PluginProbe
SureDonation – Donation Forms, Fundraising Campaigns & Donor Management / 1.1.0
SureDonation – Donation Forms, Fundraising Campaigns & Donor Management v1.1.0
1.6.0 1.5.1 1.5.0 1.4.0 1.3.0 trunk 0.0.1 1.0.0 1.1.0 1.1.1 1.1.2 1.2.0
← All changes | inc/field-validation.php +36 -824 1.6.0 → 1.1.0 View file →
@@ -35,24 +35,8 @@
35 35 */
36 36 public const VALIDATION_MESSAGES_OPTION_KEY = 'validation_messages';
37 37
38 38 /**
39 - * Canonical stored values for a checkbox field.
40 - *
41 - * Deliberately untranslated: the value is persisted to donation_data, read
42 - * back by the entry screen, the abilities runtime and the CSV export, and can
43 - * be re-imported on another site. Display layers translate it on read via
44 - * Helper::format_checkbox_field_value(); the export keeps the canonical token
45 - * so the column stays comparable across locales.
46 - *
47 - * @since 1.5.1
48 - */
49 - public const CHECKBOX_VALUES = [
50 - 'yes' => 'Yes',
51 - 'no' => 'No',
52 - ];
53 -
54 - /**
55 39 * Field blocks whose values participate in field-level validation.
56 40 *
57 41 * @since 1.1.0
58 42 */
@@ -59,13 +43,8 @@
59 43 public const VALIDATABLE_BLOCKS = [
60 44 'suredonation/input',
61 45 'suredonation/email',
62 46 'suredonation/number',
63 - 'suredonation/checkbox',
64 - 'suredonation/dropdown',
65 - 'suredonation/phone',
66 - 'suredonation/url',
67 - 'suredonation/donor-comment',
68 47 ];
69 48
70 49 /**
71 50 * Add block configuration for form fields.
@@ -188,23 +167,8 @@
188 167 break;
189 168 case 'suredonation/email':
190 169 $processed_config = self::process_email_block( $block['attrs'] );
191 170 break;
192 - case 'suredonation/checkbox':
193 - $processed_config = self::process_checkbox_block( $block['attrs'] );
194 - break;
195 - case 'suredonation/dropdown':
196 - $processed_config = self::process_dropdown_block( $block['attrs'] );
197 - break;
198 - case 'suredonation/phone':
199 - $processed_config = self::process_phone_block( $block['attrs'] );
200 - break;
201 - case 'suredonation/url':
202 - $processed_config = self::process_url_block( $block['attrs'] );
203 - break;
204 - case 'suredonation/donor-comment':
205 - $processed_config = self::process_donor_comment_block( $block['attrs'] );
206 - break;
207 171 }
208 172
209 173 /**
210 174 * Filter the stored validation config for a field block.
@@ -214,13 +178,8 @@
214 178 * persisted on save and picked up by validate_form_data(). Return a
215 179 * non-empty array (including at least a 'required' flag plus any rule
216 180 * values the validator needs) to store it under the block id.
217 181 *
218 - * Set 'is_checkbox' => true for a consent-style boolean field so the
219 - * submission handler stores its value as the canonical Yes/No token
220 - * (see CHECKBOX_VALUES) and keeps the unticked state on the record
221 - * instead of dropping it as an empty value.
222 - *
223 182 * @since 1.1.0
224 183 * @param array<string, mixed>|null $processed_config Config from core (null when unhandled).
225 184 * @param string $block_name Block name.
226 185 * @param array<string, mixed> $attrs Block attributes.
@@ -245,16 +204,12 @@
245 204 /**
246 205 * Process payment block configuration.
247 206 *
248 207 * Extracts payment-related settings that are needed for server-side validation:
249 - * - payment_type: 'one-time', 'subscription' or 'both'
250 208 * - amount_type: 'fixed' or 'variable'
251 209 * - fixed_amount: The configured fixed amount
252 210 * - minimum_amount: The minimum allowed amount for variable amounts
253 211 * - variable_amount_field: The slug of the field providing the variable amount
254 - * - one_time / subscription: per-choice amount configs, 'both' mode only
255 - * - subscription_interval / subscription_billing_cycles: billing cadence, when a
256 - * subscription path exists
257 212 *
258 213 * @param array<mixed> $attrs Block attributes.
259 214 * @param array<mixed> $blocks All blocks in the form.
260 215 * @return array<string, mixed> Processed payment configuration.
@@ -262,103 +217,48 @@
262 217 */
263 218 private static function process_payment_block( $attrs, $blocks ) {
264 219 $payment_config = [];
265 220
266 - // Extract payment type (one-time, subscription, or both).
221 + // Extract payment type (one-time or subscription).
267 222 // Default to 'one-time' if not set (Gutenberg may not save default values).
268 223 $payment_config['payment_type'] = isset( $attrs['paymentType'] ) && is_string( $attrs['paymentType'] )
269 224 ? sanitize_text_field( $attrs['paymentType'] )
270 225 : 'one-time';
271 226
272 - // Shared amount configuration. Kept at the top level for every payment type,
273 - // including 'both', so blocks saved before dual-mode support — and any code
274 - // still reading the flat keys — behave exactly as before.
275 - $payment_config = array_merge( $payment_config, self::build_amount_config( $attrs, $blocks ) );
227 + // Extract amount type (fixed or variable).
228 + // IMPORTANT: Always store this - Gutenberg may not save attributes that match defaults.
229 + // Default to 'fixed' which is the block.json default.
230 + $payment_config['amount_type'] = isset( $attrs['amountType'] ) && is_string( $attrs['amountType'] )
231 + ? sanitize_text_field( $attrs['amountType'] )
232 + : 'fixed';
276 233
277 - // In 'both' mode each choice carries its own amount configuration. Store them
278 - // as separate sub-configs so validation can check the submitted amount against
279 - // the mode the donor actually selected rather than a single shared amount.
280 - if ( 'both' === $payment_config['payment_type'] ) {
281 - $payment_config['one_time'] = self::build_amount_config( $attrs, $blocks, 'oneTime' );
282 - $payment_config['subscription'] = self::build_amount_config( $attrs, $blocks, 'subscription' );
283 - }
234 + // Extract configured fixed amount.
