| @@ -24,8 +24,16 @@ | ||
| 24 | 24 | class Generate_Form_Markup { |
| 25 | 25 | use Get_Instance; |
| 26 | 26 | |
| 27 | 27 | /** |
| 28 | + * Query arg marking an editor visit as arriving from the front-end "Edit Form" | |
| 29 | + * pill, so the click can be attributed without any front-end JavaScript. | |
| 30 | + * | |
| 31 | + * @since 2.12.6 | |
| 32 | + */ | |
| 33 | + public const EDIT_FORM_BUTTON_SOURCE_ARG = 'srfm_edit_src'; | |
| 34 | + | |
| 35 | + /** | |
| 28 | 36 | * Current block attributes for the form being rendered. |
| 29 | 37 | * Used by child blocks (like inline button) to access parent form's embed styling. |
| 30 | 38 | * |
| 31 | 39 | * @var array<string,mixed> |
| @@ -530,11 +538,30 @@ | ||
| 530 | 538 | } |
| 531 | 539 | } |
| 532 | 540 | } |
| 533 | 541 | |
| 534 | - $page_break_settings = defined( 'SRFM_PRO_VER' ) && apply_filters( 'srfm_use_page_break_layout', true ) ? get_post_meta( $id, '_srfm_page_break_settings', true ) : []; | |
| 535 | - $page_break_settings = ! empty( $page_break_settings ) && is_array( $page_break_settings ) ? $page_break_settings : []; | |
| 536 | - $is_page_break = ! empty( $page_break_settings ) ? $page_break_settings['is_page_break'] : false; | |
| 542 | + $page_break_settings = defined( 'SRFM_PRO_VER' ) && apply_filters( 'srfm_use_page_break_layout', true ) ? get_post_meta( $id, '_srfm_page_break_settings', true ) : []; | |
| 543 | + $page_break_settings = ! empty( $page_break_settings ) && is_array( $page_break_settings ) ? $page_break_settings : []; | |
| 544 | + $is_page_break = ! empty( $page_break_settings ) ? $page_break_settings['is_page_break'] : false; | |
| 545 | + // Auto-advance is read here rather than in Pro's button renderer because | |
| 546 | + // save & resume replaces that whole container through the | |
| 547 | + // srfm_page_break_buttons_html filter, which would drop the attributes. | |
| 548 | + // The form tag is rendered exactly once and is already how both step | |
| 549 | + // runtimes receive their per-form settings (form-id, ajaxurl, | |
| 550 | + // data-submit-token). | |
| 551 | + // | |
| 552 | + // Two stored settings rather than one because the two layouts are | |
| 553 | + // mutually exclusive: Pro filters srfm_use_page_break_layout to false | |
| 554 | + // when the conversational layout is on, so $page_break_settings is | |
| 555 | + // empty there and its editor panel is hidden. Each layout keeps the | |
| 556 | + // toggle with the rest of its own settings, and only one can apply. | |
| 557 | + $conversational_settings = defined( 'SRFM_PRO_VER' ) ? get_post_meta( $id, '_srfm_conversational_form', true ) : []; | |
| 558 | + $conversational_settings = ! empty( $conversational_settings ) && is_array( $conversational_settings ) ? $conversational_settings : []; | |
| 559 | + $is_conversational = ! empty( $conversational_settings['is_cf_enabled'] ); | |
| 560 | + $active_step_settings = $is_conversational ? $conversational_settings : ( $is_page_break ? $page_break_settings : [] ); | |
| 561 | + $auto_advance_key = $is_conversational ? 'cf_auto_advance' : 'auto_advance'; | |
| 562 | + $auto_advance = ! empty( $active_step_settings[ $auto_advance_key ] ); | |
| 563 | + $auto_advance_hide_next = $auto_advance && ! empty( $active_step_settings[ $auto_advance_key . '_hide_next' ] ); | |
| 537 | 564 | $page_break_progress_type = ! empty( $page_break_settings ) ? $page_break_settings['progress_indicator_type'] : 'none'; |
| 538 | 565 | $form_confirmation = get_post_meta( $id, '_srfm_form_confirmation' ); |
