PluginProbe
weForms – Easy Drag & Drop Contact Form Builder For WordPress / 1.4.3
weForms – Easy Drag & Drop Contact Form Builder For WordPress v1.4.3
1.6.7 1.6.8 1.6.9 1.6.12 1.6.13 1.6.14 1.6.15 1.6.16 1.6.17 1.6.18 1.6.19 1.6.2 1.6.20 1.6.21 1.6.22 1.6.23 1.6.24 1.6.25 1.6.26 1.6.27 1.6.28 1.6.3 1.6.4 1.6.5 1.6.6 All 74 releases
← All changes | includes/class-ajax.php +1184 -1238 1.6.161.4.3 View file →
@@ -1,1238 +1,1184 @@
1 -<?php
2 -
3 -/**
4 - * The ajax handler class
5 - */
6 -class WeForms_Ajax {
7 -
8 - public function __construct() {
9 -
10 - // backend requests
11 - add_action( 'wp_ajax_weforms_form_list', [ $this, 'get_contact_forms' ] );
12 - add_action( 'wp_ajax_weforms_get_users', [ $this, 'get_all_users' ] );
13 - add_action( 'wp_ajax_weforms_form_names', [ $this, 'get_contact_form_names' ] );
14 - add_action( 'wp_ajax_weforms_form_create', [ $this, 'create_form' ] );
15 - add_action( 'wp_ajax_weforms_form_delete', [ $this, 'delete_form' ] );
16 - add_action( 'wp_ajax_weforms_form_delete_bulk', [ $this, 'delete_form_bulk' ] );
17 - add_action( 'wp_ajax_weforms_form_duplicate', [ $this, 'duplicate_form' ] );
18 -
19 - // read logs
20 - add_action( 'wp_ajax_weforms_read_logs', [ $this, 'get_logs' ] );
21 - add_action( 'wp_ajax_weforms_delete_logs', [ $this, 'delete_logs' ] );
22 -
23 - // create from a template
24 - add_filter( 'wp_ajax_weforms_contact_form_template', [ $this, 'create_form_from_template' ] );
25 -
26 - // form settings
27 - add_action( 'wp_ajax_weforms_save_settings', [ $this, 'save_settings' ] );
28 - add_action( 'wp_ajax_weforms_get_settings', [ $this, 'get_settings' ] );
29 -
30 - // import
31 - add_action( 'wp_ajax_weforms_import_form', [ $this, 'import_form' ] );
32 -
33 - // form editing
34 - add_action( 'wp_ajax_weforms_get_form', [ $this, 'get_form' ] );
35 - add_action( 'wp_ajax_wpuf_form_builder_save_form', [ $this, 'save_form' ] );
36 -
37 - // entries
38 - add_action( 'wp_ajax_weforms_form_entries', [ $this, 'get_entries' ] );
39 -
40 - add_action( 'wp_ajax_weforms_form_entry_details', [ $this, 'get_entry_detail' ] );
41 - add_action( 'wp_ajax_weforms_form_entry_trash', [ $this, 'trash_entry' ] );
42 - add_action( 'wp_ajax_weforms_form_entry_delete', [ $this, 'delete_entry' ] );
43 - add_action( 'wp_ajax_weforms_form_entry_restore', [ $this, 'restore_entry' ] );
44 -
45 - add_action( 'wp_ajax_weforms_form_entry_trash_bulk', [ $this, 'bulk_delete_entry' ] );
46 - add_action( 'wp_ajax_weforms_form_entry_restore_bulk', [ $this, 'bulk_restore_entry' ] );
47 -
48 - // frontend requests
49 - add_action( 'wp_ajax_weforms_frontend_submit', [ $this, 'handle_frontend_submission' ] );
50 - add_action( 'wp_ajax_nopriv_weforms_frontend_submit', [ $this, 'handle_frontend_submission' ] );
51 - }
52 -
53 - /**
54 - * Administrator validation
55 - *
56 - * @return void
57 - */
58 - public function check_admin() {
59 - if ( !current_user_can( weforms_form_access_capability() ) ) {
60 - wp_send_json_error( __( 'You do not have sufficient permission.', 'weforms' ) );
61 - }
62 - }
63 -
64 - /**
65 - * Get a form to edit
66 - *
67 - * @return void
68 - */
69 - public function get_form() {
70 - $this->check_admin();
71 -
72 - $form_id = isset( $_REQUEST['form_id'] ) ? absint( $_REQUEST['form_id'] ) : 0;
73 -
74 - $form = weforms()->form->get( $form_id );
75 -
76 - $data = [
77 - 'post' => $form->data,
78 - 'form_fields' => $form->get_fields(),
79 - 'settings' => $form->get_settings(),
80 - 'notifications' => $form->get_notifications(),
81 - 'integrations' => $form->get_integrations(),
82 - ];
83 -
84 - wp_send_json_success( $data );
85 - }
86 -
87 - /**
88 - * Save the form
89 - *
90 - * @return void
91 - */
92 - public function save_form() {
93 - $post_data = wp_unslash( $_POST );
94 - if ( isset( $post_data['form_data'] ) ) {
95 - parse_str( sanitize_text_field( wp_unslash( $post_data['form_data'] ) ), $form_data );
96 - }
97 -
98 - if ( !wp_verify_nonce( $form_data['wpuf_form_builder_nonce'], 'wpuf_form_builder_save_form' ) ) {
99 - wp_send_json_error( __( 'Unauthorized operation', 'weforms' ) );
100 - }
101 -
102 - if ( empty( $form_data['wpuf_form_id'] ) ) {
103 - wp_send_json_error( __( 'Invalid form id', 'weforms' ) );
104 - }
105 -
106 - $form_fields = isset( $post_data['form_fields'] ) ? $post_data['form_fields'] : '';
107 - $notifications = isset( $post_data['notifications'] ) ? $post_data['notifications']: '';
108 - $settings = array();
109 - $integrations = array();
110 -
111 - if ( isset( $post_data['settings'] ) ) {
112 - $settings = (array) json_decode( $post_data['settings'] );
113 - $settings['message'] = sanitize_text_field( $settings['message'] );
114 - error_log(print_r($settings, true));
115 - } else {
116 - $settings = isset( $form_data['wpuf_settings'] ) ? $form_data['wpuf_settings'] : [];
117 - }
118 -
119 - if ( isset( $post_data['integrations'] ) ) {
120 - $integrations = (array) json_decode( $post_data['integrations'] );
121 - }
122 -
123 - $form_fields = json_decode( $form_fields, true );
124 - $notifications = json_decode( $notifications, true );
125 - $data = [
126 - 'form_id' => absint( $form_data['wpuf_form_id'] ),
127 - 'post_title' => $form_data['post_title'],
128 - 'form_fields' => $form_fields,
129 - 'form_settings' => $settings,
130 - 'form_settings_key' => isset( $form_data['form_settings_key'] ) ? $form_data['form_settings_key'] : '',
131 - 'notifications' => $notifications,
132 - 'integrations' => $integrations,
133 - ];
134 -
135 - $form_fields = weforms()->form->save( $data );
136 -
137 - // Update Old Entry meta_key if changed
138 - $form_id = $form_data['wpuf_form_id'];
139 - $form = weforms()->form->get( $form_id );
140 -
141 - $form->maybe_update_entries( $form_fields );
142 -
143 - do_action( 'weforms_update_form', $form_data['wpuf_form_id'], $form_fields, $settings );
144 -
145 - wp_send_json_success( [ 'form_fields' => $form_fields ] );
146 - }
147 -
148 - /**
149 - * Get all contact forms
150 - *
151 - * @return void
152 - */
153 - public function get_contact_forms() {
154 - check_ajax_referer( 'weforms' );
155 -
156 - $this->check_admin();
157 -
158 - $args = [
159 - 'posts_per_page' => isset( $_POST['posts_per_page'] ) ? intval( $_POST['posts_per_page'] ) : 10,
160 - 'paged' => isset( $_POST['page'] ) ? absint( $_POST['page'] ) : 1,
161 - 'order' => 'DESC',
162 - 'orderby' => 'post_date',
163 - ];
164 -
165 - $args = apply_filters( 'weforms_ajax_get_contact_forms_args', $args );
166 -
167 - $contact_forms = weforms()->form->get_forms( $args );
168 -
169 - array_map(
170 - function ( $form ) {
171 - $form->entries = $form->num_form_entries();
172 - $form->settings = $form->get_settings();
173 - $form->views = $form->num_form_views();
174 - $form->payments = $form->num_form_payments();
175 - $form->author = $form->get_form_author_details();
176 - }, $contact_forms['forms']
177 - );
178 -
179 - $contact_forms = $this->filter_contact_forms( $contact_forms );
180 - $contact_forms = apply_filters( 'weforms_ajax_get_contact_forms', $contact_forms );
181 -
182 - wp_send_json_success( $contact_forms );
183 - }
184 -
185 - /**
186 - * Get all users
187 - *
188 - * @return array
189 - */
190 - public function get_all_users() {
191 - check_ajax_referer( 'weforms' );
192 -
193 - $this->check_admin();
194 -
195 - $users_meta = [];
196 - $users = get_users( [ 'fields' => [ 'ID' ] ] );
197 -
198 - foreach ( $users as $user ) {
199 - $users_meta[] = [
200 - 'id' => $user->ID,
201 - 'data' => get_user_meta( $user->ID ),
202 - ];
203 - }
204 -
205 - wp_send_json_success( $users_meta );
206 - }
207 -
208 - /**
209 - * Filter
210 - *
211 - * @return void
212 - */
213 - public function filter_contact_forms( &$contact_forms ) {
214 - if ( isset( $_REQUEST['filter'] ) && $_REQUEST['filter'] == 'entries' ) {
215 - foreach ( $contact_forms['forms'] as $key => &$form ) {
216 - if ( isset( $form->entries ) && !$form->entries ) {
217 - unset( $contact_forms['forms'][ $key ] );
218 - }
219 - }
220 -
221 - $contact_forms['meta']['total'] = count( $contact_forms['forms'] );
222 - }
223 -
224 - return $contact_forms;
225 - }
226 -
227 - /**
228 - * Get the names of contact forms for generating dropdown
229 - *
230 - * @return void
231 - */
232 - public function get_contact_form_names() {
233 - check_ajax_referer( 'weforms' );
234 -
235 - $this->check_admin();
236 -
237 - $contact_forms = weforms()->form->all();
238 - $response = [];
239 -
240 - foreach ( $contact_forms['forms'] as $form ) {
241 - $response[] = [
242 - 'id' => $form->get_id(),
243 - 'title' => $form->get_name() . ' (#' . $form->get_id() . ')',
244 - ];
245 - }
246 -
247 - wp_send_json_success( $response );
248 - }
249 -
250 - /**
251 - * Create a form
252 - *
253 - * @return void
254 - */
255 - public function create_form() {
256 - check_ajax_referer( 'weforms' );
257 -
258 - $this->check_admin();
259 -
260 - $form_name = isset( $_POST['form_name'] ) ? sanitize_text_field( wp_unslash( $_POST['form_name'] ) ) : '';
261 -
262 - if ( empty( $form_name ) ) {
263 - wp_send_json_error( __( 'Please provide a form name', 'weforms' ) );
264 - }
265 -
266 - $form_id = weforms()->form->create( $form_name );
267 -
268 - if ( is_wp_error( $form_id ) ) {
269 - wp_send_json_error( $form_id->get_error_message() );
270 - }
271 -
272 - wp_send_json_success( [
273 - 'form_id' => $form_id,
274 - 'form_name' => $form_name,
275 - ] );
276 - }
277 -
278 - /**