235 + // Default to 10.00 to match block.json default.
236 + $payment_config['fixed_amount'] = isset( $attrs['fixedAmount'] )
237 + ? floatval( $attrs['fixedAmount'] )
238 + : 10.00;
284 239
285 - // Persist the billing cadence for any form with a subscription path. The admin
286 - // picks these in the editor, so the stored values are the source of truth on
287 - // submit — a tampered interval/cycles in the request cannot redirect the
288 - // gateway to a different cadence.
289 - //
290 - // Stored UNCONDITIONALLY with PHP-side defaults (not gated on
291 - // isset( subscriptionPlan )), exactly like build_amount_config() below:
292 - // block.json's subscriptionPlan default is a fully-populated object, so
293 - // Gutenberg omits the attribute whenever the admin accepts the defaults
294 - // (Monthly / Ongoing / default name). Gating on it would leave the cadence
295 - // unstored for that common case, get_subscription_cadence() would return
296 - // empty, and the submit path would fall back to the request-supplied cadence.
297 - if ( in_array( $payment_config['payment_type'], [ 'subscription', 'both' ], true ) ) {
298 - $cadence = self::derive_subscription_cadence_from_attrs( $attrs );
299 - $payment_config['subscription_interval'] = $cadence['subscription_interval'];
300 - $payment_config['subscription_billing_cycles'] = $cadence['subscription_billing_cycles'];
301 - }
240 + // Extract minimum amount for variable amounts.
241 + // Defaults to 0 (no minimum) — only enforced if the block setting specifies one.
242 + $payment_config['minimum_amount'] = isset( $attrs['minimumAmount'] )
243 + ? floatval( $attrs['minimumAmount'] )
244 + : 0.0;
302 245
303 - return $payment_config;
304 - }
246 + // Extract variable amount field reference.
247 + if ( isset( $attrs['variableAmountField'] ) ) {
248 + $variable_amount_slug = sanitize_text_field( $attrs['variableAmountField'] );
249 + $payment_config['variable_amount_field'] = $variable_amount_slug;
305 250
306 - /**
307 - * Build one amount configuration (type, fixed, minimum, variable field) from a
308 - * set of block attributes.
309 - *
310 - * Single-mode blocks use the unprefixed attributes (`amountType`, `fixedAmount`,
311 - * …); 'both' mode stores an independent configuration per choice under the
312 - * `oneTime`/`subscription` attribute prefixes. Defaults match block.json, because
313 - * Gutenberg omits attributes whose value equals the default.
314 - *
315 - * @param array<mixed> $attrs Block attributes.
316 - * @param array<mixed> $blocks All blocks in the form.
317 - * @param string $prefix Attribute prefix ('' for the shared config, 'oneTime' or 'subscription').
318 - * @return array<string, mixed> Amount configuration.
319 - * @since 1.5.1
320 - */
321 - private static function build_amount_config( $attrs, $blocks, $prefix = '' ) {
322 - // Maps a suffix onto the prefixed attribute name: an empty prefix gives
323 - // "amountType", the oneTime prefix gives "oneTimeAmountType".
324 - $attr_key = static function ( $name ) use ( $prefix ) {
325 - return '' === $prefix ? lcfirst( $name ) : $prefix . $name;
326 - };
327 -
328 - $amount_type_key = $attr_key( 'AmountType' );
329 - $fixed_key = $attr_key( 'FixedAmount' );
330 - $minimum_key = $attr_key( 'MinimumAmount' );
331 - $variable_key = $attr_key( 'VariableAmountField' );
332 -
333 - $config = [
334 - 'amount_type' => isset( $attrs[ $amount_type_key ] ) && is_string( $attrs[ $amount_type_key ] )
335 - ? sanitize_text_field( $attrs[ $amount_type_key ] )
336 - : 'fixed',
337 - 'fixed_amount' => isset( $attrs[ $fixed_key ] ) ? floatval( Helper::get_string_value( $attrs[ $fixed_key ] ) ) : 10.00,
338 - // Defaults to 0 (no minimum) — only enforced if the block setting specifies one.
339 - 'minimum_amount' => isset( $attrs[ $minimum_key ] ) ? floatval( Helper::get_string_value( $attrs[ $minimum_key ] ) ) : 0.0,
340 - ];
341 -
342 - // Stored unconditionally (empty string when unset) so absence is
343 - // unambiguous: a 'variable' choice whose field was never picked reads as
344 - // '' here, which validate_dynamic_amount_field() must reject rather than
345 - // wave through. Gutenberg omits the attribute while it equals its ''
346 - // default, so keying on isset() alone would hide that misconfiguration.
347 - $variable_amount_slug = isset( $attrs[ $variable_key ] )
348 - ? sanitize_text_field( Helper::get_string_value( $attrs[ $variable_key ] ) )
349 - : '';
350 - $config['variable_amount_field'] = $variable_amount_slug;
351 -
352 - // Find and add the block name from which the variable amount field comes from.
353 - if ( '' !== $variable_amount_slug && is_array( $blocks ) ) {
354 - $block_name = self::find_block_name_by_slug( $blocks, $variable_amount_slug );
355 - if ( $block_name ) {
356 - $config['variable_amount_field_block_name'] = $block_name;
251 + // Find and add the block name from which the variable amount field comes from.
252 + if ( ! empty( $variable_amount_slug ) && is_array( $blocks ) ) {
253 + $block_name = self::find_block_name_by_slug( $blocks, $variable_amount_slug );
254 + if ( $block_name ) {
255 + $payment_config['variable_amount_field_block_name'] = $block_name;
256 + }
357 257 }
358 258 }
359 259
360 - return $config;
260 + return $payment_config;
361 261 }
362 262
363 263 /**
364 264 * Find block name by slug recursively.
@@ -389,349 +289,8 @@
389 289 return null;
390 290 }
391 291
392 292 /**
393 - * Resolve the slugs of the core donor fields (name, email, variable amount
394 - * and the optional mapped phone) from a form's saved payment block.
