minute' => __( 'minute', "poll-maker" ),
197 - 'minutes' => __( 'minutes', "poll-maker" ),
198 - 'second' => __( 'second', "poll-maker" ),
199 - 'seconds' => __( 'seconds', "poll-maker" ),
200 - 'thank_message' => __( 'Your answer has been successfully sent to the admin. Please wait for the approval.', "poll-maker" ),
201 - 'restart' => __( 'Restart', "poll-maker" ),
191 + 'ajax_url' => admin_url('admin-ajax.php'),
192 + 'nonce' => wp_create_nonce('ays_poll_nonce'),
193 + 'alreadyVoted' =>esc_html__( "You have already voted" , "poll-maker" ),
194 + 'day' =>esc_html__( 'day', "poll-maker" ),
195 + 'days' =>esc_html__( 'days', "poll-maker" ),
196 + 'hour' =>esc_html__( 'hour', "poll-maker" ),
197 + 'hours' =>esc_html__( 'hours', "poll-maker" ),
198 + 'minute' =>esc_html__( 'minute', "poll-maker" ),
199 + 'minutes' =>esc_html__( 'minutes', "poll-maker" ),
200 + 'second' =>esc_html__( 'second', "poll-maker" ),
201 + 'seconds' =>esc_html__( 'seconds', "poll-maker" ),
202 + 'thank_message' =>esc_html__( 'Your answer has been successfully sent to the admin. Please wait for the approval.', "poll-maker" ),
203 + 'restart' =>esc_html__( 'Restart', "poll-maker" ),
202 204 )
203 205 );
204 206 }
205 207
@@ -204,13 +206,131 @@
204 206 }
205 207
206 208 public function show_chart_js() {
207 209 wp_enqueue_script( $this->plugin_name . '-charts-google', plugin_dir_url(__FILE__) . 'js/google-chart.js', array('jquery'), $this->version, true);
210 + }
211 +
212 + // Categories shortcode
213 + public function ays_poll_generate_categories_method($attr) {
214 + ob_start();
215 + global $wpdb;
216 + $id = (isset($attr['id'])) ? absint(intval($attr['id'])) : null;
217 +
218 + if (is_null($id)) {
219 + echo "<p class='wrong_shortcode_text' style='color:red;'>" . __('Wrong shortcode initialized', 'poll-maker') . "</p>";
220 + return false;
221 + }
222 +
223 + $display = ( isset($attr['display']) && $attr['display'] != '' ) ? $attr['display'] : 'all';
224 + $layout = ( isset($attr['layout']) && $attr['layout'] != '' ) ? $attr['layout'] : 'list';
225 + $count = ( isset($attr['count']) && $attr['count'] != '' ) ? absint(intval($attr['count'])) : 5;
226 + $cat_polls_sorting = (isset($attr['sorting']) && $attr['sorting'] != '' ) ? $attr['sorting'] : 'date_asc';
227 +
228 + $style = '';
229 + $conteiner_style = '';
230 + if ($layout == 'grid') {
231 + $conteiner_style = 'display: flex; flex-wrap: wrap;';
232 + $style = 'margin: 5px;';
233 + }
234 +
235 + $category = $this->ays_get_poll_category($id);
236 +
237 + $sql = "SELECT * FROM {$wpdb->prefix}ayspoll_polls WHERE `categories` LIKE '%".$id."%'";
238 +
239 + $content = "";
240 + $random_poll_id = array();
241 + if ($display === 'random') {
242 + $sql .= " ORDER BY RAND() LIMIT ".$count;
243 + }
244 +
245 + $result = '';
246 + if($cat_polls_sorting == 'popular_asc' && $display == 'all'){
247 + $popular_asc_sql = "SELECT p.*
248 + FROM {$wpdb->prefix}ayspoll_reports AS r
249 + RIGHT JOIN {$wpdb->prefix}ayspoll_polls AS p
250 + ON r.poll_id = p.id
251 + WHERE p.categories LIKE '%{$id}%'
252 + GROUP BY p.id
253 + ORDER BY COUNT(answer_id) ASC LIMIT ".$count;
254 + $result = $wpdb->get_results($popular_asc_sql, 'ARRAY_A');
255 + }elseif($cat_polls_sorting == 'popular_desc' && $display == 'all'){
256 + $popular_desc_sql = "SELECT p.id
257 + FROM {$wpdb->prefix}ayspoll_reports AS r
258 + RIGHT JOIN {$wpdb->prefix}ayspoll_polls AS p
259 + ON r.poll_id = p.id
260 + WHERE p.categories LIKE '%{$id}%'
261 + GROUP BY p.id
262 + ORDER BY COUNT(answer_id) DESC LIMIT ".$count;
263 + $result = $wpdb->get_results($popular_desc_sql, 'ARRAY_A');
264 + }else if($cat_polls_sorting == 'date_asc' && $display == 'all'){
265 + $sql = "SELECT * FROM {$wpdb->prefix}ayspoll_polls
266 + WHERE `categories`
267 + LIKE '%".$id."%'
268 + ORDER BY id ASC LIMIT ".$count;
269 + $result = $wpdb->get_results($sql, 'ARRAY_A');
270 + }else if($cat_polls_sorting == 'date_desc' && $display == 'all'){
271 + $sql = "SELECT * FROM {$wpdb->prefix}ayspoll_polls
272 + WHERE `categories`
273 + LIKE '%".$id."%'
274 + ORDER BY id DESC LIMIT ".$count;
275 + $result = $wpdb->get_results($sql, 'ARRAY_A');
276 + }else{
277 + $sql = "SELECT * FROM {$wpdb->prefix}ayspoll_polls
278 + WHERE `categories`
279 + LIKE '%".$id."%'
280 + ORDER BY RAND() LIMIT ".$count;
281 + $result = $wpdb->get_results($sql, 'ARRAY_A');
282 + }
283 +
284 +
285 + $check_poll = false;
286 + $all_poll_count = count($result);
287 + foreach ($result as $val) {
288 + $val = absint(intval($val['id']));
289 + $options = (isset($val['styles']) && $val['styles'] != null) ? json_decode($val['styles'], true) : array();
290 + $check_poll = $this->check_shedule_expired_poll( $val );
291 +
292 + if (!$check_poll) {
293 + continue;
294 + }
295 +
296 + $random_poll_id[] = $val;
297 + }
298 +
299 + $cat_settings_table = esc_sql($wpdb->prefix."ayspoll_settings");
300 + $cat_key_meta = esc_sql('options');
301 + $cat_sql = "SELECT meta_value FROM ".$cat_settings_table." WHERE meta_key = %s";
302 + $ct_sql = $wpdb->get_var(
303 + $wpdb->prepare( $cat_sql, $cat_key_meta)
304 + );
305 +
306 + $cat_options_res = ($ct_sql === false) ? json_encode(array()) : $ct_sql;
307 + $cat_option_res = json_decode($cat_options_res, true);
308 +
309 + if (isset($cat_option_res['show_cat_title']) && $cat_option_res['show_cat_title'] == 'on') {
310 + $content .= "<h2 class='ays-poll-category-title' style='text-align:center;'>
311 + <span style='font-size:3rem;'>". __( "Category", 'poll-maker') .":</span>
312 + <em>". stripslashes($category['title']) ."</em>
313 + </h2>";
314 +
315 + if(isset($category['description']) && $category['description'] != ''){
316 + $content .= "<div class='ays-poll-category-description'>". do_shortcode(stripslashes(wpautop($category['description']))) ."</div>";
317 + }
318 + }
319 +
320 + $content .= "<div class='ays-poll-category-containers' style='".$conteiner_style."'>";
321 + foreach ($random_poll_id as $poll_id) {
322 + $content .= '<div class="ays-poll-main" id="ays-poll-container-'.$poll_id.'" style="'.$style.'">';
323 + $content .= '<div class="ays-poll-category-item">';
324 + $shortcode = '[ays_poll id="'.$poll_id.'"]';
325 + $content .= do_shortcode($shortcode);
326 + $content .= '</div>';
327 + $content .= '</div>';
328 + }
329 + $content .= '</div>';
330 + echo $content;
331 + return str_replace(array("\r\n", "\n", "\r"), '', ob_get_clean());
208 332 }
209 - // public function show_column_chart_js() {
210 - // // wp_enqueue_script( $this->plugin_name . '-column-chart', 'https://www.gstatic.com/charts/loader.js', array('jquery'), $this->version, true);
211 - // wp_enqueue_script( $this->plugin_name . '-column-chart', plugin_dir_url(__FILE__) . 'js/poll-maker-chart-loader.js', array('jquery'), $this->version, true);
212 - // }
213 333
214 334 public function ays_poll_results_generate_shortcode($attr) {
215 335 ob_start();
216 336
@@ -246,9 +366,8 @@
246 366
247 367 $chart_style = false;
248 368 if (isset( $result_option_res['show_result_view']) && ( $result_option_res['show_result_view'] == 'pie_chart' || $result_option_res['show_result_view'] == 'column_chart' )) {
249 369 $this->show_chart_js();
250 - // $this->show_column_chart_js();
251 370 $chart_style = true;
252 371 }
253 372
254 373 if ($polls == null) {
@@ -390,8 +509,33 @@
390 509 }
391 510 else{
392 511 foreach ($poll_answers as $ans_key => $ans_val) {
393 512 $percent = round($one_percent*intval($ans_val['votes']));
513 + $real_votes = 0;
514 + $all_votes_bar = 0;
515 + if($polls['type'] == 'choosing'){
516 + $real_votes = isset($ans_val['votes']) ? intval($ans_val['votes']) : 0;
517 + $fake_votes = isset($ans_val['fake_votes']) ? intval($ans_val['fake_votes']) : 0;
518 + if($poll_fake_votes){
519 + if($fake_votes + $real_votes < 0){
520 + $all_votes_bar += $real_votes;
521 + }
522 + else{
523 + $all_votes_bar += ($real_votes + $fake_votes);
524 + }
525 + }
526 + else{
527 + $all_votes_bar += $real_votes;
528 + }
529 +
530 + if($sum_of_votes > 0){
531 + $percent = round((100*$all_votes_bar)/$sum_of_votes);
532 + }
533 + }
534 + else{
535 + $all_votes_bar = $ans_val['votes'];
536 + }
537 +
394 538 if ($percent == 0) {
395 539 $perc_cont = '';
396 540 }else{
397 541 $perc_cont = $percent.' %';
@@ -397,13 +541,41 @@
397 541 $perc_cont = $percent.' %';
398 542 }
399 543 switch ($polls['type']) {
400 544 case 'choosing':
401 - $content .= '<div class="answer-title flex-apm">
402 - <span class="answer-text">'.stripslashes($ans_val['answer']).'</span>
403 - <span class="answer-votes">'.$ans_val['votes'].'</span>
545 + $answer_image = isset($ans_val['answer_img']) && $ans_val['answer_img'] != '' ? sanitize_url($ans_val['answer_img']) : '';
546 + $answer_image_box = "<div class='ays-poll-answers-image-box-empty-image'></div>";
547 + $answer_image_is_empty_class = "ays-poll-answers-box-no-image";
548 + if($answer_image != ""){
549 + $answer_image_is_empty_class = "ays-poll-answers-box";
550 + $answer_image_box = "<div class='ays-poll-answers-image-box'><img src=" . $answer_image . " class='ays-poll-answers-current-image'></div>";
551 + }
552 + $content .= '
553 +
554 + <div class=' . $answer_image_is_empty_class. '>
555 + '. $answer_image_box . '
556 + <div class="ays-poll-answer-text-and-percent-box">
557 + <div class="answer-title flex-apm">
558 + <span class="answer-text">'.stripslashes($ans_val['answer']).'</span>
559 + <span class="answer-votes">'.$all_votes_bar.' ('.$percent.'%)</span>
560 + </div>
561 + <div class="progress-bar-container">
562 + <div class="answer-percent-res"
563 + style="width: '.$percent.'%;
564 + background-color: '.$polls_options['main_color'].';
565 + height: 20px;
566 + border-radius: 4px;
567 + transition: width 0.3s ease;
568 + display: flex;
569 + align-items: center;
570 + padding-left: 8px;
571 + padding-right: 13px;
572 + color: '.$polls_options['bg_color'].';">
573 + '.($percent == 0 ? '' : $percent.'%').'
