PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.7.1
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.7.1
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
sureforms / inc / global-settings / global-settings.php

global-settings.php in SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz 2.7.1, at inc/global-settings/global-settings.php

491 lines 16.6 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * Sureforms Global Settings.
4 *
5 * @package sureforms.
6 * @since 0.0.1
7 */
8
9 namespace SRFM\Inc\Global_Settings;
10
11 use SRFM\Inc\Events_Scheduler;
12 use SRFM\Inc\Helper;
13 use SRFM\Inc\Payments\Payment_Helper;
14 use SRFM\Inc\Traits\Get_Instance;
15 use WP_Error;
16 use WP_REST_Request;
17 use WP_REST_Response;
18 use WP_REST_Server;
19
20 /**
21 * Sureforms Global Settings.
22 *
23 * @since 0.0.1
24 */
25 class Global_Settings {
26 use Get_Instance;
27
28 /**
29 * Namespace.
30 *
31 * @var string
32 */
33 protected $namespace = 'sureforms/v1';
34
35 /**
36 * Constructor
37 *
38 * @since 0.0.1
39 */
40 public function __construct() {
41 add_action( 'rest_api_init', [ $this, 'register_custom_endpoint' ] );
42 }
43
44 /**
45 * Add custom API Route submit-form
46 *
47 * @return void
48 * @since 0.0.1
49 */
50 public function register_custom_endpoint() {
51 register_rest_route(
52 $this->namespace,
53 '/srfm-global-settings',
54 [
55 'methods' => WP_REST_Server::EDITABLE,
56 'callback' => [ $this, 'srfm_save_global_settings' ],
57 'permission_callback' => [ Helper::class, 'get_items_permissions_check' ],
58 ]
59 );
60 register_rest_route(
61 $this->namespace,
62 '/srfm-global-settings',
63 [
64 'methods' => WP_REST_Server::READABLE,
65 'callback' => [ $this, 'srfm_get_general_settings' ],
66 'permission_callback' => [ Helper::class, 'get_items_permissions_check' ],
67 ]
68 );
69 }
70
71 /**
72 * Save global settings options.
73 *
74 * @param WP_REST_Request $request Request object.
75 * @return WP_REST_Response|WP_Error
76 *
77 * @since 0.0.1
78 */
79 public static function srfm_save_global_settings( $request ) {
80
81 $nonce = Helper::get_string_value( $request->get_header( 'X-WP-Nonce' ) );
82
83 if ( ! wp_verify_nonce( sanitize_text_field( $nonce ), 'wp_rest' ) ) {
84 wp_send_json_error(
85 [
86 'data' => __( 'Nonce verification failed.', 'sureforms' ),
87 ]
88 );
89 }
90
91 $setting_options = $request->get_params();
92
93 $tab = $setting_options['srfm_tab'];
94
95 unset( $setting_options['srfm_tab'] );
96
97 switch ( $tab ) {
98 case 'general-settings':
99 $is_option_saved = self::srfm_save_general_settings( $setting_options );
100 break;
101 case 'general-settings-dynamic-opt':
102 $is_option_saved = self::srfm_save_general_settings_dynamic_opt( $setting_options );
103 break;
104 case 'email-settings':
105 $is_option_saved = self::srfm_save_email_summary_settings( $setting_options );
106 break;
107 case 'security-settings':
108 $is_option_saved = self::srfm_save_security_settings( $setting_options );
109 break;
110 case 'payments-settings':
111 $is_option_saved = self::srfm_save_payments_settings( $setting_options );
112 break;
113 case 'mcp-settings':
114 $is_option_saved = self::srfm_save_mcp_settings( $setting_options );
115 break;
116 default:
117 $is_option_saved = false;
118 break;
119 }
120
121 if ( ! $is_option_saved ) {
122 return new WP_Error( __( 'Error Saving Settings!', 'sureforms' ), __( 'Global Settings', 'sureforms' ) );
123 }
124 return new WP_REST_Response(
125 [
126 'data' => __( 'Settings Saved Successfully.', 'sureforms' ),
127 ]
128 );
129 }
130
131 /**
132 * Save General Settings
133 *
134 * @param array<mixed> $setting_options Setting options.
