PluginProbe
weForms – Easy Drag & Drop Contact Form Builder For WordPress / 1.3.2
weForms – Easy Drag & Drop Contact Form Builder For WordPress v1.3.2
1.6.7 1.6.8 1.6.9 1.6.12 1.6.13 1.6.14 1.6.15 1.6.16 1.6.17 1.6.18 1.6.19 1.6.2 1.6.20 1.6.21 1.6.22 1.6.23 1.6.24 1.6.25 1.6.26 1.6.27 1.6.28 1.6.3 1.6.4 1.6.5 1.6.6 All 74 releases
← All changes | includes/class-ajax.php +1170 -1257 1.6.281.3.2 View file →
@@ -1,1257 +1,1170 @@
1 -<?php
2 -
3 -/**
4 - * The ajax handler class
5 - */
6 -class WeForms_Ajax {
7 -
8 - public function __construct() {
9 -
10 - // backend requests
11 - add_action( 'wp_ajax_weforms_form_list', [ $this, 'get_contact_forms' ] );
12 - add_action( 'wp_ajax_weforms_get_users', [ $this, 'get_all_users' ] );
13 - add_action( 'wp_ajax_weforms_form_names', [ $this, 'get_contact_form_names' ] );
14 - add_action( 'wp_ajax_weforms_form_create', [ $this, 'create_form' ] );
15 - add_action( 'wp_ajax_weforms_form_delete', [ $this, 'delete_form' ] );
16 - add_action( 'wp_ajax_weforms_form_delete_bulk', [ $this, 'delete_form_bulk' ] );
17 - add_action( 'wp_ajax_weforms_form_duplicate', [ $this, 'duplicate_form' ] );
18 -
19 - // read logs
20 - add_action( 'wp_ajax_weforms_read_logs', [ $this, 'get_logs' ] );
21 - add_action( 'wp_ajax_weforms_delete_logs', [ $this, 'delete_logs' ] );
22 -
23 - // create from a template
24 - add_filter( 'wp_ajax_weforms_contact_form_template', [ $this, 'create_form_from_template' ] );
25 -
26 - // form settings
27 - add_action( 'wp_ajax_weforms_save_settings', [ $this, 'save_settings' ] );
28 - add_action( 'wp_ajax_weforms_get_settings', [ $this, 'get_settings' ] );
29 -
30 - // import
31 - add_action( 'wp_ajax_weforms_import_form', [ $this, 'import_form' ] );
32 -
33 - // form editing
34 - add_action( 'wp_ajax_weforms_get_form', [ $this, 'get_form' ] );
35 - add_action( 'wp_ajax_wpuf_form_builder_save_form', [ $this, 'save_form' ] );
36 -
37 - // entries
38 - add_action( 'wp_ajax_weforms_form_entries', [ $this, 'get_entries' ] );
39 -
40 - add_action( 'wp_ajax_weforms_form_entry_details', [ $this, 'get_entry_detail' ] );
41 - add_action( 'wp_ajax_weforms_form_entry_trash', [ $this, 'trash_entry' ] );
42 - add_action( 'wp_ajax_weforms_form_entry_delete', [ $this, 'delete_entry' ] );
43 - add_action( 'wp_ajax_weforms_form_entry_restore', [ $this, 'restore_entry' ] );
44 -
45 - add_action( 'wp_ajax_weforms_form_entry_trash_bulk', [ $this, 'bulk_delete_entry' ] );
46 - add_action( 'wp_ajax_weforms_form_entry_restore_bulk', [ $this, 'bulk_restore_entry' ] );
47 -
48 - // frontend requests
49 - add_action( 'wp_ajax_weforms_frontend_submit', [ $this, 'handle_frontend_submission' ] );
50 - add_action( 'wp_ajax_nopriv_weforms_frontend_submit', [ $this, 'handle_frontend_submission' ] );
51 - }
52 -
53 - /**
54 - * Administrator validation
55 - *
56 - * @return void
57 - */
58 - public function check_admin() {
59 - if ( !current_user_can( weforms_form_access_capability() ) ) {
60 - wp_send_json_error( __( 'You do not have sufficient permission.', 'weforms' ) );
61 - }
62 - }
63 -
64 - /**
65 - * Get a form to edit
66 - *
67 - * @return void
68 - */
69 - public function get_form() {
70 - $this->check_admin();
71 -
72 - $form_id = isset( $_REQUEST['form_id'] ) ? absint( $_REQUEST['form_id'] ) : 0;
73 -
74 - $form = weforms()->form->get( $form_id );
75 -
76 - $data = [
77 - 'post' => $form->data,
78 - 'form_fields' => $form->get_fields(),
79 - 'settings' => $form->get_settings(),
80 - 'notifications' => $form->get_notifications(),
81 - 'integrations' => $form->get_integrations(),
82 - ];
83 -
84 - wp_send_json_success( $data );
85 - }
86 -
87 - /**
88 - * Save the form
89 - *
90 - * @return void
91 - */
92 - public function save_form() {
93 - $post_data = wp_unslash( $_POST );
94 - if ( isset( $post_data['form_data'] ) ) {
95 - parse_str( sanitize_text_field( wp_unslash( $post_data['form_data'] ) ), $form_data );
96 - }
97 -
98 - if ( !wp_verify_nonce( $form_data['wpuf_form_builder_nonce'], 'wpuf_form_builder_save_form' ) ) {
99 - wp_send_json_error( __( 'Unauthorized operation', 'weforms' ) );
100 - }
101 -
102 - if ( empty( $form_data['wpuf_form_id'] ) ) {
103 - wp_send_json_error( __( 'Invalid form id', 'weforms' ) );
104 - }
105 -
106 - $form_fields = isset( $post_data['form_fields'] ) ? $post_data['form_fields'] : '';
107 - $notifications = isset( $post_data['notifications'] ) ? $post_data['notifications']: '';
108 - $settings = array();
109 - $integrations = array();
110 -
111 - if ( isset( $post_data['settings'] ) ) {
112 - $settings = json_decode( $post_data['settings'], true );
113 - $settings['message'] = sanitize_text_field( $settings['message'] );
114 - $settings['url'] = sanitize_url( $settings['url'] );
115 - $settings['limit_message'] = sanitize_text_field( $settings['limit_message'] );
116 - } else {
117 - $settings = isset( $form_data['wpuf_settings'] ) ? $form_data['wpuf_settings'] : [];
118 - }
119 -
120 - if ( isset( $post_data['integrations'] ) ) {
121 - $integrations = (array) json_decode( $post_data['integrations'] );
122 - }
123 -
124 - $form_fields = json_decode( $form_fields, true );
125 - $notifications = json_decode( $notifications, true );
126 - $data = [
127 - 'form_id' => absint( $form_data['wpuf_form_id'] ),
128 - 'post_title' => $form_data['post_title'],
129 - 'form_fields' => $form_fields,
130 - 'form_settings' => $settings,
131 - 'form_settings_key' => isset( $form_data['form_settings_key'] ) ? $form_data['form_settings_key'] : '',
132 - 'notifications' => $notifications,
133 - 'integrations' => $integrations,
134 - ];
135 -
136 - $form_fields = weforms()->form->save( $data );
137 -
138 - // Update Old Entry meta_key if changed
139 - $form_id = $form_data['wpuf_form_id'];
140 - $form = weforms()->form->get( $form_id );
141 -
142 - $form->maybe_update_entries( $form_fields );
143 -
144 - do_action( 'weforms_update_form', $form_data['wpuf_form_id'], $form_fields, $settings );
145 -
146 - wp_send_json_success(
147 - array(
148 - 'form_fields' => $form_fields,
149 - 'settings' => $settings,
150 - )
151 - );
152 - }
153 -
154 - /**
155 - * Get all contact forms
156 - *
157 - * @return void
158 - */
159 - public function get_contact_forms() {
160 - check_ajax_referer( 'weforms' );
161 -
162 - $this->check_admin();
163 -
164 - $args = [
165 - 'posts_per_page' => isset( $_POST['posts_per_page'] ) ? intval( $_POST['posts_per_page'] ) : 10,
166 - 'paged' => isset( $_POST['page'] ) ? absint( $_POST['page'] ) : 1,
167 - 'order' => 'DESC',
168 - 'orderby' => 'post_date',
169 - ];
170 -
171 - $args = apply_filters( 'weforms_ajax_get_contact_forms_args', $args );
172 -
173 - $contact_forms = weforms()->form->get_forms( $args );
174 -
175 - array_map(
176 - function ( $form ) {
177 - $form->entries = $form->num_form_entries();
178 - $form->settings = $form->get_settings();
179 - $form->views = $form->num_form_views();
180 - $form->payments = $form->num_form_payments();
181 - $form->author = $form->get_form_author_details();
182 - }, $contact_forms['forms']
183 - );
184 -
185 - $contact_forms = $this->filter_contact_forms( $contact_forms );
186 - $contact_forms = apply_filters( 'weforms_ajax_get_contact_forms', $contact_forms );
187 -
188 - wp_send_json_success( $contact_forms );
189 - }
190 -
191 - /**
192 - * Get all users
193 - *
194 - * @return array
195 - */
196 - public function get_all_users() {
197 - check_ajax_referer( 'weforms' );
198 -
199 - $this->check_admin();
200 -
201 - $users_meta = [];
202 - $users = get_users( [ 'fields' => [ 'ID' ] ] );
203 -
204 - foreach ( $users as $user ) {
205 - $users_meta[] = [
206 - 'id' => $user->ID,
207 - 'data' => get_user_meta( $user->ID ),
208 - ];
209 - }
210 -
211 - wp_send_json_success( $users_meta );
212 - }
213 -
214 - /**
215 - * Filter
216 - *
217 - * @return void
218 - */
219 - public function filter_contact_forms( &$contact_forms ) {
220 - if ( isset( $_REQUEST['filter'] ) && $_REQUEST['filter'] == 'entries' ) {
221 - foreach ( $contact_forms['forms'] as $key => &$form ) {
222 - if ( isset( $form->entries ) && !$form->entries ) {
223 - unset( $contact_forms['forms'][ $key ] );
224 - }
225 - }
226 -
227 - $contact_forms['meta']['total'] = count( $contact_forms['forms'] );
228 - }
229 -
230 - return $contact_forms;
231 - }
232 -
233 - /**
234 - * Get the names of contact forms for generating dropdown
235 - *
236 - * @return void
237 - */
238 - public function get_contact_form_names() {
239 - check_ajax_referer( 'weforms' );
240 -
241 - $this->check_admin();
242 -
243 - $contact_forms = weforms()->form->all();
244 - $response = [];
245 -
246 - foreach ( $contact_forms['forms'] as $form ) {
247 - $response[] = [
248 - 'id' => $form->get_id(),
249 - 'title' => $form->get_name() . ' (#' . $form->get_id() . ')',
250 - ];
251 - }
252 -
253 - wp_send_json_success( $response );
254 - }
255 -
256 - /**
257 - * Create a form
258 - *
259 - * @return void
260 - */
261 - public function create_form() {
262 - check_ajax_referer( 'weforms' );
263 -
264 - $this->check_admin();
265 -
266 - $form_name = isset( $_POST['form_name'] ) ? sanitize_text_field( wp_unslash( $_POST['form_name'] ) ) : '';
267 -
268 - if ( empty( $form_name ) ) {
269 - wp_send_json_error( __( 'Please provide a form name', 'weforms' ) );
270 - }
271 -
272 - $form_id = weforms()->form->create( $form_name );
273 -