404 574 </div>
405 - <div class="answer-percent" style="width: '.$percent.'%; background-color: '.$polls_options['main_color'].'; color: '.$polls_options['bg_color'].';">'.$perc_cont.'</div>';
575 + </div>
576 + </div>
577 + </div>';
406 578 break;
407 579
408 580 case 'rating':
409 581 switch ($polls['view_type']) {
@@ -478,9 +650,9 @@
478 650 $hand_type = '<i class="ays_poll_far ays_poll_fa-thumbs-down far"></i>';
479 651 }
480 652 $content .= '<div class="answer-title flex-apm">
481 653 <span class="answer-text">'.$hand_type.'</span>
482 - <span class="answer-votes">'.$ans_val['votes'].'</span>
654 + <span class="answer-votes">'.$all_votes_bar.' ('.$percent.'%)</span>
483 655 </div>
484 656 <div class="answer-percent" style="width: '.$percent.'%; background-color: '.$polls_options['main_color'].'; color: '.$polls_options['bg_color'].';">'.$perc_cont.'</div>';
485 657 break;
486 658 case 'emoji':
@@ -491,9 +663,9 @@
491 663 $emojy_type = '<i class="ays_poll_far ays_poll_fa-frown far"></i>';
492 664 }
493 665 $content .= '<div class="answer-title flex-apm">
494 666 <span class="answer-text">'.$emojy_type.'</span>
495 - <span class="answer-votes">'.$ans_val['votes'].'</span>
667 + <span class="answer-votes">'.$all_votes_bar.' ('.$percent.'%)</span>
496 668 </div>
497 669 <div class="answer-percent" style="width: '.$percent.'%; background-color: '.$polls_options['main_color'].'; color: '.$polls_options['bg_color'].';">'.$perc_cont.'</div>';
498 670
499 671 break;
@@ -599,13 +771,16 @@
599 771 if (isset($options['published']) && intval($options['published']) === 0) {
600 772 return "";
601 773 }
602 774
603 - $info_form = !empty($options['info_form']) && !empty($options['fields']);
604 - $info_form_title = !empty($options['info_form_title']) ? wp_kses_post(stripslashes($options['info_form_title'])) : "<div>" . __("Please fill out the form:", "poll-maker") . "</div>";
605 - $fields = !empty($options['fields']) ? explode(",", $options['fields']) : array();
606 - $required_fields = !empty($options['required_fields']) ? explode(",", $options['required_fields']) : array();
775 + $form_fields_option = isset($options['fields']) ? $options['fields'] : array();
776 + $form_required_fields_option = isset($options['required_fields']) ? $options['required_fields'] : array();
607 777
778 + $info_form = !empty($options['info_form']) && !empty($form_fields_option);
779 + $info_form_title = !empty($options['info_form_title']) ? wp_kses_post(stripslashes($options['info_form_title'])) : "<div>" .esc_html__("Please fill out the form:", "poll-maker") . "</div>";
780 + $fields = !empty($form_fields_option) && !is_array($form_fields_option) ? explode(",", $form_fields_option) : (is_array($form_fields_option) ? $form_fields_option : array());
781 + $required_fields = !empty($form_required_fields_option) && !is_array($form_required_fields_option) ? explode(",", $form_required_fields_option) : (is_array($form_required_fields_option) ? $form_required_fields_option : array());
782 +
608 783 $is_expired = false;
609 784 $is_start_soon = false;
610 785 $startDate = '';
611 786 $endDate = '';
@@ -692,9 +867,9 @@
692 867 $hide_results = "1";
693 868 if (!empty($options['hide_results_text'])) {
694 869 $hide_results_text = wpautop($options['hide_results_text']);
695 870 } else {
696 - $hide_results_text = __("Thanks for your answer", "poll-maker");
871 + $hide_results_text =esc_html__("Thanks for your answer", "poll-maker");
697 872 }
698 873 } else {
699 874 $hide_results = "0";
700 875 $hide_results_text = "";
@@ -709,9 +884,9 @@
709 884 $redirect_delay = isset($options['poll_every_answer_redirect_delay']) && $options['poll_every_answer_redirect_delay'] != "" ? esc_attr($options['poll_every_answer_redirect_delay']) : 0;
710 885 }
711 886 $redirect_url_href = '';
712 887 $redirect_url_checked = 1;
713 - $redirect_after_vote = "<p class='redirectionAfterVote'>" . __("You will be redirected", "poll-maker") . " " . ($redirect_delay <= 0 ? "" : __("after", "poll-maker") . " <span>" . $redirect_delay . "</span>" . " " . __("seconds", "poll-maker")) . "</p>";
888 + $redirect_after_vote = "<p class='redirectionAfterVote'>" .esc_html__("You will be redirected", "poll-maker") . " " . ($redirect_delay <= 0 ? "" :esc_html__("after", "poll-maker") . " <span>" . $redirect_delay . "</span>" . " " .esc_html__("seconds", "poll-maker")) . "</p>";
714 889 }elseif (isset($options['redirect_users']) && $options['redirect_users'] != 0 && !empty($options['redirect_after_vote_url'])) {
715 890 $redirect_after_vote_url = stripslashes($options['redirect_after_vote_url']);
716 891 $redirect_url_href = '';
717 892 $redirect_users = $options['redirect_users'];
@@ -716,9 +891,9 @@
716 891 $redirect_url_href = '';
717 892 $redirect_users = $options['redirect_users'];
718 893 $redirect_delay = $options['redirect_after_vote_delay'];
719 894 $redirect_url_checked = 0;
720 - $redirect_after_vote = "<p class='redirectionAfterVote'>" . __("You will be redirected", "poll-maker") . " " . ($redirect_delay <= 0 ? "" : __("after", "poll-maker") . " <span>" . $redirect_delay . "</span>" . " " . __("seconds", "poll-maker")) . "</p>";
895 + $redirect_after_vote = "<p class='redirectionAfterVote'>" .esc_html__("You will be redirected", "poll-maker") . " " . ($redirect_delay <= 0 ? "" :esc_html__("after", "poll-maker") . " <span>" . $redirect_delay . "</span>" . " " .esc_html__("seconds", "poll-maker")) . "</p>";
721 896 } else {
722 897 $redirect_after_vote_url = '';
723 898 $redirect_url_href = '';
724 899 $redirect_users = 0;
@@ -739,14 +914,9 @@
739 914 );
740 915
741 916 $bg_color = $options['bg_color'];
742 917 $bg_image = isset($options['bg_image']) && $options['bg_image'] != '' ? esc_url($options['bg_image']): '';
743 - // if ($bg_image != '') {
744 - // if ( !(filter_var($bg_image, FILTER_VALIDATE_URL) && wp_http_validate_url($bg_image)) ) {
745 - // // invalid URL, handle accordingly
746 - // $bg_image = '';
747 - // }
748 - // }
918 +
749 919 if( $bg_image != "" ){
750 920 $check_if_current_image_exists = Poll_Maker_Ays_Admin::ays_poll_check_if_current_image_exists($bg_image);
751 921
752 922 if( !$check_if_current_image_exists ){
@@ -806,9 +976,9 @@
806 976
807 977 $ays_see_result_button = (isset($options['see_res_btn_text']) && $options['see_res_btn_text'] != '') ? stripslashes( esc_attr( $options['see_res_btn_text'] )) : 'See Results';
808 978
809 979 if ($ays_see_result_button === 'See Results') {
810 - $ays_see_result_button_text = __("See Results", "poll-maker");
980 + $ays_see_result_button_text = esc_html__("See Results", "poll-maker");
811 981 }else{
812 982 $ays_see_result_button_text = $ays_see_result_button;
813 983 }
814 984
@@ -1003,9 +1173,9 @@
1003 1173 }
1004 1174
1005 1175 if ($poll_vote_reason) {
1006 1176 $vote_reason = "<div class='ays-poll-vote-reason'>
1007 - <div class='ays-poll-for-reason'>". __("Please add vote reason", "poll-maker")."</div>
1177 + <div class='ays-poll-for-reason'>".esc_html__("Please add vote reason", "poll-maker")."</div>
1008 1178 <div><textarea name='ays-poll-reason-text' id='ays-poll-reason-text'></textarea></div>
1009 1179 </div>";
1010 1180 } else {
1011 1181 $vote_reason = "";
@@ -1068,9 +1238,11 @@
1068 1238 // Buttons border radius
1069 1239 $buttons_border_radius = isset($options['poll_buttons_border_radius']) && $options['poll_buttons_border_radius'] != '' ? esc_attr($options['poll_buttons_border_radius']) . 'px' : '3px';
1070 1240 // Buttons width
1071 1241 $buttons_width = isset($options['poll_buttons_width']) && $options['poll_buttons_width'] != '' ? esc_attr($options['poll_buttons_width']) . 'px' : 'auto';
1072 -
1242 + // Buttons mobile width
1243 + $buttons_mobile_width = isset($options['poll_buttons_mobile_width']) && $options['poll_buttons_mobile_width'] != '' ? esc_attr($options['poll_buttons_mobile_width']) . 'px' : 'auto';
1244 +
1073 1245 // Poll View Type
1074 1246 $answer_view_type_old = isset($options['poll_answer_view_type']) && $options['poll_answer_view_type'] != '' ? esc_attr($options['poll_answer_view_type']) : 'list';
1075 1247 $answer_view_type = isset($poll['view_type']) && $poll['view_type'] != '' ? esc_attr($poll['view_type']) : $answer_view_type_old;
1076 1248
@@ -1110,8 +1282,14 @@
1110 1282
1111 1283 // Poll title font size mobile
1112 1284 $poll_title_font_size_mobile = (isset($options['poll_title_font_size_mobile']) && $options['poll_title_font_size_mobile'] != "") ? absint(intval(esc_attr($options['poll_title_font_size_mobile']))) : "20";
1113 1285
1286 + // Poll title font weight
1287 + $poll_title_font_weight = (isset($options['poll_title_font_weight']) && $options['poll_title_font_weight'] != "") ? esc_attr($options['poll_title_font_weight']) : "normal";
1288 +
1289 + // Poll title font weight mobile
1290 + $poll_title_font_weight_mobile = (isset($options['poll_title_font_weight_mobile']) && $options['poll_title_font_weight_mobile'] != "") ? esc_attr($options['poll_title_font_weight_mobile']) : $poll_title_font_weight;
1291 +
1114 1292 // Poll title alignment
1115 1293 $poll_title_alignment = ( isset($options['poll_title_alignment']) && $options['poll_title_alignment'] != "" ) ? esc_attr($options['poll_title_alignment']) : "center";
1116 1294
1117 1295 // Poll title alignment mobile
@@ -1116,8 +1294,11 @@
1116 1294
1117 1295 // Poll title alignment mobile
1118 1296 $poll_title_alignment_mobile = ( isset($options['poll_title_alignment_mobile']) && $options['poll_title_alignment_mobile'] != "" ) ? esc_attr($options['poll_title_alignment_mobile']) : $poll_title_alignment;
1119 1297
1298 + // Poll title text transform
1299 + $poll_title_text_transform = ( isset($options['poll_title_text_transform']) && $options['poll_title_text_transform'] != "" ) ? esc_attr($options['poll_title_text_transform']) : "none";
1300 +
1120 1301 // ===== Poll text type options start =====
1121 1302 $poll_view_type_text = isset($poll['view_type']) && $poll['view_type'] != "" ? $poll['view_type'] : "short_text";
1122 1303
1123 1304 $poll_text_type_length_enable = (isset($options['poll_text_type_length_enable']) && $options['poll_text_type_length_enable'] == "on") ? true : false;
@@ -1132,9 +1313,9 @@
1132 1313
1133 1314 if($poll_text_type_limit_message && ($poll_text_type_limit_length != "" && intval($poll_text_type_limit_length) != 0)){