135 * @return bool
136 * @since 0.0.1
137 */
138 public static function srfm_save_general_settings( $setting_options ) {
139
140 $srfm_ip_log = $setting_options['srfm_ip_log'] ?? false;
141 $srfm_form_analytics = $setting_options['srfm_form_analytics'] ?? false;
142 $srfm_bsf_analytics = $setting_options['srfm_bsf_analytics'] ?? false;
143 $srfm_admin_notification = isset( $setting_options['srfm_admin_notification'] ) ? (bool) $setting_options['srfm_admin_notification'] : true;
144
145 $settings = [
146 'srfm_ip_log' => $srfm_ip_log,
147 'srfm_form_analytics' => $srfm_form_analytics,
148 'srfm_admin_notification' => $srfm_admin_notification,
149 ];
150
151 /**
152 * We are updating sureforms_analytics_optin option from the general settings as it has been introduced
153 * as part of general settings. Since the option sureforms_analytics_optin is already available from BSF analytics library
154 * We are updating this independently.
155 *
156 * @since 1.7.0
157 *
158 * @since 2.5.1 - Renamed sureforms_analytics_optin to sureforms_usage_optin.
159 */
160 $analytics_result = self::update_bsf_analytics( $srfm_bsf_analytics );
161
162 $general_result = update_option( 'srfm_general_settings_options', $settings );
163
164 /**
165 * Returns the output of update_bsf_analytics or srfm_general_settings_options option.
166 *
167 * @since 1.7.0
168 */
169 return $analytics_result || $general_result;
170 }
171
172 /**
173 * Toggle BSF analytics usage tracking in WP general settings.
174 *
175 * @param array<mixed> $settings general settings array.
176 * @return bool
177 * @since 1.7.0
178 */
179 public static function update_bsf_analytics( $settings ) {
180 if ( true === $settings ) {
181 $enable_tracking = 'yes';
182 } else {
183 $enable_tracking = '';
184 }
185
186 return update_option( 'sureforms_usage_optin', $enable_tracking );
187 }
188
189 /**
190 * Save General Settings Dynamic Options
191 *
192 * @param array<mixed> $setting_options Setting options.
193 * @return bool
194 * @since 0.0.1
195 */
196 public static function srfm_save_general_settings_dynamic_opt( $setting_options ) {
197 $options_keys = [
198 'srfm_url_block_required_text',
199 'srfm_input_block_required_text',
200 'srfm_input_block_unique_text',
201 'srfm_address_block_required_text',
202 'srfm_phone_block_required_text',
203 'srfm_phone_block_unique_text',
204 'srfm_number_block_required_text',
205 'srfm_textarea_block_required_text',
206 'srfm_multi_choice_block_required_text',
207 'srfm_checkbox_block_required_text',
208 'srfm_gdpr_block_required_text',
209 'srfm_email_block_required_text',
210 'srfm_email_block_unique_text',
211 'srfm_dropdown_block_required_text',
212 'srfm_valid_phone_number',
213 'srfm_valid_url',
214 'srfm_confirm_email_same',
215 'srfm_valid_email',
216 'srfm_input_min_value',
217 'srfm_input_max_value',
218 'srfm_dropdown_min_selections',
219 'srfm_dropdown_max_selections',
220 'srfm_multi_choice_min_selections',
221 'srfm_multi_choice_max_selections',
222 ];
223
224 $options_names = [];
225
226 foreach ( $options_keys as $key ) {
227 if ( isset( $setting_options[ $key ] ) ) {
228 $value = $setting_options[ $key ];
229 $options_names[ $key ] = sanitize_text_field( is_scalar( $value ) ? (string) $value : '' );
230 }
231 }
232
233 // Re-sanitize after filter so Pro-injected keys are also covered.
234 $options_to_save = apply_filters( 'srfm_general_dynamic_options_to_save', $options_names, $setting_options );
235 $options_to_save = array_map( 'sanitize_text_field', $options_to_save );
236 return update_option( 'srfm_default_dynamic_block_option', $options_to_save );
237 }
238
239 /**
240 * Save Email Summary Settings
241 *
242 * @param array<mixed> $setting_options Setting options.
