PluginProbe
weForms – Easy Drag & Drop Contact Form Builder For WordPress / 1.4.9
weForms – Easy Drag & Drop Contact Form Builder For WordPress v1.4.9
1.6.7 1.6.8 1.6.9 1.6.12 1.6.13 1.6.14 1.6.15 1.6.16 1.6.17 1.6.18 1.6.19 1.6.2 1.6.20 1.6.21 1.6.22 1.6.23 1.6.24 1.6.25 1.6.26 1.6.27 1.6.28 1.6.3 1.6.4 1.6.5 1.6.6 All 74 releases
← All changes | includes/class-ajax.php +1227 -1228 1.6.131.4.9 View file →
@@ -1,1228 +1,1227 @@
1 -<?php
2 -
3 -/**
4 - * The ajax handler class
5 - */
6 -class WeForms_Ajax {
7 -
8 - public function __construct() {
9 -
10 - // backend requests
11 - add_action( 'wp_ajax_weforms_form_list', [ $this, 'get_contact_forms' ] );
12 - add_action( 'wp_ajax_weforms_get_users', [ $this, 'get_all_users' ] );
13 - add_action( 'wp_ajax_weforms_form_names', [ $this, 'get_contact_form_names' ] );
14 - add_action( 'wp_ajax_weforms_form_create', [ $this, 'create_form' ] );
15 - add_action( 'wp_ajax_weforms_form_delete', [ $this, 'delete_form' ] );
16 - add_action( 'wp_ajax_weforms_form_delete_bulk', [ $this, 'delete_form_bulk' ] );
17 - add_action( 'wp_ajax_weforms_form_duplicate', [ $this, 'duplicate_form' ] );
18 -
19 - // read logs
20 - add_action( 'wp_ajax_weforms_read_logs', [ $this, 'get_logs' ] );
21 - add_action( 'wp_ajax_weforms_delete_logs', [ $this, 'delete_logs' ] );
22 -
23 - // create from a template
24 - add_filter( 'wp_ajax_weforms_contact_form_template', [ $this, 'create_form_from_template' ] );
25 -
26 - // form settings
27 - add_action( 'wp_ajax_weforms_save_settings', [ $this, 'save_settings' ] );
28 - add_action( 'wp_ajax_weforms_get_settings', [ $this, 'get_settings' ] );
29 -
30 - // import
31 - add_action( 'wp_ajax_weforms_import_form', [ $this, 'import_form' ] );
32 -
33 - // form editing
34 - add_action( 'wp_ajax_weforms_get_form', [ $this, 'get_form' ] );
35 - add_action( 'wp_ajax_wpuf_form_builder_save_form', [ $this, 'save_form' ] );
36 -
37 - // entries
38 - add_action( 'wp_ajax_weforms_form_entries', [ $this, 'get_entries' ] );
39 -
40 - add_action( 'wp_ajax_weforms_form_entry_details', [ $this, 'get_entry_detail' ] );
41 - add_action( 'wp_ajax_weforms_form_entry_trash', [ $this, 'trash_entry' ] );
42 - add_action( 'wp_ajax_weforms_form_entry_delete', [ $this, 'delete_entry' ] );
43 - add_action( 'wp_ajax_weforms_form_entry_restore', [ $this, 'restore_entry' ] );
44 -
45 - add_action( 'wp_ajax_weforms_form_entry_trash_bulk', [ $this, 'bulk_delete_entry' ] );
46 - add_action( 'wp_ajax_weforms_form_entry_restore_bulk', [ $this, 'bulk_restore_entry' ] );
47 -
48 - // frontend requests
49 - add_action( 'wp_ajax_weforms_frontend_submit', [ $this, 'handle_frontend_submission' ] );
50 - add_action( 'wp_ajax_nopriv_weforms_frontend_submit', [ $this, 'handle_frontend_submission' ] );
51 - }
52 -
53 - /**
54 - * Administrator validation
55 - *
56 - * @return void
57 - */
58 - public function check_admin() {
59 - if ( !current_user_can( weforms_form_access_capability() ) ) {
60 - wp_send_json_error( __( 'You do not have sufficient permission.', 'weforms' ) );
61 - }
62 - }
63 -
64 - /**
65 - * Get a form to edit
66 - *
67 - * @return void
68 - */
69 - public function get_form() {
70 - $this->check_admin();
71 -
72 - $form_id = isset( $_REQUEST['form_id'] ) ? absint( $_REQUEST['form_id'] ) : 0;
73 -
74 - $form = weforms()->form->get( $form_id );
75 -
76 - $data = [
77 - 'post' => $form->data,
78 - 'form_fields' => $form->get_fields(),
79 - 'settings' => $form->get_settings(),
80 - 'notifications' => $form->get_notifications(),
81 - 'integrations' => $form->get_integrations(),
82 - ];
83 -
84 - wp_send_json_success( $data );
85 - }
86 -
87 - /**
88 - * Save the form
89 - *
90 - * @return void
91 - */
92 - public function save_form() {
93 - $post_data = wp_unslash( $_POST );
94 - if ( isset( $post_data['form_data'] ) ) {
95 - parse_str( sanitize_text_field( wp_unslash( $post_data['form_data'] ) ), $form_data );
96 - }
97 -
98 - if ( !wp_verify_nonce( $form_data['wpuf_form_builder_nonce'], 'wpuf_form_builder_save_form' ) ) {
99 - wp_send_json_error( __( 'Unauthorized operation', 'weforms' ) );
100 - }
101 -
102 - if ( empty( $form_data['wpuf_form_id'] ) ) {
103 - wp_send_json_error( __( 'Invalid form id', 'weforms' ) );
104 - }
105 -
106 - $form_fields = isset( $post_data['form_fields'] ) ? $post_data['form_fields'] : '';
107 - $notifications = isset( $post_data['notifications'] ) ? $post_data['notifications']: '';
108 - $settings = array();
109 - $integrations = array();
110 -
111 - if ( isset( $post_data['settings'] ) ) {
112 - $settings = (array) json_decode( $post_data['settings'] );
113 - } else {
114 - $settings = isset( $form_data['wpuf_settings'] ) ? $form_data['wpuf_settings'] : [];
115 - }
116 -
117 - if ( isset( $post_data['integrations'] ) ) {
118 - $integrations = (array) json_decode( $post_data['integrations'] );
119 - }
120 -
121 - $form_fields = json_decode( $form_fields, true );
122 - $notifications = json_decode( $notifications, true );
123 - $data = [
124 - 'form_id' => absint( $form_data['wpuf_form_id'] ),
125 - 'post_title' => $form_data['post_title'],
126 - 'form_fields' => $form_fields,
127 - 'form_settings' => $settings,
128 - 'form_settings_key' => isset( $form_data['form_settings_key'] ) ? $form_data['form_settings_key'] : '',
129 - 'notifications' => $notifications,
130 - 'integrations' => $integrations,
131 - ];
132 -
133 - $form_fields = weforms()->form->save( $data );
134 -
135 - // Update Old Entry meta_key if changed
136 - $form_id = $form_data['wpuf_form_id'];
137 - $form = weforms()->form->get( $form_id );
138 -
139 - $form->maybe_update_entries( $form_fields );
140 -
141 - do_action( 'weforms_update_form', $form_data['wpuf_form_id'], $form_fields, $settings );
142 -
143 - wp_send_json_success( [ 'form_fields' => $form_fields ] );
144 - }
145 -
146 - /**
147 - * Get all contact forms
148 - *
149 - * @return void
150 - */
151 - public function get_contact_forms() {
152 - check_ajax_referer( 'weforms' );
153 -
154 - $this->check_admin();
155 -
156 - $args = [
157 - 'posts_per_page' => isset( $_POST['posts_per_page'] ) ? intval( $_POST['posts_per_page'] ) : 10,
158 - 'paged' => isset( $_POST['page'] ) ? absint( $_POST['page'] ) : 1,
159 - 'order' => 'DESC',
160 - 'orderby' => 'post_date',
161 - ];
162 -
163 - $args = apply_filters( 'weforms_ajax_get_contact_forms_args', $args );
164 -
165 - $contact_forms = weforms()->form->get_forms( $args );
166 -
167 - array_map(
168 - function ( $form ) {
169 - $form->entries = $form->num_form_entries();
170 - $form->settings = $form->get_settings();
171 - $form->views = $form->num_form_views();
172 - $form->payments = $form->num_form_payments();
173 - $form->author = $form->get_form_author_details();
174 - }, $contact_forms['forms']
175 - );
176 -
177 - $contact_forms = $this->filter_contact_forms( $contact_forms );
178 - $contact_forms = apply_filters( 'weforms_ajax_get_contact_forms', $contact_forms );
179 -
180 - wp_send_json_success( $contact_forms );
181 - }
182 -
183 - /**
184 - * Get all users
185 - *
186 - * @return array
187 - */
188 - public function get_all_users() {
189 - check_ajax_referer( 'weforms' );
190 -
191 - $this->check_admin();
192 -
193 - $users_meta = [];
194 - $users = get_users( [ 'fields' => [ 'ID' ] ] );
195 -
196 - foreach ( $users as $user ) {
197 - $users_meta[] = [
198 - 'id' => $user->ID,
199 - 'data' => get_user_meta( $user->ID ),
200 - ];
201 - }
202 -
203 - wp_send_json_success( $users_meta );
204 - }
205 -
206 - /**
207 - * Filter
208 - *
209 - * @return void
210 - */
211 - public function filter_contact_forms( &$contact_forms ) {
212 - if ( isset( $_REQUEST['filter'] ) && $_REQUEST['filter'] == 'entries' ) {
213 - foreach ( $contact_forms['forms'] as $key => &$form ) {
214 - if ( isset( $form->entries ) && !$form->entries ) {
215 - unset( $contact_forms['forms'][ $key ] );
216 - }
217 - }
218 -
219 - $contact_forms['meta']['total'] = count( $contact_forms['forms'] );
220 - }
221 -
222 - return $contact_forms;
223 - }
224 -
225 - /**
226 - * Get the names of contact forms for generating dropdown
227 - *
228 - * @return void
229 - */
230 - public function get_contact_form_names() {
231 - check_ajax_referer( 'weforms' );
232 -
233 - $this->check_admin();
234 -
235 - $contact_forms = weforms()->form->all();
236 - $response = [];
237 -
238 - foreach ( $contact_forms['forms'] as $form ) {
239 - $response[] = [
240 - 'id' => $form->get_id(),
241 - 'title' => $form->get_name() . ' (#' . $form->get_id() . ')',
242 - ];
243 - }
244 -
245 - wp_send_json_success( $response );
246 - }
247 -
248 - /**
249 - * Create a form
250 - *
251 - * @return void
252 - */
253 - public function create_form() {
254 - check_ajax_referer( 'weforms' );
255 -
256 - $this->check_admin();
257 -
258 - $form_name = isset( $_POST['form_name'] ) ? sanitize_text_field( wp_unslash( $_POST['form_name'] ) ) : '';
259 -
260 - if ( empty( $form_name ) ) {
261 - wp_send_json_error( __( 'Please provide a form name', 'weforms' ) );
262 - }
263 -
264 - $form_id = weforms()->form->create( $form_name );
265 -
266 - if ( is_wp_error( $form_id ) ) {
267 - wp_send_json_error( $form_id->get_error_message() );
268 - }
269 -
270 - wp_send_json_success( [
271 - 'form_id' => $form_id,
272 - 'form_name' => $form_name,
273 - ] );
274 - }
275 -
276 - /**
277 - * Delete a form
278 - *
279 - * @return void
280 - */
281 - public function delete_form() {
282 - check_ajax_referer( 'weforms' );
283 -
284 - $this->check_admin();
285 -
286 - $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
287 -
288 - if ( !$form_id ) {
