| @@ -114,12 +114,46 @@ | ||
| 114 | 114 | { |
| 115 | 115 | if (is_array($value)) { |
| 116 | 116 | $value = ''; |
| 117 | 117 | } |
| 118 | + $id = intval($this->id); | |
| 119 | + | |
| 120 | + // If resuming draft submission via Save & Continue and $value doesn't have saved_values, | |
| 121 | + // attempt to restore from draft $entry if available | |
| 122 | + if (empty($value) || (is_string($value) && strpos($value, 'saved_values') === false)) { | |
| 123 | + if (!empty($entry) && is_array($entry) && !empty($entry[$id])) { | |
| 124 | + $entry_data = maybe_unserialize($entry[$id]); | |
| 125 | + if (is_array($entry_data) && !empty($entry_data)) { | |
| 126 | + $decoded_value = !empty($value) ? json_decode($value, true) : array(); | |
| 127 | + if (!is_array($decoded_value)) { | |
| 128 | + $decoded_value = array(); | |
| 129 | + } | |
| 130 | + $row_ids = array_keys($entry_data); | |
| 131 | + $decoded_value['count'] = count($row_ids); | |
| 132 | + $decoded_value['id'] = $row_ids; | |
| 133 | + $saved_rows = array(); | |
| 134 | + foreach ($entry_data as $row_id => $row_inputs) { | |
| 135 | + if (is_array($row_inputs)) { | |
| 136 | + foreach ($row_inputs as $in_name => $in_val) { | |
| 137 | + if (is_array($in_val)) { | |
| 138 | + foreach ($in_val as $sub_k => $sub_v) { | |
| 139 | + $saved_rows[$row_id]['input_' . str_replace('.', '_', $sub_k) . '__' . $row_id] = $sub_v; | |
| 140 | + } | |
| 141 | + } else { | |
| 142 | + $saved_rows[$row_id][$in_name] = $in_val; | |
| 143 | + } | |
| 144 | + } | |
| 145 | + } | |
| 146 | + } | |
| 147 | + $decoded_value['saved_values'] = $saved_rows; | |
| 148 | + $value = wp_json_encode($decoded_value); | |
| 149 | + } | |
| 150 | + } | |
| 151 | + } | |
| 152 | + | |
| 118 | 153 | $is_entry_detail = $this->is_entry_detail(); |
| 119 | 154 | $is_form_editor = $this->is_form_editor(); |
| 120 | 155 | $form_id = $form['id']; |
| 121 | - $id = intval($this->id); | |
| 122 | 156 | $field_id = $is_entry_detail || $is_form_editor || $form_id == 0 ? "input_$id" : 'input_' . $form_id . "_$id"; |
| 123 | 157 | $size = $this->size; |
| 124 | 158 | $disabled_text = $is_form_editor ? "disabled='disabled'" : ''; |
| 125 | 159 | $class_suffix = $is_entry_detail ? '_admin' : ''; |
| @@ -145,10 +179,10 @@ | ||
| 145 | 179 | $limit = 9999; |
| 146 | 180 | } |
| 147 | 181 | $limit = apply_filters("yeeaddons_gf_repeater_limit", 5, $limit); |
| 148 | 182 | $initial_rows = apply_filters("yeeaddons_gf_repeater_initial_rows", 1, $initial_rows); |
| 149 | - $input = "<input data-initial_rows_map_check='" . $this->repeater_initial_rows_map . "' data-initial_rows_map='input_{$form_id}_" . $this->repeater_initial_rows_map . "' data-map_id='field_" . $form_id . "_" . $id . "' name='input_{$id}' id='{$field_id}' type='{$html_input_type}' value='{$value}' class='{$class}' {$tabindex} {$placeholder_attribute} {$required_attribute} {$invalid_attribute} {$disabled_text}/>"; | |
| 150 | - $html = '<div data-initial_rows_map_check="' . $this->repeater_initial_rows_map . '" class="repeater-field-warp-item-data" data-initial_rows="' . $initial_rows . '" data-limit="' . $limit . '" data-initial_rows_map="input_' . $form_id . '_' . $this->repeater_initial_rows_map . '" data-map_id="field_' . $form_id . '_' . $id . '"> | |
