PluginProbe
weForms – Easy Drag & Drop Contact Form Builder For WordPress / 1.4.0
weForms – Easy Drag & Drop Contact Form Builder For WordPress v1.4.0
1.6.7 1.6.8 1.6.9 1.6.12 1.6.13 1.6.14 1.6.15 1.6.16 1.6.17 1.6.18 1.6.19 1.6.2 1.6.20 1.6.21 1.6.22 1.6.23 1.6.24 1.6.25 1.6.26 1.6.27 1.6.28 1.6.3 1.6.4 1.6.5 1.6.6 All 74 releases
weforms / includes / class-ajax.php

class-ajax.php in weForms – Easy Drag & Drop Contact Form Builder For WordPress 1.4.0, at includes/class-ajax.php

1,197 lines 39.1 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 /**
4 * The ajax handler class
5 */
6 class WeForms_Ajax {
7
8 public function __construct() {
9
10 // backend requests
11 add_action( 'wp_ajax_weforms_form_list', array( $this, 'get_contact_forms' ) );
12 add_action( 'wp_ajax_weforms_get_users', array( $this, 'get_all_users' ) );
13 add_action( 'wp_ajax_weforms_form_names', array( $this, 'get_contact_form_names' ) );
14 add_action( 'wp_ajax_weforms_form_create', array( $this, 'create_form' ) );
15 add_action( 'wp_ajax_weforms_form_delete', array( $this, 'delete_form' ) );
16 add_action( 'wp_ajax_weforms_form_delete_bulk', array( $this, 'delete_form_bulk' ) );
17 add_action( 'wp_ajax_weforms_form_duplicate', array( $this, 'duplicate_form' ) );
18
19 // read logs
20 add_action( 'wp_ajax_weforms_read_logs', array( $this, 'get_logs' ) );
21 add_action( 'wp_ajax_weforms_delete_logs', array( $this, 'delete_logs' ) );
22
23 // create from a template
24 add_filter( 'wp_ajax_weforms_contact_form_template', array( $this, 'create_form_from_template' ) );
25
26 // form settings
27 add_action( 'wp_ajax_weforms_save_settings', array( $this, 'save_settings' ) );
28 add_action( 'wp_ajax_weforms_get_settings', array( $this, 'get_settings' ) );
29
30 // import
31 add_action( 'wp_ajax_weforms_import_form', array( $this, 'import_form' ) );
32
33 // form editing
34 add_action( 'wp_ajax_weforms_get_form', array( $this, 'get_form' ) );
35 add_action( 'wp_ajax_wpuf_form_builder_save_form', array( $this, 'save_form' ) );
36
37 // entries
38 add_action( 'wp_ajax_weforms_form_entries', array( $this, 'get_entries' ) );
39
40 add_action( 'wp_ajax_weforms_form_entry_details', array( $this, 'get_entry_detail' ) );
41 add_action( 'wp_ajax_weforms_form_entry_trash', array( $this, 'trash_entry' ) );
42 add_action( 'wp_ajax_weforms_form_entry_delete', array( $this, 'delete_entry' ) );
43 add_action( 'wp_ajax_weforms_form_entry_restore', array( $this, 'restore_entry' ) );
44
45 add_action( 'wp_ajax_weforms_form_entry_trash_bulk', array( $this, 'bulk_delete_entry' ) );
46 add_action( 'wp_ajax_weforms_form_entry_restore_bulk', array( $this, 'bulk_restore_entry' ) );
47
48 // frontend requests
49 add_action( 'wp_ajax_weforms_frontend_submit', array( $this, 'handle_frontend_submission' ) );
50 add_action( 'wp_ajax_nopriv_weforms_frontend_submit', array( $this, 'handle_frontend_submission' ) );
51 }
52
53 /**
54 * Administrator validation
55 *
56 * @return void
57 */
58 public function check_admin() {
59 if ( ! current_user_can( weforms_form_access_capability() ) ) {
60 wp_send_json_error( __( 'You do not have sufficient permission.', 'weforms' ) );
61 }
62 }
63
64 /**
65 * Get a form to edit
66 *
67 * @return void
68 */
69 public function get_form() {
70
71 $this->check_admin();
72
73 $form_id = isset( $_REQUEST['form_id'] ) ? absint( $_REQUEST['form_id'] ) : 0;
74
75 $form = weforms()->form->get( $form_id );
76
77 $data = array(
78 'post' => $form->data,
79 'form_fields' => $form->get_fields(),
80 'settings' => $form->get_settings(),
81 'notifications' => $form->get_notifications(),
82 'integrations' => $form->get_integrations()
83 );
84
85 wp_send_json_success( $data );
86 }
87
88 /**
89 * Save the form
90 *
91 * @return void
92 */
93 public function save_form() {
94 parse_str( $_POST['form_data'], $form_data );
95
96 if ( ! wp_verify_nonce( $form_data['wpuf_form_builder_nonce'], 'wpuf_form_builder_save_form' ) ) {
97 wp_send_json_error( __( 'Unauthorized operation', 'weforms' ) );
98 }
99
100 if ( empty( $form_data['wpuf_form_id'] ) ) {
101 wp_send_json_error( __( 'Invalid form id', 'weforms' ) );
102 }
103
104 $form_fields = isset( $_POST['form_fields'] ) ? $_POST['form_fields'] : '';