274 - if ( is_wp_error( $form_id ) ) {
275 - wp_send_json_error( $form_id->get_error_message() );
276 - }
277 -
278 - wp_send_json_success( [
279 - 'form_id' => $form_id,
280 - 'form_name' => $form_name,
281 - ] );
282 - }
283 -
284 - /**
285 - * Delete a form
286 - *
287 - * @return void
288 - */
289 - public function delete_form() {
290 - check_ajax_referer( 'weforms' );
291 -
292 - $this->check_admin();
293 -
294 - $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
295 -
296 - if ( !$form_id ) {
297 - wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
298 - }
299 -
300 - weforms()->form->delete( $form_id );
301 -
302 - wp_send_json_success();
303 - }
304 -
305 - public function delete_form_bulk() {
306 - check_ajax_referer( 'weforms' );
307 -
308 - $this->check_admin();
309 -
310 - $form_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : [];
311 -
312 - if ( !$form_ids ) {
313 - wp_send_json_error( __( 'No form ids provided!', 'weforms' ) );
314 - }
315 -
316 - foreach ( $form_ids as $form_id ) {
317 - weforms()->form->delete( $form_id );
318 - }
319 -
320 - wp_send_json_success();
321 - }
322 -
323 - /**
324 - * Duplicate a form
325 - *
326 - * @return voiud
327 - */
328 - public function duplicate_form() {
329 - check_ajax_referer( 'weforms' );
330 -
331 - $this->check_admin();
332 -
333 - $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
334 -
335 - $form = weforms()->form->duplicate( $form_id );
336 - $form->settings = $form->get_settings();
337 -
338 - wp_send_json_success( $form );
339 - }
340 -
341 - /**
342 - * Create form from a template
343 - *
344 - * @return void
345 - */
346 - public function create_form_from_template() {
347 - check_ajax_referer( 'weforms' );
348 -
349 - $template = isset( $_REQUEST['template'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['template'] ) ) : '';
350 -
351 - $form_id = weforms()->templates->create( $template );
352 -
353 - if ( is_wp_error( $form_id ) ) {
354 - wp_send_json_error( __( 'Could not create the form', 'weforms' ) );
355 - }
356 -
357 - wp_send_json_success( [
358 - 'id' => $form_id,
359 - ] );
360 - }
361 -
362 - /**
363 - * Save the weForms settings
364 - *
365 - * @return void
366 - */
367 - public function save_settings() {
368 - check_ajax_referer( 'weforms' );
369 - $this->check_admin();
370 -
371 - $requires_wpuf_update = false;
372 - $wpuf_update_array = array();
373 - $settings = isset( $_POST['settings'] ) ? (array) json_decode( wp_unslash( $_POST['settings'] ) ) : [];
374 - update_option( 'weforms_settings', $settings );
375 -
376 - // wpuf settings sync
377 - if ( isset( $settings['gmap_api'] ) ) {
378 - $requires_wpuf_update = true;
379 - $wpuf_update_array['gmap_api_key'] = $settings['gmap_api'];
380 - }
381 -
382 - if ( isset( $settings['recaptcha'] ) ) {
383 - $requires_wpuf_update = true;
384 - $wpuf_update_array['recaptcha_public'] = $settings['recaptcha']->key;
385 - $wpuf_update_array['recaptcha_private'] = $settings['recaptcha']->secret;
386 - $wpuf_update_array['recaptcha_type'] = $settings['recaptcha']->type;
387 - }
388 -
389 - if ( isset( $settings['no_conflict'] ) ) {
390 - $requires_wpuf_update = true;
391 - $wpuf_update_array['no_conflict'] = $settings['no_conflict'];
392 - }
393 -
394 - if ( isset( $settings['email_footer'] ) ) {
395 - $requires_wpuf_update = true;
396 - $wpuf_update_array['email_footer'] = $settings['email_footer'];
397 - }
398 -
399 - if ( $requires_wpuf_update ) {
400 - $wpuf_settings = get_option( 'wpuf_general', [] );
401 -
402 - $wpuf_settings = array_merge( $wpuf_settings, $wpuf_update_array );
403 - update_option( 'wpuf_general', $wpuf_settings );
404 - }
405 -
406 - do_action( 'weforms_save_settings', $settings );
407 -
408 - $settings = apply_filters( 'weforms_after_save_settings', $settings );
409 - wp_send_json_success( $settings );
410 - }
411 -
412 - /**
413 - * Get the weForms Settings
414 - *
415 - * @return void
416 - */
417 - public function get_settings() {
418 - check_ajax_referer( 'weforms' );
419 -
420 - $this->check_admin();
421 -
422 - $settings = weforms_get_settings();
423 - // checking to prevent js error, will be removed in future
424 - if ( !isset( $settings['credit'] ) ) {
425 - $settings['credit'] = false;
426 - }
427 -
428 - if ( !isset( $settings['permission'] ) ) {
429 - $settings['permission'] = 'manage_options';
430 - }
431 -
432 - wp_send_json_success( $settings );
433 - }
434 -
435 - /**
436 - * Get all entries
437 - *
438 - * @return void
439 - */
440 - public function get_entries() {
441 - check_ajax_referer( 'weforms' );
442 -
443 - $this->check_admin();
444 -
445 - $form_id = isset( $_REQUEST['id'] ) ? intval( $_REQUEST['id'] ) : 0;
446 - $current_page = isset( $_REQUEST['page'] ) ? intval( $_REQUEST['page'] ) : 1;
447 - $status = isset( $_REQUEST['status'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['status'] ) ) : 'publish';
448 - $per_page = 20;
449 - $offset = ( $current_page - 1 ) * $per_page;
450 -
451 - if ( !$form_id ) {
452 - wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
453 - }
454 -
455 - $entries = weforms_get_form_entries(
456 - $form_id, [
457 - 'number' => $per_page,
458 - 'offset' => $offset,
459 - 'status' => $status,
460 - ]
461 - );
462 -
463 - $columns = weforms_get_entry_columns( $form_id );
464 - $total_entries = weforms_count_form_entries( $form_id, $status );
465 -
466 - array_map(
467 - function ( $entry ) use ( $columns ) {
468 - $entry_id = $entry->id;
469 - $entry->fields = [];
470 -
471 - foreach ( $columns as $meta_key => $label ) {
472 - if ( empty( $meta_key ) ) {
473 - continue;
474 - }
475 - $value = weforms_get_entry_meta( $entry_id, $meta_key, true );
476 - $entry->fields[ $meta_key ] = str_replace( WeForms::$field_separator, ' ', $value );
477 - }
478 - }, $entries
479 - );
480 -
481 - $entries = apply_filters( 'weforms_get_entries', $entries, $form_id );
482 -
483 - $response = [
484 - 'columns' => $columns,
485 - 'entries' => $entries,
486 - 'form_title' => get_post_field( 'post_title', $form_id ),
487 - 'pagination' => [
488 - 'total' => $total_entries,
489 - 'per_page' => $per_page,
490 - 'pages' => ceil( $total_entries / $per_page ),
491 - 'current' => $current_page,
492 - ],
493 - 'meta' => [
494 - 'total' => weforms_count_form_entries( $form_id ),
495 - 'totalTrash' => weforms_count_form_entries( $form_id, 'trash' ),
496 - ],
497 - ];
498 -
499 - wp_send_json_success( $response );
500 - }
501 -
502 - /**
503 - * Get an entry details
504 - *
505 - * @return void
506 - */
507 - public function get_entry_detail() {
508 - check_ajax_referer( 'weforms' );
509 -
510 - $this->check_admin();
511 -
512 - $form_id = isset( $_REQUEST['form_id'] ) ? intval( $_REQUEST['form_id'] ) : 0;
513 - $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
514 -
515 - $form = weforms()->form->get( $form_id );
516 - $form_settings = $form->get_settings();
517 - $entry = $form->entries()->get( $entry_id );
518 - $fields = $entry->get_fields();
519 - $metadata = $entry->get_metadata();
520 - $payment = $entry->get_payment_data();
521 -
522 - if ( isset( $payment->payment_data ) && is_serialized( $payment->payment_data ) ) {
523 - // Security fix: Prevent PHP Object Injection by restricting allowed classes
524 - $payment->payment_data = @unserialize( $payment->payment_data, [ 'allowed_classes' => false ] );
525 - }
526 -
527 - if ( false === $fields ) {
528 - wp_send_json_error( __( 'No form fields found!', 'weforms' ) );
529 - }
530 -
531 - if ( sizeof( $fields ) < 1 ) {
532 - $fields[] = [
533 - 'label' => __( 'No form fields found!', 'weforms' ),
534 - ];
535 - }
536 -
537 - $has_empty = false;
538 - $answers = [];
539 - $respondentPoints = isset( $form_settings['total_points'] ) ? floatval( $form_settings['total_points'] ) : 0;
540 - $fields_formatted = array();
541 - foreach ( $fields as $key => $field ) {
542 - if ( $form_settings['quiz_form'] == 'yes' ) {
543 - $selectedAnswers = isset( $field['selected_answers'] ) ? $field['selected_answers'] : '';
544 - $givenAnswer = isset( $field['value'] ) ? $field['value'] : '';
545 - $options = isset( $field['options'] ) ? $field['options'] : '';
546 - $template = $field['template'];
547 - $fieldPoints = isset( $field['points'] ) ? floatval( $field['points'] ) : 0;
548 -
549 - if ( $template == 'radio_field' || $template == 'dropdown_field' ) {
550 - $answers[$field['name']] = true;
551 - if ( empty( $givenAnswer ) ) {
552 - $answers[$field['name']] = false;
553 - $respondentPoints -= $fieldPoints;
554 - } else {
555 - foreach ( $options as $key => $value ) {
556 - if ( $givenAnswer == $value ) {
557 - if ( $key != $selectedAnswers ) {
558 - $answers[$field['name']] = false;
559 - $respondentPoints -= $fieldPoints;
560 - }
561 - }
562 - }
563 - }
564 - } elseif ( $template == 'checkbox_field' || $template == 'multiple_select' ) {
565 - $answers[$field['name']] = true;
566 - $userAnswer = [];
567 -
568 - foreach ( $options as $key => $value ) {
569 - foreach ( $givenAnswer as $answer ) {
570 - if ( $value == $answer ) {
571 - $userAnswer[] = $key;
572 - }
573 - }
574 - }
575 -
576 - $userAnswer = implode( '|', $userAnswer );
577 - $rightAnswers = implode( '|', $selectedAnswers );
578 -
579 - if ( $userAnswer != $rightAnswers || empty( $userAnswer ) ) {
580 - $answers[$field['name']] = false;
581 - $respondentPoints -= $fieldPoints;