395 - *
396 - * These fields are surfaced as first-class donation data and persisted in
397 - * their own columns, so the stored "additional" field set omits them.
398 - * Deriving the slugs from the saved form here (instead of trusting a
399 - * client-supplied list) keeps the exclusion authoritative — a tampered
400 - * submission cannot smuggle a core field into the additional set.
401 - *
402 - * @since 1.1.1
403 - * @param int $form_id The donation form post ID.
404 - * @return array<int, string> List of core field slugs (empty when none/invalid).
405 - */
406 - public static function get_core_field_slugs( $form_id ) {
407 - if ( ! is_int( $form_id ) || $form_id <= 0 || ! function_exists( 'parse_blocks' ) ) {
408 - return [];
409 - }
410 -
411 - $post = get_post( $form_id );
412 - if ( ! ( $post instanceof \WP_Post ) || empty( $post->post_content ) ) {
413 - return [];
414 - }
415 -
416 - $blocks = parse_blocks( $post->post_content );
417 - $slugs = [];
418 -
419 - $payment_attrs = self::find_payment_block_attrs( $blocks );
420 - if ( ! empty( $payment_attrs ) ) {
421 - foreach ( [ 'customerNameField', 'customerEmailField', 'customerPhoneField', 'variableAmountField' ] as $attr ) {
422 - if ( isset( $payment_attrs[ $attr ] ) && is_string( $payment_attrs[ $attr ] ) ) {
423 - $slug = sanitize_text_field( $payment_attrs[ $attr ] );
424 - if ( '' !== $slug ) {
425 - $slugs[] = $slug;
426 - }
427 - }
428 - }
429 - }
430 -
431 - // The donor comment also lives in its own column, so it is excluded from
432 - // the additional set for the same reason. Unlike the fields above it is not
433 - // mapped on the payment block — the presence of the block is the mapping —
434 - // so it is resolved from the already-parsed tree rather than through
435 - // get_donor_comment_slug(), which would parse the form a second time.
436 - $comment_slug = self::find_slug_by_block_name( $blocks, 'suredonation/donor-comment' );
437 - if ( is_string( $comment_slug ) && '' !== $comment_slug ) {
438 - $slugs[] = sanitize_text_field( $comment_slug );
439 - }
440 -
441 - return array_values( array_unique( $slugs ) );
442 - }
443 -
444 - /**
445 - * Resolve the slug of the form's Donor Comment field.
446 - *
447 - * Unlike the donor phone — which is mapped through a picker on the payment
448 - * block — the Donor Comment field is its own block, so the block's presence
449 - * in the saved form *is* the mapping. Returning the slug lets the submission
450 - * handlers read the already-validated value out of the submitted field set
451 - * and store it in the dedicated donor_comment column, rather than trusting a
452 - * separate client-supplied key. A comment posted against a form that has no
453 - * Donor Comment block is therefore ignored, matching how
454 - * Payment_Helper::get_submitted_is_anonymous() derives the anonymity option
455 - * from the saved form.
456 - *
457 - * Only one field can feed the single column: when a form somehow contains
458 - * more than one block (the editor warns against it), the first in document
459 - * order wins.
460 - *
461 - * @since 1.6.0
462 - * @param int $form_id The donation form post ID.
463 - * @return string The Donor Comment field slug, or '' when the form has none.
464 - */
465 - public static function get_donor_comment_slug( $form_id ) {
466 - $form_id = (int) $form_id;
467 - if ( $form_id <= 0 || ! function_exists( 'parse_blocks' ) ) {
468 - return '';
469 - }
470 -
471 - // form_id is attacker-chosen on a public endpoint, so confirm it really is
472 - // a donation form before parsing its content — otherwise the request can
473 - // aim a full block parse at any post in the database.
474 - $post = get_post( $form_id );
475 - if ( ! ( $post instanceof \WP_Post )
476 - || \SureDonation\Inc\Post_Types\Donation_Form::POST_TYPE !== $post->post_type
477 - || empty( $post->post_content ) ) {
478 - return '';
479 - }
480 -
481 - $slug = self::find_slug_by_block_name( parse_blocks( $post->post_content ), 'suredonation/donor-comment' );
482 -
483 - return null === $slug ? '' : sanitize_text_field( $slug );
484 - }
485 -
486 - /**
487 - * Find the `slug` attribute of the first block with the given name.
488 - *
489 - * The inverse of find_block_name_by_slug(). Walks in document order, parents
490 - * before children, so "first match" is stable and matches what the editor
491 - * shows the author.
492 - *
493 - * @since 1.6.0
494 - * @param array<mixed> $blocks Array of parsed blocks.
495 - * @param string $block_name Block name to look for.
496 - * @return string|null The slug, or null when the block is absent or has no slug.
497 - */
498 - private static function find_slug_by_block_name( $blocks, $block_name ) {
499 - if ( ! is_array( $blocks ) ) {
500 - return null;
501 - }
502 -
503 - foreach ( $blocks as $block ) {
504 - if ( ! is_array( $block ) ) {
505 - continue;
506 - }
507 -
508 - if ( isset( $block['blockName'] ) && $block_name === $block['blockName']
509 - && isset( $block['attrs']['slug'] ) && is_string( $block['attrs']['slug'] )
510 - && '' !== $block['attrs']['slug'] ) {
511 - return $block['attrs']['slug'];
512 - }
513 -
514 - if ( ! empty( $block['innerBlocks'] ) && is_array( $block['innerBlocks'] ) ) {
515 - $found = self::find_slug_by_block_name( $block['innerBlocks'], $block_name );
516 - if ( null !== $found ) {
517 - return $found;
518 - }
519 - }
520 - }
521 -
522 - return null;
523 - }
524 -
525 - /**
526 - * Find the suredonation/payment block's attributes recursively.
527 - *
528 - * @since 1.1.1
529 - * @param array<mixed> $blocks Array of parsed blocks.
530 - * @return array<string, mixed>|null The payment block attributes, or null when absent.
