PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | inc/generate-form-markup.php +241 -4 2.12.3 → 2.12.8 View file →
@@ -24,8 +24,16 @@
24 24 class Generate_Form_Markup {
25 25 use Get_Instance;
26 26
27 27 /**
28 + * Query arg marking an editor visit as arriving from the front-end "Edit Form"
29 + * pill, so the click can be attributed without any front-end JavaScript.
30 + *
31 + * @since 2.12.6
32 + */
33 + public const EDIT_FORM_BUTTON_SOURCE_ARG = 'srfm_edit_src';
34 +
35 + /**
28 36 * Current block attributes for the form being rendered.
29 37 * Used by child blocks (like inline button) to access parent form's embed styling.
30 38 *
31 39 * @var array<string,mixed>
@@ -530,11 +538,30 @@
530 538 }
531 539 }
532 540 }
533 541
534 - $page_break_settings = defined( 'SRFM_PRO_VER' ) && apply_filters( 'srfm_use_page_break_layout', true ) ? get_post_meta( $id, '_srfm_page_break_settings', true ) : [];
535 - $page_break_settings = ! empty( $page_break_settings ) && is_array( $page_break_settings ) ? $page_break_settings : [];
536 - $is_page_break = ! empty( $page_break_settings ) ? $page_break_settings['is_page_break'] : false;
542 + $page_break_settings = defined( 'SRFM_PRO_VER' ) && apply_filters( 'srfm_use_page_break_layout', true ) ? get_post_meta( $id, '_srfm_page_break_settings', true ) : [];
543 + $page_break_settings = ! empty( $page_break_settings ) && is_array( $page_break_settings ) ? $page_break_settings : [];
544 + $is_page_break = ! empty( $page_break_settings ) ? $page_break_settings['is_page_break'] : false;
545 + // Auto-advance is read here rather than in Pro's button renderer because
546 + // save & resume replaces that whole container through the
547 + // srfm_page_break_buttons_html filter, which would drop the attributes.
548 + // The form tag is rendered exactly once and is already how both step
549 + // runtimes receive their per-form settings (form-id, ajaxurl,
550 + // data-submit-token).
551 + //
552 + // Two stored settings rather than one because the two layouts are
553 + // mutually exclusive: Pro filters srfm_use_page_break_layout to false
554 + // when the conversational layout is on, so $page_break_settings is
555 + // empty there and its editor panel is hidden. Each layout keeps the
556 + // toggle with the rest of its own settings, and only one can apply.
557 + $conversational_settings = defined( 'SRFM_PRO_VER' ) ? get_post_meta( $id, '_srfm_conversational_form', true ) : [];
558 + $conversational_settings = ! empty( $conversational_settings ) && is_array( $conversational_settings ) ? $conversational_settings : [];
559 + $is_conversational = ! empty( $conversational_settings['is_cf_enabled'] );
560 + $active_step_settings = $is_conversational ? $conversational_settings : ( $is_page_break ? $page_break_settings : [] );
561 + $auto_advance_key = $is_conversational ? 'cf_auto_advance' : 'auto_advance';
562 + $auto_advance = ! empty( $active_step_settings[ $auto_advance_key ] );
563 + $auto_advance_hide_next = $auto_advance && ! empty( $active_step_settings[ $auto_advance_key . '_hide_next' ] );
537 564 $page_break_progress_type = ! empty( $page_break_settings ) ? $page_break_settings['progress_indicator_type'] : 'none';
538 565 $form_confirmation = get_post_meta( $id, '_srfm_form_confirmation' );
539 566 $confirmation_type = '';
540 567 $submission_action = '';
@@ -854,12 +881,25 @@
854 881 self::$current_block_attrs = [];
855 882 return ob_get_clean();
856 883 }
857 884 $submit_token = Submit_Token::generate( (int) $id );
885 + // Separately namespaced from the submission token: this one is only good
886 + // for incrementing a view counter, so scraping it from the page buys an
887 + // attacker nothing beyond what the beacon already does, and it cannot be
888 + // replayed against the submit endpoint.
