PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | inc/global-settings/global-settings.php +581 -88 0.0.13 → 2.12.8 View file →
@@ -7,17 +7,22 @@
7 7 */
8 8
9 9 namespace SRFM\Inc\Global_Settings;
10 10
11 -use SRFM\Inc\Global_Settings\Email_Summary;
11 +use SRFM\Inc\Client_Logger;
12 12 use SRFM\Inc\Events_Scheduler;
13 +use SRFM\Inc\Helper;
14 +use SRFM\Inc\Payments\Payment_Helper;
13 15 use SRFM\Inc\Traits\Get_Instance;
14 -use SRFM\Inc\Helper;
16 +use WP_Error;
17 +use WP_REST_Request;
18 +use WP_REST_Response;
15 19 use WP_REST_Server;
16 -use WP_REST_Response;
17 -use WP_REST_Request;
18 -use WP_Error;
19 20
21 +if ( ! defined( 'ABSPATH' ) ) {
22 + exit;
23 +}
24 +
20 25 /**
21 26 * Sureforms Global Settings.
22 27 *
23 28 * @since 0.0.1
@@ -47,9 +52,8 @@
47 52 * @return void
48 53 * @since 0.0.1
49 54 */
50 55 public function register_custom_endpoint() {
51 - $sureforms_helper = new Helper();
52 56 register_rest_route(
53 57 $this->namespace,
54 58 '/srfm-global-settings',
55 59 [
@@ -54,9 +58,9 @@
54 58 '/srfm-global-settings',
55 59 [
56 60 'methods' => WP_REST_Server::EDITABLE,
57 61 'callback' => [ $this, 'srfm_save_global_settings' ],
58 - 'permission_callback' => [ $sureforms_helper, 'get_items_permissions_check' ],
62 + 'permission_callback' => [ Helper::class, 'get_items_permissions_check' ],
59 63 ]
60 64 );
61 65 register_rest_route(
62 66 $this->namespace,
@@ -63,9 +67,9 @@
63 67 '/srfm-global-settings',
64 68 [
65 69 'methods' => WP_REST_Server::READABLE,
66 70 'callback' => [ $this, 'srfm_get_general_settings' ],
67 - 'permission_callback' => [ $sureforms_helper, 'get_items_permissions_check' ],
71 + 'permission_callback' => [ Helper::class, 'get_items_permissions_check' ],
68 72 ]
69 73 );
70 74 }
71 75
@@ -81,48 +85,60 @@
81 85
82 86 $nonce = Helper::get_string_value( $request->get_header( 'X-WP-Nonce' ) );
83 87
84 88 if ( ! wp_verify_nonce( sanitize_text_field( $nonce ), 'wp_rest' ) ) {
85 - wp_send_json_error(
86 - [
87 - 'data' => __( 'Nonce verification failed.', 'sureforms' ),
88 - ]
89 - );
89 + return new WP_Error( 'rest_nonce_invalid', __( 'Nonce verification failed.', 'sureforms' ), [ 'status' => 403 ] );
90 90 }
91 91
92 92 $setting_options = $request->get_params();
93 93
94 - $tab = $setting_options['srfm_tab'];
94 + $tab = $setting_options['srfm_tab'] ?? '';
95 95
96 96 unset( $setting_options['srfm_tab'] );
97 97
98 98 switch ( $tab ) {
99 99 case 'general-settings':
100 - $is_option_saved = self::srfm_save_general_settings( $setting_options );
100 + self::srfm_save_general_settings( $setting_options );
101 101 break;
102 102 case 'general-settings-dynamic-opt':
103 - $is_option_saved = self::srfm_save_general_settings_dynamic_opt( $setting_options );
103 + self::srfm_save_general_settings_dynamic_opt( $setting_options );
104 104 break;
105 105 case 'email-settings':
106 - $is_option_saved = self::srfm_save_email_summary_settings( $setting_options );
106 + self::srfm_save_email_summary_settings( $setting_options );
107 107 break;
108 108 case 'security-settings':
109 - $is_option_saved = self::srfm_save_security_settings( $setting_options );
109 + self::srfm_save_security_settings( $setting_options );
110 110 break;
111 + case 'payments-settings':
112 + self::srfm_save_payments_settings( $setting_options );
113 + break;
114 + case 'mcp-settings':
115 + self::srfm_save_mcp_settings( $setting_options );
116 + break;
117 + case 'form-restriction-settings':
118 + self::srfm_save_form_restriction_settings( $setting_options );
119 + break;
120 + case 'compliance-settings':
121 + self::srfm_save_compliance_settings( $setting_options );
122 + break;
123 + case 'form-confirmation-settings':
124 + self::srfm_save_form_confirmation_settings( $setting_options );
125 + break;
126 + case 'email-notification-settings':
127 + self::srfm_save_email_notification_settings( $setting_options );
128 + break;
111 129 default:
112 - $is_option_saved = false;
113 - break;
130 + return new WP_Error( 'srfm_invalid_tab', __( 'Invalid settings tab.', 'sureforms' ), [ 'status' => 400 ] );
114 131 }
115 132
116 - if ( ! $is_option_saved ) {
117 - return new WP_Error( 'Error Saving Settings!', 'Global Settings' );
118 - } else {
119 - return new WP_REST_Response(
120 - [
121 - 'data' => __( 'Settings Saved Successfully.', 'sureforms' ),
122 - ]
123 - );
124 - }
133 + // update_option() returns false when the stored value already matches
134 + // the new value — that is not an error, so we only flag truly invalid
135 + // tabs (handled in default above) and always return success here.