243 * @return bool
244 * @since 0.0.1
245 */
246 public static function srfm_save_email_summary_settings( $setting_options ) {
247
248 $srfm_email_summary = $setting_options['srfm_email_summary'] ?? false;
249 $srfm_email_sent_to = sanitize_email( $setting_options['srfm_email_sent_to'] ?? get_option( 'admin_email' ) );
250 $srfm_schedule_report = $setting_options['srfm_schedule_report'] ?? __( 'Monday', 'sureforms' );
251
252 Events_Scheduler::unschedule_events( 'srfm_weekly_scheduled_events' );
253
254 if ( $srfm_email_summary ) {
255 Email_Summary::schedule_weekly_entries_email();
256 }
257
258 return update_option(
259 'srfm_email_summary_settings_options',
260 [
261 'srfm_email_summary' => $srfm_email_summary,
262 'srfm_email_sent_to' => $srfm_email_sent_to,
263 'srfm_schedule_report' => $srfm_schedule_report,
264 ]
265 );
266 }
267
268 /**
269 * Save Security Settings
270 *
271 * @param array<mixed> $setting_options Setting options.
272 * @return bool
273 * @since 0.0.1
274 */
275 public static function srfm_save_security_settings( $setting_options ) {
276
277 $srfm_v2_checkbox_site_key = $setting_options['srfm_v2_checkbox_site_key'] ?? '';
278 $srfm_v2_checkbox_secret_key = $setting_options['srfm_v2_checkbox_secret_key'] ?? '';
279 $srfm_v2_invisible_site_key = $setting_options['srfm_v2_invisible_site_key'] ?? '';
280 $srfm_v2_invisible_secret_key = $setting_options['srfm_v2_invisible_secret_key'] ?? '';
281 $srfm_v3_site_key = $setting_options['srfm_v3_site_key'] ?? '';
282 $srfm_v3_secret_key = $setting_options['srfm_v3_secret_key'] ?? '';
283 $srfm_cf_appearance_mode = $setting_options['srfm_cf_appearance_mode'] ?? 'auto';
284 $srfm_cf_turnstile_site_key = $setting_options['srfm_cf_turnstile_site_key'] ?? '';
285 $srfm_cf_turnstile_secret_key = $setting_options['srfm_cf_turnstile_secret_key'] ?? '';
286 $srfm_hcaptcha_site_key = ! empty( $setting_options['srfm_hcaptcha_site_key'] ) ? $setting_options['srfm_hcaptcha_site_key'] : '';
287 $srfm_hcaptcha_secret_key = ! empty( $setting_options['srfm_hcaptcha_secret_key'] ) ? $setting_options['srfm_hcaptcha_secret_key'] : '';
288 $srfm_honeypot = $setting_options['srfm_honeypot'] ?? false;
289
290 return update_option(
291 'srfm_security_settings_options',
292 [
293 'srfm_v2_checkbox_site_key' => $srfm_v2_checkbox_site_key,
294 'srfm_v2_checkbox_secret_key' => $srfm_v2_checkbox_secret_key,
295 'srfm_v2_invisible_site_key' => $srfm_v2_invisible_site_key,
296 'srfm_v2_invisible_secret_key' => $srfm_v2_invisible_secret_key,
297 'srfm_v3_site_key' => $srfm_v3_site_key,
298 'srfm_v3_secret_key' => $srfm_v3_secret_key,
299 'srfm_cf_appearance_mode' => $srfm_cf_appearance_mode,
300 'srfm_cf_turnstile_site_key' => $srfm_cf_turnstile_site_key,
301 'srfm_cf_turnstile_secret_key' => $srfm_cf_turnstile_secret_key,
302 'srfm_hcaptcha_site_key' => $srfm_hcaptcha_site_key,
303 'srfm_hcaptcha_secret_key' => $srfm_hcaptcha_secret_key,
304 'srfm_honeypot' => $srfm_honeypot,
305 ]
306 );
307 }
308
309 /**
310 * Save Payments Settings
311 *
312 * Handles saving of both global payment settings (currency, payment_mode) and
313 * gateway-specific settings based on the gateway parameter.