1134 1315 $poll_box_for_limit_message = '<div class="ays_quiz_question_text_conteiner">
1135 1316 <div class="ays_quiz_question_text_message">
1136 - <span class="ays_poll_question_text_message_span">'. $poll_text_type_limit_length . '</span> ' . $poll_text_type_limit_type . ' '. __( ' left' , "poll-maker" ) . '
1317 + <span class="ays_poll_question_text_message_span">'. $poll_text_type_limit_length . '</span> ' . $poll_text_type_limit_type . ' '. esc_html__( ' left' , "poll-maker" ) . '
1137 1318 </div>
1138 1319 </div>';
1139 1320 }
1140 1321 $poll_text_type_ready_width = "";
@@ -1176,9 +1357,9 @@
1176 1357 $poll_enable_password_visibility = (isset($options['poll_enable_password_visibility']) && $options['poll_enable_password_visibility'] == 'on') ? true : false;
1177 1358
1178 1359
1179 1360 $password_input_val = isset($_POST['ays_poll_password_val_'. $id ]) && $_POST['ays_poll_password_val_'. $id ] != "" ? stripslashes(esc_attr($_POST['ays_poll_password_val_'. $id ])) : '';
1180 - $poll_password_message = (isset($options['poll_password_message']) && $options['poll_password_message'] != '') ? stripslashes( wpautop( $options['poll_password_message'] ) ) : "<p>" . __( "Please enter password", "poll-maker" ) . "</p>";
1361 + $poll_password_message = (isset($options['poll_password_message']) && $options['poll_password_message'] != '') ? stripslashes( wpautop( $options['poll_password_message'] ) ) : "<p>" .esc_html__( "Please enter password", "poll-maker" ) . "</p>";
1181 1362
1182 1363 $poll_check_only_logged = (isset($options['enable_logged_users']) && $options['enable_logged_users'] == 1 && !is_user_logged_in()) ? true : false;
1183 1364 $poll_password_message_input = "<input type='password' class='ays-poll-password-input' id='ays_poll_password_val_". $id ."' name='ays_poll_password_val_". $id ."' required autocomplete='off'>";
1184 1365
@@ -1183,10 +1364,10 @@
1183 1364 $poll_password_message_input = "<input type='password' class='ays-poll-password-input' id='ays_poll_password_val_". $id ."' name='ays_poll_password_val_". $id ."' required autocomplete='off'>";
1184 1365
1185 1366 if ( $poll_enable_password_visibility ) {
1186 1367 $password_message_with_toggle_class = "ays-poll-password-input-box-visibility";
1187 - $password_message_with_toggle .= "<img src='". POLL_MAKER_AYS_PUBLIC_URL ."/images/poll-maker-eye-visibility-off.svg' class='ays-poll-password-toggle ays-poll-password-toggle-visibility-off'>";
1188 - $password_message_with_toggle .= "<img src='". POLL_MAKER_AYS_PUBLIC_URL ."/images/poll-maker-eye-visibility.svg' class='ays-poll-password-toggle ays-poll-password-toggle-visibility ays_poll_display_none'>";
1368 + $password_message_with_toggle .= "<img src='". esc_url(POLL_MAKER_AYS_PUBLIC_URL) ."/images/poll-maker-eye-visibility-off.svg' class='ays-poll-password-toggle ays-poll-password-toggle-visibility-off'>";
1369 + $password_message_with_toggle .= "<img src='". esc_url(POLL_MAKER_AYS_PUBLIC_URL) ."/images/poll-maker-eye-visibility.svg' class='ays-poll-password-toggle ays-poll-password-toggle-visibility ays_poll_display_none'>";
1189 1370 }
1190 1371
1191 1372
1192 1373 if($poll_enable_password){
@@ -1200,9 +1381,9 @@
1200 1381 ".$poll_password_message_input."
1201 1382 ".$password_message_with_toggle."
1202 1383 </div>
1203 1384 <div class='ays-poll-password-button-box'>
1204 - <input type='submit' class='ays-poll-password-button' name='ays_poll_password_sub_". $id ."' class='ays_poll_password' value='".__( "Submit", "poll-maker" )."'>
1385 + <input type='submit' class='ays-poll-password-button' name='ays_poll_password_sub_". $id ."' class='ays_poll_password' value='". esc_html__( "Submit", "poll-maker" )."'>
1205 1386 </div>
1206 1387 </div>
1207 1388 </div></div></form></div>";
1208 1389 }
@@ -1278,8 +1459,12 @@
1278 1459 width: 55px;
1279 1460 height: 55px;
1280 1461 }
1281 1462
1463 + #".$this_poll_id." span.ayspoll-answers-votes-count-before-voting{
1464 + padding: 10px !important;
1465 + }
1466 +
1282 1467 .$this_poll_id.ays-minimal-theme .apm-choosing input[type=radio]:checked + label, .$this_poll_id.ays-minimal-theme .apm-choosing label.ays_enable_hover:hover{
1283 1468 background-color: " . ($answer_hover_color ? $answer_hover_color : "initial") . " !important;
1284 1469 color: $main_color !important;
1285 1470 border-color: $main_color !important;
@@ -1396,8 +1581,10 @@
1396 1581 padding: " . $buttons_top_bottom_padding . " " . $buttons_left_right_padding . ";
1397 1582 border-radius: " . $buttons_border_radius . ";
1398 1583 color: ". $poll_button_text_color ." !important;
1399 1584 background: ". $button_bg_color ." !important;
1585 + border: none;
1586 + line-height: 12px !important;
1400 1587 }
1401 1588
1402 1589 #".$this_poll_id ." .apm-add-answer input.ays-poll-new-answer-apply-text{
1403 1590 width: 100%;
@@ -1424,9 +1611,9 @@
1424 1611 }
1425 1612
1426 1613 #".$this_poll_id.".box-apm .apm-choosing .ays-poll-each-answer-grid{
1427 1614 width: 100%;
1428 - text-align: center;
1615 + text-align: left;
1429 1616 display: inline-block;
1430 1617 word-break: break-word;
1431 1618 }
1432 1619
@@ -1482,11 +1669,13 @@
1482 1669 }
1483 1670
1484 1671 #".$this_poll_id.".box-apm .apm-title-box div{
1485 1672 font-size: ".$poll_title_font_size."px;
1673 + font-weight: ".$poll_title_font_weight.";
1486 1674 word-break: break-word;
1487 1675 word-wrap: break-word;
1488 1676 text-align: ".$poll_title_alignment.";
1677 + text-transform: ".$poll_title_text_transform.";
1489 1678 }
1490 1679
1491 1680 #".$this_poll_id.".box-apm .ays-poll-answer-container-list{
1492 1681 margin-bottom: ".$poll_answer_margin."px;
@@ -1521,8 +1710,9 @@
1521 1710
1522 1711 #".$this_poll_id.".box-apm .apm-answers .apm-choosing label.ays_label_poll{
1523 1712 ".$answers_box_shadow_content.";
1524 1713 border-radius: ".$poll_answer_border_radius."px;
1714 + position: relative;
1525 1715 }
1526 1716
1527 1717 #".$this_poll_id.".box-apm.text-poll .apm-answers .ays-poll-text-types-inputs{
1528 1718 font-size: ".$poll_answer_font_size.";
@@ -1719,17 +1909,20 @@
1719 1909 #".$this_poll_id.".box-apm {
1720 1910 width: $poll_width_for_mobile;
1721 1911 }
1722 1912
1913 + #".$this_poll_id.".box-apm .ays-poll-btn{
1914 + width: ".$buttons_mobile_width.";
1915 + }
1916 +
1723 1917 .$this_poll_id.box-apm .ays_question p{
1724 1918 font-size: ".$poll_question_font_size_mobile."px;
1725 1919 }";
1726 1920
1727 1921 if ($answers_grid_column_mobile) {
1728 - $content .= "
1729 - .".$this_poll_id." .apm-answers,
1730 - .".$this_poll_id." .ays_poll_grid_view_container {
1731 - flex-direction: column;
1922 + $content .= "
1923 + .".$this_poll_id." .apm-answers .apm-rating i.ays_poll_fa-star {
1924 + font-size: 4vw !important;
1732 1925 }
1733 1926 #".$this_poll_id.".box-apm .ays-poll-answer-container-gird{
1734 1927 width: 100%;
1735 1928 }";
@@ -1737,9 +1930,11 @@
1737 1930
1738 1931 $content .= "
1739 1932 #".$this_poll_id.".box-apm .apm-title-box div{
1740 1933 font-size: ".$poll_title_font_size_mobile."px;
1934 + font-weight: ".$poll_title_font_weight_mobile.";
1741 1935 text-align: ".$poll_title_alignment_mobile.";
1936 + text-transform: ".$poll_title_text_transform.";
1742 1937 word-break: break-word;
1743 1938 word-wrap: break-word;
1744 1939 }
1745 1940
@@ -1876,9 +2071,9 @@
1876 2071 if ($endDate_atr > 0) {
1877 2072 $show_timer .= '<p class="show_timer_countdown" data-timer_countdown="'.$endDate_atr.'"></p>';
1878 2073 }
1879 2074 }else if ($show_timer_type == 'enddate') {
1880 - $show_timer .= '<p class="show_timer_countdown">'.__('This Poll is active until ', "poll-maker").gmdate('jS \of F Y H:i:s', intval($endDate)).'</p>';
2075 + $show_timer .= '<p class="show_timer_countdown">'. esc_html__('This Poll is active until ', "poll-maker").gmdate('jS \of F Y H:i:s', intval($endDate)).'</p>';
1881 2076 }
1882 2077 $show_timer .= "</div>";
1883 2078 }
1884 2079 }elseif ($activeDateCheck && $activeActiveDateCheck && $is_start_soon) {
@@ -1886,9 +2081,9 @@
1886 2081 $show_timer .= "<div class='ays_poll_show_timer'>";
1887 2082 if ($show_timer_type == 'countdown') {
1888 2083 $show_timer .= '<p class="show_timer_countdown" data-timer_countdown="'.$startDate_atr.'"></p>';
1889 2084 }else if ($show_timer_type == 'enddate') {
1890 - $show_timer .= '<p class="show_timer_countdown">'.__('This Poll will start ', "poll-maker").gmdate('jS \of F Y H:i:s', intval($startDate)).'</p>';
2085 + $show_timer .= '<p class="show_timer_countdown">'. esc_html__('This Poll will start ', "poll-maker").gmdate('jS \of F Y H:i:s', intval($startDate)).'</p>';
1891 2086 }
1892 2087 $show_timer .= "</div>";
1893 2088 }
1894 2089 }
@@ -1896,9 +2091,9 @@
1896 2091 $show_cd_and_author = "<div class='ays_poll_cb_and_a'>";
1897 2092 if($show_create_date){
1898 2093 $poll_create_date = (isset($options['create_date']) && $options['create_date'] != '') ? $options['create_date'] : "0000-00-00 00:00:00";
1899 2094 if(Poll_Maker_Ays_Admin::validateDate($poll_create_date)){
1900 - $show_cd_and_author .= "<span>".__("Created on", "poll-maker")." </span><strong><time>".date("F d, Y", strtotime($poll_create_date))."</time></strong>";
2095 + $show_cd_and_author .= "<span>". esc_html__("Created on", "poll-maker")." </span><strong><time>".date("F d, Y", strtotime($poll_create_date))."</time></strong>";
1901 2096 }else{
1902 2097 $show_cd_and_author .= "";
1903 2098 }
1904 2099 }
@@ -1919,11 +2114,11 @@
1919 2114 }
1920 2115 $image = get_avatar($user_id, 32);
1921 2116 if(isset( $author['name'] ) && $author['name'] !== "Unknown"){
1922 2117 if($show_create_date){
1923 - $text = __("By", "poll-maker");
2118 + $text =esc_html__("By", "poll-maker");
1924 2119 }else{
1925 - $text = __("Created by", "poll-maker");
2120 + $text =esc_html__("Created by", "poll-maker");
1926 2121 }
1927 2122 $show_cd_and_author .= "<span> ".$text." </span>".$image."<strong>".$author['name']."</strong>";
1928 2123 }else{
1929 2124 $show_cd_and_author .= "";
@@ -1931,8 +2126,13 @@
1931 2126 }
1932 2127
1933 2128 $show_cd_and_author .= "</div>";
1934 2129
2130 + // Show votes count per answers before voting
2131 + $options['show_votes_before_voting'] = isset($options['show_votes_before_voting']) ? $options['show_votes_before_voting'] : 'off';
