PluginProbe
Repeater Fields for Gravity Forms / 3.2.2
Repeater Fields for Gravity Forms v3.2.2
3.2.2 3.2.1 3.2.0 3.1.1 3.1.0 3.0.4 3.0.3 3.0.2 3.0.1 3.0.0 2.5.1 2.5.0 2.4.6 trunk 2.0.5 2.0.9 2.1.0 2.3.2 2.3.7 2.4.1 2.4.3 2.4.4 2.4.5
← All changes | fields/repeater_field.php +472 -109 2.4.5 → 3.2.2 View file →
@@ -1,7 +1,7 @@
1 1 <?php
2 2 // If Gravity Forms isn't loaded, bail.
3 -if (! class_exists('GFForms')) {
3 +if (!class_exists('GFForms')) {
4 4 die();
5 5 }
6 6 /**
7 7 * Class GF_Field_Phone
@@ -40,9 +40,9 @@
40 40 public function get_form_editor_button()
41 41 {
42 42 return array(
43 43 'group' => 'advanced_fields',
44 - 'text' => $this->get_form_editor_field_title()
44 + 'text' => $this->get_form_editor_field_title()
45 45 );
46 46 }
47 47 /**
48 48 * Defines the field settings available within the field editor.
@@ -114,24 +114,58 @@
114 114 {
115 115 if (is_array($value)) {
116 116 $value = '';
117 117 }
118 + $id = intval($this->id);
119 +
120 + // If resuming draft submission via Save & Continue and $value doesn't have saved_values,
121 + // attempt to restore from draft $entry if available
122 + if (empty($value) || (is_string($value) && strpos($value, 'saved_values') === false)) {
123 + if (!empty($entry) && is_array($entry) && !empty($entry[$id])) {
124 + $entry_data = maybe_unserialize($entry[$id]);
125 + if (is_array($entry_data) && !empty($entry_data)) {
126 + $decoded_value = !empty($value) ? json_decode($value, true) : array();
127 + if (!is_array($decoded_value)) {
128 + $decoded_value = array();
129 + }
130 + $row_ids = array_keys($entry_data);
131 + $decoded_value['count'] = count($row_ids);
132 + $decoded_value['id'] = $row_ids;
133 + $saved_rows = array();
134 + foreach ($entry_data as $row_id => $row_inputs) {
135 + if (is_array($row_inputs)) {
136 + foreach ($row_inputs as $in_name => $in_val) {
137 + if (is_array($in_val)) {
138 + foreach ($in_val as $sub_k => $sub_v) {
139 + $saved_rows[$row_id]['input_' . str_replace('.', '_', $sub_k) . '__' . $row_id] = $sub_v;
140 + }
141 + } else {
142 + $saved_rows[$row_id][$in_name] = $in_val;
143 + }
144 + }
145 + }
146 + }
147 + $decoded_value['saved_values'] = $saved_rows;
148 + $value = wp_json_encode($decoded_value);
149 + }
150 + }
151 + }
152 +
118 153 $is_entry_detail = $this->is_entry_detail();
119 - $is_form_editor = $this->is_form_editor();
120 - $form_id = $form['id'];
121 - $id = intval($this->id);
154 + $is_form_editor = $this->is_form_editor();
155 + $form_id = $form['id'];
122 156 $field_id = $is_entry_detail || $is_form_editor || $form_id == 0 ? "input_$id" : 'input_' . $form_id . "_$id";
123 - $size = $this->size;
157 + $size = $this->size;
124 158 $disabled_text = $is_form_editor ? "disabled='disabled'" : '';
125 - $class_suffix = $is_entry_detail ? '_admin' : '';
126 - $class = $size . $class_suffix . " gf-field-repeater-data hidden";
127 - $class = esc_attr($class);
159 + $class_suffix = $is_entry_detail ? '_admin' : '';
160 + $class = $size . $class_suffix . " gf-field-repeater-data hidden";
161 + $class = esc_attr($class);
128 162 $instruction_div = '';
129 - $html_input_type = 'hidden';
163 + $html_input_type = 'hidden';
130 164 $placeholder_attribute = $this->get_field_placeholder_attribute();
131 - $required_attribute = $this->isRequired ? 'aria-required="true"' : '';
132 - $invalid_attribute = $this->failed_validation ? 'aria-invalid="true"' : 'aria-invalid="false"';
133 - $aria_describedby = $this->get_aria_describedby();
165 + $required_attribute = $this->isRequired ? 'aria-required="true"' : '';
166 + $invalid_attribute = $this->failed_validation ? 'aria-invalid="true"' : 'aria-invalid="false"';
167 + $aria_describedby = $this->get_aria_describedby();
134 168 $tabindex = $this->get_tabindex();
135 169 $repeater_add_button = $this->field_repeater_end_text;
136 170 if ($repeater_add_button == "") {
137 171 $repeater_add_button = esc_attr__("Add more", "gravityforms-repeater");
@@ -145,10 +179,10 @@
145 179 $limit = 9999;
146 180 }
147 181 $limit = apply_filters("yeeaddons_gf_repeater_limit", 5, $limit);
148 182 $initial_rows = apply_filters("yeeaddons_gf_repeater_initial_rows", 1, $initial_rows);