531 - */
532 - private static function find_payment_block_attrs( $blocks ) {
533 - if ( ! is_array( $blocks ) ) {
534 - return null;
535 - }
536 -
537 - foreach ( $blocks as $block ) {
538 - if ( ! is_array( $block ) ) {
539 - continue;
540 - }
541 -
542 - if ( isset( $block['blockName'] ) && 'suredonation/payment' === $block['blockName'] && isset( $block['attrs'] ) && is_array( $block['attrs'] ) ) {
543 - return $block['attrs'];
544 - }
545 -
546 - if ( ! empty( $block['innerBlocks'] ) && is_array( $block['innerBlocks'] ) ) {
547 - $found = self::find_payment_block_attrs( $block['innerBlocks'] );
548 - if ( null !== $found ) {
549 - return $found;
550 - }
551 - }
552 - }
553 -
554 - return null;
555 - }
556 -
557 - /**
558 - * Derive the billing cadence from a payment block's attributes.
559 - *
560 - * Single source of truth shared by build_amount_config() (store time) and
561 - * resolve_subscription_cadence_from_content() (legacy re-resolve). block.json's
562 - * subscriptionPlan default is a fully-populated object, so Gutenberg omits the
563 - * attribute whenever the admin accepts the defaults — hence the PHP-side
564 - * defaults of month / ongoing here.
565 - *
566 - * @since 1.5.1
567 - * @param array<string, mixed> $attrs Parsed payment-block attributes.
568 - * @return array{subscription_interval: string, subscription_billing_cycles: int|string}
569 - */
570 - private static function derive_subscription_cadence_from_attrs( $attrs ) {
571 - $plan = isset( $attrs['subscriptionPlan'] ) && is_array( $attrs['subscriptionPlan'] )
572 - ? $attrs['subscriptionPlan']
573 - : [];
574 -
575 - $interval = isset( $plan['interval'] ) && is_string( $plan['interval'] )
576 - ? sanitize_text_field( $plan['interval'] )
577 - : 'month';
578 -
579 - if ( isset( $plan['billingCycles'] ) ) {
580 - // billingCycles is either an integer count or the string 'ongoing'.
581 - $cycles = $plan['billingCycles'];
582 - $billing_cycles = is_numeric( $cycles )
583 - ? (int) $cycles
584 - : sanitize_text_field( Helper::get_string_value( $cycles ) );
585 - } else {
586 - $billing_cycles = 'ongoing';
587 - }
588 -
589 - return [
590 - 'subscription_interval' => $interval,
591 - 'subscription_billing_cycles' => $billing_cycles,
592 - ];
593 - }
594 -
595 - /**
596 - * Re-resolve a form's billing cadence from its stored post content.
597 - *
598 - * Forms saved before the cadence was persisted into the block config carry no
599 - * subscription_interval/billing_cycles keys in stored meta, and the config is
600 - * only rebuilt on save_post — so those keys never appear until the admin
601 - * happens to re-save. Rather than let the submit path assume month / ongoing
602 - * (which silently rewrites the admin's real plan — e.g. a 5-cycle yearly plan
603 - * becomes ongoing monthly), re-derive from the parsed payment block. This is
604 - * still server-side and untamperable: it reads post_content, never the request.
605 - *
606 - * @since 1.5.1
607 - * @param int $form_id Donation form post ID.
608 - * @return array{subscription_interval: string, subscription_billing_cycles: int|string}|null
609 - * Cadence, or null when the form has no readable payment block.
610 - */
611 - public static function resolve_subscription_cadence_from_content( $form_id ) {
612 - if ( ! is_int( $form_id ) || $form_id <= 0 || ! function_exists( 'parse_blocks' ) ) {
613 - return null;
614 - }
615 -
616 - $post = get_post( $form_id );
617 - if ( ! ( $post instanceof \WP_Post ) || empty( $post->post_content ) ) {
618 - return null;
619 - }
620 -
621 - $attrs = self::find_payment_block_attrs( parse_blocks( $post->post_content ) );
622 - if ( ! is_array( $attrs ) ) {
623 - return null;
624 - }
625 -
626 - return self::derive_subscription_cadence_from_attrs( $attrs );
627 - }
628 -
629 - /**
630 - * Resolve the slug of the field mapped to the donor phone on the payment block.
631 - *
632 - * The mapping is optional: when an author maps a Phone field via the payment
633 - * block's "Customer Phone Field" picker, its value is stored in the dedicated
634 - * donor_phone column. Returning the slug lets the submission handlers read the
635 - * already-validated value from the submitted fields rather than trusting a
636 - * separate client-supplied donor_phone field.
637 - *
638 - * @since 1.1.1
639 - * @param int $form_id The donation form post ID.
640 - * @return string The mapped phone field slug, or '' when unset/invalid.
641 - */
642 - public static function get_mapped_phone_slug( $form_id ) {
643 - if ( ! is_int( $form_id ) || $form_id <= 0 || ! function_exists( 'parse_blocks' ) ) {
644 - return '';
645 - }
646 -
647 - $post = get_post( $form_id );
648 - if ( ! ( $post instanceof \WP_Post ) || empty( $post->post_content ) ) {
649 - return '';
650 - }
651 -
652 - $payment_attrs = self::find_payment_block_attrs( parse_blocks( $post->post_content ) );
653 - if ( empty( $payment_attrs ) || ! isset( $payment_attrs['customerPhoneField'] ) || ! is_string( $payment_attrs['customerPhoneField'] ) ) {
654 - return '';
655 - }
656 -
657 - return sanitize_text_field( $payment_attrs['customerPhoneField'] );
658 - }
659 -
660 - /**
661 - * Build a map of field slug => label from a form's saved blocks.
662 - *
663 - * The label persisted with each submitted field is resolved from the saved
664 - * form (the authoritative source) rather than scraped from the rendered
665 - * page and trusted from the request — mirroring how SureForms recovers a
666 - * field's label server-side instead of from client-supplied text. Gutenberg
667 - * omits attributes left at their default, so a slug missing from this map
668 - * simply has no customized label and the caller falls back to the label
669 - * sent with the submission.
670 - *
671 - * @since 1.1.1
672 - * @param int $form_id The donation form post ID.
