| @@ -108,12 +108,9 @@ | ||
| 108 | 108 | $settings = array(); |
| 109 | 109 | $integrations = array(); |
| 110 | 110 | |
| 111 | 111 | if ( isset( $post_data['settings'] ) ) { |
| 112 | - $settings = json_decode( $post_data['settings'], true ); | |
| 113 | - $settings['message'] = sanitize_text_field( $settings['message'] ); | |
| 114 | - $settings['url'] = sanitize_url( $settings['url'] ); | |
| 115 | - $settings['limit_message'] = sanitize_text_field( $settings['limit_message'] ); | |
| 112 | + $settings = (array) json_decode( $post_data['settings'] ); | |
| 116 | 113 | } else { |
| 117 | 114 | $settings = isset( $form_data['wpuf_settings'] ) ? $form_data['wpuf_settings'] : []; |
| 118 | 115 | } |
| 119 | 116 | |
| @@ -120,8 +117,11 @@ | ||
| 120 | 117 | if ( isset( $post_data['integrations'] ) ) { |
| 121 | 118 | $integrations = (array) json_decode( $post_data['integrations'] ); |
| 122 | 119 | } |
| 123 | 120 | |
| 121 | + // $form_fields = wp_unslash( $form_fields ); | |
| 122 | + // $notifications = wp_unslash( $notifications ); | |
| 123 | + | |
| 124 | 124 | $form_fields = json_decode( $form_fields, true ); |
| 125 | 125 | $notifications = json_decode( $notifications, true ); |
| 126 | 126 | $data = [ |
| 127 | 127 | 'form_id' => absint( $form_data['wpuf_form_id'] ), |
| @@ -134,22 +134,11 @@ | ||
| 134 | 134 | ]; |
| 135 | 135 | |
| 136 | 136 | $form_fields = weforms()->form->save( $data ); |
| 137 | 137 | |
| 138 | - // Update Old Entry meta_key if changed | |
| 139 | - $form_id = $form_data['wpuf_form_id']; | |
| 140 | - $form = weforms()->form->get( $form_id ); | |
| 141 | - | |
| 142 | - $form->maybe_update_entries( $form_fields ); | |
| 143 | - | |
| 144 | 138 | do_action( 'weforms_update_form', $form_data['wpuf_form_id'], $form_fields, $settings ); |
| 145 | 139 | |
| 146 | - wp_send_json_success( | |
| 147 | - array( | |
| 148 | - 'form_fields' => $form_fields, | |
| 149 | - 'settings' => $settings, | |
| 150 | - ) | |
| 151 | - ); | |
| 140 | + wp_send_json_success( [ 'form_fields' => $form_fields ] ); | |
| 152 | 141 | } |
| 153 | 142 | |
| 154 | 143 | /** |
| 155 | 144 | * Get all contact forms |
| @@ -535,9 +524,9 @@ | ||
| 535 | 524 | |
| 536 | 525 | $has_empty = false; |
| 537 | 526 | $answers = []; |
| 538 | 527 | $respondentPoints = isset( $form_settings['total_points'] ) ? floatval( $form_settings['total_points'] ) : 0; |
| 539 | - $fields_formatted = array(); | |
| 528 | + | |
| 540 | 529 | foreach ( $fields as $key => $field ) { |
| 541 | 530 | if ( $form_settings['quiz_form'] == 'yes' ) { |
| 542 | 531 | $selectedAnswers = isset( $field['selected_answers'] ) ? $field['selected_answers'] : ''; |
| 543 | 532 | $givenAnswer = isset( $field['value'] ) ? $field['value'] : ''; |
| @@ -546,8 +535,9 @@ | ||
| 546 | 535 | $fieldPoints = isset( $field['points'] ) ? floatval( $field['points'] ) : 0; |
| 547 | 536 | |
| 548 | 537 | if ( $template == 'radio_field' || $template == 'dropdown_field' ) { |
| 549 | 538 | $answers[$field['name']] = true; |
| 539 | + | |
| 550 | 540 | if ( empty( $givenAnswer ) ) { |
| 551 | 541 | $answers[$field['name']] = false; |
| 552 | 542 | $respondentPoints -= $fieldPoints; |
| 553 | 543 | } else { |
| @@ -581,16 +571,14 @@ | ||
| 581 | 571 | } |
| 582 | 572 | } |
| 583 | 573 | } elseif ( empty( $field['value'] ) ) { |
| 584 | 574 | $has_empty = true; |
| 585 | - continue; | |
| 586 | - } else { | |
| 587 | - $field = WeForms_Form_Entry_Manager::format_entry_value( $field ); | |
| 588 | - array_push( $fields_formatted, $field ); | |
| 575 | + break; | |
| 589 | 576 | } |
| 590 | 577 | } |
| 578 | + | |
| 591 | 579 | $response = [ |
| 592 | - 'form_fields' => $fields_formatted, | |
| 580 | + 'form_fields' => $fields, | |
| 593 | 581 | 'form_settings' => $form_settings, |
| 594 | 582 | 'meta_data' => $metadata, |
| 595 | 583 | 'payment_data' => $payment, |
| 596 | 584 | 'has_empty' => $has_empty, |
| @@ -597,9 +585,8 @@ | ||
| 597 | 585 | 'respondent_points' => $respondentPoints, |
| 598 | 586 | 'answers' => $answers, |
| 599 | 587 | ]; |
| 600 | 588 | |
| 601 | - | |
| 602 | 589 | wp_send_json_success( $response ); |
| 603 | 590 | } |
| 604 | 591 | |
| 605 | 592 | /** |
| @@ -708,24 +695,13 @@ | ||
