| @@ -149,8 +149,19 @@ | ||
| 149 | 149 | |
| 150 | 150 | wp_enqueue_script( SRFM_SLUG . $form_editor_script, SRFM_URL . 'assets/build/formEditor.js', $script_info['dependencies'], $script_info['version'], true ); |
| 151 | 151 | wp_localize_script( SRFM_SLUG . $form_editor_script, 'scIcons', [ 'path' => SRFM_URL . 'assets/build/icon-assets' ] ); |
| 152 | 152 | |
| 153 | + // Deep-link (#3030): the "Finish setting up" Thank You notice CTA opens this | |
| 154 | + // editor with ?srfm_focus=… to auto-open a settings tab. Gutenberg strips | |
| 155 | + // unrecognised query args client-side before the editor bundle can read them, | |
| 156 | + // so surface the value from the server — where it is never stripped — as a | |
| 157 | + // global the bundle reads at evaluation time. Validated to a known allowlist. | |
| 158 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Read-only deep-link hint on an authenticated editor screen; no state change. | |
| 159 | + $srfm_focus = isset( $_GET['srfm_focus'] ) ? sanitize_key( wp_unslash( $_GET['srfm_focus'] ) ) : ''; | |
| 160 | + if ( in_array( $srfm_focus, [ 'thankyou', 'notifications' ], true ) ) { | |
| 161 | + wp_add_inline_script( SRFM_SLUG . $form_editor_script, 'window.srfmDeepLinkFocus = ' . wp_json_encode( $srfm_focus ) . ';', 'before' ); | |
| 162 | + } | |
| 163 | + | |
| 153 | 164 | // Enqueue the code editor for the Custom CSS Editor in SureForms. |
| 154 | 165 | wp_enqueue_code_editor( [ 'type' => 'text/css' ] ); |
| 155 | 166 | wp_enqueue_script( 'wp-theme-plugin-editor' ); |
| 156 | 167 | wp_enqueue_style( 'wp-codemirror' ); |
| @@ -202,12 +213,15 @@ | ||
| 202 | 213 | 'post_url' => admin_url( 'post.php' ), |
| 203 | 214 | 'current_screen' => $screen, |
| 204 | 215 | 'smart_tags_array' => Smart_Tags::smart_tag_list(), |
| 205 | 216 | 'smart_tags_array_email' => Smart_Tags::email_smart_tag_list(), |
| 206 | - 'srfm_form_markup_nonce' => wp_create_nonce( 'srfm_form_markup' ), | |
| 217 | + // No srfm_form_markup nonce: the generate-form-markup route is gated by a | |
| 218 | + // capability check, not by holding a nonce. It used to be minted here for | |
| 219 | + // every editor user and read from the query string, which is precisely how | |
| 220 | + // that route ended up with no real authorization (#2995). | |
| 207 | 221 | 'get_form_markup_url' => 'sureforms/v1/generate-form-markup', |
| 208 | 222 | 'is_pro_active' => Helper::has_pro(), |
| 209 | - 'srfm_default_dynamic_block_option' => get_option( 'srfm_default_dynamic_block_option', Helper::default_dynamic_block_option() ), | |
| 223 | + 'srfm_default_dynamic_block_option' => wp_parse_args( Helper::get_array_value( get_option( 'srfm_default_dynamic_block_option', [] ) ), Helper::default_dynamic_block_option() ), | |
| 210 | 224 | 'form_selector_nonce' => Helper::current_user_can( 'edit_posts' ) ? wp_create_nonce( 'wp_rest' ) : '', |
| 211 | 225 | 'is_admin_user' => Helper::current_user_can(), |
| 212 | 226 | 'site_url' => $site_url, |
| 213 | 227 | 'is_suremails_active' => is_plugin_active( 'suremails/suremails.php' ), |