289 - wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
290 - }
291 -
292 - weforms()->form->delete( $form_id );
293 -
294 - wp_send_json_success();
295 - }
296 -
297 - public function delete_form_bulk() {
298 - check_ajax_referer( 'weforms' );
299 -
300 - $this->check_admin();
301 -
302 - $form_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : [];
303 -
304 - if ( !$form_ids ) {
305 - wp_send_json_error( __( 'No form ids provided!', 'weforms' ) );
306 - }
307 -
308 - foreach ( $form_ids as $form_id ) {
309 - weforms()->form->delete( $form_id );
310 - }
311 -
312 - wp_send_json_success();
313 - }
314 -
315 - /**
316 - * Duplicate a form
317 - *
318 - * @return voiud
319 - */
320 - public function duplicate_form() {
321 - check_ajax_referer( 'weforms' );
322 -
323 - $this->check_admin();
324 -
325 - $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
326 -
327 - $form = weforms()->form->duplicate( $form_id );
328 - $form->settings = $form->get_settings();
329 -
330 - wp_send_json_success( $form );
331 - }
332 -
333 - /**
334 - * Create form from a template
335 - *
336 - * @return void
337 - */
338 - public function create_form_from_template() {
339 - check_ajax_referer( 'weforms' );
340 -
341 - $template = isset( $_REQUEST['template'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['template'] ) ) : '';
342 -
343 - $form_id = weforms()->templates->create( $template );
344 -
345 - if ( is_wp_error( $form_id ) ) {
346 - wp_send_json_error( __( 'Could not create the form', 'weforms' ) );
347 - }
348 -
349 - wp_send_json_success( [
350 - 'id' => $form_id,
351 - ] );
352 - }
353 -
354 - /**
355 - * Save the weForms settings
356 - *
357 - * @return void
358 - */
359 - public function save_settings() {
360 - check_ajax_referer( 'weforms' );
361 - $this->check_admin();
362 -
363 - $requires_wpuf_update = false;
364 - $wpuf_update_array = array();
365 - $settings = isset( $_POST['settings'] ) ? (array) json_decode( wp_unslash( $_POST['settings'] ) ) : [];
366 - update_option( 'weforms_settings', $settings );
367 -
368 - // wpuf settings sync
369 - if ( isset( $settings['gmap_api'] ) ) {
370 - $requires_wpuf_update = true;
371 - $wpuf_update_array['gmap_api_key'] = $settings['gmap_api'];
372 - }
373 -
374 - if ( isset( $settings['recaptcha'] ) ) {
375 - $requires_wpuf_update = true;
376 - $wpuf_update_array['recaptcha_public'] = $settings['recaptcha']->key;
377 - $wpuf_update_array['recaptcha_private'] = $settings['recaptcha']->secret;
378 - $wpuf_update_array['recaptcha_type'] = $settings['recaptcha']->type;
379 - }
380 -
381 - if ( isset( $settings['no_conflict'] ) ) {
382 - $requires_wpuf_update = true;
383 - $wpuf_update_array['no_conflict'] = $settings['no_conflict'];
384 - }
385 -
386 - if ( isset( $settings['email_footer'] ) ) {
387 - $requires_wpuf_update = true;
388 - $wpuf_update_array['email_footer'] = $settings['email_footer'];
389 - }
390 -
391 - if ( $requires_wpuf_update ) {
392 - $wpuf_settings = get_option( 'wpuf_general', [] );
393 -
394 - $wpuf_settings = array_merge( $wpuf_settings, $wpuf_update_array );
395 - update_option( 'wpuf_general', $wpuf_settings );
396 - }
397 -
398 - do_action( 'weforms_save_settings', $settings );
399 -
400 - $settings = apply_filters( 'weforms_after_save_settings', $settings );
401 - wp_send_json_success( $settings );
402 - }
403 -
404 - /**
405 - * Get the weForms Settings
406 - *
407 - * @return void
408 - */
409 - public function get_settings() {
410 - check_ajax_referer( 'weforms' );
411 -
412 - $this->check_admin();
413 -
414 - $settings = weforms_get_settings();
415 - // checking to prevent js error, will be removed in future
416 - if ( !isset( $settings['credit'] ) ) {
417 - $settings['credit'] = false;
418 - }
419 -
420 - if ( !isset( $settings['permission'] ) ) {
421 - $settings['permission'] = 'manage_options';
422 - }
423 -
424 - wp_send_json_success( $settings );
425 - }
426 -
427 - /**
428 - * Get all entries
429 - *
430 - * @return void
431 - */
432 - public function get_entries() {
433 - check_ajax_referer( 'weforms' );
434 -
435 - $this->check_admin();
436 -
437 - $form_id = isset( $_REQUEST['id'] ) ? intval( $_REQUEST['id'] ) : 0;
438 - $current_page = isset( $_REQUEST['page'] ) ? intval( $_REQUEST['page'] ) : 1;
439 - $status = isset( $_REQUEST['status'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['status'] ) ) : 'publish';
440 - $per_page = 20;
441 - $offset = ( $current_page - 1 ) * $per_page;
442 -
443 - if ( !$form_id ) {
444 - wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
445 - }
446 -
447 - $entries = weforms_get_form_entries(
448 - $form_id, [
449 - 'number' => $per_page,
450 - 'offset' => $offset,
451 - 'status' => $status,
452 - ]
453 - );
454 -
455 - $columns = weforms_get_entry_columns( $form_id );
456 - $total_entries = weforms_count_form_entries( $form_id, $status );
457 -
458 - array_map(
459 - function ( $entry ) use ( $columns ) {
460 - $entry_id = $entry->id;
461 - $entry->fields = [];
462 -
463 - foreach ( $columns as $meta_key => $label ) {
464 - if ( empty( $meta_key ) ) {
465 - continue;
466 - }
467 - $value = weforms_get_entry_meta( $entry_id, $meta_key, true );
468 - $entry->fields[ $meta_key ] = str_replace( WeForms::$field_separator, ' ', $value );
469 - }
470 - }, $entries
471 - );
472 -
473 - $entries = apply_filters( 'weforms_get_entries', $entries, $form_id );
474 -
475 - $response = [
476 - 'columns' => $columns,
477 - 'entries' => $entries,
478 - 'form_title' => get_post_field( 'post_title', $form_id ),
479 - 'pagination' => [
480 - 'total' => $total_entries,
481 - 'per_page' => $per_page,
482 - 'pages' => ceil( $total_entries / $per_page ),
483 - 'current' => $current_page,
484 - ],
485 - 'meta' => [
486 - 'total' => weforms_count_form_entries( $form_id ),
487 - 'totalTrash' => weforms_count_form_entries( $form_id, 'trash' ),
488 - ],
489 - ];
490 -
491 - wp_send_json_success( $response );
492 - }
493 -
494 - /**
495 - * Get an entry details
496 - *
497 - * @return void
498 - */
499 - public function get_entry_detail() {
500 - check_ajax_referer( 'weforms' );
501 -
502 - $this->check_admin();
503 -
504 - $form_id = isset( $_REQUEST['form_id'] ) ? intval( $_REQUEST['form_id'] ) : 0;
505 - $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
506 -
507 - $form = weforms()->form->get( $form_id );
508 - $form_settings = $form->get_settings();
509 - $entry = $form->entries()->get( $entry_id );
510 - $fields = $entry->get_fields();
511 - $metadata = $entry->get_metadata();
512 - $payment = $entry->get_payment_data();
513 -
514 - if ( isset( $payment->payment_data ) && is_serialized( $payment->payment_data ) ) {
515 - $payment->payment_data = unserialize( $payment->payment_data );
516 - }
517 -
518 - if ( false === $fields ) {
519 - wp_send_json_error( __( 'No form fields found!', 'weforms' ) );
520 - }
521 -
522 - if ( sizeof( $fields ) < 1 ) {
523 - $fields[] = [
524 - 'label' => __( 'No form fields found!', 'weforms' ),
525 - ];
526 - }
527 -
528 - $has_empty = false;
529 - $answers = [];
530 - $respondentPoints = isset( $form_settings['total_points'] ) ? floatval( $form_settings['total_points'] ) : 0;
531 - $fields_formatted = array();
532 - foreach ( $fields as $key => $field ) {
533 - if ( $form_settings['quiz_form'] == 'yes' ) {
534 - $selectedAnswers = isset( $field['selected_answers'] ) ? $field['selected_answers'] : '';
535 - $givenAnswer = isset( $field['value'] ) ? $field['value'] : '';
536 - $options = isset( $field['options'] ) ? $field['options'] : '';
537 - $template = $field['template'];
538 - $fieldPoints = isset( $field['points'] ) ? floatval( $field['points'] ) : 0;
539 -
540 - if ( $template == 'radio_field' || $template == 'dropdown_field' ) {
541 - $answers[$field['name']] = true;
542 - if ( empty( $givenAnswer ) ) {
543 - $answers[$field['name']] = false;
544 - $respondentPoints -= $fieldPoints;
545 - } else {
546 - foreach ( $options as $key => $value ) {
547 - if ( $givenAnswer == $value ) {
548 - if ( $key != $selectedAnswers ) {
549 - $answers[$field['name']] = false;
550 - $respondentPoints -= $fieldPoints;
551 - }
552 - }
553 - }
554 - }
555 - } elseif ( $template == 'checkbox_field' || $template == 'multiple_select' ) {
556 - $answers[$field['name']] = true;
557 - $userAnswer = [];
558 -
559 - foreach ( $options as $key => $value ) {
560 - foreach ( $givenAnswer as $answer ) {
561 - if ( $value == $answer ) {
562 - $userAnswer[] = $key;
563 - }
564 - }
565 - }
566 -
567 - $userAnswer = implode( '|', $userAnswer );
568 - $rightAnswers = implode( '|', $selectedAnswers );
569 -
570 - if ( $userAnswer != $rightAnswers || empty( $userAnswer ) ) {
571 - $answers[$field['name']] = false;
572 - $respondentPoints -= $fieldPoints;
573 - }
574 - }
575 - } elseif ( empty( $field['value'] ) ) {
576 - $has_empty = true;
577 - break;
578 - } else {
579 - $field = WeForms_Form_Entry_Manager::format_entry_value( $field );
580 - array_push( $fields_formatted, $field );
581 - }
582 - }
583 - $response = [
584 - 'form_fields' => $fields_formatted,
585 - 'form_settings' => $form_settings,
586 - 'meta_data' => $metadata,
587 - 'payment_data' => $payment,
588 - 'has_empty' => $has_empty,
589 - 'respondent_points' => $respondentPoints,
590 - 'answers' => $answers,
591 - ];
592 -
593 -
594 - wp_send_json_success( $response );
595 - }
596 -
597 - /**
598 - * Trash an entry
599 - *
600 - * @return void
601 - */
602 - public function trash_entry() {
603 - check_ajax_referer( 'weforms' );
604 -
605 - $this->check_admin();
606 -
