PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | inc/payments/admin/admin-handler.php +52 -19 2.8.1 → 2.12.8 View file →
@@ -770,17 +770,11 @@
770 770 }
771 771
772 772 // Add status filter - map frontend status to database status.
773 773 if ( ! empty( $status ) ) {
774 - $db_status = $this->map_frontend_status_to_db( $status );
775 - if ( $db_status ) {
776 - $where_conditions[] = [
777 - [
778 - 'key' => 'status',
779 - 'compare' => '=',
780 - 'value' => $db_status,
781 - ],
782 - ];
774 + $status_clause = $this->build_status_where_clause( $status );
775 + if ( ! empty( $status_clause ) ) {
776 + $where_conditions[] = $status_clause;
783 777 }
784 778 }
785 779
786 780 // Add form_id filter.
@@ -877,9 +871,9 @@
877 871 return [ 0 ];
878 872 }
879 873
880 874 // phpcs:disable WordPress.DB.PreparedSQL.InterpolatedNotPrepared
881 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching -- Custom table query for search, table name is validated and cannot be parameterized with prepare().
875 + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, PluginCheck.Security.DirectDB.UnescapedDBParameter -- Custom table query for search; table name from get_tablename() and validated (not user input); cannot be parameterized with prepare().
882 876 $results = $wpdb->get_col(
883 877 $wpdb->prepare(
884 878 "SELECT DISTINCT id FROM {$payments_table}
885 879 WHERE id LIKE %s
@@ -1049,17 +1043,11 @@
1049 1043 ];
1050 1044 }
1051 1045
1052 1046 if ( ! empty( $status ) ) {
1053 - $db_status = $this->map_frontend_status_to_db( $status );
1054 - if ( $db_status ) {
1055 - $where_conditions[] = [
1056 - [
1057 - 'key' => 'status',
1058 - 'compare' => '=',
1059 - 'value' => $db_status,
1060 - ],
1061 - ];
1047 + $status_clause = $this->build_status_where_clause( $status );
1048 + if ( ! empty( $status_clause ) ) {
1049 + $where_conditions[] = $status_clause;
1062 1050 }
1063 1051 }
1064 1052
1065 1053 // Add form_id filter.
@@ -1117,8 +1105,53 @@
1117 1105 }
1118 1106 }
1119 1107
1120 1108 return Payments::get_total_main_payments_by_status( 'all', 0, $where_conditions );
1109 + }
1110 +
1111 + /**
1112 + * Build the WHERE clause group for the frontend status filter.
1113 + *
1114 + * For 'cancelled' the parent subscription row keeps its transaction
1115 + * `status` (e.g. 'succeeded'/'active') after cancellation, with the
1116 + * lifecycle tracked on `subscription_status`. To keep canceled
1117 + * subscriptions findable via the dropdown — and stay backward
1118 + * compatible with legacy rows that still have `status='canceled'` — we
1119 + * match either column.
1120 + *
1121 + * @param string $frontend_status Status value from the frontend filter.
1122 + * @since 2.9.0
1123 + * @return array<int|string,mixed> WHERE clause group, or empty array if invalid.
1124 + */
1125 + private function build_status_where_clause( $frontend_status ) {
1126 + $db_status = $this->map_frontend_status_to_db( $frontend_status );
1127 + if ( ! $db_status ) {
1128 + return [];
1129 + }
1130 +
1131 + if ( 'canceled' === $db_status ) {
1132 + return [
1133 + 'RELATION' => 'OR',
1134 + [
1135 + 'key' => 'status',
1136 + 'compare' => '=',
1137 + 'value' => 'canceled',
1138 + ],
1139 + [
1140 + 'key' => 'subscription_status',
1141 + 'compare' => '=',
1142 + 'value' => 'canceled',
1143 + ],
1144 + ];
1145 + }
1146 +
1147 + return [
1148 + [
1149 + 'key' => 'status',
1150 + 'compare' => '=',
1151 + 'value' => $db_status,
1152 + ],
1153 + ];
1121 1154 }
1122 1155
1123 1156 /**
1124 1157 * Get subscription billing interval from payment data.