279 - * Delete a form
280 - *
281 - * @return void
282 - */
283 - public function delete_form() {
284 - check_ajax_referer( 'weforms' );
285 -
286 - $this->check_admin();
287 -
288 - $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
289 -
290 - if ( !$form_id ) {
291 - wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
292 - }
293 -
294 - weforms()->form->delete( $form_id );
295 -
296 - wp_send_json_success();
297 - }
298 -
299 - public function delete_form_bulk() {
300 - check_ajax_referer( 'weforms' );
301 -
302 - $this->check_admin();
303 -
304 - $form_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : [];
305 -
306 - if ( !$form_ids ) {
307 - wp_send_json_error( __( 'No form ids provided!', 'weforms' ) );
308 - }
309 -
310 - foreach ( $form_ids as $form_id ) {
311 - weforms()->form->delete( $form_id );
312 - }
313 -
314 - wp_send_json_success();
315 - }
316 -
317 - /**
318 - * Duplicate a form
319 - *
320 - * @return voiud
321 - */
322 - public function duplicate_form() {
323 - check_ajax_referer( 'weforms' );
324 -
325 - $this->check_admin();
326 -
327 - $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
328 -
329 - $form = weforms()->form->duplicate( $form_id );
330 - $form->settings = $form->get_settings();
331 -
332 - wp_send_json_success( $form );
333 - }
334 -
335 - /**
336 - * Create form from a template
337 - *
338 - * @return void
339 - */
340 - public function create_form_from_template() {
341 - check_ajax_referer( 'weforms' );
342 -
343 - $template = isset( $_REQUEST['template'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['template'] ) ) : '';
344 -
345 - $form_id = weforms()->templates->create( $template );
346 -
347 - if ( is_wp_error( $form_id ) ) {
348 - wp_send_json_error( __( 'Could not create the form', 'weforms' ) );
349 - }
350 -
351 - wp_send_json_success( [
352 - 'id' => $form_id,
353 - ] );
354 - }
355 -
356 - /**
357 - * Save the weForms settings
358 - *
359 - * @return void
360 - */
361 - public function save_settings() {
362 - check_ajax_referer( 'weforms' );
363 - $this->check_admin();
364 -
365 - $requires_wpuf_update = false;
366 - $wpuf_update_array = array();
367 - $settings = isset( $_POST['settings'] ) ? (array) json_decode( wp_unslash( $_POST['settings'] ) ) : [];
368 - update_option( 'weforms_settings', $settings );
369 -
370 - // wpuf settings sync
371 - if ( isset( $settings['gmap_api'] ) ) {
372 - $requires_wpuf_update = true;
373 - $wpuf_update_array['gmap_api_key'] = $settings['gmap_api'];
374 - }
375 -
376 - if ( isset( $settings['recaptcha'] ) ) {
377 - $requires_wpuf_update = true;
378 - $wpuf_update_array['recaptcha_public'] = $settings['recaptcha']->key;
379 - $wpuf_update_array['recaptcha_private'] = $settings['recaptcha']->secret;
380 - $wpuf_update_array['recaptcha_type'] = $settings['recaptcha']->type;
381 - }
382 -
383 - if ( isset( $settings['no_conflict'] ) ) {
384 - $requires_wpuf_update = true;
385 - $wpuf_update_array['no_conflict'] = $settings['no_conflict'];
386 - }
387 -
388 - if ( isset( $settings['email_footer'] ) ) {
389 - $requires_wpuf_update = true;
390 - $wpuf_update_array['email_footer'] = $settings['email_footer'];
391 - }
392 -
393 - if ( $requires_wpuf_update ) {
394 - $wpuf_settings = get_option( 'wpuf_general', [] );
395 -
396 - $wpuf_settings = array_merge( $wpuf_settings, $wpuf_update_array );
397 - update_option( 'wpuf_general', $wpuf_settings );
398 - }
399 -
400 - do_action( 'weforms_save_settings', $settings );
401 -
402 - $settings = apply_filters( 'weforms_after_save_settings', $settings );
403 - wp_send_json_success( $settings );
404 - }
405 -
406 - /**
407 - * Get the weForms Settings
408 - *
409 - * @return void
410 - */
411 - public function get_settings() {
412 - check_ajax_referer( 'weforms' );
413 -
414 - $this->check_admin();
415 -
416 - $settings = weforms_get_settings();
417 - // checking to prevent js error, will be removed in future
418 - if ( !isset( $settings['credit'] ) ) {
419 - $settings['credit'] = false;
420 - }
421 -
422 - if ( !isset( $settings['permission'] ) ) {
423 - $settings['permission'] = 'manage_options';
424 - }
425 -
426 - wp_send_json_success( $settings );
427 - }
428 -
429 - /**
430 - * Get all entries
431 - *
432 - * @return void
433 - */
434 - public function get_entries() {
435 - check_ajax_referer( 'weforms' );
436 -
437 - $this->check_admin();
438 -
439 - $form_id = isset( $_REQUEST['id'] ) ? intval( $_REQUEST['id'] ) : 0;
440 - $current_page = isset( $_REQUEST['page'] ) ? intval( $_REQUEST['page'] ) : 1;
441 - $status = isset( $_REQUEST['status'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['status'] ) ) : 'publish';
442 - $per_page = 20;
443 - $offset = ( $current_page - 1 ) * $per_page;
444 -
445 - if ( !$form_id ) {
446 - wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
447 - }
448 -
449 - $entries = weforms_get_form_entries(
450 - $form_id, [
451 - 'number' => $per_page,
452 - 'offset' => $offset,
453 - 'status' => $status,
454 - ]
455 - );
456 -
457 - $columns = weforms_get_entry_columns( $form_id );
458 - $total_entries = weforms_count_form_entries( $form_id, $status );
459 -
460 - array_map(
461 - function ( $entry ) use ( $columns ) {
462 - $entry_id = $entry->id;
463 - $entry->fields = [];
464 -
465 - foreach ( $columns as $meta_key => $label ) {
466 - if ( empty( $meta_key ) ) {
467 - continue;
468 - }
469 - $value = weforms_get_entry_meta( $entry_id, $meta_key, true );
470 - $entry->fields[ $meta_key ] = str_replace( WeForms::$field_separator, ' ', $value );
471 - }
472 - }, $entries
473 - );
474 -
475 - $entries = apply_filters( 'weforms_get_entries', $entries, $form_id );
476 -
477 - $response = [
478 - 'columns' => $columns,
479 - 'entries' => $entries,
480 - 'form_title' => get_post_field( 'post_title', $form_id ),
481 - 'pagination' => [
482 - 'total' => $total_entries,
483 - 'per_page' => $per_page,
484 - 'pages' => ceil( $total_entries / $per_page ),
485 - 'current' => $current_page,
486 - ],
487 - 'meta' => [
488 - 'total' => weforms_count_form_entries( $form_id ),
489 - 'totalTrash' => weforms_count_form_entries( $form_id, 'trash' ),
490 - ],
491 - ];
492 -
493 - wp_send_json_success( $response );
494 - }
495 -
496 - /**
497 - * Get an entry details
498 - *
499 - * @return void
500 - */
501 - public function get_entry_detail() {
502 - check_ajax_referer( 'weforms' );
503 -
504 - $this->check_admin();
505 -
506 - $form_id = isset( $_REQUEST['form_id'] ) ? intval( $_REQUEST['form_id'] ) : 0;
507 - $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
508 -
509 - $form = weforms()->form->get( $form_id );
510 - $form_settings = $form->get_settings();
511 - $entry = $form->entries()->get( $entry_id );
512 - $fields = $entry->get_fields();
513 - $metadata = $entry->get_metadata();
514 - $payment = $entry->get_payment_data();
515 -
516 - if ( isset( $payment->payment_data ) && is_serialized( $payment->payment_data ) ) {
517 - $payment->payment_data = unserialize( $payment->payment_data );
518 - }
519 -
520 - if ( false === $fields ) {
521 - wp_send_json_error( __( 'No form fields found!', 'weforms' ) );
522 - }
523 -
524 - if ( sizeof( $fields ) < 1 ) {
525 - $fields[] = [
526 - 'label' => __( 'No form fields found!', 'weforms' ),
527 - ];
528 - }
529 -
530 - $has_empty = false;
531 - $answers = [];
532 - $respondentPoints = isset( $form_settings['total_points'] ) ? floatval( $form_settings['total_points'] ) : 0;
533 - $fields_formatted = array();
534 - foreach ( $fields as $key => $field ) {
535 - if ( $form_settings['quiz_form'] == 'yes' ) {
536 - $selectedAnswers = isset( $field['selected_answers'] ) ? $field['selected_answers'] : '';
537 - $givenAnswer = isset( $field['value'] ) ? $field['value'] : '';
538 - $options = isset( $field['options'] ) ? $field['options'] : '';
539 - $template = $field['template'];
540 - $fieldPoints = isset( $field['points'] ) ? floatval( $field['points'] ) : 0;
541 -
542 - if ( $template == 'radio_field' || $template == 'dropdown_field' ) {
543 - $answers[$field['name']] = true;
544 - if ( empty( $givenAnswer ) ) {
545 - $answers[$field['name']] = false;
546 - $respondentPoints -= $fieldPoints;
547 - } else {
548 - foreach ( $options as $key => $value ) {
549 - if ( $givenAnswer == $value ) {
550 - if ( $key != $selectedAnswers ) {
551 - $answers[$field['name']] = false;
552 - $respondentPoints -= $fieldPoints;
553 - }
554 - }
555 - }
556 - }
557 - } elseif ( $template == 'checkbox_field' || $template == 'multiple_select' ) {
558 - $answers[$field['name']] = true;
559 - $userAnswer = [];
560 -
561 - foreach ( $options as $key => $value ) {
562 - foreach ( $givenAnswer as $answer ) {
563 - if ( $value == $answer ) {
564 - $userAnswer[] = $key;
565 - }
566 - }
567 - }
568 -
569 - $userAnswer = implode( '|', $userAnswer );
570 - $rightAnswers = implode( '|', $selectedAnswers );
571 -
572 - if ( $userAnswer != $rightAnswers || empty( $userAnswer ) ) {
573 - $answers[$field['name']] = false;
574 - $respondentPoints -= $fieldPoints;
575 - }
576 - }
577 - } elseif ( empty( $field['value'] ) ) {
578 - $has_empty = true;
579 - continue;
580 - } else {
581 - $field = WeForms_Form_Entry_Manager::format_entry_value( $field );
582 - array_push( $fields_formatted, $field );
583 - }
584 - }
585 - $response = [
586 - 'form_fields' => $fields_formatted,
587 - 'form_settings' => $form_settings,
588 - 'meta_data' => $metadata,
589 - 'payment_data' => $payment,