607 - $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
608 -
609 - weforms_change_entry_status( $entry_id, 'trash' );
610 - wp_send_json_success();
611 - }
612 -
613 - /**
614 - * Trash an entry
615 - *
616 - * @return void
617 - */
618 - public function delete_entry() {
619 - check_ajax_referer( 'weforms' );
620 -
621 - $this->check_admin();
622 -
623 - $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
624 -
625 - weforms_delete_entry( $entry_id );
626 -
627 - wp_send_json_success();
628 - }
629 -
630 - /**
631 - * Restore Entry
632 - *
633 - * @return void
634 - */
635 - public function restore_entry() {
636 - check_ajax_referer( 'weforms' );
637 -
638 - $this->check_admin();
639 -
640 - $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
641 -
642 - weforms_change_entry_status( $entry_id, 'publish' );
643 - wp_send_json_success();
644 - }
645 -
646 - /**
647 - * Bulk trash entries
648 - *
649 - * @return void
650 - */
651 - public function bulk_delete_entry() {
652 - check_ajax_referer( 'weforms' );
653 -
654 - $this->check_admin();
655 -
656 - $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : array();
657 - $permanent = isset( $_POST['permanent'] ) && ( sanitize_text_field( wp_unslash ( $_POST['permanent'] ) ) ) ? true : false;
658 -
659 - if ( !$entry_ids ) {
660 - wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
661 - }
662 -
663 - foreach ( $entry_ids as $entry_id ) {
664 - if ( $permanent ) {
665 - weforms_delete_entry( $entry_id );
666 - } else {
667 - weforms_change_entry_status( $entry_id, 'trash' );
668 - }
669 - }
670 -
671 - wp_send_json_success();
672 - }
673 -
674 - /**
675 - * Bulk trash entries
676 - *
677 - * @return void
678 - */
679 - public function bulk_restore_entry() {
680 - check_ajax_referer( 'weforms' );
681 -
682 - $this->check_admin();
683 -
684 - $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : [];
685 -
686 - if ( !$entry_ids ) {
687 - wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
688 - }
689 -
690 - foreach ( $entry_ids as $entry_id ) {
691 - weforms_change_entry_status( $entry_id, 'publish' );
692 - }
693 -
694 - wp_send_json_success();
695 - }
696 -
697 - /**
698 - * Handle the frontend submission
699 - *
700 - * @return void
701 - */
702 - public function handle_frontend_submission() {
703 - check_ajax_referer( 'wpuf_form_add' );
704 -
705 - $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
706 - $page_id = isset( $_POST['page_id'] ) ? intval( $_POST['page_id'] ) : 0;
707 -
708 - $form = weforms()->form->get( $form_id );
709 - $form_settings = $form->get_settings();
710 - $form_fields = $form->get_fields();
711 - $entry_fields = $form->prepare_entries();
712 - $form_entries = weforms_get_form_entries( $form_id, [ 'number' => '', 'offset' => '' ] );
713 -
714 - if ( $form_fields && count( $form_entries ) && count( $entry_fields ) ) {
715 - foreach ( $entry_fields as $field_key => $field_value ) {
716 - $duplicate_check = false;
717 - $field_label = 'This';
718 -
719 - foreach ( $form_fields as $form_field ) {
720 - if ( in_array( $form_field['template'], [ 'text_field', 'website_url', 'numeric_text_field', 'email_address' ] ) && $form_field['name'] == $field_key && isset( $form_field['duplicate'] ) && 'no' == $form_field['duplicate'] ) {
721 - $duplicate_check = true;
722 - $field_label = $form_field['label'];
723 - }
724 - }
725 -
726 - if ( $duplicate_check ) {
727 - foreach ( $form_entries as $entry ) {
728 - $existing = weforms_get_entry_meta( $entry->id, $field_key, true );
729 -
730 - if ( $existing && $field_value == $existing ) {
731 - wp_send_json( [
732 - 'success' => false,
733 - 'error' => sprintf( __( '"%s" field requires a unique entry and "%s" has already been used.', 'weforms' ), $field_label, $field_value ),
734 - ] );
735 - }
736 - }
737 - }
738 - }
739 - }
740 -
741 - if ( !$form_fields ) {
742 - wp_send_json( [
743 - 'success' => false,
744 - 'error' => __( 'No form field was found.', 'weforms' ),
745 - ] );
746 - }
747 -
748 - if ( $form->has_field( 'recaptcha' ) ) {
749 - $settings = weforms_get_settings( 'recaptcha' );
750 - $type = isset( $settings->type ) ? $settings->type : '';
751 - $secret = isset( $settings->secret ) ? $settings->secret : '';
752 - if( $type == 'v3' ) {
753 - $this->validate_reCaptchav3( $secret );
754 - } else {
755 - $this->validate_reCaptcha();
756 - }
757 - }
758 -
759 - // vaidate submission
760 - $this->validate_submission( $entry_fields, $form, $form_settings, $form_fields );
761 -
762 - $entry_fields = apply_filters( 'weforms_before_entry_submission', $entry_fields, $form, $form_settings, $form_fields );
763 -
764 - $entry_id = 1;
765 - $global_settings = weforms_get_settings();
766 - if ( empty( $form_settings['after_submission'] ) ) {
767 - $entry_id = weforms_insert_entry( [
768 - 'form_id' => $form_id,
769 - ], $entry_fields );
770 - if ( is_wp_error( $entry_id ) ) {
771 - wp_send_json( [
772 - 'success' => false,
773 - 'error' => $entry_id->get_error_message(),
774 - ] );
775 - }
776 - // Fire a hook for integration
777 - do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
778 - $notification = new WeForms_Notification( [
779 - 'form_id' => $form_id,
780 - 'page_id' => $page_id,
781 - 'entry_id' => $entry_id,
782 - ] );
783 - $notification->send_notifications();
784 - }
785 - // redirect URL
786 - $show_message = false;
787 - $redirect_to = false;
788 - if ( $form_settings['redirect_to'] == 'page' ) {
789 - $redirect_to = get_permalink( $form_settings['page_id'] );
790 - } elseif ( $form_settings['redirect_to'] == 'url' ) {
791 - $redirect_to = $form_settings['url'];
792 - } elseif ( $form_settings['redirect_to'] == 'same' ) {
793 - $show_message = true;
794 - } else {
795 - $show_message = true;
796 - }
797 - $field_search = $field_replace = [];
798 - foreach ( $form_fields as $r_field ) {
799 - $field_search[] = '{' . $r_field['name'] . '}';
800 - if ( $r_field['template'] == 'name_field' ) {
801 - $field_replace[] = implode( ' ', explode( '|', $entry_fields[ $r_field['name'] ] ) );
802 - } else if ( $r_field['template'] == 'address_field' ) {
803 - $field_replace[] = implode( ', ', $entry_fields[ $r_field['name'] ] );
804 - } else {
805 - $field_replace[] = isset( $entry_fields[ $r_field['name'] ] ) ? $entry_fields[ $r_field['name'] ] : '';
806 - }
807 - }
808 - $message = str_replace( $field_search, $field_replace, $form_settings['message'] );
809 - // send the response
810 - $response = apply_filters( 'weforms_entry_submission_response', [
811 - 'success' => true,
812 - 'redirect_to' => $redirect_to,
813 - 'show_message' => $show_message,
814 - 'message' => $message,
815 - 'data' => $_POST,
816 - 'form_id' => $form_id,
817 - 'entry_id' => $entry_id,
818 - 'entry_fields' =>$entry_fields,
819 - ] );
820 - weforms_clear_buffer();
821 - wp_send_json( $response );
822 - }
823 -
824 - function validate_reCaptchav3( $secret ) {
825 - check_ajax_referer( 'wpuf_form_add' );
826 -
827 - $post_data = wp_unslash($_POST);
828 - $token = $post_data['g-recaptcha-response'];
829 - $action = $post_data['g-action'];
830 - $google_captcha_url = esc_url( 'https://www.google.com/recaptcha/api/siteverify' );
831 -
832 - $response = wp_remote_post( $google_captcha_url,
833 - array(
834 - 'method' => 'POST',
835 - 'body' => array(
836 - 'secret' => $secret,
837 - 'response' => $token
838 - )
839 - )
840 - );
841 -
842 -
843 - if ( is_wp_error( $response ) ) {
844 - wp_send_json( [
845 - 'success' => false,
846 - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
847 - ] );
848 - } else {
849 - $api_response = json_decode( wp_remote_retrieve_body( $response ), true );
850 - if( $api_response["success"] == '1' && $api_response["action"] == $action ) {
851 - return true;
852 - } else {
853 - wp_send_json( [
854 - 'success' => false,
855 - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
856 - ] );
857 - }
858 - }
859 - }
860 - /**
861 - * reCaptcha Validation
862 - *
863 - * @return void
864 - */
865 - function validate_reCaptcha() {
866 - check_ajax_referer( 'wpuf_form_add' );
867 - if ( class_exists( 'WPUF_ReCaptcha' ) ) {
868 - $recaptcha_class = 'WPUF_ReCaptcha';
869 - } else {
870 - if ( !function_exists( 'recaptcha_get_html' ) ) {
871 - require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib.php';
872 - }
873 -
874 - require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib_noCaptcha.php';
875 - $recaptcha_class = 'Weforms_ReCaptcha';
876 - }
877 -
878 - $invisible = isset( $_POST['g-recaptcha-response'] ) ? false : true;
879 -
880 - $recaptcha_settings = weforms_get_settings( 'recaptcha' );
881 - $secret = isset( $recaptcha_settings->secret ) ? $recaptcha_settings->secret : '';
882 -
883 - if ( ! $invisible ) {
884 - $response = null;
885 - $reCaptcha = new $recaptcha_class( $secret );
886 - $remote_ADDR = isset( $_SERVER['REMOTE_ADDR'] ) ? sanitize_text_field( wp_unslash( $_SERVER['REMOTE_ADDR'] ) ) : '';
887 - $recaptcha_response = isset( $_POST['g-recaptcha-response'] ) ? sanitize_text_field( wp_unslash( $_POST['g-recaptcha-response'] ) ) : '';
888 - $resp = $reCaptcha->verifyResponse(
889 - $remote_ADDR,
890 - $recaptcha_response
891 - );
892 -
893 - if ( !$resp->success ) {
894 - wp_send_json( [
895 - 'success' => false,
896 - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
897 - ] );
898 - }
899 -
900 - } else {
901 -
902 - $recap_challenge = isset( $_POST['recaptcha_challenge_field'] ) ? sanitize_text_field( wp_unslash( $_POST['recaptcha_challenge_field'] ) ) : '';
903 - $recap_response = isset( $_POST['recaptcha_response_field'] ) ? sanitize_text_field( wp_unslash( $_POST['recaptcha_response_field'] ) ) : '';