| 183 | + $input = "<input data-initial_rows_map_check='" . esc_attr($this->repeater_initial_rows_map) . "' data-initial_rows_map='input_{$form_id}_" . esc_attr($this->repeater_initial_rows_map) . "' data-map_id='field_" . $form_id . "_" . $id . "' name='input_{$id}' id='{$field_id}' type='{$html_input_type}' value='" . esc_attr($value) . "' class='{$class}' {$tabindex} {$placeholder_attribute} {$required_attribute} {$invalid_attribute} {$disabled_text}/>"; | |
| 184 | + $html = '<div data-initial_rows_map_check="' . esc_attr($this->repeater_initial_rows_map) . '" class="repeater-field-warp-item-data" data-initial_rows="' . $initial_rows . '" data-limit="' . $limit . '" data-initial_rows_map="input_' . $form_id . '_' . esc_attr($this->repeater_initial_rows_map) . '" data-map_id="field_' . $form_id . '_' . $id . '"> | |
| 151 | 185 | <div class="repeater-field-warp-item"> |
| 152 | 186 | </div> |
| 153 | 187 | <div class="repeater-field-footer"><a href="#"" class="gf-repeater-field-button-add" >' . $repeater_add_button . '</a></div> |
| 154 | 188 | ' . $input . ' |
| @@ -160,8 +194,72 @@ | ||
| 160 | 194 | } else { |
| 161 | 195 | return sprintf("<div class='ginput_container'>%s</div>", $html); |
| 162 | 196 | } |
| 163 | 197 | } |
| 198 | + public static function save_draft_submission_values($submitted_values, $form) | |
| 199 | + { | |
| 200 | + if (empty($form['fields']) || !is_array($form['fields'])) { | |
| 201 | + return $submitted_values; | |
| 202 | + } | |
| 203 | + | |
| 204 | + foreach ($form['fields'] as $field) { | |
| 205 | + if ($field->type !== 'repeater_end') { | |
| 206 | + continue; | |
| 207 | + } | |
| 208 | + | |
| 209 | + $raw_value = rgar($submitted_values, $field->id); | |
| 210 | + if (empty($raw_value)) { | |
| 211 | + $raw_value = rgpost('input_' . $field->id); | |
| 212 | + } | |
| 213 | + | |
| 214 | + if (empty($raw_value)) { | |
| 215 | + continue; | |
| 216 | + } | |
| 217 | + | |
| 218 | + $repeater_data = is_array($raw_value) ? $raw_value : json_decode($raw_value, true); | |
| 219 | + if (!is_array($repeater_data) || empty($repeater_data['id']) || !is_array($repeater_data['id'])) { | |
| 220 | + continue; | |
| 221 | + } | |
| 222 | + | |
| 223 | + // Capture all $_POST values for each repeater row | |
| 224 | + $saved_rows = array(); | |
| 225 | + foreach ($repeater_data['id'] as $id_rand) { | |
| 226 | + $row_data = array(); | |
| 227 | + foreach ($_POST as $post_key => $post_val) { | |
| 228 | + if (strpos($post_key, '__' . $id_rand) !== false) { | |
| 229 | + $row_data[$post_key] = wp_unslash($post_val); | |
| 230 | + } | |
| 231 | + } | |
| 232 | + | |
| 233 | + // Also check if any file was uploaded in this row | |
| 234 | + $transient_keys = array(); | |
| 235 | + $unique_id = rgpost('gform_unique_id'); | |
| 236 | + if (!empty($unique_id)) { | |
| 237 | + $transient_keys[] = 'gf_repeater_files_' . $unique_id; | |
| 238 | + } | |
| 239 | + $transient_keys[] = 'gf_repeater_files_' . $form['id']; | |
| 240 | + $transient_keys[] = 'gf_repeater_files_1'; | |
| 241 | + | |
| 242 | + foreach ($transient_keys as $t_key) { | |
| 243 | + $transient_files = get_transient($t_key); | |
| 244 | + if (is_array($transient_files)) { | |
| 245 | + foreach ($transient_files as $tk => $tv) { | |
| 246 | + if (strpos($tk, '__' . $id_rand) !== false && !empty($tv)) { | |
| 247 | + $row_data[$tk] = $tv; | |
| 248 | + } | |
| 249 | + } | |