590 - 'has_empty' => $has_empty,
591 - 'respondent_points' => $respondentPoints,
592 - 'answers' => $answers,
593 - ];
594 -
595 -
596 - wp_send_json_success( $response );
597 - }
598 -
599 - /**
600 - * Trash an entry
601 - *
602 - * @return void
603 - */
604 - public function trash_entry() {
605 - check_ajax_referer( 'weforms' );
606 -
607 - $this->check_admin();
608 -
609 - $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
610 -
611 - weforms_change_entry_status( $entry_id, 'trash' );
612 - wp_send_json_success();
613 - }
614 -
615 - /**
616 - * Trash an entry
617 - *
618 - * @return void
619 - */
620 - public function delete_entry() {
621 - check_ajax_referer( 'weforms' );
622 -
623 - $this->check_admin();
624 -
625 - $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
626 -
627 - weforms_delete_entry( $entry_id );
628 -
629 - wp_send_json_success();
630 - }
631 -
632 - /**
633 - * Restore Entry
634 - *
635 - * @return void
636 - */
637 - public function restore_entry() {
638 - check_ajax_referer( 'weforms' );
639 -
640 - $this->check_admin();
641 -
642 - $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
643 -
644 - weforms_change_entry_status( $entry_id, 'publish' );
645 - wp_send_json_success();
646 - }
647 -
648 - /**
649 - * Bulk trash entries
650 - *
651 - * @return void
652 - */
653 - public function bulk_delete_entry() {
654 - check_ajax_referer( 'weforms' );
655 -
656 - $this->check_admin();
657 -
658 - $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : array();
659 - $permanent = isset( $_POST['permanent'] ) && ( sanitize_text_field( wp_unslash ( $_POST['permanent'] ) ) ) ? true : false;
660 -
661 - if ( !$entry_ids ) {
662 - wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
663 - }
664 -
665 - foreach ( $entry_ids as $entry_id ) {
666 - if ( $permanent ) {
667 - weforms_delete_entry( $entry_id );
668 - } else {
669 - weforms_change_entry_status( $entry_id, 'trash' );
670 - }
671 - }
672 -
673 - wp_send_json_success();
674 - }
675 -
676 - /**
677 - * Bulk trash entries
678 - *
679 - * @return void
680 - */
681 - public function bulk_restore_entry() {
682 - check_ajax_referer( 'weforms' );
683 -
684 - $this->check_admin();
685 -
686 - $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : [];
687 -
688 - if ( !$entry_ids ) {
689 - wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
690 - }
691 -
692 - foreach ( $entry_ids as $entry_id ) {
693 - weforms_change_entry_status( $entry_id, 'publish' );
694 - }
695 -
696 - wp_send_json_success();
697 - }
698 -
699 - /**
700 - * Handle the frontend submission
701 - *
702 - * @return void
703 - */
704 - public function handle_frontend_submission() {
705 - check_ajax_referer( 'wpuf_form_add' );
706 - $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
707 - $page_id = isset( $_POST['page_id'] ) ? intval( $_POST['page_id'] ) : 0;
708 -
709 - $form = weforms()->form->get( $form_id );
710 - $form_settings = $form->get_settings();
711 - $form_fields = $form->get_fields();
712 - $entry_fields = $form->prepare_entries();
713 - $form_entries = weforms_get_form_entries( $form_id, [ 'number' => '', 'offset' => '' ] );
714 -
715 - if ( $form_fields && count( $form_entries ) && count( $entry_fields ) ) {
716 - foreach ( $entry_fields as $field_key => $field_value ) {
717 - $duplicate_check = false;
718 - $field_label = 'This';
719 -
720 - foreach ( $form_fields as $form_field ) {
721 - if ( in_array( $form_field['template'], [ 'text_field', 'website_url', 'numeric_text_field', 'email_address' ] ) && $form_field['name'] == $field_key && isset( $form_field['duplicate'] ) && 'no' == $form_field['duplicate'] ) {
722 - $duplicate_check = true;
723 - $field_label = $form_field['label'];
724 - }
725 - }
726 -
727 - if ( $duplicate_check ) {
728 - foreach ( $form_entries as $entry ) {
729 - $existing = weforms_get_entry_meta( $entry->id, $field_key, true );
730 -
731 - if ( $existing && $field_value == $existing ) {
732 - wp_send_json( [
733 - 'success' => false,
734 - 'error' => sprintf( __( '"%s" field requires a unique entry and "%s" has already been used.', 'weforms' ), $field_label, $field_value ),
735 - ] );
736 - }
737 - }
738 - }
739 - }
740 - }
741 -
742 - if ( !$form_fields ) {
743 - wp_send_json( [
744 - 'success' => false,
745 - 'error' => __( 'No form field was found.', 'weforms' ),
746 - ] );
747 - }
748 -
749 - if ( $form->has_field( 'recaptcha' ) ) {
750 - $settings = weforms_get_settings( 'recaptcha' );
751 - $type = isset( $settings->type ) ? $settings->type : '';
752 - $secret = isset( $settings->secret ) ? $settings->secret : '';
753 - if( $type == 'v3' ) {
754 - $this->validate_reCaptchav3( $secret );
755 - } else {
756 - $this->validate_reCaptcha();
757 - }
758 - }
759 -
760 - // vaidate submission
761 - $this->validate_submission( $entry_fields, $form, $form_settings, $form_fields );
762 -
763 - $entry_fields = apply_filters( 'weforms_before_entry_submission', $entry_fields, $form, $form_settings, $form_fields );
764 -
765 - //check for entry_fields for a return error
766 - if ( is_wp_error( $entry_fields ) ) {
767 - wp_send_json( [
768 - 'success' => false,
769 - 'error' => $entry_fields->get_error_message(),
770 - ] );
771 - } else {
772 - $entry_id = 1;
773 - $global_settings = weforms_get_settings();
774 - if ( empty( $form_settings['after_submission'] ) ) {
775 - $entry_id = weforms_insert_entry( [
776 - 'form_id' => $form_id,
777 - ], $entry_fields );
778 - if ( is_wp_error( $entry_id ) ) {
779 - wp_send_json( [
780 - 'success' => false,
781 - 'error' => $entry_id->get_error_message(),
782 - ] );
783 - }
784 - // Fire a hook for integration
785 - do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
786 - $notification = new WeForms_Notification( [
787 - 'form_id' => $form_id,
788 - 'page_id' => $page_id,
789 - 'entry_id' => $entry_id,
790 - ] );
791 - $notification->send_notifications();
792 - }
793 - }
794 - // redirect URL
795 - $show_message = false;
796 - $redirect_to = false;
797 - if ( $form_settings['redirect_to'] == 'page' ) {
798 - $redirect_to = get_permalink( $form_settings['page_id'] );
799 - } elseif ( $form_settings['redirect_to'] == 'url' ) {
800 - $redirect_to = $form_settings['url'];
801 - } elseif ( $form_settings['redirect_to'] == 'same' ) {
802 - $show_message = true;
803 - } else {
804 - $show_message = true;
805 - }
806 - $field_search = $field_replace = [];
807 - foreach ( $form_fields as $r_field ) {
808 - $field_search[] = '{' . $r_field['name'] . '}';
809 - if ( $r_field['template'] == 'name_field' ) {
810 - $field_replace[] = implode( ' ', explode( '|', $entry_fields[ $r_field['name'] ] ) );
811 - } else if ( $r_field['template'] == 'address_field' ) {
812 - $field_replace[] = implode( ', ', $entry_fields[ $r_field['name'] ] );
813 - } else {
814 - $field_replace[] = isset( $entry_fields[ $r_field['name'] ] ) ? $entry_fields[ $r_field['name'] ] : '';
815 - }
816 - }
817 - $message = str_replace( $field_search, $field_replace, $form_settings['message'] );
818 - // send the response
819 - $response = apply_filters( 'weforms_entry_submission_response', [
820 - 'success' => true,
821 - 'redirect_to' => $redirect_to,
822 - 'show_message' => $show_message,
823 - 'message' => $message,
824 - 'data' => $_POST,
825 - 'form_id' => $form_id,
826 - 'entry_id' => $entry_id,
827 - 'entry_fields' =>$entry_fields,
828 - ] );
829 -
830 - weforms_clear_buffer();
831 - wp_send_json( $response );
832 - }
833 -
834 - function validate_reCaptchav3( $secret ) {
835 - check_ajax_referer( 'wpuf_form_add' );
836 -
837 - $post_data = wp_unslash($_POST);
838 - $token = $post_data['g-recaptcha-response'];
839 - $action = $post_data['g-action'];
840 - $google_captcha_url = esc_url( 'https://www.google.com/recaptcha/api/siteverify' );
841 -
842 - $response = wp_remote_post( $google_captcha_url,
843 - array(
844 - 'method' => 'POST',
845 - 'body' => array(
846 - 'secret' => $secret,
847 - 'response' => $token
848 - )
849 - )
850 - );
851 -
852 -
853 - if ( is_wp_error( $response ) ) {
854 - wp_send_json( [
855 - 'success' => false,
856 - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
857 - ] );
858 - } else {
859 - $api_response = json_decode( wp_remote_retrieve_body( $response ), true );
860 - if( $api_response["success"] == '1' && $api_response["action"] == $action ) {
861 - return true;
862 - } else {
863 - wp_send_json( [
864 - 'success' => false,
865 - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
866 - ] );
867 - }
868 - }
869 - }
870 - /**
871 - * reCaptcha Validation
872 - *
873 - * @return void
874 - */
875 - function validate_reCaptcha() {
876 - check_ajax_referer( 'wpuf_form_add' );
877 - if ( class_exists( 'WPUF_ReCaptcha' ) ) {
878 - $recaptcha_class = 'WPUF_ReCaptcha';
879 - } else {
880 - if ( !function_exists( 'recaptcha_get_html' ) ) {
881 - require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib.php';
882 - }
883 -
884 - require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib_noCaptcha.php';
885 - $recaptcha_class = 'Weforms_ReCaptcha';
886 - }
887 -
888 - $invisible = isset( $_POST['g-recaptcha-response'] ) ? false : true;
889 -
890 - $recaptcha_settings = weforms_get_settings( 'recaptcha' );
891 - $secret = isset( $recaptcha_settings->secret ) ? $recaptcha_settings->secret : '';
892 -
893 - if ( ! $invisible ) {
894 - $response = null;
895 - $reCaptcha = new $recaptcha_class( $secret );