136 + return new WP_REST_Response(
137 + [
138 + 'data' => __( 'Settings Saved Successfully.', 'sureforms' ),
139 + ]
140 + );
125 141 }
126 142
127 143 /**
128 144 * Save General Settings
@@ -132,24 +148,64 @@
132 148 * @since 0.0.1
133 149 */
134 150 public static function srfm_save_general_settings( $setting_options ) {
135 151
136 - $srfm_ip_log = isset( $setting_options['srfm_ip_log'] ) ? $setting_options['srfm_ip_log'] : false;
137 - $srfm_honeypot = isset( $setting_options['srfm_honeypot'] ) ? $setting_options['srfm_honeypot'] : false;
138 - $srfm_form_analytics = isset( $setting_options['srfm_form_analytics'] ) ? $setting_options['srfm_form_analytics'] : false;
152 + $srfm_ip_log = $setting_options['srfm_ip_log'] ?? false;
153 + $srfm_form_analytics = $setting_options['srfm_form_analytics'] ?? false;
154 + $srfm_bsf_analytics = $setting_options['srfm_bsf_analytics'] ?? false;
155 + $srfm_admin_notification = isset( $setting_options['srfm_admin_notification'] ) ? (bool) $setting_options['srfm_admin_notification'] : true;
156 + $srfm_form_views_tracking = isset( $setting_options['srfm_form_views_tracking'] ) ? (bool) $setting_options['srfm_form_views_tracking'] : false;
157 + // Absent means on, matching Client_Logger::is_enabled(). A save that omits
158 + // the key must not be read as the site opting out.
159 + $srfm_enable_logs = isset( $setting_options['srfm_enable_logs'] ) ? (bool) $setting_options['srfm_enable_logs'] : true;
139 160
140 - return update_option(
141 - 'srfm_general_settings_options',
142 - [
143 - 'srfm_ip_log' => $srfm_ip_log,
144 - 'srfm_honeypot' => $srfm_honeypot,
145 - 'srfm_form_analytics' => $srfm_form_analytics,
146 - ]
147 - );
161 + $settings = [
162 + 'srfm_ip_log' => $srfm_ip_log,
163 + 'srfm_form_analytics' => $srfm_form_analytics,
164 + 'srfm_admin_notification' => $srfm_admin_notification,
165 + 'srfm_form_views_tracking' => $srfm_form_views_tracking,
166 + 'srfm_enable_logs' => $srfm_enable_logs,
167 + ];
148 168
169 + /**
170 + * We are updating sureforms_analytics_optin option from the general settings as it has been introduced
171 + * as part of general settings. Since the option sureforms_analytics_optin is already available from BSF analytics library
172 + * We are updating this independently.
173 + *
174 + * @since 1.7.0
175 + *
176 + * @since 2.5.1 - Renamed sureforms_analytics_optin to sureforms_usage_optin.
177 + */
178 + $analytics_result = self::update_bsf_analytics( $srfm_bsf_analytics );
179 +
180 + $general_result = update_option( 'srfm_general_settings_options', $settings );
181 +
182 + /**
183 + * Returns the output of update_bsf_analytics or srfm_general_settings_options option.
184 + *
185 + * @since 1.7.0
186 + */
187 + return $analytics_result || $general_result;
149 188 }
150 189
151 190 /**
191 + * Toggle BSF analytics usage tracking in WP general settings.
192 + *
193 + * @param array<mixed> $settings general settings array.
194 + * @return bool
195 + * @since 1.7.0
196 + */
197 + public static function update_bsf_analytics( $settings ) {
198 + if ( true === $settings ) {
199 + $enable_tracking = 'yes';
200 + } else {
201 + $enable_tracking = '';
202 + }
203 +
204 + return update_option( 'sureforms_usage_optin', $enable_tracking );
205 + }
206 +
207 + /**
152 208 * Save General Settings Dynamic Options
153 209 *
154 210 * @param array<mixed> $setting_options Setting options.
