| @@ -7,14 +7,12 @@ | ||
| 7 | 7 | */ |
| 8 | 8 | |
| 9 | 9 | namespace SRFM\Inc; |
| 10 | 10 | |
| 11 | +use SRFM\Inc\AI_Form_Builder\AI_Helper; | |
| 12 | +use SRFM\Inc\Traits\Get_Instance; | |
| 13 | +use WP_Error; | |
| 11 | 14 | use WP_REST_Response; |
| 12 | -use WP_REST_Request; | |
| 13 | -use WP_Error; | |
| 14 | -use WP_Post_Type; | |
| 15 | -use SRFM\Inc\Traits\Get_Instance; | |
| 16 | -use SRFM\Inc\Helper; | |
| 17 | 15 | |
| 18 | 16 | if ( ! defined( 'ABSPATH' ) ) { |
| 19 | 17 | exit; // Exit if accessed directly. |
| 20 | 18 | } |
| @@ -48,68 +46,43 @@ | ||
| 48 | 46 | '/create-new-form', |
| 49 | 47 | [ |
| 50 | 48 | 'methods' => 'POST', |
| 51 | 49 | 'callback' => [ $this, 'create_form' ], |
| 52 | - 'permission_callback' => [ $this, 'get_items_permissions_check' ], | |
| 50 | + 'permission_callback' => [ Helper::class, 'get_items_permissions_check' ], | |
| 53 | 51 | ] |
| 54 | 52 | ); |
| 55 | 53 | } |
| 56 | 54 | |
| 57 | 55 | /** |
| 58 | - * Checks whether a given request has permission to create new forms. | |
| 59 | - * | |
| 60 | - * @param WP_REST_Request $request Full details about the request. | |
| 61 | - * @return true|WP_Error True if the request has read access, WP_Error object otherwise. | |
| 62 | - * @since 0.0.1 | |
| 63 | - */ | |
| 64 | - public function get_items_permissions_check( $request ) { | |
| 65 | - if ( current_user_can( 'edit_posts' ) ) { | |
| 66 | - return true; | |
| 67 | - } | |
| 68 | - foreach ( get_post_types( [ 'show_in_rest' => true ], 'objects' ) as $post_type ) { | |
| 69 | - /** | |
| 70 | - * The post type. | |
| 71 | - * | |
| 72 | - * @var WP_Post_Type $post_type | |
| 73 | - */ | |
| 74 | - if ( current_user_can( $post_type->cap->edit_posts ) ) { | |
| 75 | - return true; | |
| 76 | - } | |
| 77 | - } | |
| 78 | - | |
| 79 | - return new \WP_Error( | |
| 80 | - 'rest_cannot_view', | |
| 81 | - __( 'Sorry, you are not allowed to create forms.', 'sureforms' ), | |
| 82 | - [ 'status' => \rest_authorization_required_code() ] | |
| 83 | - ); | |
| 84 | - } | |
| 85 | - | |
| 86 | - /** | |
| 87 | 56 | * Get default post metas for form when creating using template. |
| 88 | 57 | * |
| 89 | - * @return array<string, array<int, int|string>> Default meta keys. | |
| 58 | + * @return array<string, int|string|bool> Default meta keys. | |
| 59 | + * @since 2.0.0 updated the return type. | |
| 90 | 60 | * @since 0.0.2 |
| 91 | 61 | */ |
| 92 | 62 | public static function get_default_meta_keys() { |
| 93 | - return [ | |
| 94 | - '_srfm_submit_button_text' => [ 'Submit' ], | |
| 95 | - '_srfm_use_label_as_placeholder' => [ '' ], | |
| 96 | - '_srfm_single_page_form_title' => [ 1 ], | |
| 97 | - '_srfm_instant_form' => [ '' ], | |
| 98 | - '_srfm_form_container_width' => [ 650 ], | |
| 99 | - '_srfm_bg_type' => [ 'image' ], | |
| 100 | - '_srfm_bg_image' => [ '' ], | |
| 101 | - '_srfm_cover_image' => [ '' ], | |
| 102 | - '_srfm_bg_color' => [ '#ffffff' ], | |
| 103 | - '_srfm_submit_width_backend' => [ 'max-content' ], | |
| 104 | - '_srfm_submit_alignment' => [ 'left' ], | |
| 105 | - '_srfm_submit_alignment_backend' => [ '100%' ], | |
| 106 | - '_srfm_submit_width' => [ '' ], | |
| 107 | - '_srfm_inherit_theme_button' => [ '' ], | |
| 108 | - '_srfm_additional_classes' => [ '' ], | |
| 109 | - '_srfm_submit_type' => [ 'message' ], | |
| 110 | - '_srfm_form_recaptcha' => [ 'none' ], | |
| 63 | + $default_values = [ | |
| 64 | + '_srfm_submit_button_text' => __( 'Submit', 'sureforms' ), | |
| 65 | + '_srfm_use_label_as_placeholder' => false, | |
| 66 | + '_srfm_single_page_form_title' => 1, | |
| 67 | + '_srfm_instant_form' => '', | |
| 68 | + '_srfm_form_container_width' => 650, | |
| 69 | + '_srfm_bg_type' => 'image', | |
| 70 | + '_srfm_bg_image' => '', | |
| 71 | + '_srfm_cover_image' => '', | |
| 72 | + '_srfm_bg_color' => '#ffffff', | |
| 73 | + '_srfm_submit_width_backend' => 'max-content', | |
| 74 | + '_srfm_submit_alignment' => 'left', | |
| 75 | + '_srfm_submit_alignment_backend' => '100%', | |
| 76 | + '_srfm_submit_width' => '', | |
| 77 | + '_srfm_inherit_theme_button' => false, | |
| 78 | + '_srfm_additional_classes' => '', | |