| 539 | 566 | $confirmation_type = ''; |
| 540 | 567 | $submission_action = ''; |
| @@ -854,12 +881,25 @@ | ||
| 854 | 881 | self::$current_block_attrs = []; |
| 855 | 882 | return ob_get_clean(); |
| 856 | 883 | } |
| 857 | 884 | $submit_token = Submit_Token::generate( (int) $id ); |
| 885 | + // Separately namespaced from the submission token: this one is only good | |
| 886 | + // for incrementing a view counter, so scraping it from the page buys an | |
| 887 | + // attacker nothing beyond what the beacon already does, and it cannot be | |
| 888 | + // replayed against the submit endpoint. | |
| 889 | + $view_token = Submit_Token::generate( (int) $id, Submit_Token::NAMESPACE_VIEW ); | |
| 858 | 890 | |
| 891 | + // Admin-only shortcut into the form editor. Emitted here, immediately | |
| 892 | + // above the <form>, so it occupies its own row in normal flow and can | |
| 893 | + // never overlap a field. Already inside the `.srfm-form-container` | |
| 894 | + // branch, so a zero-block form (no container) never reaches here and | |
| 895 | + // cannot emit an orphaned pill. Works for every embed method (block, | |
| 896 | + // shortcode, widget) because they all render through this function. | |
| 897 | + self::render_edit_form_button( (int) $id ); | |
| 898 | + | |
| 859 | 899 | ?> |
| 860 | 900 | <form method="post" enctype="multipart/form-data" id="srfm-form-<?php echo esc_attr( Helper::get_string_value( $id ) ); ?>" class="srfm-form <?php echo esc_attr( 'sureforms_form' === $post_type ? 'srfm-single-form ' : '' ); ?>" |
| 861 | - form-id="<?php echo esc_attr( Helper::get_string_value( $id ) ); ?>" after-submission="<?php echo esc_attr( $submission_action ); ?>" message-type="<?php echo esc_attr( $confirmation_type ? $confirmation_type : 'same page' ); ?>" success-url="<?php echo esc_attr( $success_url ? $success_url : '' ); ?>" ajaxurl="<?php echo esc_url( admin_url( 'admin-ajax.php' ) ); ?>" data-submit-token="<?php echo esc_attr( $submit_token ); ?>" | |
| 901 | + form-id="<?php echo esc_attr( Helper::get_string_value( $id ) ); ?>" after-submission="<?php echo esc_attr( $submission_action ); ?>" message-type="<?php echo esc_attr( $confirmation_type ? $confirmation_type : 'same page' ); ?>" success-url="<?php echo esc_attr( $success_url ? $success_url : '' ); ?>" ajaxurl="<?php echo esc_url( admin_url( 'admin-ajax.php' ) ); ?>" data-submit-token="<?php echo esc_attr( $submit_token ); ?>" data-view-token="<?php echo esc_attr( $view_token ); ?>"<?php echo $auto_advance ? ' data-srfm-auto-advance="1"' : ''; ?><?php echo $auto_advance_hide_next ? ' data-srfm-hide-next="1"' : ''; ?> | |
| 862 | 902 | > |
| 863 | 903 | <?php |
| 864 | 904 | // Submission security is handled via the HMAC token in data-submit-token. |
| 865 | 905 | $global_setting_options = get_option( 'srfm_security_settings_options' ); |
| @@ -1312,6 +1352,203 @@ | ||
| 1312 | 1352 | $redirect_url = html_entity_decode( str_replace( $multi_value_delimiters, '|', $resolved_redirect_url ) ); |
| 1313 | 1353 | } |
| 1314 | 1354 | |
| 1315 | 1355 | return esc_url_raw( apply_filters( 'srfm_after_submit_redirect_url', $redirect_url ) ); |
| 1356 | + } | |
| 1357 | + | |
| 1358 | + /** | |
| 1359 | + * Print the admin-only "Edit Form" shortcut on an embedded form. | |
| 1360 | + * | |
| 1361 | + * Renders a small pill link that opens the block editor for this form, on its | |
| 1362 | + * own right-aligned row directly above the form. | |
| 1363 | + * | |