155 211 * @return bool
@@ -155,28 +211,51 @@
155 211 * @return bool
156 212 * @since 0.0.1
157 213 */
158 214 public static function srfm_save_general_settings_dynamic_opt( $setting_options ) {
215 + $options_keys = [
216 + 'srfm_url_block_required_text',
217 + 'srfm_input_block_required_text',
218 + 'srfm_input_block_unique_text',
219 + 'srfm_address_block_required_text',
220 + 'srfm_phone_block_required_text',
221 + 'srfm_phone_block_unique_text',
222 + 'srfm_number_block_required_text',
223 + 'srfm_textarea_block_required_text',
224 + 'srfm_multi_choice_block_required_text',
225 + 'srfm_checkbox_block_required_text',
226 + 'srfm_gdpr_block_required_text',
227 + 'srfm_email_block_required_text',
228 + 'srfm_email_block_unique_text',
229 + 'srfm_dropdown_block_required_text',
230 + 'srfm_valid_phone_number',
231 + 'srfm_valid_url',
232 + 'srfm_confirm_email_same',
233 + 'srfm_valid_email',
234 + 'srfm_textarea_min_chars',
235 + 'srfm_email_local_max_length',
236 + 'srfm_email_domain_max_length',
237 + 'srfm_input_min_value',
238 + 'srfm_input_max_value',
239 + 'srfm_dropdown_min_selections',
240 + 'srfm_dropdown_max_selections',
241 + 'srfm_multi_choice_min_selections',
242 + 'srfm_multi_choice_max_selections',
243 + ];
159 244
160 - $options_names = [
161 - 'srfm_url_block_required_text' => $setting_options['srfm_url_block_required_text'],
162 - 'srfm_input_block_required_text' => $setting_options['srfm_input_block_required_text'],
163 - 'srfm_input_block_unique_text' => $setting_options['srfm_input_block_unique_text'],
164 - 'srfm_address_block_required_text' => $setting_options['srfm_address_block_required_text'],
165 - 'srfm_phone_block_required_text' => $setting_options['srfm_phone_block_required_text'],
166 - 'srfm_phone_block_unique_text' => $setting_options['srfm_phone_block_unique_text'],
167 - 'srfm_number_block_required_text' => $setting_options['srfm_number_block_required_text'],
168 - 'srfm_textarea_block_required_text' => $setting_options['srfm_textarea_block_required_text'],
169 - 'srfm_multi_choice_block_required_text' => $setting_options['srfm_multi_choice_block_required_text'],
170 - 'srfm_checkbox_block_required_text' => $setting_options['srfm_checkbox_block_required_text'],
171 - 'srfm_gdpr_block_required_text' => $setting_options['srfm_gdpr_block_required_text'],
172 - 'srfm_email_block_required_text' => $setting_options['srfm_email_block_required_text'],
173 - 'srfm_email_block_unique_text' => $setting_options['srfm_email_block_unique_text'],
174 - 'srfm_dropdown_block_required_text' => $setting_options['srfm_dropdown_block_required_text'],
175 - ];
245 + $options_names = [];
176 246
177 - return update_option( 'get_default_dynamic_block_option', apply_filters( 'srfm_general_dynamic_options_to_save', $options_names, $setting_options ) );
247 + foreach ( $options_keys as $key ) {
248 + if ( isset( $setting_options[ $key ] ) ) {
249 + $value = $setting_options[ $key ];
250 + $options_names[ $key ] = sanitize_text_field( is_scalar( $value ) ? (string) $value : '' );
251 + }
252 + }
178 253
254 + // Re-sanitize after filter so Pro-injected keys are also covered.
255 + $options_to_save = apply_filters( 'srfm_general_dynamic_options_to_save', $options_names, $setting_options );
256 + $options_to_save = array_map( 'sanitize_text_field', $options_to_save );
257 + return update_option( 'srfm_default_dynamic_block_option', $options_to_save );
179 258 }
180 259
181 260 /**
182 261 * Save Email Summary Settings
@@ -186,11 +265,11 @@
186 265 * @since 0.0.1
187 266 */
188 267 public static function srfm_save_email_summary_settings( $setting_options ) {
189 268
190 - $srfm_email_summary = isset( $setting_options['srfm_email_summary'] ) ? $setting_options['srfm_email_summary'] : false;
191 - $srfm_email_sent_to = isset( $setting_options['srfm_email_sent_to'] ) ? $setting_options['srfm_email_sent_to'] : get_option( 'admin_email' );
192 - $srfm_schedule_report = isset( $setting_options['srfm_schedule_report'] ) ? $setting_options['srfm_schedule_report'] : 'Monday';
269 + $srfm_email_summary = $setting_options['srfm_email_summary'] ?? false;
270 + $srfm_email_sent_to = sanitize_email( $setting_options['srfm_email_sent_to'] ?? get_option( 'admin_email' ) );
271 + $srfm_schedule_report = $setting_options['srfm_schedule_report'] ?? __( 'Monday', 'sureforms' );
193 272
194 273 Events_Scheduler::unschedule_events( 'srfm_weekly_scheduled_events' );
195 274
196 275 if ( $srfm_email_summary ) {
@@ -215,19 +294,20 @@
215 294 * @since 0.0.1
216 295 */
217 296 public static function srfm_save_security_settings( $setting_options ) {
218 297
219 - $srfm_v2_checkbox_site_key = isset( $setting_options['srfm_v2_checkbox_site_key'] ) ? $setting_options['srfm_v2_checkbox_site_key'] : '';
220 - $srfm_v2_checkbox_secret_key = isset( $setting_options['srfm_v2_checkbox_secret_key'] ) ? $setting_options['srfm_v2_checkbox_secret_key'] : '';
221 - $srfm_v2_invisible_site_key = isset( $setting_options['srfm_v2_invisible_site_key'] ) ? $setting_options['srfm_v2_invisible_site_key'] : '';
222 - $srfm_v2_invisible_secret_key = isset( $setting_options['srfm_v2_invisible_secret_key'] ) ? $setting_options['srfm_v2_invisible_secret_key'] : '';
223 - $srfm_v3_site_key = isset( $setting_options['srfm_v3_site_key'] ) ? $setting_options['srfm_v3_site_key'] : '';
224 - $srfm_v3_secret_key = isset( $setting_options['srfm_v3_secret_key'] ) ? $setting_options['srfm_v3_secret_key'] : '';