673 - * @return array<string, string> Map of field slug => label (empty when none/invalid).
674 - */
675 - public static function get_field_labels_map( $form_id ) {
676 - if ( ! is_int( $form_id ) || $form_id <= 0 || ! function_exists( 'parse_blocks' ) ) {
677 - return [];
678 - }
679 -
680 - $post = get_post( $form_id );
681 - if ( ! ( $post instanceof \WP_Post ) || empty( $post->post_content ) ) {
682 - return [];
683 - }
684 -
685 - $labels = [];
686 - self::collect_field_labels( parse_blocks( $post->post_content ), $labels );
687 -
688 - return $labels;
689 - }
690 -
691 - /**
692 - * Recursively collect slug => label pairs from parsed blocks.
693 - *
694 - * Inner blocks are walked first so nested sub-fields are captured before
695 - * their container; the first label seen for a slug wins.
696 - *
697 - * @since 1.1.1
698 - * @param array<mixed> $blocks Parsed blocks.
699 - * @param array<string, string> $labels Accumulator passed by reference.
700 - * @return void
701 - */
702 - private static function collect_field_labels( $blocks, &$labels ) {
703 - if ( ! is_array( $blocks ) ) {
704 - return;
705 - }
706 -
707 - foreach ( $blocks as $block ) {
708 - if ( ! is_array( $block ) ) {
709 - continue;
710 - }
711 -
712 - if ( ! empty( $block['innerBlocks'] ) && is_array( $block['innerBlocks'] ) ) {
713 - self::collect_field_labels( $block['innerBlocks'], $labels );
714 - }
715 -
716 - if ( ! isset( $block['attrs'] ) || ! is_array( $block['attrs'] ) ) {
717 - continue;
718 - }
719 -
720 - $slug = isset( $block['attrs']['slug'] ) && is_string( $block['attrs']['slug'] )
721 - ? sanitize_text_field( $block['attrs']['slug'] )
722 - : '';
723 - if ( '' === $slug || isset( $labels[ $slug ] ) ) {
724 - continue;
725 - }
726 -
727 - if ( isset( $block['attrs']['label'] ) && is_string( $block['attrs']['label'] ) ) {
728 - $labels[ $slug ] = sanitize_text_field( $block['attrs']['label'] );
729 - }
730 - }
731 - }
732 -
733 - /**
734 293 * Process donation-amount block configuration.
735 294 *
736 295 * @param array<mixed> $attrs Block attributes.
737 296 * @return array<string, mixed> Processed donation-amount configuration.
@@ -903,193 +462,8 @@
903 462 return $email_config;
904 463 }
905 464
906 465 /**
907 - * Process dropdown block configuration.
908 - *
909 - * Stores required state, multi-select bounds and the allowed option labels so
910 - * the server can enforce required/min/max selections and reject tampered values.
911 - *
912 - * @param array<mixed> $attrs Block attributes.
913 - * @return array<string, mixed> Processed dropdown block configuration.
914 - * @since 1.1.1
915 - */
916 - private static function process_dropdown_block( $attrs ) {
917 - $dropdown_config = [
918 - 'required' => ! empty( $attrs['required'] ),
919 - 'multi_select' => ! empty( $attrs['multiSelect'] ),
920 - 'min_selection' => isset( $attrs['minSelection'] ) ? absint( Helper::get_string_value( $attrs['minSelection'] ) ) : 0,
921 - 'max_selection' => isset( $attrs['maxSelection'] ) ? absint( Helper::get_string_value( $attrs['maxSelection'] ) ) : 0,
922 - ];
923 -
924 - // Allowed option labels (the submitted value(s) must match one of these).
925 - $options = [];
926 - if ( isset( $attrs['options'] ) && is_array( $attrs['options'] ) ) {
927 - foreach ( $attrs['options'] as $option ) {
928 - if ( is_array( $option ) && isset( $option['label'] ) && '' !== $option['label'] ) {
929 - $options[] = sanitize_text_field( Helper::get_string_value( $option['label'] ) );
930 - }
931 - }
932 - }
933 - $dropdown_config['options'] = $options;
934 -
935 - $error_msg = isset( $attrs['errorMsg'] ) ? sanitize_text_field( Helper::get_string_value( $attrs['errorMsg'] ) ) : '';
936 - if ( '' !== $error_msg ) {
937 - $dropdown_config['error_msg'] = $error_msg;
938 - }
939 -
940 - return $dropdown_config;
941 - }
942 -
943 - /**
944 - * Process phone block configuration.
945 - *
946 - * Stores required state and the optional per-field custom required message for
947 - * server-side enforcement. Phone-number format is validated loosely (see
948 - * validate_field_value) because the submitted value is the E.164-style number
949 - * produced by intl-tel-input.
950 - *
951 - * @param array<mixed> $attrs Block attributes.
952 - * @return array<string, mixed> Processed phone block configuration.
953 - * @since 1.1.1
954 - */
955 - private static function process_phone_block( $attrs ) {
956 - $phone_config = [
957 - 'required' => ! empty( $attrs['required'] ),
958 - ];
959 -
960 - $error_msg = isset( $attrs['errorMsg'] ) ? sanitize_text_field( Helper::get_string_value( $attrs['errorMsg'] ) ) : '';
961 - if ( '' !== $error_msg ) {
962 - $phone_config['error_msg'] = $error_msg;
963 - }
964 -
965 - return $phone_config;
966 - }
967 -
968 - /**
969 - * Process url block configuration.
970 - *
971 - * Stores required state, the optional per-field custom required message and
972 - * the per-field invalid-URL message for server-side enforcement.
973 - *
974 - * @param array<mixed> $attrs Block attributes.
975 - * @return array<string, mixed> Processed url block configuration.