| 250 | + } | |
| 251 | + } | |
| 252 | + | |
| 253 | + $saved_rows[$id_rand] = $row_data; | |
| 254 | + } | |
| 255 | + | |
| 256 | + $repeater_data['saved_values'] = $saved_rows; | |
| 257 | + $submitted_values[$field->id] = wp_json_encode($repeater_data); | |
| 258 | + } | |
| 259 | + | |
| 260 | + return $submitted_values; | |
| 261 | + } | |
| 164 | 262 | public static function remove_validation($form) |
| 165 | 263 | { |
| 166 | 264 | $zo = false; |
| 167 | 265 | $zo_datas = array(); |
| @@ -257,17 +355,27 @@ | ||
| 257 | 355 | } else { |
| 258 | 356 | $failedValidation = true; |
| 259 | 357 | } |
| 260 | 358 | break; |
| 359 | + case 'radio': | |
| 360 | + if (rgblank($getInputData)) { | |
| 361 | + $failedValidation = true; | |
| 362 | + } elseif ($getInputData === 'gf_other_choice') { | |
| 363 | + $other_val = rgpost($field . "_other__" . $id); | |
| 364 | + if (rgblank($other_val)) { | |
| 365 | + $failedValidation = true; | |
| 366 | + } | |
| 367 | + } | |
| 368 | + break; | |
| 261 | 369 | default: |
| 262 | 370 | if (is_array($getInputData)) { |
| 263 | 371 | foreach ($getInputData as $vl) { |
| 264 | - if (empty($vl)) { | |
| 372 | + if (rgblank($vl)) { | |
| 265 | 373 | $failedValidation = true; |
| 266 | 374 | } |
| 267 | 375 | } |
| 268 | 376 | } else { |
| 269 | - if (empty($getInputData)) { | |
| 377 | + if (rgblank($getInputData)) { | |
| 270 | 378 | $failedValidation = true; |
| 271 | 379 | } |
| 272 | 380 | } |
| 273 | 381 | break; |
| @@ -372,8 +480,11 @@ | ||
| 372 | 480 | public function get_value_save_entry($value, $form, $input_name, $lead_id, $lead) |
| 373 | 481 | { |
| 374 | 482 | $this->lead_id = $lead_id; |
| 375 | 483 | $datas = json_decode($value, true); |
| 484 | + if (!is_array($datas) || !isset($datas["id"]) || !is_array($datas["id"])) { | |
| 485 | + return maybe_serialize(array()); | |
| 486 | + } | |
| 376 | 487 | |
| 377 | 488 | $values = array(); |
| 378 | 489 | $form_id = $this->formId; |
| 379 | 490 | $get_form = GFFormsModel::get_form_meta_by_id($form_id); |
| @@ -378,11 +489,16 @@ | ||
| 378 | 489 | $form_id = $this->formId; |
| 379 | 490 | $get_form = GFFormsModel::get_form_meta_by_id($form_id); |
| 380 | 491 | $form = $get_form[0]; |
| 381 | 492 | $fields = array(); |
| 382 | - foreach ($datas["fields"] as $f) { | |
| 383 | - $datas_f = explode(".", $f); | |
| 384 | - $fields[] = $datas_f[0]; | |
| 493 | + if (isset($datas["fields"]) && is_array($datas["fields"])) { | |
| 494 | + foreach ($datas["fields"] as $f) { | |
| 495 | + if (!is_string($f) || empty($f)) { | |
| 496 | + continue; | |
| 497 | + } | |
| 498 | + $datas_f = explode(".", $f); | |
| 499 | + $fields[] = $datas_f[0]; | |
| 500 | + } | |
| 385 | 501 | } |
| 386 | 502 | $fields = array_unique($fields); |
| 387 | 503 | foreach ($datas["id"] as $id_rand) { |
| 388 | 504 | $datas_step = array(); |
| @@ -393,9 +509,17 @@ | ||
| 393 | 509 | $getInputData = array(); |
| 394 | 510 | foreach ($inputs as $child_input) { |
| 395 | 511 | $getInputName = "input_" . $child_input["id"] . "__" . $id_rand; |
| 396 | 512 | $vl = rgpost(str_replace('.', '_', strval($getInputName))); |
| 397 | - if ($vl != "") { | |
| 513 | + if ($vl !== "" && $vl !== false && $vl !== null) { | |
| 514 | + $child_field_type = $this->get_type($form, "input_" . $child_input["id"], $form_id); | |
| 515 | + if (is_string($vl)) { | |