904 - $resp = recaptcha_check_answer( $secret, $remote_ADDR, $recap_challenge, $recap_response );
905 -
906 - if ( !$resp->is_valid ) {
907 - ob_clean();
908 -
909 - wp_send_json( [
910 - 'success' => false,
911 - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
912 - ] );
913 - }
914 - }
915 - }
916 -
917 - /**
918 - * Validate submission
919 - *
920 - * @param array $entry_fields
921 - * @param object $form
922 - * @param array $form_settings
923 - * @param array $form_fields
924 - *
925 - * @return bool|json
926 - */
927 - public function validate_submission( $entry_fields, $form, $form_settings, $form_fields ) {
928 - foreach ( $form_fields as $key => $field ) {
929 -
930 - //skip custom html field as it is not saved
931 - if ( 'custom_html' == $field['name'] ) {
932 - continue;
933 - }
934 -
935 - //skip recaptcha field as it is not saved
936 - if ( 'recaptcha' == $field['name'] ) {
937 - continue;
938 - }
939 -
940 - $value = $entry_fields[ $field['name'] ];
941 -
942 - if ( 'single_product' === $field['template'] ) {
943 - if ( !$value ) {
944 - $value = [];
945 - }
946 -
947 - $value['price'] = isset( $value['price'] ) ? floatval( $value['price'] ) : 0;
948 - $value['quantity'] = isset( $value['quantity'] ) ? floatval( $value['quantity'] ) : 0;
949 - $quantity = isset( $field['quantity'] ) ? $field['quantity'] : [];
950 - $price = isset( $field['price'] ) ? $field['price'] : [];
951 -
952 - if ( isset( $price['is_flexible'] ) && $price['is_flexible'] ) {
953 - $min = isset( $price['min'] ) ? floatval( $price['min'] ) : 0;
954 - $max = isset( $price['max'] ) ? floatval( $price['max'] ) : 0;
955 -
956 - if ( $value['price'] < $min ) {
957 - wp_send_json( [
958 - 'success' => false,
959 - 'error' => __( sprintf(
960 - '%s price must be equal or greater than %s',
961 - $field['weforms'],
962 - $min ),
963 - 'weforms' ),
964 - ] );
965 - }
966 -
967 - if ( $max && $value['price'] > $max ) {
968 - wp_send_json( [
969 - 'success' => false,
970 - 'error' => __( sprintf(
971 - '%s price must be equal or less than %s',
972 - $field['weforms'],
973 - $max ),
974 - 'weforms' ),
975 - ] );
976 - }
977 - }
978 -
979 - if ( isset( $quantity['status'] ) && $quantity['status'] ) {
980 - $min = isset( $quantity['min'] ) ? floatval( $quantity['min'] ) : 0;
981 - $max = isset( $quantity['max'] ) ? floatval( $quantity['max'] ) : 0;
982 -
983 - if ( $value['quantity'] < $min ) {
984 - wp_send_json( [
985 - 'success' => false,
986 - 'error' => __( sprintf(
987 - '%s quantity must be equal or greater than %s',
988 - $field['weforms'],
989 - $min ),
990 - 'weforms' ),
991 - ] );
992 - }
993 -
994 - if ( $max && $value['quantity'] > $max ) {
995 - wp_send_json( [
996 - 'success' => false,
997 - 'error' => __( sprintf(
998 - '%s quantity must be equal or less than %s',
999 - $field['weforms'],
1000 - $max ),
1001 - 'weforms' ),
1002 - ] );
1003 - }
1004 - }
1005 - }
1006 - }
1007 - }
1008 -
1009 - public static function prepare_meta_fields( $meta_vars ) {
1010 - check_ajax_referer( 'wpuf_form_add' );
1011 - // loop through custom fields
1012 - // skip files, put in a key => value paired array for later executation
1013 - // process repeatable fields separately
1014 - // if the input is array type, implode with separator in a field
1015 - $files = [];
1016 - $meta_key_value = [];
1017 - $multi_repeated = []; // multi repeated fields will in sotre duplicated meta key
1018 -
1019 - foreach ( $meta_vars as $key => $value ) {
1020 - switch ( $value['template'] ) {
1021 -
1022 - // put files in a separate array, we'll process it later
1023 - case 'file_upload':
1024 - case 'image_upload':
1025 - $files[] = [
1026 - 'name' => $value['name'],
1027 - 'value' => isset( $_POST['wpuf_files'][ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST['wpuf_files'][ $value['name'] ] ) ) : array(),
1028 - 'count' => $value['count']
1029 - ];
1030 - break;
1031 -
1032 - case 'repeat_field':
1033 - // if it is a multi column repeat field
1034 - if ( isset( $value['multiple'] ) && $value['multiple'] == 'true' ) {
1035 -
1036 - // if there's any items in the array, process it
1037 - if ( isset( $_POST[ $value['name'] ] ) ) {
1038 - $ref_arr = [];
1039 - $cols = count( $value['columns'] );
1040 - $first = array_shift( array_values( sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) ) ); // first element
1041 - $rows = count( $first );
1042 -
1043 - // loop through columns
1044 - for ( $i = 0; $i < $rows; $i++ ) {
1045 -
1046 - // loop through the rows and store in a temp array
1047 - $temp = [];
1048 - for ( $j = 0; $j < $cols; $j++ ) {
1049 - $temp[] = isset( $_POST[ $value['name'] ][ $j ][ $i ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ][ $j ][ $i ] ) ) : '';
1050 - }
1051 -
1052 - // store all fields in a row with WeForms::$field_separator separated
1053 - $ref_arr[] = implode( WeForms::$field_separator, $temp );
1054 - }
1055 -
1056 - // now, if we found anything in $ref_arr, store to $multi_repeated
1057 - if ( $ref_arr ) {
1058 - $multi_repeated[ $value['name'] ] = array_slice( $ref_arr, 0, $rows );
1059 - }
1060 - }
1061 - } else {
1062 - $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) );
1063 - }
1064 -
1065 - break;
1066 -
1067 - case 'address_field':
1068 - if ( isset( $_POST[ $value['name'] ] ) && is_array( $_POST[ $value['name'] ] ) ) {
1069 - $post_value = sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) );
1070 - foreach ( $post_value as $address_field => $field_value ) {
1071 - $meta_key_value[ $value['name'] ][ $address_field ] = sanitize_text_field( $field_value );
1072 - }
1073 - }
1074 -
1075 - break;
1076 -
1077 - case 'text_field':
1078 - case 'email_address':
1079 - case 'numeric_text_field':
1080 - case 'date_field':
1081 - $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : '';
1082 -
1083 - break;
1084 -
1085 - case 'textarea_field':
1086 - $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : '';
1087 -
1088 - break;
1089 -
1090 - case 'dropdown_field':
1091 - case 'radio_field':
1092 - $val = sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) );
1093 - $meta_key_value[ $value['name'] ] = isset( $value['options'][ $val ] ) ? $value['options'][ $val ] : '';
1094 - break;
1095 -
1096 - case 'multiple_select':
1097 - case 'checkbox_field':
1098 - $val = ( is_array( $_POST[ $value['name'] ] ) && sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : array();
1099 - $meta_key_value[ $value['name'] ] = $val;
1100 -
1101 - if ( $val ) {
1102 - $new_val = [];
1103 -
1104 - foreach ( $val as $option_key ) {
1105 - $new_val[] = isset( $value['options'][ $option_key ] ) ? $value['options'][ $option_key ] : '';
1106 - }
1107 -
1108 - $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, $new_val );
1109 - }
1110 - break;
1111 -
1112 - default:
1113 - // if it's an array, implode with this->separator
1114 - if ( is_array( $_POST[ $value['name'] ] ) ) {
1115 - $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) );
1116 - } else {
1117 - $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ): '';
1118 - }
1119 -
1120 - break;
1121 - }
1122 - } //end foreach
1123 -
1124 - return [ $meta_key_value, $multi_repeated, $files ];
1125 - }
1126 -
1127 - /**
1128 - * Import a form from a JSON file
1129 - *
1130 - * @return void
1131 - */
1132 - public function import_form() {
1133 - check_ajax_referer( 'weforms' );
1134 -
1135 - $this->check_admin();
1136 -
1137 - $the_file = isset( $_FILES['importFile'] ) ? $_FILES['importFile'] : false;
1138 -
1139 - if ( !$the_file ) {
1140 - wp_send_json_error( __( 'No file found to import.', 'weforms' ) );
1141 - }
1142 -
1143 - $file_ext = pathinfo( $the_file['name'], PATHINFO_EXTENSION );
1144 -
1145 - if ( !class_exists( 'WeForms_Admin_Tools' ) ) {
1146 - require_once __DIR__ . '/admin/class-admin-tools.php';
1147 - }
1148 -
1149 - if ( ( $file_ext == 'json' ) && ( $the_file['size'] < 500000 ) ) {
1150 - $status = WeForms_Admin_Tools::import_json_file( $the_file['tmp_name'] );
1151 -
1152 - if ( $status ) {
1153 - wp_send_json_success( __( 'The forms have been imported successfully!', 'weforms' ) );
1154 - } else {
1155 - wp_send_json_error( __( 'Something went wrong importing the file.', 'weforms' ) );
1156 - }
1157 - } else {
1158 - wp_send_json_error( __( 'Invalid file or file size too big.', 'weforms' ) );
1159 - }
1160 - }
1161 -
1162 - /**
1163 - * Read Log file
1164 - *
1165 - * @return json
1166 - **/
1167 - public function get_logs() {
1168 - check_ajax_referer( 'weforms' );
1169 -
1170 - $this->check_admin();
1171 -
1172 - $file = weforms_log_file_path();
1173 -
1174 - if ( !file_exists( $file ) ) {
1175 - return;
1176 - }
1177 -
1178 - $data = file_get_contents( $file );
1179 - $data = explode( "\n", $data );
1180 - $data = array_reverse( $data );
1181 - $data = array_filter( $data );
1182 -
1183 - if ( empty( $data ) ) {
1184 - return;
1185 - }
1186 -
1187 - $logs = [];
1188 -
1189 - foreach ( $data as $key => $row ) {
1190 - preg_match( '/\[(?<time>.+?)\]\[(?<type>.+?)\](?<message>.+)/im', $row, $log );
1191 -
1192 - if ( empty( $log['message'] ) ) {
1193 - $log = [];
1194 - $log['message'] = !empty( $log['message'] ) ? $log['message'] : $row;
1195 - }
1196 -
1197 - if ( !empty( $log['time'] ) ) {
1198 - $human_time = human_time_diff( strtotime( $log['time'] ), current_time( 'timestamp' ) );
1199 - $log['time'] = $human_time ? $human_time . ' ' . __( 'ago', 'weforms' ) : $log['time'];
1200 - }
1201 -
1202 - $logs[] = $log;
1203 - }
1204 -