2132 + $show_votes_before_voting = (isset($options['show_votes_before_voting']) && $options['show_votes_before_voting'] == 'on') ? true : false;
2133 + $show_votes_before_voting_by = (isset($options['show_votes_before_voting_by']) && $options['show_votes_before_voting_by'] != '') ? $options['show_votes_before_voting_by'] : 'by_count';
2134 +
1935 2135 $poll_login_form = "";
1936 2136 if($show_login_form){
1937 2137 $args = array(
1938 2138 'echo' => false,
@@ -1949,9 +2149,9 @@
1949 2149 $user_first_name = (isset( $poll_user_information['user_first_name'] ) && $poll_user_information['user_first_name'] != "") ? $poll_user_information['user_first_name'] : '';
1950 2150 $user_last_name = (isset( $poll_user_information['user_last_name'] ) && $poll_user_information['user_last_name'] != "") ? $poll_user_information['user_last_name'] : '';
1951 2151 $creation_date = (isset( $poll['styles']['create_date'] ) && $poll['styles']['create_date'] != '') ? $poll['styles']['create_date'] : '';
1952 2152
1953 - $current_poll_author = __( "Unknown", "poll-maker" );
2153 + $current_poll_author = esc_html__( "Unknown", "poll-maker" );
1954 2154 if( !empty($options['author']) ){
1955 2155 if( !is_array($options['author']) ){
1956 2156 $options['author'] = json_decode($options['author'], true);
1957 2157 }
@@ -1964,8 +2164,9 @@
1964 2164 }
1965 2165 }
1966 2166
1967 2167 $user_nickname = '';
2168 + $user_first_name = '';
1968 2169 $user_display_name = '';
1969 2170 $user_wordpress_email = '';
1970 2171 $user_wordpress_roles = '';
1971 2172 $user_wordpress_website = '';
@@ -1974,8 +2175,9 @@
1974 2175 if($user_id != 0){
1975 2176 $usermeta = get_user_meta( $user_id );
1976 2177 if($usermeta !== null){
1977 2178 $user_nickname = (isset($usermeta['nickname'][0]) && sanitize_text_field( $usermeta['nickname'][0] != '') ) ? sanitize_text_field( $usermeta['nickname'][0] ) : '';
2179 + $user_first_name = (isset($usermeta['first_name'][0]) && sanitize_text_field( $usermeta['first_name'][0] != '') ) ? sanitize_text_field( $usermeta['first_name'][0] ) : '';
1978 2180 }
1979 2181
1980 2182 $current_user_data = get_userdata( $user_id );
1981 2183 if ( ! is_null( $current_user_data ) && $current_user_data ) {
@@ -1993,9 +2195,9 @@
1993 2195
1994 2196 $user_wordpress_website_url = ( isset( $current_user_data->user_url ) && ! empty( $current_user_data->user_url ) ) ? sanitize_url($current_user_data->user_url) : "";
1995 2197
1996 2198 if( !empty( $user_wordpress_website_url ) ){
1997 - $user_wordpress_website = "<a href='". esc_url( $user_wordpress_website_url ) ."' target='_blank' class='ays-poll-user-website-link-a-tag'>". __( "Website", "poll-maker" ) ."</a>";
2199 + $user_wordpress_website = "<a href='". esc_url( $user_wordpress_website_url ) ."' target='_blank' class='ays-poll-user-website-link-a-tag'>".esc_html__( "Website", "poll-maker" ) ."</a>";
1998 2200 }
1999 2201 }
2000 2202 }
2001 2203
@@ -2080,9 +2282,9 @@
2080 2282 }
2081 2283 if (!$is_expired) {
2082 2284 //CHECK IF ENABLED ONLY LOGGED IN USERS OPTION
2083 2285 if (isset($options['enable_logged_users']) && $options['enable_logged_users'] == 1 && !is_user_logged_in()) {
2084 - $logged_users_message = isset($options['enable_logged_users_message']) && $options['enable_logged_users_message'] != '' ? $this->ays_autoembed(stripslashes($options['enable_logged_users_message'])) : "<p>" . __('You must sign in for voting.', "poll-maker") . "</p>"; // smbo
2286 + $logged_users_message = isset($options['enable_logged_users_message']) && $options['enable_logged_users_message'] != '' ? $this->ays_autoembed(stripslashes($options['enable_logged_users_message'])) : "<p>" .esc_html__('You must sign in for voting.', "poll-maker") . "</p>"; // smbo
2085 2287
2086 2288 $content .= "<div class='apm-need-sign-in'>".$logged_users_message."</div>";
2087 2289
2088 2290 if($logged_users_message !== null){
@@ -2096,9 +2298,9 @@
2096 2298 // Users role Aro start
2097 2299 global $wp_roles;
2098 2300 $user = wp_get_current_user();
2099 2301 $users_roles = $wp_roles->role_names;
2100 - $message = (isset($options['restriction_pass_message']) && $options['restriction_pass_message'] != '') ? stripslashes($options['restriction_pass_message']) : ("<p>" . __('You not have permissions for voting.', "poll-maker") . "</p>");
2302 + $message = (isset($options['restriction_pass_message']) && $options['restriction_pass_message'] != '') ? stripslashes($options['restriction_pass_message']) : ("<p>" .esc_html__('You not have permissions for voting.', "poll-maker") . "</p>");
2101 2303 $users_role = (isset($options['users_role']) && $options['users_role'] != '') ? $options['users_role'] : '';
2102 2304 $users_role = json_decode($users_role);
2103 2305 if(!empty($users_role)){
2104 2306 if (is_array($users_role)) {
@@ -2211,9 +2413,9 @@
2211 2413 $multiple_select = 'multiple';
2212 2414 $allow_multivote_answer = 'on';
2213 2415 $poll_multivote_min_count = (isset($options['multivote_answer_min_count']) && $options['multivote_answer_min_count'] != '') ? absint(intval($options['multivote_answer_min_count'])) : '1';
2214 2416 $poll_multivote_min_count_content = "<input type='hidden' id='ays_poll_multivote_min_count' data-allow='true' value='".$poll_multivote_min_count."'/>";
2215 - $poll_multivote_message_content = "<div class='ays-poll-multivote-message add_answer_for_grid'>".__("Min votes count should be" , "poll-maker")." ".$poll_multivote_min_count."</div>";
2417 + $poll_multivote_message_content = "<div class='ays-poll-multivote-message add_answer_for_grid'>". esc_html__("Min votes count should be" , "poll-maker")." ".$poll_multivote_min_count."</div>";
2216 2418 }else{
2217 2419 $multiple_select = '';
2218 2420 $allow_multivote_answer = '';
2219 2421 }
@@ -2242,9 +2444,11 @@
2242 2444 }
2243 2445 }else{
2244 2446 $answer_icon_class = '';
2245 2447 }
2246 -
2448 +
2449 + $poll_answer_votes = null;
2450 + $poll_answer_votes_sum = null;
2247 2451 $content .= "<div class='apm-answers $without_vote ".$answers_container."'>";
2248 2452 switch ( $poll['type'] ) {
2249 2453 case 'choosing':
2250 2454 $pol_answer_view_type = isset($poll['styles']['poll_answer_view_type']) && $poll['styles']['poll_answer_view_type'] != "" ? esc_attr($poll['styles']['poll_answer_view_type']) : "list";
@@ -2259,8 +2463,26 @@
2259 2463 $numbering_type_arr = array();
2260 2464 if($answers_count){
2261 2465 $numbering_type_arr = $this->ays_answer_numbering($show_answers_numbering , $answers_count);
2262 2466 }
2467 +
2468 + $poll_answer_percentages = array();
2469 + $poll_answer_votes = array();
2470 + foreach ( $poll['answers'] as $index => $answer ) {
2471 +
2472 + $poll_answer_votes[$answer['id']] = intval( $answer['votes'] );
2473 + }
2474 +
2475 + $poll_answer_votes_sum = array_sum( $poll_answer_votes );
2476 + $poll_answer_percentages = array();
2477 + foreach ( $poll_answer_votes as $index => $answer_vote_count ) {
2478 + if( $poll_answer_votes_sum != 0 ){
2479 + $poll_answer_percentages[$index] = round( ( $answer_vote_count * 100 ) / $poll_answer_votes_sum, 1);
2480 + }else{
2481 + $poll_answer_percentages[$index] = 0;
2482 + }
2483 + }
2484 +
2263 2485 if($poll_allow_multivote){
2264 2486 $content .= "<input type='hidden' id='multivot_answer_count' value='".$multivote_answer_count."'/>";
2265 2487 $content .= $poll_multivote_min_count_content;
2266 2488 }
@@ -2282,8 +2504,29 @@
2282 2504 if ($poll_view_more_button_count - 1 < $index) {
2283 2505 $answer_style_class = 'ays_poll_display_none';
2284 2506 }
2285 2507 }
2508 +
2509 + $show_votes_before_voting_display_none = "";
2510 + if( !$show_votes_before_voting ){
2511 + $show_votes_before_voting_display_none = "display:none;";
2512 + }
2513 + $opacity_bg_color_svbv = $poll['view_type'] == 'grid' ? 0.6 : 0.3;
2514 + $show_votes_before_voting_color = $this->rgb2hex( $text_color );
2515 + $show_votes_before_voting_color = $this->hex2rgba( $show_votes_before_voting_color, $opacity_bg_color_svbv );
2516 +
2517 + $show_votes_before_voting_display = "style='text-shadow: 0px 0px 5px " . $bg_color . ";'";
2518 + $show_votes_before_voting_display_width = "";
2519 + if( !$show_votes_before_voting ){
2520 + $show_votes_before_voting_display = "style='{$show_votes_before_voting_display_none}text-shadow: 0px 0px 5px " . $bg_color . ";'";
2521 + $show_votes_before_voting_display_width = "style='{$show_votes_before_voting_display_none}text-shadow: 0px 0px 5px " . $bg_color . ";'";
2522 + }
2523 +
2524 + if( $poll['view_type'] == 'grid' ){
2525 + $show_votes_before_voting_display = "style='{$show_votes_before_voting_display_none}justify-content:center;font-weight:900;text-shadow: 0px 0px 5px " . $bg_color . ";'";
2526 + $show_votes_before_voting_display_width = "style='{$show_votes_before_voting_display_none}text-shadow: 0px 0px 5px " . $bg_color . ";'";
2527 + }
2528 +
2286 2529 $pol_answer_view_type_show = 'ays_poll_list_view_item';
2287 2530 $pol_answer_view_type_image = 'ays-poll-each-image-list';
2288 2531 $pol_answer_view_type_cont = 'ays-poll-answer-container-list';
2289 2532 $pol_answer_view_type_label_cont = 'ays-poll-answer-container-label-list';
@@ -2310,8 +2553,22 @@
2310 2553 $pol_answer_view_type_text_show = 'ays-poll-each-answer-list';
2311 2554
2312 2555 $poll_class_for_answer_label_text = "ays_poll_label_text_with_padding";
2313 2556 }
2557 +
2558 + $answer_votes_count_before_voting = "";
2559 + switch ( $show_votes_before_voting_by ) {
2560 + case 'by_percentage':
2561 + $answer_votes_count_before_voting = $poll_answer_percentages[$answer['id']] . "%";
2562 + break;
2563 + default:
2564 + $real_votes = isset($answer['votes']) && $answer['votes'] != "" ? intval( $answer['votes'] ) : 0;
2565 +
2566 + $answer_votes_count_before_voting = $real_votes;
2567 +
2568 + break;
2569 + }
2570 +
2314 2571 $content .= "
2315 2572 <div class='apm-choosing answer-$this_poll_id ". $answer_style_class ." ays-poll-field ".$pol_answer_view_type_cont."' >
2316 2573 <input type=".$poll_multivote_checkbox." name='answer' id='radio-$index-$this_poll_id' value='{$answer['id']}' {$autocomplete_attr}>
2317 2574 <label
@@ -2319,9 +2576,16 @@
2319 2576 class='ays_label_poll ".$answers_sound_class." ".$redirect_after_submit." ".$disable_answer_hover." ays_label_font_size ".$answer_icon_class." ".$poll_class_for_answer_label." ".$pol_answer_view_type_label_cont."'