225 - $srfm_cf_appearance_mode = isset( $setting_options['srfm_cf_appearance_mode'] ) ? $setting_options['srfm_cf_appearance_mode'] : 'auto';
226 - $srfm_cf_turnstile_site_key = isset( $setting_options['srfm_cf_turnstile_site_key'] ) ? $setting_options['srfm_cf_turnstile_site_key'] : '';
227 - $srfm_cf_turnstile_secret_key = isset( $setting_options['srfm_cf_turnstile_secret_key'] ) ? $setting_options['srfm_cf_turnstile_secret_key'] : '';
228 - $srfm_hcaptcha_site_key = ! empty( $setting_options['srfm_hcaptcha_site_key'] ) ? $setting_options['srfm_hcaptcha_site_key'] : '';
229 - $srfm_hcaptcha_secret_key = ! empty( $setting_options['srfm_hcaptcha_secret_key'] ) ? $setting_options['srfm_hcaptcha_secret_key'] : '';
298 + $srfm_v2_checkbox_site_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_v2_checkbox_site_key'] ?? '' ) );
299 + $srfm_v2_checkbox_secret_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_v2_checkbox_secret_key'] ?? '' ) );
300 + $srfm_v2_invisible_site_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_v2_invisible_site_key'] ?? '' ) );
301 + $srfm_v2_invisible_secret_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_v2_invisible_secret_key'] ?? '' ) );
302 + $srfm_v3_site_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_v3_site_key'] ?? '' ) );
303 + $srfm_v3_secret_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_v3_secret_key'] ?? '' ) );
304 + $srfm_cf_appearance_mode = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_cf_appearance_mode'] ?? 'auto' ) );
305 + $srfm_cf_turnstile_site_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_cf_turnstile_site_key'] ?? '' ) );
306 + $srfm_cf_turnstile_secret_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_cf_turnstile_secret_key'] ?? '' ) );
307 + $srfm_hcaptcha_site_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_hcaptcha_site_key'] ?? '' ) );
308 + $srfm_hcaptcha_secret_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_hcaptcha_secret_key'] ?? '' ) );
309 + $srfm_honeypot = $setting_options['srfm_honeypot'] ?? false;
230 310
231 311 return update_option(
232 312 'srfm_security_settings_options',
233 313 [
@@ -241,18 +321,315 @@
241 321 'srfm_cf_turnstile_site_key' => $srfm_cf_turnstile_site_key,
242 322 'srfm_cf_turnstile_secret_key' => $srfm_cf_turnstile_secret_key,
243 323 'srfm_hcaptcha_site_key' => $srfm_hcaptcha_site_key,
244 324 'srfm_hcaptcha_secret_key' => $srfm_hcaptcha_secret_key,
325 + 'srfm_honeypot' => $srfm_honeypot,
245 326 ]
246 327 );
328 + }
247 329
330 + /**
331 + * Save Payments Settings
332 + *
333 + * Handles saving of both global payment settings (currency, payment_mode) and
334 + * gateway-specific settings based on the gateway parameter.
335 + *
336 + * @param array<mixed> $setting_options Setting options.
337 + * @return bool
338 + * @since 2.0.0
339 + */
340 + public static function srfm_save_payments_settings( $setting_options ) {
341 + $gateway = isset( $setting_options['gateway'] ) && is_string( $setting_options['gateway'] )
342 + ? sanitize_text_field( $setting_options['gateway'] )
343 + : 'stripe';
344 +
345 + // Handle global settings (currency, payment_mode).
346 + if ( isset( $setting_options['currency'] ) && ! empty( $setting_options['currency'] ) && is_string( $setting_options['currency'] ) ) {
347 + $currency = sanitize_text_field( $setting_options['currency'] );
348 + Payment_Helper::update_global_setting( 'currency', $currency );
349 + }
350 +
351 + $payment_mode = null;
352 + if ( isset( $setting_options['payment_mode'] ) && ! empty( $setting_options['payment_mode'] ) && is_string( $setting_options['payment_mode'] ) ) {
353 + $payment_mode = sanitize_text_field( $setting_options['payment_mode'] );
354 + Payment_Helper::update_global_setting( 'payment_mode', $payment_mode );
355 + }
356 +
357 + // Save currency sign position.
358 + if ( isset( $setting_options['currency_sign_position'] ) && ! empty( $setting_options['currency_sign_position'] ) && is_string( $setting_options['currency_sign_position'] ) ) {
359 + $currency_sign_position = sanitize_text_field( $setting_options['currency_sign_position'] );
360 + Payment_Helper::update_global_setting( 'currency_sign_position', $currency_sign_position );
361 + }
362 +
363 + // Handle gateway-specific settings.
364 + if ( 'stripe' === $gateway ) {
365 + $current_stripe_settings = Payment_Helper::get_gateway_settings( 'stripe' );
366 +
367 + // Update payment_mode in stripe settings as well (if provided).
368 + if ( null !== $payment_mode ) {
369 + $current_stripe_settings['payment_mode'] = $payment_mode;
370 + }
371 +
372 + // Connection data (keys, account info) is managed separately via OAuth.
373 + return Payment_Helper::update_gateway_settings( 'stripe', $current_stripe_settings );
374 + }
375 +
376 + return true;
248 377 }
249 378
250 379 /**
380 + * Save MCP Settings
381 + *
382 + * @param array<mixed> $setting_options Setting options.
383 + * @return bool
384 + * @since 2.6.0
385 + */
386 + public static function srfm_save_mcp_settings( $setting_options ) {
387 + $srfm_abilities_api = ! empty( $setting_options['srfm_abilities_api'] );
388 + $srfm_abilities_api_edit = ! empty( $setting_options['srfm_abilities_api_edit'] );
389 + $srfm_abilities_api_delete = ! empty( $setting_options['srfm_abilities_api_delete'] );
390 + $srfm_mcp_server = ! empty( $setting_options['srfm_mcp_server'] );
391 +
392 + // Save as individual options for the Abilities API permission_callback.