| 516 | + if ($child_field_type === 'textarea') { | |
| 517 | + $vl = sanitize_textarea_field($vl); | |
| 518 | + } else { | |
| 519 | + $vl = sanitize_text_field($vl); | |
| 520 | + } | |
| 521 | + } | |
| 398 | 522 | $getInputData[$child_input["id"]] = $vl; |
| 399 | 523 | } |
| 400 | 524 | } |
| 401 | 525 | $datas_step[$getInputName] = $getInputData; |
| @@ -468,8 +592,20 @@ | ||
| 468 | 592 | if (empty($saved_url)) { |
| 469 | 593 | $saved_url = rgpost(str_replace('.', '_', strval($getInputName))); |
| 470 | 594 | } |
| 471 | 595 | |
| 596 | + // Sanitize theo kiểu trường trước khi lưu vào DB | |
| 597 | + $field_type = $this->get_type($form, $field, $form_id); | |
| 598 | + if (is_string($saved_url)) { | |
| 599 | + if ($field_type === 'textarea') { | |
| 600 | + $saved_url = sanitize_textarea_field($saved_url); | |
| 601 | + } elseif ($field_type === 'fileupload' || filter_var($saved_url, FILTER_VALIDATE_URL) !== false) { | |
| 602 | + $saved_url = esc_url_raw($saved_url); | |
| 603 | + } else { | |
| 604 | + $saved_url = sanitize_text_field($saved_url); | |
| 605 | + } | |
| 606 | + } | |
| 607 | + | |
| 472 | 608 | $datas_step[$getInputName] = $saved_url; |
| 473 | 609 | } |
| 474 | 610 | } |
| 475 | 611 | $values[$id_rand] = $datas_step; |
| @@ -514,15 +650,20 @@ | ||
| 514 | 650 | $dataArray = GFFormsModel::unserialize($value); |
| 515 | 651 | $get_form = GFFormsModel::get_form_meta_by_id($form_id); |
| 516 | 652 | $form = $get_form[0]; |
| 517 | 653 | if (isset($_GET['lid'])) { |
| 518 | - $result = GFAPI::get_entry($_GET['lid']); | |
| 654 | + $result = GFAPI::get_entry(absint($_GET['lid'])); | |
| 519 | 655 | } else { |
| 520 | 656 | $table = $wpdb->prefix . "gf_entry"; |
| 521 | 657 | $mylink = $wpdb->get_row("SELECT id FROM $table ORDER BY id DESC"); |
| 522 | - $result = GFAPI::get_entry($mylink->id); | |
| 658 | + $result = ($mylink && isset($mylink->id)) ? GFAPI::get_entry($mylink->id) : array(); | |
| 523 | 659 | } |
| 524 | - //var_dump($dataArray); | |
| 660 | + if (!is_array($result) || is_wp_error($result)) { | |
| 661 | + $result = array(); | |
| 662 | + } | |
| 663 | + if (!is_array($dataArray) || empty($dataArray)) { | |
| 664 | + return ''; | |
| 665 | + } | |
| 525 | 666 | if ($format === 'html') { |
| 526 | 667 | $html = '<ol>'; |
| 527 | 668 | foreach ($dataArray as $step_datas) { |
| 528 | 669 | $html .= '<li><ul>'; |
| @@ -534,20 +675,60 @@ | ||
| 534 | 675 | case "address": |
| 535 | 676 | $vl_data = ""; |
| 536 | 677 | foreach ($vl as $k => $v) { |
| 537 | 678 | $child_lb = $this->get_custom_field_label($form, "input_" . $k, $type, true); |
| 538 | - $vl_data .= $child_lb . ": " . $v . "<br>"; | |
| 679 | + $vl_data .= esc_html($child_lb) . ": " . esc_html($v) . "<br>"; | |
| 539 | 680 | } |
| 540 | - $html .= '<li>' . $lb . ": <br>" . $vl_data . "</li>"; | |
| 681 | + $html .= '<li>' . esc_html($lb) . ": <br>" . $vl_data . "</li>"; | |
| 541 | 682 | break; |
| 542 | 683 | default: |
| 543 | - $vl_data = implode(", ", $vl); | |
| 544 | - $html .= '<li>' . $lb . ": " . $vl_data . "</li>"; | |
| 684 | + $vl_data = implode(", ", array_map('esc_html', $vl)); | |
| 685 | + $html .= '<li>' . esc_html($lb) . ": " . $vl_data . "</li>"; | |
| 545 | 686 | break; |
| 546 | 687 | } |
| 547 | 688 | } else { |
| 548 | 689 | $vl_data = $vl; |
| 549 | 690 | |