105 $notifications = isset( $_POST['notifications'] ) ? $_POST['notifications'] : '';
106 $settings = array();
107 $integrations = array();
108
109 if ( isset( $_POST['settings'] ) ) {
110 $settings = (array) json_decode( wp_unslash( $_POST['settings'] ) );
111 } else {
112 $settings = isset( $form_data['wpuf_settings'] ) ? $form_data['wpuf_settings'] : array();
113 }
114
115 if ( isset( $_POST['integrations'] ) ) {
116 $integrations = (array) json_decode( wp_unslash( $_POST['integrations'] ) );
117 }
118
119 $form_fields = wp_unslash( $form_fields );
120 $notifications = wp_unslash( $notifications );
121
122 $form_fields = json_decode( $form_fields, true );
123 $notifications = json_decode( $notifications, true );
124
125 $data = array(
126 'form_id' => absint( $form_data['wpuf_form_id'] ),
127 'post_title' => sanitize_text_field( $form_data['post_title'] ),
128 'form_fields' => $form_fields,
129 'form_settings' => $settings,
130 'form_settings_key' => isset( $form_data['form_settings_key'] ) ? $form_data['form_settings_key'] : '',
131 'notifications' => $notifications,
132 'integrations' => $integrations
133 );
134
135 $form_fields = weforms()->form->save( $data );
136
137 wp_send_json_success( array( 'form_fields' => $form_fields ) );
138 }
139
140 /**
141 * Get all contact forms
142 *
143 * @return void
144 */
145 public function get_contact_forms() {
146 check_ajax_referer( 'weforms' );
147
148 $this->check_admin();
149
150 $args = array(
151 'posts_per_page' => isset( $_POST['posts_per_page'] ) ? intval( $_POST['posts_per_page'] ) : 10,
152 'paged' => isset( $_POST['page'] ) ? absint( $_POST['page'] ) : 1,
153 'order' => 'DESC',
154 'orderby' => 'post_date'
155 );
156
157 $args = apply_filters( 'weforms_ajax_get_contact_forms_args', $args );
158
159 $contact_forms = weforms()->form->get_forms( $args );
160
161 array_map(
162 function( $form ) {
163 $form->entries = $form->num_form_entries();
164 $form->settings = $form->get_settings();
165 $form->views = $form->num_form_views();
166 $form->payments = $form->num_form_payments();
167 }, $contact_forms['forms']
168 );
169
170 $contact_forms = $this->filter_contact_forms( $contact_forms );
171 $contact_forms = apply_filters( 'weforms_ajax_get_contact_forms', $contact_forms );
172
173 wp_send_json_success( $contact_forms );
174 }
175
176 /**
177 * Get all users
178 *
179 * @return array
180 */
181 public function get_all_users() {
182 check_ajax_referer( 'weforms' );
183
184 $this->check_admin();
185
186 $users_meta = array();
187 $users = get_users( array( 'fields' => array( 'ID' ) ) );
188
189 foreach($users as $user) {
190 $users_meta[] = array(
191 'id' => $user->ID,
192 'data' => get_user_meta ( $user->ID )
193 );
194 };
195
196 wp_send_json_success( $users_meta );
197 }
198
199 /**
200 * Filter
201 *
202 * @return void
203 */
204 public function filter_contact_forms( &$contact_forms ) {
205
206 if ( isset( $_REQUEST['filter'] ) && $_REQUEST['filter'] == 'entries' ) {
207 foreach ( $contact_forms['forms'] as $key => &$form ) {
208 if ( isset( $form->entries ) && ! $form->entries ) {
209 unset( $contact_forms['forms'][ $key ] );
210 }
211 }
212
213 $contact_forms['meta']['total'] = count( $contact_forms['forms'] );
214 }
215
216 return $contact_forms;
217 }
218
219 /**
220 * Get the names of contact forms for generating dropdown
221 *
222 * @return void
223 */
224 public function get_contact_form_names() {
225 check_ajax_referer( 'weforms' );
226
227 $this->check_admin();
228
229 $contact_forms = weforms()->form->all();
230 $response = array();
231
232 foreach ( $contact_forms['forms'] as $form ) {
233 $response[] = array(
234 'id' => $form->get_id(),
235 'title' => $form->get_name() . ' (#' . $form->get_id() . ')'
236 );
237 }
238
239 wp_send_json_success( $response );
240 }
241
242 /**
243 * Create a form
244 *
245 * @return void
246 */
247 public function create_form() {
248 check_ajax_referer( 'weforms' );
249
250 $this->check_admin();
251
252 $form_name = isset( $_POST['form_name'] ) ? sanitize_text_field( $_POST['form_name'] ) : '';
253
254 if ( empty( $form_name ) ) {
255 wp_send_json_error( __( 'Please provide a form name', 'weforms' ) );
256 }
257
258 $form_id = weforms()->form->create( $form_name );