896 - $remote_ADDR = isset( $_SERVER['REMOTE_ADDR'] ) ? sanitize_text_field( wp_unslash( $_SERVER['REMOTE_ADDR'] ) ) : '';
897 - $recaptcha_response = isset( $_POST['g-recaptcha-response'] ) ? sanitize_text_field( wp_unslash( $_POST['g-recaptcha-response'] ) ) : '';
898 - $resp = $reCaptcha->verifyResponse(
899 - $remote_ADDR,
900 - $recaptcha_response
901 - );
902 -
903 - if ( !$resp->success ) {
904 - wp_send_json( [
905 - 'success' => false,
906 - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
907 - ] );
908 - }
909 -
910 - } else {
911 -
912 - $recap_challenge = isset( $_POST['recaptcha_challenge_field'] ) ? sanitize_text_field( wp_unslash( $_POST['recaptcha_challenge_field'] ) ) : '';
913 - $recap_response = isset( $_POST['recaptcha_response_field'] ) ? sanitize_text_field( wp_unslash( $_POST['recaptcha_response_field'] ) ) : '';
914 - $resp = recaptcha_check_answer( $secret, $remote_ADDR, $recap_challenge, $recap_response );
915 -
916 - if ( !$resp->is_valid ) {
917 - ob_clean();
918 -
919 - wp_send_json( [
920 - 'success' => false,
921 - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
922 - ] );
923 - }
924 - }
925 - }
926 -
927 - /**
928 - * Validate submission
929 - *
930 - * @param array $entry_fields
931 - * @param object $form
932 - * @param array $form_settings
933 - * @param array $form_fields
934 - *
935 - * @return bool|json
936 - */
937 - public function validate_submission( $entry_fields, $form, $form_settings, $form_fields ) {
938 - foreach ( $form_fields as $key => $field ) {
939 -
940 - //skip custom html field as it is not saved
941 - if ( 'custom_html' == $field['name'] ) {
942 - continue;
943 - }
944 -
945 - //skip recaptcha field as it is not saved
946 - if ( 'recaptcha' == $field['name'] ) {
947 - continue;
948 - }
949 -
950 - $value = $entry_fields[ $field['name'] ];
951 -
952 - if ( 'single_product' === $field['template'] ) {
953 - if ( !$value ) {
954 - $value = [];
955 - }
956 -
957 - $value['price'] = isset( $value['price'] ) ? floatval( $value['price'] ) : 0;
958 - $value['quantity'] = isset( $value['quantity'] ) ? floatval( $value['quantity'] ) : 0;
959 - $quantity = isset( $field['quantity'] ) ? $field['quantity'] : [];
960 - $price = isset( $field['price'] ) ? $field['price'] : [];
961 -
962 - if ( isset( $price['is_flexible'] ) && $price['is_flexible'] ) {
963 - $min = isset( $price['min'] ) ? floatval( $price['min'] ) : 0;
964 - $max = isset( $price['max'] ) ? floatval( $price['max'] ) : 0;
965 -
966 - if ( $value['price'] < $min ) {
967 - wp_send_json( [
968 - 'success' => false,
969 - 'error' => __( sprintf(
970 - '%s price must be equal or greater than %s',
971 - $field['weforms'],
972 - $min ),
973 - 'weforms' ),
974 - ] );
975 - }
976 -
977 - if ( $max && $value['price'] > $max ) {
978 - wp_send_json( [
979 - 'success' => false,
980 - 'error' => __( sprintf(
981 - '%s price must be equal or less than %s',
982 - $field['weforms'],
983 - $max ),
984 - 'weforms' ),
985 - ] );
986 - }
987 - }
988 -
989 - if ( isset( $quantity['status'] ) && $quantity['status'] ) {
990 - $min = isset( $quantity['min'] ) ? floatval( $quantity['min'] ) : 0;
991 - $max = isset( $quantity['max'] ) ? floatval( $quantity['max'] ) : 0;
992 -
993 - if ( $value['quantity'] < $min ) {
994 - wp_send_json( [
995 - 'success' => false,
996 - 'error' => __( sprintf(
997 - '%s quantity must be equal or greater than %s',
998 - $field['weforms'],
999 - $min ),
1000 - 'weforms' ),
1001 - ] );
1002 - }
1003 -
1004 - if ( $max && $value['quantity'] > $max ) {
1005 - wp_send_json( [
1006 - 'success' => false,
1007 - 'error' => __( sprintf(
1008 - '%s quantity must be equal or less than %s',
1009 - $field['weforms'],
1010 - $max ),
1011 - 'weforms' ),
1012 - ] );
1013 - }
1014 - }
1015 - }
1016 - }
1017 - }
1018 -
1019 - public static function prepare_meta_fields( $meta_vars ) {
1020 - check_ajax_referer( 'wpuf_form_add' );
1021 - // loop through custom fields
1022 - // skip files, put in a key => value paired array for later executation
1023 - // process repeatable fields separately
1024 - // if the input is array type, implode with separator in a field
1025 - $files = [];
1026 - $meta_key_value = [];
1027 - $multi_repeated = []; // multi repeated fields will in sotre duplicated meta key
1028 -
1029 - foreach ( $meta_vars as $key => $value ) {
1030 - switch ( $value['template'] ) {
1031 -
1032 - // put files in a separate array, we'll process it later
1033 - case 'file_upload':
1034 - case 'image_upload':
1035 - $files[] = [
1036 - 'name' => $value['name'],
1037 - 'value' => isset( $_POST['wpuf_files'][ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST['wpuf_files'][ $value['name'] ] ) ) : array(),
1038 - 'count' => $value['count']
1039 - ];
1040 - break;
1041 -
1042 - case 'repeat_field':
1043 - // if it is a multi column repeat field
1044 - if ( isset( $value['multiple'] ) && $value['multiple'] == 'true' ) {
1045 -
1046 - // if there's any items in the array, process it
1047 - if ( isset( $_POST[ $value['name'] ] ) ) {
1048 - $ref_arr = [];
1049 - $cols = count( $value['columns'] );
1050 - $first = array_shift( array_values( sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) ) ); // first element
1051 - $rows = count( $first );
1052 -
1053 - // loop through columns
1054 - for ( $i = 0; $i < $rows; $i++ ) {
1055 -
1056 - // loop through the rows and store in a temp array
1057 - $temp = [];
1058 - for ( $j = 0; $j < $cols; $j++ ) {
1059 - $temp[] = isset( $_POST[ $value['name'] ][ $j ][ $i ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ][ $j ][ $i ] ) ) : '';
1060 - }
1061 -
1062 - // store all fields in a row with WeForms::$field_separator separated
1063 - $ref_arr[] = implode( WeForms::$field_separator, $temp );
1064 - }
1065 -
1066 - // now, if we found anything in $ref_arr, store to $multi_repeated
1067 - if ( $ref_arr ) {
1068 - $multi_repeated[ $value['name'] ] = array_slice( $ref_arr, 0, $rows );
1069 - }
1070 - }
1071 - } else {
1072 - $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) );
1073 - }
1074 -
1075 - break;
1076 -
1077 - case 'address_field':
1078 - if ( isset( $_POST[ $value['name'] ] ) && is_array( $_POST[ $value['name'] ] ) ) {
1079 - $post_value = sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) );
1080 - foreach ( $post_value as $address_field => $field_value ) {
1081 - $meta_key_value[ $value['name'] ][ $address_field ] = sanitize_text_field( $field_value );
1082 - }
1083 - }
1084 -
1085 - break;
1086 -
1087 - case 'text_field':
1088 - case 'email_address':
1089 - case 'numeric_text_field':
1090 - case 'date_field':
1091 - $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : '';
1092 -
1093 - break;
1094 -
1095 - case 'textarea_field':
1096 - $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : '';
1097 -
1098 - break;
1099 -
1100 - case 'dropdown_field':
1101 - case 'radio_field':
1102 - $val = sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) );
1103 - $meta_key_value[ $value['name'] ] = isset( $value['options'][ $val ] ) ? $value['options'][ $val ] : '';
1104 - break;
1105 -
1106 - case 'multiple_select':
1107 - case 'checkbox_field':
1108 - $val = ( is_array( $_POST[ $value['name'] ] ) && sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : array();
1109 - $meta_key_value[ $value['name'] ] = $val;
1110 -
1111 - if ( $val ) {
1112 - $new_val = [];
1113 -
1114 - foreach ( $val as $option_key ) {
1115 - $new_val[] = isset( $value['options'][ $option_key ] ) ? $value['options'][ $option_key ] : '';
1116 - }
1117 -
1118 - $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, $new_val );
1119 - }
1120 - break;
1121 -
1122 - default:
1123 - // if it's an array, implode with this->separator
1124 - if ( is_array( $_POST[ $value['name'] ] ) ) {
1125 - $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) );
1126 - } else {
1127 - $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ): '';
1128 - }
1129 -
1130 - break;
1131 - }
1132 - } //end foreach
1133 -
1134 - return [ $meta_key_value, $multi_repeated, $files ];
1135 - }
1136 -
1137 - /**
1138 - * Import a form from a JSON file
1139 - *
1140 - * @return void
1141 - */
1142 - public function import_form() {
1143 - check_ajax_referer( 'weforms' );
1144 -
1145 - $this->check_admin();
1146 -
1147 - $the_file = isset( $_FILES['importFile'] ) ? $_FILES['importFile'] : false;
1148 -
1149 - if ( !$the_file ) {
1150 - wp_send_json_error( __( 'No file found to import.', 'weforms' ) );
1151 - }
1152 -
1153 - $file_ext = pathinfo( $the_file['name'], PATHINFO_EXTENSION );
1154 -
1155 - if ( !class_exists( 'WeForms_Admin_Tools' ) ) {
1156 - require_once __DIR__ . '/admin/class-admin-tools.php';
1157 - }
1158 -
1159 - if ( ( $file_ext == 'json' ) && ( $the_file['size'] < 500000 ) ) {
1160 - $status = WeForms_Admin_Tools::import_json_file( $the_file['tmp_name'] );
1161 -
1162 - if ( $status ) {
1163 - wp_send_json_success( __( 'The forms have been imported successfully!', 'weforms' ) );
1164 - } else {
1165 - wp_send_json_error( __( 'Something went wrong importing the file.', 'weforms' ) );
1166 - }
1167 - } else {
1168 - wp_send_json_error( __( 'Invalid file or file size too big.', 'weforms' ) );
1169 - }
1170 - }
1171 -
1172 - /**
1173 - * Read Log file
1174 - *
1175 - * @return json
1176 - **/
1177 - public function get_logs() {
1178 - check_ajax_referer( 'weforms' );
1179 -
1180 - $this->check_admin();
1181 -
1182 - $file = weforms_log_file_path();
1183 -
