PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | inc/gutenberg-hooks.php +16 -2 2.10.0 → 2.12.8 View file →
@@ -149,8 +149,19 @@
149 149
150 150 wp_enqueue_script( SRFM_SLUG . $form_editor_script, SRFM_URL . 'assets/build/formEditor.js', $script_info['dependencies'], $script_info['version'], true );
151 151 wp_localize_script( SRFM_SLUG . $form_editor_script, 'scIcons', [ 'path' => SRFM_URL . 'assets/build/icon-assets' ] );
152 152
153 + // Deep-link (#3030): the "Finish setting up" Thank You notice CTA opens this
154 + // editor with ?srfm_focus=… to auto-open a settings tab. Gutenberg strips
155 + // unrecognised query args client-side before the editor bundle can read them,
156 + // so surface the value from the server — where it is never stripped — as a
157 + // global the bundle reads at evaluation time. Validated to a known allowlist.
158 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Read-only deep-link hint on an authenticated editor screen; no state change.
159 + $srfm_focus = isset( $_GET['srfm_focus'] ) ? sanitize_key( wp_unslash( $_GET['srfm_focus'] ) ) : '';
160 + if ( in_array( $srfm_focus, [ 'thankyou', 'notifications' ], true ) ) {
161 + wp_add_inline_script( SRFM_SLUG . $form_editor_script, 'window.srfmDeepLinkFocus = ' . wp_json_encode( $srfm_focus ) . ';', 'before' );
162 + }
163 +
153 164 // Enqueue the code editor for the Custom CSS Editor in SureForms.
154 165 wp_enqueue_code_editor( [ 'type' => 'text/css' ] );
155 166 wp_enqueue_script( 'wp-theme-plugin-editor' );
156 167 wp_enqueue_style( 'wp-codemirror' );
@@ -202,12 +213,15 @@
202 213 'post_url' => admin_url( 'post.php' ),
203 214 'current_screen' => $screen,
204 215 'smart_tags_array' => Smart_Tags::smart_tag_list(),
205 216 'smart_tags_array_email' => Smart_Tags::email_smart_tag_list(),
206 - 'srfm_form_markup_nonce' => wp_create_nonce( 'srfm_form_markup' ),
217 + // No srfm_form_markup nonce: the generate-form-markup route is gated by a
218 + // capability check, not by holding a nonce. It used to be minted here for
219 + // every editor user and read from the query string, which is precisely how
220 + // that route ended up with no real authorization (#2995).
207 221 'get_form_markup_url' => 'sureforms/v1/generate-form-markup',
208 222 'is_pro_active' => Helper::has_pro(),
209 - 'srfm_default_dynamic_block_option' => get_option( 'srfm_default_dynamic_block_option', Helper::default_dynamic_block_option() ),
223 + 'srfm_default_dynamic_block_option' => wp_parse_args( Helper::get_array_value( get_option( 'srfm_default_dynamic_block_option', [] ) ), Helper::default_dynamic_block_option() ),
210 224 'form_selector_nonce' => Helper::current_user_can( 'edit_posts' ) ? wp_create_nonce( 'wp_rest' ) : '',
211 225 'is_admin_user' => Helper::current_user_can(),
212 226 'site_url' => $site_url,
213 227 'is_suremails_active' => is_plugin_active( 'suremails/suremails.php' ),