2320 2577 data-answers-url='".(isset($answer['redirect']) && is_string($answer['redirect']) ? esc_url($answer['redirect']) : '')."'
2321 2578 >".$poll_answer_image_show." <p style='".$poll_added_style."' class='ays-poll-answers'><span class='".$pol_answer_view_type_text_show."'>"
2322 2579 . $numbering_type . esc_attr(stripcslashes($answer['answer'])) .
2323 - "</span></p></label>
2580 + "</span></p>";
2581 +
2582 + $content .= "<span class='ayspoll-answers-votes-count-before-voting' ". $show_votes_before_voting_display .">". $answer_votes_count_before_voting ."</span>
2583 + <span class='ayspoll-answers-votes-count-before-voting-width' ". $show_votes_before_voting_display_width .">
2584 + <span style='width: ". $poll_answer_percentages[$answer['id']] ."%; background-color:" . $show_votes_before_voting_color . ";'></span>
2585 + </span>";
2586 +
2587 + $content .= " </label>
2324 2588 </div>";
2325 2589 }
2326 2590 }
2327 2591 }
@@ -2328,9 +2592,9 @@
2328 2592 $add_answer_for_grid = isset($poll['view_type']) && $poll['view_type'] == 'grid' ? 'add_answer_for_grid' : '';
2329 2593 if ($poll_allow_answer && $with_vote) {
2330 2594 $content .= "
2331 2595 <div class='apm-choosing answer-$this_poll_id ".$this_poll_id."_addAnswer apm-add-answer ".$add_answer_for_grid."'>
2332 - <input type='text' placeholder='" . __("Other - please specify", "poll-maker") . "' class='ays-poll-new-answer-apply-text' name='ays_poll_new_answer'>
2596 + <input type='text' placeholder='" .esc_html__("Other - please specify", "poll-maker") . "' class='ays-poll-new-answer-apply-text' name='ays_poll_new_answer'>
2333 2597 </div>
2334 2598 ";
2335 2599 $allow_multi_vote_for_other = isset($options["poll_allow_multivote"]) && $options["poll_allow_multivote"] == "on" ? true : false;
2336 2600 if(!$allow_multi_vote_for_other){
@@ -2335,9 +2599,9 @@
2335 2599 $allow_multi_vote_for_other = isset($options["poll_allow_multivote"]) && $options["poll_allow_multivote"] == "on" ? true : false;
2336 2600 if(!$allow_multi_vote_for_other){
2337 2601 $content .= "
2338 2602 <div class='ays-poll-add-answer-note ays-poll-add-answer-note-enable'>
2339 - <div class='ays-poll-add-answer-note-text'><img src='".POLL_MAKER_AYS_ADMIN_URL."/images/icons/other-answer-note.svg' >".__( "If 'Other' is filled, checked answers are ignored.", "poll-maker")."</div>
2603 + <div class='ays-poll-add-answer-note-text'><img src='".esc_url(POLL_MAKER_AYS_ADMIN_URL)."/images/icons/other-answer-note.svg' >". esc_html__( "If 'Other' is filled, checked answers are ignored.", "poll-maker")."</div>
2340 2604 </div>
2341 2605 ";
2342 2606 }
2343 2607 }
@@ -2427,9 +2691,9 @@
2427 2691
2428 2692 if ($view_more_button_flag) {
2429 2693 $content .= '
2430 2694 <div class="ays-poll-view-more-button-box">
2431 - <input type="button" class="btn ays-poll-btn ays-poll-view-more-button" value="'. __( "View more", "poll-maker" ) .'">
2695 + <input type="button" class="btn ays-poll-btn ays-poll-view-more-button" value="'.esc_html__( "View more", "poll-maker" ) .'">
2432 2696 </div>';
2433 2697 }
2434 2698
2435 2699 $content .= "</div>";
@@ -2442,9 +2706,9 @@
2442 2706 $content .= "</div>";
2443 2707 if ($info_form) {
2444 2708 $this->fields_placeholders = $this->ays_set_poll_fields_placeholders_texts();
2445 2709 $content .= "\n
2446 - <div class='apm-info-form' data-text='" . __("Send", "poll-maker") . "' style='display: none;'>
2710 + <div class='apm-info-form' data-text='" .esc_html__("Send", "poll-maker") . "' style='display: none;'>
2447 2711 $info_form_title
2448 2712 <div class='amp-info-form-input-box'>
2449 2713 ";
2450 2714 foreach ( $fields as $f ) {
@@ -2478,12 +2742,12 @@
2478 2742 }
2479 2743 $content .= "</div></div>";
2480 2744 }
2481 2745 } else {
2482 - $content .= "<div class='ays-poll-limitation'>" . (isset($options['limitation_message']) && $options['limitation_message'] != '' ? stripslashes($options['limitation_message']) : ("<p>" . __("You have already voted.", "poll-maker") . "</p>")) . "</div>";
2746 + $content .= "<div class='ays-poll-limitation'>" . (isset($options['limitation_message']) && $options['limitation_message'] != '' ? stripslashes($options['limitation_message']) : ("<p>" .esc_html__("You have already voted.", "poll-maker") . "</p>")) . "</div>";
2483 2747 if (isset($options['redirect_url']) && $options['redirect_url'] != '' && isset($options['redirection_delay']) && $options['redirection_delay'] != 0) {
2484 2748 $content .= "<div class='apm-redirection apm-redirection-$this_poll_id'>
2485 - <p data-id='$this_poll_id' data-href='" . stripslashes($options['redirect_url']) . "' data-delay='{$options['redirection_delay']}'>" . __('Redirecting after', "poll-maker")
2749 + <p data-id='$this_poll_id' data-href='" . stripslashes($options['redirect_url']) . "' data-delay='{$options['redirection_delay']}'>" .esc_html__('Redirecting after', "poll-maker")
2486 2750 . " <b>{$this->secondsToWords($options['redirection_delay'])}</b>
2487 2751 </p>
2488 2752 </div>";
2489 2753 }
@@ -2531,9 +2795,9 @@
2531 2795
2532 2796 $ays_vote_button = (isset($options['btn_text']) && $options['btn_text'] != '') ? stripslashes($options['btn_text']) : 'Vote';
2533 2797
2534 2798 if ($ays_vote_button === 'Vote') {
2535 - $ays_vote_button_text = __("Vote", "poll-maker");
2799 + $ays_vote_button_text = esc_html__("Vote", "poll-maker");
2536 2800 }else{
2537 2801 $ays_vote_button_text = $ays_vote_button;
2538 2802 }
2539 2803
@@ -2556,9 +2820,9 @@
2556 2820
2557 2821 $poll_block_preview_message = "";
2558 2822 if( $is_elementor_exists || $is_editor_exists ){
2559 2823 $poll_block_preview_message = '
2560 - <span class="ays_poll_small_hint_text ays_poll_preview_mode_hint">'. esc_attr( __( "You're in the preview mode. Note: All elements work correctly on the front end." , "poll-maker") ) .'</span>';
2824 + <span class="ays_poll_small_hint_text ays_poll_preview_mode_hint">'. esc_attr(esc_html__( "You're in the preview mode. Note: All elements work correctly on the front end." , "poll-maker") ) .'</span>';
2561 2825 }
2562 2826
2563 2827 $content .= $poll_block_preview_message;
2564 2828 $content .= $result_message;
@@ -2563,13 +2827,13 @@
2563 2827 $content .= $poll_block_preview_message;
2564 2828 $content .= $result_message;
2565 2829 $content .= $redirect_after_vote;
2566 2830 } elseif ($is_start_soon) {
2567 - $poll_is_start_message = isset($options['active_date_message_soon']) ? stripslashes($options['active_date_message_soon']) : "<p>" . __('The poll will be available soon.', "poll-maker") . "</p>";
2831 + $poll_is_start_message = isset($options['active_date_message_soon']) ? stripslashes($options['active_date_message_soon']) : "<p>" .esc_html__('The poll will be available soon.', "poll-maker") . "</p>";
2568 2832 $content .= "<div class='apm_expired_poll'>".$poll_is_start_message."</div>";
2569 2833
2570 2834 } else {
2571 - $expired_poll_message = isset($options['active_date_message']) ? stripslashes($options['active_date_message']) : "<p>" . __('The poll has expired.', "poll-maker") . "</p>";
2835 + $expired_poll_message = isset($options['active_date_message']) ? stripslashes($options['active_date_message']) : "<p>" .esc_html__('The poll has expired.', "poll-maker") . "</p>";
2572 2836 $content .= "<div class='apm_expired_poll'>$expired_poll_message</div>";
2573 2837
2574 2838 if ($show_res_btn_sch) {
2575 2839 $content .= $see_result_button;
@@ -2652,9 +2916,9 @@
2652 2916 $polls_pool = $this->ays_get_polls_pool($new_res);
2653 2917
2654 2918 $ays_next_button = (isset($cat_opt['next_text']) && $cat_opt['next_text'] != '') ? stripslashes($cat_opt['next_text']) : 'Next';
2655 2919 if ($ays_next_button === 'Next') {
2656 - $ays_next_button_text = __("Next", "poll-maker");
2920 + $ays_next_button_text = esc_html__("Next", "poll-maker");
2657 2921 } else {
2658 2922 $ays_next_button_text = $ays_next_button;
2659 2923 }
2660 2924
@@ -2659,9 +2923,9 @@
2659 2923 }
2660 2924
2661 2925 $ays_previous_button = (isset($cat_opt['previous_text']) && $cat_opt['previous_text'] != '') ? stripslashes($cat_opt['previous_text']) : 'Previous';
2662 2926 if ($ays_previous_button === 'Previous') {
2663 - $ays_previous_button_text = __("Previous", "poll-maker");
2927 + $ays_previous_button_text = esc_html__("Previous", "poll-maker");
2664 2928 }else{
2665 2929 $ays_previous_button_text = $ays_previous_button;
2666 2930 }
2667 2931
@@ -2770,9 +3034,11 @@
2770 3034 return $poll;
2771 3035 }
2772 3036
2773 3037 private static function get_user_ip() {
2774 - $ipaddress = '';
3038 +
3039 + $ipaddress = false;
3040 +
2775 3041 if (getenv('HTTP_CLIENT_IP')) {
2776 3042 $ipaddress = getenv('HTTP_CLIENT_IP');
2777 3043 } else if (getenv('HTTP_X_FORWARDED_FOR')) {
2778 3044 $ipaddress = getenv('HTTP_X_FORWARDED_FOR');
@@ -2781,15 +3047,20 @@
2781 3047 } else if (getenv('HTTP_FORWARDED_FOR')) {
2782 3048 $ipaddress = getenv('HTTP_FORWARDED_FOR');
2783 3049 } else if (getenv('HTTP_FORWARDED')) {
2784 3050 $ipaddress = getenv('HTTP_FORWARDED');
2785 - } else if (getenv('REMOTE_ADDR')) {
2786 - $ipaddress = getenv('REMOTE_ADDR');
2787 - } else {
2788 - $ipaddress = 'UNKNOWN';
2789 3051 }
2790 3052
2791 - return $ipaddress;
3053 + if ( $ipaddress !== false && filter_var( $ipaddress, FILTER_VALIDATE_IP ) !== false ) {
3054 + return $ipaddress;
3055 + }
3056 +
3057 + $remote_address = getenv('REMOTE_ADDR');
3058 + if ( $remote_address !== false && filter_var( $remote_address, FILTER_VALIDATE_IP ) !== false ) {
3059 + return $remote_address;
3060 + }
3061 +
3062 + return 'UNKNOWN';
2792 3063 }
2793 3064
2794 3065 public static function get_user_ip_validated(){
2795 3066 $headers_to_check = array(
@@ -2827,27 +3098,27 @@
2827 3098