1184 - if ( !file_exists( $file ) ) {
1185 - return;
1186 - }
1187 -
1188 - $data = file_get_contents( $file );
1189 - $data = explode( "\n", $data );
1190 - $data = array_reverse( $data );
1191 - $data = array_filter( $data );
1192 -
1193 - if ( empty( $data ) ) {
1194 - return;
1195 - }
1196 -
1197 - $logs = [];
1198 -
1199 - foreach ( $data as $key => $row ) {
1200 - preg_match( '/\[(?<time>.+?)\]\[(?<type>.+?)\](?<message>.+)/im', $row, $log );
1201 -
1202 - if ( empty( $log['message'] ) ) {
1203 - $log = [];
1204 - $log['message'] = !empty( $log['message'] ) ? $log['message'] : $row;
1205 - }
1206 -
1207 - if ( !empty( $log['time'] ) ) {
1208 - $human_time = human_time_diff( strtotime( $log['time'] ), current_time( 'timestamp' ) );
1209 - $log['time'] = $human_time ? $human_time . ' ' . __( 'ago', 'weforms' ) : $log['time'];
1210 - }
1211 -
1212 - $logs[] = $log;
1213 - }
1214 -
1215 - wp_send_json_success( $logs );
1216 - }
1217 -
1218 - /**
1219 - * Read Log file
1220 - *
1221 - * @return json
1222 - **/
1223 - public function delete_logs() {
1224 - check_ajax_referer( 'weforms' );
1225 -
1226 - $this->check_admin();
1227 -
1228 - $file = weforms_log_file_path();
1229 -
1230 - if ( !file_exists( $file ) ) {
1231 - return;
1232 - }
1233 -
1234 - @unlink( $file );
1235 -
1236 - wp_send_json_success();
1237 - }
1238 -}
1 +<?php
2 +
3 +/**
4 + * The ajax handler class
5 + */
6 +class WeForms_Ajax {
7 +
8 + public function __construct() {
9 +
10 + // backend requests
11 + add_action( 'wp_ajax_weforms_form_list', [ $this, 'get_contact_forms' ] );
12 + add_action( 'wp_ajax_weforms_get_users', [ $this, 'get_all_users' ] );
13 + add_action( 'wp_ajax_weforms_form_names', [ $this, 'get_contact_form_names' ] );
14 + add_action( 'wp_ajax_weforms_form_create', [ $this, 'create_form' ] );
15 + add_action( 'wp_ajax_weforms_form_delete', [ $this, 'delete_form' ] );
16 + add_action( 'wp_ajax_weforms_form_delete_bulk', [ $this, 'delete_form_bulk' ] );
17 + add_action( 'wp_ajax_weforms_form_duplicate', [ $this, 'duplicate_form' ] );
18 +
19 + // read logs
20 + add_action( 'wp_ajax_weforms_read_logs', [ $this, 'get_logs' ] );
21 + add_action( 'wp_ajax_weforms_delete_logs', [ $this, 'delete_logs' ] );
22 +
23 + // create from a template
24 + add_filter( 'wp_ajax_weforms_contact_form_template', [ $this, 'create_form_from_template' ] );
25 +
26 + // form settings
27 + add_action( 'wp_ajax_weforms_save_settings', [ $this, 'save_settings' ] );
28 + add_action( 'wp_ajax_weforms_get_settings', [ $this, 'get_settings' ] );
29 +
30 + // import
31 + add_action( 'wp_ajax_weforms_import_form', [ $this, 'import_form' ] );
32 +
33 + // form editing
34 + add_action( 'wp_ajax_weforms_get_form', [ $this, 'get_form' ] );
35 + add_action( 'wp_ajax_wpuf_form_builder_save_form', [ $this, 'save_form' ] );
36 +
37 + // entries
38 + add_action( 'wp_ajax_weforms_form_entries', [ $this, 'get_entries' ] );
39 +
40 + add_action( 'wp_ajax_weforms_form_entry_details', [ $this, 'get_entry_detail' ] );
41 + add_action( 'wp_ajax_weforms_form_entry_trash', [ $this, 'trash_entry' ] );
42 + add_action( 'wp_ajax_weforms_form_entry_delete', [ $this, 'delete_entry' ] );
43 + add_action( 'wp_ajax_weforms_form_entry_restore', [ $this, 'restore_entry' ] );
44 +
45 + add_action( 'wp_ajax_weforms_form_entry_trash_bulk', [ $this, 'bulk_delete_entry' ] );
46 + add_action( 'wp_ajax_weforms_form_entry_restore_bulk', [ $this, 'bulk_restore_entry' ] );
47 +
48 + // frontend requests
49 + add_action( 'wp_ajax_weforms_frontend_submit', [ $this, 'handle_frontend_submission' ] );
50 + add_action( 'wp_ajax_nopriv_weforms_frontend_submit', [ $this, 'handle_frontend_submission' ] );
51 + }
52 +
53 + /**
54 + * Administrator validation
55 + *
56 + * @return void
57 + */
58 + public function check_admin() {
59 + if ( !current_user_can( weforms_form_access_capability() ) ) {
60 + wp_send_json_error( __( 'You do not have sufficient permission.', 'weforms' ) );
61 + }
62 + }
63 +
64 + /**
65 + * Get a form to edit
66 + *
67 + * @return void
68 + */
69 + public function get_form() {
70 + $this->check_admin();
71 +
72 + $form_id = isset( $_REQUEST['form_id'] ) ? absint( $_REQUEST['form_id'] ) : 0;
73 +
74 + $form = weforms()->form->get( $form_id );
75 +
76 + $data = [
77 + 'post' => $form->data,
78 + 'form_fields' => $form->get_fields(),
79 + 'settings' => $form->get_settings(),
80 + 'notifications' => $form->get_notifications(),
81 + 'integrations' => $form->get_integrations(),
82 + ];
83 +
84 + wp_send_json_success( $data );
85 + }
86 +
87 + /**
88 + * Save the form
89 + *
90 + * @return void
91 + */
92 + public function save_form() {
93 +
94 + if ( isset( $_POST['form_data'] ) ) {
95 + parse_str( sanitize_text_field( wp_unslash( $_POST['form_data'] ) ), $form_data );
96 + }
97 +
98 + if ( !wp_verify_nonce( $form_data['wpuf_form_builder_nonce'], 'wpuf_form_builder_save_form' ) ) {
99 + wp_send_json_error( __( 'Unauthorized operation', 'weforms' ) );
100 + }
101 +
102 + if ( empty( $form_data['wpuf_form_id'] ) ) {
103 + wp_send_json_error( __( 'Invalid form id', 'weforms' ) );
104 + }
105 +
106 + $form_fields = isset( $_POST['form_fields'] ) ? sanitize_text_field( wp_unslash( $_POST['form_fields'] ) ) : '';
107 + $notifications = isset( $_POST['notifications'] ) ? sanitize_text_field( wp_unslash( $_POST['notifications'] ) ) : '';
108 + $settings = array();
109 + $integrations = array();
110 +
111 + if ( isset( $_POST['settings'] ) ) {
112 + $settings = (array) json_decode( sanitize_text_field( wp_unslash( $_POST['settings'] ) ) );
113 + } else {
114 + $settings = isset( $form_data['wpuf_settings'] ) ? $form_data['wpuf_settings'] : [];
115 + }
116 +
117 + if ( isset( $_POST['integrations'] ) ) {
118 + $integrations = (array) json_decode( sanitize_text_field( wp_unslash( $_POST['integrations'] ) ) );
119 + }
120 +
121 + $form_fields = wp_unslash( $form_fields );
122 + $notifications = wp_unslash( $notifications );
123 +
124 + $form_fields = json_decode( $form_fields, true );
125 + $notifications = json_decode( $notifications, true );
126 +
127 + $data = [
128 + 'form_id' => absint( $form_data['wpuf_form_id'] ),
129 + 'post_title' => sanitize_text_field( $form_data['post_title'] ),
130 + 'form_fields' => $form_fields,
131 + 'form_settings' => $settings,
132 + 'form_settings_key' => isset( $form_data['form_settings_key'] ) ? $form_data['form_settings_key'] : '',
133 + 'notifications' => $notifications,
134 + 'integrations' => $integrations,
135 + ];
136 +
137 + $form_fields = weforms()->form->save( $data );
138 +
139 + wp_send_json_success( [ 'form_fields' => $form_fields ] );
140 + }
141 +
142 + /**
143 + * Get all contact forms
144 + *
145 + * @return void
146 + */
147 + public function get_contact_forms() {
148 + check_ajax_referer( 'weforms' );
149 +
150 + $this->check_admin();
151 +
152 + $args = [
153 + 'posts_per_page' => isset( $_POST['posts_per_page'] ) ? intval( $_POST['posts_per_page'] ) : 10,
154 + 'paged' => isset( $_POST['page'] ) ? absint( $_POST['page'] ) : 1,
155 + 'order' => 'DESC',
156 + 'orderby' => 'post_date',
157 + ];
158 +
159 + $args = apply_filters( 'weforms_ajax_get_contact_forms_args', $args );
160 +
161 + $contact_forms = weforms()->form->get_forms( $args );
162 +
163 + array_map(
164 + function ( $form ) {
165 + $form->entries = $form->num_form_entries();
166 + $form->settings = $form->get_settings();
167 + $form->views = $form->num_form_views();
168 + $form->payments = $form->num_form_payments();
169 + $form->author = $form->get_form_author_details();
170 + }, $contact_forms['forms']
171 + );
172 +
173 + $contact_forms = $this->filter_contact_forms( $contact_forms );
174 + $contact_forms = apply_filters( 'weforms_ajax_get_contact_forms', $contact_forms );
175 +
176 + wp_send_json_success( $contact_forms );
177 + }
178 +
179 + /**
180 + * Get all users
181 + *
182 + * @return array
183 + */
184 + public function get_all_users() {
185 + check_ajax_referer( 'weforms' );
186 +
187 + $this->check_admin();
188 +
189 + $users_meta = [];
190 + $users = get_users( [ 'fields' => [ 'ID' ] ] );
191 +
192 + foreach ( $users as $user ) {
193 + $users_meta[] = [
194 + 'id' => $user->ID,
195 + 'data' => get_user_meta( $user->ID ),
196 + ];
197 + }
198 +
199 + wp_send_json_success( $users_meta );
200 + }
201 +
202 + /**
203 + * Filter
204 + *
205 + * @return void
206 + */
207 + public function filter_contact_forms( &$contact_forms ) {
208 + if ( isset( $_REQUEST['filter'] ) && $_REQUEST['filter'] == 'entries' ) {
209 + foreach ( $contact_forms['forms'] as $key => &$form ) {
210 + if ( isset( $form->entries ) && !$form->entries ) {
211 + unset( $contact_forms['forms'][ $key ] );
212 + }
213 + }
214 +
215 + $contact_forms['meta']['total'] = count( $contact_forms['forms'] );
216 + }
217 +
218 + return $contact_forms;
219 + }
220 +
221 + /**
222 + * Get the names of contact forms for generating dropdown
223 + *
224 + * @return void
225 + */
226 + public function get_contact_form_names() {
227 + check_ajax_referer( 'weforms' );
228 +
229 + $this->check_admin();
230 +
231 + $contact_forms = weforms()->form->all();
232 + $response = [];
233 +
234 + foreach ( $contact_forms['forms'] as $form ) {
235 + $response[] = [
236 + 'id' => $form->get_id(),
237 + 'title' => $form->get_name() . ' (#' . $form->get_id() . ')',
238 + ];
239 + }
240 +
241 + wp_send_json_success( $response );
242 + }
243 +
244 + /**
245 + * Create a form
246 + *