149 - $input = "<input data-initial_rows_map_check='" . $this->repeater_initial_rows_map . "' data-initial_rows_map='input_{$form_id}_" . $this->repeater_initial_rows_map . "' data-map_id='field_" . $form_id . "_" . $id . "' name='input_{$id}' id='{$field_id}' type='{$html_input_type}' value='{$value}' class='{$class}' {$tabindex} {$placeholder_attribute} {$required_attribute} {$invalid_attribute} {$disabled_text}/>";
150 - $html = '<div data-initial_rows_map_check="' . $this->repeater_initial_rows_map . '" class="repeater-field-warp-item-data" data-initial_rows="' . $initial_rows . '" data-limit="' . $limit . '" data-initial_rows_map="input_' . $form_id . '_' . $this->repeater_initial_rows_map . '" data-map_id="field_' . $form_id . '_' . $id . '">
183 + $input = "<input data-initial_rows_map_check='" . esc_attr($this->repeater_initial_rows_map) . "' data-initial_rows_map='input_{$form_id}_" . esc_attr($this->repeater_initial_rows_map) . "' data-map_id='field_" . $form_id . "_" . $id . "' name='input_{$id}' id='{$field_id}' type='{$html_input_type}' value='" . esc_attr($value) . "' class='{$class}' {$tabindex} {$placeholder_attribute} {$required_attribute} {$invalid_attribute} {$disabled_text}/>";
184 + $html = '<div data-initial_rows_map_check="' . esc_attr($this->repeater_initial_rows_map) . '" class="repeater-field-warp-item-data" data-initial_rows="' . $initial_rows . '" data-limit="' . $limit . '" data-initial_rows_map="input_' . $form_id . '_' . esc_attr($this->repeater_initial_rows_map) . '" data-map_id="field_' . $form_id . '_' . $id . '">
151 185 <div class="repeater-field-warp-item">
152 186 </div>
153 187 <div class="repeater-field-footer"><a href="#"" class="gf-repeater-field-button-add" >' . $repeater_add_button . '</a></div>
154 188 ' . $input . '
@@ -160,8 +194,72 @@
160 194 } else {
161 195 return sprintf("<div class='ginput_container'>%s</div>", $html);
162 196 }
163 197 }
198 + public static function save_draft_submission_values($submitted_values, $form)
199 + {
200 + if (empty($form['fields']) || !is_array($form['fields'])) {
201 + return $submitted_values;
202 + }
203 +
204 + foreach ($form['fields'] as $field) {
205 + if ($field->type !== 'repeater_end') {
206 + continue;
207 + }
208 +
209 + $raw_value = rgar($submitted_values, $field->id);
210 + if (empty($raw_value)) {
211 + $raw_value = rgpost('input_' . $field->id);
212 + }
213 +
214 + if (empty($raw_value)) {
215 + continue;
216 + }
217 +
218 + $repeater_data = is_array($raw_value) ? $raw_value : json_decode($raw_value, true);
219 + if (!is_array($repeater_data) || empty($repeater_data['id']) || !is_array($repeater_data['id'])) {
220 + continue;
221 + }
222 +
223 + // Capture all $_POST values for each repeater row
224 + $saved_rows = array();
225 + foreach ($repeater_data['id'] as $id_rand) {
226 + $row_data = array();
227 + foreach ($_POST as $post_key => $post_val) {
228 + if (strpos($post_key, '__' . $id_rand) !== false) {
229 + $row_data[$post_key] = wp_unslash($post_val);
230 + }
231 + }
232 +
233 + // Also check if any file was uploaded in this row
234 + $transient_keys = array();
235 + $unique_id = rgpost('gform_unique_id');
236 + if (!empty($unique_id)) {
237 + $transient_keys[] = 'gf_repeater_files_' . $unique_id;
238 + }
239 + $transient_keys[] = 'gf_repeater_files_' . $form['id'];
240 + $transient_keys[] = 'gf_repeater_files_1';
241 +
242 + foreach ($transient_keys as $t_key) {
243 + $transient_files = get_transient($t_key);
244 + if (is_array($transient_files)) {
245 + foreach ($transient_files as $tk => $tv) {
246 + if (strpos($tk, '__' . $id_rand) !== false && !empty($tv)) {
247 + $row_data[$tk] = $tv;
248 + }
249 + }
250 + }
251 + }
252 +
253 + $saved_rows[$id_rand] = $row_data;
254 + }
255 +
256 + $repeater_data['saved_values'] = $saved_rows;
257 + $submitted_values[$field->id] = wp_json_encode($repeater_data);
258 + }
259 +
260 + return $submitted_values;
261 + }
164 262 public static function remove_validation($form)
165 263 {
166 264 $zo = false;
167 265 $zo_datas = array();
@@ -179,8 +277,9 @@
179 277 if (!isset($field->repeater_validate)) {
180 278 $field->repeater_validate = array("isRequired" => $field->isRequired);
181 279 }
182 280 $field->isRequired = false;
281 + $field->validateState = false;