582 - }
583 - }
584 - } elseif ( empty( $field['value'] ) ) {
585 - $has_empty = true;
586 - continue;
587 - } else {
588 - $field = WeForms_Form_Entry_Manager::format_entry_value( $field );
589 - array_push( $fields_formatted, $field );
590 - }
591 - }
592 - $response = [
593 - 'form_fields' => $fields_formatted,
594 - 'form_settings' => $form_settings,
595 - 'meta_data' => $metadata,
596 - 'payment_data' => $payment,
597 - 'has_empty' => $has_empty,
598 - 'respondent_points' => $respondentPoints,
599 - 'answers' => $answers,
600 - ];
601 -
602 -
603 - wp_send_json_success( $response );
604 - }
605 -
606 - /**
607 - * Trash an entry
608 - *
609 - * @return void
610 - */
611 - public function trash_entry() {
612 - check_ajax_referer( 'weforms' );
613 -
614 - $this->check_admin();
615 -
616 - $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
617 -
618 - weforms_change_entry_status( $entry_id, 'trash' );
619 - wp_send_json_success();
620 - }
621 -
622 - /**
623 - * Trash an entry
624 - *
625 - * @return void
626 - */
627 - public function delete_entry() {
628 - check_ajax_referer( 'weforms' );
629 -
630 - $this->check_admin();
631 -
632 - $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
633 -
634 - weforms_delete_entry( $entry_id );
635 -
636 - wp_send_json_success();
637 - }
638 -
639 - /**
640 - * Restore Entry
641 - *
642 - * @return void
643 - */
644 - public function restore_entry() {
645 - check_ajax_referer( 'weforms' );
646 -
647 - $this->check_admin();
648 -
649 - $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
650 -
651 - weforms_change_entry_status( $entry_id, 'publish' );
652 - wp_send_json_success();
653 - }
654 -
655 - /**
656 - * Bulk trash entries
657 - *
658 - * @return void
659 - */
660 - public function bulk_delete_entry() {
661 - check_ajax_referer( 'weforms' );
662 -
663 - $this->check_admin();
664 -
665 - $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : array();
666 - $permanent = isset( $_POST['permanent'] ) && ( sanitize_text_field( wp_unslash ( $_POST['permanent'] ) ) ) ? true : false;
667 -
668 - if ( !$entry_ids ) {
669 - wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
670 - }
671 -
672 - foreach ( $entry_ids as $entry_id ) {
673 - if ( $permanent ) {
674 - weforms_delete_entry( $entry_id );
675 - } else {
676 - weforms_change_entry_status( $entry_id, 'trash' );
677 - }
678 - }
679 -
680 - wp_send_json_success();
681 - }
682 -
683 - /**
684 - * Bulk trash entries
685 - *
686 - * @return void
687 - */
688 - public function bulk_restore_entry() {
689 - check_ajax_referer( 'weforms' );
690 -
691 - $this->check_admin();
692 -
693 - $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : [];
694 -
695 - if ( !$entry_ids ) {
696 - wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
697 - }
698 -
699 - foreach ( $entry_ids as $entry_id ) {
700 - weforms_change_entry_status( $entry_id, 'publish' );
701 - }
702 -
703 - wp_send_json_success();
704 - }
705 -
706 - /**
707 - * Handle the frontend submission
708 - *
709 - * @return void
710 - */
711 - public function handle_frontend_submission() {
712 - check_ajax_referer( 'wpuf_form_add' );
713 - $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
714 - $page_id = isset( $_POST['page_id'] ) ? intval( $_POST['page_id'] ) : 0;
715 - $form = weforms()->form->get( $form_id );
716 -
717 - /**
718 - * Check if form submission is open. This resolves broken access control with unauthenticated users.
719 - * Access is now checked on frontend form rendering and submission.
720 - */
721 - $form_submission_status = $form->is_submission_open();
722 - if ( is_wp_error( $form_submission_status ) ) {
723 - wp_send_json( [
724 - 'success' => false,
725 - 'error' => __( 'Login Required for submission.', 'weforms' ),
726 - ] );
727 - }
728 -
729 - $form_settings = $form->get_settings();
730 - $form_fields = $form->get_fields();
731 - $entry_fields = $form->prepare_entries();
732 - $form_entries = weforms_get_form_entries( $form_id, [ 'number' => '', 'offset' => '' ] );
733 -
734 - if ( $form_fields && count( $form_entries ) && count( $entry_fields ) ) {
735 - foreach ( $entry_fields as $field_key => $field_value ) {
736 - $duplicate_check = false;
737 - $field_label = 'This';
738 -
739 - foreach ( $form_fields as $form_field ) {
740 - if ( in_array( $form_field['template'], [ 'text_field', 'website_url', 'numeric_text_field', 'email_address' ] ) && $form_field['name'] == $field_key && isset( $form_field['duplicate'] ) && 'no' == $form_field['duplicate'] ) {
741 - $duplicate_check = true;
742 - $field_label = $form_field['label'];
743 - }
744 - }
745 -
746 - if ( $duplicate_check ) {
747 - foreach ( $form_entries as $entry ) {
748 - $existing = weforms_get_entry_meta( $entry->id, $field_key, true );
749 -
750 - if ( $existing && $field_value == $existing ) {
751 - wp_send_json( [
752 - 'success' => false,
753 - 'error' => sprintf( __( '"%s" field requires a unique entry and "%s" has already been used.', 'weforms' ), $field_label, $field_value ),
754 - ] );
755 - }
756 - }
757 - }
758 - }
759 - }
760 -
761 - if ( !$form_fields ) {
762 - wp_send_json( [
763 - 'success' => false,
764 - 'error' => __( 'No form field was found.', 'weforms' ),
765 - ] );
766 - }
767 -
768 - if ( $form->has_field( 'recaptcha' ) ) {
769 - $settings = weforms_get_settings( 'recaptcha' );
770 - $type = isset( $settings->type ) ? $settings->type : '';
771 - $secret = isset( $settings->secret ) ? $settings->secret : '';
772 - if( $type == 'v3' ) {
773 - $this->validate_reCaptchav3( $secret );
774 - } else {
775 - $this->validate_reCaptcha();
776 - }
777 - }
778 -
779 - // vaidate submission
780 - $this->validate_submission( $entry_fields, $form, $form_settings, $form_fields );
781 -
782 - $entry_fields = apply_filters( 'weforms_before_entry_submission', $entry_fields, $form, $form_settings, $form_fields );
783 -
784 - //check for entry_fields for a return error
785 - if ( is_wp_error( $entry_fields ) ) {
786 - wp_send_json( [
787 - 'success' => false,
788 - 'error' => $entry_fields->get_error_message(),
789 - ] );
790 - } else {
791 - $entry_id = 1;
792 - $global_settings = weforms_get_settings();
793 - if ( empty( $form_settings['after_submission'] ) ) {
794 - $entry_id = weforms_insert_entry( [
795 - 'form_id' => $form_id,
796 - ], $entry_fields );
797 - if ( is_wp_error( $entry_id ) ) {
798 - wp_send_json( [
799 - 'success' => false,
800 - 'error' => $entry_id->get_error_message(),
801 - ] );
802 - }
803 - // Fire a hook for integration
804 - do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
805 - $notification = new WeForms_Notification( [
806 - 'form_id' => $form_id,
807 - 'page_id' => $page_id,
808 - 'entry_id' => $entry_id,
809 - ] );
810 - $notification->send_notifications();
811 - }
812 - }
813 - // redirect URL
814 - $show_message = false;
815 - $redirect_to = false;
816 - if ( $form_settings['redirect_to'] == 'page' ) {
817 - $redirect_to = get_permalink( $form_settings['page_id'] );
818 - } elseif ( $form_settings['redirect_to'] == 'url' ) {
819 - $redirect_to = $form_settings['url'];
820 - } elseif ( $form_settings['redirect_to'] == 'same' ) {
821 - $show_message = true;
822 - } else {
823 - $show_message = true;
824 - }
825 - $field_search = $field_replace = [];
826 - foreach ( $form_fields as $r_field ) {
827 - $field_search[] = '{' . $r_field['name'] . '}';
828 - if ( $r_field['template'] == 'name_field' ) {
829 - $field_replace[] = implode( ' ', explode( '|', $entry_fields[ $r_field['name'] ] ) );
830 - } else if ( $r_field['template'] == 'address_field' ) {
831 - $field_replace[] = implode( ', ', $entry_fields[ $r_field['name'] ] );
832 - } else {
833 - $field_replace[] = isset( $entry_fields[ $r_field['name'] ] ) ? $entry_fields[ $r_field['name'] ] : '';
834 - }
835 - }
836 - $message = str_replace( $field_search, $field_replace, $form_settings['message'] );
837 - // send the response
838 - $response = apply_filters( 'weforms_entry_submission_response', [
839 - 'success' => true,
840 - 'redirect_to' => $redirect_to,
841 - 'show_message' => $show_message,
842 - 'message' => $message,
843 - 'data' => $_POST,
844 - 'form_id' => $form_id,
845 - 'entry_id' => $entry_id,
846 - 'entry_fields' =>$entry_fields,
847 - ] );
848 -
849 - weforms_clear_buffer();
850 - wp_send_json( $response );
851 - }
852 -
853 - function validate_reCaptchav3( $secret ) {
854 - check_ajax_referer( 'wpuf_form_add' );
855 -
856 - $post_data = wp_unslash($_POST);
857 - $token = $post_data['g-recaptcha-response'];
858 - $action = $post_data['g-action'];
859 - $google_captcha_url = esc_url( 'https://www.google.com/recaptcha/api/siteverify' );
860 -
861 - $response = wp_remote_post( $google_captcha_url,
862 - array(
863 - 'method' => 'POST',
864 - 'body' => array(
865 - 'secret' => $secret,
866 - 'response' => $token
867 - )
868 - )
869 - );
870 -
871 -
872 - if ( is_wp_error( $response ) ) {
873 - wp_send_json( [
874 - 'success' => false,
875 - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
876 - ] );
877 - } else {
878 - $api_response = json_decode( wp_remote_retrieve_body( $response ), true );
879 - if( $api_response["success"] == '1' && $api_response["action"] == $action ) {
880 - return true;
881 - } else {
882 - wp_send_json( [
883 - 'success' => false,
884 - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