393 + update_option( 'srfm_abilities_api', $srfm_abilities_api );
394 + update_option( 'srfm_abilities_api_edit', $srfm_abilities_api_edit );
395 + update_option( 'srfm_abilities_api_delete', $srfm_abilities_api_delete );
396 + update_option( 'srfm_mcp_server', $srfm_mcp_server );
397 +
398 + // Save grouped option for the settings UI fetch.
399 + return update_option(
400 + 'srfm_mcp_settings_options',
401 + [
402 + 'srfm_abilities_api' => $srfm_abilities_api,
403 + 'srfm_abilities_api_edit' => $srfm_abilities_api_edit,
404 + 'srfm_abilities_api_delete' => $srfm_abilities_api_delete,
405 + 'srfm_mcp_server' => $srfm_mcp_server,
406 + ]
407 + );
408 + }
409 +
410 + /**
411 + * Save Form Restriction Settings
412 + *
413 + * Handles saving of the free Maximum Entries subsection. Pro-only
414 + * subsections (IP, Country, Keyword) are persisted via the Pro plugin's
415 + * own REST endpoint and option key, so the existing values for those
416 + * sub-keys are preserved here via array merge.
417 + *
418 + * @param array<mixed> $setting_options Setting options.
419 + * @return bool
420 + * @since 2.9.0
421 + */
422 + public static function srfm_save_form_restriction_settings( $setting_options ) {
423 + $max_entries = isset( $setting_options['max_entries'] ) && is_array( $setting_options['max_entries'] ) ? $setting_options['max_entries'] : [];
424 +
425 + $existing = get_option( 'srfm_form_restriction_settings_options', [] );
426 + if ( ! is_array( $existing ) ) {
427 + $existing = [];
428 + }
429 +
430 + $settings = $existing;
431 + $settings['max_entries'] = [
432 + 'status' => isset( $max_entries['status'] ) ? (bool) $max_entries['status'] : false,
433 + 'maxEntries' => isset( $max_entries['maxEntries'] ) ? absint( $max_entries['maxEntries'] ) : 0,
434 + 'message' => isset( $max_entries['message'] ) ? sanitize_textarea_field( (string) $max_entries['message'] ) : __( "This form is now closed as we've received all the entries.", 'sureforms' ),
435 + ];
436 +
437 + return update_option( 'srfm_form_restriction_settings_options', $settings );
438 + }
439 +
440 + /**
441 + * Save Compliance Settings
442 + *
443 + * Handles saving of global compliance settings that serve as defaults
444 + * for newly created forms.
445 + *
446 + * @param array<mixed> $setting_options Setting options.
447 + * @return bool
448 + * @since 2.9.0
449 + */
450 + public static function srfm_save_compliance_settings( $setting_options ) {
451 + $settings = [
452 + 'gdpr' => isset( $setting_options['gdpr'] ) ? (bool) $setting_options['gdpr'] : false,
453 + 'do_not_store_entries' => isset( $setting_options['do_not_store_entries'] ) ? (bool) $setting_options['do_not_store_entries'] : false,
454 + 'auto_delete_entries' => isset( $setting_options['auto_delete_entries'] ) ? (bool) $setting_options['auto_delete_entries'] : false,
455 + 'auto_delete_days' => isset( $setting_options['auto_delete_days'] ) ? absint( $setting_options['auto_delete_days'] ) : 30,
456 + ];
457 +
458 + return update_option( 'srfm_compliance_settings_options', $settings );
459 + }
460 +
461 + /**
462 + * Get default compliance settings.
463 + *
464 + * @return array<string, mixed>
465 + * @since 2.9.0
466 + */
467 + public static function get_default_compliance_settings() {
468 + return [
469 + 'gdpr' => false,
470 + 'do_not_store_entries' => false,
471 + 'auto_delete_entries' => false,
472 + 'auto_delete_days' => 30,
473 + ];
474 + }
475 +
476 + /**
477 + * Save Form Confirmation Settings
478 + *
479 + * Handles saving of global form confirmation settings that serve as defaults
480 + * for newly created forms.
481 + *
482 + * @param array<mixed> $setting_options Setting options.
483 + * @return bool
484 + * @since 2.9.0
485 + */
486 + public static function srfm_save_form_confirmation_settings( $setting_options ) {
487 + $valid_confirmation_types = [ 'same page', 'different page', 'custom url' ];
488 + $valid_submission_actions = [ 'hide form', 'reset form' ];
489 +
490 + $message = isset( $setting_options['message'] ) ? wp_kses_post( Helper::get_string_value( $setting_options['message'] ) ) : __( 'Thank you for contacting us! We will be in touch with you shortly.', 'sureforms' );
491 +
492 + // Sanitize query parameters — each item is a key-value object.