183 282 }
184 283 }
185 284 return $form;
186 285 }
@@ -198,8 +297,37 @@
198 297 }
199 298 }
200 299 }
201 300 if (isset($datas["id"]) && is_array($datas["id"])) {
301 + // Check if file upload is attempted without the Pro version activated
302 + if (!class_exists('Yeeaddons_Upgrade_GF_Repeater_Plugin')) {
303 + $is_fileupload_attempt = false;
304 + foreach ($datas["id"] as $id) {
305 + foreach ($datas["fields"] as $field) {
306 + if ($field == "") {
307 + continue;
308 + }
309 + $field = str_replace('[]', '', $field);
310 + $input_name = $field . "__" . $id;
311 + // Standard file upload
312 + if (isset($_FILES[$input_name]) && !empty($_FILES[$input_name]['name']) && (is_array($_FILES[$input_name]['name']) ? !empty(array_filter($_FILES[$input_name]['name'])) : true)) {
313 + $is_fileupload_attempt = true;
314 + break 2;
315 + }
316 + // Multi-file upload (Ajax/plupload)
317 + if (strpos($field, 'gform_multifile_upload_') === 0 && !empty($_POST[$input_name])) {
318 + $is_fileupload_attempt = true;
319 + break 2;
320 + }
321 + }
322 + }
323 + if ($is_fileupload_attempt) {
324 + $this->failed_validation = true;
325 + $this->validation_message = esc_html__('File upload in repeater is only supported in the Pro version.', 'repeater-for-gravity-forms');
326 + return;
327 + }
328 + }
329 +
202 330 foreach ($datas["id"] as $id) {
203 331 foreach ($datas["fields"] as $field) {
204 332 if ($field == "") {
205 333 continue;
@@ -210,9 +338,9 @@
210 338 switch ($list_fields_validate[$field]) {
211 339 case "name":
212 340 $first_name = rgpost($field . "_3__" . $id);
213 341 $last_name = rgpost($field . "_6__" . $id);
214 - if (empty($first_name) || empty($last_name)) {
342 + if (empty($first_name) || empty($last_name)) {
215 343 $failedValidation = true;
216 344 }
217 345 break;
218 346 case 'address':
@@ -227,17 +355,27 @@
227 355 } else {
228 356 $failedValidation = true;
229 357 }
230 358 break;
359 + case 'radio':
360 + if (rgblank($getInputData)) {
361 + $failedValidation = true;
362 + } elseif ($getInputData === 'gf_other_choice') {
363 + $other_val = rgpost($field . "_other__" . $id);
364 + if (rgblank($other_val)) {
365 + $failedValidation = true;
366 + }
367 + }
368 + break;
231 369 default:
232 370 if (is_array($getInputData)) {
233 371 foreach ($getInputData as $vl) {
234 - if (empty($vl)) {
372 + if (rgblank($vl)) {
235 373 $failedValidation = true;
236 374 }
237 375 }
238 376 } else {
239 - if (empty($getInputData)) {
377 + if (rgblank($getInputData)) {
240 378 $failedValidation = true;
241 379 }
242 380 }
243 381 break;
@@ -245,9 +383,9 @@
245 383 }
246 384 }
247 385 }
248 386 if ($failedValidation) {
249 - $this->failed_validation = true;
387 + $this->failed_validation = true;
250 388 if ($this->errorMessage) {
251 389 $this->validation_message = $this->errorMessage;
252 390 } else {
253 391 $this->validation_message = esc_html__('This field is required.', 'gravityforms');
@@ -253,9 +391,9 @@
253 391 $this->validation_message = esc_html__('This field is required.', 'gravityforms');
254 392 }
255 393 return;
256 394 } else {
257 - $this->failed_validation = false;
395 + $this->failed_validation = false;
258 396 }
259 397 }
260 398 }
261 399 function custom_validation($form)
@@ -263,10 +401,8 @@
263 401 $dataRepeater = array();
264 402 $zo = false;
265 403 $zo_datas = array();
266 404 foreach ($form["fields"] as $field) {
267 - var_dump($field);
268 - die();
269 405 $type = $field->type;
270 406 if ($type == "repeater_start") {
271 407 $zo = true;
272 408 continue;
@@ -271,9 +407,8 @@
271 407 $zo = true;
272 408 continue;
273 409 }
274 410 if ($zo) {
275 - var_dump($field);
276 411 $zo_datas[$field->id] = array("isRequired" => $field->isRequired);
277 412 $field->isRequired = false;
278 413 }
279 414 if ($type == "repeater_end") {
@@ -345,17 +480,25 @@
345 480 public function get_value_save_entry($value, $form, $input_name, $lead_id, $lead)
346 481 {
347 482 $this->lead_id = $lead_id;
348 483 $datas = json_decode($value, true);
349 - //var_dump($value);
484 + if (!is_array($datas) || !isset($datas["id"]) || !is_array($datas["id"])) {
485 + return maybe_serialize(array());
486 + }
487 +
350 488 $values = array();
351 489 $form_id = $this->formId;