2828 3099 /*** get the days ***/
2829 3100 $days = (int)($seconds / (3600 * 24));
2830 3101 if ($days > 0) {
2831 - $ret .= "$days " . __( 'days', "poll-maker" ) . ' ';
3102 + $ret .= "$days " .esc_html__( 'days', "poll-maker" ) . ' ';
2832 3103 }
2833 3104
2834 3105 /*** get the hours ***/
2835 3106 $hours = (int)(($seconds / 3600) % 24);
2836 3107 if ($hours > 0) {
2837 - $ret .= "$hours " . __( 'hours', "poll-maker" ) . ' ';
3108 + $ret .= "$hours " .esc_html__( 'hours', "poll-maker" ) . ' ';
2838 3109 }
2839 3110
2840 3111 /*** get the minutes ***/
2841 3112 $minutes = (int)(($seconds / 60) % 60);
2842 3113 if ($minutes > 0) {
2843 - $ret .= "$minutes " . __( 'minutes', "poll-maker" ) . ' ';
3114 + $ret .= "$minutes " .esc_html__( 'minutes', "poll-maker" ) . ' ';
2844 3115 }
2845 3116
2846 3117 /*** get the seconds ***/
2847 3118 $seconds = (int)(($seconds) % 60);
2848 3119 if ($seconds > 0) {
2849 - $ret .= "$seconds " . __( 'seconds', "poll-maker" );
3120 + $ret .= "$seconds " .esc_html__( 'seconds', "poll-maker" );
2850 3121 }
2851 3122
2852 3123 return $ret;
2853 3124 }
@@ -2873,8 +3144,28 @@
2873 3144
2874 3145 return $result;
2875 3146 }
2876 3147
3148 + public static function get_poll_category_by_ids($ids){
3149 + global $wpdb;
3150 +
3151 + $ids = array_map('intval', explode(',', $ids));
3152 + $ids = array_filter($ids);
3153 +
3154 + if (empty($ids)) {
3155 + return [];
3156 + }
3157 +
3158 + $ids_sql = implode(',', $ids);
3159 +
3160 + $sql = "SELECT *
3161 + FROM {$wpdb->prefix}ayspoll_categories
3162 + WHERE id IN ($ids_sql)
3163 + ORDER BY FIELD(id, $ids_sql)";
3164 +
3165 + return $wpdb->get_results($sql, ARRAY_A);
3166 + }
3167 +
2877 3168 public function get_poll_status($id) {
2878 3169 global $wpdb;
2879 3170 $poll_id = absint(intval($id));
2880 3171 $poll_table = $wpdb->prefix . 'ayspoll_polls';
@@ -2893,18 +3184,22 @@
2893 3184 }
2894 3185 }
2895 3186
2896 3187 public function ays_poll_get_user_information() {
2897 - if (is_user_logged_in()) {
2898 - $output = json_encode(wp_get_current_user());
2899 - } else {
2900 - $output = null;
3188 + if ( ! check_ajax_referer( 'ays_poll_nonce', '_ajax_nonce', false ) ) {
3189 + wp_send_json_error( array( 'message' => 'Invalid request' ), 403 );
2901 3190 }
3191 + if ( ! is_user_logged_in() ) {
3192 + wp_send_json_error( array( 'message' => 'User not logged in' ), 401 );
3193 + }
2902 3194
2903 - ob_end_clean();
2904 - $ob_get_clean = ob_get_clean();
2905 - echo $output;
2906 - wp_die();
3195 + $user = wp_get_current_user();
3196 +
3197 + wp_send_json_success( array(
3198 + 'display_name' => $user->display_name,
3199 + 'user_email' => $user->user_email,
3200 +
3201 + ) );
2907 3202 }
2908 3203
2909 3204 public function ays_finish_poll() {
2910 3205 global $wpdb;
@@ -2979,8 +3274,22 @@
2979 3274 $poll_answers_count = isset($poll['answers']) ? count($poll['answers']) : 0;
2980 3275 $added_answer_id = array();
2981 3276
2982 3277 $poll_title = (isset($poll['title']) && $poll['title'] != '') ? stripslashes( sanitize_text_field( $poll['title'] ) ) : '';
3278 +
3279 + // Poll category title
3280 + $poll_category_title = "";
3281 +
3282 + $poll_cats = isset( $poll['categories'] ) ? trim( $poll['categories'], ',' ) : '';
3283 + $poll_category_ids = $poll_cats !== '' ? sanitize_text_field( $poll_cats ) : '';
3284 +
3285 + if ( $poll_category_ids != '' ) {
3286 + $categories = self::get_poll_category_by_ids( $poll_category_ids );
3287 + $category_names = wp_list_pluck( $categories, 'title' );
3288 +
3289 + $poll_category_title = implode( ', ', $category_names );
3290 + }
3291 +
2983 3292 $poll_vote_reason_text = "";
2984 3293 $poll_vote_reason = false;
2985 3294 $show_answers_numbering = (isset($options['show_answers_numbering']) && sanitize_text_field( $options['show_answers_numbering'] ) != '') ? sanitize_text_field( $options['show_answers_numbering'] ) : 'none';
2986 3295 if (isset($options['poll_vote_reason']) && $options['poll_vote_reason'] == "on" && isset($_POST['ays-poll-reason-text'])) {
@@ -3187,9 +3496,14 @@
3187 3496 $user_last_name = (isset( $poll_user_information['user_last_name'] ) && $poll_user_information['user_last_name'] != "") ? $poll_user_information['user_last_name'] : '';
3188 3497 $creation_date = (isset( $poll['styles']['create_date'] ) && $poll['styles']['create_date'] != '') ? $poll['styles']['create_date'] : '';
3189 3498
3190 3499
3191 - $current_poll_author = __( "Unknown", "poll-maker" );
3500 + $current_poll_author = esc_html__( "Unknown", "poll-maker" );
3501 + $current_poll_author_email = '';
3502 + $current_poll_author_nickname = '';
3503 + $current_poll_author_display_name = '';
3504 + $current_poll_author_website_url = '';
3505 + $current_poll_author_registered = '';
3192 3506 if( !empty($options['author']) ){
3193 3507 if( !is_array($options['author']) ){
3194 3508 $options['author'] = json_decode($options['author'], true);
3195 3509 }
@@ -3198,14 +3512,40 @@
3198 3512
3199 3513 $current_poll_user_data = get_userdata( $poll_current_author );
3200 3514 if ( ! is_null( $current_poll_user_data ) && $current_poll_user_data ) {
3201 3515 $current_poll_author = ( isset( $current_poll_user_data->data->display_name ) && $current_poll_user_data->data->display_name != '' ) ? sanitize_text_field( $current_poll_user_data->data->display_name ) : "";
3516 + $current_poll_author_email = ( isset( $current_poll_user_data->data->user_email ) && $current_poll_user_data->data->user_email != '' ) ? sanitize_text_field( $current_poll_user_data->data->user_email ) : "";
3517 + $current_poll_author_nickname = ( isset( $current_poll_user_data->data->user_nicename ) && $current_poll_user_data->data->user_nicename != '' ) ? sanitize_text_field( $current_poll_user_data->data->user_nicename ) : "";
3518 + $current_poll_author_display_name = ( isset( $current_poll_user_data->data->display_name ) && $current_poll_user_data->data->display_name != '' ) ? sanitize_text_field( $current_poll_user_data->data->display_name ) : "";
3519 + $current_poll_author_website_url = ( isset( $current_poll_user_data->data->user_url ) && $current_poll_user_data->data->user_url != '' ) ? sanitize_text_field( $current_poll_user_data->data->user_url ) : "";
3520 + $current_poll_author_registered = ( isset( $current_poll_user_data->data->user_registered ) && $current_poll_user_data->data->user_registered != '' ) ? sanitize_text_field( $current_poll_user_data->data->user_registered ) : "";
3202 3521 }
3203 3522 }
3204 3523
3524 + // Get Current date
3205 3525 $poll_current_date = date_i18n( 'M d, Y', strtotime( sanitize_text_field( $_REQUEST['end_date'] ) ) );
3206 3526
3527 + // Get Current time
3528 + $poll_current_time = date_i18n( get_option( 'time_format' ), strtotime( sanitize_text_field( $_REQUEST['end_date'] ) ) );
3529 +
3530 + // Get Current day
3531 + $poll_current_day = date_i18n( 'l', strtotime( sanitize_text_field( $_REQUEST['end_date'] ) ) );
3532 +
3533 + // Get Current month
3534 + $poll_current_month = date_i18n( 'F', strtotime( sanitize_text_field( $_REQUEST['end_date'] ) ) );
3535 +
3536 + // Get Post Title
3537 + $post_id = url_to_postid( $_POST['_wp_http_referer'] );
3538 + $post_title = get_the_title( $post_id );
3539 + $get_site_title = get_bloginfo('name');
3540 + $get_site_description = get_bloginfo('description');
3541 +
3542 + // WP home page url
3543 + $home_main_url = home_url();
3544 + $home_page_url = '<a href="'. $home_main_url .'" target="_blank">'. $home_main_url .'</a>';
3545 +
3207 3546 $user_nickname = '';
3547 + $user_first_name = '';
3208 3548 $user_display_name = '';
3209 3549 $user_wordpress_email = '';
3210 3550 $user_wordpress_roles = '';
3211 3551 $user_wordpress_website = '';
@@ -3210,12 +3550,46 @@
3210 3550 $user_wordpress_roles = '';
3211 3551 $user_wordpress_website = '';
3212 3552 $user_ip_address = '';
3213 3553 $user_id = get_current_user_id();
3214 - if($user_id != 0){
3554 + $user_data = wp_get_current_user();
3555 + $super_admin_email = get_option('admin_email');
3556 +
3557 + $post_author = get_post_field( 'post_author', $post_id );
3558 + $author_id = get_the_author_meta('ID', $post_author);
3559 + $post_author_email = get_the_author_meta( 'email', $author_id );
3560 + $post_author_display_name = get_the_author_meta( 'display_name', $author_id );
3561 + $post_author_nickname = get_the_author_meta( 'nickname', $author_id );
3562 + $post_author_first_name = get_the_author_meta( 'first_name', $author_id );
3563 + $post_author_last_name = get_the_author_meta( 'last_name', $author_id );
3564 + $post_author_website_url = get_the_author_meta( 'url', $author_id );
3565 +
3566 + $post_author_roles = '';
3567 + $user_registered = '';
3568 + if ( is_user_logged_in() ) {
3569 + $post_author_roles = get_the_author_meta( 'roles', $author_id );
3570 + $user_registered = $user_data->user_registered;
3571 + }
3572 +
3573 + if ( ! empty( $post_author_website_url ) ) {
3574 + $post_author_website_url = '<a href="'. $post_author_website_url .'" target="_blank">'. $post_author_website_url .'</a>';
3575 + }
3576 +
3577 + if ( ! empty( $current_poll_author_website_url ) ) {
3578 + $current_poll_author_website_url = '<a href="'. $current_poll_author_website_url .'" target="_blank">'. $current_poll_author_website_url .'</a>';
3579 + }
3580 +
3581 + if ( ! empty( $post_author_roles ) && $post_author_roles != "" ) {
3582 + if ( is_array( $post_author_roles ) ) {
3583 + $post_author_roles = implode( ", ", $post_author_roles );
3584 + }
3585 + }
3586 +
3587 + if( $user_id != 0 ){
3215 3588 $usermeta = get_user_meta( $user_id );
3216 3589 if($usermeta !== null){