247 + * @return void
248 + */
249 + public function create_form() {
250 + check_ajax_referer( 'weforms' );
251 +
252 + $this->check_admin();
253 +
254 + $form_name = isset( $_POST['form_name'] ) ? sanitize_text_field( wp_unslash( $_POST['form_name'] ) ) : '';
255 +
256 + if ( empty( $form_name ) ) {
257 + wp_send_json_error( __( 'Please provide a form name', 'weforms' ) );
258 + }
259 +
260 + $form_id = weforms()->form->create( $form_name );
261 +
262 + if ( is_wp_error( $form_id ) ) {
263 + wp_send_json_error( $form_id->get_error_message() );
264 + }
265 +
266 + wp_send_json_success( [
267 + 'form_id' => $form_id,
268 + 'form_name' => $form_name,
269 + ] );
270 + }
271 +
272 + /**
273 + * Delete a form
274 + *
275 + * @return void
276 + */
277 + public function delete_form() {
278 + check_ajax_referer( 'weforms' );
279 +
280 + $this->check_admin();
281 +
282 + $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
283 +
284 + if ( !$form_id ) {
285 + wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
286 + }
287 +
288 + weforms()->form->delete( $form_id );
289 +
290 + wp_send_json_success();
291 + }
292 +
293 + public function delete_form_bulk() {
294 + check_ajax_referer( 'weforms' );
295 +
296 + $this->check_admin();
297 +
298 + $form_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : [];
299 +
300 + if ( !$form_ids ) {
301 + wp_send_json_error( __( 'No form ids provided!', 'weforms' ) );
302 + }
303 +
304 + foreach ( $form_ids as $form_id ) {
305 + weforms()->form->delete( $form_id );
306 + }
307 +
308 + wp_send_json_success();
309 + }
310 +
311 + /**
312 + * Duplicate a form
313 + *
314 + * @return voiud
315 + */
316 + public function duplicate_form() {
317 + check_ajax_referer( 'weforms' );
318 +
319 + $this->check_admin();
320 +
321 + $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
322 +
323 + $form = weforms()->form->duplicate( $form_id );
324 + $form->settings = $form->get_settings();
325 +
326 + wp_send_json_success( $form );
327 + }
328 +
329 + /**
330 + * Create form from a template
331 + *
332 + * @return void
333 + */
334 + public function create_form_from_template() {
335 + check_ajax_referer( 'weforms' );
336 +
337 + $template = isset( $_REQUEST['template'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['template'] ) ) : '';
338 +
339 + $form_id = weforms()->templates->create( $template );
340 +
341 + if ( is_wp_error( $form_id ) ) {
342 + wp_send_json_error( __( 'Could not create the form', 'weforms' ) );
343 + }
344 +
345 + wp_send_json_success( [
346 + 'id' => $form_id,
347 + ] );
348 + }
349 +
350 + /**
351 + * Save the weForms settings
352 + *
353 + * @return void
354 + */
355 + public function save_settings() {
356 + check_ajax_referer( 'weforms' );
357 +
358 + $this->check_admin();
359 +
360 + $requires_wpuf_update = false;
361 + $wpuf_update_array = array();
362 + $settings = isset( $_POST['settings'] ) ? (array) json_decode( sanitize_text_field( wp_unslash( $_POST['settings'] ) ) ) : [];
363 + update_option( 'weforms_settings', $settings );
364 +
365 + // wpuf settings sync
366 + if ( isset( $settings['gmap_api'] ) ) {
367 + $requires_wpuf_update = true;
368 + $wpuf_update_array['gmap_api_key'] = $settings['gmap_api'];
369 + }
370 +
371 + if ( isset( $settings['recaptcha'] ) ) {
372 + $requires_wpuf_update = true;
373 + $wpuf_update_array['recaptcha_public'] = $settings['recaptcha']->key;
374 + $wpuf_update_array['recaptcha_private'] = $settings['recaptcha']->secret;
375 + }
376 +
377 + if ( isset( $settings['no_conflict'] ) ) {
378 + $requires_wpuf_update = true;
379 + $wpuf_update_array['no_conflict'] = $settings['no_conflict'];
380 + }
381 +
382 + if ( isset( $settings['email_footer'] ) ) {
383 + $requires_wpuf_update = true;
384 + $wpuf_update_array['email_footer'] = $settings['email_footer'];
385 + }
386 +
387 + if ( $requires_wpuf_update ) {
388 + $wpuf_settings = get_option( 'wpuf_general', [] );
389 +
390 + $wpuf_settings = array_merge( $wpuf_settings, $wpuf_update_array );
391 + update_option( 'wpuf_general', $wpuf_settings );
392 + }
393 +
394 + do_action( 'weforms_save_settings', $settings );
395 +
396 + $settings = apply_filters( 'weforms_after_save_settings', $settings );
397 +
398 + wp_send_json_success( $settings );
399 + }
400 +
401 + /**
402 + * Get the weForms Settings
403 + *
404 + * @return void
405 + */
406 + public function get_settings() {
407 + check_ajax_referer( 'weforms' );
408 +
409 + $this->check_admin();
410 +
411 + $settings = weforms_get_settings();
412 +
413 + // checking to prevent js error, will be removed in future
414 + if ( !isset( $settings['credit'] ) ) {
415 + $settings['credit'] = false;
416 + }
417 +
418 + if ( !isset( $settings['permission'] ) ) {
419 + $settings['permission'] = 'manage_options';
420 + }
421 +
422 + wp_send_json_success( $settings );
423 + }
424 +
425 + /**
426 + * Get all entries
427 + *
428 + * @return void
429 + */
430 + public function get_entries() {
431 + check_ajax_referer( 'weforms' );
432 +
433 + $this->check_admin();
434 +
435 + $form_id = isset( $_REQUEST['id'] ) ? intval( $_REQUEST['id'] ) : 0;
436 + $current_page = isset( $_REQUEST['page'] ) ? intval( $_REQUEST['page'] ) : 1;
437 + $status = isset( $_REQUEST['status'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['status'] ) ) : 'publish';
438 + $per_page = 20;
439 + $offset = ( $current_page - 1 ) * $per_page;
440 +
441 + if ( !$form_id ) {
442 + wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
443 + }
444 +
445 + $entries = weforms_get_form_entries(
446 + $form_id, [
447 + 'number' => $per_page,
448 + 'offset' => $offset,
449 + 'status' => $status,
450 + ]
451 + );
452 +
453 + $columns = weforms_get_entry_columns( $form_id );
454 + $total_entries = weforms_count_form_entries( $form_id, $status );
455 +
456 + array_map(
457 + function ( $entry ) use ( $columns ) {
458 + $entry_id = $entry->id;
459 + $entry->fields = [];
460 +
461 + foreach ( $columns as $meta_key => $label ) {
462 + if ( empty( $meta_key ) ) {
463 + continue;
464 + }
465 + $value = weforms_get_entry_meta( $entry_id, $meta_key, true );
466 + $entry->fields[ $meta_key ] = str_replace( WeForms::$field_separator, ' ', $value );
467 + }
468 + }, $entries
469 + );
470 +
471 + $entries = apply_filters( 'weforms_get_entries', $entries, $form_id );
472 +
473 + $response = [
474 + 'columns' => $columns,
475 + 'entries' => $entries,
476 + 'form_title' => get_post_field( 'post_title', $form_id ),
477 + 'pagination' => [
478 + 'total' => $total_entries,
479 + 'per_page' => $per_page,
480 + 'pages' => ceil( $total_entries / $per_page ),
481 + 'current' => $current_page,
482 + ],
483 + 'meta' => [
484 + 'total' => weforms_count_form_entries( $form_id ),
485 + 'totalTrash' => weforms_count_form_entries( $form_id, 'trash' ),
486 + ],
487 + ];
488 +
489 + wp_send_json_success( $response );
490 + }
491 +
492 + /**
493 + * Get an entry details
494 + *
495 + * @return void
496 + */
497 + public function get_entry_detail() {
498 + check_ajax_referer( 'weforms' );
499 +
500 + $this->check_admin();
501 +
502 + $form_id = isset( $_REQUEST['form_id'] ) ? intval( $_REQUEST['form_id'] ) : 0;
503 + $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
504 +
505 + $form = weforms()->form->get( $form_id );
506 + $form_settings = $form->get_settings();
507 + $entry = $form->entries()->get( $entry_id );
508 + $fields = $entry->get_fields();
509 + $metadata = $entry->get_metadata();
510 + $payment = $entry->get_payment_data();
511 +
512 + if ( isset( $payment->payment_data ) && is_serialized( $payment->payment_data ) ) {
513 + $payment->payment_data = unserialize( $payment->payment_data );
514 + }
515 +
516 + if ( false === $fields ) {
517 + wp_send_json_error( __( 'No form fields found!', 'weforms' ) );
518 + }
519 +
520 + if ( sizeof( $fields ) < 1 ) {
521 + $fields[] = [
522 + 'label' => __( 'No form fields found!', 'weforms' ),
523 + ];
524 + }
525 +
526 + $has_empty = false;
527 + $answers = [];
528 + $respondentPoints = isset( $form_settings['total_points'] ) ? floatval( $form_settings['total_points'] ) : 0;
529 +
530 + foreach ( $fields as $key => $field ) {
531 + if ( $form_settings['quiz_form'] == 'yes' ) {
532 + $selectedAnswers = isset( $field['selected_answers'] ) ? $field['selected_answers'] : '';
533 + $givenAnswer = isset( $field['value'] ) ? $field['value'] : '';
534 + $options = isset( $field['options'] ) ? $field['options'] : '';
535 + $template = $field['template'];
536 + $fieldPoints = isset( $field['points'] ) ? floatval( $field['points'] ) : 0;
537 +
538 + if ( $template == 'radio_field' || $template == 'dropdown_field' ) {
539 + $answers[$field['name']] = true;
540 +
541 + if ( empty( $givenAnswer ) ) {
542 + $answers[$field['name']] = false;
543 + $respondentPoints -= $fieldPoints;
544 + } else {
545 + foreach ( $options as $key => $value ) {
546 + if ( $givenAnswer == $value ) {
547 + if ( $key != $selectedAnswers ) {
548 + $answers[$field['name']] = false;
549 + $respondentPoints -= $fieldPoints;
550 + }
551 + }
552 + }
553 + }
554 + } elseif ( $template == 'checkbox_field' || $template == 'multiple_select' ) {
555 + $answers[$field['name']] = true;
556 + $userAnswer = [];
557 +
558 + foreach ( $options as $key => $value ) {
559 + foreach ( $givenAnswer as $answer ) {
560 + if ( $value == $answer ) {
561 + $userAnswer[] = $key;
562 + }
563 + }
564 + }
565 +
566 + $userAnswer = implode( '|', $userAnswer );