885 - ] );
886 - }
887 - }
888 - }
889 - /**
890 - * reCaptcha Validation
891 - *
892 - * @return void
893 - */
894 - function validate_reCaptcha() {
895 - check_ajax_referer( 'wpuf_form_add' );
896 - if ( class_exists( 'WPUF_ReCaptcha' ) ) {
897 - $recaptcha_class = 'WPUF_ReCaptcha';
898 - } else {
899 - if ( !function_exists( 'recaptcha_get_html' ) ) {
900 - require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib.php';
901 - }
902 -
903 - require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib_noCaptcha.php';
904 - $recaptcha_class = 'Weforms_ReCaptcha';
905 - }
906 -
907 - $invisible = isset( $_POST['g-recaptcha-response'] ) ? false : true;
908 -
909 - $recaptcha_settings = weforms_get_settings( 'recaptcha' );
910 - $secret = isset( $recaptcha_settings->secret ) ? $recaptcha_settings->secret : '';
911 -
912 - if ( ! $invisible ) {
913 - $response = null;
914 - $reCaptcha = new $recaptcha_class( $secret );
915 - $remote_ADDR = isset( $_SERVER['REMOTE_ADDR'] ) ? sanitize_text_field( wp_unslash( $_SERVER['REMOTE_ADDR'] ) ) : '';
916 - $recaptcha_response = isset( $_POST['g-recaptcha-response'] ) ? sanitize_text_field( wp_unslash( $_POST['g-recaptcha-response'] ) ) : '';
917 - $resp = $reCaptcha->verifyResponse(
918 - $remote_ADDR,
919 - $recaptcha_response
920 - );
921 -
922 - if ( !$resp->success ) {
923 - wp_send_json( [
924 - 'success' => false,
925 - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
926 - ] );
927 - }
928 -
929 - } else {
930 -
931 - $recap_challenge = isset( $_POST['recaptcha_challenge_field'] ) ? sanitize_text_field( wp_unslash( $_POST['recaptcha_challenge_field'] ) ) : '';
932 - $recap_response = isset( $_POST['recaptcha_response_field'] ) ? sanitize_text_field( wp_unslash( $_POST['recaptcha_response_field'] ) ) : '';
933 - $resp = recaptcha_check_answer( $secret, $remote_ADDR, $recap_challenge, $recap_response );
934 -
935 - if ( !$resp->is_valid ) {
936 - ob_clean();
937 -
938 - wp_send_json( [
939 - 'success' => false,
940 - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
941 - ] );
942 - }
943 - }
944 - }
945 -
946 - /**
947 - * Validate submission
948 - *
949 - * @param array $entry_fields
950 - * @param object $form
951 - * @param array $form_settings
952 - * @param array $form_fields
953 - *
954 - * @return bool|json
955 - */
956 - public function validate_submission( $entry_fields, $form, $form_settings, $form_fields ) {
957 - foreach ( $form_fields as $key => $field ) {
958 -
959 - //skip custom html field as it is not saved
960 - if ( 'custom_html' == $field['name'] ) {
961 - continue;
962 - }
963 -
964 - //skip recaptcha field as it is not saved
965 - if ( 'recaptcha' == $field['name'] ) {
966 - continue;
967 - }
968 -
969 - $value = $entry_fields[ $field['name'] ];
970 -
971 - if ( 'single_product' === $field['template'] ) {
972 - if ( !$value ) {
973 - $value = [];
974 - }
975 -
976 - $value['price'] = isset( $value['price'] ) ? floatval( $value['price'] ) : 0;
977 - $value['quantity'] = isset( $value['quantity'] ) ? floatval( $value['quantity'] ) : 0;
978 - $quantity = isset( $field['quantity'] ) ? $field['quantity'] : [];
979 - $price = isset( $field['price'] ) ? $field['price'] : [];
980 -
981 - if ( isset( $price['is_flexible'] ) && $price['is_flexible'] ) {
982 - $min = isset( $price['min'] ) ? floatval( $price['min'] ) : 0;
983 - $max = isset( $price['max'] ) ? floatval( $price['max'] ) : 0;
984 -
985 - if ( $value['price'] < $min ) {
986 - wp_send_json( [
987 - 'success' => false,
988 - 'error' => __( sprintf(
989 - '%s price must be equal or greater than %s',
990 - $field['weforms'],
991 - $min ),
992 - 'weforms' ),
993 - ] );
994 - }
995 -
996 - if ( $max && $value['price'] > $max ) {
997 - wp_send_json( [
998 - 'success' => false,
999 - 'error' => __( sprintf(
1000 - '%s price must be equal or less than %s',
1001 - $field['weforms'],
1002 - $max ),
1003 - 'weforms' ),
1004 - ] );
1005 - }
1006 - }
1007 -
1008 - if ( isset( $quantity['status'] ) && $quantity['status'] ) {
1009 - $min = isset( $quantity['min'] ) ? floatval( $quantity['min'] ) : 0;
1010 - $max = isset( $quantity['max'] ) ? floatval( $quantity['max'] ) : 0;
1011 -
1012 - if ( $value['quantity'] < $min ) {
1013 - wp_send_json( [
1014 - 'success' => false,
1015 - 'error' => __( sprintf(
1016 - '%s quantity must be equal or greater than %s',
1017 - $field['weforms'],
1018 - $min ),
1019 - 'weforms' ),
1020 - ] );
1021 - }
1022 -
1023 - if ( $max && $value['quantity'] > $max ) {
1024 - wp_send_json( [
1025 - 'success' => false,
1026 - 'error' => __( sprintf(
1027 - '%s quantity must be equal or less than %s',
1028 - $field['weforms'],
1029 - $max ),
1030 - 'weforms' ),
1031 - ] );
1032 - }
1033 - }
1034 - }
1035 - }
1036 - }
1037 -
1038 - public static function prepare_meta_fields( $meta_vars ) {
1039 - check_ajax_referer( 'wpuf_form_add' );
1040 - // loop through custom fields
1041 - // skip files, put in a key => value paired array for later executation
1042 - // process repeatable fields separately
1043 - // if the input is array type, implode with separator in a field
1044 - $files = [];
1045 - $meta_key_value = [];
1046 - $multi_repeated = []; // multi repeated fields will in sotre duplicated meta key
1047 -
1048 - foreach ( $meta_vars as $key => $value ) {
1049 - switch ( $value['template'] ) {
1050 -
1051 - // put files in a separate array, we'll process it later
1052 - case 'file_upload':
1053 - case 'image_upload':
1054 - $files[] = [
1055 - 'name' => $value['name'],
1056 - 'value' => isset( $_POST['wpuf_files'][ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST['wpuf_files'][ $value['name'] ] ) ) : array(),
1057 - 'count' => $value['count']
1058 - ];
1059 - break;
1060 -
1061 - case 'repeat_field':
1062 - // if it is a multi column repeat field
1063 - if ( isset( $value['multiple'] ) && $value['multiple'] == 'true' ) {
1064 -
1065 - // if there's any items in the array, process it
1066 - if ( isset( $_POST[ $value['name'] ] ) ) {
1067 - $ref_arr = [];
1068 - $cols = count( $value['columns'] );
1069 - $first = array_shift( array_values( sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) ) ); // first element
1070 - $rows = count( $first );
1071 -
1072 - // loop through columns
1073 - for ( $i = 0; $i < $rows; $i++ ) {
1074 -
1075 - // loop through the rows and store in a temp array
1076 - $temp = [];
1077 - for ( $j = 0; $j < $cols; $j++ ) {
1078 - $temp[] = isset( $_POST[ $value['name'] ][ $j ][ $i ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ][ $j ][ $i ] ) ) : '';
1079 - }
1080 -
1081 - // store all fields in a row with WeForms::$field_separator separated
1082 - $ref_arr[] = implode( WeForms::$field_separator, $temp );
1083 - }
1084 -
1085 - // now, if we found anything in $ref_arr, store to $multi_repeated
1086 - if ( $ref_arr ) {
1087 - $multi_repeated[ $value['name'] ] = array_slice( $ref_arr, 0, $rows );
1088 - }
1089 - }
1090 - } else {
1091 - $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) );
1092 - }
1093 -
1094 - break;
1095 -
1096 - case 'address_field':
1097 - if ( isset( $_POST[ $value['name'] ] ) && is_array( $_POST[ $value['name'] ] ) ) {
1098 - $post_value = sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) );
1099 - foreach ( $post_value as $address_field => $field_value ) {
1100 - $meta_key_value[ $value['name'] ][ $address_field ] = sanitize_text_field( $field_value );
1101 - }
1102 - }
1103 -
1104 - break;
1105 -
1106 - case 'text_field':
1107 - case 'email_address':
1108 - case 'numeric_text_field':
1109 - case 'date_field':
1110 - $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : '';
1111 -
1112 - break;
1113 -
1114 - case 'textarea_field':
1115 - $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : '';
1116 -
1117 - break;
1118 -
1119 - case 'dropdown_field':
1120 - case 'radio_field':
1121 - $val = sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) );
1122 - $meta_key_value[ $value['name'] ] = isset( $value['options'][ $val ] ) ? $value['options'][ $val ] : '';
1123 - break;
1124 -
1125 - case 'multiple_select':
1126 - case 'checkbox_field':
1127 - $val = ( is_array( $_POST[ $value['name'] ] ) && sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : array();
1128 - $meta_key_value[ $value['name'] ] = $val;
1129 -
1130 - if ( $val ) {
1131 - $new_val = [];
1132 -
1133 - foreach ( $val as $option_key ) {
1134 - $new_val[] = isset( $value['options'][ $option_key ] ) ? $value['options'][ $option_key ] : '';
1135 - }
1136 -
1137 - $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, $new_val );
1138 - }
1139 - break;
1140 -
1141 - default:
1142 - // if it's an array, implode with this->separator
1143 - if ( is_array( $_POST[ $value['name'] ] ) ) {
1144 - $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) );
1145 - } else {
1146 - $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ): '';
1147 - }
1148 -
1149 - break;
1150 - }
1151 - } //end foreach
1152 -
1153 - return [ $meta_key_value, $multi_repeated, $files ];
1154 - }
1155 -
1156 - /**
1157 - * Import a form from a JSON file
1158 - *
1159 - * @return void
1160 - */
1161 - public function import_form() {
1162 - check_ajax_referer( 'weforms' );
1163 -
1164 - $this->check_admin();
1165 -
1166 - $the_file = isset( $_FILES['importFile'] ) ? $_FILES['importFile'] : false;
1167 -
1168 - if ( !$the_file ) {