493 + $query_params = [];
494 + if ( isset( $setting_options['query_params'] ) && is_array( $setting_options['query_params'] ) ) {
495 + foreach ( $setting_options['query_params'] as $param ) {
496 + if ( is_array( $param ) ) {
497 + $sanitized_param = [];
498 + foreach ( $param as $key => $value ) {
499 + $sanitized_param[ sanitize_text_field( $key ) ] = sanitize_text_field( $value );
500 + }
501 + $query_params[] = $sanitized_param;
502 + }
503 + }
504 + }
505 +
506 + $settings = [
507 + 'confirmation_type' => isset( $setting_options['confirmation_type'] ) && in_array( $setting_options['confirmation_type'], $valid_confirmation_types, true )
508 + ? sanitize_text_field( $setting_options['confirmation_type'] )
509 + : 'same page',
510 + 'message' => $message,
511 + 'submission_action' => isset( $setting_options['submission_action'] ) && in_array( $setting_options['submission_action'], $valid_submission_actions, true )
512 + ? sanitize_text_field( $setting_options['submission_action'] )
513 + : 'hide form',
514 + 'page_url' => isset( $setting_options['page_url'] ) ? esc_url_raw( $setting_options['page_url'] ) : '',
515 + 'custom_url' => isset( $setting_options['custom_url'] ) ? esc_url_raw( $setting_options['custom_url'] ) : '',
516 + 'enable_query_params' => ! empty( $setting_options['enable_query_params'] ),
517 + 'query_params' => $query_params,
518 + ];
519 +
520 + return update_option( 'srfm_form_confirmation_settings_options', $settings );
521 + }
522 +
523 + /**
524 + * Get the default confirmation success message HTML.
525 + *
526 + * Builds the rich HTML block (icon + heading + description) used as the
527 + * initial value for the form confirmation message field. Centralised here
528 + * so both the settings GET endpoint and the form-defaults applier share
529 + * exactly the same value without duplication.
530 + *
531 + * @return string
532 + * @since 2.9.0
533 + */
534 + public static function get_default_confirmation_message() {
535 + $check_icon = esc_url( plugins_url( 'images/check-icon.svg', SRFM_FILE ) );
536 + return '<p style="text-align: center;"><img src="' . $check_icon . '" alt="" aria-hidden="true" /></p><h2 style="text-align: center;">'
537 + . esc_html__( 'Thank you', 'sureforms' ) . '</h2><p style="text-align: center;">'
538 + . esc_html__( 'Your form has been submitted successfully. We\'ll review your details and get back to you soon.', 'sureforms' ) . '</p>';
539 + }
540 +
541 + /**
542 + * Get default form confirmation settings.
543 + *
544 + * @return array<string, mixed>
545 + * @since 2.9.0
546 + */
547 + public static function get_default_form_confirmation_settings() {
548 + return [
549 + 'confirmation_type' => 'same page',
550 + 'message' => self::get_default_confirmation_message(),
551 + 'submission_action' => 'hide form',
552 + 'page_url' => '',
553 + 'custom_url' => '',
554 + 'enable_query_params' => false,
555 + 'query_params' => [],
556 + ];
557 + }
558 +
559 + /**
560 + * Save Email Notification Settings
561 + *
562 + * Handles saving of global email notification settings that serve as defaults
563 + * for newly created forms.
564 + *
565 + * @param array<mixed> $setting_options Setting options.
566 + * @return bool
567 + * @since 2.9.0
568 + */
569 + public static function srfm_save_email_notification_settings( $setting_options ) {
570 + $settings = [
571 + 'email_to' => isset( $setting_options['email_to'] ) ? sanitize_text_field( Helper::get_string_value( $setting_options['email_to'] ) ) : '',
572 + 'subject' => isset( $setting_options['subject'] ) ? sanitize_text_field( Helper::get_string_value( $setting_options['subject'] ) ) : '',
573 + 'email_body' => isset( $setting_options['email_body'] ) ? wp_kses_post( Helper::get_string_value( $setting_options['email_body'] ) ) : '',
574 + 'from_name' => isset( $setting_options['from_name'] ) ? sanitize_text_field( Helper::get_string_value( $setting_options['from_name'] ) ) : '{site_title}',
575 + 'from_email' => isset( $setting_options['from_email'] ) ? sanitize_text_field( Helper::get_string_value( $setting_options['from_email'] ) ) : '{admin_email}',
576 + 'email_cc' => isset( $setting_options['email_cc'] ) ? sanitize_text_field( Helper::get_string_value( $setting_options['email_cc'] ) ) : '',
577 + 'email_bcc' => isset( $setting_options['email_bcc'] ) ? sanitize_text_field( Helper::get_string_value( $setting_options['email_bcc'] ) ) : '',
578 + 'email_reply_to' => isset( $setting_options['email_reply_to'] ) ? sanitize_text_field( Helper::get_string_value( $setting_options['email_reply_to'] ) ) : '',
579 + ];
580 +
581 + return update_option( 'srfm_email_notification_settings_options', $settings );
582 + }
583 +
584 + /**
585 + * Get default email notification settings.
586 + *
587 + * @return array<string, mixed>
588 + * @since 2.9.0
589 + */
590 + public static function get_default_email_notification_settings() {
591 + return [
592 + 'email_to' => '{admin_email}',
593 + 'subject' => sprintf(
594 + /* translators: %s: {form_title} smart tag placeholder. */
595 + __( 'New Form Submission - %s', 'sureforms' ),
596 + '{form_title}'
597 + ),
598 + 'email_body' => '{all_data}',
599 + 'from_name' => '{site_title}',
600 + 'from_email' => '{admin_email}',
601 + 'email_cc' => '{admin_email}',
602 + 'email_bcc' => '{admin_email}',
603 + 'email_reply_to' => '{admin_email}',
604 + ];
605 + }
606 +
607 + /**
608 + * Get default form restriction settings.