| 691 | + // Helper functions kiểm tra và render file/hình ảnh | |
| 692 | + $encode_url = function ($url) { | |
| 693 | + return preg_replace_callback('/[^\x20-\x7E]/u', function ($match) { | |
| 694 | + return rawurlencode($match[0]); | |
| 695 | + }, trim($url)); | |
| 696 | + }; | |
| 697 | + | |
| 698 | + $is_valid_url = function ($url) use ($encode_url) { | |
| 699 | + if (empty($url)) | |
| 700 | + return false; | |
| 701 | + $encoded = $encode_url($url); | |
| 702 | + return filter_var($encoded, FILTER_VALIDATE_URL) !== false; | |
| 703 | + }; | |
| 704 | + | |
| 705 | + $is_image_url = function ($url) { | |
| 706 | + if (!is_string($url) || empty($url)) | |
| 707 | + return false; | |
| 708 | + $clean_path = parse_url($url, PHP_URL_PATH); | |
| 709 | + if (!$clean_path) { | |
| 710 | + $clean_path = $url; | |
| 711 | + } | |
| 712 | + $ext = strtolower(pathinfo($clean_path, PATHINFO_EXTENSION)); | |
| 713 | + return in_array($ext, array('jpg', 'jpeg', 'png', 'gif', 'webp', 'svg', 'bmp', 'ico', 'avif', 'heic'), true); | |
| 714 | + }; | |
| 715 | + | |
| 716 | + $render_file_or_image = function ($file_url, $display_name = '') use ($is_image_url) { | |
| 717 | + $file_url = trim($file_url); | |
| 718 | + if (empty($file_url)) | |
| 719 | + return ''; | |
| 720 | + $filename = !empty($display_name) ? $display_name : basename($file_url); | |
| 721 | + | |
| 722 | + if ($is_image_url($file_url)) { | |
| 723 | + return '<a href="' . esc_url($file_url) . '" target="_blank" class="repeater-image-preview" style="display:inline-block; margin: 4px 6px 4px 0;">' | |
| 724 | + . '<img src="' . esc_url($file_url) . '" alt="' . esc_attr($filename) . '" style="max-width: 150px; max-height: 150px; object-fit: contain; border-radius: 4px; border: 1px solid #e2e8f0; display: inline-block; vertical-align: middle;" />' | |
| 725 | + . '</a>'; | |
| 726 | + } else { | |
| 727 | + return '<a href="' . esc_url($file_url) . '" download>' . esc_html($filename) . '</a>'; | |
| 728 | + } | |
| 729 | + }; | |
| 730 | + | |
| 550 | 731 | switch ($type) { |
| 551 | 732 | case "fileupload": |
| 552 | 733 | if ($vl_data === "Upgrade to pro version") { |
| 553 | 734 | $html .= '<li>' . esc_html($lb) . ": " . esc_html($vl_data) . "</li>"; |
| @@ -553,23 +734,8 @@ | ||
| 553 | 734 | $html .= '<li>' . esc_html($lb) . ": " . esc_html($vl_data) . "</li>"; |
| 554 | 735 | break; |
| 555 | 736 | } |
| 556 | 737 | |
| 557 | - // Hàm helper nhỏ để encode Unicode URL an toàn | |
| 558 | - $encode_url = function ($url) { | |
| 559 | - return preg_replace_callback('/[^\x20-\x7E]/u', function ($match) { | |
| 560 | - return rawurlencode($match[0]); | |
| 561 | - }, trim($url)); | |
| 562 | - }; | |
| 563 | - | |
| 564 | - // Hàm kiểm tra URL hợp lệ (chấp nhận cả ký tự Unicode) | |
| 565 | - $is_valid_url = function ($url) use ($encode_url) { | |
| 566 | - if (empty($url)) | |
| 567 | - return false; | |
| 568 | - $encoded = $encode_url($url); | |
| 569 | - return filter_var($encoded, FILTER_VALIDATE_URL) !== false; | |
| 570 | - }; | |
| 571 | - | |
| 572 | 738 | // Tách chuỗi theo dấu phẩy phòng trường hợp có nhiều file |
| 573 | 739 | $parts = array_filter(array_map('trim', explode(",", $vl_data))); |
| 574 | 740 | $content = array(); |
| 575 | 741 | |
| @@ -584,12 +750,11 @@ | ||
| 584 | 750 | |
| 585 | 751 | if ($all_are_urls) { |