567 + $rightAnswers = implode( '|', $selectedAnswers );
568 +
569 + if ( $userAnswer != $rightAnswers || empty( $userAnswer ) ) {
570 + $answers[$field['name']] = false;
571 + $respondentPoints -= $fieldPoints;
572 + }
573 + }
574 + } elseif ( empty( $field['value'] ) ) {
575 + $has_empty = true;
576 + break;
577 + }
578 + }
579 +
580 + $response = [
581 + 'form_fields' => $fields,
582 + 'form_settings' => $form_settings,
583 + 'meta_data' => $metadata,
584 + 'payment_data' => $payment,
585 + 'has_empty' => $has_empty,
586 + 'respondent_points' => $respondentPoints,
587 + 'answers' => $answers,
588 + ];
589 +
590 + wp_send_json_success( $response );
591 + }
592 +
593 + /**
594 + * Trash an entry
595 + *
596 + * @return void
597 + */
598 + public function trash_entry() {
599 + check_ajax_referer( 'weforms' );
600 +
601 + $this->check_admin();
602 +
603 + $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
604 +
605 + weforms_change_entry_status( $entry_id, 'trash' );
606 + wp_send_json_success();
607 + }
608 +
609 + /**
610 + * Trash an entry
611 + *
612 + * @return void
613 + */
614 + public function delete_entry() {
615 + check_ajax_referer( 'weforms' );
616 +
617 + $this->check_admin();
618 +
619 + $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
620 +
621 + weforms_delete_entry( $entry_id );
622 +
623 + wp_send_json_success();
624 + }
625 +
626 + /**
627 + * Restore Entry
628 + *
629 + * @return void
630 + */
631 + public function restore_entry() {
632 + check_ajax_referer( 'weforms' );
633 +
634 + $this->check_admin();
635 +
636 + $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
637 +
638 + weforms_change_entry_status( $entry_id, 'publish' );
639 + wp_send_json_success();
640 + }
641 +
642 + /**
643 + * Bulk trash entries
644 + *
645 + * @return void
646 + */
647 + public function bulk_delete_entry() {
648 + check_ajax_referer( 'weforms' );
649 +
650 + $this->check_admin();
651 +
652 + $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : array();
653 + $permanent = isset( $_POST['permanent'] ) && ( sanitize_text_field( wp_unslash ( $_POST['permanent'] ) ) ) ? true : false;
654 +
655 + if ( !$entry_ids ) {
656 + wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
657 + }
658 +
659 + foreach ( $entry_ids as $entry_id ) {
660 + if ( $permanent ) {
661 + weforms_delete_entry( $entry_id );
662 + } else {
663 + weforms_change_entry_status( $entry_id, 'trash' );
664 + }
665 + }
666 +
667 + wp_send_json_success();
668 + }
669 +
670 + /**
671 + * Bulk trash entries
672 + *
673 + * @return void
674 + */
675 + public function bulk_restore_entry() {
676 + check_ajax_referer( 'weforms' );
677 +
678 + $this->check_admin();
679 +
680 + $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : [];
681 +
682 + if ( !$entry_ids ) {
683 + wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
684 + }
685 +
686 + foreach ( $entry_ids as $entry_id ) {
687 + weforms_change_entry_status( $entry_id, 'publish' );
688 + }
689 +
690 + wp_send_json_success();
691 + }
692 +
693 + /**
694 + * Handle the frontend submission
695 + *
696 + * @return void
697 + */
698 + public function handle_frontend_submission() {
699 + check_ajax_referer( 'wpuf_form_add' );
700 +
701 + $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
702 + $page_id = isset( $_POST['page_id'] ) ? intval( $_POST['page_id'] ) : 0;
703 +
704 + $form = weforms()->form->get( $form_id );
705 + $form_settings = $form->get_settings();
706 + $form_fields = $form->get_fields();
707 + $entry_fields = $form->prepare_entries();
708 + $form_entries = weforms_get_form_entries( $form_id, [ 'number' => '', 'offset' => '' ] );
709 +
710 + if ( $form_fields && count( $form_entries ) && count( $entry_fields ) ) {
711 + foreach ( $entry_fields as $field_key => $field_value ) {
712 + $duplicate_check = false;
713 + $field_label = 'This';
714 +
715 + foreach ( $form_fields as $form_field ) {
716 + if ( in_array( $form_field['template'], [ 'text_field', 'website_url', 'numeric_text_field', 'email_address' ] ) && $form_field['name'] == $field_key && isset( $form_field['duplicate'] ) && 'no' == $form_field['duplicate'] ) {
717 + $duplicate_check = true;
718 + $field_label = $form_field['label'];
719 + }
720 + }
721 +
722 + if ( $duplicate_check ) {
723 + foreach ( $form_entries as $entry ) {
724 + $existing = weforms_get_entry_meta( $entry->id, $field_key, true );
725 +
726 + if ( $existing && $field_value == $existing ) {
727 + wp_send_json( [
728 + 'success' => false,
729 + 'error' => sprintf( __( '"%s" field requires a unique entry and "%s" has already been used.', 'weforms' ), $field_label, $field_value ),
730 + ] );
731 + }
732 + }
733 + }
734 + }
735 + }
736 +
737 + if ( !$form_fields ) {
738 + wp_send_json( [
739 + 'success' => false,
740 + 'error' => __( 'No form field was found.', 'weforms' ),
741 + ] );
742 + }
743 +
744 + if ( $form->has_field( 'recaptcha' ) ) {
745 + $this->validate_reCaptcha();
746 + }
747 +
748 + // vaidate submission
749 + $this->validate_submission( $entry_fields, $form, $form_settings, $form_fields );
750 +
751 + $entry_fields = apply_filters( 'weforms_before_entry_submission', $entry_fields, $form, $form_settings, $form_fields );
752 +
753 + $entry_id = weforms_insert_entry( [
754 + 'form_id' => $form_id,
755 + ], $entry_fields );
756 +
757 + if ( is_wp_error( $entry_id ) ) {
758 + wp_send_json( [
759 + 'success' => false,
760 + 'error' => $entry_id->get_error_message(),
761 + ] );
762 + }
763 +
764 + // redirect URL
765 + $show_message = false;
766 + $redirect_to = false;
767 +
768 + if ( $form_settings['redirect_to'] == 'page' ) {
769 + $redirect_to = get_permalink( $form_settings['page_id'] );
770 + } elseif ( $form_settings['redirect_to'] == 'url' ) {
771 + $redirect_to = $form_settings['url'];
772 + } elseif ( $form_settings['redirect_to'] == 'same' ) {
773 + $show_message = true;
774 + } else {
775 + $redirect_to = get_permalink( $post_id );
776 + }
777 +
778 + // Fire a hook for integration
779 + do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
780 +
781 + $field_search = $field_replace = [];
782 +
783 + foreach ( $form_fields as $r_field ) {
784 + $field_search[] = '{' . $r_field['name'] . '}';
785 +
786 + if ( $r_field['template'] == 'name_field' ) {
787 + $field_replace[] = implode( ' ', explode( '|', $entry_fields[$r_field['name']] ) );
788 + } else {
789 + $field_replace[] = isset( $entry_fields[$r_field['name']] ) ? $entry_fields[$r_field['name']] : '';
790 + }
791 + }
792 + $message = str_replace( $field_search, $field_replace, $form_settings['message'] );
793 +
794 + // send the response
795 + $response = apply_filters( 'weforms_entry_submission_response', [
796 + 'success' => true,
797 + 'redirect_to' => $redirect_to,
798 + 'show_message' => $show_message,
799 + 'message' => $message,
800 + 'data' => $_POST,
801 + 'form_id' => $form_id,
802 + 'entry_id' => $entry_id,
803 + ] );
804 +
805 + $notification = new WeForms_Notification( [
806 + 'form_id' => $form_id,
807 + 'page_id' => $page_id,
808 + 'entry_id' => $entry_id,
809 + ] );
810 +
811 + $notification->send_notifications();
812 +
813 + weforms_clear_buffer();
814 + wp_send_json( $response );
815 + }
816 +
817 + /**
818 + * reCaptcha Validation
819 + *
820 + * @return void
821 + */
822 + function validate_reCaptcha() {
823 + check_ajax_referer( 'wpuf_form_add' );
824 + if ( class_exists( 'WPUF_ReCaptcha' ) ) {
825 + $recaptcha_class = 'WPUF_ReCaptcha';
826 + } else {
827 + if ( !function_exists( 'recaptcha_get_html' ) ) {
828 + require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib.php';
829 + }
830 +
831 + require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib_noCaptcha.php';
832 + $recaptcha_class = 'Weforms_ReCaptcha';
833 + }
834 +
835 + $invisible = isset( $_POST['g-recaptcha-response'] ) ? false : true;
836 +
837 + $recaptcha_settings = weforms_get_settings( 'recaptcha' );
838 + $secret = isset( $recaptcha_settings->secret ) ? $recaptcha_settings->secret : '';
839 +
840 + if ( ! $invisible ) {
841 + $response = null;
842 + $reCaptcha = new $recaptcha_class( $secret );
843 + $remote_ADDR = isset( $_SERVER['REMOTE_ADDR'] ) ? sanitize_text_field( wp_unslash( $_SERVER['REMOTE_ADDR'] ) ) : '';
844 + $recaptcha_response = isset( $_SERVER['g-recaptcha-response'] ) ? sanitize_text_field( wp_unslash( $_POST['g-recaptcha-response'] ) ) : '';
845 + $resp = $reCaptcha->verifyResponse(
846 + $remote_ADDR,
847 + $recaptcha_response
848 + );
849 +
850 + if ( !$resp->success ) {
851 + wp_send_json( [
852 + 'success' => false,
853 + 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
854 + ] );
855 + }
856 + } else {
857 +
858 + $recap_challenge = isset( $_POST['recaptcha_challenge_field'] ) ? sanitize_text_field( wp_unslash( $_POST['recaptcha_challenge_field'] ) ) : '';
859 + $recap_response = isset( $_POST['recaptcha_response_field'] ) ? sanitize_text_field( wp_unslash( $_POST['recaptcha_response_field'] ) ) : '';
860 + $resp = recaptcha_check_answer( $secret, $remote_ADDR, $recap_challenge, $recap_response );
861 +
862 + if ( !$resp->is_valid ) {
863 + ob_clean();
864 +
865 + wp_send_json( [
866 + 'success' => false,
867 + 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
868 + ] );
869 + }
870 + }
871 + }
872 +
873 + /**
874 + * Validate submission
875 + *
876 + * @param array $entry_fields
877 + * @param object $form
878 + * @param array $form_settings
879 + * @param array $form_fields
880 + *