259
260 if ( is_wp_error( $form_id ) ) {
261 wp_send_json_error( $form_id->get_error_message() );
262 }
263
264 wp_send_json_success( array(
265 'form_id' => $form_id,
266 'form_name' => $form_name
267 ) );
268 }
269
270 /**
271 * Delete a form
272 *
273 * @return void
274 */
275 public function delete_form() {
276 check_ajax_referer( 'weforms' );
277
278 $this->check_admin();
279
280 $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
281
282 if ( ! $form_id ) {
283 wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
284 }
285
286 weforms()->form->delete( $form_id );
287
288 wp_send_json_success();
289 }
290
291 public function delete_form_bulk() {
292 check_ajax_referer( 'weforms' );
293
294 $this->check_admin();
295
296 $form_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : array();
297
298 if ( ! $form_ids ) {
299 wp_send_json_error( __( 'No form ids provided!', 'weforms' ) );
300 }
301
302 foreach ( $form_ids as $form_id ) {
303 weforms()->form->delete( $form_id );
304 }
305
306 wp_send_json_success();
307 }
308
309 /**
310 * Duplicate a form
311 *
312 * @return voiud
313 */
314 public function duplicate_form() {
315 check_ajax_referer( 'weforms' );
316
317 $this->check_admin();
318
319 $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
320
321 $form = weforms()->form->duplicate( $form_id );
322 $form->settings = $form->get_settings();
323
324 wp_send_json_success( $form );
325 }
326
327 /**
328 * Create form from a template
329 *
330 * @return void
331 */
332 public function create_form_from_template() {
333 check_ajax_referer( 'weforms' );
334
335 $template = isset( $_REQUEST['template'] ) ? sanitize_text_field( $_REQUEST['template'] ) : '';
336
337 $form_id = weforms()->templates->create( $template );
338
339 if ( is_wp_error( $form_id ) ) {
340 wp_send_json_error( __( 'Could not create the form', 'weforms' ) );
341 }
342
343 wp_send_json_success( array(
344 'id' => $form_id
345 ) );
346 }
347
348 /**
349 * Save the weForms settings
350 *
351 * @return void
352 */
353 public function save_settings() {
354 check_ajax_referer( 'weforms' );
355
356 $this->check_admin();
357
358 $requires_wpuf_update = false;
359 $wpuf_update_array = array();
360 $settings = (array) json_decode( wp_unslash( $_POST['settings'] ) );
361
362 update_option( 'weforms_settings', $settings );
363
364 // wpuf settings sync
365 if ( isset( $settings['gmap_api'] ) ) {
366 $requires_wpuf_update = true;
367 $wpuf_update_array['gmap_api_key'] = $settings['gmap_api'];
368 }
369
370 if ( isset( $settings['recaptcha'] ) ) {
371 $requires_wpuf_update = true;
372 $wpuf_update_array['recaptcha_public'] = $settings['recaptcha']->key;
373 $wpuf_update_array['recaptcha_private'] = $settings['recaptcha']->secret;
374 }
375
376 if ( isset( $settings['no_conflict'] ) ) {
377 $requires_wpuf_update = true;
378 $wpuf_update_array['no_conflict'] = $settings['no_conflict'];
379 }
380
381 if ( $requires_wpuf_update ) {
382 $wpuf_settings = get_option( 'wpuf_general', array() );
383
384 $wpuf_settings = array_merge( $wpuf_settings, $wpuf_update_array );
385 update_option( 'wpuf_general', $wpuf_settings );
386 }
387
388 do_action( 'weforms_save_settings', $settings );
389
390 $settings = apply_filters( 'weforms_after_save_settings', $settings );
391
392 wp_send_json_success( $settings );
393 }
394
395 /**
396 * Get the weForms Settings
397 *
398 * @return void
399 */
400 public function get_settings() {
401 check_ajax_referer( 'weforms' );
402
403 $this->check_admin();
404
405 $settings = weforms_get_settings();
406
407 // checking to prevent js error, will be removed in future
408 if ( ! isset( $settings['credit'] ) ) {
409 $settings['credit'] = false;
410 }
411
412 if ( ! isset( $settings['permission'] ) ) {
413 $settings['permission'] = 'manage_options';
414 }
415
416 wp_send_json_success( $settings );
417 }
418
419 /**
420 * Get all entries
421 *
422 * @return void
423 */
424 public function get_entries() {
425 check_ajax_referer( 'weforms' );
426
427 $this->check_admin();
428
429 $form_id = isset( $_REQUEST['id'] ) ? intval( $_REQUEST['id'] ) : 0;
430 $current_page = isset( $_REQUEST['page'] ) ? intval( $_REQUEST['page'] ) : 1;
