PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | inc/global-settings/global-settings.php +364 -48 2.7.1 → 2.12.8 View file →
@@ -7,8 +7,9 @@
7 7 */
8 8
9 9 namespace SRFM\Inc\Global_Settings;
10 10
11 +use SRFM\Inc\Client_Logger;
11 12 use SRFM\Inc\Events_Scheduler;
12 13 use SRFM\Inc\Helper;
13 14 use SRFM\Inc\Payments\Payment_Helper;
14 15 use SRFM\Inc\Traits\Get_Instance;
@@ -16,8 +17,12 @@
16 17 use WP_REST_Request;
17 18 use WP_REST_Response;
18 19 use WP_REST_Server;
19 20
21 +if ( ! defined( 'ABSPATH' ) ) {
22 + exit;
23 +}
24 +
20 25 /**
21 26 * Sureforms Global Settings.
22 27 *
23 28 * @since 0.0.1
@@ -80,48 +85,55 @@
80 85
81 86 $nonce = Helper::get_string_value( $request->get_header( 'X-WP-Nonce' ) );
82 87
83 88 if ( ! wp_verify_nonce( sanitize_text_field( $nonce ), 'wp_rest' ) ) {
84 - wp_send_json_error(
85 - [
86 - 'data' => __( 'Nonce verification failed.', 'sureforms' ),
87 - ]
88 - );
89 + return new WP_Error( 'rest_nonce_invalid', __( 'Nonce verification failed.', 'sureforms' ), [ 'status' => 403 ] );
89 90 }
90 91
91 92 $setting_options = $request->get_params();
92 93
93 - $tab = $setting_options['srfm_tab'];
94 + $tab = $setting_options['srfm_tab'] ?? '';
94 95
95 96 unset( $setting_options['srfm_tab'] );
96 97
97 98 switch ( $tab ) {
98 99 case 'general-settings':
99 - $is_option_saved = self::srfm_save_general_settings( $setting_options );
100 + self::srfm_save_general_settings( $setting_options );
100 101 break;
101 102 case 'general-settings-dynamic-opt':
102 - $is_option_saved = self::srfm_save_general_settings_dynamic_opt( $setting_options );
103 + self::srfm_save_general_settings_dynamic_opt( $setting_options );
103 104 break;
104 105 case 'email-settings':
105 - $is_option_saved = self::srfm_save_email_summary_settings( $setting_options );
106 + self::srfm_save_email_summary_settings( $setting_options );
106 107 break;
107 108 case 'security-settings':
108 - $is_option_saved = self::srfm_save_security_settings( $setting_options );
109 + self::srfm_save_security_settings( $setting_options );
109 110 break;
110 111 case 'payments-settings':
111 - $is_option_saved = self::srfm_save_payments_settings( $setting_options );
112 + self::srfm_save_payments_settings( $setting_options );
112 113 break;
113 114 case 'mcp-settings':
114 - $is_option_saved = self::srfm_save_mcp_settings( $setting_options );
115 + self::srfm_save_mcp_settings( $setting_options );
115 116 break;
117 + case 'form-restriction-settings':
118 + self::srfm_save_form_restriction_settings( $setting_options );
119 + break;
120 + case 'compliance-settings':
121 + self::srfm_save_compliance_settings( $setting_options );
122 + break;
123 + case 'form-confirmation-settings':
124 + self::srfm_save_form_confirmation_settings( $setting_options );
125 + break;
126 + case 'email-notification-settings':
127 + self::srfm_save_email_notification_settings( $setting_options );
128 + break;
116 129 default:
117 - $is_option_saved = false;
118 - break;
130 + return new WP_Error( 'srfm_invalid_tab', __( 'Invalid settings tab.', 'sureforms' ), [ 'status' => 400 ] );
119 131 }
120 132
121 - if ( ! $is_option_saved ) {
122 - return new WP_Error( __( 'Error Saving Settings!', 'sureforms' ), __( 'Global Settings', 'sureforms' ) );
123 - }
133 + // update_option() returns false when the stored value already matches
134 + // the new value — that is not an error, so we only flag truly invalid
135 + // tabs (handled in default above) and always return success here.