609 + *
610 + * Free only ships defaults for the Maximum Entries subsection. Pro-only
611 + * subsections (IP, Country, Keyword) ship their own defaults from the
612 + * Pro plugin.
613 + *
614 + * @return array<string, array<string, mixed>>
615 + * @since 2.9.0
616 + */
617 + public static function get_default_form_restriction_settings() {
618 + return [
619 + 'max_entries' => [
620 + 'status' => false,
621 + 'maxEntries' => 0,
622 + 'message' => __( "This form is now closed as we've received all the entries.", 'sureforms' ),
623 + ],
624 + ];
625 + }
626 +
627 + /**
251 628 * Get Settings Form Data
252 629 *
253 630 * @param \WP_REST_Request $request Request object or array containing form data.
254 - * @return void
631 + * @return WP_REST_Response|WP_Error
255 632 * @since 0.0.1
256 633 */
257 634 public static function srfm_get_general_settings( $request ) {
258 635
@@ -258,13 +635,9 @@
258 635
259 636 $nonce = Helper::get_string_value( $request->get_header( 'X-WP-Nonce' ) );
260 637
261 638 if ( ! wp_verify_nonce( sanitize_text_field( $nonce ), 'wp_rest' ) ) {
262 - wp_send_json_error(
263 - [
264 - 'data' => __( 'Nonce verification failed.', 'sureforms' ),
265 - ]
266 - );
639 + return new WP_Error( 'rest_nonce_invalid', __( 'Nonce verification failed.', 'sureforms' ), [ 'status' => 403 ] );
267 640 }
268 641
269 642 $options_to_get = $request->get_param( 'options_to_fetch' );
270 643
@@ -271,25 +644,73 @@
271 644 $options_to_get = Helper::get_string_value( $options_to_get );
272 645
273 646 $options_to_get = explode( ',', $options_to_get );
274 647
275 - $global_setting_options = get_options( $options_to_get );
648 + // Restrict fetched keys to known plugin options to prevent reading
649 + // arbitrary wp_options values (even though manage_options is required).
650 + $allowed_options = [
651 + 'srfm_general_settings_options',
652 + 'srfm_email_summary_settings_options',
653 + 'srfm_security_settings_options',
654 + 'srfm_default_dynamic_block_option',
655 + 'srfm_mcp_settings_options',
656 + 'srfm_form_restriction_settings_options',
657 + 'srfm_compliance_settings_options',
658 + 'srfm_form_confirmation_settings_options',
659 + 'srfm_email_notification_settings_options',
660 + ];
661 + $options_to_get = array_values( array_intersect( array_map( 'sanitize_text_field', $options_to_get ), $allowed_options ) );
276 662
277 - if ( empty( $global_setting_options['srfm_general_settings_options'] ) ) {
278 - $global_setting_options['srfm_general_settings_options'] = [
279 - 'srfm_ip_log' => false,
280 - 'srfm_honeypot' => false,
281 - 'srfm_form_analytics' => false,
282 - ];
663 + $global_setting_options = [];
664 + foreach ( $options_to_get as $option_name ) {
665 + $global_setting_options[ $option_name ] = get_option( $option_name, [] );
283 666 }
284 - if ( empty( $global_setting_options['get_default_dynamic_block_option'] ) ) {
285 - $global_setting_options['get_default_dynamic_block_option'] = Helper::default_dynamic_block_option();
667 +
668 + if ( empty( $global_setting_options['srfm_general_settings_options'] ) || ! is_array( $global_setting_options['srfm_general_settings_options'] ) ) {
669 + $global_setting_options['srfm_general_settings_options'] = [
670 + 'srfm_ip_log' => false,
671 + 'srfm_form_analytics' => false,
672 + 'srfm_admin_notification' => true,
673 + 'srfm_form_views_tracking' => false,
674 + 'srfm_enable_logs' => true,
675 + ];
286 676 }
677 +
678 + if ( ! isset( $global_setting_options['srfm_general_settings_options']['srfm_admin_notification'] ) ) {
679 + $global_setting_options['srfm_general_settings_options']['srfm_admin_notification'] = true;
680 + }
681 +
682 + if ( ! isset( $global_setting_options['srfm_general_settings_options']['srfm_form_views_tracking'] ) ) {
683 + $global_setting_options['srfm_general_settings_options']['srfm_form_views_tracking'] = false;
684 + }
685 +
686 + // Back-fill for installs whose option predates the setting. Logging is on by
687 + // default, so an absent key means on, not off.
688 + if ( ! isset( $global_setting_options['srfm_general_settings_options']['srfm_enable_logs'] ) ) {
689 + $global_setting_options['srfm_general_settings_options']['srfm_enable_logs'] = true;
690 + }
691 +
692 + $global_setting_options['srfm_log_file_size'] = Client_Logger::get_file_size();
693 +
694 + /**
695 + * We have introduced toggle for analytics optin in the general settings.
696 + * Hence retrieving the option sureforms_analytics_optin to get current status.
697 + *
698 + * @since 1.7.0
699 + *
700 + * @since 2.5.1 - Renamed sureforms_analytics_optin to sureforms_usage_optin.