431 $status = isset( $_REQUEST['status'] ) ? $_REQUEST['status'] : 'publish';
432 $per_page = 20;
433 $offset = ( $current_page - 1 ) * $per_page;
434
435 if ( ! $form_id ) {
436 wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
437 }
438
439 $entries = weforms_get_form_entries(
440 $form_id, array(
441 'number' => $per_page,
442 'offset' => $offset,
443 'status' => $status,
444 )
445 );
446
447 $columns = weforms_get_entry_columns( $form_id );
448 $total_entries = weforms_count_form_entries( $form_id, $status );
449
450 array_map(
451 function( $entry ) use ( $columns ) {
452 $entry_id = $entry->id;
453 $entry->fields = array();
454
455 foreach ( $columns as $meta_key => $label ) {
456 $value = weforms_get_entry_meta( $entry_id, $meta_key, true );
457 $entry->fields[ $meta_key ] = str_replace( WeForms::$field_separator, ' ', $value );
458 }
459 }, $entries
460 );
461
462 $entries = apply_filters( 'weforms_get_entries', $entries, $form_id );
463
464 $response = array(
465 'columns' => $columns,
466 'entries' => $entries,
467 'form_title' => get_post_field( 'post_title', $form_id ),
468 'pagination' => array(
469 'total' => $total_entries,
470 'per_page' => $per_page,
471 'pages' => ceil( $total_entries / $per_page ),
472 'current' => $current_page
473 ),
474 'meta' => array(
475 'total' => weforms_count_form_entries( $form_id ),
476 'totalTrash' => weforms_count_form_entries( $form_id, 'trash' ),
477 ),
478 );
479
480 wp_send_json_success( $response );
481 }
482
483
484
485 /**
486 * Get an entry details
487 *
488 * @return void
489 */
490 public function get_entry_detail() {
491 check_ajax_referer( 'weforms' );
492
493 $this->check_admin();
494
495 $form_id = isset( $_REQUEST['form_id'] ) ? intval( $_REQUEST['form_id'] ) : 0;
496 $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
497
498 $form = weforms()->form->get( $form_id );
499 $form_settings = $form->get_settings();
500 $entry = $form->entries()->get( $entry_id );
501 $fields = $entry->get_fields();
502 $metadata = $entry->get_metadata();
503 $payment = $entry->get_payment_data();
504
505 if ( isset( $payment->payment_data ) && is_serialized( $payment->payment_data ) ) {
506 $payment->payment_data = unserialize( $payment->payment_data );
507 }
508
509 if ( false === $fields ) {
510 wp_send_json_error( __( 'No form fields found!', 'weforms' ) );
511 }
512
513 if ( sizeof( $fields ) < 1 ) {
514 $fields[] = array(
515 'label' => __( 'No form fields found!', 'weforms' )
516 );
517 }
518
519 $has_empty = false;
520 $answers = array();
521 $respondentPoints = isset($form_settings['total_points']) ? floatval( $form_settings['total_points'] ) : 0 ;
522
523 foreach ( $fields as $key => $field ) {
524 if ( $form_settings['quiz_form'] == 'yes' ) {
525 $selectedAnswers = isset($field['selected_answers']) ? $field['selected_answers'] : '';
526 $givenAnswer = isset($field['value']) ? $field['value'] : '';
527 $options = isset($field['options']) ? $field['options'] : '';
528 $template = $field['template'];
529 $fieldPoints = isset($field['points']) ? floatval( $field['points'] ) : 0;
530
531 if ( $template == 'radio_field' || $template == 'dropdown_field' ) {
532 $answers[$field['name']] = true;
533
534 if ( empty($givenAnswer) ) {
535 $answers[$field['name']] = false;
536 $respondentPoints -= $fieldPoints;
537 }else {
538 foreach ($options as $key => $value) {
539 if ( $givenAnswer == $value ) {
540 if ( $key != $selectedAnswers ) {
541 $answers[$field['name']] = false;
542 $respondentPoints -= $fieldPoints;
543 }
544 }
545 }
546 }
547 } elseif ( $template == 'checkbox_field' || $template == 'multiple_select' ) {
548 $answers[$field['name']] = true;
549 $userAnswer = [];
550
551 foreach ($options as $key => $value) {
552 foreach ($givenAnswer as $answer) {
553 if ($value == $answer) {
554 $userAnswer[] = $key;
555 }
556 }
557 }
558
559 $userAnswer = implode('|', $userAnswer);
560 $rightAnswers = implode('|', $selectedAnswers);
561
562 if ( $userAnswer != $rightAnswers || empty($userAnswer) ) {
563 $answers[$field['name']] = false;
564 $respondentPoints -= $fieldPoints;
565 }
566 }
567 } elseif ( empty( $field['value'] ) ) {
568 $has_empty = true;
569 break;
570 }
571
572 }
573
574 $response = array(
575 'form_fields' => $fields,