| 586 | 752 | foreach ($parts as $part) { |
| 587 | 753 | $filename = basename($part); |
| 588 | - // Dùng esc_url() của WP để tự động encode và bảo mật output | |
| 589 | - $content[] = '<a href="' . esc_url($part) . '" download>' . esc_html($filename) . '</a>'; | |
| 754 | + $content[] = $render_file_or_image($part, $filename); | |
| 590 | 755 | } |
| 591 | - $html .= '<li>' . esc_html($lb) . ': ' . implode(" | ", $content) . "</li>"; | |
| 756 | + $html .= '<li>' . esc_html($lb) . ': ' . implode(" ", $content) . "</li>"; | |
| 592 | 757 | break; |
| 593 | 758 | } |
| 594 | 759 | |
| 595 | 760 | // TRƯỜNG HỢP 2: Chuỗi chứa tên file hoặc URL không hợp lệ -> Tìm trong $result |
| @@ -611,9 +776,9 @@ | ||
| 611 | 776 | |
| 612 | 777 | foreach ($data_uploads as $upload_file) { |
| 613 | 778 | // Regex khớp chính xác tên file gốc hoặc tên file có đánh số thứ tự |
| 614 | 779 | if (preg_match('/' . $name_s . '(\d+)?\./i', $upload_file)) { |
| 615 | - $content[] = '<a href="' . esc_url($upload_file) . '" download>' . esc_html($clean_n) . '</a>'; | |
| 780 | + $content[] = $render_file_or_image($upload_file, $clean_n); | |
| 616 | 781 | break; |
| 617 | 782 | } |
| 618 | 783 | } |
| 619 | 784 | } |
| @@ -618,13 +783,17 @@ | ||
| 618 | 783 | } |
| 619 | 784 | } |
| 620 | 785 | } |
| 621 | 786 | |
| 622 | - $html .= '<li>' . esc_html($lb) . ': ' . (!empty($content) ? implode(" | ", $content) : esc_html($vl_data)) . "</li>"; | |
| 787 | + $html .= '<li>' . esc_html($lb) . ': ' . (!empty($content) ? implode(" ", $content) : esc_html($vl_data)) . "</li>"; | |
| 623 | 788 | break; |
| 624 | 789 | |
| 625 | 790 | default: |
| 626 | - $html .= '<li>' . esc_html($lb) . ": " . esc_html($vl_data) . "</li>"; | |
| 791 | + if (is_string($vl_data) && $is_valid_url($vl_data) && $is_image_url($vl_data)) { | |
| 792 | + $html .= '<li>' . esc_html($lb) . ': ' . $render_file_or_image($vl_data) . "</li>"; | |
| 793 | + } else { | |
| 794 | + $html .= '<li>' . esc_html($lb) . ": " . esc_html($vl_data) . "</li>"; | |
| 795 | + } | |
| 627 | 796 | break; |
| 628 | 797 | } |
| 629 | 798 | } |
| 630 | 799 | } |
| @@ -629,17 +798,22 @@ | ||
| 629 | 798 | } |
| 630 | 799 | } |
| 631 | 800 | $html .= '</ul></li>'; |
| 632 | 801 | } |
| 633 | - $html .= '<ol>'; | |
| 802 | + $html .= '</ol>'; | |
| 634 | 803 | $html = apply_filters("yeeadons_gravity_forms_repeater_html", $html, $dataArray, $form); |
| 635 | 804 | return $html; |
| 636 | 805 | } else { |
| 637 | - $html = ''; | |
| 806 | + $text = ''; | |
| 638 | 807 | foreach ($dataArray as $step_datas) { |
| 808 | + if (!is_array($step_datas)) { | |
| 809 | + continue; | |
| 810 | + } | |
| 639 | 811 | foreach ($step_datas as $name => $vl) { |
| 640 | 812 | $type = $this->get_type($form, $name, $form_id); |
| 641 | 813 | $lb = $this->get_custom_field_label($form, $name, $type, false, $form_id); |
| 814 | + $lb = esc_html($lb); | |
| 815 | + | |
| 642 | 816 | if (is_array($vl)) { |
| 643 | 817 | switch ($type) { |
| 644 | 818 | case "address": |
| 645 | 819 | $vl_data = ""; |
| @@ -644,15 +818,15 @@ | ||
| 644 | 818 | case "address": |
| 645 | 819 | $vl_data = ""; |
| 646 | 820 | foreach ($vl as $k => $v) { |
| 647 | 821 | $child_lb = $this->get_custom_field_label($form, "input_" . $k, $type, true); |
| 648 | - $vl_data .= $child_lb . ": " . $v . "\n"; | |