889 + $view_token = Submit_Token::generate( (int) $id, Submit_Token::NAMESPACE_VIEW );
858 890
891 + // Admin-only shortcut into the form editor. Emitted here, immediately
892 + // above the <form>, so it occupies its own row in normal flow and can
893 + // never overlap a field. Already inside the `.srfm-form-container`
894 + // branch, so a zero-block form (no container) never reaches here and
895 + // cannot emit an orphaned pill. Works for every embed method (block,
896 + // shortcode, widget) because they all render through this function.
897 + self::render_edit_form_button( (int) $id );
898 +
859 899 ?>
860 900 <form method="post" enctype="multipart/form-data" id="srfm-form-<?php echo esc_attr( Helper::get_string_value( $id ) ); ?>" class="srfm-form <?php echo esc_attr( 'sureforms_form' === $post_type ? 'srfm-single-form ' : '' ); ?>"
861 - form-id="<?php echo esc_attr( Helper::get_string_value( $id ) ); ?>" after-submission="<?php echo esc_attr( $submission_action ); ?>" message-type="<?php echo esc_attr( $confirmation_type ? $confirmation_type : 'same page' ); ?>" success-url="<?php echo esc_attr( $success_url ? $success_url : '' ); ?>" ajaxurl="<?php echo esc_url( admin_url( 'admin-ajax.php' ) ); ?>" data-submit-token="<?php echo esc_attr( $submit_token ); ?>"
901 + form-id="<?php echo esc_attr( Helper::get_string_value( $id ) ); ?>" after-submission="<?php echo esc_attr( $submission_action ); ?>" message-type="<?php echo esc_attr( $confirmation_type ? $confirmation_type : 'same page' ); ?>" success-url="<?php echo esc_attr( $success_url ? $success_url : '' ); ?>" ajaxurl="<?php echo esc_url( admin_url( 'admin-ajax.php' ) ); ?>" data-submit-token="<?php echo esc_attr( $submit_token ); ?>" data-view-token="<?php echo esc_attr( $view_token ); ?>"<?php echo $auto_advance ? ' data-srfm-auto-advance="1"' : ''; ?><?php echo $auto_advance_hide_next ? ' data-srfm-hide-next="1"' : ''; ?>
862 902 >
863 903 <?php
864 904 // Submission security is handled via the HMAC token in data-submit-token.
865 905 $global_setting_options = get_option( 'srfm_security_settings_options' );
@@ -1312,6 +1352,203 @@
1312 1352 $redirect_url = html_entity_decode( str_replace( $multi_value_delimiters, '|', $resolved_redirect_url ) );
1313 1353 }
1314 1354
1315 1355 return esc_url_raw( apply_filters( 'srfm_after_submit_redirect_url', $redirect_url ) );
1356 + }
1357 +
1358 + /**
1359 + * Print the admin-only "Edit Form" shortcut on an embedded form.
1360 + *
1361 + * Renders a small pill link that opens the block editor for this form, on its
1362 + * own right-aligned row directly above the form.
1363 + *
1364 + * It sits in normal flow rather than being absolutely positioned over the
1365 + * form's top-right corner, which is what it used to do. An overlay can only
1366 + * avoid the fields when the container happens to have enough top padding —
1367 + * with the default theme styling it landed on top of the first row's last
1368 + * field (#3062). Flow layout cannot overlap anything by construction, at any
1369 + * width, with any theme. The cost is that the form shifts down by the pill's
1370 + * height, which happens only for users who can edit the form; the markup and
1371 + * its styles remain entirely absent from the DOM for everyone else, so no
1372 + * regular visitor sees a layout change.
1373 + *
1374 + * Admin-only by construction: the `sureforms_form` CPT registers with
1375 + * `map_meta_cap => false`, so `edit_post` collapses to a blanket
1376 + * `manage_options` check with no per-post component — an editor never sees the
1377 + * pill on any form. For every other viewer the markup and its styles are
1378 + * entirely absent from the DOM.
1379 + *
1380 + * The stylesheet is attached to a registered inline-only handle so `WP_Styles`
1381 + * dedupes it by handle (surviving a discarded `the_content` pass, e.g. an SEO
1382 + * plugin building `og:description` during `wp_head`) and it survives a strict
1383 + * `style-src` CSP. It is not cache-signalled here: the payload is only a
1384 + * `wp-admin/post.php?post=N` link an anonymous visitor cannot act on, and a
1385 + * `DONOTCACHEPAGE` define from a fragment renderer is both inert on the normal
1386 + * (headers-already-sent) path and an irreversible process-global side effect.