3217 3590 $user_nickname = (isset($usermeta['nickname'][0]) && sanitize_text_field( $usermeta['nickname'][0] != '') ) ? sanitize_text_field( $usermeta['nickname'][0] ) : '';
3591 + $user_first_name = (isset($usermeta['first_name'][0]) && sanitize_text_field( $usermeta['first_name'][0] != '') ) ? sanitize_text_field( $usermeta['first_name'][0] ) : '';
3218 3592 }
3219 3593
3220 3594 $current_user_data = get_userdata( $user_id );
3221 3595 if ( ! is_null( $current_user_data ) && $current_user_data ) {
@@ -3233,13 +3607,19 @@
3233 3607
3234 3608 $user_wordpress_website_url = ( isset( $current_user_data->user_url ) && ! empty( $current_user_data->user_url ) ) ? sanitize_url($current_user_data->user_url) : "";
3235 3609
3236 3610 if( !empty( $user_wordpress_website_url ) ){
3237 - $user_wordpress_website = "<a href='". esc_url( $user_wordpress_website_url ) ."' target='_blank' class='ays-poll-user-website-link-a-tag'>". __( "Website", "poll-maker" ) ."</a>";
3611 + $user_wordpress_website = "<a href='". esc_url( $user_wordpress_website_url ) ."' target='_blank' class='ays-poll-user-website-link-a-tag'>".esc_html__( "Website", "poll-maker" ) ."</a>";
3238 3612 }
3239 3613 }
3240 3614 }
3241 3615
3616 + if ( is_user_logged_in() ) {
3617 + $current_user_id = get_current_user_id();
3618 + } else {
3619 + $current_user_id = '';
3620 + }
3621 +
3242 3622 $report_table = $wpdb->prefix."ayspoll_reports";
3243 3623 $answ_table = $wpdb->prefix."ayspoll_answers";
3244 3624
3245 3625 $sql = "SELECT COUNT(*)
@@ -3255,36 +3635,104 @@
3255 3635
3256 3636 $ays_protocol = ((!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] != 'off') || $_SERVER['SERVER_PORT'] == 443) ? "https://" : "http://";
3257 3637
3258 3638 $current_poll_page_link = isset( $_REQUEST['ays_poll_curent_page_link'] ) && $_REQUEST['ays_poll_curent_page_link'] != '' ? sanitize_url( $_REQUEST['ays_poll_curent_page_link'] ) : "";
3259 - $current_poll_page_link_html = "<a href='". esc_sql( $current_poll_page_link ) ."' target='_blank' class='ays-poll-curent-page-link-a-tag'>". __( "Poll link", "poll-maker" ) ."</a>";
3639 + $current_poll_page_link_html = "<a href='". esc_sql( $current_poll_page_link ) ."' target='_blank' class='ays-poll-curent-page-link-a-tag'>".esc_html__( "Poll link", "poll-maker" ) ."</a>";
3260 3640
3261 3641 $form_apm_name = (isset($_POST['apm_name']) && $_POST['apm_name'] != "") ? esc_attr($_POST['apm_name']) : "";
3262 3642 $form_apm_email = (isset($_POST['apm_email']) && $_POST['apm_email'] != "") ? esc_attr($_POST['apm_email']) : "";
3263 3643 $form_apm_phone = (isset($_POST['apm_phone']) && $_POST['apm_phone'] != "") ? esc_attr($_POST['apm_phone']) : "";
3264 -
3644 +
3265 3645 $message_data = array(
3266 - 'user_name' => $form_apm_name,
3267 - 'user_email' => $form_apm_email,
3268 - 'user_phone' => $form_apm_phone,
3269 - 'poll_title' => $poll_title,
3270 - 'users_first_name' => $user_first_name,
3271 - 'users_last_name' => $user_last_name,
3272 - 'creation_date' => $creation_date,
3273 - 'current_date' => $poll_current_date,
3274 - 'current_poll_author' => $current_poll_author,
3275 - 'user_nickname' => $user_nickname,
3276 - 'user_display_name' => $user_display_name,
3277 - 'user_wordpress_email' => $user_wordpress_email,
3278 - 'user_wordpress_roles' => $user_wordpress_roles,
3279 - 'poll_pass_count' => $pass_count,
3280 - 'passed_poll_count_per_user' => $passed_poll_count_per_user,
3281 - 'current_poll_page_link' => $current_poll_page_link_html,
3282 - 'user_wordpress_website' => $user_wordpress_website,
3283 - 'user_ip_address' => $user_ip_address,
3646 + 'user_name' => $form_apm_name,
3647 + 'user_email' => $form_apm_email,
3648 + 'user_phone' => $form_apm_phone,
3649 + 'poll_title' => $poll_title,
3650 + 'poll_category_title' => $poll_category_title,
3651 + 'poll_id' => $poll_id,
3652 + 'users_first_name' => $user_first_name,
3653 + 'users_last_name' => $user_last_name,
3654 + 'creation_date' => $creation_date,
3655 + 'current_date' => $poll_current_date,
3656 + 'current_time' => $poll_current_time,
3657 + 'current_day' => $poll_current_day,
3658 + 'current_month' => $poll_current_month,
3659 + 'current_poll_page_link' => $current_poll_page_link_html,
3660 + 'current_poll_author' => $current_poll_author,
3661 + 'current_poll_author_email' => $current_poll_author_email,
3662 + 'current_poll_author_nickname' => $current_poll_author_nickname,
3663 + 'current_poll_author_display_name' => $current_poll_author_display_name,
3664 + 'current_poll_author_website_url' => $current_poll_author_website_url,
3665 + 'current_poll_author_registered' => $current_poll_author_registered,
3666 + 'admin_email' => $super_admin_email,
3667 + 'user_nickname' => $user_nickname,
3668 + 'user_first_name' => $user_first_name,
3669 + 'user_display_name' => $user_display_name,
3670 + 'user_wordpress_email' => $user_wordpress_email,
3671 + 'user_wordpress_roles' => $user_wordpress_roles,
3672 + 'poll_pass_count' => $pass_count,
3673 + 'passed_poll_count_per_user' => $passed_poll_count_per_user,
3674 + 'user_wordpress_website' => $user_wordpress_website,
3675 + 'user_ip_address' => $user_ip_address,
3676 + 'user_id' => $current_user_id,
3677 + 'user_registered' => $user_registered,
3678 + 'post_title' => $post_title,
3679 + 'post_author_email' => $post_author_email,
3680 + 'post_author_display_name' => $post_author_display_name,
3681 + 'post_author_nickname' => $post_author_nickname,
3682 + 'post_author_first_name' => $post_author_first_name,
3683 + 'post_author_last_name' => $post_author_last_name,
3684 + 'post_author_website_url' => $post_author_website_url,
3685 + 'post_author_roles' => $post_author_roles,
3686 + 'post_id' => $post_id,
3687 + 'site_title' => $get_site_title,
3688 + 'site_description' => $get_site_description,
3689 + 'home_page_url' => $home_page_url,
3284 3690 );
3285 3691
3286 3692 $user_ip = esc_sql($user_ips);
3693 +
3694 + // Race condition fix
3695 + $limitusers = isset($poll['styles']['limit_users']) ? intval($poll['styles']['limit_users']) : 0;
3696 +
3697 + if ($limitusers > 0) {
3698 +
3699 + $limit_users_method = isset($poll['styles']['limit_users_method']) ? $poll['styles']['limit_users_method'] : "ip";
3700 +
3701 + switch ($limit_users_method) {
3702 + case 'ip':
3703 + default:
3704 + $wpdb->query("START TRANSACTION");
3705 + $already_voted = $wpdb->get_var($wpdb->prepare(
3706 + "SELECT COUNT(*) FROM {$report_table} WHERE user_ip = %s AND poll_id = %d FOR UPDATE",
3707 + $user_ip,
3708 + $poll_id
3709 + ));
3710 + break;
3711 + case 'cookie':
3712 + $wpdb->query("START TRANSACTION");
3713 + $already_voted = isset($_COOKIE["ays_this_poll_cookie_" . $poll_id]) ? 1 : 0;
3714 + break;
3715 + case 'user':
3716 + $wpdb->query("START TRANSACTION");
3717 + $already_voted = $wpdb->get_var($wpdb->prepare(
3718 + "SELECT COUNT(*) FROM {$report_table} WHERE user_id = %s AND poll_id = %d FOR UPDATE",
3719 + $user_id,
3720 + $poll_id
3721 + ));
3722 + break;
3723 + }
3724 +
3725 + if ($already_voted > 0) {
3726 + $wpdb->query("ROLLBACK");
3727 +
3728 + $res = $this->get_poll_by_id($poll_id);
3729 + $res['voted_status'] = false;
3730 + echo json_encode($res);
3731 + wp_die();
3732 + }
3733 + }
3734 +
3287 3735 $multi_answer_ids = array();
3288 3736 if ((is_array($answer_id) && !empty($answer_id)) && $allow_multi_vote) {
3289 3737 $multi_answer_ids = $answer_id;
3290 3738 $answer_changed_id = $answer_id[0];
@@ -3340,8 +3788,14 @@
3340 3788 '%d', // poll_id
3341 3789 '%s', // multi_answer_ids
3342 3790 )
3343 3791 );
3792 +
3793 + // Race condition fix
3794 + if ($limitusers > 0) {
3795 + $wpdb->query("COMMIT");
3796 + }
3797 +
3344 3798 // $answers = $this->get_answer_by_id($answer_changed_id);
3345 3799 if (!empty($options['notify_email_on'])) {
3346 3800 $notify_admin_email = $options['notify_email'];
3347 3801 $use_answered = '';
@@ -3353,9 +3807,9 @@
3353 3807 $headers .= "Content-Type: text/html; charset=UTF-8\r\n";
3354 3808 $attachment = array();
3355 3809 $mail_text = (
3356 3810 /* translators: 1: user answer variable, 2: poll title variable 3: anchor tag */
3357 - sprintf( __( "Someone's answer %1\$s in your %2\$s poll on %3\$s.", "poll-maker" ),
3811 + sprintf(esc_html__( "Someone's answer %1\$s in your %2\$s poll on %3\$s.", "poll-maker" ),
3358 3812 $use_answered,
3359 3813 '"' . $poll_title . '"',
3360 3814 "<a href='" . home_url() . "' target='_blank'>" . home_url() . "</a>"
3361 3815 ));
@@ -3425,11 +3879,49 @@
3425 3879
3426 3880
3427 3881 $res['styles']['result_message'] = ( isset( $res['styles']['result_message'] ) && $res['styles']['result_message'] != "" ) ? $this->ays_autoembed($this->replace_message_variables($res['styles']['result_message'], $message_data)) : "";
3428 3882 $res['styles']['hide_results_text'] = ( isset( $res['styles']['hide_results_text'] ) && $res['styles']['hide_results_text'] != "" ) ? $this->ays_autoembed($this->replace_message_variables($res['styles']['hide_results_text'], $message_data)) : "";
3429 -
3883 + $sensitive_fields = [
3884 + 'notify_email',
3885 + 'author',
3886 + 'poll_create_author',
3887 + 'mailchimp_list',
3888 + 'users_role'
3889 + ];
3890 + if (!current_user_can('manage_options')) {
3891 + foreach ($sensitive_fields as $field) {
3892 + if (isset($res['styles'][$field]) && $res['styles'][$field] != "") {
3893 + unset($res['styles'][$field]);
3894 + }
3895 + }
3896 + }
3430 3897 $res['styles']['poll_social_buttons_heading'] = ( isset( $res['styles']['poll_social_buttons_heading'] ) && $res['styles']['poll_social_buttons_heading'] != "" ) ? $this->ays_autoembed($res['styles']['poll_social_buttons_heading']) : "";
3431 3898 $res['check_admin_approval'] = $check_admin_approval;
3899 +
3900 + /**
3901 + * Fires after a user successfully submits a vote in Poll Maker.