1169 - wp_send_json_error( __( 'No file found to import.', 'weforms' ) );
1170 - }
1171 -
1172 - $file_ext = pathinfo( $the_file['name'], PATHINFO_EXTENSION );
1173 -
1174 - if ( !class_exists( 'WeForms_Admin_Tools' ) ) {
1175 - require_once __DIR__ . '/admin/class-admin-tools.php';
1176 - }
1177 -
1178 - if ( ( $file_ext == 'json' ) && ( $the_file['size'] < 500000 ) ) {
1179 - $status = WeForms_Admin_Tools::import_json_file( $the_file['tmp_name'] );
1180 -
1181 - if ( $status ) {
1182 - wp_send_json_success( __( 'The forms have been imported successfully!', 'weforms' ) );
1183 - } else {
1184 - wp_send_json_error( __( 'Something went wrong importing the file.', 'weforms' ) );
1185 - }
1186 - } else {
1187 - wp_send_json_error( __( 'Invalid file or file size too big.', 'weforms' ) );
1188 - }
1189 - }
1190 -
1191 - /**
1192 - * Read Log file
1193 - *
1194 - * @return json
1195 - **/
1196 - public function get_logs() {
1197 - check_ajax_referer( 'weforms' );
1198 -
1199 - $this->check_admin();
1200 -
1201 - $file = weforms_log_file_path();
1202 -
1203 - if ( !file_exists( $file ) ) {
1204 - return;
1205 - }
1206 -
1207 - $data = file_get_contents( $file );
1208 - $data = explode( "\n", $data );
1209 - $data = array_reverse( $data );
1210 - $data = array_filter( $data );
1211 -
1212 - if ( empty( $data ) ) {
1213 - return;
1214 - }
1215 -
1216 - $logs = [];
1217 -
1218 - foreach ( $data as $key => $row ) {
1219 - preg_match( '/\[(?<time>.+?)\]\[(?<type>.+?)\](?<message>.+)/im', $row, $log );
1220 -
1221 - if ( empty( $log['message'] ) ) {
1222 - $log = [];
1223 - $log['message'] = !empty( $log['message'] ) ? $log['message'] : $row;
1224 - }
1225 -
1226 - if ( !empty( $log['time'] ) ) {
1227 - $human_time = human_time_diff( strtotime( $log['time'] ), current_time( 'timestamp' ) );
1228 - $log['time'] = $human_time ? $human_time . ' ' . __( 'ago', 'weforms' ) : $log['time'];
1229 - }
1230 -
1231 - $logs[] = $log;
1232 - }
1233 -
1234 - wp_send_json_success( $logs );
1235 - }
1236 -
1237 - /**
1238 - * Read Log file
1239 - *
1240 - * @return json
1241 - **/
1242 - public function delete_logs() {
1243 - check_ajax_referer( 'weforms' );
1244 -
1245 - $this->check_admin();
1246 -
1247 - $file = weforms_log_file_path();
1248 -
1249 - if ( !file_exists( $file ) ) {
1250 - return;
1251 - }
1252 -
1253 - @unlink( $file );
1254 -
1255 - wp_send_json_success();
1256 - }
1257 -}
1 +<?php
2 +
3 +/**
4 + * The ajax handler class
5 + */
6 +class WeForms_Ajax {
7 +
8 + public function __construct() {
9 +
10 + // backend requests
11 + add_action( 'wp_ajax_weforms_form_list', array( $this, 'get_contact_forms' ) );
12 + add_action( 'wp_ajax_weforms_form_names', array( $this, 'get_contact_form_names' ) );
13 + add_action( 'wp_ajax_weforms_form_create', array( $this, 'create_form' ) );
14 + add_action( 'wp_ajax_weforms_form_delete', array( $this, 'delete_form' ) );
15 + add_action( 'wp_ajax_weforms_form_delete_bulk', array( $this, 'delete_form_bulk' ) );
16 + add_action( 'wp_ajax_weforms_form_duplicate', array( $this, 'duplicate_form' ) );
17 +
18 + // read logs
19 + add_action( 'wp_ajax_weforms_read_logs', array( $this, 'get_logs' ) );
20 + add_action( 'wp_ajax_weforms_delete_logs', array( $this, 'delete_logs' ) );
21 +
22 + // create from a template
23 + add_filter( 'wp_ajax_weforms_contact_form_template', array( $this, 'create_form_from_template' ) );
24 +
25 + // form settings
26 + add_action( 'wp_ajax_weforms_save_settings', array( $this, 'save_settings' ) );
27 + add_action( 'wp_ajax_weforms_get_settings', array( $this, 'get_settings' ) );
28 +
29 + // import
30 + add_action( 'wp_ajax_weforms_import_form', array( $this, 'import_form' ) );
31 +
32 + // form editing
33 + add_action( 'wp_ajax_weforms_get_form', array( $this, 'get_form' ) );
34 + add_action( 'wp_ajax_wpuf_form_builder_save_form', array( $this, 'save_form' ) );
35 +
36 + // entries
37 + add_action( 'wp_ajax_weforms_form_entries', array( $this, 'get_entries' ) );
38 +
39 + add_action( 'wp_ajax_weforms_form_entry_details', array( $this, 'get_entry_detail' ) );
40 + add_action( 'wp_ajax_weforms_form_entry_trash', array( $this, 'trash_entry' ) );
41 + add_action( 'wp_ajax_weforms_form_entry_delete', array( $this, 'delete_entry' ) );
42 + add_action( 'wp_ajax_weforms_form_entry_restore', array( $this, 'restore_entry' ) );
43 +
44 + add_action( 'wp_ajax_weforms_form_entry_trash_bulk', array( $this, 'bulk_delete_entry' ) );
45 + add_action( 'wp_ajax_weforms_form_entry_restore_bulk', array( $this, 'bulk_restore_entry' ) );
46 +
47 + // frontend requests
48 + add_action( 'wp_ajax_weforms_frontend_submit', array( $this, 'handle_frontend_submission' ) );
49 + add_action( 'wp_ajax_nopriv_weforms_frontend_submit', array( $this, 'handle_frontend_submission' ) );
50 + }
51 +
52 + /**
53 + * Administrator validation
54 + *
55 + * @return void
56 + */
57 + public function check_admin() {
58 + if ( ! current_user_can( weforms_form_access_capability() ) ) {
59 + wp_send_json_error( __( 'You do not have sufficient permission.', 'weforms' ) );
60 + }
61 + }
62 +
63 + /**
64 + * Get a form to edit
65 + *
66 + * @return void
67 + */
68 + public function get_form() {
69 +
70 + $this->check_admin();
71 +
72 + $form_id = isset( $_REQUEST['form_id'] ) ? absint( $_REQUEST['form_id'] ) : 0;
73 +
74 + $form = weforms()->form->get( $form_id );
75 +
76 + $data = array(
77 + 'post' => $form->data,
78 + 'form_fields' => $form->get_fields(),
79 + 'settings' => $form->get_settings(),
80 + 'notifications' => $form->get_notifications(),
81 + 'integrations' => $form->get_integrations()
82 + );
83 +
84 + wp_send_json_success( $data );
85 + }
86 +
87 + /**
88 + * Save the form
89 + *
90 + * @return void
91 + */
92 + public function save_form() {
93 + parse_str( $_POST['form_data'], $form_data );
94 +
95 + if ( ! wp_verify_nonce( $form_data['wpuf_form_builder_nonce'], 'wpuf_form_builder_save_form' ) ) {
96 + wp_send_json_error( __( 'Unauthorized operation', 'weforms' ) );
97 + }
98 +
99 + if ( empty( $form_data['wpuf_form_id'] ) ) {
100 + wp_send_json_error( __( 'Invalid form id', 'weforms' ) );
101 + }
102 +
103 + $form_fields = isset( $_POST['form_fields'] ) ? $_POST['form_fields'] : '';
104 + $notifications = isset( $_POST['notifications'] ) ? $_POST['notifications'] : '';
105 + $settings = array();
106 + $integrations = array();
107 +
108 + if ( isset( $_POST['settings'] ) ) {
109 + $settings = (array) json_decode( wp_unslash( $_POST['settings'] ) );
110 + } else {
111 + $settings = isset( $form_data['wpuf_settings'] ) ? $form_data['wpuf_settings'] : array();
112 + }
113 +
114 + if ( isset( $_POST['integrations'] ) ) {
115 + $integrations = (array) json_decode( wp_unslash( $_POST['integrations'] ) );
116 + }
117 +
118 + $form_fields = wp_unslash( $form_fields );
119 + $notifications = wp_unslash( $notifications );
120 +
121 + $form_fields = json_decode( $form_fields, true );
122 + $notifications = json_decode( $notifications, true );
123 +
124 + $data = array(
125 + 'form_id' => absint( $form_data['wpuf_form_id'] ),
126 + 'post_title' => sanitize_text_field( $form_data['post_title'] ),
127 + 'form_fields' => $form_fields,
128 + 'form_settings' => $settings,
129 + 'form_settings_key' => isset( $form_data['form_settings_key'] ) ? $form_data['form_settings_key'] : '',
130 + 'notifications' => $notifications,
131 + 'integrations' => $integrations
132 + );
133 +
134 + $form_fields = weforms()->form->save( $data );
135 +
136 + wp_send_json_success( array( 'form_fields' => $form_fields ) );
137 + }
138 +
139 + /**
140 + * Get all contact forms
141 + *
142 + * @return void
143 + */
144 + public function get_contact_forms() {
145 + check_ajax_referer( 'weforms' );
146 +
147 + $this->check_admin();
148 +
149 + $args = array(
150 + 'posts_per_page' => isset( $_POST['posts_per_page'] ) ? intval( $_POST['posts_per_page'] ) : 10,
151 + 'paged' => isset( $_POST['page'] ) ? absint( $_POST['page'] ) : 1,
152 + 'order' => 'DESC',
153 + 'orderby' => 'post_date'
154 + );
155 +
156 + $args = apply_filters( 'weforms_ajax_get_contact_forms_args', $args );
157 +
158 + $contact_forms = weforms()->form->get_forms( $args );
159 +
160 + array_map(
161 + function( $form ) {
162 + $form->entries = $form->num_form_entries();
163 + $form->views = $form->num_form_views();
164 + $form->payments = $form->num_form_payments();
165 + }, $contact_forms['forms']
166 + );
167 +
168 + $contact_forms = $this->filter_contact_forms( $contact_forms );
169 + $contact_forms = apply_filters( 'weforms_ajax_get_contact_forms', $contact_forms );
170 +
171 + wp_send_json_success( $contact_forms );
172 + }
173 +
174 + /**
175 + * Filter
176 + *
177 + * @return void
178 + */
179 + public function filter_contact_forms( &$contact_forms ) {
180 +
181 + if ( isset( $_REQUEST['filter'] ) && $_REQUEST['filter'] == 'entries' ) {
182 + foreach ( $contact_forms['forms'] as $key => &$form ) {
183 + if ( isset( $form->entries ) && ! $form->entries ) {
184 + unset( $contact_forms['forms'][ $key ] );
185 + }
186 + }
187 +
188 + $contact_forms['meta']['total'] = count( $contact_forms['forms'] );
189 + }
190 +
191 + return $contact_forms;
192 + }
193 +
194 + /**
195 + * Get the names of contact forms for generating dropdown
196 + *
197 + * @return void
198 + */
199 + public function get_contact_form_names() {
200 + check_ajax_referer( 'weforms' );