124 136 return new WP_REST_Response(
125 137 [
126 138 'data' => __( 'Settings Saved Successfully.', 'sureforms' ),
127 139 ]
@@ -136,17 +148,23 @@
136 148 * @since 0.0.1
137 149 */
138 150 public static function srfm_save_general_settings( $setting_options ) {
139 151
140 - $srfm_ip_log = $setting_options['srfm_ip_log'] ?? false;
141 - $srfm_form_analytics = $setting_options['srfm_form_analytics'] ?? false;
142 - $srfm_bsf_analytics = $setting_options['srfm_bsf_analytics'] ?? false;
143 - $srfm_admin_notification = isset( $setting_options['srfm_admin_notification'] ) ? (bool) $setting_options['srfm_admin_notification'] : true;
152 + $srfm_ip_log = $setting_options['srfm_ip_log'] ?? false;
153 + $srfm_form_analytics = $setting_options['srfm_form_analytics'] ?? false;
154 + $srfm_bsf_analytics = $setting_options['srfm_bsf_analytics'] ?? false;
155 + $srfm_admin_notification = isset( $setting_options['srfm_admin_notification'] ) ? (bool) $setting_options['srfm_admin_notification'] : true;
156 + $srfm_form_views_tracking = isset( $setting_options['srfm_form_views_tracking'] ) ? (bool) $setting_options['srfm_form_views_tracking'] : false;
157 + // Absent means on, matching Client_Logger::is_enabled(). A save that omits
158 + // the key must not be read as the site opting out.
159 + $srfm_enable_logs = isset( $setting_options['srfm_enable_logs'] ) ? (bool) $setting_options['srfm_enable_logs'] : true;
144 160
145 161 $settings = [
146 - 'srfm_ip_log' => $srfm_ip_log,
147 - 'srfm_form_analytics' => $srfm_form_analytics,
148 - 'srfm_admin_notification' => $srfm_admin_notification,
162 + 'srfm_ip_log' => $srfm_ip_log,
163 + 'srfm_form_analytics' => $srfm_form_analytics,
164 + 'srfm_admin_notification' => $srfm_admin_notification,
165 + 'srfm_form_views_tracking' => $srfm_form_views_tracking,
166 + 'srfm_enable_logs' => $srfm_enable_logs,
149 167 ];
150 168
151 169 /**
152 170 * We are updating sureforms_analytics_optin option from the general settings as it has been introduced
@@ -212,8 +230,11 @@
212 230 'srfm_valid_phone_number',
213 231 'srfm_valid_url',
214 232 'srfm_confirm_email_same',
215 233 'srfm_valid_email',
234 + 'srfm_textarea_min_chars',
235 + 'srfm_email_local_max_length',
236 + 'srfm_email_domain_max_length',
216 237 'srfm_input_min_value',
217 238 'srfm_input_max_value',
218 239 'srfm_dropdown_min_selections',
219 240 'srfm_dropdown_max_selections',
@@ -273,19 +294,19 @@
273 294 * @since 0.0.1
274 295 */
275 296 public static function srfm_save_security_settings( $setting_options ) {
276 297
277 - $srfm_v2_checkbox_site_key = $setting_options['srfm_v2_checkbox_site_key'] ?? '';
278 - $srfm_v2_checkbox_secret_key = $setting_options['srfm_v2_checkbox_secret_key'] ?? '';
279 - $srfm_v2_invisible_site_key = $setting_options['srfm_v2_invisible_site_key'] ?? '';
280 - $srfm_v2_invisible_secret_key = $setting_options['srfm_v2_invisible_secret_key'] ?? '';
281 - $srfm_v3_site_key = $setting_options['srfm_v3_site_key'] ?? '';
282 - $srfm_v3_secret_key = $setting_options['srfm_v3_secret_key'] ?? '';
283 - $srfm_cf_appearance_mode = $setting_options['srfm_cf_appearance_mode'] ?? 'auto';
284 - $srfm_cf_turnstile_site_key = $setting_options['srfm_cf_turnstile_site_key'] ?? '';
285 - $srfm_cf_turnstile_secret_key = $setting_options['srfm_cf_turnstile_secret_key'] ?? '';
