PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | inc/ai-form-builder/ai-form-builder.php +12 -0 2.11.0 → 2.12.8 View file →
@@ -51,8 +51,20 @@
51 51 // Add the message to the start of the messages to send to the SCS Middleware.
52 52 array_unshift( $messages, $current_message );
53 53 }
54 54
55 + // Bail if no usable prompt remained after filtering empty messages.
56 + if ( empty( $messages ) || empty( $messages[0]['content'] ) ) {
57 + wp_send_json_error( [ 'message' => __( 'No prompt was supplied.', 'sureforms' ) ] );
58 + }
59 +
60 + // Server-side prompt-length cap. The UI enforces a 2000-char limit via maxlength, but that
61 + // is client-side only and can be bypassed by a crafted request, so mirror it here. This is
62 + // cost/resource hardening — output is always escaped, so this is not an XSS concern.
63 + if ( mb_strlen( (string) $messages[0]['content'] ) > 2000 ) {
64 + wp_send_json_error( [ 'message' => __( 'The prompt is too long. Please shorten it and try again.', 'sureforms' ) ] );
65 + }
66 +
55 67 // Get the response from the endpoint.
56 68 $response = AI_Helper::get_chat_completions_response(
57 69 apply_filters(
58 70 'srfm_ai_form_generator_body',