314 *
315 * @param array<mixed> $setting_options Setting options.
316 * @return bool
317 * @since 2.0.0
318 */
319 public static function srfm_save_payments_settings( $setting_options ) {
320 $gateway = isset( $setting_options['gateway'] ) && is_string( $setting_options['gateway'] )
321 ? sanitize_text_field( $setting_options['gateway'] )
322 : 'stripe';
323
324 // Handle global settings (currency, payment_mode).
325 if ( isset( $setting_options['currency'] ) && ! empty( $setting_options['currency'] ) && is_string( $setting_options['currency'] ) ) {
326 $currency = sanitize_text_field( $setting_options['currency'] );
327 Payment_Helper::update_global_setting( 'currency', $currency );
328 }
329
330 $payment_mode = null;
331 if ( isset( $setting_options['payment_mode'] ) && ! empty( $setting_options['payment_mode'] ) && is_string( $setting_options['payment_mode'] ) ) {
332 $payment_mode = sanitize_text_field( $setting_options['payment_mode'] );
333 Payment_Helper::update_global_setting( 'payment_mode', $payment_mode );
334 }
335
336 // Save currency sign position.
337 if ( isset( $setting_options['currency_sign_position'] ) && ! empty( $setting_options['currency_sign_position'] ) && is_string( $setting_options['currency_sign_position'] ) ) {
338 $currency_sign_position = sanitize_text_field( $setting_options['currency_sign_position'] );
339 Payment_Helper::update_global_setting( 'currency_sign_position', $currency_sign_position );
340 }
341
342 // Handle gateway-specific settings.
343 if ( 'stripe' === $gateway ) {
344 $current_stripe_settings = Payment_Helper::get_gateway_settings( 'stripe' );
345
346 // Update payment_mode in stripe settings as well (if provided).
347 if ( null !== $payment_mode ) {
348 $current_stripe_settings['payment_mode'] = $payment_mode;
349 }
350
351 // Connection data (keys, account info) is managed separately via OAuth.
352 return Payment_Helper::update_gateway_settings( 'stripe', $current_stripe_settings );
353 }
354
355 return true;
356 }
357
358 /**
359 * Save MCP Settings
360 *
361 * @param array<mixed> $setting_options Setting options.
362 * @return bool
363 * @since 2.6.0
364 */
365 public static function srfm_save_mcp_settings( $setting_options ) {
366 $srfm_abilities_api = ! empty( $setting_options['srfm_abilities_api'] );
367 $srfm_abilities_api_edit = ! empty( $setting_options['srfm_abilities_api_edit'] );
368 $srfm_abilities_api_delete = ! empty( $setting_options['srfm_abilities_api_delete'] );
369 $srfm_mcp_server = ! empty( $setting_options['srfm_mcp_server'] );
370
371 // Save as individual options for the Abilities API permission_callback.
372 update_option( 'srfm_abilities_api', $srfm_abilities_api );
373 update_option( 'srfm_abilities_api_edit', $srfm_abilities_api_edit );
374 update_option( 'srfm_abilities_api_delete', $srfm_abilities_api_delete );
375 update_option( 'srfm_mcp_server', $srfm_mcp_server );
376
377 // Save grouped option for the settings UI fetch.
378 return update_option(
379 'srfm_mcp_settings_options',
380 [
381 'srfm_abilities_api' => $srfm_abilities_api,
382 'srfm_abilities_api_edit' => $srfm_abilities_api_edit,
383 'srfm_abilities_api_delete' => $srfm_abilities_api_delete,
384 'srfm_mcp_server' => $srfm_mcp_server,
385 ]
386 );
387 }
388
389 /**
390 * Get Settings Form Data
391 *
392 * @param \WP_REST_Request $request Request object or array containing form data.