576 'form_settings' => $form_settings,
577 'meta_data' => $metadata,
578 'payment_data' => $payment,
579 'has_empty' => $has_empty,
580 'respondent_points' => $respondentPoints,
581 'answers' => $answers,
582 );
583
584 wp_send_json_success( $response );
585 }
586
587 /**
588 * Trash an entry
589 *
590 * @return void
591 */
592 public function trash_entry() {
593 check_ajax_referer( 'weforms' );
594
595 $this->check_admin();
596
597 $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
598
599 weforms_change_entry_status( $entry_id, 'trash' );
600 wp_send_json_success();
601 }
602
603 /**
604 * Trash an entry
605 *
606 * @return void
607 */
608 public function delete_entry() {
609 check_ajax_referer( 'weforms' );
610
611 $this->check_admin();
612
613 $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
614
615 weforms_delete_entry( $entry_id );
616
617 wp_send_json_success();
618 }
619
620 /**
621 * Restore Entry
622 *
623 * @return void
624 */
625 public function restore_entry() {
626 check_ajax_referer( 'weforms' );
627
628 $this->check_admin();
629
630 $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
631
632 weforms_change_entry_status( $entry_id, 'publish' );
633 wp_send_json_success();
634 }
635
636 /**
637 * Bulk trash entries
638 *
639 * @return void
640 */
641 public function bulk_delete_entry() {
642 check_ajax_referer( 'weforms' );
643
644 $this->check_admin();
645
646 $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : array();
647 $permanent = isset( $_POST['permanent'] ) && ( $_POST['permanent'] ) ? true : false;
648
649 if ( ! $entry_ids ) {
650 wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
651 }
652
653 foreach ( $entry_ids as $entry_id ) {
654 if ( $permanent ) {
655 weforms_delete_entry( $entry_id );
656 } else {
657 weforms_change_entry_status( $entry_id, 'trash' );
658 }
659 }
660
661 wp_send_json_success();
662 }
663
664 /**
665 * Bulk trash entries
666 *
667 * @return void
668 */
669 public function bulk_restore_entry() {
670 check_ajax_referer( 'weforms' );
671
672 $this->check_admin();
673
674 $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : array();
675
676 if ( ! $entry_ids ) {
677 wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
678 }
679
680 foreach ( $entry_ids as $entry_id ) {
681 weforms_change_entry_status( $entry_id, 'publish' );
682 }
683
684 wp_send_json_success();
685 }
686
687 /**
688 * Handle the frontend submission
689 *
690 * @return void
691 */
692 public function handle_frontend_submission() {
693 check_ajax_referer( 'wpuf_form_add' );
694
695 $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
696 $page_id = isset( $_POST['page_id'] ) ? intval( $_POST['page_id'] ) : 0;
697
698 $form = weforms()->form->get( $form_id );
699 $form_settings = $form->get_settings();
700 $form_fields = $form->get_fields();
701 $entry_fields = $form->prepare_entries();
702 $form_entries = weforms_get_form_entries( $form_id, array( 'number' => '', 'offset' => '' ) );
703
704 if ( $form_fields && count( $form_entries ) && count( $entry_fields ) ) {
705
706 foreach ( $entry_fields as $field_key => $field_value ) {
707 $duplicate_check = false;
708 $field_label = 'This';
709
710 foreach ( $form_fields as $form_field ) {
711 if ( in_array( $form_field['template'], array( 'text_field', 'website_url', 'numeric_text_field', 'email_address' ) ) && $form_field['name'] == $field_key && isset( $form_field['duplicate'] ) && 'no' == $form_field['duplicate'] ) {
712 $duplicate_check = true;
713 $field_label = $form_field['label'];
714 }
715 }
716
717 if ( $duplicate_check ) {
718
719 foreach ( $form_entries as $entry ) {
720 $existing = weforms_get_entry_meta( $entry->id, $field_key, true );
721
722 if ( $existing && $field_value == $existing ) {
723 wp_send_json( array(
724 'success' => false,
725 'error' => sprintf( __( '"%s" field requires a unique entry and "%s" has already been used.', 'weforms' ), $field_label, $field_value )
726 ) );
727 }
728 }
729 }
730 }
731 }
732
733 if ( ! $form_fields ) {
734 wp_send_json( array(
735 'success' => false,
736 'error' => __( 'No form field was found.', 'weforms' ),
737 ) );
738 }
739
740 if ( $form->has_field( 'recaptcha' ) ) {
741 $this->validate_reCaptcha();
742 }
743