| 822 | + $vl_data .= esc_html($child_lb) . ": " . esc_html($v) . "\n"; | |
| 649 | 823 | } |
| 650 | - $html .= $lb . " : " . $vl_data . "\n"; | |
| 824 | + $text .= $lb . " : \n" . $vl_data; | |
| 651 | 825 | break; |
| 652 | 826 | default: |
| 653 | - $vl_data = implode(", ", $vl); | |
| 654 | - $html .= $lb . ": " . $vl_data . "\n"; | |
| 827 | + $vl_escaped = array_map('esc_html', $vl); | |
| 828 | + $text .= $lb . ": " . implode(", ", $vl_escaped) . "\n"; | |
| 655 | 829 | break; |
| 656 | 830 | } |
| 657 | 831 | } else { |
| 658 | 832 | $vl_data = $vl; |
| @@ -657,59 +831,66 @@ | ||
| 657 | 831 | } else { |
| 658 | 832 | $vl_data = $vl; |
| 659 | 833 | switch ($type) { |
| 660 | 834 | case "fileupload": |
| 661 | - if (filter_var($vl_data, FILTER_VALIDATE_URL) === FALSE) { | |
| 662 | - $content = array(); | |
| 663 | - $parts = array_map('trim', explode(",", $vl_data)); | |
| 664 | - $is_urls = true; | |
| 835 | + if ($vl_data === "Upgrade to pro version") { | |
| 836 | + $text .= $lb . ": " . esc_html($vl_data) . "\n"; | |
| 837 | + break; | |
| 838 | + } | |
| 839 | + $parts = array_filter(array_map('trim', explode(",", $vl_data))); | |
| 840 | + $content = array(); | |
| 841 | + | |
| 842 | + $all_are_urls = !empty($parts); | |
| 843 | + foreach ($parts as $part) { | |
| 844 | + if (filter_var($part, FILTER_VALIDATE_URL) === false) { | |
| 845 | + $all_are_urls = false; | |
| 846 | + break; | |
| 847 | + } | |
| 848 | + } | |
| 849 | + | |
| 850 | + if ($all_are_urls) { | |
| 665 | 851 | foreach ($parts as $part) { |
| 666 | - if (empty($part) || filter_var($part, FILTER_VALIDATE_URL) === FALSE) { | |
| 667 | - $is_urls = false; | |
| 668 | - break; | |
| 669 | - } | |
| 852 | + $filename = basename($part); | |
| 853 | + $content[] = esc_html($filename) . ' (' . esc_url($part) . ')'; | |
| 670 | 854 | } |
| 671 | - if ($is_urls) { | |
| 672 | - foreach ($parts as $part) { | |
| 673 | - $filename = basename($part); | |
| 674 | - $content[] = '<a href="' . esc_url($part) . '" download>' . esc_html($filename) . '</a>'; | |
| 855 | + $text .= $lb . ': ' . implode(", ", $content) . "\n"; | |
| 856 | + } else { | |
| 857 | + $main_name = explode("__", $name); | |
| 858 | + $main_name = explode("_", $main_name[0]); | |
| 859 | + $main_name_id = isset($main_name[4]) ? $main_name[4] : (isset($main_name[1]) ? $main_name[1] : null); | |
| 860 | + | |
| 861 | + if ($main_name_id && isset($result[$main_name_id])) { | |
| 862 | + $raw_uploads = $result[$main_name_id]; | |
| 863 | + $data_uploads = is_array($raw_uploads) ? $raw_uploads : json_decode($raw_uploads, true); | |
| 864 | + if (!is_array($data_uploads)) { | |
| 865 | + $data_uploads = array_filter(array_map('trim', explode(",", (string)$raw_uploads))); | |
| 675 | 866 | } |
| 676 | - $html .= $lb . ': ' . implode(" | ", $content) . "\n"; | |
| 677 | - } else { | |
| 678 | - $main_name = explode("__", $name); | |
| 679 | - $main_name = explode("_", $main_name[0]); | |
| 680 | - $main_name_id = $main_name[4]; | |
| 681 | - if (isset($result[$main_name_id])) { | |
| 682 | - $data_uploads = json_decode($result[$main_name_id], true); | |
| 683 | - foreach ($parts as $n) { | |
| 684 | - $n = sanitize_file_name($n); | |
| 685 | - foreach ($data_uploads as $name) { | |
| 686 | - $name_s = explode(".", $n); | |
| 687 | - $name_s = $name_s[0]; | |