201 +
202 + $this->check_admin();
203 +
204 + $contact_forms = weforms()->form->all();
205 + $response = array();
206 +
207 + foreach ( $contact_forms['forms'] as $form ) {
208 + $response[] = array(
209 + 'id' => $form->get_id(),
210 + 'title' => $form->get_name() . ' (#' . $form->get_id() . ')'
211 + );
212 + }
213 +
214 + wp_send_json_success( $response );
215 + }
216 +
217 + /**
218 + * Create a form
219 + *
220 + * @return void
221 + */
222 + public function create_form() {
223 + check_ajax_referer( 'weforms' );
224 +
225 + $this->check_admin();
226 +
227 + $form_name = isset( $_POST['form_name'] ) ? sanitize_text_field( $_POST['form_name'] ) : '';
228 +
229 + if ( empty( $form_name ) ) {
230 + wp_send_json_error( __( 'Please provide a form name', 'weforms' ) );
231 + }
232 +
233 + $form_id = weforms()->form->create( $form_name );
234 +
235 + if ( is_wp_error( $form_id ) ) {
236 + wp_send_json_error( $form_id->get_error_message() );
237 + }
238 +
239 + wp_send_json_success( array(
240 + 'form_id' => $form_id,
241 + 'form_name' => $form_name
242 + ) );
243 + }
244 +
245 + /**
246 + * Delete a form
247 + *
248 + * @return void
249 + */
250 + public function delete_form() {
251 + check_ajax_referer( 'weforms' );
252 +
253 + $this->check_admin();
254 +
255 + $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
256 +
257 + if ( ! $form_id ) {
258 + wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
259 + }
260 +
261 + weforms()->form->delete( $form_id );
262 +
263 + wp_send_json_success();
264 + }
265 +
266 + public function delete_form_bulk() {
267 + check_ajax_referer( 'weforms' );
268 +
269 + $this->check_admin();
270 +
271 + $form_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : array();
272 +
273 + if ( ! $form_ids ) {
274 + wp_send_json_error( __( 'No form ids provided!', 'weforms' ) );
275 + }
276 +
277 + foreach ( $form_ids as $form_id ) {
278 + weforms()->form->delete( $form_id );
279 + }
280 +
281 + wp_send_json_success();
282 + }
283 +
284 + /**
285 + * Duplicate a form
286 + *
287 + * @return voiud
288 + */
289 + public function duplicate_form() {
290 + check_ajax_referer( 'weforms' );
291 +
292 + $this->check_admin();
293 +
294 + $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
295 +
296 + $form = weforms()->form->duplicate( $form_id );
297 +
298 + wp_send_json_success( $form );
299 + }
300 +
301 + /**
302 + * Create form from a template
303 + *
304 + * @return void
305 + */
306 + public function create_form_from_template() {
307 + check_ajax_referer( 'weforms' );
308 +
309 + $template = isset( $_REQUEST['template'] ) ? sanitize_text_field( $_REQUEST['template'] ) : '';
310 +
311 + $form_id = weforms()->templates->create( $template );
312 +
313 + if ( is_wp_error( $form_id ) ) {
314 + wp_send_json_error( __( 'Could not create the form', 'weforms' ) );
315 + }
316 +
317 + wp_send_json_success( array(
318 + 'id' => $form_id
319 + ) );
320 + }
321 +
322 + /**
323 + * Save the weForms settings
324 + *
325 + * @return void
326 + */
327 + public function save_settings() {
328 + check_ajax_referer( 'weforms' );
329 +
330 + $this->check_admin();
331 +
332 + $requires_wpuf_update = false;
333 + $wpuf_update_array = array();
334 + $settings = (array) json_decode( wp_unslash( $_POST['settings'] ) );
335 +
336 + update_option( 'weforms_settings', $settings );
337 +
338 + // wpuf settings sync
339 + if ( isset( $settings['gmap_api'] ) ) {
340 + $requires_wpuf_update = true;
341 + $wpuf_update_array['gmap_api_key'] = $settings['gmap_api'];
342 + }
343 +
344 + if ( isset( $settings['recaptcha'] ) ) {
345 + $requires_wpuf_update = true;
346 + $wpuf_update_array['recaptcha_public'] = $settings['recaptcha']->key;
347 + $wpuf_update_array['recaptcha_private'] = $settings['recaptcha']->secret;
348 + }
349 +
350 + if ( isset( $settings['no_conflict'] ) ) {
351 + $requires_wpuf_update = true;
352 + $wpuf_update_array['no_conflict'] = $settings['no_conflict'];
353 + }
354 +
355 + if ( $requires_wpuf_update ) {
356 + $wpuf_settings = get_option( 'wpuf_general', array() );
357 +
358 + $wpuf_settings = array_merge( $wpuf_settings, $wpuf_update_array );
359 + update_option( 'wpuf_general', $wpuf_settings );
360 + }
361 +
362 + do_action( 'weforms_save_settings', $settings );
363 +
364 + $settings = apply_filters( 'weforms_after_save_settings', $settings );
365 +
366 + wp_send_json_success( $settings );
367 + }
368 +
369 + /**
370 + * Get the weForms Settings
371 + *
372 + * @return void
373 + */
374 + public function get_settings() {
375 + check_ajax_referer( 'weforms' );
376 +
377 + $this->check_admin();
378 +
379 + $settings = weforms_get_settings();
380 +
381 + // checking to prevent js error, will be removed in future
382 + if ( ! isset( $settings['credit'] ) ) {
383 + $settings['credit'] = false;
384 + }
385 +
386 + if ( ! isset( $settings['permission'] ) ) {
387 + $settings['permission'] = 'manage_options';
388 + }
389 +
390 + wp_send_json_success( $settings );
391 + }
392 +
393 + /**
394 + * Get all entries
395 + *
396 + * @return void
397 + */
398 + public function get_entries() {
399 + check_ajax_referer( 'weforms' );
400 +
401 + $this->check_admin();
402 +
403 + $form_id = isset( $_REQUEST['id'] ) ? intval( $_REQUEST['id'] ) : 0;
404 + $current_page = isset( $_REQUEST['page'] ) ? intval( $_REQUEST['page'] ) : 1;
405 + $status = isset( $_REQUEST['status'] ) ? $_REQUEST['status'] : 'publish';
406 + $per_page = 20;
407 + $offset = ( $current_page - 1 ) * $per_page;
408 +
409 + if ( ! $form_id ) {
410 + wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
411 + }
412 +
413 + $entries = weforms_get_form_entries(
414 + $form_id, array(
415 + 'number' => $per_page,
416 + 'offset' => $offset,
417 + 'status' => $status,
418 + )
419 + );
420 +
421 + $columns = weforms_get_entry_columns( $form_id );
422 + $total_entries = weforms_count_form_entries( $form_id, $status );
423 +
424 + array_map(
425 + function( $entry ) use ( $columns ) {
426 + $entry_id = $entry->id;
427 + $entry->fields = array();
428 +
429 + foreach ( $columns as $meta_key => $label ) {
430 + $value = weforms_get_entry_meta( $entry_id, $meta_key, true );
431 + $entry->fields[ $meta_key ] = str_replace( WeForms::$field_separator, ' ', $value );
432 + }
433 + }, $entries
434 + );
435 +
436 + $entries = apply_filters( 'weforms_get_entries', $entries, $form_id );
437 +
438 + $response = array(
439 + 'columns' => $columns,
440 + 'entries' => $entries,
441 + 'form_title' => get_post_field( 'post_title', $form_id ),
442 + 'pagination' => array(
443 + 'total' => $total_entries,
444 + 'per_page' => $per_page,
445 + 'pages' => ceil( $total_entries / $per_page ),
446 + 'current' => $current_page
447 + ),
448 + 'meta' => array(
449 + 'total' => weforms_count_form_entries( $form_id ),
450 + 'totalTrash' => weforms_count_form_entries( $form_id, 'trash' ),
451 + ),
452 + );
453 +
454 + wp_send_json_success( $response );
455 + }
456 +
457 +
458 +
459 + /**
460 + * Get an entry details
461 + *
462 + * @return void
463 + */
464 + public function get_entry_detail() {
465 + check_ajax_referer( 'weforms' );
466 +
467 + $this->check_admin();
468 +
469 + $form_id = isset( $_REQUEST['form_id'] ) ? intval( $_REQUEST['form_id'] ) : 0;
470 + $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
471 +
472 + $form = weforms()->form->get( $form_id );
473 + $form_settings = $form->get_settings();
474 + $entry = $form->entries()->get( $entry_id );
475 + $fields = $entry->get_fields();
476 + $metadata = $entry->get_metadata();
477 + $payment = $entry->get_payment_data();
478 +
479 + if ( isset( $payment->payment_data ) && is_serialized( $payment->payment_data ) ) {
480 + $payment->payment_data = unserialize( $payment->payment_data );
481 + }
482 +
483 + if ( false === $fields ) {
484 + wp_send_json_error( __( 'No form fields found!', 'weforms' ) );
485 + }
486 +
487 + if ( sizeof( $fields ) < 1 ) {
488 + $fields[] = array(
489 + 'label' => __( 'No form fields found!', 'weforms' )
490 + );
491 + }
492 +
493 + $has_empty = false;
494 + $answers = array();
495 + $respondentPoints = isset($form_settings['total_points']) ? floatval( $form_settings['total_points'] ) : 0 ;
496 +
497 + foreach ( $fields as $key => $field ) {
498 +
499 + if ( $form_settings['quiz_form'] == 'yes' ) {
500 + $selectedAnswers = isset($field['selected_answers']) ? $field['selected_answers'] : '';
501 + $givenAnswer = isset($field['value']) ? $field['value'] : '';
502 + $options = isset($field['options']) ? $field['options'] : '';
503 + $template = $field['template'];
504 + $fieldPoints = isset($field['points']) ? floatval( $field['points'] ) : 0;
505 +
506 + if ( $template == 'radio_field' || $template == 'dropdown_field' ) {
507 + $answers[$field['name']] = true;
508 +
509 + if ( empty($givenAnswer) ) {
510 + $answers[$field['name']] = false;
511 + $respondentPoints -= $fieldPoints;
512 + }else {
513 + foreach ($options as $key => $value) {
514 + if ( $givenAnswer == $value ) {
515 + if ( $key != $selectedAnswers ) {
516 + $answers[$field['name']] = false;
517 + $respondentPoints -= $fieldPoints;
518 + }
519 + }
520 + }
521 + }
522 + } elseif ( $template == 'checkbox_field' || $template == 'multiple_select' ) {
523 + $answers[$field['name']] = true;
524 + $userAnswer = [];
525 +
526 + foreach ($options as $key => $value) {
527 + foreach ($givenAnswer as $answer) {