976 - * @since 1.1.1
977 - */
978 - private static function process_url_block( $attrs ) {
979 - $url_config = [
980 - 'required' => ! empty( $attrs['required'] ),
981 - ];
982 -
983 - $error_msg = isset( $attrs['errorMsg'] ) ? sanitize_text_field( Helper::get_string_value( $attrs['errorMsg'] ) ) : '';
984 - if ( '' !== $error_msg ) {
985 - $url_config['error_msg'] = $error_msg;
986 - }
987 -
988 - $invalid_url_msg = isset( $attrs['invalidUrlMsg'] ) ? sanitize_text_field( Helper::get_string_value( $attrs['invalidUrlMsg'] ) ) : '';
989 - if ( '' !== $invalid_url_msg ) {
990 - $url_config['invalid_url_msg'] = $invalid_url_msg;
991 - }
992 -
993 - return $url_config;
994 - }
995 -
996 - /**
997 - * Process donor comment block configuration.
998 - *
999 - * Stores required state, max length and the optional per-field custom
1000 - * required message for server-side enforcement. Mirrors the text input's
1001 - * rules — the field is a plain textarea with no format constraint.
1002 - *
1003 - * @param array<mixed> $attrs Block attributes.
1004 - * @return array<string, mixed> Processed donor comment block configuration.
1005 - * @since 1.6.0
1006 - */
1007 - private static function process_donor_comment_block( $attrs ) {
1008 - $comment_config = [
1009 - 'required' => ! empty( $attrs['required'] ),
1010 - 'max_length' => isset( $attrs['maxLength'] ) ? absint( Helper::get_string_value( $attrs['maxLength'] ) ) : 500,
1011 - ];
1012 -
1013 - $error_msg = isset( $attrs['errorMsg'] ) ? sanitize_text_field( Helper::get_string_value( $attrs['errorMsg'] ) ) : '';
1014 - if ( '' !== $error_msg ) {
1015 - $comment_config['error_msg'] = $error_msg;
1016 - }
1017 -
1018 - return $comment_config;
1019 - }
1020 -
1021 - /**
1022 - * Process checkbox block configuration.
1023 - *
1024 - * A checkbox carries no format or range rules — only the required flag and
1025 - * the optional per-field error message. `is_checkbox` is stored so the
1026 - * submission handler can recognise the field by its saved configuration
1027 - * (rather than trusting the request) when it renders the value as Yes/No.
1028 - *
1029 - * @param array<mixed> $attrs Block attributes.
1030 - * @return array<string, mixed> Processed checkbox configuration.
1031 - * @since 1.5.1
1032 - */
1033 - private static function process_checkbox_block( $attrs ) {
1034 - $checkbox_config = [
1035 - 'required' => ! empty( $attrs['required'] ),
1036 - 'is_checkbox' => true,
1037 - ];
1038 -
1039 - $error_msg = isset( $attrs['errorMsg'] ) ? sanitize_text_field( Helper::get_string_value( $attrs['errorMsg'] ) ) : '';
1040 - if ( '' !== $error_msg ) {
1041 - $checkbox_config['error_msg'] = $error_msg;
1042 - }
1043 -
1044 - return $checkbox_config;
1045 - }
1046 -
1047 - /**
1048 - * Resolve the slugs of the form's checkbox fields.
1049 - *
1050 - * Read from the saved form's stored block configuration, so a submission
1051 - * cannot claim a field is (or is not) a checkbox. Used to render the
1052 - * submitted value as a readable Yes/No rather than a bare "1"/empty, and to
1053 - * keep an unchecked box in the stored record instead of dropping it as an
1054 - * empty value.
1055 - *
1056 - * Only `suredonation/checkbox` fields are returned. The fixed-purpose
1057 - * consent checkboxes (anonymous donation, cover fees, privacy consent) are
1058 - * not form-editor field blocks and have no entry in the block config, so
1059 - * their storage is unaffected.
1060 - *
1061 - * @param int $form_id Donation form post ID.
1062 - * @return array<int, string> Checkbox field slugs.
1063 - * @since 1.5.1
1064 - */
1065 - public static function get_checkbox_field_slugs( $form_id ) {
1066 - $form_id = absint( $form_id );
1067 - if ( $form_id <= 0 ) {
1068 - return [];
1069 - }
1070 -
1071 - $block_config = self::get_or_migrate_block_config_for_legacy_form( $form_id );
1072 - if ( empty( $block_config ) || ! is_array( $block_config ) ) {
1073 - return [];
1074 - }
1075 -
1076 - $slugs = [];
1077 - foreach ( $block_config as $config ) {
1078 - if ( ! is_array( $config ) || empty( $config['is_checkbox'] ) ) {
1079 - continue;
1080 - }
1081 -
1082 - $slug = isset( $config['slug'] ) && is_string( $config['slug'] ) ? $config['slug'] : '';
1083 - if ( '' !== $slug ) {
1084 - $slugs[] = $slug;
1085 - }
1086 - }
1087 -
1088 - return $slugs;
1089 - }
1090 -
1091 - /**
1092 466 * Get the block types that participate in field validation.
1093 467 *
1094 468 * Extensions register new validatable field blocks (e.g. phone, address,
1095 469 * url) via the filter so their values run through validate_form_data().