393 * @return void
394 * @since 0.0.1
395 */
396 public static function srfm_get_general_settings( $request ) {
397
398 $nonce = Helper::get_string_value( $request->get_header( 'X-WP-Nonce' ) );
399
400 if ( ! wp_verify_nonce( sanitize_text_field( $nonce ), 'wp_rest' ) ) {
401 wp_send_json_error(
402 [
403 'data' => __( 'Nonce verification failed.', 'sureforms' ),
404 ]
405 );
406 }
407
408 $options_to_get = $request->get_param( 'options_to_fetch' );
409
410 $options_to_get = Helper::get_string_value( $options_to_get );
411
412 $options_to_get = explode( ',', $options_to_get );
413
414 // Restrict to known SureForms options to prevent arbitrary option disclosure.
415 $allowed_options = [
416 'srfm_general_settings_options',
417 'srfm_email_summary_settings_options',
418 'srfm_security_settings_options',
419 'srfm_default_dynamic_block_option',
420 ];
421 $options_to_get = array_values( array_intersect( array_map( 'sanitize_text_field', $options_to_get ), $allowed_options ) );
422
423 $global_setting_options = get_options( $options_to_get );
424
425 if ( empty( $global_setting_options['srfm_general_settings_options'] ) ) {
426 $global_setting_options['srfm_general_settings_options'] = [
427 'srfm_ip_log' => false,
428 'srfm_form_analytics' => false,
429 'srfm_admin_notification' => true,
430 ];
431 }
432
433 if ( ! isset( $global_setting_options['srfm_general_settings_options']['srfm_admin_notification'] ) ) {
434 $global_setting_options['srfm_general_settings_options']['srfm_admin_notification'] = true;
435 }
436
437 /**
438 * We have introduced toggle for analytics optin in the general settings.
439 * Hence retrieving the option sureforms_analytics_optin to get current status.
440 *
441 * @since 1.7.0
442 *
443 * @since 2.5.1 - Renamed sureforms_analytics_optin to sureforms_usage_optin.
444 */
445 $srfm_bsf_analytics = get_option( 'sureforms_usage_optin', false ) === 'yes' ? true : false;
446 $global_setting_options['srfm_general_settings_options']['srfm_bsf_analytics'] = $srfm_bsf_analytics;
447
448 if ( empty( $global_setting_options['srfm_default_dynamic_block_option'] ) ) {
449 $global_setting_options['srfm_default_dynamic_block_option'] = Helper::default_dynamic_block_option();
450 }
451 if ( empty( $global_setting_options['srfm_email_summary_settings_options'] ) ) {
452 $global_setting_options['srfm_email_summary_settings_options'] = [
453 'srfm_email_summary' => false,
454 'srfm_email_sent_to' => get_option( 'admin_email' ),
455 'srfm_schedule_report' => __( 'Monday', 'sureforms' ),
456 ];
457 }
458 if ( empty( $global_setting_options['srfm_security_settings_options'] ) ) {
459 $global_setting_options['srfm_security_settings_options'] = [
460 'srfm_v2_checkbox_site_key' => '',
461 'srfm_v2_checkbox_secret_key' => '',
462 'srfm_v2_invisible_site_key' => '',
463 'srfm_v2_invisible_secret_key' => '',
464 'srfm_v3_site_key' => '',
465 'srfm_v3_secret_key' => '',
466 'srfm_cf_appearance_mode' => 'auto',
467 'srfm_cf_turnstile_site_key' => '',
468 'srfm_cf_turnstile_secret_key' => '',
469 'srfm_hcaptcha_site_key' => '',
470 'srfm_hcaptcha_secret_key' => '',
471 'srfm_honeypot' => false,
472 ];
473 }
474
475 if ( empty( $global_setting_options['srfm_mcp_settings_options'] ) ) {
476 $global_setting_options['srfm_mcp_settings_options'] = [
477 'srfm_abilities_api' => (bool) get_option( 'srfm_abilities_api', false ),
478 'srfm_abilities_api_edit' => (bool) get_option( 'srfm_abilities_api_edit', false ),
479 'srfm_abilities_api_delete' => (bool) get_option( 'srfm_abilities_api_delete', false ),
480 'srfm_mcp_server' => (bool) get_option( 'srfm_mcp_server', false ),
481 ];
482 }
483
484 // Apply filter to allow other modules to add their settings.
485 $global_setting_options = apply_filters( 'srfm_global_settings_data', $global_setting_options );
486
487 wp_send_json( $global_setting_options );
488 }
489
490 }
491