1205 - wp_send_json_success( $logs );
1206 - }
1207 -
1208 - /**
1209 - * Read Log file
1210 - *
1211 - * @return json
1212 - **/
1213 - public function delete_logs() {
1214 - check_ajax_referer( 'weforms' );
1215 -
1216 - $this->check_admin();
1217 -
1218 - $file = weforms_log_file_path();
1219 -
1220 - if ( !file_exists( $file ) ) {
1221 - return;
1222 - }
1223 -
1224 - @unlink( $file );
1225 -
1226 - wp_send_json_success();
1227 - }
1228 -}
1 +<?php
2 +
3 +/**
4 + * The ajax handler class
5 + */
6 +class WeForms_Ajax {
7 +
8 + public function __construct() {
9 +
10 + // backend requests
11 + add_action( 'wp_ajax_weforms_form_list', [ $this, 'get_contact_forms' ] );
12 + add_action( 'wp_ajax_weforms_get_users', [ $this, 'get_all_users' ] );
13 + add_action( 'wp_ajax_weforms_form_names', [ $this, 'get_contact_form_names' ] );
14 + add_action( 'wp_ajax_weforms_form_create', [ $this, 'create_form' ] );
15 + add_action( 'wp_ajax_weforms_form_delete', [ $this, 'delete_form' ] );
16 + add_action( 'wp_ajax_weforms_form_delete_bulk', [ $this, 'delete_form_bulk' ] );
17 + add_action( 'wp_ajax_weforms_form_duplicate', [ $this, 'duplicate_form' ] );
18 +
19 + // read logs
20 + add_action( 'wp_ajax_weforms_read_logs', [ $this, 'get_logs' ] );
21 + add_action( 'wp_ajax_weforms_delete_logs', [ $this, 'delete_logs' ] );
22 +
23 + // create from a template
24 + add_filter( 'wp_ajax_weforms_contact_form_template', [ $this, 'create_form_from_template' ] );
25 +
26 + // form settings
27 + add_action( 'wp_ajax_weforms_save_settings', [ $this, 'save_settings' ] );
28 + add_action( 'wp_ajax_weforms_get_settings', [ $this, 'get_settings' ] );
29 +
30 + // import
31 + add_action( 'wp_ajax_weforms_import_form', [ $this, 'import_form' ] );
32 +
33 + // form editing
34 + add_action( 'wp_ajax_weforms_get_form', [ $this, 'get_form' ] );
35 + add_action( 'wp_ajax_wpuf_form_builder_save_form', [ $this, 'save_form' ] );
36 +
37 + // entries
38 + add_action( 'wp_ajax_weforms_form_entries', [ $this, 'get_entries' ] );
39 +
40 + add_action( 'wp_ajax_weforms_form_entry_details', [ $this, 'get_entry_detail' ] );
41 + add_action( 'wp_ajax_weforms_form_entry_trash', [ $this, 'trash_entry' ] );
42 + add_action( 'wp_ajax_weforms_form_entry_delete', [ $this, 'delete_entry' ] );
43 + add_action( 'wp_ajax_weforms_form_entry_restore', [ $this, 'restore_entry' ] );
44 +
45 + add_action( 'wp_ajax_weforms_form_entry_trash_bulk', [ $this, 'bulk_delete_entry' ] );
46 + add_action( 'wp_ajax_weforms_form_entry_restore_bulk', [ $this, 'bulk_restore_entry' ] );
47 +
48 + // frontend requests
49 + add_action( 'wp_ajax_weforms_frontend_submit', [ $this, 'handle_frontend_submission' ] );
50 + add_action( 'wp_ajax_nopriv_weforms_frontend_submit', [ $this, 'handle_frontend_submission' ] );
51 + }
52 +
53 + /**
54 + * Administrator validation
55 + *
56 + * @return void
57 + */
58 + public function check_admin() {
59 + if ( !current_user_can( weforms_form_access_capability() ) ) {
60 + wp_send_json_error( __( 'You do not have sufficient permission.', 'weforms' ) );
61 + }
62 + }
63 +
64 + /**
65 + * Get a form to edit
66 + *
67 + * @return void
68 + */
69 + public function get_form() {
70 + $this->check_admin();
71 +
72 + $form_id = isset( $_REQUEST['form_id'] ) ? absint( $_REQUEST['form_id'] ) : 0;
73 +
74 + $form = weforms()->form->get( $form_id );
75 +
76 + $data = [
77 + 'post' => $form->data,
78 + 'form_fields' => $form->get_fields(),
79 + 'settings' => $form->get_settings(),
80 + 'notifications' => $form->get_notifications(),
81 + 'integrations' => $form->get_integrations(),
82 + ];
83 +
84 + wp_send_json_success( $data );
85 + }
86 +
87 + /**
88 + * Save the form
89 + *
90 + * @return void
91 + */
92 + public function save_form() {
93 + $post_data = wp_unslash( $_POST );
94 + if ( isset( $post_data['form_data'] ) ) {
95 + parse_str( sanitize_text_field( wp_unslash( $post_data['form_data'] ) ), $form_data );
96 + }
97 +
98 + if ( !wp_verify_nonce( $form_data['wpuf_form_builder_nonce'], 'wpuf_form_builder_save_form' ) ) {
99 + wp_send_json_error( __( 'Unauthorized operation', 'weforms' ) );
100 + }
101 +
102 + if ( empty( $form_data['wpuf_form_id'] ) ) {
103 + wp_send_json_error( __( 'Invalid form id', 'weforms' ) );
104 + }
105 +
106 + $form_fields = isset( $post_data['form_fields'] ) ? $post_data['form_fields'] : '';
107 + $notifications = isset( $post_data['notifications'] ) ? $post_data['notifications']: '';
108 + $settings = array();
109 + $integrations = array();
110 +
111 + if ( isset( $post_data['settings'] ) ) {
112 + $settings = (array) json_decode( $post_data['settings'] );
113 + } else {
114 + $settings = isset( $form_data['wpuf_settings'] ) ? $form_data['wpuf_settings'] : [];
115 + }
116 +
117 + if ( isset( $post_data['integrations'] ) ) {
118 + $integrations = (array) json_decode( $post_data['integrations'] );
119 + }
120 +
121 + // $form_fields = wp_unslash( $form_fields );
122 + // $notifications = wp_unslash( $notifications );
123 +
124 + $form_fields = json_decode( $form_fields, true );
125 + $notifications = json_decode( $notifications, true );
126 + $data = [
127 + 'form_id' => absint( $form_data['wpuf_form_id'] ),
128 + 'post_title' => $form_data['post_title'],
129 + 'form_fields' => $form_fields,
130 + 'form_settings' => $settings,
131 + 'form_settings_key' => isset( $form_data['form_settings_key'] ) ? $form_data['form_settings_key'] : '',
132 + 'notifications' => $notifications,
133 + 'integrations' => $integrations,
134 + ];
135 +
136 + $form_fields = weforms()->form->save( $data );
137 +
138 + wp_send_json_success( [ 'form_fields' => $form_fields ] );
139 + }
140 +
141 + /**
142 + * Get all contact forms
143 + *
144 + * @return void
145 + */
146 + public function get_contact_forms() {
147 + check_ajax_referer( 'weforms' );
148 +
149 + $this->check_admin();
150 +
151 + $args = [
152 + 'posts_per_page' => isset( $_POST['posts_per_page'] ) ? intval( $_POST['posts_per_page'] ) : 10,
153 + 'paged' => isset( $_POST['page'] ) ? absint( $_POST['page'] ) : 1,
154 + 'order' => 'DESC',
155 + 'orderby' => 'post_date',
156 + ];
157 +
158 + $args = apply_filters( 'weforms_ajax_get_contact_forms_args', $args );
159 +
160 + $contact_forms = weforms()->form->get_forms( $args );
161 +
162 + array_map(
163 + function ( $form ) {
164 + $form->entries = $form->num_form_entries();
165 + $form->settings = $form->get_settings();
166 + $form->views = $form->num_form_views();
167 + $form->payments = $form->num_form_payments();
168 + $form->author = $form->get_form_author_details();
169 + }, $contact_forms['forms']
170 + );
171 +
172 + $contact_forms = $this->filter_contact_forms( $contact_forms );
173 + $contact_forms = apply_filters( 'weforms_ajax_get_contact_forms', $contact_forms );
174 +
175 + wp_send_json_success( $contact_forms );
176 + }
177 +
178 + /**
179 + * Get all users
180 + *
181 + * @return array
182 + */
183 + public function get_all_users() {
184 + check_ajax_referer( 'weforms' );
185 +
186 + $this->check_admin();
187 +
188 + $users_meta = [];
189 + $users = get_users( [ 'fields' => [ 'ID' ] ] );
190 +
191 + foreach ( $users as $user ) {
192 + $users_meta[] = [
193 + 'id' => $user->ID,
194 + 'data' => get_user_meta( $user->ID ),
195 + ];
196 + }
197 +
198 + wp_send_json_success( $users_meta );
199 + }
200 +
201 + /**
202 + * Filter
203 + *
204 + * @return void
205 + */
206 + public function filter_contact_forms( &$contact_forms ) {
207 + if ( isset( $_REQUEST['filter'] ) && $_REQUEST['filter'] == 'entries' ) {
208 + foreach ( $contact_forms['forms'] as $key => &$form ) {
209 + if ( isset( $form->entries ) && !$form->entries ) {
210 + unset( $contact_forms['forms'][ $key ] );
211 + }
212 + }
213 +
214 + $contact_forms['meta']['total'] = count( $contact_forms['forms'] );
215 + }
216 +
217 + return $contact_forms;
218 + }
219 +
220 + /**
221 + * Get the names of contact forms for generating dropdown
222 + *
223 + * @return void
224 + */
225 + public function get_contact_form_names() {
226 + check_ajax_referer( 'weforms' );
227 +
228 + $this->check_admin();
229 +
230 + $contact_forms = weforms()->form->all();
231 + $response = [];
232 +
233 + foreach ( $contact_forms['forms'] as $form ) {
234 + $response[] = [
235 + 'id' => $form->get_id(),
236 + 'title' => $form->get_name() . ' (#' . $form->get_id() . ')',
237 + ];
238 + }
239 +
240 + wp_send_json_success( $response );
241 + }
242 +
243 + /**
244 + * Create a form
245 + *
246 + * @return void
247 + */
248 + public function create_form() {
249 + check_ajax_referer( 'weforms' );
250 +
251 + $this->check_admin();
252 +
253 + $form_name = isset( $_POST['form_name'] ) ? sanitize_text_field( wp_unslash( $_POST['form_name'] ) ) : '';
254 +
255 + if ( empty( $form_name ) ) {
256 + wp_send_json_error( __( 'Please provide a form name', 'weforms' ) );
257 + }
258 +
259 + $form_id = weforms()->form->create( $form_name );
260 +
261 + if ( is_wp_error( $form_id ) ) {
262 + wp_send_json_error( $form_id->get_error_message() );
263 + }
264 +
265 + wp_send_json_success( [
266 + 'form_id' => $form_id,
267 + 'form_name' => $form_name,
268 + ] );
269 + }
270 +
271 + /**
272 + * Delete a form
273 + *
274 + * @return void
275 + */
276 + public function delete_form() {
277 + check_ajax_referer( 'weforms' );
278 +
279 + $this->check_admin();
280 +
281 + $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
282 +
283 + if ( !$form_id ) {
284 + wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
285 + }
286 +
287 + weforms()->form->delete( $form_id );
288 +
289 + wp_send_json_success();
290 + }
291 +