528 + if ($value == $answer) {
529 + $userAnswer[] = $key;
530 + }
531 + }
532 + }
533 +
534 + $userAnswer = implode('|', $userAnswer);
535 + $rightAnswers = implode('|', $selectedAnswers);
536 +
537 + if ( $userAnswer != $rightAnswers || empty($userAnswer) ) {
538 + $answers[$field['name']] = false;
539 + $respondentPoints -= $fieldPoints;
540 + }
541 + }
542 + } elseif ( empty( $field['value'] ) ) {
543 + $has_empty = true;
544 + break;
545 + }
546 +
547 + }
548 +
549 + $response = array(
550 + 'form_fields' => $fields,
551 + 'form_settings' => $form_settings,
552 + 'meta_data' => $metadata,
553 + 'payment_data' => $payment,
554 + 'has_empty' => $has_empty,
555 + 'respondent_points' => $respondentPoints,
556 + 'answers' => $answers,
557 + );
558 +
559 + wp_send_json_success( $response );
560 + }
561 +
562 + /**
563 + * Trash an entry
564 + *
565 + * @return void
566 + */
567 + public function trash_entry() {
568 + check_ajax_referer( 'weforms' );
569 +
570 + $this->check_admin();
571 +
572 + $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
573 +
574 + weforms_change_entry_status( $entry_id, 'trash' );
575 + wp_send_json_success();
576 + }
577 +
578 + /**
579 + * Trash an entry
580 + *
581 + * @return void
582 + */
583 + public function delete_entry() {
584 + check_ajax_referer( 'weforms' );
585 +
586 + $this->check_admin();
587 +
588 + $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
589 +
590 + weforms_delete_entry( $entry_id );
591 +
592 + wp_send_json_success();
593 + }
594 +
595 + /**
596 + * Restore Entry
597 + *
598 + * @return void
599 + */
600 + public function restore_entry() {
601 + check_ajax_referer( 'weforms' );
602 +
603 + $this->check_admin();
604 +
605 + $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
606 +
607 + weforms_change_entry_status( $entry_id, 'publish' );
608 + wp_send_json_success();
609 + }
610 +
611 + /**
612 + * Bulk trash entries
613 + *
614 + * @return void
615 + */
616 + public function bulk_delete_entry() {
617 + check_ajax_referer( 'weforms' );
618 +
619 + $this->check_admin();
620 +
621 + $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : array();
622 + $permanent = isset( $_POST['permanent'] ) && ( $_POST['permanent'] ) ? true : false;
623 +
624 + if ( ! $entry_ids ) {
625 + wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
626 + }
627 +
628 + foreach ( $entry_ids as $entry_id ) {
629 + if ( $permanent ) {
630 + weforms_delete_entry( $entry_id );
631 + } else {
632 + weforms_change_entry_status( $entry_id, 'trash' );
633 + }
634 + }
635 +
636 + wp_send_json_success();
637 + }
638 +
639 + /**
640 + * Bulk trash entries
641 + *
642 + * @return void
643 + */
644 + public function bulk_restore_entry() {
645 + check_ajax_referer( 'weforms' );
646 +
647 + $this->check_admin();
648 +
649 + $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : array();
650 +
651 + if ( ! $entry_ids ) {
652 + wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
653 + }
654 +
655 + foreach ( $entry_ids as $entry_id ) {
656 + weforms_change_entry_status( $entry_id, 'publish' );
657 + }
658 +
659 + wp_send_json_success();
660 + }
661 +
662 + /**
663 + * Handle the frontend submission
664 + *
665 + * @return void
666 + */
667 + public function handle_frontend_submission() {
668 + check_ajax_referer( 'wpuf_form_add' );
669 +
670 + $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
671 + $page_id = isset( $_POST['page_id'] ) ? intval( $_POST['page_id'] ) : 0;
672 +
673 + $form = weforms()->form->get( $form_id );
674 + $form_settings = $form->get_settings();
675 + $form_fields = $form->get_fields();
676 + $entry_fields = $form->prepare_entries();
677 + $form_entries = weforms_get_form_entries( $form_id, array( 'number' => '', 'offset' => '' ) );
678 +
679 + if ( $form_fields && count( $form_entries ) && count( $entry_fields ) ) {
680 +
681 + foreach ( $entry_fields as $field_key => $field_value ) {
682 + $duplicate_check = false;
683 + $field_label = 'This';
684 +
685 + foreach ( $form_fields as $form_field ) {
686 + if ( in_array( $form_field['template'], array( 'text_field', 'website_url', 'numeric_text_field', 'email_address' ) ) && $form_field['name'] == $field_key && isset( $form_field['duplicate'] ) && 'no' == $form_field['duplicate'] ) {
687 + $duplicate_check = true;
688 + $field_label = $form_field['label'];
689 + }
690 + }
691 +
692 + if ( $duplicate_check ) {
693 +
694 + foreach ( $form_entries as $entry ) {
695 + $existing = weforms_get_entry_meta( $entry->id, $field_key, true );
696 +
697 + if ( $existing && $field_value == $existing ) {
698 + wp_send_json( array(
699 + 'success' => false,
700 + 'error' => sprintf( __( '"%s" field requires a unique entry and "%s" has already been used.', 'weforms' ), $field_label, $field_value )
701 + ) );
702 + }
703 + }
704 + }
705 + }
706 + }
707 +
708 + if ( ! $form_fields ) {
709 + wp_send_json( array(
710 + 'success' => false,
711 + 'error' => __( 'No form field was found.', 'weforms' ),
712 + ) );
713 + }
714 +
715 + if ( $form->has_field( 'recaptcha' ) ) {
716 + $this->validate_reCaptcha();
717 + }
718 +
719 + // vaidate submission
720 + $this->validate_submission( $entry_fields, $form, $form_settings, $form_fields );
721 +
722 + $entry_fields = apply_filters( 'weforms_before_entry_submission', $entry_fields, $form, $form_settings, $form_fields );
723 +
724 + $entry_id = weforms_insert_entry( array(
725 + 'form_id' => $form_id
726 + ), $entry_fields );
727 +
728 + if ( is_wp_error( $entry_id ) ) {
729 + wp_send_json( array(
730 + 'success' => false,
731 + 'error' => $entry_id->get_error_message(),
732 + ) );
733 + }
734 +
735 + // redirect URL
736 + $show_message = false;
737 + $redirect_to = false;
738 +
739 + if ( $form_settings['redirect_to'] == 'page' ) {
740 + $redirect_to = get_permalink( $form_settings['page_id'] );
741 + } elseif ( $form_settings['redirect_to'] == 'url' ) {
742 + $redirect_to = $form_settings['url'];
743 + } elseif ( $form_settings['redirect_to'] == 'same' ) {
744 + $show_message = true;
745 + } else {
746 + $redirect_to = get_permalink( $post_id );
747 + }
748 +
749 + // Fire a hook for integration
750 + do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
751 +
752 + $field_search = $field_replace = array();
753 +
754 + foreach ( $form_fields as $r_field ) {
755 + $field_search[] = '{'.$r_field['name'].'}';
756 + if ( $r_field['template'] == 'name_field' ) {
757 + $field_replace[] = implode( ' ' , explode( '|', $entry_fields[$r_field['name']] ));
758 + } else {
759 + $field_replace[] = $entry_fields[$r_field['name']];
760 + }
761 + }
762 + $message = str_replace( $field_search, $field_replace, $form_settings['message'] );
763 +
764 + // send the response
765 + $response = apply_filters( 'weforms_entry_submission_response', array(
766 + 'success' => true,
767 + 'redirect_to' => $redirect_to,
768 + 'show_message' => $show_message,
769 + 'message' => $message,
770 + 'data' => $_POST,
771 + 'form_id' => $form_id,
772 + 'entry_id' => $entry_id,
773 + ) );
774 +
775 + $notification = new WeForms_Notification( array(
776 + 'form_id' => $form_id,
777 + 'page_id' => $page_id,
778 + 'entry_id' => $entry_id
779 + ) );
780 +
781 + $notification->send_notifications();
782 +
783 + weforms_clear_buffer();
784 + wp_send_json( $response );
785 + }
786 +
787 + /**
788 + * reCaptcha Validation
789 + *
790 + * @return void
791 + */
792 + function validate_reCaptcha() {
793 +
794 + if ( class_exists( 'WPUF_ReCaptcha' ) ) {
795 + $recaptcha_class = 'WPUF_Recaptcha';
796 + } else {
797 + require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib.php';
798 + require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib_noCaptcha.php';
799 + $recaptcha_class = 'Weforms_ReCaptcha';
800 + }
801 +
802 + $invisible = isset( $_POST['g-recaptcha-response'] ) ? false : true;
803 +
804 + $recaptcha_settings = weforms_get_settings( 'recaptcha' );
805 + $secret = isset( $recaptcha_settings->secret ) ? $recaptcha_settings->secret : '';
806 +
807 + if ( ! $invisible ) {
808 +
809 + $response = null;
810 + $reCaptcha = new $recaptcha_class( $secret );
811 +
812 + $resp = $reCaptcha->verifyResponse(
813 + $_SERVER['REMOTE_ADDR'],
814 + $_POST['g-recaptcha-response']
815 + );
816 +
817 + if ( ! $resp->success ) {
818 + wp_send_json( array(
819 + 'success' => false,
820 + 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
821 + ) );
822 + }
823 + } else {
824 +
825 + $recap_challenge = isset( $_POST['recaptcha_challenge_field'] ) ? $_POST['recaptcha_challenge_field'] : '';
826 + $recap_response = isset( $_POST['recaptcha_response_field'] ) ? $_POST['recaptcha_response_field'] : '';
827 +
828 + $resp = recaptcha_check_answer( $secret, $_SERVER['REMOTE_ADDR'], $recap_challenge, $recap_response );
829 +
830 + if ( ! $resp->is_valid ) {
831 +
832 + ob_clean();
833 +
834 + wp_send_json( array(
835 + 'success' => false,
836 + 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
837 + ) );
838 + }
839 + }
840 +
841 + }
842 +
843 + /**
844 + * Validate submission
845 + *
846 + * @param array $entry_fields
847 + * @param object $form
848 + * @param array $form_settings
849 + * @param array $form_fields
850 + *
851 + * @return bool|json
852 + */
853 + function validate_submission( $entry_fields, $form, $form_settings, $form_fields ) {
854 +
855 + foreach ( $form_fields as $key => $field ) {