1387 + *
1388 + * @param int $form_id Form post ID.
1389 + *
1390 + * @return void
1391 + * @since 2.12.4
1392 + */
1393 + public static function render_edit_form_button( $form_id ) {
1394 + $form_id = absint( $form_id );
1395 +
1396 + // Only for real SureForms forms — the [sureforms] shortcode accepts any
1397 + // post ID, and a non-form target would map `edit_post` normally and leak
1398 + // the pill to an ordinary editor.
1399 + if ( 0 === $form_id || ! defined( 'SRFM_FORMS_POST_TYPE' ) || SRFM_FORMS_POST_TYPE !== get_post_type( $form_id ) ) {
1400 + return;
1401 + }
1402 +
1403 + // Capability gate first, before the suppression filter, so no work is done
1404 + // for the anonymous visitors who make up almost every page view.
1405 + if ( ! current_user_can( 'edit_post', $form_id ) ) {
1406 + return;
1407 + }
1408 +
1409 + // Contexts where the pill is redundant or wrong:
1410 + // - the single-form / Instant Form page, where the form IS the whole page
1411 + // and the admin bar already links to its editor. This is also what
1412 + // suppresses the block editor's preview — that preview is an iframe to
1413 + // the form's own permalink (an ordinary front-end request), NOT a REST
1414 + // render, so `is_singular` is the load-bearing guard there;
1415 + // - any admin / AJAX / REST / JSON request, or a feed (the markup would
1416 + // otherwise land inside `content:encoded` CDATA).
1417 + if (
1418 + is_singular( SRFM_FORMS_POST_TYPE )
1419 + || is_admin()
1420 + || wp_doing_ajax()
1421 + || wp_is_json_request()
1422 + || ( defined( 'REST_REQUEST' ) && REST_REQUEST )
1423 + || is_feed()
1424 + ) {
1425 + return;
1426 + }
1427 +
1428 + // Page-builder editor canvases render the form directly (not over REST),
1429 + // where their own element-edit handles would collide with the pill.
1430 + // `$instance` is checked as well as the class name: Elementor declares
1431 + // `public static $instance = null` and only populates it on boot, so the
1432 + // class can exist while the singleton is still null. Dereferencing it then
1433 + // is a fatal Error, not a warning, and guarding only on class_exists() left
1434 + // that reachable — test-generate-form-markup.php hit it. The bundled stub
1435 + // types $instance as non-nullable, which is why PHPStan reads the isset()
1436 + // as redundant and has to be told otherwise.
1437 + //
1438 + // ->editor is checked for the same reason one level down: Elementor assigns it
1439 + // in init_components() on `init`, while the singleton itself is created on
1440 + // `plugins_loaded`. Between those two hooks $instance is set and ->editor is
1441 + // still null, so checking only the singleton reproduces the original fatal a
1442 + // property later.
1443 + // @phpstan-ignore-next-line -- Stub disagrees with runtime; see above.
1444 + if ( class_exists( '\Elementor\Plugin' ) && isset( \Elementor\Plugin::$instance->editor ) && \Elementor\Plugin::$instance->editor->is_edit_mode() ) {
1445 + return;
1446 + }
1447 + if ( function_exists( 'bricks_is_builder' ) && bricks_is_builder() ) {
1448 + return;
1449 + }
1450 +
1451 + /**
1452 + * Allow integrations to suppress the admin "Edit Form" shortcut entirely.
1453 + *
1454 + * @param bool $show Whether to render the shortcut. Default true.
1455 + * @param int $form_id Form post ID.
1456 + *
1457 + * @since 2.12.4
1458 + */
1459 + if ( ! apply_filters( 'srfm_show_edit_form_button', true, $form_id ) ) {
1460 + return;
1461 + }
1462 +
1463 + $edit_link = get_edit_post_link( $form_id, 'raw' );
1464 +
1465 + if ( empty( $edit_link ) ) {
1466 + return;
1467 + }
1468 +
1469 + // Attribution marker read back by Admin::maybe_track_edit_form_button_click()
1470 + // when the editor loads. Added before the filter below so an integration that
1471 + // replaces the link wholesale drops the marker with it, rather than having our
1472 + // query arg appended to a third-party URL.