701 + */
702 + $srfm_bsf_analytics = get_option( 'sureforms_usage_optin', false ) === 'yes' ? true : false;
703 + $global_setting_options['srfm_general_settings_options']['srfm_bsf_analytics'] = $srfm_bsf_analytics;
704 +
705 + if ( empty( $global_setting_options['srfm_default_dynamic_block_option'] ) ) {
706 + $global_setting_options['srfm_default_dynamic_block_option'] = Helper::default_dynamic_block_option();
707 + }
287 708 if ( empty( $global_setting_options['srfm_email_summary_settings_options'] ) ) {
288 709 $global_setting_options['srfm_email_summary_settings_options'] = [
289 710 'srfm_email_summary' => false,
290 711 'srfm_email_sent_to' => get_option( 'admin_email' ),
291 - 'srfm_schedule_report' => 'Monday',
712 + 'srfm_schedule_report' => __( 'Monday', 'sureforms' ),
292 713 ];
293 714 }
294 715 if ( empty( $global_setting_options['srfm_security_settings_options'] ) ) {
295 716 $global_setting_options['srfm_security_settings_options'] = [
@@ -303,11 +724,83 @@
303 724 'srfm_cf_turnstile_site_key' => '',
304 725 'srfm_cf_turnstile_secret_key' => '',
305 726 'srfm_hcaptcha_site_key' => '',
306 727 'srfm_hcaptcha_secret_key' => '',
728 + 'srfm_honeypot' => false,
307 729 ];
308 730 }
309 731
310 - wp_send_json( $global_setting_options );
732 + if ( empty( $global_setting_options['srfm_mcp_settings_options'] ) ) {
733 + $global_setting_options['srfm_mcp_settings_options'] = [
734 + 'srfm_abilities_api' => (bool) get_option( 'srfm_abilities_api', false ),
735 + 'srfm_abilities_api_edit' => (bool) get_option( 'srfm_abilities_api_edit', false ),
736 + 'srfm_abilities_api_delete' => (bool) get_option( 'srfm_abilities_api_delete', false ),
737 + 'srfm_mcp_server' => (bool) get_option( 'srfm_mcp_server', false ),
738 + ];
739 + }
740 +
741 + // Get form restriction settings with defaults.
742 + $form_restriction_settings = get_option( 'srfm_form_restriction_settings_options', [] );
743 + if ( empty( $form_restriction_settings ) || ! is_array( $form_restriction_settings ) ) {
744 + $form_restriction_settings = self::get_default_form_restriction_settings();
745 + } else {
746 + // Merge with defaults to ensure all keys exist.
747 + $form_restriction_settings = array_replace_recursive(
748 + self::get_default_form_restriction_settings(),
749 + $form_restriction_settings
750 + );
751 + }
752 + $global_setting_options['srfm_form_restriction_settings_options'] = $form_restriction_settings;
753 +
754 + // Get compliance settings with defaults.
755 + $compliance_settings = get_option( 'srfm_compliance_settings_options', [] );
756 + if ( empty( $compliance_settings ) || ! is_array( $compliance_settings ) ) {
757 + $compliance_settings = self::get_default_compliance_settings();
758 + } else {
759 + // Merge with defaults to ensure all keys exist.
760 + $compliance_settings = array_merge(
761 + self::get_default_compliance_settings(),
762 + $compliance_settings
763 + );
764 + }
765 + $global_setting_options['srfm_compliance_settings_options'] = $compliance_settings;
766 +
767 + // Get form confirmation settings with defaults.
768 + $form_confirmation_settings = get_option( 'srfm_form_confirmation_settings_options', [] );
769 + if ( empty( $form_confirmation_settings ) || ! is_array( $form_confirmation_settings ) ) {
770 + $form_confirmation_settings = self::get_default_form_confirmation_settings();
771 + } else {
772 + // Merge with defaults to ensure all keys exist.
773 + $form_confirmation_settings = array_merge(
774 + self::get_default_form_confirmation_settings(),
775 + $form_confirmation_settings
776 + );
777 + }
778 + // Restore "data:" prefix stripped by wp_kses_post() in previous saves.
779 + if ( isset( $form_confirmation_settings['message'] ) && is_string( $form_confirmation_settings['message'] ) && false !== strpos( $form_confirmation_settings['message'], 'src="image/svg+xml;base64' ) ) {
780 + $normalized = preg_replace( '/src="image\/svg\+xml;base64/', 'src="data:image/svg+xml;base64', $form_confirmation_settings['message'] );
781 + if ( is_string( $normalized ) ) {
782 + $form_confirmation_settings['message'] = $normalized;
783 + }
784 + }
785 + $global_setting_options['srfm_form_confirmation_settings_options'] = $form_confirmation_settings;
786 +
787 + // Get email notification settings with defaults.
788 + $email_notification_settings = get_option( 'srfm_email_notification_settings_options', [] );
789 + if ( empty( $email_notification_settings ) || ! is_array( $email_notification_settings ) ) {
790 + $email_notification_settings = self::get_default_email_notification_settings();
791 + } else {
792 + // Merge with defaults to ensure all keys exist.
793 + $email_notification_settings = array_merge(
794 + self::get_default_email_notification_settings(),
795 + $email_notification_settings
796 + );
797 + }
798 + $global_setting_options['srfm_email_notification_settings_options'] = $email_notification_settings;
799 +
800 + // Apply filter to allow other modules to add their settings.
801 + $global_setting_options = apply_filters( 'srfm_global_settings_data', $global_setting_options );
802 +
803 + return new WP_REST_Response( $global_setting_options );
311 804 }
312 805
313 806 }