286 - $srfm_hcaptcha_site_key = ! empty( $setting_options['srfm_hcaptcha_site_key'] ) ? $setting_options['srfm_hcaptcha_site_key'] : '';
287 - $srfm_hcaptcha_secret_key = ! empty( $setting_options['srfm_hcaptcha_secret_key'] ) ? $setting_options['srfm_hcaptcha_secret_key'] : '';
298 + $srfm_v2_checkbox_site_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_v2_checkbox_site_key'] ?? '' ) );
299 + $srfm_v2_checkbox_secret_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_v2_checkbox_secret_key'] ?? '' ) );
300 + $srfm_v2_invisible_site_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_v2_invisible_site_key'] ?? '' ) );
301 + $srfm_v2_invisible_secret_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_v2_invisible_secret_key'] ?? '' ) );
302 + $srfm_v3_site_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_v3_site_key'] ?? '' ) );
303 + $srfm_v3_secret_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_v3_secret_key'] ?? '' ) );
304 + $srfm_cf_appearance_mode = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_cf_appearance_mode'] ?? 'auto' ) );
305 + $srfm_cf_turnstile_site_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_cf_turnstile_site_key'] ?? '' ) );
306 + $srfm_cf_turnstile_secret_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_cf_turnstile_secret_key'] ?? '' ) );
307 + $srfm_hcaptcha_site_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_hcaptcha_site_key'] ?? '' ) );
308 + $srfm_hcaptcha_secret_key = sanitize_text_field( Helper::get_string_value( $setting_options['srfm_hcaptcha_secret_key'] ?? '' ) );
288 309 $srfm_honeypot = $setting_options['srfm_honeypot'] ?? false;
289 310
290 311 return update_option(
291 312 'srfm_security_settings_options',
@@ -386,12 +407,229 @@
386 407 );
387 408 }
388 409
389 410 /**
411 + * Save Form Restriction Settings
412 + *
413 + * Handles saving of the free Maximum Entries subsection. Pro-only
414 + * subsections (IP, Country, Keyword) are persisted via the Pro plugin's
415 + * own REST endpoint and option key, so the existing values for those
416 + * sub-keys are preserved here via array merge.
417 + *
418 + * @param array<mixed> $setting_options Setting options.
419 + * @return bool
420 + * @since 2.9.0
421 + */
422 + public static function srfm_save_form_restriction_settings( $setting_options ) {
423 + $max_entries = isset( $setting_options['max_entries'] ) && is_array( $setting_options['max_entries'] ) ? $setting_options['max_entries'] : [];
424 +
425 + $existing = get_option( 'srfm_form_restriction_settings_options', [] );
426 + if ( ! is_array( $existing ) ) {
427 + $existing = [];
428 + }
429 +
430 + $settings = $existing;
431 + $settings['max_entries'] = [
432 + 'status' => isset( $max_entries['status'] ) ? (bool) $max_entries['status'] : false,
433 + 'maxEntries' => isset( $max_entries['maxEntries'] ) ? absint( $max_entries['maxEntries'] ) : 0,
434 + 'message' => isset( $max_entries['message'] ) ? sanitize_textarea_field( (string) $max_entries['message'] ) : __( "This form is now closed as we've received all the entries.", 'sureforms' ),
435 + ];
436 +
437 + return update_option( 'srfm_form_restriction_settings_options', $settings );
438 + }
439 +
440 + /**
441 + * Save Compliance Settings
442 + *
443 + * Handles saving of global compliance settings that serve as defaults
444 + * for newly created forms.
445 + *
446 + * @param array<mixed> $setting_options Setting options.