292 + public function delete_form_bulk() {
293 + check_ajax_referer( 'weforms' );
294 +
295 + $this->check_admin();
296 +
297 + $form_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : [];
298 +
299 + if ( !$form_ids ) {
300 + wp_send_json_error( __( 'No form ids provided!', 'weforms' ) );
301 + }
302 +
303 + foreach ( $form_ids as $form_id ) {
304 + weforms()->form->delete( $form_id );
305 + }
306 +
307 + wp_send_json_success();
308 + }
309 +
310 + /**
311 + * Duplicate a form
312 + *
313 + * @return voiud
314 + */
315 + public function duplicate_form() {
316 + check_ajax_referer( 'weforms' );
317 +
318 + $this->check_admin();
319 +
320 + $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
321 +
322 + $form = weforms()->form->duplicate( $form_id );
323 + $form->settings = $form->get_settings();
324 +
325 + wp_send_json_success( $form );
326 + }
327 +
328 + /**
329 + * Create form from a template
330 + *
331 + * @return void
332 + */
333 + public function create_form_from_template() {
334 + check_ajax_referer( 'weforms' );
335 +
336 + $template = isset( $_REQUEST['template'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['template'] ) ) : '';
337 +
338 + $form_id = weforms()->templates->create( $template );
339 +
340 + if ( is_wp_error( $form_id ) ) {
341 + wp_send_json_error( __( 'Could not create the form', 'weforms' ) );
342 + }
343 +
344 + wp_send_json_success( [
345 + 'id' => $form_id,
346 + ] );
347 + }
348 +
349 + /**
350 + * Save the weForms settings
351 + *
352 + * @return void
353 + */
354 + public function save_settings() {
355 + check_ajax_referer( 'weforms' );
356 + $this->check_admin();
357 +
358 + $requires_wpuf_update = false;
359 + $wpuf_update_array = array();
360 + $settings = isset( $_POST['settings'] ) ? (array) json_decode( wp_unslash( $_POST['settings'] ) ) : [];
361 + update_option( 'weforms_settings', $settings );
362 +
363 + // wpuf settings sync
364 + if ( isset( $settings['gmap_api'] ) ) {
365 + $requires_wpuf_update = true;
366 + $wpuf_update_array['gmap_api_key'] = $settings['gmap_api'];
367 + }
368 +
369 + if ( isset( $settings['recaptcha'] ) ) {
370 + $requires_wpuf_update = true;
371 + $wpuf_update_array['recaptcha_public'] = $settings['recaptcha']->key;
372 + $wpuf_update_array['recaptcha_private'] = $settings['recaptcha']->secret;
373 + $wpuf_update_array['recaptcha_type'] = $settings['recaptcha']->type;
374 + }
375 +
376 + if ( isset( $settings['no_conflict'] ) ) {
377 + $requires_wpuf_update = true;
378 + $wpuf_update_array['no_conflict'] = $settings['no_conflict'];
379 + }
380 +
381 + if ( isset( $settings['email_footer'] ) ) {
382 + $requires_wpuf_update = true;
383 + $wpuf_update_array['email_footer'] = $settings['email_footer'];
384 + }
385 +
386 + if ( $requires_wpuf_update ) {
387 + $wpuf_settings = get_option( 'wpuf_general', [] );
388 +
389 + $wpuf_settings = array_merge( $wpuf_settings, $wpuf_update_array );
390 + update_option( 'wpuf_general', $wpuf_settings );
391 + }
392 +
393 + do_action( 'weforms_save_settings', $settings );
394 +
395 + $settings = apply_filters( 'weforms_after_save_settings', $settings );
396 + wp_send_json_success( $settings );
397 + }
398 +
399 + /**
400 + * Get the weForms Settings
401 + *
402 + * @return void
403 + */
404 + public function get_settings() {
405 + check_ajax_referer( 'weforms' );
406 +
407 + $this->check_admin();
408 +
409 + $settings = weforms_get_settings();
410 + // checking to prevent js error, will be removed in future
411 + if ( !isset( $settings['credit'] ) ) {
412 + $settings['credit'] = false;
413 + }
414 +
415 + if ( !isset( $settings['permission'] ) ) {
416 + $settings['permission'] = 'manage_options';
417 + }
418 +
419 + wp_send_json_success( $settings );
420 + }
421 +
422 + /**
423 + * Get all entries
424 + *
425 + * @return void
426 + */
427 + public function get_entries() {
428 + check_ajax_referer( 'weforms' );
429 +
430 + $this->check_admin();
431 +
432 + $form_id = isset( $_REQUEST['id'] ) ? intval( $_REQUEST['id'] ) : 0;
433 + $current_page = isset( $_REQUEST['page'] ) ? intval( $_REQUEST['page'] ) : 1;
434 + $status = isset( $_REQUEST['status'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['status'] ) ) : 'publish';
435 + $per_page = 20;
436 + $offset = ( $current_page - 1 ) * $per_page;
437 +
438 + if ( !$form_id ) {
439 + wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
440 + }
441 +
442 + $entries = weforms_get_form_entries(
443 + $form_id, [
444 + 'number' => $per_page,
445 + 'offset' => $offset,
446 + 'status' => $status,
447 + ]
448 + );
449 +
450 + $columns = weforms_get_entry_columns( $form_id );
451 + $total_entries = weforms_count_form_entries( $form_id, $status );
452 +
453 + array_map(
454 + function ( $entry ) use ( $columns ) {
455 + $entry_id = $entry->id;
456 + $entry->fields = [];
457 +
458 + foreach ( $columns as $meta_key => $label ) {
459 + if ( empty( $meta_key ) ) {
460 + continue;
461 + }
462 + $value = weforms_get_entry_meta( $entry_id, $meta_key, true );
463 + $entry->fields[ $meta_key ] = str_replace( WeForms::$field_separator, ' ', $value );
464 + }
465 + }, $entries
466 + );
467 +
468 + $entries = apply_filters( 'weforms_get_entries', $entries, $form_id );
469 +
470 + $response = [
471 + 'columns' => $columns,
472 + 'entries' => $entries,
473 + 'form_title' => get_post_field( 'post_title', $form_id ),
474 + 'pagination' => [
475 + 'total' => $total_entries,
476 + 'per_page' => $per_page,
477 + 'pages' => ceil( $total_entries / $per_page ),
478 + 'current' => $current_page,
479 + ],
480 + 'meta' => [
481 + 'total' => weforms_count_form_entries( $form_id ),
482 + 'totalTrash' => weforms_count_form_entries( $form_id, 'trash' ),
483 + ],
484 + ];
485 +
486 + wp_send_json_success( $response );
487 + }
488 +
489 + /**
490 + * Get an entry details
491 + *
492 + * @return void
493 + */
494 + public function get_entry_detail() {
495 + check_ajax_referer( 'weforms' );
496 +
497 + $this->check_admin();
498 +
499 + $form_id = isset( $_REQUEST['form_id'] ) ? intval( $_REQUEST['form_id'] ) : 0;
500 + $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
501 +
502 + $form = weforms()->form->get( $form_id );
503 + $form_settings = $form->get_settings();
504 + $entry = $form->entries()->get( $entry_id );
505 + $fields = $entry->get_fields();
506 + $metadata = $entry->get_metadata();
507 + $payment = $entry->get_payment_data();
508 +
509 + if ( isset( $payment->payment_data ) && is_serialized( $payment->payment_data ) ) {
510 + $payment->payment_data = unserialize( $payment->payment_data );
511 + }
512 +
513 + if ( false === $fields ) {
514 + wp_send_json_error( __( 'No form fields found!', 'weforms' ) );
515 + }
516 +
517 + if ( sizeof( $fields ) < 1 ) {
518 + $fields[] = [
519 + 'label' => __( 'No form fields found!', 'weforms' ),
520 + ];
521 + }
522 +
523 + $has_empty = false;
524 + $answers = [];
525 + $respondentPoints = isset( $form_settings['total_points'] ) ? floatval( $form_settings['total_points'] ) : 0;
526 +
527 + foreach ( $fields as $key => $field ) {
528 + if ( $form_settings['quiz_form'] == 'yes' ) {
529 + $selectedAnswers = isset( $field['selected_answers'] ) ? $field['selected_answers'] : '';
530 + $givenAnswer = isset( $field['value'] ) ? $field['value'] : '';
531 + $options = isset( $field['options'] ) ? $field['options'] : '';
532 + $template = $field['template'];
533 + $fieldPoints = isset( $field['points'] ) ? floatval( $field['points'] ) : 0;
534 +
535 + if ( $template == 'radio_field' || $template == 'dropdown_field' ) {
536 + $answers[$field['name']] = true;
537 +
538 + if ( empty( $givenAnswer ) ) {
539 + $answers[$field['name']] = false;
540 + $respondentPoints -= $fieldPoints;
541 + } else {
542 + foreach ( $options as $key => $value ) {
543 + if ( $givenAnswer == $value ) {
544 + if ( $key != $selectedAnswers ) {
545 + $answers[$field['name']] = false;
546 + $respondentPoints -= $fieldPoints;
547 + }
548 + }
549 + }
550 + }
551 + } elseif ( $template == 'checkbox_field' || $template == 'multiple_select' ) {
552 + $answers[$field['name']] = true;
553 + $userAnswer = [];
554 +
555 + foreach ( $options as $key => $value ) {
556 + foreach ( $givenAnswer as $answer ) {
557 + if ( $value == $answer ) {
558 + $userAnswer[] = $key;
559 + }
560 + }
561 + }
562 +
563 + $userAnswer = implode( '|', $userAnswer );
564 + $rightAnswers = implode( '|', $selectedAnswers );
565 +
566 + if ( $userAnswer != $rightAnswers || empty( $userAnswer ) ) {
567 + $answers[$field['name']] = false;
568 + $respondentPoints -= $fieldPoints;
569 + }
570 + }
571 + } elseif ( empty( $field['value'] ) ) {
572 + $has_empty = true;
573 + break;
574 + }
575 + }
576 +
577 + $response = [
578 + 'form_fields' => $fields,
579 + 'form_settings' => $form_settings,
580 + 'meta_data' => $metadata,
581 + 'payment_data' => $payment,
582 + 'has_empty' => $has_empty,
583 + 'respondent_points' => $respondentPoints,
584 + 'answers' => $answers,
585 + ];
586 +
587 + wp_send_json_success( $response );
588 + }
589 +
590 + /**
591 + * Trash an entry
592 + *
593 + * @return void
594 + */
595 + public function trash_entry() {
596 + check_ajax_referer( 'weforms' );
597 +
598 + $this->check_admin();
599 +
600 + $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
601 +
602 + weforms_change_entry_status( $entry_id, 'trash' );
603 + wp_send_json_success();
604 + }
605 +
606 + /**
607 + * Trash an entry
608 + *
609 + * @return void
610 + */
611 + public function delete_entry() {
612 + check_ajax_referer( 'weforms' );
613 +
614 + $this->check_admin();
615 +
