| @@ -79,9 +79,17 @@ | ||
| 79 | 79 | foreach ( $post_ids as $post_id ) { |
| 80 | 80 | $post_id = intval( $post_id ); |
| 81 | 81 | $post = get_post( $post_id ); |
| 82 | 82 | $post_meta = get_post_meta( $post_id ); |
| 83 | - $posts[] = [ | |
| 83 | + | |
| 84 | + // The view counter belongs to this site's traffic, not to the form. These | |
| 85 | + // payloads feed shared starter templates, so shipping it would hand every | |
| 86 | + // importer a stranger's numbers. The import side already refuses the key, | |
| 87 | + // so this is about not exporting it in the first place. | |
| 88 | + if ( is_array( $post_meta ) ) { | |
| 89 | + unset( $post_meta[ \SRFM\Inc\Form_Views::META_KEY ] ); | |
| 90 | + } | |
| 91 | + $posts[] = [ | |
| 84 | 92 | 'post' => $post, |
| 85 | 93 | 'post_meta' => $post_meta, |
| 86 | 94 | ]; |
| 87 | 95 | } |
| @@ -295,8 +303,14 @@ | ||
| 295 | 303 | if ( ! in_array( $meta_key, $allowed_keys, true ) ) { |
| 296 | 304 | continue; |
| 297 | 305 | } |
| 298 | 306 | |
| 307 | + // Note: add_post_meta() internally runs wp_unslash() on the value before | |
| 308 | + // invoking the registered sanitize_callback. Imported values are unslashed, | |
| 309 | + // so without re-slashing, backslashes are stripped — corrupting JSON-string | |
| 310 | + // metas (e.g. _srfm_save_resume, _srfm_conditional_confirmation) whose escaped | |
| 311 | + // quotes (\") then fail json_decode() in their sanitizers, wiping the value to | |
| 312 | + // an empty string. wp_slash() pre-escapes so wp_unslash() restores the original. | |
| 299 | 313 | if ( in_array( $meta_key, $unserialized_meta_keys, true ) ) { |
| 300 | 314 | // Complex array metas — sanitize_callback registered via register_post_meta() |
| 301 | 315 | // is automatically invoked by add_post_meta() → update_metadata() pipeline. |
| 302 | 316 | // When Pro is inactive, some keys may lack a registered callback — apply fallback. |
| @@ -302,9 +316,9 @@ | ||
| 302 | 316 | // When Pro is inactive, some keys may lack a registered callback — apply fallback. |
| 303 | 317 | if ( empty( $registered[ $meta_key ]['sanitize_callback'] ) ) { |
| 304 | 318 | $meta_value = Helper::sanitize_by_type( $meta_value ); |
| 305 | 319 | } |
| 306 | - add_post_meta( $post_id, $meta_key, $meta_value ); | |
| 320 | + add_post_meta( $post_id, $meta_key, wp_slash( $meta_value ) ); | |
| 307 | 321 | } else { |
| 308 | 322 | // Scalar metas — unwrap single-element arrays produced by get_post_meta(). |
| 309 | 323 | $raw_value = is_array( $meta_value ) && isset( $meta_value[0] ) ? $meta_value[0] : $meta_value; |
| 310 | 324 | // Fallback sanitization — skip when a registered callback already handles it. |
| @@ -310,9 +324,9 @@ | ||
| 310 | 324 | // Fallback sanitization — skip when a registered callback already handles it. |
| 311 | 325 | if ( is_string( $raw_value ) && empty( $registered[ $meta_key ]['sanitize_callback'] ) ) { |
| 312 | 326 | $raw_value = sanitize_text_field( $raw_value ); |
| 313 | 327 | } |
| 314 | - add_post_meta( $post_id, $meta_key, $raw_value ); | |
| 328 | + add_post_meta( $post_id, $meta_key, wp_slash( $raw_value ) ); | |
| 315 | 329 | } |
| 316 | 330 | } |
| 317 | 331 | } else { |
| 318 | 332 | return new \WP_Error( 'import_forms_invalid_post_type', __( 'Unable to import form.', 'sureforms' ) ); |