447 + * @return bool
448 + * @since 2.9.0
449 + */
450 + public static function srfm_save_compliance_settings( $setting_options ) {
451 + $settings = [
452 + 'gdpr' => isset( $setting_options['gdpr'] ) ? (bool) $setting_options['gdpr'] : false,
453 + 'do_not_store_entries' => isset( $setting_options['do_not_store_entries'] ) ? (bool) $setting_options['do_not_store_entries'] : false,
454 + 'auto_delete_entries' => isset( $setting_options['auto_delete_entries'] ) ? (bool) $setting_options['auto_delete_entries'] : false,
455 + 'auto_delete_days' => isset( $setting_options['auto_delete_days'] ) ? absint( $setting_options['auto_delete_days'] ) : 30,
456 + ];
457 +
458 + return update_option( 'srfm_compliance_settings_options', $settings );
459 + }
460 +
461 + /**
462 + * Get default compliance settings.
463 + *
464 + * @return array<string, mixed>
465 + * @since 2.9.0
466 + */
467 + public static function get_default_compliance_settings() {
468 + return [
469 + 'gdpr' => false,
470 + 'do_not_store_entries' => false,
471 + 'auto_delete_entries' => false,
472 + 'auto_delete_days' => 30,
473 + ];
474 + }
475 +
476 + /**
477 + * Save Form Confirmation Settings
478 + *
479 + * Handles saving of global form confirmation settings that serve as defaults
480 + * for newly created forms.
481 + *
482 + * @param array<mixed> $setting_options Setting options.
483 + * @return bool
484 + * @since 2.9.0
485 + */
486 + public static function srfm_save_form_confirmation_settings( $setting_options ) {
487 + $valid_confirmation_types = [ 'same page', 'different page', 'custom url' ];
488 + $valid_submission_actions = [ 'hide form', 'reset form' ];
489 +
490 + $message = isset( $setting_options['message'] ) ? wp_kses_post( Helper::get_string_value( $setting_options['message'] ) ) : __( 'Thank you for contacting us! We will be in touch with you shortly.', 'sureforms' );
491 +
492 + // Sanitize query parameters — each item is a key-value object.
493 + $query_params = [];
494 + if ( isset( $setting_options['query_params'] ) && is_array( $setting_options['query_params'] ) ) {
495 + foreach ( $setting_options['query_params'] as $param ) {
496 + if ( is_array( $param ) ) {
497 + $sanitized_param = [];
498 + foreach ( $param as $key => $value ) {
499 + $sanitized_param[ sanitize_text_field( $key ) ] = sanitize_text_field( $value );
500 + }
501 + $query_params[] = $sanitized_param;
502 + }
503 + }
504 + }
505 +
506 + $settings = [
507 + 'confirmation_type' => isset( $setting_options['confirmation_type'] ) && in_array( $setting_options['confirmation_type'], $valid_confirmation_types, true )
508 + ? sanitize_text_field( $setting_options['confirmation_type'] )
509 + : 'same page',
510 + 'message' => $message,
511 + 'submission_action' => isset( $setting_options['submission_action'] ) && in_array( $setting_options['submission_action'], $valid_submission_actions, true )
512 + ? sanitize_text_field( $setting_options['submission_action'] )
513 + : 'hide form',
514 + 'page_url' => isset( $setting_options['page_url'] ) ? esc_url_raw( $setting_options['page_url'] ) : '',
515 + 'custom_url' => isset( $setting_options['custom_url'] ) ? esc_url_raw( $setting_options['custom_url'] ) : '',
516 + 'enable_query_params' => ! empty( $setting_options['enable_query_params'] ),
517 + 'query_params' => $query_params,
518 + ];
519 +
520 + return update_option( 'srfm_form_confirmation_settings_options', $settings );
521 + }
522 +
523 + /**
524 + * Get the default confirmation success message HTML.
525 + *
526 + * Builds the rich HTML block (icon + heading + description) used as the
527 + * initial value for the form confirmation message field. Centralised here
528 + * so both the settings GET endpoint and the form-defaults applier share
529 + * exactly the same value without duplication.
530 + *
531 + * @return string
532 + * @since 2.9.0
533 + */
534 + public static function get_default_confirmation_message() {
535 + $check_icon = esc_url( plugins_url( 'images/check-icon.svg', SRFM_FILE ) );
536 + return '<p style="text-align: center;"><img src="' . $check_icon . '" alt="" aria-hidden="true" /></p><h2 style="text-align: center;">'
537 + . esc_html__( 'Thank you', 'sureforms' ) . '</h2><p style="text-align: center;">'
538 + . esc_html__( 'Your form has been submitted successfully. We\'ll review your details and get back to you soon.', 'sureforms' ) . '</p>';
539 + }
540 +
541 + /**
542 + * Get default form confirmation settings.