352 490 $get_form = GFFormsModel::get_form_meta_by_id($form_id);
353 491 $form = $get_form[0];
354 492 $fields = array();
355 - foreach ($datas["fields"] as $f) {
356 - $datas_f = explode(".", $f);
357 - $fields[] = $datas_f[0];
493 + if (isset($datas["fields"]) && is_array($datas["fields"])) {
494 + foreach ($datas["fields"] as $f) {
495 + if (!is_string($f) || empty($f)) {
496 + continue;
497 + }
498 + $datas_f = explode(".", $f);
499 + $fields[] = $datas_f[0];
500 + }
358 501 }
359 502 $fields = array_unique($fields);
360 503 foreach ($datas["id"] as $id_rand) {
361 504 $datas_step = array();
@@ -366,9 +509,17 @@
366 509 $getInputData = array();
367 510 foreach ($inputs as $child_input) {
368 511 $getInputName = "input_" . $child_input["id"] . "__" . $id_rand;
369 512 $vl = rgpost(str_replace('.', '_', strval($getInputName)));
370 - if ($vl != "") {
513 + if ($vl !== "" && $vl !== false && $vl !== null) {
514 + $child_field_type = $this->get_type($form, "input_" . $child_input["id"], $form_id);
515 + if (is_string($vl)) {
516 + if ($child_field_type === 'textarea') {
517 + $vl = sanitize_textarea_field($vl);
518 + } else {
519 + $vl = sanitize_text_field($vl);
520 + }
521 + }
371 522 $getInputData[$child_input["id"]] = $vl;
372 523 }
373 524 }
374 525 $datas_step[$getInputName] = $getInputData;
@@ -373,16 +524,89 @@
373 524 }
374 525 $datas_step[$getInputName] = $getInputData;
375 526 } else {
376 527 $getInputName = $field . "__" . $id_rand;
377 - if (isset($_FILES[$getInputName])) {
378 - $datas_step[$getInputName] = apply_filters("yeeaddons_gf_repeater_file", "Upgrade to pro version", $form_id, $_FILES[$getInputName]);
379 - } else if (isset($_POST[$getInputName])) {
380 - $datas_step[$getInputName] = rgpost(str_replace('.', '_', strval($getInputName)));
381 - } else {
382 - $getInputData = rgpost(str_replace('.', '_', strval($getInputName)));
383 - $datas_step[$getInputName] = $getInputData;
528 + $saved_url = '';
529 +
530 + // 1. Check transient saved across multi-step pages by gform_unique_id or form_id
531 + $unique_id = rgpost('gform_unique_id');
532 + $transient_keys = array();
533 + if (!empty($unique_id)) {
534 + $transient_keys[] = 'gf_repeater_files_' . $unique_id;
384 535 }
536 + $transient_keys[] = 'gf_repeater_files_' . $form_id;
537 + $transient_keys[] = 'gf_repeater_files_1';
538 +
539 + foreach ($transient_keys as $t_key) {
540 + $transient_files = get_transient($t_key);
541 + if (is_array($transient_files)) {
542 + if (!empty($transient_files[$getInputName])) {
543 + $saved_url = $transient_files[$getInputName];
544 + break;
545 + }
546 + // Also check alternative key name format
547 + foreach ($transient_files as $tk => $tv) {
548 + if (strpos($tk, '__' . $id_rand) !== false && !empty($tv)) {
549 + $clean_f = str_replace('gform_multifile_upload_' . $form_id . '_', '', $field);
550 + $clean_f = str_replace('input_', '', $clean_f);
551 + if (strpos($tk, '_' . $clean_f . '__') !== false || strpos($tk, 'input_' . $clean_f . '__') !== false) {
552 + $saved_url = $tv;
553 + break 2;
554 + }
555 + }
556 + }
557 + }
558 + }
559 +
560 +
561 + // 2. Check if $_POST contains a direct URL
562 + if (empty($saved_url)) {
563 + $post_val = rgpost(str_replace('.', '_', strval($getInputName)));
564 + if (!empty($post_val) && is_string($post_val) && strpos($post_val, 'http') === 0) {
565 + $saved_url = $post_val;
566 + }
567 + }
568 +
569 + // 3. Check gform_uploaded_files (GF native temp file store)
570 + if (empty($saved_url)) {
571 + $uploaded_files_json = rgpost('gform_uploaded_files');
572 + if (!empty($uploaded_files_json)) {
573 + $uploaded_files = json_decode(stripslashes($uploaded_files_json), true);
574 + if (is_array($uploaded_files) && isset($uploaded_files[$getInputName])) {
575 + $file_info = $uploaded_files[$getInputName];
576 + if (is_string($file_info) && strpos($file_info, 'http') === 0) {
577 + $saved_url = $file_info;
578 + }
579 + }
580 + }
581 + }
582 +
583 + // 4. Check $_FILES if uploaded on the current submit step
584 + if (empty($saved_url) && isset($_FILES[$getInputName]) && !empty($_FILES[$getInputName]['name']) && (is_array($_FILES[$getInputName]['name']) ? !empty(array_filter($_FILES[$getInputName]['name'])) : ($_FILES[$getInputName]['error'] === UPLOAD_ERR_OK))) {
