PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | inc/frontend-assets.php +78 -1 2.12.2 → 2.12.8 View file →
@@ -105,12 +105,27 @@
105 105
106 106 // Scripts.
107 107 foreach ( self::$js_assets as $handle => $name ) {
108 108 if ( 'form-submit' === $handle ) {
109 + // No 'wp-api-fetch' dependency: the script talks to the REST API via a
110 + // plain fetch() against the URLs localized below, not wp.apiFetch(),
111 + // so submissions no longer depend on that second script having loaded
112 + // and executed correctly. See the wp_localize_script() call below for
113 + // why wp.apiFetch's middleware (root-URL resolution, nonce injection)
114 + // isn't needed for either endpoint this script calls.
115 + //
116 + // 'wp-i18n' and 'wp-hooks' ARE required and must stay. The bundle imports
117 + // __() and applyFilters(), which @wordpress/scripts externalises to the
118 + // wp.i18n / window.wp.hooks globals instead of inlining — the generated
119 + // assets/build/formSubmit.asset.php is the authority on this list. They
120 + // used to arrive for free because 'wp-api-fetch' pulled them in through
121 + // its own dependency graph; dropping that above removed them, and an
122 + // undeclared wp.hooks is undefined under a JS-combining optimizer, which
123 + // kills every submission with the same TypeError this change prevents.
109 124 wp_register_script(
110 125 SRFM_SLUG . '-' . $handle,
111 126 SRFM_URL . 'assets/build/' . $name . '.js',
112 - [ 'wp-api-fetch' ],
127 + [ 'wp-i18n', 'wp-hooks' ],
113 128 SRFM_VER,
114 129 true
115 130 );
116 131 } else {
@@ -143,13 +158,35 @@
143 158 SRFM_SLUG . '_submit',
144 159 [
145 160 'site_url' => site_url(),
146 161 'nonce' => wp_create_nonce( 'wp_rest' ),
162 + // Fully resolved REST endpoint URL, so the frontend can call it with a
163 + // plain fetch() instead of wp.apiFetch(). rest_url() already accounts
164 + // for pretty vs. plain permalinks (the latter needs a `?rest_route=`
165 + // query var rather than a path segment), subdirectory installs, and
166 + // multisite domain mapping — the same resolution wp.apiFetch's root-URL
167 + // middleware would otherwise do from a second, independently-loaded
168 + // script. submit-form's auth does not depend on that script either: it
169 + // is guarded by the X-WP-Submit-Token header (Submit_Token::verify()).
170 + //
171 + // The after-submission URL is deliberately NOT localized. It needs the
172 + // submission id and a per-submission nonce, so it is built server-side
173 + // and returned in the submit response instead (see Form_Submit). A base
174 + // URL here invited the client to concatenate those on, which silently
175 + // produced an unroutable URL wherever rest_url() returns a
176 + // `?rest_route=` form.
177 + 'submit_form_url' => esc_url_raw( rest_url( 'sureforms/v1/submit-form' ) ),
147 178 'messages' => $validation_messages,
148 179 'is_rtl' => $is_rtl,
149 180 // Resolved RFC 5321 email limits so the client honors the
150 181 // srfm_email_field_char_limits filter instead of hardcoding 64/255.
151 182 'email_char_limits' => Field_Validation::get_email_char_limits(),
183 + // Hint only. This value is baked into cached HTML and can be a full
184 + // cache TTL out of date, so the server re-checks on every write --
185 + // see Form_Submit::client_error_log_permissions_check(). Its job is
186 + // to keep the browser from posting when logging is plainly off.
187 + 'logging_enabled' => Client_Logger::is_enabled(),
188 + 'log_error_url' => esc_url_raw( rest_url( 'sureforms/v1/log-client-error' ) ),
152 189 ]
153 190 );
154 191
155 192 $current_post = get_post();
@@ -510,8 +547,10 @@
510 547 // Bail if not SureForms post type.
511 548 return $template;
512 549 }
513 550
551 + self::reset_printed_assets();
552 +
514 553 $file_name = 'single-form.php';
515 554 $template = locate_template( $file_name );
516 555
517 556 /**
@@ -519,7 +558,45 @@
519 558 *
520 559 * @since 0.0.1
521 560 */
522 561 return apply_filters( 'srfm_form_template', $template ? $template : SRFM_DIR . '/templates/' . $file_name );
562 + }
563 +
564 + /**
565 + * Let the Instant Form template print assets a discarded render already claimed.
566 + *
567 + * `page_template()` runs on `template_include` at PHP_INT_MAX and returns the
568 + * Instant Form template regardless of what earlier filters returned. A page
569 + * builder that renders the whole page inside its own `template_include`
570 + * filter has therefore already run `wp_head()` and `wp_footer()` into an
571 + * output buffer that is about to be thrown away.
572 + *
573 + * The buffer goes, but `WP_Styles::$done` and `WP_Scripts::$done` still hold
574 + * every handle it claimed, so `do_items()` skips them when `single-form.php`
575 + * calls `wp_head()` and `wp_footer()` for real. The form arrives with no
576 + * stylesheets, and -- because `srfm-form-submit` is registered for the footer
577 + * -- no submit handler either.
578 + *
579 + * Clearing both `done` lists wholesale is the right scope rather than an
580 + * over-broad one: only the render that begins after this filter returns
581 + * reaches the browser, so nothing recorded before it was ever delivered. The
582 + * handles are re-enqueued by the second `wp_enqueue_scripts` pass, so they
583 + * print normally once `done` stops shadowing them.
584 + *
585 + * Guarded on `wp_head` having already fired, so this is inert on the ordinary
586 + * path where no builder rendered first and nothing has been printed yet.
587 + *
588 + * @since 2.12.7
589 + * @return void
590 + */
591 + private static function reset_printed_assets() {
592 + // No earlier wp_head() means no discarded render, so there is nothing to
593 + // forget. Deny is the fallthrough: act only on the state this repairs.
594 + if ( ! did_action( 'wp_head' ) ) {
595 + return;
596 + }
597 +
598 + wp_styles()->done = [];
599 + wp_scripts()->done = [];
523 600 }
524 601
525 602 }