@@ -1212,37 +586,19 @@
1212 586 * @since 1.1.0
1213 587 */
1214 588 public static function default_validation_messages() {
1215 589 $messages = [
1216 - 'suredonation_input_block_required_text' => __( 'This field is required.', 'suredonation' ),
1217 - 'suredonation_email_block_required_text' => __( 'This field is required.', 'suredonation' ),
1218 - 'suredonation_number_block_required_text' => __( 'This field is required.', 'suredonation' ),
1219 - 'suredonation_checkbox_block_required_text' => __( 'This field is required.', 'suredonation' ),
1220 - 'suredonation_dropdown_block_required_text' => __( 'This field is required.', 'suredonation' ),
1221 - 'suredonation_phone_block_required_text' => __( 'This field is required.', 'suredonation' ),
1222 - 'suredonation_url_block_required_text' => __( 'This field is required.', 'suredonation' ),
1223 - 'suredonation_donor_comment_block_required_text' => __( 'This field is required.', 'suredonation' ),
1224 - 'suredonation_valid_email' => __( 'Please enter a valid email address.', 'suredonation' ),
1225 - 'suredonation_valid_number' => __( 'Please enter a valid number.', 'suredonation' ),
1226 - 'suredonation_valid_phone' => __( 'Please enter a valid phone number.', 'suredonation' ),
1227 - 'suredonation_valid_url' => __( 'Please enter a valid URL.', 'suredonation' ),
1228 - 'suredonation_dropdown_invalid_option' => __( 'Please select a valid option.', 'suredonation' ),
1229 - /* translators: %s: minimum number of selections required. */
1230 - 'suredonation_dropdown_min_selection' => __( 'Please select at least %s option(s).', 'suredonation' ),
1231 - /* translators: %s: maximum number of selections allowed. */
1232 - 'suredonation_dropdown_max_selection' => __( 'Please select no more than %s option(s).', 'suredonation' ),
590 + 'suredonation_input_block_required_text' => __( 'This field is required.', 'suredonation' ),
591 + 'suredonation_email_block_required_text' => __( 'This field is required.', 'suredonation' ),
592 + 'suredonation_number_block_required_text' => __( 'This field is required.', 'suredonation' ),
593 + 'suredonation_valid_email' => __( 'Please enter a valid email address.', 'suredonation' ),
594 + 'suredonation_valid_number' => __( 'Please enter a valid number.', 'suredonation' ),
1233 595 /* translators: %s: maximum number of characters allowed. */
1234 - 'suredonation_input_max_length' => __( 'Maximum length is %s characters.', 'suredonation' ),
1235 - /* translators: %s: maximum characters allowed before the @ symbol. */
1236 - 'suredonation_email_local_max_length' => __( 'The part before @ may not exceed %s characters.', 'suredonation' ),
1237 - /* translators: %s: maximum characters allowed after the @ symbol. */
1238 - 'suredonation_email_domain_max_length' => __( 'The part after @ may not exceed %s characters.', 'suredonation' ),
1239 - /* translators: %s: maximum total characters allowed in an email address. */
1240 - 'suredonation_email_max_length' => __( 'The email address may not exceed %s characters.', 'suredonation' ),
596 + 'suredonation_input_max_length' => __( 'Maximum length is %s characters.', 'suredonation' ),
1241 597 /* translators: %s: minimum allowed value. */
1242 - 'suredonation_input_min_value' => __( 'Minimum value is %s.', 'suredonation' ),
598 + 'suredonation_input_min_value' => __( 'Minimum value is %s.', 'suredonation' ),
1243 599 /* translators: %s: maximum allowed value. */
1244 - 'suredonation_input_max_value' => __( 'Maximum value is %s.', 'suredonation' ),
600 + 'suredonation_input_max_value' => __( 'Maximum value is %s.', 'suredonation' ),
1245 601 ];
1246 602
1247 603 /**
1248 604 * Filter the default validation messages.
@@ -1305,9 +661,8 @@
1305 661 }
1306 662
1307 663 switch ( $block_name ) {
1308 664 case 'suredonation/input':
1309 - case 'suredonation/donor-comment':
1310 665 $max_length = isset( $config['max_length'] ) && is_numeric( $config['max_length'] ) ? (int) $config['max_length'] : 0;
1311 666 $length = function_exists( 'mb_strlen' ) ? mb_strlen( $value ) : strlen( $value );
1312 667 if ( $max_length > 0 && $length > $max_length ) {
1313 668 // str_replace (not sprintf) because the message is admin/translator
@@ -1322,41 +677,10 @@
1322 677 return $config['invalid_email_msg'];
1323 678 }
1324 679 return self::get_validation_message( 'suredonation_valid_email' );
1325 680 }
1326 -
1327 - $email_length_error = self::validate_email_length( $value );
1328 - if ( '' !== $email_length_error ) {
1329 - return $email_length_error;
1330 - }
1331 681 break;
1332 682
1333 - case 'suredonation/url':
1334 - // Intentional dotted-host-only restriction (same as SureForms): the
1335 - // value must be a domain with a TLD or an IPv4 host, with an optional
1336 - // scheme, port, path, query and fragment. Bare single-label hosts
1337 - // (localhost, intranet names, typos like "abcdef") are deliberately
1338 - // rejected for a public "website" field. The 2048-byte cap
1339 - // short-circuits before the regex on overlong, public, unauthenticated
1340 - // input so its host-label sub-pattern cannot backtrack (ReDoS guard).
1341 - // Kept in sync with the client check in src/form-frontend/validation.js.
1342 - if ( strlen( $value ) > 2048 || ! preg_match( '#^(https?://)?((([a-z\d]([a-z\d-]*[a-z\d])*)\.)+[a-z]{2,}|((\d{1,3}\.){3}\d{1,3}))(:\d+)?(/[-a-z\d%_.~+]*)*(\?[;&a-z\d%_.~+=-]*)?(\#[-a-z\d_]*)?$#i', $value ) ) {
1343 - if ( ! empty( $config['invalid_url_msg'] ) && is_string( $config['invalid_url_msg'] ) ) {
1344 - return $config['invalid_url_msg'];
1345 - }
1346 - return self::get_validation_message( 'suredonation_valid_url' );
1347 - }
1348 - break;
1349 -
1350 - case 'suredonation/phone':
1351 - // Loose format check: digits plus the common phone punctuation,
1352 - // 6–20 characters. The strict country-aware check happens client-side
1353 - // via intl-tel-input; this guards against obviously bad submissions.
1354 - if ( ! preg_match( '/^[\d\s()+.\-]{6,20}$/', $value ) ) {
1355 - return self::get_validation_message( 'suredonation_valid_phone' );
1356 - }
1357 - break;
1358 -
1359 683 case 'suredonation/number':
1360 684 if ( ! is_numeric( $value ) ) {
1361 685 return self::get_validation_message( 'suredonation_valid_number' );
1362 686 }
@@ -1371,120 +695,8 @@
1371 695 if ( $validation_max > 0 && $number > $validation_max ) {
1372 696 return str_replace( '%s', self::format_number( $validation_max ), self::get_validation_message( 'suredonation_input_max_value' ) );
1373 697 }
1374 698 break;
1375 -
1376 - case 'suredonation/dropdown':
1377 - $multi_select = ! empty( $config['multi_select'] );
1378 - // Deduplicate before the min/max count check — the server is the
1379 - // trust boundary, and a crafted "A|A|A" must not pass max_selection
1380 - // (or min_selection) with a single distinct value.