| 1364 | + * It sits in normal flow rather than being absolutely positioned over the | |
| 1365 | + * form's top-right corner, which is what it used to do. An overlay can only | |
| 1366 | + * avoid the fields when the container happens to have enough top padding — | |
| 1367 | + * with the default theme styling it landed on top of the first row's last | |
| 1368 | + * field (#3062). Flow layout cannot overlap anything by construction, at any | |
| 1369 | + * width, with any theme. The cost is that the form shifts down by the pill's | |
| 1370 | + * height, which happens only for users who can edit the form; the markup and | |
| 1371 | + * its styles remain entirely absent from the DOM for everyone else, so no | |
| 1372 | + * regular visitor sees a layout change. | |
| 1373 | + * | |
| 1374 | + * Admin-only by construction: the `sureforms_form` CPT registers with | |
| 1375 | + * `map_meta_cap => false`, so `edit_post` collapses to a blanket | |
| 1376 | + * `manage_options` check with no per-post component — an editor never sees the | |
| 1377 | + * pill on any form. For every other viewer the markup and its styles are | |
| 1378 | + * entirely absent from the DOM. | |
| 1379 | + * | |
| 1380 | + * The stylesheet is attached to a registered inline-only handle so `WP_Styles` | |
| 1381 | + * dedupes it by handle (surviving a discarded `the_content` pass, e.g. an SEO | |
| 1382 | + * plugin building `og:description` during `wp_head`) and it survives a strict | |
| 1383 | + * `style-src` CSP. It is not cache-signalled here: the payload is only a | |
| 1384 | + * `wp-admin/post.php?post=N` link an anonymous visitor cannot act on, and a | |
| 1385 | + * `DONOTCACHEPAGE` define from a fragment renderer is both inert on the normal | |
| 1386 | + * (headers-already-sent) path and an irreversible process-global side effect. | |
| 1387 | + * | |
| 1388 | + * @param int $form_id Form post ID. | |
| 1389 | + * | |
| 1390 | + * @return void | |
| 1391 | + * @since 2.12.4 | |
| 1392 | + */ | |
| 1393 | + public static function render_edit_form_button( $form_id ) { | |
| 1394 | + $form_id = absint( $form_id ); | |
| 1395 | + | |
| 1396 | + // Only for real SureForms forms — the [sureforms] shortcode accepts any | |
| 1397 | + // post ID, and a non-form target would map `edit_post` normally and leak | |
| 1398 | + // the pill to an ordinary editor. | |
| 1399 | + if ( 0 === $form_id || ! defined( 'SRFM_FORMS_POST_TYPE' ) || SRFM_FORMS_POST_TYPE !== get_post_type( $form_id ) ) { | |
| 1400 | + return; | |
| 1401 | + } | |
| 1402 | + | |
| 1403 | + // Capability gate first, before the suppression filter, so no work is done | |
| 1404 | + // for the anonymous visitors who make up almost every page view. | |
| 1405 | + if ( ! current_user_can( 'edit_post', $form_id ) ) { | |
| 1406 | + return; | |
| 1407 | + } | |
| 1408 | + | |
| 1409 | + // Contexts where the pill is redundant or wrong: | |
| 1410 | + // - the single-form / Instant Form page, where the form IS the whole page | |
| 1411 | + // and the admin bar already links to its editor. This is also what | |
| 1412 | + // suppresses the block editor's preview — that preview is an iframe to | |
| 1413 | + // the form's own permalink (an ordinary front-end request), NOT a REST | |
| 1414 | + // render, so `is_singular` is the load-bearing guard there; | |
| 1415 | + // - any admin / AJAX / REST / JSON request, or a feed (the markup would | |
| 1416 | + // otherwise land inside `content:encoded` CDATA). | |
| 1417 | + if ( | |