543 + *
544 + * @return array<string, mixed>
545 + * @since 2.9.0
546 + */
547 + public static function get_default_form_confirmation_settings() {
548 + return [
549 + 'confirmation_type' => 'same page',
550 + 'message' => self::get_default_confirmation_message(),
551 + 'submission_action' => 'hide form',
552 + 'page_url' => '',
553 + 'custom_url' => '',
554 + 'enable_query_params' => false,
555 + 'query_params' => [],
556 + ];
557 + }
558 +
559 + /**
560 + * Save Email Notification Settings
561 + *
562 + * Handles saving of global email notification settings that serve as defaults
563 + * for newly created forms.
564 + *
565 + * @param array<mixed> $setting_options Setting options.
566 + * @return bool
567 + * @since 2.9.0
568 + */
569 + public static function srfm_save_email_notification_settings( $setting_options ) {
570 + $settings = [
571 + 'email_to' => isset( $setting_options['email_to'] ) ? sanitize_text_field( Helper::get_string_value( $setting_options['email_to'] ) ) : '',
572 + 'subject' => isset( $setting_options['subject'] ) ? sanitize_text_field( Helper::get_string_value( $setting_options['subject'] ) ) : '',
573 + 'email_body' => isset( $setting_options['email_body'] ) ? wp_kses_post( Helper::get_string_value( $setting_options['email_body'] ) ) : '',
574 + 'from_name' => isset( $setting_options['from_name'] ) ? sanitize_text_field( Helper::get_string_value( $setting_options['from_name'] ) ) : '{site_title}',
575 + 'from_email' => isset( $setting_options['from_email'] ) ? sanitize_text_field( Helper::get_string_value( $setting_options['from_email'] ) ) : '{admin_email}',
576 + 'email_cc' => isset( $setting_options['email_cc'] ) ? sanitize_text_field( Helper::get_string_value( $setting_options['email_cc'] ) ) : '',
577 + 'email_bcc' => isset( $setting_options['email_bcc'] ) ? sanitize_text_field( Helper::get_string_value( $setting_options['email_bcc'] ) ) : '',
578 + 'email_reply_to' => isset( $setting_options['email_reply_to'] ) ? sanitize_text_field( Helper::get_string_value( $setting_options['email_reply_to'] ) ) : '',
579 + ];
580 +
581 + return update_option( 'srfm_email_notification_settings_options', $settings );
582 + }
583 +
584 + /**
585 + * Get default email notification settings.
586 + *
587 + * @return array<string, mixed>
588 + * @since 2.9.0
589 + */
590 + public static function get_default_email_notification_settings() {
591 + return [
592 + 'email_to' => '{admin_email}',
593 + 'subject' => sprintf(
594 + /* translators: %s: {form_title} smart tag placeholder. */
595 + __( 'New Form Submission - %s', 'sureforms' ),
596 + '{form_title}'
597 + ),
598 + 'email_body' => '{all_data}',
599 + 'from_name' => '{site_title}',
600 + 'from_email' => '{admin_email}',
601 + 'email_cc' => '{admin_email}',
602 + 'email_bcc' => '{admin_email}',
603 + 'email_reply_to' => '{admin_email}',
604 + ];
605 + }
606 +
607 + /**
608 + * Get default form restriction settings.
609 + *
610 + * Free only ships defaults for the Maximum Entries subsection. Pro-only
611 + * subsections (IP, Country, Keyword) ship their own defaults from the
612 + * Pro plugin.
613 + *
614 + * @return array<string, array<string, mixed>>
615 + * @since 2.9.0
616 + */
617 + public static function get_default_form_restriction_settings() {
618 + return [
619 + 'max_entries' => [
620 + 'status' => false,
621 + 'maxEntries' => 0,
622 + 'message' => __( "This form is now closed as we've received all the entries.", 'sureforms' ),
623 + ],
624 + ];
625 + }
626 +
627 + /**
390 628 * Get Settings Form Data
391 629 *
392 630 * @param \WP_REST_Request $request Request object or array containing form data.