744 // vaidate submission
745 $this->validate_submission( $entry_fields, $form, $form_settings, $form_fields );
746
747 $entry_fields = apply_filters( 'weforms_before_entry_submission', $entry_fields, $form, $form_settings, $form_fields );
748
749 $entry_id = weforms_insert_entry( array(
750 'form_id' => $form_id
751 ), $entry_fields );
752
753 if ( is_wp_error( $entry_id ) ) {
754 wp_send_json( array(
755 'success' => false,
756 'error' => $entry_id->get_error_message(),
757 ) );
758 }
759
760 // redirect URL
761 $show_message = false;
762 $redirect_to = false;
763
764 if ( $form_settings['redirect_to'] == 'page' ) {
765 $redirect_to = get_permalink( $form_settings['page_id'] );
766 } elseif ( $form_settings['redirect_to'] == 'url' ) {
767 $redirect_to = $form_settings['url'];
768 } elseif ( $form_settings['redirect_to'] == 'same' ) {
769 $show_message = true;
770 } else {
771 $redirect_to = get_permalink( $post_id );
772 }
773
774 // Fire a hook for integration
775 do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
776
777 $field_search = $field_replace = array();
778
779 foreach ( $form_fields as $r_field ) {
780 $field_search[] = '{'.$r_field['name'].'}';
781 if ( $r_field['template'] == 'name_field' ) {
782 $field_replace[] = implode( ' ' , explode( '|', $entry_fields[$r_field['name']] ));
783 } else {
784 $field_replace[] = isset( $entry_fields[$r_field['name']] ) ? $entry_fields[$r_field['name']] : '';
785 }
786 }
787 $message = str_replace( $field_search, $field_replace, $form_settings['message'] );
788
789 // send the response
790 $response = apply_filters( 'weforms_entry_submission_response', array(
791 'success' => true,
792 'redirect_to' => $redirect_to,
793 'show_message' => $show_message,
794 'message' => $message,
795 'data' => $_POST,
796 'form_id' => $form_id,
797 'entry_id' => $entry_id,
798 ) );
799
800 $notification = new WeForms_Notification( array(
801 'form_id' => $form_id,
802 'page_id' => $page_id,
803 'entry_id' => $entry_id
804 ) );
805
806 $notification->send_notifications();
807
808 weforms_clear_buffer();
809 wp_send_json( $response );
810 }
811
812 /**
813 * reCaptcha Validation
814 *
815 * @return void
816 */
817 function validate_reCaptcha() {
818
819 if ( class_exists( 'WPUF_ReCaptcha' ) ) {
820 $recaptcha_class = 'WPUF_ReCaptcha';
821 } else {
822 if ( ! function_exists( 'recaptcha_get_html' ) ) {
823 require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib.php';
824 }
825
826 require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib_noCaptcha.php';
827 $recaptcha_class = 'Weforms_ReCaptcha';
828 }
829
830 $invisible = isset( $_POST['g-recaptcha-response'] ) ? false : true;
831
832 $recaptcha_settings = weforms_get_settings( 'recaptcha' );
833 $secret = isset( $recaptcha_settings->secret ) ? $recaptcha_settings->secret : '';
834
835 if ( ! $invisible ) {
836
837 $response = null;
838 $reCaptcha = new $recaptcha_class( $secret );
839
840 $resp = $reCaptcha->verifyResponse(
841 $_SERVER['REMOTE_ADDR'],
842 $_POST['g-recaptcha-response']
843 );
844
845 if ( ! $resp->success ) {
846 wp_send_json( array(
847 'success' => false,
848 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
849 ) );
850 }
851 } else {
852
853 $recap_challenge = isset( $_POST['recaptcha_challenge_field'] ) ? $_POST['recaptcha_challenge_field'] : '';
854 $recap_response = isset( $_POST['recaptcha_response_field'] ) ? $_POST['recaptcha_response_field'] : '';
855
856 $resp = recaptcha_check_answer( $secret, $_SERVER['REMOTE_ADDR'], $recap_challenge, $recap_response );
857
858 if ( ! $resp->is_valid ) {
859
860 ob_clean();
861
862 wp_send_json( array(
863 'success' => false,
864 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
865 ) );
866 }
867 }
868
869 }
870
871 /**
872 * Validate submission
873 *
874 * @param array $entry_fields
875 * @param object $form
876 * @param array $form_settings
877 * @param array $form_fields
878 *
879 * @return bool|json
880 */
881 function validate_submission( $entry_fields, $form, $form_settings, $form_fields ) {
882
883 foreach ( $form_fields as $key => $field ) {
884
885 //skip custom html field as it is not saved
886 if ( 'custom_html' == $field['name'] )
887 continue;
888