616 + $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
617 +
618 + weforms_delete_entry( $entry_id );
619 +
620 + wp_send_json_success();
621 + }
622 +
623 + /**
624 + * Restore Entry
625 + *
626 + * @return void
627 + */
628 + public function restore_entry() {
629 + check_ajax_referer( 'weforms' );
630 +
631 + $this->check_admin();
632 +
633 + $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
634 +
635 + weforms_change_entry_status( $entry_id, 'publish' );
636 + wp_send_json_success();
637 + }
638 +
639 + /**
640 + * Bulk trash entries
641 + *
642 + * @return void
643 + */
644 + public function bulk_delete_entry() {
645 + check_ajax_referer( 'weforms' );
646 +
647 + $this->check_admin();
648 +
649 + $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : array();
650 + $permanent = isset( $_POST['permanent'] ) && ( sanitize_text_field( wp_unslash ( $_POST['permanent'] ) ) ) ? true : false;
651 +
652 + if ( !$entry_ids ) {
653 + wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
654 + }
655 +
656 + foreach ( $entry_ids as $entry_id ) {
657 + if ( $permanent ) {
658 + weforms_delete_entry( $entry_id );
659 + } else {
660 + weforms_change_entry_status( $entry_id, 'trash' );
661 + }
662 + }
663 +
664 + wp_send_json_success();
665 + }
666 +
667 + /**
668 + * Bulk trash entries
669 + *
670 + * @return void
671 + */
672 + public function bulk_restore_entry() {
673 + check_ajax_referer( 'weforms' );
674 +
675 + $this->check_admin();
676 +
677 + $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : [];
678 +
679 + if ( !$entry_ids ) {
680 + wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
681 + }
682 +
683 + foreach ( $entry_ids as $entry_id ) {
684 + weforms_change_entry_status( $entry_id, 'publish' );
685 + }
686 +
687 + wp_send_json_success();
688 + }
689 +
690 + /**
691 + * Handle the frontend submission
692 + *
693 + * @return void
694 + */
695 + public function handle_frontend_submission() {
696 + check_ajax_referer( 'wpuf_form_add' );
697 +
698 + $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
699 + $page_id = isset( $_POST['page_id'] ) ? intval( $_POST['page_id'] ) : 0;
700 +
701 + $form = weforms()->form->get( $form_id );
702 + $form_settings = $form->get_settings();
703 + $form_fields = $form->get_fields();
704 + $entry_fields = $form->prepare_entries();
705 + $form_entries = weforms_get_form_entries( $form_id, [ 'number' => '', 'offset' => '' ] );
706 +
707 + if ( $form_fields && count( $form_entries ) && count( $entry_fields ) ) {
708 + foreach ( $entry_fields as $field_key => $field_value ) {
709 + $duplicate_check = false;
710 + $field_label = 'This';
711 +
712 + foreach ( $form_fields as $form_field ) {
713 + if ( in_array( $form_field['template'], [ 'text_field', 'website_url', 'numeric_text_field', 'email_address' ] ) && $form_field['name'] == $field_key && isset( $form_field['duplicate'] ) && 'no' == $form_field['duplicate'] ) {
714 + $duplicate_check = true;
715 + $field_label = $form_field['label'];
716 + }
717 + }
718 +
719 + if ( $duplicate_check ) {
720 + foreach ( $form_entries as $entry ) {
721 + $existing = weforms_get_entry_meta( $entry->id, $field_key, true );
722 +
723 + if ( $existing && $field_value == $existing ) {
724 + wp_send_json( [
725 + 'success' => false,
726 + 'error' => sprintf( __( '"%s" field requires a unique entry and "%s" has already been used.', 'weforms' ), $field_label, $field_value ),
727 + ] );
728 + }
729 + }
730 + }
731 + }
732 + }
733 +
734 + if ( !$form_fields ) {
735 + wp_send_json( [
736 + 'success' => false,
737 + 'error' => __( 'No form field was found.', 'weforms' ),
738 + ] );
739 + }
740 +
741 + if ( $form->has_field( 'recaptcha' ) ) {
742 + $settings = weforms_get_settings( 'recaptcha' );
743 + $type = isset( $settings->type ) ? $settings->type : '';
744 + $secret = isset( $settings->secret ) ? $settings->secret : '';
745 + if( $type == 'v3' ) {
746 + $this->validate_reCaptchav3( $secret );
747 + } else {
748 + $this->validate_reCaptcha();
749 + }
750 + }
751 +
752 + // vaidate submission
753 + $this->validate_submission( $entry_fields, $form, $form_settings, $form_fields );
754 +
755 + $entry_fields = apply_filters( 'weforms_before_entry_submission', $entry_fields, $form, $form_settings, $form_fields );
756 +
757 + $entry_id = weforms_insert_entry( [
758 + 'form_id' => $form_id,
759 + ], $entry_fields );
760 +
761 + if ( is_wp_error( $entry_id ) ) {
762 + wp_send_json( [
763 + 'success' => false,
764 + 'error' => $entry_id->get_error_message(),
765 + ] );
766 + }
767 +
768 + // redirect URL
769 + $show_message = false;
770 + $redirect_to = false;
771 +
772 + if ( $form_settings['redirect_to'] == 'page' ) {
773 + $redirect_to = get_permalink( $form_settings['page_id'] );
774 + } elseif ( $form_settings['redirect_to'] == 'url' ) {
775 + $redirect_to = $form_settings['url'];
776 + } elseif ( $form_settings['redirect_to'] == 'same' ) {
777 + $show_message = true;
778 + } else {
779 + $show_message = true;
780 + }
781 +
782 + // Fire a hook for integration
783 + do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
784 +
785 + $field_search = $field_replace = [];
786 +
787 + foreach ( $form_fields as $r_field ) {
788 + $field_search[] = '{' . $r_field['name'] . '}';
789 +
790 + if ( $r_field['template'] == 'name_field' ) {
791 + $field_replace[] = implode( ' ', explode( '|', $entry_fields[ $r_field['name'] ] ) );
792 + } else if ( $r_field['template'] == 'address_field' ) {
793 + $field_replace[] = implode( ', ', $entry_fields[ $r_field['name'] ] );
794 + } else {
795 + $field_replace[] = isset( $entry_fields[ $r_field['name'] ] ) ? $entry_fields[ $r_field['name'] ] : '';
796 + }
797 + }
798 + $message = str_replace( $field_search, $field_replace, $form_settings['message'] );
799 +
800 + // send the response
801 + $response = apply_filters( 'weforms_entry_submission_response', [
802 + 'success' => true,
803 + 'redirect_to' => $redirect_to,
804 + 'show_message' => $show_message,
805 + 'message' => $message,
806 + 'data' => $_POST,
807 + 'form_id' => $form_id,
808 + 'entry_id' => $entry_id,
809 + ] );
810 +
811 + $notification = new WeForms_Notification( [
812 + 'form_id' => $form_id,
813 + 'page_id' => $page_id,
814 + 'entry_id' => $entry_id,
815 + ] );
816 +
817 + $notification->send_notifications();
818 +
819 + weforms_clear_buffer();
820 + wp_send_json( $response );
821 + }
822 +
823 + function validate_reCaptchav3( $secret ) {
824 + check_ajax_referer( 'wpuf_form_add' );
825 +
826 + $post_data = wp_unslash($_POST);
827 + $token = $post_data['g-recaptcha-response'];
828 + $action = $post_data['g-action'];
829 + $google_captcha_url = esc_url( 'https://www.google.com/recaptcha/api/siteverify' );
830 +
831 + $response = wp_remote_post( $google_captcha_url,
832 + array(
833 + 'method' => 'POST',
834 + 'body' => array(
835 + 'secret' => $secret,
836 + 'response' => $token
837 + )
838 + )
839 + );
840 +
841 +
842 + if ( is_wp_error( $response ) ) {
843 + wp_send_json( [
844 + 'success' => false,
845 + 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
846 + ] );
847 + } else {
848 + $api_response = json_decode( wp_remote_retrieve_body( $response ), true );
849 + if( $api_response["success"] == '1' && $api_response["action"] == $action ) {
850 + return true;
851 + } else {
852 + wp_send_json( [
853 + 'success' => false,
854 + 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
855 + ] );
856 + }
857 + }
858 + }
859 + /**
860 + * reCaptcha Validation
861 + *
862 + * @return void
863 + */
864 + function validate_reCaptcha() {
865 + check_ajax_referer( 'wpuf_form_add' );
866 + if ( class_exists( 'WPUF_ReCaptcha' ) ) {
867 + $recaptcha_class = 'WPUF_ReCaptcha';
868 + } else {
869 + if ( !function_exists( 'recaptcha_get_html' ) ) {
870 + require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib.php';
871 + }
872 +
873 + require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib_noCaptcha.php';
874 + $recaptcha_class = 'Weforms_ReCaptcha';
875 + }
876 +
877 + $invisible = isset( $_POST['g-recaptcha-response'] ) ? false : true;
878 +
879 + $recaptcha_settings = weforms_get_settings( 'recaptcha' );
880 + $secret = isset( $recaptcha_settings->secret ) ? $recaptcha_settings->secret : '';
881 +
882 + if ( ! $invisible ) {
883 + $response = null;
884 + $reCaptcha = new $recaptcha_class( $secret );
885 + $remote_ADDR = isset( $_SERVER['REMOTE_ADDR'] ) ? sanitize_text_field( wp_unslash( $_SERVER['REMOTE_ADDR'] ) ) : '';
886 + $recaptcha_response = isset( $_POST['g-recaptcha-response'] ) ? sanitize_text_field( wp_unslash( $_POST['g-recaptcha-response'] ) ) : '';
887 + $resp = $reCaptcha->verifyResponse(
888 + $remote_ADDR,
889 + $recaptcha_response
890 + );
891 +
892 + if ( !$resp->success ) {
893 + wp_send_json( [
894 + 'success' => false,
895 + 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
896 + ] );
897 + }
898 +
899 + } else {
900 +
901 + $recap_challenge = isset( $_POST['recaptcha_challenge_field'] ) ? sanitize_text_field( wp_unslash( $_POST['recaptcha_challenge_field'] ) ) : '';
902 + $recap_response = isset( $_POST['recaptcha_response_field'] ) ? sanitize_text_field( wp_unslash( $_POST['recaptcha_response_field'] ) ) : '';
903 + $resp = recaptcha_check_answer( $secret, $remote_ADDR, $recap_challenge, $recap_response );
904 +
905 + if ( !$resp->is_valid ) {
906 + ob_clean();
907 +
908 + wp_send_json( [
909 + 'success' => false,
910 + 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
911 + ] );
912 + }
913 + }
914 + }
915 +
916 + /**
917 + * Validate submission
918 + *
919 + * @param array $entry_fields
920 + * @param object $form