881 + * @return bool|json
882 + */
883 + public function validate_submission( $entry_fields, $form, $form_settings, $form_fields ) {
884 + foreach ( $form_fields as $key => $field ) {
885 +
886 + //skip custom html field as it is not saved
887 + if ( 'custom_html' == $field['name'] ) {
888 + continue;
889 + }
890 +
891 + //skip recaptcha field as it is not saved
892 + if ( 'recaptcha' == $field['name'] ) {
893 + continue;
894 + }
895 +
896 + $value = $entry_fields[ $field['name'] ];
897 +
898 + if ( 'single_product' === $field['template'] ) {
899 + if ( !$value ) {
900 + $value = [];
901 + }
902 +
903 + $value['price'] = isset( $value['price'] ) ? floatval( $value['price'] ) : 0;
904 + $value['quantity'] = isset( $value['quantity'] ) ? floatval( $value['quantity'] ) : 0;
905 + $quantity = isset( $field['quantity'] ) ? $field['quantity'] : [];
906 + $price = isset( $field['price'] ) ? $field['price'] : [];
907 +
908 + if ( isset( $price['is_flexible'] ) && $price['is_flexible'] ) {
909 + $min = isset( $price['min'] ) ? floatval( $price['min'] ) : 0;
910 + $max = isset( $price['max'] ) ? floatval( $price['max'] ) : 0;
911 +
912 + if ( $value['price'] < $min ) {
913 + wp_send_json( [
914 + 'success' => false,
915 + 'error' => __( sprintf(
916 + '%s price must be equal or greater than %s',
917 + $field['weforms'],
918 + $min ),
919 + 'weforms' ),
920 + ] );
921 + }
922 +
923 + if ( $max && $value['price'] > $max ) {
924 + wp_send_json( [
925 + 'success' => false,
926 + 'error' => __( sprintf(
927 + '%s price must be equal or less than %s',
928 + $field['weforms'],
929 + $max ),
930 + 'weforms' ),
931 + ] );
932 + }
933 + }
934 +
935 + if ( isset( $quantity['status'] ) && $quantity['status'] ) {
936 + $min = isset( $quantity['min'] ) ? floatval( $quantity['min'] ) : 0;
937 + $max = isset( $quantity['max'] ) ? floatval( $quantity['max'] ) : 0;
938 +
939 + if ( $value['quantity'] < $min ) {
940 + wp_send_json( [
941 + 'success' => false,
942 + 'error' => __( sprintf(
943 + '%s quantity must be equal or greater than %s',
944 + $field['weforms'],
945 + $min ),
946 + 'weforms' ),
947 + ] );
948 + }
949 +
950 + if ( $max && $value['quantity'] > $max ) {
951 + wp_send_json( [
952 + 'success' => false,
953 + 'error' => __( sprintf(
954 + '%s quantity must be equal or less than %s',
955 + $field['weforms'],
956 + $max ),
957 + 'weforms' ),
958 + ] );
959 + }
960 + }
961 + }
962 + }
963 + }
964 +
965 + public static function prepare_meta_fields( $meta_vars ) {
966 + check_ajax_referer( 'wpuf_form_add' );
967 + // loop through custom fields
968 + // skip files, put in a key => value paired array for later executation
969 + // process repeatable fields separately
970 + // if the input is array type, implode with separator in a field
971 + $files = [];
972 + $meta_key_value = [];
973 + $multi_repeated = []; // multi repeated fields will in sotre duplicated meta key
974 +
975 + foreach ( $meta_vars as $key => $value ) {
976 + switch ( $value['template'] ) {
977 +
978 + // put files in a separate array, we'll process it later
979 + case 'file_upload':
980 + case 'image_upload':
981 + $files[] = [
982 + 'name' => $value['name'],
983 + 'value' => isset( $_POST['wpuf_files'][ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST['wpuf_files'][ $value['name'] ] ) ) : array(),
984 + 'count' => $value['count']
985 + ];
986 + break;
987 +
988 + case 'repeat_field':
989 + // if it is a multi column repeat field
990 + if ( isset( $value['multiple'] ) && $value['multiple'] == 'true' ) {
991 +
992 + // if there's any items in the array, process it
993 + if ( isset( $_POST[ $value['name'] ] ) ) {
994 + $ref_arr = [];
995 + $cols = count( $value['columns'] );
996 + $first = array_shift( array_values( sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) ) ); // first element
997 + $rows = count( $first );
998 +
999 + // loop through columns
1000 + for ( $i = 0; $i < $rows; $i++ ) {
1001 +
1002 + // loop through the rows and store in a temp array
1003 + $temp = [];
1004 + for ( $j = 0; $j < $cols; $j++ ) {
1005 + $temp[] = isset( $_POST[ $value['name'] ][ $j ][ $i ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ][ $j ][ $i ] ) ) : '';
1006 + }
1007 +
1008 + // store all fields in a row with WeForms::$field_separator separated
1009 + $ref_arr[] = implode( WeForms::$field_separator, $temp );
1010 + }
1011 +
1012 + // now, if we found anything in $ref_arr, store to $multi_repeated
1013 + if ( $ref_arr ) {
1014 + $multi_repeated[ $value['name'] ] = array_slice( $ref_arr, 0, $rows );
1015 + }
1016 + }
1017 + } else {
1018 + $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) );
1019 + }
1020 +
1021 + break;
1022 +
1023 + case 'address_field':
1024 + if ( isset( $_POST[ $value['name'] ] ) && is_array( $_POST[ $value['name'] ] ) ) {
1025 + $post_value = sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) );
1026 + foreach ( $post_value as $address_field => $field_value ) {
1027 + $meta_key_value[ $value['name'] ][ $address_field ] = sanitize_text_field( $field_value );
1028 + }
1029 + }
1030 +
1031 + break;
1032 +
1033 + case 'text_field':
1034 + case 'email_address':
1035 + case 'numeric_text_field':
1036 + case 'date_field':
1037 + $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : '';
1038 +
1039 + break;
1040 +
1041 + case 'textarea_field':
1042 + $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : '';
1043 +
1044 + break;
1045 +
1046 + case 'dropdown_field':
1047 + case 'radio_field':
1048 + $val = sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) );
1049 + $meta_key_value[ $value['name'] ] = isset( $value['options'][ $val ] ) ? $value['options'][ $val ] : '';
1050 + break;
1051 +
1052 + case 'multiple_select':
1053 + case 'checkbox_field':
1054 + $val = ( is_array( $_POST[ $value['name'] ] ) && sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : array();
1055 + $meta_key_value[ $value['name'] ] = $val;
1056 +
1057 + if ( $val ) {
1058 + $new_val = [];
1059 +
1060 + foreach ( $val as $option_key ) {
1061 + $new_val[] = isset( $value['options'][ $option_key ] ) ? $value['options'][ $option_key ] : '';
1062 + }
1063 +
1064 + $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, $new_val );
1065 + }
1066 + break;
1067 +
1068 + default:
1069 + // if it's an array, implode with this->separator
1070 + if ( is_array( $_POST[ $value['name'] ] ) ) {
1071 + $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) );
1072 + } else {
1073 + $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ): '';
1074 + }
1075 +
1076 + break;
1077 + }
1078 + } //end foreach
1079 +
1080 + return [ $meta_key_value, $multi_repeated, $files ];
1081 + }
1082 +
1083 + /**
1084 + * Import a form from a JSON file
1085 + *
1086 + * @return void
1087 + */
1088 + public function import_form() {
1089 + check_ajax_referer( 'weforms' );
1090 +
1091 + $this->check_admin();
1092 +
1093 + $the_file = isset( $_FILES['importFile'] ) ? sanitize_text_field( wp_unslash( $_FILES['importFile'] ) ) : false;
1094 +
1095 + if ( !$the_file ) {
1096 + wp_send_json_error( __( 'No file found to import.', 'weforms' ) );
1097 + }
1098 +
1099 + $file_ext = pathinfo( $the_file['name'], PATHINFO_EXTENSION );
1100 +
1101 + if ( !class_exists( 'WeForms_Admin_Tools' ) ) {
1102 + require_once __DIR__ . '/admin/class-admin-tools.php';
1103 + }
1104 +
1105 + if ( ( $file_ext == 'json' ) && ( $the_file['size'] < 500000 ) ) {
1106 + $status = WeForms_Admin_Tools::import_json_file( $the_file['tmp_name'] );
1107 +
1108 + if ( $status ) {
1109 + wp_send_json_success( __( 'The forms have been imported successfully!', 'weforms' ) );
1110 + } else {
1111 + wp_send_json_error( __( 'Something went wrong importing the file.', 'weforms' ) );
1112 + }
1113 + } else {
1114 + wp_send_json_error( __( 'Invalid file or file size too big.', 'weforms' ) );
1115 + }
1116 + }
1117 +
1118 + /**
1119 + * Read Log file
1120 + *
1121 + * @return json
1122 + **/
1123 + public function get_logs() {
1124 + check_ajax_referer( 'weforms' );
1125 +
1126 + $this->check_admin();
1127 +
1128 + $file = weforms_log_file_path();
1129 +
1130 + if ( !file_exists( $file ) ) {
1131 + return;
1132 + }
1133 +
1134 + $data = file_get_contents( $file );
1135 + $data = explode( "\n", $data );
1136 + $data = array_reverse( $data );
1137 + $data = array_filter( $data );
1138 +
1139 + if ( empty( $data ) ) {
1140 + return;
1141 + }
1142 +
1143 + $logs = [];
1144 +
1145 + foreach ( $data as $key => $row ) {
1146 + preg_match( '/\[(?<time>.+?)\]\[(?<type>.+?)\](?<message>.+)/im', $row, $log );
1147 +
1148 + if ( empty( $log['message'] ) ) {
1149 + $log = [];
1150 + $log['message'] = !empty( $log['message'] ) ? $log['message'] : $row;
1151 + }
1152 +
1153 + if ( !empty( $log['time'] ) ) {
1154 + $human_time = human_time_diff( strtotime( $log['time'] ), current_time( 'timestamp' ) );
1155 + $log['time'] = $human_time ? $human_time . ' ' . __( 'ago', 'weforms' ) : $log['time'];
1156 + }
1157 +
1158 + $logs[] = $log;
1159 + }
1160 +
1161 + wp_send_json_success( $logs );
1162 + }
1163 +
1164 + /**
1165 + * Read Log file
1166 + *
1167 + * @return json
1168 + **/
1169 + public function delete_logs() {
1170 + check_ajax_referer( 'weforms' );
1171 +
1172 + $this->check_admin();
1173 +
1174 + $file = weforms_log_file_path();
1175 +
1176 + if ( !file_exists( $file ) ) {
1177 + return;
1178 + }
1179 +
1180 + @unlink( $file );
1181 +
1182 + wp_send_json_success();
1183 + }
1184 +}