393 - * @return void
631 + * @return WP_REST_Response|WP_Error
394 632 * @since 0.0.1
395 633 */
396 634 public static function srfm_get_general_settings( $request ) {
397 635
@@ -397,13 +635,9 @@
397 635
398 636 $nonce = Helper::get_string_value( $request->get_header( 'X-WP-Nonce' ) );
399 637
400 638 if ( ! wp_verify_nonce( sanitize_text_field( $nonce ), 'wp_rest' ) ) {
401 - wp_send_json_error(
402 - [
403 - 'data' => __( 'Nonce verification failed.', 'sureforms' ),
404 - ]
405 - );
639 + return new WP_Error( 'rest_nonce_invalid', __( 'Nonce verification failed.', 'sureforms' ), [ 'status' => 403 ] );
406 640 }
407 641
408 642 $options_to_get = $request->get_param( 'options_to_fetch' );
409 643
@@ -410,24 +644,35 @@
410 644 $options_to_get = Helper::get_string_value( $options_to_get );
411 645
412 646 $options_to_get = explode( ',', $options_to_get );
413 647
414 - // Restrict to known SureForms options to prevent arbitrary option disclosure.
648 + // Restrict fetched keys to known plugin options to prevent reading
649 + // arbitrary wp_options values (even though manage_options is required).
415 650 $allowed_options = [
416 651 'srfm_general_settings_options',
417 652 'srfm_email_summary_settings_options',
418 653 'srfm_security_settings_options',
419 654 'srfm_default_dynamic_block_option',
655 + 'srfm_mcp_settings_options',
656 + 'srfm_form_restriction_settings_options',
657 + 'srfm_compliance_settings_options',
658 + 'srfm_form_confirmation_settings_options',
659 + 'srfm_email_notification_settings_options',
420 660 ];
421 661 $options_to_get = array_values( array_intersect( array_map( 'sanitize_text_field', $options_to_get ), $allowed_options ) );
422 662
423 - $global_setting_options = get_options( $options_to_get );
663 + $global_setting_options = [];
664 + foreach ( $options_to_get as $option_name ) {
665 + $global_setting_options[ $option_name ] = get_option( $option_name, [] );
666 + }
424 667
425 - if ( empty( $global_setting_options['srfm_general_settings_options'] ) ) {
668 + if ( empty( $global_setting_options['srfm_general_settings_options'] ) || ! is_array( $global_setting_options['srfm_general_settings_options'] ) ) {
426 669 $global_setting_options['srfm_general_settings_options'] = [
427 - 'srfm_ip_log' => false,
428 - 'srfm_form_analytics' => false,
429 - 'srfm_admin_notification' => true,
670 + 'srfm_ip_log' => false,
671 + 'srfm_form_analytics' => false,
672 + 'srfm_admin_notification' => true,
673 + 'srfm_form_views_tracking' => false,
674 + 'srfm_enable_logs' => true,
430 675 ];
431 676 }
432 677
433 678 if ( ! isset( $global_setting_options['srfm_general_settings_options']['srfm_admin_notification'] ) ) {
@@ -433,8 +678,20 @@
433 678 if ( ! isset( $global_setting_options['srfm_general_settings_options']['srfm_admin_notification'] ) ) {
434 679 $global_setting_options['srfm_general_settings_options']['srfm_admin_notification'] = true;
435 680 }
436 681
682 + if ( ! isset( $global_setting_options['srfm_general_settings_options']['srfm_form_views_tracking'] ) ) {
683 + $global_setting_options['srfm_general_settings_options']['srfm_form_views_tracking'] = false;
684 + }
685 +
686 + // Back-fill for installs whose option predates the setting. Logging is on by
687 + // default, so an absent key means on, not off.