| 688 | - $re = "/" . $name_s . "\.|" . $name_s . "[\d]\./"; | |
| 689 | - if (preg_match($re, $name)) { | |
| 690 | - $content[] = '<a href="' . $name . '" download>' . $n . "</a> "; | |
| 691 | - break; | |
| 692 | - } | |
| 867 | + | |
| 868 | + foreach ($parts as $n) { | |
| 869 | + $clean_n = sanitize_file_name($n); | |
| 870 | + $name_s = preg_quote(pathinfo($clean_n, PATHINFO_FILENAME), '/'); | |
| 871 | + foreach ($data_uploads as $upload_file) { | |
| 872 | + if (preg_match('/' . $name_s . '(\d+)?\./i', $upload_file)) { | |
| 873 | + $content[] = esc_html($clean_n) . ' (' . esc_url($upload_file) . ')'; | |
| 874 | + break; | |
| 693 | 875 | } |
| 694 | 876 | } |
| 695 | 877 | } |
| 696 | - $html .= $lb . ': ' . implode(" | ", $content) . "\n"; | |
| 697 | 878 | } |
| 698 | - } else { | |
| 699 | - $html .= $lb . ':' . $vl_data . "\n"; | |
| 879 | + $text .= $lb . ': ' . (!empty($content) ? implode(", ", $content) : esc_html($vl_data)) . "\n"; | |
| 700 | 880 | } |
| 701 | 881 | break; |
| 882 | + | |
| 702 | 883 | default: |
| 703 | - $html .= $lb . ": " . $vl_data . "\n"; | |
| 884 | + $text .= $lb . ": " . esc_html($vl_data) . "\n"; | |
| 704 | 885 | break; |
| 705 | 886 | } |
| 706 | 887 | } |
| 707 | 888 | } |
| 708 | - $html .= "\n"; | |
| 889 | + $text .= "\n"; | |
| 709 | 890 | } |
| 710 | - $html = apply_filters("yeeadons_gravity_forms_repeater_text", $html, $dataArray, $form); | |
| 711 | - return $html; | |
| 891 | + $text = apply_filters("yeeadons_gravity_forms_repeater_text", $text, $dataArray, $form); | |
| 892 | + return $text; | |
| 712 | 893 | } |
| 713 | 894 | } |
| 714 | 895 | public function get_value_export($entry, $input_id = '', $use_text = false, $is_csv = false) |
| 715 | 896 | { |
| @@ -749,9 +930,9 @@ | ||
| 749 | 930 | } |
| 750 | 931 | $name = str_replace("gform_multifile_upload_" . $form_id, "input", $name); |
| 751 | 932 | $names = explode("__", $name); |
| 752 | 933 | $names = explode("_", $names[0]); |
| 753 | - $name = $names[1]; | |
| 934 | + $name = isset($names[1]) ? $names[1] : $names[0]; | |
| 754 | 935 | foreach ($form['fields'] as $field_key => $field_value) { |
| 755 | 936 | if (is_array($field_value->inputs)) { |
| 756 | 937 | foreach ($field_value->inputs as $children_id) { |
| 757 | 938 | if ($children_id["id"] == $name) { |
| @@ -780,9 +961,9 @@ | ||
| 780 | 961 | return false; |
| 781 | 962 | } |
| 782 | 963 | $names = explode("__", $name); |
| 783 | 964 | $names = explode("_", $names[0]); |
| 784 | - $name = $names[1]; | |
| 965 | + $name = isset($names[1]) ? $names[1] : $names[0]; | |
| 785 | 966 | foreach ($form['fields'] as $field_key => $field_value) { |
| 786 | 967 | if ($field_value->id == $name) { |
| 787 | 968 | if ($field_value->type == "date") { |
| 788 | 969 | return $name; |
| @@ -805,9 +986,9 @@ | ||
| 805 | 986 | } |
| 806 | 987 | $name = str_replace("gform_multifile_upload_" . $form_id, "input", $name); |
| 807 | 988 | $names = explode("__", $name); |
| 808 | 989 | $names = explode("_", $names[0]); |
| 809 | - $name = $names[1]; | |
| 990 | + $name = isset($names[1]) ? $names[1] : $names[0]; | |
| 810 | 991 | foreach ($form['fields'] as $field_key => $field_value) { |
| 811 | 992 | if (is_array($field_value->inputs)) { |
| 812 | 993 | foreach ($field_value->inputs as $children_id) { |
| 813 | 994 | if ($children_id["id"] == $name) { |