585 + $res = apply_filters("yeeaddons_gf_repeater_file", "", $form_id, $_FILES[$getInputName]);
586 + if ($res && $res !== "Upgrade to pro version") {
587 + $saved_url = $res;
588 + }
589 + }
590 +
591 + // 5. Fallback to $_POST value if available
592 + if (empty($saved_url)) {
593 + $saved_url = rgpost(str_replace('.', '_', strval($getInputName)));
594 + }
595 +
596 + // Sanitize theo kiểu trường trước khi lưu vào DB
597 + $field_type = $this->get_type($form, $field, $form_id);
598 + if (is_string($saved_url)) {
599 + if ($field_type === 'textarea') {
600 + $saved_url = sanitize_textarea_field($saved_url);
601 + } elseif ($field_type === 'fileupload' || filter_var($saved_url, FILTER_VALIDATE_URL) !== false) {
602 + $saved_url = esc_url_raw($saved_url);
603 + } else {
604 + $saved_url = sanitize_text_field($saved_url);
605 + }
606 + }
607 +
608 + $datas_step[$getInputName] = $saved_url;
385 609 }
386 610 }
387 611 $values[$id_rand] = $datas_step;
388 612 }
@@ -390,9 +614,9 @@
390 614 }
391 615 public function upload_file($form_id, $file)
392 616 {
393 617 $target = GFFormsModel::get_file_upload_path($form_id, $file['name']);
394 - if (! $target) {
618 + if (!$target) {
395 619 return 'FAILED (Upload folder could not be created.)';
396 620 }
397 621 if (move_uploaded_file($file['tmp_name'], $target['path'])) {
398 622 $this->set_permissions($target['path']);
@@ -426,14 +650,20 @@
426 650 $dataArray = GFFormsModel::unserialize($value);
427 651 $get_form = GFFormsModel::get_form_meta_by_id($form_id);
428 652 $form = $get_form[0];
429 653 if (isset($_GET['lid'])) {
430 - $result = GFAPI::get_entry($_GET['lid']);
654 + $result = GFAPI::get_entry(absint($_GET['lid']));
431 655 } else {
432 656 $table = $wpdb->prefix . "gf_entry";
433 657 $mylink = $wpdb->get_row("SELECT id FROM $table ORDER BY id DESC");
434 - $result = GFAPI::get_entry($mylink->id);
658 + $result = ($mylink && isset($mylink->id)) ? GFAPI::get_entry($mylink->id) : array();
435 659 }
660 + if (!is_array($result) || is_wp_error($result)) {
661 + $result = array();
662 + }
663 + if (!is_array($dataArray) || empty($dataArray)) {
664 + return '';
665 + }
436 666 if ($format === 'html') {
437 667 $html = '<ol>';
438 668 foreach ($dataArray as $step_datas) {
439 669 $html .= '<li><ul>';
@@ -438,64 +668,132 @@
438 668 foreach ($dataArray as $step_datas) {
439 669 $html .= '<li><ul>';
440 670 foreach ($step_datas as $name => $vl) {
441 671 $type = $this->get_type($form, $name, $form_id);
442 - $lb = $this->get_field_label($form, $name, $type, false, $form_id);
672 + $lb = $this->get_custom_field_label($form, $name, $type, false, $form_id);
443 673 if (is_array($vl)) {
444 674 switch ($type) {
445 675 case "address":
446 676 $vl_data = "";
447 677 foreach ($vl as $k => $v) {
448 - $child_lb = $this->get_field_label($form, "input_" . $k, $type, true);
449 - $vl_data .= $child_lb . ": " . $v . "<br>";
678 + $child_lb = $this->get_custom_field_label($form, "input_" . $k, $type, true);
679 + $vl_data .= esc_html($child_lb) . ": " . esc_html($v) . "<br>";
450 680 }
451 - $html .= '<li>' . $lb . ": <br>" . $vl_data . "</li>";
681 + $html .= '<li>' . esc_html($lb) . ": <br>" . $vl_data . "</li>";
452 682 break;
453 683 default:
454 - $vl_data = implode(", ", $vl);
455 - $html .= '<li>' . $lb . ": " . $vl_data . "</li>";
684 + $vl_data = implode(", ", array_map('esc_html', $vl));
685 + $html .= '<li>' . esc_html($lb) . ": " . $vl_data . "</li>";
456 686 break;
457 687 }
458 688 } else {
459 689 $vl_data = $vl;
690 +
691 + // Helper functions kiểm tra và render file/hình ảnh
692 + $encode_url = function ($url) {
693 + return preg_replace_callback('/[^\x20-\x7E]/u', function ($match) {
694 + return rawurlencode($match[0]);
695 + }, trim($url));
696 + };
697 +
698 + $is_valid_url = function ($url) use ($encode_url) {
699 + if (empty($url))
700 + return false;
701 + $encoded = $encode_url($url);
702 + return filter_var($encoded, FILTER_VALIDATE_URL) !== false;
703 + };
704 +
705 + $is_image_url = function ($url) {
706 + if (!is_string($url) || empty($url))
707 + return false;
708 + $clean_path = parse_url($url, PHP_URL_PATH);
709 + if (!$clean_path) {