1473 + // 'url' context, not the default 'display': the latter returns &amp;-escaped
1474 + // separators, and feeding those to add_query_arg() only round-trips because
1475 + // build_query() happens to re-emit the mangled `amp;action` key verbatim. The
1476 + // raw form has no such dependency, and esc_url() below still escapes on output.
1477 + $edit_link = add_query_arg( self::EDIT_FORM_BUTTON_SOURCE_ARG, 'embed', $edit_link );
1478 +
1479 + /**
1480 + * Filter the target of the admin "Edit Form" shortcut.
1481 + *
1482 + * @param string $edit_link Editor URL for the form.
1483 + * @param int $form_id Form post ID.
1484 + *
1485 + * @since 2.12.4
1486 + */
1487 + $edit_link = Helper::get_string_value( apply_filters( 'srfm_edit_form_button_link', $edit_link, $form_id ) );
1488 +
1489 + if ( '' === $edit_link ) {
1490 + return;
1491 + }
1492 +
1493 + // Registered inline-only handle: WP_Styles dedupes by handle across every
1494 + // embedded form and prints via print_late_styles() in the footer even when
1495 + // enqueued this late (during the_content).
1496 + $style_handle = 'srfm-edit-form-btn';
1497 + if ( ! wp_style_is( $style_handle, 'registered' ) ) {
1498 + wp_register_style( $style_handle, false, [], SRFM_VER );
1499 + wp_add_inline_style( $style_handle, self::get_edit_form_button_css() );
1500 + }
1501 + wp_enqueue_style( $style_handle );
1502 + ?>
1503 + <div class="srfm-edit-form-btn-wrap">
1504 + <a class="srfm-edit-form-btn" href="<?php echo esc_url( $edit_link ); ?>" target="_blank" rel="noopener noreferrer">
1505 + <svg width="20" height="20" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M12 20h9"></path><path d="M16.5 3.5a2.12 2.12 0 0 1 3 3L7 19l-4 1 1-4Z"></path></svg>
1506 + <span><?php esc_html_e( 'Edit Form', 'sureforms' ); ?></span>
1507 + <span class="screen-reader-text"><?php esc_html_e( '(opens in a new tab)', 'sureforms' ); ?></span>
1508 + </a>
1509 + </div>
1510 + <?php
1511 + }
1512 +
1513 + /**
1514 + * Stylesheet for the admin "Edit Form" pill (#3029).
1515 + *
1516 + * The wrapper is a flow-level flex row rather than an absolute overlay, so the
1517 + * pill reserves its own space and cannot cover a field (#3062). `justify-content`
1518 + * uses the logical `flex-end`, which follows the writing direction and is
1519 + * therefore RTL-correct without a separate rule.
1520 + *
1521 + * No `position: relative` on the container any more: that rule existed solely to
1522 + * be the positioning context for the old overlay.
1523 + *
1524 + * @return string
1525 + * @since 2.12.4
1526 + */
1527 + private static function get_edit_form_button_css() {
1528 + return '
1529 + .srfm-edit-form-btn-wrap {
1530 + display: flex;
1531 + justify-content: flex-end;
1532 + margin-block-end: 8px;
1533 + }
1534 + .srfm-edit-form-btn {
1535 + display: inline-flex;
1536 + align-items: center;
1537 + gap: 6px;
1538 + padding: 6px 12px;
1539 + font-size: 13px;
1540 + font-weight: 500;
1541 + line-height: 1;
1542 + color: #1e293b;
1543 + background: #ffffff;
1544 + border: 1px solid #e2e8f0;
1545 + border-radius: 9999px;
1546 + box-shadow: 0 2px 6px rgba( 0, 0, 0, 0.12 );
1547 + text-decoration: none;
1548 + }
1549 + .srfm-edit-form-btn:hover { border-color: #cbd5e1; color: #0f172a; }
1550 + .srfm-edit-form-btn:focus-visible { outline: 2px solid #2563eb; outline-offset: 2px; }
1551 + .srfm-edit-form-btn svg { width: 14px; height: 14px; }
1552 + ';
1316 1553 }
1317 1554 }