| 1 |
<?php |
| 2 |
/** |
| 3 |
* Donation form markup renderer. |
| 4 |
* |
| 5 |
* Shared by the donation-form block and the [suredonation_form] shortcode so |
| 6 |
* both produce identical markup (wrapper, form, field blocks, success box) and |
| 7 |
* pick up per-form styling from a single place. |
| 8 |
* |
| 9 |
* Callers handle validation, campaign resolution, and asset enqueueing; this |
| 10 |
* class only builds the markup. |
| 11 |
* |
| 12 |
* @package SureDonation |
| 13 |
* @since 1.0.0 |
| 14 |
*/ |
| 15 |
|
| 16 |
namespace SureDonation\Inc\Fields; |
| 17 |
|
| 18 |
use SureDonation\Inc\Helper; |
| 19 |
|
| 20 |
if ( ! defined( 'ABSPATH' ) ) { |
| 21 |
exit; // Exit if accessed directly. |
| 22 |
} |
| 23 |
|
| 24 |
/** |
| 25 |
* Form_Renderer class. |
| 26 |
* |
| 27 |
* @since 1.0.0 |
| 28 |
*/ |
| 29 |
class Form_Renderer { |
| 30 |
|
| 31 |
/** |
| 32 |
* Render the donation form markup for a form + campaign. |
| 33 |
* |
| 34 |
* @param \WP_Post $form Donation form post. |
| 35 |
* @param int $campaign_id Resolved campaign ID (0 for a standalone form). |
| 36 |
* @return string Form HTML. |
| 37 |
* @since 1.0.0 |
| 38 |
*/ |
| 39 |
public static function render( $form, $campaign_id ) { |
| 40 |
if ( ! $form instanceof \WP_Post ) { |
| 41 |
return ''; |
| 42 |
} |
| 43 |
|
| 44 |
$form_id = (int) $form->ID; |
| 45 |
$campaign_id = (int) $campaign_id; |
| 46 |
$unique_form_id = 'suredonation-form-' . $form_id . '-' . wp_rand(); |
| 47 |
$form_style = Form_Styling::get_style_attr( $form_id ); |
| 48 |
$custom_css = Form_Custom_CSS::get_style_block( $form_id ); |
| 49 |
$nonce_action = Helper::get_donation_nonce_action( $campaign_id ); |
| 50 |
$blocks = parse_blocks( $form->post_content ); |
| 51 |
|
| 52 |
// Marker class when default styling is disabled, so custom CSS can |
| 53 |
// target the unstyled state (get_style_attr already returned ''). |
| 54 |
$container_classes = 'sd-form-container'; |
| 55 |
if ( Form_Styling::is_default_styling_disabled( $form_id ) ) { |
| 56 |
$container_classes .= ' sd-styling-none'; |
| 57 |
} |
| 58 |
|
| 59 |
ob_start(); |
| 60 |
?> |
| 61 |
<div id="<?php echo esc_attr( $unique_form_id ); ?>" class="<?php echo esc_attr( $container_classes ); ?>" data-form-id="<?php echo esc_attr( (string) $form_id ); ?>" data-campaign-id="<?php echo esc_attr( (string) $campaign_id ); ?>"<?php echo '' !== $form_style ? ' style="' . esc_attr( $form_style ) . '"' : ''; ?>> |
| 62 |
<?php |
| 63 |
// Generated markup whose CSS is already sanitized by |
| 64 |
// Form_Custom_CSS::sanitize(). It must not go through |
| 65 |
// Helper::get_allowed_form_html() like the block output below: that |
| 66 |
// allowlist permits `style` attributes but not the `style` tag, so kses |
| 67 |
// would strip the whole block. |
| 68 |
echo $custom_css; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped |
| 69 |
?> |
| 70 |
<form class="sd-form" method="post"> |
| 71 |
<?php wp_nonce_field( $nonce_action, 'suredonation_nonce' ); ?> |
| 72 |
<input type="hidden" name="form_id" value="<?php echo esc_attr( (string) $form_id ); ?>"> |
| 73 |
<input type="hidden" name="campaign_id" value="<?php echo esc_attr( (string) $campaign_id ); ?>"> |
| 74 |
<?php if ( ! $campaign_id ) { ?> |
| 75 |
<input type="hidden" name="is_standalone" value="1"> |
| 76 |
<?php } ?> |
| 77 |
<input type="hidden" name="action" value="suredonation_submit_donation"> |
| 78 |
<?php Helper::render_honeypot_field(); ?> |
| 79 |
|
| 80 |
<?php |
| 81 |
// Privacy fields (consent / privacy policy / terms) enabled in the |
| 82 |
// Privacy settings are injected as the last thing before the submit |
| 83 |
// button so the donor sees them right before submitting. Anchor on the |
| 84 |
// donate button; if a form has none, fall back to the payment block, and |
| 85 |
// finally to the end of the form. The anchor may be nested inside a |
| 86 |
// layout block (Group/Columns), so match the top-level block that either |
| 87 |
// is, or contains, the anchor. |
| 88 |
$privacy_fields = \SureDonation\Inc\Privacy\Privacy_Frontend::render_form_fields(); |
| 89 |
$privacy_anchor = Helper::block_tree_contains( $blocks, 'suredonation/donate-button' ) ? 'suredonation/donate-button' : 'suredonation/payment'; |
| 90 |
$privacy_injected = false; |
| 91 |
foreach ( $blocks as $block ) { |
| 92 |
if ( empty( $block['blockName'] ) ) { |
| 93 |
continue; |
| 94 |
} |
| 95 |
$is_anchor = $block['blockName'] === $privacy_anchor |
| 96 |
|| ( ! empty( $block['innerBlocks'] ) && is_array( $block['innerBlocks'] ) && Helper::block_tree_contains( $block['innerBlocks'], $privacy_anchor ) ); |
| 97 |
if ( ! $privacy_injected && '' !== $privacy_fields && $is_anchor ) { |
| 98 |
echo wp_kses( $privacy_fields, Helper::get_allowed_form_html() ); |
| 99 |
$privacy_injected = true; |
| 100 |
} |
| 101 |
$block['attrs']['formId'] = $form_id; |
| 102 |
// Allow the data: protocol so a lazy-load optimizer's inline SVG |
| 103 |
// placeholder (Image block) survives this second kses pass. |
| 104 |
echo wp_kses( render_block( $block ), Helper::get_allowed_form_html(), array_merge( wp_allowed_protocols(), [ 'data' ] ) ); |
| 105 |
} |
| 106 |
if ( ! $privacy_injected && '' !== $privacy_fields ) { |
| 107 |
echo wp_kses( $privacy_fields, Helper::get_allowed_form_html() ); |
| 108 |
} |
| 109 |
?> |
| 110 |
</form> |
| 111 |
<!-- Success Message Container --> |
| 112 |
<div class="sd-single-form sd-success-box"> |
| 113 |
<div aria-live="polite" aria-atomic="true" role="alert" id="sd-success-message-<?php echo esc_attr( (string) $form_id ); ?>" class="sd-success-box-description"></div> |
| 114 |
</div> |
| 115 |
</div> |
| 116 |
<?php |
| 117 |
$output = ob_get_clean(); |
| 118 |
return false !== $output ? $output : ''; |
| 119 |
} |
| 120 |
} |
| 121 |
|