| 79 | + '_srfm_submit_type' => 'message', | |
| 80 | + '_srfm_form_recaptcha' => 'none', | |
| 81 | + '_srfm_is_inline_button' => false, // @since 2.0.0 -- adding required default value. | |
| 111 | 82 | ]; |
| 83 | + | |
| 84 | + return apply_filters( 'srfm_add_post_meta_defaults', $default_values ); | |
| 112 | 85 | } |
| 113 | 86 | |
| 114 | 87 | /** |
| 115 | 88 | * Create new form post from selected template. |
| @@ -155,49 +128,66 @@ | ||
| 155 | 128 | ); |
| 156 | 129 | } |
| 157 | 130 | } |
| 158 | 131 | |
| 159 | - $title = isset( $form_info_obj->template_name ) ? $form_info_obj->template_name : ''; | |
| 160 | - $content = isset( $form_info_obj->form_data ) ? $form_info_obj->form_data : ''; | |
| 161 | - $template_metas = isset( $form_info_obj->template_metas ) ? (array) $form_info_obj->template_metas : []; | |
| 132 | + $title = $form_info_obj->template_name ?? ''; | |
| 133 | + $content = $form_info_obj->form_data ?? ''; | |
| 162 | 134 | |
| 163 | - // if post content contains srfm/page-break block, then set _srfm_is_page_break meta to true. | |
| 164 | - if ( strpos( $content, 'srfm/page-break' ) !== false ) { | |
| 165 | - $template_metas['_srfm_is_page_break'] = [ 'true' ]; | |
| 166 | - } | |
| 135 | + // Create post metas for the creating form. | |
| 136 | + $post_metas = apply_filters( | |
| 137 | + 'srfm_modify_ai_post_metas', | |
| 138 | + [], | |
| 139 | + $form_info_obj, | |
| 140 | + ); | |
| 167 | 141 | |
| 168 | 142 | $post_id = wp_insert_post( |
| 169 | 143 | [ |
| 170 | 144 | 'post_title' => $title, |
| 171 | 145 | 'post_content' => $content, |
| 146 | + 'meta_input' => $post_metas, | |
| 172 | 147 | 'post_status' => 'draft', |
| 173 | 148 | 'post_type' => 'sureforms_form', |
| 174 | - ] | |
| 149 | + ], | |
| 150 | + true | |
| 175 | 151 | ); |
| 176 | 152 | |
| 177 | - if ( ! empty( $post_id ) ) { | |
| 178 | - if ( ! empty( $template_metas ) ) { | |
| 179 | - $default_post_metas = self::get_default_meta_keys(); | |
| 180 | - $post_metas = array_merge( $default_post_metas, $template_metas ); | |
| 181 | - | |
| 182 | - foreach ( $post_metas as $meta_key => $meta_value ) { | |
| 183 | - add_post_meta( $post_id, $meta_key, $meta_value[0] ); | |
| 184 | - } | |
| 153 | + if ( is_wp_error( $post_id ) ) { | |
| 154 | + // Pass the raw WP_Error through the shared sanitizer so any URLs, | |
| 155 | + // request IDs, or model names injected by a filter on | |
| 156 | + // wp_insert_post don't leak via the REST response. The raw message | |
| 157 | + // is still logged server-side (gated on WP_DEBUG / WP_DEBUG_LOG). | |
| 158 | + $sanitized = AI_Helper::sanitize_ai_error_message( $post_id->get_error_message(), 'wp_insert_post' ); | |
| 159 | + if ( '' === $sanitized ) { | |
| 160 | + $sanitized = __( 'Error creating SureForms Form.', 'sureforms' ); | |
| 185 | 161 | } |
| 186 | - | |
| 187 | 162 | return new WP_REST_Response( |
| 188 | 163 | [ |
| 189 | - 'message' => __( 'SureForms Form created successfully.', 'sureforms' ), | |
| 190 | - 'id' => $post_id, | |
| 191 | - ] | |
| 164 | + 'message' => $sanitized, | |
| 165 | + ], | |
| 166 | + 500 | |
| 192 | 167 | ); |
| 193 | - } else { | |
| 194 | - wp_send_json_error( | |
| 168 | + } | |
| 169 | + | |
| 170 | + if ( ! is_int( $post_id ) || $post_id <= 0 ) { | |
| 171 | + return new WP_REST_Response( | |
| 195 | 172 | [ |
| 196 | - 'message' => __( 'Error creating SureForms Form, ', 'sureforms' ), | |
| 197 | - ] | |
| 173 | + 'message' => __( 'Error creating SureForms Form.', 'sureforms' ), | |
| 174 | + ], | |
| 175 | + 500 | |
| 198 | 176 | ); |
| 199 | 177 | } |
| 178 | + | |
| 179 | + /** | |
| 180 | + * Update _srfm_is_ai_generated meta to true. | |
| 181 | + * If the request is coming here then the form is AI generated. | |
| 182 | + */ | |
| 183 | + update_post_meta( $post_id, '_srfm_is_ai_generated', true ); | |
| 184 | + | |
| 185 | + return new WP_REST_Response( | |
| 186 | + [ | |
| 187 | + 'message' => __( 'SureForms Form created successfully.', 'sureforms' ), | |
| 188 | + 'id' => $post_id, | |
| 189 | + ] | |
| 190 | + ); | |
| 200 | 191 | } |
| 201 | - | |
| 202 | 192 | |
| 203 | 193 | } |