| 1418 | + is_singular( SRFM_FORMS_POST_TYPE ) | |
| 1419 | + || is_admin() | |
| 1420 | + || wp_doing_ajax() | |
| 1421 | + || wp_is_json_request() | |
| 1422 | + || ( defined( 'REST_REQUEST' ) && REST_REQUEST ) | |
| 1423 | + || is_feed() | |
| 1424 | + ) { | |
| 1425 | + return; | |
| 1426 | + } | |
| 1427 | + | |
| 1428 | + // Page-builder editor canvases render the form directly (not over REST), | |
| 1429 | + // where their own element-edit handles would collide with the pill. | |
| 1430 | + // `$instance` is checked as well as the class name: Elementor declares | |
| 1431 | + // `public static $instance = null` and only populates it on boot, so the | |
| 1432 | + // class can exist while the singleton is still null. Dereferencing it then | |
| 1433 | + // is a fatal Error, not a warning, and guarding only on class_exists() left | |
| 1434 | + // that reachable — test-generate-form-markup.php hit it. The bundled stub | |
| 1435 | + // types $instance as non-nullable, which is why PHPStan reads the isset() | |
| 1436 | + // as redundant and has to be told otherwise. | |
| 1437 | + // | |
| 1438 | + // ->editor is checked for the same reason one level down: Elementor assigns it | |
| 1439 | + // in init_components() on `init`, while the singleton itself is created on | |
| 1440 | + // `plugins_loaded`. Between those two hooks $instance is set and ->editor is | |
| 1441 | + // still null, so checking only the singleton reproduces the original fatal a | |
| 1442 | + // property later. | |
| 1443 | + // @phpstan-ignore-next-line -- Stub disagrees with runtime; see above. | |
| 1444 | + if ( class_exists( '\Elementor\Plugin' ) && isset( \Elementor\Plugin::$instance->editor ) && \Elementor\Plugin::$instance->editor->is_edit_mode() ) { | |
| 1445 | + return; | |
| 1446 | + } | |
| 1447 | + if ( function_exists( 'bricks_is_builder' ) && bricks_is_builder() ) { | |
| 1448 | + return; | |
| 1449 | + } | |
| 1450 | + | |
| 1451 | + /** | |
| 1452 | + * Allow integrations to suppress the admin "Edit Form" shortcut entirely. | |
| 1453 | + * | |
| 1454 | + * @param bool $show Whether to render the shortcut. Default true. | |
| 1455 | + * @param int $form_id Form post ID. | |
| 1456 | + * | |
| 1457 | + * @since 2.12.4 | |
| 1458 | + */ | |
| 1459 | + if ( ! apply_filters( 'srfm_show_edit_form_button', true, $form_id ) ) { | |
| 1460 | + return; | |
| 1461 | + } | |
| 1462 | + | |
| 1463 | + $edit_link = get_edit_post_link( $form_id, 'raw' ); | |
| 1464 | + | |
| 1465 | + if ( empty( $edit_link ) ) { | |
| 1466 | + return; | |
| 1467 | + } | |
| 1468 | + | |
| 1469 | + // Attribution marker read back by Admin::maybe_track_edit_form_button_click() | |
| 1470 | + // when the editor loads. Added before the filter below so an integration that | |
| 1471 | + // replaces the link wholesale drops the marker with it, rather than having our | |
| 1472 | + // query arg appended to a third-party URL. | |
| 1473 | + // 'url' context, not the default 'display': the latter returns &-escaped | |
| 1474 | + // separators, and feeding those to add_query_arg() only round-trips because | |
| 1475 | + // build_query() happens to re-emit the mangled `amp;action` key verbatim. The | |
| 1476 | + // raw form has no such dependency, and esc_url() below still escapes on output. | |
| 1477 | + $edit_link = add_query_arg( self::EDIT_FORM_BUTTON_SOURCE_ARG, 'embed', $edit_link ); | |
| 1478 | + | |
| 1479 | + /** | |
| 1480 | + * Filter the target of the admin "Edit Form" shortcut. | |