921 + * @param array $form_settings
922 + * @param array $form_fields
923 + *
924 + * @return bool|json
925 + */
926 + public function validate_submission( $entry_fields, $form, $form_settings, $form_fields ) {
927 + foreach ( $form_fields as $key => $field ) {
928 +
929 + //skip custom html field as it is not saved
930 + if ( 'custom_html' == $field['name'] ) {
931 + continue;
932 + }
933 +
934 + //skip recaptcha field as it is not saved
935 + if ( 'recaptcha' == $field['name'] ) {
936 + continue;
937 + }
938 +
939 + $value = $entry_fields[ $field['name'] ];
940 +
941 + if ( 'single_product' === $field['template'] ) {
942 + if ( !$value ) {
943 + $value = [];
944 + }
945 +
946 + $value['price'] = isset( $value['price'] ) ? floatval( $value['price'] ) : 0;
947 + $value['quantity'] = isset( $value['quantity'] ) ? floatval( $value['quantity'] ) : 0;
948 + $quantity = isset( $field['quantity'] ) ? $field['quantity'] : [];
949 + $price = isset( $field['price'] ) ? $field['price'] : [];
950 +
951 + if ( isset( $price['is_flexible'] ) && $price['is_flexible'] ) {
952 + $min = isset( $price['min'] ) ? floatval( $price['min'] ) : 0;
953 + $max = isset( $price['max'] ) ? floatval( $price['max'] ) : 0;
954 +
955 + if ( $value['price'] < $min ) {
956 + wp_send_json( [
957 + 'success' => false,
958 + 'error' => __( sprintf(
959 + '%s price must be equal or greater than %s',
960 + $field['weforms'],
961 + $min ),
962 + 'weforms' ),
963 + ] );
964 + }
965 +
966 + if ( $max && $value['price'] > $max ) {
967 + wp_send_json( [
968 + 'success' => false,
969 + 'error' => __( sprintf(
970 + '%s price must be equal or less than %s',
971 + $field['weforms'],
972 + $max ),
973 + 'weforms' ),
974 + ] );
975 + }
976 + }
977 +
978 + if ( isset( $quantity['status'] ) && $quantity['status'] ) {
979 + $min = isset( $quantity['min'] ) ? floatval( $quantity['min'] ) : 0;
980 + $max = isset( $quantity['max'] ) ? floatval( $quantity['max'] ) : 0;
981 +
982 + if ( $value['quantity'] < $min ) {
983 + wp_send_json( [
984 + 'success' => false,
985 + 'error' => __( sprintf(
986 + '%s quantity must be equal or greater than %s',
987 + $field['weforms'],
988 + $min ),
989 + 'weforms' ),
990 + ] );
991 + }
992 +
993 + if ( $max && $value['quantity'] > $max ) {
994 + wp_send_json( [
995 + 'success' => false,
996 + 'error' => __( sprintf(
997 + '%s quantity must be equal or less than %s',
998 + $field['weforms'],
999 + $max ),
1000 + 'weforms' ),
1001 + ] );
1002 + }
1003 + }
1004 + }
1005 + }
1006 + }
1007 +
1008 + public static function prepare_meta_fields( $meta_vars ) {
1009 + check_ajax_referer( 'wpuf_form_add' );
1010 + // loop through custom fields
1011 + // skip files, put in a key => value paired array for later executation
1012 + // process repeatable fields separately
1013 + // if the input is array type, implode with separator in a field
1014 + $files = [];
1015 + $meta_key_value = [];
1016 + $multi_repeated = []; // multi repeated fields will in sotre duplicated meta key
1017 +
1018 + foreach ( $meta_vars as $key => $value ) {
1019 + switch ( $value['template'] ) {
1020 +
1021 + // put files in a separate array, we'll process it later
1022 + case 'file_upload':
1023 + case 'image_upload':
1024 + $files[] = [
1025 + 'name' => $value['name'],
1026 + 'value' => isset( $_POST['wpuf_files'][ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST['wpuf_files'][ $value['name'] ] ) ) : array(),
1027 + 'count' => $value['count']
1028 + ];
1029 + break;
1030 +
1031 + case 'repeat_field':
1032 + // if it is a multi column repeat field
1033 + if ( isset( $value['multiple'] ) && $value['multiple'] == 'true' ) {
1034 +
1035 + // if there's any items in the array, process it
1036 + if ( isset( $_POST[ $value['name'] ] ) ) {
1037 + $ref_arr = [];
1038 + $cols = count( $value['columns'] );
1039 + $first = array_shift( array_values( sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) ) ); // first element
1040 + $rows = count( $first );
1041 +
1042 + // loop through columns
1043 + for ( $i = 0; $i < $rows; $i++ ) {
1044 +
1045 + // loop through the rows and store in a temp array
1046 + $temp = [];
1047 + for ( $j = 0; $j < $cols; $j++ ) {
1048 + $temp[] = isset( $_POST[ $value['name'] ][ $j ][ $i ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ][ $j ][ $i ] ) ) : '';
1049 + }
1050 +
1051 + // store all fields in a row with WeForms::$field_separator separated
1052 + $ref_arr[] = implode( WeForms::$field_separator, $temp );
1053 + }
1054 +
1055 + // now, if we found anything in $ref_arr, store to $multi_repeated
1056 + if ( $ref_arr ) {
1057 + $multi_repeated[ $value['name'] ] = array_slice( $ref_arr, 0, $rows );
1058 + }
1059 + }
1060 + } else {
1061 + $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) );
1062 + }
1063 +
1064 + break;
1065 +
1066 + case 'address_field':
1067 + if ( isset( $_POST[ $value['name'] ] ) && is_array( $_POST[ $value['name'] ] ) ) {
1068 + $post_value = sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) );
1069 + foreach ( $post_value as $address_field => $field_value ) {
1070 + $meta_key_value[ $value['name'] ][ $address_field ] = sanitize_text_field( $field_value );
1071 + }
1072 + }
1073 +
1074 + break;
1075 +
1076 + case 'text_field':
1077 + case 'email_address':
1078 + case 'numeric_text_field':
1079 + case 'date_field':
1080 + $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : '';
1081 +
1082 + break;
1083 +
1084 + case 'textarea_field':
1085 + $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : '';
1086 +
1087 + break;
1088 +
1089 + case 'dropdown_field':
1090 + case 'radio_field':
1091 + $val = sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) );
1092 + $meta_key_value[ $value['name'] ] = isset( $value['options'][ $val ] ) ? $value['options'][ $val ] : '';
1093 + break;
1094 +
1095 + case 'multiple_select':
1096 + case 'checkbox_field':
1097 + $val = ( is_array( $_POST[ $value['name'] ] ) && sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : array();
1098 + $meta_key_value[ $value['name'] ] = $val;
1099 +
1100 + if ( $val ) {
1101 + $new_val = [];
1102 +
1103 + foreach ( $val as $option_key ) {
1104 + $new_val[] = isset( $value['options'][ $option_key ] ) ? $value['options'][ $option_key ] : '';
1105 + }
1106 +
1107 + $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, $new_val );
1108 + }
1109 + break;
1110 +
1111 + default:
1112 + // if it's an array, implode with this->separator
1113 + if ( is_array( $_POST[ $value['name'] ] ) ) {
1114 + $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) );
1115 + } else {
1116 + $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ): '';
1117 + }
1118 +
1119 + break;
1120 + }
1121 + } //end foreach
1122 +
1123 + return [ $meta_key_value, $multi_repeated, $files ];
1124 + }
1125 +
1126 + /**
1127 + * Import a form from a JSON file
1128 + *
1129 + * @return void
1130 + */
1131 + public function import_form() {
1132 + check_ajax_referer( 'weforms' );
1133 +
1134 + $this->check_admin();
1135 +
1136 + $the_file = isset( $_FILES['importFile'] ) ? sanitize_text_field( wp_unslash( $_FILES['importFile'] ) ) : false;
1137 +
1138 + if ( !$the_file ) {
1139 + wp_send_json_error( __( 'No file found to import.', 'weforms' ) );
1140 + }
1141 +
1142 + $file_ext = pathinfo( $the_file['name'], PATHINFO_EXTENSION );
1143 +
1144 + if ( !class_exists( 'WeForms_Admin_Tools' ) ) {
1145 + require_once __DIR__ . '/admin/class-admin-tools.php';
1146 + }
1147 +
1148 + if ( ( $file_ext == 'json' ) && ( $the_file['size'] < 500000 ) ) {
1149 + $status = WeForms_Admin_Tools::import_json_file( $the_file['tmp_name'] );
1150 +
1151 + if ( $status ) {
1152 + wp_send_json_success( __( 'The forms have been imported successfully!', 'weforms' ) );
1153 + } else {
1154 + wp_send_json_error( __( 'Something went wrong importing the file.', 'weforms' ) );
1155 + }
1156 + } else {
1157 + wp_send_json_error( __( 'Invalid file or file size too big.', 'weforms' ) );
1158 + }
1159 + }
1160 +
1161 + /**
1162 + * Read Log file
1163 + *
1164 + * @return json
1165 + **/
1166 + public function get_logs() {
1167 + check_ajax_referer( 'weforms' );
1168 +
1169 + $this->check_admin();
1170 +
1171 + $file = weforms_log_file_path();
1172 +
1173 + if ( !file_exists( $file ) ) {
1174 + return;
1175 + }
1176 +
1177 + $data = file_get_contents( $file );
1178 + $data = explode( "\n", $data );
1179 + $data = array_reverse( $data );
1180 + $data = array_filter( $data );
1181 +
1182 + if ( empty( $data ) ) {
1183 + return;
1184 + }
1185 +
1186 + $logs = [];
1187 +
1188 + foreach ( $data as $key => $row ) {
1189 + preg_match( '/\[(?<time>.+?)\]\[(?<type>.+?)\](?<message>.+)/im', $row, $log );
1190 +
1191 + if ( empty( $log['message'] ) ) {
1192 + $log = [];
1193 + $log['message'] = !empty( $log['message'] ) ? $log['message'] : $row;
1194 + }
1195 +
1196 + if ( !empty( $log['time'] ) ) {
1197 + $human_time = human_time_diff( strtotime( $log['time'] ), current_time( 'timestamp' ) );
1198 + $log['time'] = $human_time ? $human_time . ' ' . __( 'ago', 'weforms' ) : $log['time'];
1199 + }
1200 +
1201 + $logs[] = $log;
1202 + }
1203 +
1204 + wp_send_json_success( $logs );
1205 + }
1206 +
1207 + /**
1208 + * Read Log file
1209 + *
1210 + * @return json
1211 + **/
1212 + public function delete_logs() {
1213 + check_ajax_referer( 'weforms' );
1214 +
1215 + $this->check_admin();
1216 +
1217 + $file = weforms_log_file_path();
1218 +
1219 + if ( !file_exists( $file ) ) {
1220 + return;
1221 + }
1222 +
1223 + @unlink( $file );
1224 +
1225 + wp_send_json_success();
1226 + }
1227 +}