889 //skip recaptcha field as it is not saved
890 if ( 'recaptcha' == $field['name'] )
891 continue;
892
893 $value = $entry_fields[ $field['name'] ];
894
895 if ( 'single_product' === $field['template'] ) {
896
897 if ( ! $value ) {
898 $value = array();
899 }
900
901 $value['price'] = isset( $value['price'] ) ? floatval( $value['price'] ) : 0;
902 $value['quantity'] = isset( $value['quantity'] ) ? floatval( $value['quantity'] ) : 0;
903 $quantity = isset( $field['quantity'] ) ? $field['quantity'] : array();
904 $price = isset( $field['price'] ) ? $field['price'] : array();
905
906 if ( isset( $price['is_flexible'] ) && $price['is_flexible'] ) {
907
908 $min = isset( $price['min'] ) ? floatval( $price['min'] ) : 0;
909 $max = isset( $price['max'] ) ? floatval( $price['max'] ) : 0;
910
911 if ( $value['price'] < $min ) {
912
913 wp_send_json( array(
914 'success' => false,
915 'error' => __( sprintf(
916 '%s price must be equal or greater than %s',
917 $field['weforms'],
918 $min),
919 'weforms' ),
920 ) );
921 }
922
923 if ( $max && $value['price'] > $max ) {
924
925 wp_send_json( array(
926 'success' => false,
927 'error' => __( sprintf(
928 '%s price must be equal or less than %s',
929 $field['weforms'],
930 $max),
931 'weforms' ),
932 ) );
933 }
934 }
935
936 if ( isset( $quantity['status'] ) && $quantity['status'] ) {
937
938 $min = isset( $quantity['min'] ) ? floatval( $quantity['min'] ) : 0;
939 $max = isset( $quantity['max'] ) ? floatval( $quantity['max'] ) : 0;
940
941 if ( $value['quantity'] < $min ) {
942
943 wp_send_json( array(
944 'success' => false,
945 'error' => __( sprintf(
946 '%s quantity must be equal or greater than %s',
947 $field['weforms'],
948 $min),
949 'weforms' ),
950 ) );
951 }
952
953 if ( $max && $value['quantity'] > $max ) {
954
955 wp_send_json( array(
956 'success' => false,
957 'error' => __( sprintf(
958 '%s quantity must be equal or less than %s',
959 $field['weforms'],
960 $max),
961 'weforms' ),
962 ) );
963 }
964 }
965 }
966 }
967 }
968
969 public static function prepare_meta_fields( $meta_vars ) {
970 // loop through custom fields
971 // skip files, put in a key => value paired array for later executation
972 // process repeatable fields separately
973 // if the input is array type, implode with separator in a field
974 $files = array();
975 $meta_key_value = array();
976 $multi_repeated = array(); // multi repeated fields will in sotre duplicated meta key
977
978 foreach ( $meta_vars as $key => $value ) {
979
980 switch ( $value['template'] ) {
981
982 // put files in a separate array, we'll process it later
983 case 'file_upload':
984 case 'image_upload':
985 $files[] = array(
986 'name' => $value['name'],
987 'value' => isset( $_POST['wpuf_files'][ $value['name'] ] ) ? $_POST['wpuf_files'][ $value['name'] ] : array(),
988 'count' => $value['count']
989 );
990 break;
991
992 case 'repeat_field':
993 // if it is a multi column repeat field
994 if ( isset( $value['multiple'] ) && $value['multiple'] == 'true' ) {
995
996 // if there's any items in the array, process it
997 if ( $_POST[ $value['name'] ] ) {
998
999 $ref_arr = array();
1000 $cols = count( $value['columns'] );
1001 $first = array_shift( array_values( $_POST[ $value['name'] ] ) ); // first element
1002 $rows = count( $first );
1003
1004 // loop through columns
1005 for ( $i = 0; $i < $rows; $i++ ) {
1006
1007 // loop through the rows and store in a temp array
1008 $temp = array();
1009 for ( $j = 0; $j < $cols; $j++ ) {
1010
1011 $temp[] = $_POST[ $value['name'] ][ $j ][ $i ];
1012 }
1013
1014 // store all fields in a row with WeForms::$field_separator separated
1015 $ref_arr[] = implode( WeForms::$field_separator, $temp );
1016 }
1017
1018 // now, if we found anything in $ref_arr, store to $multi_repeated
1019 if ( $ref_arr ) {
1020 $multi_repeated[ $value['name'] ] = array_slice( $ref_arr, 0, $rows );
1021 }
1022 }
1023 } else {
1024 $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, $_POST[ $value['name'] ] );
1025 }
1026
1027 break;
1028
1029 case 'address_field':
1030 if ( isset( $_POST[ $value['name'] ] ) && is_array( $_POST[ $value['name'] ] ) ) {
1031 foreach ( $_POST[ $value['name'] ] as $address_field => $field_value ) {