856 +
857 + //skip custom html field as it is not saved
858 + if ( 'custom_html' == $field['name'] )
859 + continue;
860 +
861 + $value = $entry_fields[ $field['name'] ];
862 +
863 + // if ( isset( $field['required'] ) && $field['required'] && empty( $value ) ) {
864 + // wp_send_json( array(
865 + // 'success' => false,
866 + // 'error' => __( sprintf( '%s field is required', $field['label'] ), 'weforms' ),
867 + // ) );
868 + // }
869 + if ( 'single_product' === $field['template'] ) {
870 +
871 + if ( ! $value ) {
872 + $value = array();
873 + }
874 +
875 + $value['price'] = isset( $value['price'] ) ? floatval( $value['price'] ) : 0;
876 + $value['quantity'] = isset( $value['quantity'] ) ? floatval( $value['quantity'] ) : 0;
877 + $quantity = isset( $field['quantity'] ) ? $field['quantity'] : array();
878 + $price = isset( $field['price'] ) ? $field['price'] : array();
879 +
880 + if ( isset( $price['is_flexible'] ) && $price['is_flexible'] ) {
881 +
882 + $min = isset( $price['min'] ) ? floatval( $price['min'] ) : 0;
883 + $max = isset( $price['max'] ) ? floatval( $price['max'] ) : 0;
884 +
885 + if ( $value['price'] < $min ) {
886 +
887 + wp_send_json( array(
888 + 'success' => false,
889 + 'error' => __( sprintf(
890 + '%s price must be equal or greater than %s',
891 + $field['weforms'],
892 + $min),
893 + 'weforms' ),
894 + ) );
895 + }
896 +
897 + if ( $max && $value['price'] > $max ) {
898 +
899 + wp_send_json( array(
900 + 'success' => false,
901 + 'error' => __( sprintf(
902 + '%s price must be equal or less than %s',
903 + $field['weforms'],
904 + $max),
905 + 'weforms' ),
906 + ) );
907 + }
908 + }
909 +
910 + if ( isset( $quantity['status'] ) && $quantity['status'] ) {
911 +
912 + $min = isset( $quantity['min'] ) ? floatval( $quantity['min'] ) : 0;
913 + $max = isset( $quantity['max'] ) ? floatval( $quantity['max'] ) : 0;
914 +
915 + if ( $value['quantity'] < $min ) {
916 +
917 + wp_send_json( array(
918 + 'success' => false,
919 + 'error' => __( sprintf(
920 + '%s quantity must be equal or greater than %s',
921 + $field['weforms'],
922 + $min),
923 + 'weforms' ),
924 + ) );
925 + }
926 +
927 + if ( $max && $value['quantity'] > $max ) {
928 +
929 + wp_send_json( array(
930 + 'success' => false,
931 + 'error' => __( sprintf(
932 + '%s quantity must be equal or less than %s',
933 + $field['weforms'],
934 + $max),
935 + 'weforms' ),
936 + ) );
937 + }
938 + }
939 + }
940 + }
941 + }
942 +
943 + public static function prepare_meta_fields( $meta_vars ) {
944 + // loop through custom fields
945 + // skip files, put in a key => value paired array for later executation
946 + // process repeatable fields separately
947 + // if the input is array type, implode with separator in a field
948 + $files = array();
949 + $meta_key_value = array();
950 + $multi_repeated = array(); // multi repeated fields will in sotre duplicated meta key
951 +
952 + foreach ( $meta_vars as $key => $value ) {
953 +
954 + switch ( $value['template'] ) {
955 +
956 + // put files in a separate array, we'll process it later
957 + case 'file_upload':
958 + case 'image_upload':
959 + $files[] = array(
960 + 'name' => $value['name'],
961 + 'value' => isset( $_POST['wpuf_files'][ $value['name'] ] ) ? $_POST['wpuf_files'][ $value['name'] ] : array(),
962 + 'count' => $value['count']
963 + );
964 + break;
965 +
966 + case 'repeat_field':
967 + // if it is a multi column repeat field
968 + if ( isset( $value['multiple'] ) && $value['multiple'] == 'true' ) {
969 +
970 + // if there's any items in the array, process it
971 + if ( $_POST[ $value['name'] ] ) {
972 +
973 + $ref_arr = array();
974 + $cols = count( $value['columns'] );
975 + $first = array_shift( array_values( $_POST[ $value['name'] ] ) ); // first element
976 + $rows = count( $first );
977 +
978 + // loop through columns
979 + for ( $i = 0; $i < $rows; $i++ ) {
980 +
981 + // loop through the rows and store in a temp array
982 + $temp = array();
983 + for ( $j = 0; $j < $cols; $j++ ) {
984 +
985 + $temp[] = $_POST[ $value['name'] ][ $j ][ $i ];
986 + }
987 +
988 + // store all fields in a row with WeForms::$field_separator separated
989 + $ref_arr[] = implode( WeForms::$field_separator, $temp );
990 + }
991 +
992 + // now, if we found anything in $ref_arr, store to $multi_repeated
993 + if ( $ref_arr ) {
994 + $multi_repeated[ $value['name'] ] = array_slice( $ref_arr, 0, $rows );
995 + }
996 + }
997 + } else {
998 + $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, $_POST[ $value['name'] ] );
999 + }
1000 +
1001 + break;
1002 +
1003 + case 'address_field':
1004 + if ( isset( $_POST[ $value['name'] ] ) && is_array( $_POST[ $value['name'] ] ) ) {
1005 + foreach ( $_POST[ $value['name'] ] as $address_field => $field_value ) {
1006 + $meta_key_value[ $value['name'] ][ $address_field ] = sanitize_text_field( $field_value );
1007 + }
1008 + }
1009 +
1010 + break;
1011 +
1012 + case 'text_field':
1013 + case 'email_address':
1014 + case 'numeric_text_field':
1015 + case 'date_field':
1016 + $meta_key_value[ $value['name'] ] = sanitize_text_field( trim( $_POST[ $value['name'] ] ) );
1017 +
1018 + break;
1019 +
1020 + case 'textarea_field':
1021 + $meta_key_value[ $value['name'] ] = wp_kses_post( $_POST[ $value['name'] ] );
1022 +
1023 + break;
1024 +
1025 + case 'dropdown_field':
1026 + case 'radio_field':
1027 + $val = $_POST[ $value['name'] ];
1028 + $meta_key_value[ $value['name'] ] = isset( $value['options'][ $val ] ) ? $value['options'][ $val ] : '';
1029 + break;
1030 +
1031 + case 'multiple_select':
1032 + case 'checkbox_field':
1033 + $val = ( is_array( $_POST[ $value['name'] ] ) && $_POST[ $value['name'] ] ) ? $_POST[ $value['name'] ] : array();
1034 + $meta_key_value[ $value['name'] ] = $val;
1035 +
1036 + if ( $val ) {
1037 + $new_val = array();
1038 +
1039 + foreach ( $val as $option_key ) {
1040 + $new_val[] = isset( $value['options'][ $option_key ] ) ? $value['options'][ $option_key ] : '';
1041 + }
1042 +
1043 + $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, $new_val );
1044 + }
1045 + break;
1046 +
1047 + default:
1048 + // if it's an array, implode with this->separator
1049 + if ( is_array( $_POST[ $value['name'] ] ) ) {
1050 +
1051 + $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, $_POST[ $value['name'] ] );
1052 +
1053 + } else {
1054 + $meta_key_value[ $value['name'] ] = trim( $_POST[ $value['name'] ] );
1055 + }
1056 +
1057 + break;
1058 + }
1059 + } //end foreach
1060 +
1061 + return array( $meta_key_value, $multi_repeated, $files );
1062 + }
1063 +
1064 + /**
1065 + * Import a form from a JSON file
1066 + *
1067 + * @return void
1068 + */
1069 + public function import_form() {
1070 + check_ajax_referer( 'weforms' );
1071 +
1072 + $this->check_admin();
1073 +
1074 + $the_file = isset( $_FILES['importFile'] ) ? $_FILES['importFile'] : false;
1075 +
1076 + if ( ! $the_file ) {
1077 + wp_send_json_error( __( 'No file found to import.', 'weforms' ) );
1078 + }
1079 +
1080 + $file_ext = pathinfo( $the_file['name'], PATHINFO_EXTENSION );
1081 +
1082 + if ( ! class_exists( 'WeForms_Admin_Tools' ) ) {
1083 + require_once dirname( __FILE__ ) . '/admin/class-admin-tools.php';
1084 + }
1085 +
1086 + if ( ( $file_ext == 'json' ) && ( $the_file['size'] < 500000 ) ) {
1087 +
1088 + $status = WeForms_Admin_Tools::import_json_file( $the_file['tmp_name'] );
1089 +
1090 + if ( $status ) {
1091 + wp_send_json_success( __( 'The forms have been imported successfully!', 'weforms' ) );
1092 + } else {
1093 + wp_send_json_error( __( 'Something went wrong importing the file.', 'weforms' ) );
1094 + }
1095 + } else {
1096 + wp_send_json_error( __( 'Invalid file or file size too big.', 'weforms' ) );
1097 + }
1098 + }
1099 +
1100 + /**
1101 + * Read Log file
1102 + *
1103 + * @return json
1104 + **/
1105 + function get_logs() {
1106 +
1107 + check_ajax_referer( 'weforms' );
1108 +
1109 + $this->check_admin();
1110 +
1111 + $file = weforms_log_file_path();
1112 +
1113 + if ( ! file_exists( $file ) ) {
1114 + return;
1115 + }
1116 +
1117 + $data = file_get_contents( $file );
1118 + $data = explode( "\n", $data );
1119 + $data = array_reverse( $data );
1120 + $data = array_filter( $data );
1121 +
1122 + if ( empty( $data ) ) {
1123 + return;
1124 + }
1125 +
1126 + $logs = array();
1127 +
1128 + foreach ( $data as $key => $row ) {
1129 +
1130 + preg_match( '/\[(?<time>.+?)\]\[(?<type>.+?)\](?<message>.+)/im', $row, $log );
1131 +
1132 + if ( empty( $log['message'] ) ) {
1133 + $log = array();
1134 + $log['message'] = ! empty( $log['message'] ) ? $log['message'] : $row;
1135 + }
1136 +
1137 + if ( ! empty( $log['time'] ) ) {
1138 + $human_time = human_time_diff( strtotime( $log['time'] ) , current_time( 'timestamp' ) );
1139 + $log['time'] = $human_time ? $human_time . ' ' . __( 'ago', 'weforms' ) : $log['time'];
1140 + }
1141 +
1142 + $logs[] = $log;
1143 + }
1144 +
1145 + wp_send_json_success( $logs );
1146 + }
1147 +
1148 + /**
1149 + * Read Log file
1150 + *
1151 + * @return json
1152 + **/
1153 + function delete_logs() {
1154 +
1155 + check_ajax_referer( 'weforms' );
1156 +
1157 + $this->check_admin();
1158 +
1159 + $file = weforms_log_file_path();
1160 +
1161 + if ( ! file_exists( $file ) ) {
1162 + return;
1163 + }
1164 +
1165 + @unlink( $file );
1166 +
1167 + wp_send_json_success();
1168 + }
1169 +
1170 +}