PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | inc/ai-form-builder/ai-form-builder.php +58 -15 2.8.0 → 2.12.8 View file →
@@ -51,8 +51,20 @@
51 51 // Add the message to the start of the messages to send to the SCS Middleware.
52 52 array_unshift( $messages, $current_message );
53 53 }
54 54
55 + // Bail if no usable prompt remained after filtering empty messages.
56 + if ( empty( $messages ) || empty( $messages[0]['content'] ) ) {
57 + wp_send_json_error( [ 'message' => __( 'No prompt was supplied.', 'sureforms' ) ] );
58 + }
59 +
60 + // Server-side prompt-length cap. The UI enforces a 2000-char limit via maxlength, but that
61 + // is client-side only and can be bypassed by a crafted request, so mirror it here. This is
62 + // cost/resource hardening — output is always escaped, so this is not an XSS concern.
63 + if ( mb_strlen( (string) $messages[0]['content'] ) > 2000 ) {
64 + wp_send_json_error( [ 'message' => __( 'The prompt is too long. Please shorten it and try again.', 'sureforms' ) ] );
65 + }
66 +
55 67 // Get the response from the endpoint.
56 68 $response = AI_Helper::get_chat_completions_response(
57 69 apply_filters(
58 70 'srfm_ai_form_generator_body',
@@ -69,24 +81,55 @@
69 81 }
70 82
71 83 if ( ! empty( $response['error'] ) ) {
72 84 // If the response has an error, handle it and report it back.
73 - $message = '';
74 - if ( ! empty( $response['error']['message'] ) ) { // If any error message received from OpenAI.
75 - $message = $response['error']['message'];
76 - } elseif ( is_string( $response['error'] ) ) { // If any error message received from server.
77 - if ( ! empty( $response['code'] && is_string( $response['code'] ) ) ) {
78 - $message = __( 'The SureForms AI Middleware encountered an error.', 'sureforms' );
79 - }
80 - $message = ! empty( $message ) ? $message : $response['error'];
85 + // We sanitize before returning so OpenAI / middleware infra details
86 + // (URLs, request IDs, model names, account IDs) do not leak to the
87 + // client; the raw message is preserved in the debug log via
88 + // AI_Helper::sanitize_ai_error_message() when WP_DEBUG[_LOG] is on.
89 + $raw = '';
90 + if ( is_array( $response['error'] ) && ! empty( $response['error']['message'] ) ) {
91 + // If any error message received from OpenAI.
92 + $raw = $response['error']['message'];
93 + } elseif ( is_string( $response['error'] ) ) {
94 + // If any error message received from the middleware server.
95 + $raw = $response['error'];
81 96 }
97 + $message = AI_Helper::sanitize_ai_error_message( $raw, 'generate/form' );
98 + if ( '' === $message ) {
99 + $message = __( 'The SureForms AI Middleware encountered an error.', 'sureforms' );
100 + }
82 101 wp_send_json_error( [ 'message' => $message ] );
83 - } elseif ( is_array( $response['form'] ) && ! empty( $response['form']['formTitle'] ) && is_array( $response['form']['formFields'] ) && ! empty( $response['form']['formFields'] ) ) {
84 - // If the message was sent successfully, send it successfully.
85 - wp_send_json_success( $response );
86 - } else {
87 - // If you've reached here, then something has definitely gone amuck. Abandon ship.
88 - wp_send_json_error( $response );
89 - }//end if
102 + }
103 +
104 + // Validate the expected form structure piece by piece so we can return specific errors.
105 + if ( empty( $response['form'] ) || ! is_array( $response['form'] ) ) {
106 + wp_send_json_error(
107 + [
108 + 'message' => __( 'The AI did not return a form. Please refine your prompt and try again.', 'sureforms' ),
109 + ]
110 + );
111 + }
112 +
113 + if ( empty( $response['form']['formTitle'] ) ) {
114 + wp_send_json_error(
115 + [
116 + 'message' => __( 'The AI response is missing a form title. Please try again.', 'sureforms' ),
117 + ]
118 + );
119 + }
120 +
121 + if (
122 + empty( $response['form']['formFields'] ) ||
123 + ! is_array( $response['form']['formFields'] )
124 + ) {
125 + wp_send_json_error(
126 + [
127 + 'message' => __( 'The AI was unable to generate form fields. Please try again.', 'sureforms' ),
128 + ]
129 + );
130 + }
131 +
132 + wp_send_json_success( $response );
90 133 }
91 134
92 135 }