688 + if ( ! isset( $global_setting_options['srfm_general_settings_options']['srfm_enable_logs'] ) ) {
689 + $global_setting_options['srfm_general_settings_options']['srfm_enable_logs'] = true;
690 + }
691 +
692 + $global_setting_options['srfm_log_file_size'] = Client_Logger::get_file_size();
693 +
437 694 /**
438 695 * We have introduced toggle for analytics optin in the general settings.
439 696 * Hence retrieving the option sureforms_analytics_optin to get current status.
440 697 *
@@ -480,11 +737,70 @@
480 737 'srfm_mcp_server' => (bool) get_option( 'srfm_mcp_server', false ),
481 738 ];
482 739 }
483 740
741 + // Get form restriction settings with defaults.
742 + $form_restriction_settings = get_option( 'srfm_form_restriction_settings_options', [] );
743 + if ( empty( $form_restriction_settings ) || ! is_array( $form_restriction_settings ) ) {
744 + $form_restriction_settings = self::get_default_form_restriction_settings();
745 + } else {
746 + // Merge with defaults to ensure all keys exist.
747 + $form_restriction_settings = array_replace_recursive(
748 + self::get_default_form_restriction_settings(),
749 + $form_restriction_settings
750 + );
751 + }
752 + $global_setting_options['srfm_form_restriction_settings_options'] = $form_restriction_settings;
753 +
754 + // Get compliance settings with defaults.
755 + $compliance_settings = get_option( 'srfm_compliance_settings_options', [] );
756 + if ( empty( $compliance_settings ) || ! is_array( $compliance_settings ) ) {
757 + $compliance_settings = self::get_default_compliance_settings();
758 + } else {
759 + // Merge with defaults to ensure all keys exist.
760 + $compliance_settings = array_merge(
761 + self::get_default_compliance_settings(),
762 + $compliance_settings
763 + );
764 + }
765 + $global_setting_options['srfm_compliance_settings_options'] = $compliance_settings;
766 +
767 + // Get form confirmation settings with defaults.
768 + $form_confirmation_settings = get_option( 'srfm_form_confirmation_settings_options', [] );
769 + if ( empty( $form_confirmation_settings ) || ! is_array( $form_confirmation_settings ) ) {
770 + $form_confirmation_settings = self::get_default_form_confirmation_settings();
771 + } else {
772 + // Merge with defaults to ensure all keys exist.
773 + $form_confirmation_settings = array_merge(
774 + self::get_default_form_confirmation_settings(),
775 + $form_confirmation_settings
776 + );
777 + }
778 + // Restore "data:" prefix stripped by wp_kses_post() in previous saves.
779 + if ( isset( $form_confirmation_settings['message'] ) && is_string( $form_confirmation_settings['message'] ) && false !== strpos( $form_confirmation_settings['message'], 'src="image/svg+xml;base64' ) ) {
780 + $normalized = preg_replace( '/src="image\/svg\+xml;base64/', 'src="data:image/svg+xml;base64', $form_confirmation_settings['message'] );
781 + if ( is_string( $normalized ) ) {
782 + $form_confirmation_settings['message'] = $normalized;
783 + }
784 + }
785 + $global_setting_options['srfm_form_confirmation_settings_options'] = $form_confirmation_settings;
786 +
787 + // Get email notification settings with defaults.
788 + $email_notification_settings = get_option( 'srfm_email_notification_settings_options', [] );
789 + if ( empty( $email_notification_settings ) || ! is_array( $email_notification_settings ) ) {
790 + $email_notification_settings = self::get_default_email_notification_settings();
791 + } else {
792 + // Merge with defaults to ensure all keys exist.
793 + $email_notification_settings = array_merge(
794 + self::get_default_email_notification_settings(),
795 + $email_notification_settings
796 + );
797 + }
798 + $global_setting_options['srfm_email_notification_settings_options'] = $email_notification_settings;
799 +
484 800 // Apply filter to allow other modules to add their settings.
485 801 $global_setting_options = apply_filters( 'srfm_global_settings_data', $global_setting_options );
486 802
487 - wp_send_json( $global_setting_options );
803 + return new WP_REST_Response( $global_setting_options );
488 804 }
489 805
490 806 }