710 + $clean_path = $url;
711 + }
712 + $ext = strtolower(pathinfo($clean_path, PATHINFO_EXTENSION));
713 + return in_array($ext, array('jpg', 'jpeg', 'png', 'gif', 'webp', 'svg', 'bmp', 'ico', 'avif', 'heic'), true);
714 + };
715 +
716 + $render_file_or_image = function ($file_url, $display_name = '') use ($is_image_url) {
717 + $file_url = trim($file_url);
718 + if (empty($file_url))
719 + return '';
720 + $filename = !empty($display_name) ? $display_name : basename($file_url);
721 +
722 + if ($is_image_url($file_url)) {
723 + return '<a href="' . esc_url($file_url) . '" target="_blank" class="repeater-image-preview" style="display:inline-block; margin: 4px 6px 4px 0;">'
724 + . '<img src="' . esc_url($file_url) . '" alt="' . esc_attr($filename) . '" style="max-width: 150px; max-height: 150px; object-fit: contain; border-radius: 4px; border: 1px solid #e2e8f0; display: inline-block; vertical-align: middle;" />'
725 + . '</a>';
726 + } else {
727 + return '<a href="' . esc_url($file_url) . '" download>' . esc_html($filename) . '</a>';
728 + }
729 + };
730 +
460 731 switch ($type) {
461 732 case "fileupload":
462 - if ($vl_data == "Upgrade to pro version") {
463 - $html .= '<li>' . $lb . ": " . $vl_data . "</li>";
464 - } else {
465 - if (filter_var($vl_data, FILTER_VALIDATE_URL) === FALSE) {
466 - $content = array();
467 - $main_name = explode("__", $name);
468 - $main_name = explode("_", $main_name[0]);
469 - if (isset($main_name[4])) {
470 - $main_name_id = $main_name[4];
471 - } else {
472 - $main_name_id = $main_name[1];
473 - }
474 - $vl_data = explode(",", $vl_data);
475 - if (isset($result[$main_name_id])) {
476 - $data_uploads = json_decode($result[$main_name_id], true);
477 - foreach ($vl_data as $n) {
478 - $n = sanitize_file_name($n);
479 - foreach ($data_uploads as $name) {
480 - $name_s = explode(".", $n);
481 - $name_s = $name_s[0];
482 - $re = "/" . $name_s . "\.|" . $name_s . "[\d]\./";
483 - if (preg_match($re, $name)) {
484 - $content[] = '<a href="' . $name . '" download>' . $n . "</a> ";
485 - break;
486 - }
487 - }
733 + if ($vl_data === "Upgrade to pro version") {
734 + $html .= '<li>' . esc_html($lb) . ": " . esc_html($vl_data) . "</li>";
735 + break;
736 + }
737 +
738 + // Tách chuỗi theo dấu phẩy phòng trường hợp có nhiều file
739 + $parts = array_filter(array_map('trim', explode(",", $vl_data)));
740 + $content = array();
741 +
742 + // TRƯỜNG HỢP 1: Tất cả các phần tử đều là URL hợp lệ
743 + $all_are_urls = !empty($parts);
744 + foreach ($parts as $part) {
745 + if (!$is_valid_url($part)) {
746 + $all_are_urls = false;
747 + break;
748 + }
749 + }
750 +
751 + if ($all_are_urls) {
752 + foreach ($parts as $part) {
753 + $filename = basename($part);
754 + $content[] = $render_file_or_image($part, $filename);
755 + }
756 + $html .= '<li>' . esc_html($lb) . ': ' . implode(" ", $content) . "</li>";
757 + break;
758 + }
759 +
760 + // TRƯỜNG HỢP 2: Chuỗi chứa tên file hoặc URL không hợp lệ -> Tìm trong $result
761 + $main_name = explode("__", $name);
762 + $main_name = explode("_", $main_name[0]);
763 + $main_name_id = isset($main_name[4]) ? $main_name[4] : (isset($main_name[1]) ? $main_name[1] : null);
764 +
765 + if ($main_name_id && isset($result[$main_name_id])) {
766 + $raw_uploads = $result[$main_name_id];
767 + $data_uploads = is_array($raw_uploads) ? $raw_uploads : json_decode($raw_uploads, true);
768 +
769 + if (!is_array($data_uploads)) {
770 + $data_uploads = array_filter(array_map('trim', explode(",", (string) $raw_uploads)));
771 + }
772 +
773 + foreach ($parts as $n) {
774 + $clean_n = sanitize_file_name($n);
775 + $name_s = preg_quote(pathinfo($clean_n, PATHINFO_FILENAME), '/');
776 +
777 + foreach ($data_uploads as $upload_file) {
778 + // Regex khớp chính xác tên file gốc hoặc tên file có đánh số thứ tự
779 + if (preg_match('/' . $name_s . '(\d+)?\./i', $upload_file)) {
780 + $content[] = $render_file_or_image($upload_file, $clean_n);
781 + break;
488 782 }
489 783 }
490 - $html .= '<li>' . $lb . ': ' . implode(" | ", $content) . "</li>";
491 - } else {
492 - $html .= '<li>' . $lb . ': <a href="' . $vl_data . '" download>' . $vl_data . "</a></li>";
493 784 }
494 785 }
786 +