1381 - $selections = $multi_select
1382 - ? array_values( array_unique( array_filter( array_map( 'trim', explode( '|', $value ) ), 'strlen' ) ) )
1383 - : [ $value ];
1384 -
1385 - // Reject values that are not among the configured options.
1386 - $allowed = isset( $config['options'] ) && is_array( $config['options'] ) ? $config['options'] : [];
1387 - if ( ! empty( $allowed ) ) {
1388 - foreach ( $selections as $selection ) {
1389 - if ( ! in_array( $selection, $allowed, true ) ) {
1390 - return self::get_validation_message( 'suredonation_dropdown_invalid_option' );
1391 - }
1392 - }
1393 - }
1394 -
1395 - // Min/max apply to multi-select only.
1396 - if ( $multi_select ) {
1397 - $count = count( $selections );
1398 - $min = isset( $config['min_selection'] ) ? (int) $config['min_selection'] : 0;
1399 - $max = isset( $config['max_selection'] ) ? (int) $config['max_selection'] : 0;
1400 -
1401 - if ( $min > 0 && $count < $min ) {
1402 - return str_replace( '%s', number_format_i18n( $min ), self::get_validation_message( 'suredonation_dropdown_min_selection' ) );
1403 - }
1404 - if ( $max > 0 && $count > $max ) {
1405 - return str_replace( '%s', number_format_i18n( $max ), self::get_validation_message( 'suredonation_dropdown_max_selection' ) );
1406 - }
1407 - }
1408 - break;
1409 - }
1410 -
1411 - return '';
1412 - }
1413 -
1414 - /**
1415 - * Enforce RFC 5321 length limits on an email value.
1416 - *
1417 - * The value is split on the last @ so the local part (before @, max 64) and
1418 - * domain part (after @, max 255) are bounded separately. Limits are
1419 - * overridable via the suredonation_email_field_char_limits filter.
1420 - *
1421 - * Public so the payment layer can length-cap the persisted donor_email
1422 - * (which is separate from the validation-only fields[] copy this class
1423 - * normally inspects). A value with no @ — possible when the caller has not
1424 - * already run is_email() — is bounded by the local-part limit so oversized
1425 - * junk still cannot be stored.
1426 - *
1427 - * @param string $value Submitted, trimmed email value.
1428 - * @return string Error message, or '' when the value passes.
1429 - * @since 1.1.1
1430 - */
1431 - public static function validate_email_length( $value ) {
1432 - $defaults = [
1433 - 'local' => 64,
1434 - 'domain' => 255,
1435 - ];
1436 -
1437 - /**
1438 - * Filter the RFC 5321 character limits enforced on the Email field.
1439 - *
1440 - * @since 1.1.1
1441 - * @param array{local:int,domain:int} $limits Max characters for the local and domain parts.
1442 - */
1443 - $limits = apply_filters( 'suredonation_email_field_char_limits', $defaults );
1444 -
1445 - // Fall back to defaults if the filter returns junk or non-positive values.
1446 - $local_limit = is_array( $limits ) && isset( $limits['local'] ) && (int) $limits['local'] > 0 ? (int) $limits['local'] : $defaults['local'];
1447 - $domain_limit = is_array( $limits ) && isset( $limits['domain'] ) && (int) $limits['domain'] > 0 ? (int) $limits['domain'] : $defaults['domain'];
1448 -
1449 - $at = strrpos( $value, '@' );
1450 - if ( false === $at ) {
1451 - // No @ (caller did not run is_email first): bound the whole value by
1452 - // the local-part limit so oversized junk cannot be persisted.
1453 - $length = function_exists( 'mb_strlen' ) ? mb_strlen( $value ) : strlen( $value );
1454 - if ( $length > $local_limit ) {
1455 - return str_replace( '%s', number_format_i18n( $local_limit ), self::get_validation_message( 'suredonation_email_local_max_length' ) );
1456 - }
1457 - // Defensive total cap (see below): only reachable if a filter raised the
1458 - // local limit past 254; keeps a no-@ value within the VARCHAR(255) column.
1459 - if ( $length > 254 ) {
1460 - return str_replace( '%s', number_format_i18n( 254 ), self::get_validation_message( 'suredonation_email_max_length' ) );
1461 - }
1462 - return '';
1463 - }
1464 -
1465 - $local_part = substr( $value, 0, $at );
1466 - $domain_part = substr( $value, $at + 1 );
1467 -
1468 - $local_length = function_exists( 'mb_strlen' ) ? mb_strlen( $local_part ) : strlen( $local_part );
1469 - $domain_length = function_exists( 'mb_strlen' ) ? mb_strlen( $domain_part ) : strlen( $domain_part );
1470 -
1471 - // str_replace (not sprintf) because the message is admin/translator
1472 - // editable; a stray literal % would make sprintf throw on PHP 8.
1473 - if ( $local_length > $local_limit ) {
1474 - return str_replace( '%s', number_format_i18n( $local_limit ), self::get_validation_message( 'suredonation_email_local_max_length' ) );
1475 - }
1476 -
1477 - if ( $domain_length > $domain_limit ) {
1478 - return str_replace( '%s', number_format_i18n( $domain_limit ), self::get_validation_message( 'suredonation_email_domain_max_length' ) );
1479 - }
1480 -
1481 - // RFC 5321 §4.5.3.1.3: the whole address may not exceed 254 chars. This is a
1482 - // fixed cap (independent of the per-part filter) because it also guarantees
1483 - // the value fits the VARCHAR(255) donor_email/email columns, which the
1484 - // per-part caps alone do not — they sum to 320.
1485 - if ( ( $local_length + 1 + $domain_length ) > 254 ) {
1486 - return str_replace( '%s', number_format_i18n( 254 ), self::get_validation_message( 'suredonation_email_max_length' ) );
1487 699 }
1488 700
1489 701 return '';
1490 702 }