1032 $meta_key_value[ $value['name'] ][ $address_field ] = sanitize_text_field( $field_value );
1033 }
1034 }
1035
1036 break;
1037
1038 case 'text_field':
1039 case 'email_address':
1040 case 'numeric_text_field':
1041 case 'date_field':
1042 $meta_key_value[ $value['name'] ] = sanitize_text_field( trim( $_POST[ $value['name'] ] ) );
1043
1044 break;
1045
1046 case 'textarea_field':
1047 $meta_key_value[ $value['name'] ] = wp_kses_post( $_POST[ $value['name'] ] );
1048
1049 break;
1050
1051 case 'dropdown_field':
1052 case 'radio_field':
1053 $val = $_POST[ $value['name'] ];
1054 $meta_key_value[ $value['name'] ] = isset( $value['options'][ $val ] ) ? $value['options'][ $val ] : '';
1055 break;
1056
1057 case 'multiple_select':
1058 case 'checkbox_field':
1059 $val = ( is_array( $_POST[ $value['name'] ] ) && $_POST[ $value['name'] ] ) ? $_POST[ $value['name'] ] : array();
1060 $meta_key_value[ $value['name'] ] = $val;
1061
1062 if ( $val ) {
1063 $new_val = array();
1064
1065 foreach ( $val as $option_key ) {
1066 $new_val[] = isset( $value['options'][ $option_key ] ) ? $value['options'][ $option_key ] : '';
1067 }
1068
1069 $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, $new_val );
1070 }
1071 break;
1072
1073 default:
1074 // if it's an array, implode with this->separator
1075 if ( is_array( $_POST[ $value['name'] ] ) ) {
1076
1077 $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, $_POST[ $value['name'] ] );
1078
1079 } else {
1080 $meta_key_value[ $value['name'] ] = trim( $_POST[ $value['name'] ] );
1081 }
1082
1083 break;
1084 }
1085 } //end foreach
1086
1087 return array( $meta_key_value, $multi_repeated, $files );
1088 }
1089
1090 /**
1091 * Import a form from a JSON file
1092 *
1093 * @return void
1094 */
1095 public function import_form() {
1096 check_ajax_referer( 'weforms' );
1097
1098 $this->check_admin();
1099
1100 $the_file = isset( $_FILES['importFile'] ) ? $_FILES['importFile'] : false;
1101
1102 if ( ! $the_file ) {
1103 wp_send_json_error( __( 'No file found to import.', 'weforms' ) );
1104 }
1105
1106 $file_ext = pathinfo( $the_file['name'], PATHINFO_EXTENSION );
1107
1108 if ( ! class_exists( 'WeForms_Admin_Tools' ) ) {
1109 require_once dirname( __FILE__ ) . '/admin/class-admin-tools.php';
1110 }
1111
1112 if ( ( $file_ext == 'json' ) && ( $the_file['size'] < 500000 ) ) {
1113
1114 $status = WeForms_Admin_Tools::import_json_file( $the_file['tmp_name'] );
1115
1116 if ( $status ) {
1117 wp_send_json_success( __( 'The forms have been imported successfully!', 'weforms' ) );
1118 } else {
1119 wp_send_json_error( __( 'Something went wrong importing the file.', 'weforms' ) );
1120 }
1121 } else {
1122 wp_send_json_error( __( 'Invalid file or file size too big.', 'weforms' ) );
1123 }
1124 }
1125
1126 /**
1127 * Read Log file
1128 *
1129 * @return json
1130 **/
1131 function get_logs() {
1132
1133 check_ajax_referer( 'weforms' );
1134
1135 $this->check_admin();
1136
1137 $file = weforms_log_file_path();
1138
1139 if ( ! file_exists( $file ) ) {
1140 return;
1141 }
1142
1143 $data = file_get_contents( $file );
1144 $data = explode( "\n", $data );
1145 $data = array_reverse( $data );
1146 $data = array_filter( $data );
1147
1148 if ( empty( $data ) ) {
1149 return;
1150 }
1151
1152 $logs = array();
1153
1154 foreach ( $data as $key => $row ) {
1155
1156 preg_match( '/\[(?<time>.+?)\]\[(?<type>.+?)\](?<message>.+)/im', $row, $log );
1157
1158 if ( empty( $log['message'] ) ) {
1159 $log = array();
1160 $log['message'] = ! empty( $log['message'] ) ? $log['message'] : $row;
1161 }
1162
1163 if ( ! empty( $log['time'] ) ) {
1164 $human_time = human_time_diff( strtotime( $log['time'] ) , current_time( 'timestamp' ) );
1165 $log['time'] = $human_time ? $human_time . ' ' . __( 'ago', 'weforms' ) : $log['time'];
1166 }
1167
1168 $logs[] = $log;
1169 }
1170
1171 wp_send_json_success( $logs );
1172 }
1173
1174 /**
1175 * Read Log file
1176 *
1177 * @return json
1178 **/
1179 function delete_logs() {
1180
1181 check_ajax_referer( 'weforms' );
1182
1183 $this->check_admin();
1184
1185 $file = weforms_log_file_path();
1186
1187 if ( ! file_exists( $file ) ) {
1188 return;
1189 }
1190
1191 @unlink( $file );
1192
1193 wp_send_json_success();
1194 }
1195
1196 }
1197