787 + $html .= '<li>' . esc_html($lb) . ': ' . (!empty($content) ? implode(" ", $content) : esc_html($vl_data)) . "</li>";
495 788 break;
789 +
496 790 default:
497 - $html .= '<li>' . $lb . ": " . $vl_data . "</li>";
791 + if (is_string($vl_data) && $is_valid_url($vl_data) && $is_image_url($vl_data)) {
792 + $html .= '<li>' . esc_html($lb) . ': ' . $render_file_or_image($vl_data) . "</li>";
793 + } else {
794 + $html .= '<li>' . esc_html($lb) . ": " . esc_html($vl_data) . "</li>";
795 + }
498 796 break;
499 797 }
500 798 }
501 799 }
@@ -500,30 +798,35 @@
500 798 }
501 799 }
502 800 $html .= '</ul></li>';
503 801 }
504 - $html .= '<ol>';
802 + $html .= '</ol>';
505 803 $html = apply_filters("yeeadons_gravity_forms_repeater_html", $html, $dataArray, $form);
506 804 return $html;
507 805 } else {
508 - $html = '';
806 + $text = '';
509 807 foreach ($dataArray as $step_datas) {
808 + if (!is_array($step_datas)) {
809 + continue;
810 + }
510 811 foreach ($step_datas as $name => $vl) {
511 812 $type = $this->get_type($form, $name, $form_id);
512 - $lb = $this->get_field_label($form, $name, $type, false, $form_id);
813 + $lb = $this->get_custom_field_label($form, $name, $type, false, $form_id);
814 + $lb = esc_html($lb);
815 +
513 816 if (is_array($vl)) {
514 817 switch ($type) {
515 818 case "address":
516 819 $vl_data = "";
517 820 foreach ($vl as $k => $v) {
518 - $child_lb = $this->get_field_label($form, "input_" . $k, $type, true);
519 - $vl_data .= $child_lb . ": " . $v . "\n";
821 + $child_lb = $this->get_custom_field_label($form, "input_" . $k, $type, true);
822 + $vl_data .= esc_html($child_lb) . ": " . esc_html($v) . "\n";
520 823 }
521 - $html .= $lb . " : " . $vl_data . "\n";
824 + $text .= $lb . " : \n" . $vl_data;
522 825 break;
523 826 default:
524 - $vl_data = implode(", ", $vl);
525 - $html .= $lb . ": " . $vl_data . "\n";
827 + $vl_escaped = array_map('esc_html', $vl);
828 + $text .= $lb . ": " . implode(", ", $vl_escaped) . "\n";
526 829 break;
527 830 }
528 831 } else {
529 832 $vl_data = $vl;
@@ -528,44 +831,66 @@
528 831 } else {
529 832 $vl_data = $vl;
530 833 switch ($type) {
531 834 case "fileupload":
532 - if (filter_var($vl_data, FILTER_VALIDATE_URL) === FALSE) {
533 - $content = array();
835 + if ($vl_data === "Upgrade to pro version") {
836 + $text .= $lb . ": " . esc_html($vl_data) . "\n";
837 + break;
838 + }
839 + $parts = array_filter(array_map('trim', explode(",", $vl_data)));
840 + $content = array();
841 +
842 + $all_are_urls = !empty($parts);
843 + foreach ($parts as $part) {
844 + if (filter_var($part, FILTER_VALIDATE_URL) === false) {
845 + $all_are_urls = false;
846 + break;
847 + }
848 + }
849 +
850 + if ($all_are_urls) {
851 + foreach ($parts as $part) {
852 + $filename = basename($part);
853 + $content[] = esc_html($filename) . ' (' . esc_url($part) . ')';
854 + }
855 + $text .= $lb . ': ' . implode(", ", $content) . "\n";
856 + } else {
534 857 $main_name = explode("__", $name);
535 858 $main_name = explode("_", $main_name[0]);
536 - $main_name_id = $main_name[4];
537 - $vl_data = explode(",", $vl_data);
538 - if (isset($result[$main_name_id])) {
539 - $data_uploads = json_decode($result[$main_name_id], true);
540 - foreach ($vl_data as $n) {
541 - $n = sanitize_file_name($n);
542 - foreach ($data_uploads as $name) {
543 - $name_s = explode(".", $n);
544 - $name_s = $name_s[0];
545 - $re = "/" . $name_s . "\.|" . $name_s . "[\d]\./";
546 - if (preg_match($re, $name)) {
547 - $content[] = '<a href="' . $name . '" download>' . $n . "</a> ";
859 + $main_name_id = isset($main_name[4]) ? $main_name[4] : (isset($main_name[1]) ? $main_name[1] : null);
860 +
861 + if ($main_name_id && isset($result[$main_name_id])) {
862 + $raw_uploads = $result[$main_name_id];
863 + $data_uploads = is_array($raw_uploads) ? $raw_uploads : json_decode($raw_uploads, true);
864 + if (!is_array($data_uploads)) {
865 + $data_uploads = array_filter(array_map('trim', explode(",", (string)$raw_uploads)));
866 + }
867 +
868 + foreach ($parts as $n) {
869 + $clean_n = sanitize_file_name($n);
870 + $name_s = preg_quote(pathinfo($clean_n, PATHINFO_FILENAME), '/');
871 + foreach ($data_uploads as $upload_file) {
872 + if (preg_match('/' . $name_s . '(\d+)?\./i', $upload_file)) {
