PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | inc/create-new-form.php +35 -15 2.8.0 → 2.12.8 View file →
@@ -7,8 +7,9 @@
7 7 */
8 8
9 9 namespace SRFM\Inc;
10 10
11 +use SRFM\Inc\AI_Form_Builder\AI_Helper;
11 12 use SRFM\Inc\Traits\Get_Instance;
12 13 use WP_Error;
13 14 use WP_REST_Response;
14 15
@@ -144,30 +145,49 @@
144 145 'post_content' => $content,
145 146 'meta_input' => $post_metas,
146 147 'post_status' => 'draft',
147 148 'post_type' => 'sureforms_form',
148 - ]
149 + ],
150 + true
149 151 );
150 152
151 - if ( ! empty( $post_id ) ) {
152 -
153 - /**
154 - * Update _srfm_is_ai_generated meta to true.
155 - * If the request is coming here then the form is AI generated.
156 - */
157 - update_post_meta( $post_id, '_srfm_is_ai_generated', true );
158 -
153 + if ( is_wp_error( $post_id ) ) {
154 + // Pass the raw WP_Error through the shared sanitizer so any URLs,
155 + // request IDs, or model names injected by a filter on
156 + // wp_insert_post don't leak via the REST response. The raw message
157 + // is still logged server-side (gated on WP_DEBUG / WP_DEBUG_LOG).
158 + $sanitized = AI_Helper::sanitize_ai_error_message( $post_id->get_error_message(), 'wp_insert_post' );
159 + if ( '' === $sanitized ) {
160 + $sanitized = __( 'Error creating SureForms Form.', 'sureforms' );
161 + }
159 162 return new WP_REST_Response(
160 163 [
161 - 'message' => __( 'SureForms Form created successfully.', 'sureforms' ),
162 - 'id' => $post_id,
163 - ]
164 + 'message' => $sanitized,
165 + ],
166 + 500
164 167 );
165 168 }
166 - wp_send_json_error(
169 +
170 + if ( ! is_int( $post_id ) || $post_id <= 0 ) {
171 + return new WP_REST_Response(
167 172 [
168 - 'message' => __( 'Error creating SureForms Form, ', 'sureforms' ),
169 - ]
173 + 'message' => __( 'Error creating SureForms Form.', 'sureforms' ),
174 + ],
175 + 500
170 176 );
177 + }
178 +
179 + /**
180 + * Update _srfm_is_ai_generated meta to true.
181 + * If the request is coming here then the form is AI generated.
182 + */
183 + update_post_meta( $post_id, '_srfm_is_ai_generated', true );
184 +
185 + return new WP_REST_Response(
186 + [
187 + 'message' => __( 'SureForms Form created successfully.', 'sureforms' ),
188 + 'id' => $post_id,
189 + ]
190 + );
171 191 }
172 192
173 193 }