3902 + *
3903 + * @since 1.0.0
3904 + *
3905 + * @param int $poll_id The poll ID.
3906 + */
3907 + if (has_action('ays_poll_maker_after_vote')) {
3908 + // Collect extra contextual data for hooks
3909 + $user_id = get_current_user_id();
3910 + $data = array_merge(
3911 + (array) $message_data,
3912 + array(
3913 + 'poll_id' => $poll_id,
3914 + 'answer_id' => $answer_id,
3915 + 'user_id' => $user_id,
3916 + )
3917 + );
3918 + do_action(
3919 + 'ays_poll_maker_after_vote',
3920 + $data
3921 + );
3922 + }
3923 +
3432 3924 ob_end_clean();
3433 3925 $ob_get_clean = ob_get_clean();
3434 3926 echo json_encode($res);
3435 3927 wp_die();
@@ -3701,10 +4193,10 @@
3701 4193 $poll = $this->get_poll_by_id($id);
3702 4194 $polls_options = $poll['styles'];
3703 4195
3704 4196
3705 - $poll_answer_sorting = isset($polls_options['result_sort_type']) && $polls_options['result_sort_type'] != "none" ? $polls_options['result_sort_type'] : "ASC";
3706 - $ans_sql = "SELECT * FROM ".$answ_table." WHERE poll_id =%d ORDER BY votes ".$poll_answer_sorting;
4197 + // $poll_answer_sorting = isset($polls_options['result_sort_type']) && $polls_options['result_sort_type'] != "none" ? $polls_options['result_sort_type'] : "ASC";
4198 + $ans_sql = "SELECT * FROM ".$answ_table." WHERE poll_id =%d ORDER BY votes DESC";
3707 4199 $poll_answers = $wpdb->get_results(
3708 4200 $wpdb->prepare( $ans_sql, $id),
3709 4201 'ARRAY_A'
3710 4202 );
@@ -3771,8 +4263,9 @@
3771 4263 }
3772 4264 foreach ($poll_answers as $ans_key => $ans_val) {
3773 4265 $poll_avatars_content = "";
3774 4266 $poll_user_avatars = "";
4267 + $answer_img = (isset( $ans_val['answer_img'] ) && $ans_val['answer_img'] != '') ? $ans_val['answer_img'] : "";
3775 4268 if(isset($ans_val["avatar"]) && !empty($ans_val["avatar"])){
3776 4269 $x = array_splice($ans_val["avatar"] , 0 ,$poll_avatars_count);
3777 4270 $poll_user_avatars = implode(" " , $x);
3778 4271
@@ -3780,22 +4273,26 @@
3780 4273 if($poll_show_avatars && $poll_user_avatars != ""){
3781 4274 $poll_avatars_content = '<div class="ays-user-count">
3782 4275 '.$poll_user_avatars.'
3783 4276 <div class="ays-users-profile-pics">
3784 - <img src="'.POLL_MAKER_AYS_PUBLIC_URL.'/images/more.png" width="24" height="24" class="ays-user-image-more" data-answer-id='.$ans_val["id"].'>
4277 + <img src="'.esc_url(POLL_MAKER_AYS_PUBLIC_URL).'/images/more.png" width="24" height="24" class="ays-user-image-more" data-answer-id='.$ans_val["id"].'>
3785 4278 </div>
3786 4279 </div>';
3787 4280 }
3788 4281 $perc_cont = '';
3789 4282 $percent = round($one_percent*intval($ans_val['votes']));
4283 + $perc_conta_hide_or_no = '';
3790 4284 if($poll_show_answer_perc){
3791 4285 if ($percent == 0) {
3792 - $perc_cont = '';
4286 + $perc_cont = '0 %';
4287 + $perc_conta_hide_or_no = '';
3793 4288 }else{
3794 4289 $perc_cont = $percent.' %';
4290 + $perc_conta_hide_or_no = '('.$percent.'%'.')';
3795 4291 }
3796 4292
3797 4293 }
4294 +
3798 4295 $answer_votes_count = '';
3799 4296 if($poll_show_votes_count){
3800 4297 $answer_votes_count = isset($ans_val['votes']) ? esc_attr($ans_val['votes']) : '';
3801 4298 }
@@ -3800,14 +4297,32 @@
3800 4297 $answer_votes_count = isset($ans_val['votes']) ? esc_attr($ans_val['votes']) : '';
3801 4298 }
3802 4299 switch ($polls['type']) {
3803 4300 case 'choosing':
4301 + $content .= "<div class='ays-poll-answers-box'>";
4302 + if($answer_img != ''){
4303 + $content .= "<div class='ays-poll-answers-image-box'>
4304 +
4305 + <img src='" . $answer_img ."' class='ays-poll-answers-current-image'>
4306 +
4307 + </div>";
4308 + }
4309 +
4310 + $content .= '<div class="ays-poll-answer-text-and-percent-box">';
3804 4311 $content .= '<div class="answer-title flex-apm">
3805 - <span class="answer-text">'.stripslashes($ans_val['answer']).'</span>
3806 - <span class="answer-votes">'.$answer_votes_count.'</span>
3807 - </div>
3808 - '.$poll_avatars_content.'
3809 - <div class="answer-percent" style="width: '.$percent.'%; background-color: '.$poll_main_color.'; color: '.$poll_bg_color.';">'.$perc_cont.'</div>';
4312 + <span class="answer-text">' . stripslashes($ans_val['answer']) . '</span>
4313 + <span class="answer-votes">'.$answer_votes_count.' '.$perc_conta_hide_or_no.'</span>
4314 + </div>
4315 + ' . $poll_avatars_content . '
4316 + <div class="answer-percent-res" style="width: ' . ($percent == 0 ? '10' : $percent) . '%;
4317 + border-radius: 20px;
4318 + background-color: ' . $poll_main_color . ';
4319 + color: ' . $poll_bg_color . ';
4320 + padding-left: 10px;
4321 + font-size: 15px;
4322 + text-align: left;">' . $perc_cont . '</div>';
4323 + $content .= '</div>';
4324 + $content .= '</div>';
3810 4325 break;
3811 4326
3812 4327 case 'rating':
3813 4328 switch ($polls['view_type']) {
@@ -3921,8 +4436,24 @@
3921 4436 $content .= "</div>";
3922 4437 return $content;
3923 4438 }
3924 4439
4440 + public function intToRoman($num) {
4441 + $map = array(
4442 + 1000 => 'M', 900 => 'CM', 500 => 'D', 400 => 'CD',
4443 + 100 => 'C', 90 => 'XC', 50 => 'L', 40 => 'XL',
4444 + 10 => 'X', 9 => 'IX', 5 => 'V', 4 => 'IV', 1 => 'I'
4445 + );
4446 + $roman = '';
4447 + foreach ($map as $value => $symbol) {
4448 + while ($num >= $value) {
4449 + $roman .= $symbol;
4450 + $num -= $value;
4451 + }
4452 + }
4453 + return $roman;
4454 + }
4455 +
3925 4456 public function ays_answer_numbering($numbering , $count){
3926 4457 $keyword_arr = array();
3927 4458 switch ($numbering) {
3928 4459 case '1.':
@@ -3968,8 +4499,15 @@
3968 4499 $columns[] = strtolower($value) . ")";
3969 4500 }
3970 4501 $keyword_arr = $columns;
3971 4502 break;
4503 + case 'VI.':
4504 + $columns = array();
4505 + for ($i = 1; $i <= $count; $i++) {
4506 + $columns[] = $this->intToRoman($i) . ".";
4507 + }
4508 + $keyword_arr = $columns;
4509 + break;
3972 4510 default:
3973 4511 break;
3974 4512 }
3975 4513 return $keyword_arr;
@@ -4189,11 +4727,11 @@
4189 4727
4190 4728 $poll_fields_placeholder_phone = (isset($settings_placeholders_texts['poll_fields_placeholder_phone']) && $settings_placeholders_texts['poll_fields_placeholder_phone'] != '') ? stripslashes( esc_attr( $settings_placeholders_texts['poll_fields_placeholder_phone'] ) ) : 'Phone';
4191 4729
4192 4730
4193 - $poll_fields_placeholder_name_text = $poll_fields_placeholder_name === 'Name' ? __('Name', "poll-maker") : $poll_fields_placeholder_name;
4194 - $poll_fields_placeholder_email_text = $poll_fields_placeholder_email === 'Email' ? __('Email', "poll-maker") : $poll_fields_placeholder_email;
4195 - $poll_fields_placeholder_phone_text = $poll_fields_placeholder_phone === 'Phone' ? __('Phone', "poll-maker") : $poll_fields_placeholder_phone;
4731 + $poll_fields_placeholder_name_text = $poll_fields_placeholder_name === 'Name' ?esc_html__('Name', "poll-maker") : $poll_fields_placeholder_name;
4732 + $poll_fields_placeholder_email_text = $poll_fields_placeholder_email === 'Email' ?esc_html__('Email', "poll-maker") : $poll_fields_placeholder_email;
4733 + $poll_fields_placeholder_phone_text = $poll_fields_placeholder_phone === 'Phone' ?esc_html__('Phone', "poll-maker") : $poll_fields_placeholder_phone;
4196 4734
4197 4735
4198 4736 $poll_fields_label_name = (isset($settings_placeholders_texts['poll_fields_label_name']) && $settings_placeholders_texts['poll_fields_label_name'] != '') ? stripslashes( esc_attr( $settings_placeholders_texts['poll_fields_label_name'] ) ) : 'Name';
4199 4737
@@ -4201,11 +4739,11 @@
4201 4739
4202 4740 $poll_fields_label_phone = (isset($settings_placeholders_texts['poll_fields_label_phone']) && $settings_placeholders_texts['poll_fields_label_phone'] != '') ? stripslashes( esc_attr( $settings_placeholders_texts['poll_fields_label_phone'] ) ) : 'Phone';
4203 4741
4204 4742
4205 - $poll_fields_label_name_text = $poll_fields_label_name === 'Name' ? __('Name', "poll-maker") : $poll_fields_label_name;
4206 - $poll_fields_label_email_text = $poll_fields_label_email === 'Email' ? __('Email', "poll-maker") : $poll_fields_label_email;
4207 - $poll_fields_label_phone_text = $poll_fields_label_phone === 'Phone' ? __('Phone', "poll-maker") : $poll_fields_label_phone;
4743 + $poll_fields_label_name_text = $poll_fields_label_name === 'Name' ?esc_html__('Name', "poll-maker") : $poll_fields_label_name;
4744 + $poll_fields_label_email_text = $poll_fields_label_email === 'Email' ?esc_html__('Email', "poll-maker") : $poll_fields_label_email;
4745 + $poll_fields_label_phone_text = $poll_fields_label_phone === 'Phone' ?esc_html__('Phone', "poll-maker") : $poll_fields_label_phone;
4208 4746
4209 4747 $texts = array(
4210 4748 'namePlaceholder' => $poll_fields_placeholder_name_text,
4211 4749 'emailPlaceholder' => $poll_fields_placeholder_email_text,
@@ -4273,5 +4811,5 @@
4273 4811 $id = isset($last_poll_sql['id']) && $last_poll_sql['id'] !== 0 ? absint(intval($last_poll_sql['id'])) : "";
4274 4812
4275 4813 return $id;
4276 4814 }
4277 -}
4815 +}