873 + $content[] = esc_html($clean_n) . ' (' . esc_url($upload_file) . ')';
548 874 break;
549 875 }
550 876 }
551 877 }
552 878 }
553 - $html .= $lb . ': ' . implode(" | ", $content) . "\n";
554 - } else {
555 - $html .= $lb . ':' . $vl_data . "\n";
879 + $text .= $lb . ': ' . (!empty($content) ? implode(", ", $content) : esc_html($vl_data)) . "\n";
556 880 }
557 881 break;
882 +
558 883 default:
559 - $html .= $lb . ": " . $vl_data . "\n";
884 + $text .= $lb . ": " . esc_html($vl_data) . "\n";
560 885 break;
561 886 }
562 887 }
563 888 }
564 - $html .= "\n";
889 + $text .= "\n";
565 890 }
566 - $html = apply_filters("yeeadons_gravity_forms_repeater_text", $html, $dataArray, $form);
567 - return $html;
891 + $text = apply_filters("yeeadons_gravity_forms_repeater_text", $text, $dataArray, $form);
892 + return $text;
568 893 }
569 894 }
570 895 public function get_value_export($entry, $input_id = '', $use_text = false, $is_csv = false)
571 896 {
@@ -593,9 +918,9 @@
593 918 $return = $this->get_datas_field($format, $value, $form_id);
594 919 return $return;
595 920 }
596 921 }
597 - function get_field_label($form, $name = '', $type = '', $child = false, $form_id = '')
922 + function get_custom_field_label($form, $name = '', $type = '', $child = false, $form_id = '')
598 923 {
599 924 if (is_array($form)) {
600 925 if (!array_key_exists('fields', $form)) {
601 926 return false;
@@ -605,12 +930,12 @@
605 930 }
606 931 $name = str_replace("gform_multifile_upload_" . $form_id, "input", $name);
607 932 $names = explode("__", $name);
608 933 $names = explode("_", $names[0]);
609 - $name = $names[1];
934 + $name = isset($names[1]) ? $names[1] : $names[0];
610 935 foreach ($form['fields'] as $field_key => $field_value) {
611 936 if (is_array($field_value->inputs)) {
612 - foreach ($field_value->inputs as $children_id) {
937 + foreach ($field_value->inputs as $children_id) {
613 938 if ($children_id["id"] == $name) {
614 939 if ($child) {
615 940 return $children_id["label"];
616 941 } else {
@@ -636,9 +961,9 @@
636 961 return false;
637 962 }
638 963 $names = explode("__", $name);
639 964 $names = explode("_", $names[0]);
640 - $name = $names[1];
965 + $name = isset($names[1]) ? $names[1] : $names[0];
641 966 foreach ($form['fields'] as $field_key => $field_value) {
642 967 if ($field_value->id == $name) {
643 968 if ($field_value->type == "date") {
644 969 return $name;
@@ -661,12 +986,12 @@
661 986 }
662 987 $name = str_replace("gform_multifile_upload_" . $form_id, "input", $name);
663 988 $names = explode("__", $name);
664 989 $names = explode("_", $names[0]);
665 - $name = $names[1];
990 + $name = isset($names[1]) ? $names[1] : $names[0];
666 991 foreach ($form['fields'] as $field_key => $field_value) {
667 992 if (is_array($field_value->inputs)) {
668 - foreach ($field_value->inputs as $children_id) {
993 + foreach ($field_value->inputs as $children_id) {
669 994 if ($children_id["id"] == $name) {
670 995 return $field_value->type;
671 996 }
672 997 }
@@ -676,8 +1001,46 @@
676 1001 }
677 1002 }
678 1003 }
679 1004 return "";
1005 + }
1006 +
1007 + public static function remove_child_fields($form)
1008 + {
1009 + if (!is_admin()) {
1010 + return $form;
1011 + }
1012 +
1013 + $page = isset($_GET['page']) ? $_GET['page'] : '';
1014 + $gf_page = isset($_GET['gf_page']) ? $_GET['gf_page'] : '';
1015 +
1016 + $target_pages = array('gf_entries', 'gf_export');
1017 + $target_gf_pages = array('select_columns', 'print-entry');
1018 +
1019 + if (in_array($page, $target_pages) || in_array($gf_page, $target_gf_pages)) {
1020 + $fields = array();
1021 + $zo = false;
1022 + foreach ($form["fields"] as $field) {
1023 + $type = $field->type;
1024 + if ($type == "repeater_start") {
1025 + $zo = true;
1026 + $fields[] = $field;
1027 + continue;
1028 + }
1029 + if ($type == "repeater_end") {
1030 + $zo = false;
1031 + $fields[] = $field;
1032 + continue;
1033 + }
1034 + if ($zo) {
1035 + continue;
1036 + }
1037 + $fields[] = $field;
1038 + }
1039 + $form["fields"] = $fields;
1040 + }
1041 +
1042 + return $form;
680 1043 }
681 1044 }
682 1045 // Register the phone field with the field framework.
683 1046 GF_Fields::register(new Superaddons_GFRepeater_Field());