| 1481 | + * | |
| 1482 | + * @param string $edit_link Editor URL for the form. | |
| 1483 | + * @param int $form_id Form post ID. | |
| 1484 | + * | |
| 1485 | + * @since 2.12.4 | |
| 1486 | + */ | |
| 1487 | + $edit_link = Helper::get_string_value( apply_filters( 'srfm_edit_form_button_link', $edit_link, $form_id ) ); | |
| 1488 | + | |
| 1489 | + if ( '' === $edit_link ) { | |
| 1490 | + return; | |
| 1491 | + } | |
| 1492 | + | |
| 1493 | + // Registered inline-only handle: WP_Styles dedupes by handle across every | |
| 1494 | + // embedded form and prints via print_late_styles() in the footer even when | |
| 1495 | + // enqueued this late (during the_content). | |
| 1496 | + $style_handle = 'srfm-edit-form-btn'; | |
| 1497 | + if ( ! wp_style_is( $style_handle, 'registered' ) ) { | |
| 1498 | + wp_register_style( $style_handle, false, [], SRFM_VER ); | |
| 1499 | + wp_add_inline_style( $style_handle, self::get_edit_form_button_css() ); | |
| 1500 | + } | |
| 1501 | + wp_enqueue_style( $style_handle ); | |
| 1502 | + ?> | |
| 1503 | + <div class="srfm-edit-form-btn-wrap"> | |
| 1504 | + <a class="srfm-edit-form-btn" href="<?php echo esc_url( $edit_link ); ?>" target="_blank" rel="noopener noreferrer"> | |
| 1505 | + <svg width="20" height="20" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M12 20h9"></path><path d="M16.5 3.5a2.12 2.12 0 0 1 3 3L7 19l-4 1 1-4Z"></path></svg> | |
| 1506 | + <span><?php esc_html_e( 'Edit Form', 'sureforms' ); ?></span> | |
| 1507 | + <span class="screen-reader-text"><?php esc_html_e( '(opens in a new tab)', 'sureforms' ); ?></span> | |
| 1508 | + </a> | |
| 1509 | + </div> | |
| 1510 | + <?php | |
| 1511 | + } | |
| 1512 | + | |
| 1513 | + /** | |
| 1514 | + * Stylesheet for the admin "Edit Form" pill (#3029). | |
| 1515 | + * | |
| 1516 | + * The wrapper is a flow-level flex row rather than an absolute overlay, so the | |
| 1517 | + * pill reserves its own space and cannot cover a field (#3062). `justify-content` | |
| 1518 | + * uses the logical `flex-end`, which follows the writing direction and is | |
| 1519 | + * therefore RTL-correct without a separate rule. | |
| 1520 | + * | |
| 1521 | + * No `position: relative` on the container any more: that rule existed solely to | |
| 1522 | + * be the positioning context for the old overlay. | |
| 1523 | + * | |
| 1524 | + * @return string | |
| 1525 | + * @since 2.12.4 | |
| 1526 | + */ | |
| 1527 | + private static function get_edit_form_button_css() { | |
| 1528 | + return ' | |
| 1529 | + .srfm-edit-form-btn-wrap { | |
| 1530 | + display: flex; | |
| 1531 | + justify-content: flex-end; | |
| 1532 | + margin-block-end: 8px; | |
| 1533 | + } | |
| 1534 | + .srfm-edit-form-btn { | |
| 1535 | + display: inline-flex; | |
| 1536 | + align-items: center; | |
| 1537 | + gap: 6px; | |
| 1538 | + padding: 6px 12px; | |
| 1539 | + font-size: 13px; | |
| 1540 | + font-weight: 500; | |
| 1541 | + line-height: 1; | |
| 1542 | + color: #1e293b; | |
| 1543 | + background: #ffffff; | |
| 1544 | + border: 1px solid #e2e8f0; | |
| 1545 | + border-radius: 9999px; | |
| 1546 | + box-shadow: 0 2px 6px rgba( 0, 0, 0, 0.12 ); | |
| 1547 | + text-decoration: none; | |
| 1548 | + } | |
| 1549 | + .srfm-edit-form-btn:hover { border-color: #cbd5e1; color: #0f172a; } | |
| 1550 | + .srfm-edit-form-btn:focus-visible { outline: 2px solid #2563eb; outline-offset: 2px; } | |
| 1551 | + .srfm-edit-form-btn svg { width: 14px; height: 14px; } | |
| 1552 | + '; | |
| 1316 | 1553 | } |
| 1317 | 1554 | } |