| 708 | 695 | * @return void |
| 709 | 696 | */ |
| 710 | 697 | public function handle_frontend_submission() { |
| 711 | 698 | check_ajax_referer( 'wpuf_form_add' ); |
| 699 | + | |
| 712 | 700 | $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0; |
| 713 | 701 | $page_id = isset( $_POST['page_id'] ) ? intval( $_POST['page_id'] ) : 0; |
| 702 | + | |
| 714 | 703 | $form = weforms()->form->get( $form_id ); |
| 715 | - | |
| 716 | - /** | |
| 717 | - * Check if form submission is open. This resolves broken access control with unauthenticated users. | |
| 718 | - * Access is now checked on frontend form rendering and submission. | |
| 719 | - */ | |
| 720 | - $form_submission_status = $form->is_submission_open(); | |
| 721 | - if ( is_wp_error( $form_submission_status ) ) { | |
| 722 | - wp_send_json( [ | |
| 723 | - 'success' => false, | |
| 724 | - 'error' => __( 'Login Required for submission.', 'weforms' ), | |
| 725 | - ] ); | |
| 726 | - } | |
| 727 | - | |
| 728 | 704 | $form_settings = $form->get_settings(); |
| 729 | 705 | $form_fields = $form->get_fields(); |
| 730 | 706 | $entry_fields = $form->prepare_entries(); |
| 731 | 707 | $form_entries = weforms_get_form_entries( $form_id, [ 'number' => '', 'offset' => '' ] ); |
| @@ -779,40 +755,23 @@ | ||
| 779 | 755 | $this->validate_submission( $entry_fields, $form, $form_settings, $form_fields ); |
| 780 | 756 | |
| 781 | 757 | $entry_fields = apply_filters( 'weforms_before_entry_submission', $entry_fields, $form, $form_settings, $form_fields ); |
| 782 | 758 | |
| 783 | - //check for entry_fields for a return error | |
| 784 | - if ( is_wp_error( $entry_fields ) ) { | |
| 759 | + $entry_id = weforms_insert_entry( [ | |
| 760 | + 'form_id' => $form_id, | |
| 761 | + ], $entry_fields ); | |
| 762 | + | |
| 763 | + if ( is_wp_error( $entry_id ) ) { | |
| 785 | 764 | wp_send_json( [ |
| 786 | 765 | 'success' => false, |
| 787 | - 'error' => $entry_fields->get_error_message(), | |
| 766 | + 'error' => $entry_id->get_error_message(), | |
| 788 | 767 | ] ); |
| 789 | - } else { | |
| 790 | - $entry_id = 1; | |
| 791 | - $global_settings = weforms_get_settings(); | |
| 792 | - if ( empty( $form_settings['after_submission'] ) ) { | |
| 793 | - $entry_id = weforms_insert_entry( [ | |
| 794 | - 'form_id' => $form_id, | |
| 795 | - ], $entry_fields ); | |
| 796 | - if ( is_wp_error( $entry_id ) ) { | |
| 797 | - wp_send_json( [ | |
| 798 | - 'success' => false, | |
| 799 | - 'error' => $entry_id->get_error_message(), | |
| 800 | - ] ); | |
| 801 | - } | |
| 802 | - // Fire a hook for integration | |
| 803 | - do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings ); | |
| 804 | - $notification = new WeForms_Notification( [ | |
| 805 | - 'form_id' => $form_id, | |
| 806 | - 'page_id' => $page_id, | |
| 807 | - 'entry_id' => $entry_id, | |
| 808 | - ] ); | |
| 809 | - $notification->send_notifications(); | |
| 810 | - } | |
| 811 | 768 | } |
| 769 | + | |
| 812 | 770 | // redirect URL |
| 813 | 771 | $show_message = false; |
| 814 | - $redirect_to = false; | |
| 772 | + $redirect_to = false; | |
| 773 | + | |
| 815 | 774 | if ( $form_settings['redirect_to'] == 'page' ) { |
| 816 | 775 | $redirect_to = get_permalink( $form_settings['page_id'] ); |
| 817 | 776 | } elseif ( $form_settings['redirect_to'] == 'url' ) { |
| 818 | 777 | $redirect_to = $form_settings['url']; |
| @@ -820,11 +779,17 @@ | ||
| 820 | 779 | $show_message = true; |
| 821 | 780 | } else { |
| 822 | 781 | $show_message = true; |
| 823 | 782 | } |
| 783 | + | |
| 784 | + // Fire a hook for integration | |
| 785 | + do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings ); | |
| 786 | + | |
| 824 | 787 | $field_search = $field_replace = []; |
| 788 | + | |
| 825 | 789 | foreach ( $form_fields as $r_field ) { |
| 826 | 790 | $field_search[] = '{' . $r_field['name'] . '}'; |
| 791 | + | |
| 827 | 792 | if ( $r_field['template'] == 'name_field' ) { |
| 828 | 793 | $field_replace[] = implode( ' ', explode( '|', $entry_fields[ $r_field['name'] ] ) ); |
| 829 | 794 | } else if ( $r_field['template'] == 'address_field' ) { |
| 830 | 795 | $field_replace[] = implode( ', ', $entry_fields[ $r_field['name'] ] ); |
| @@ -832,60 +797,68 @@ | ||
| 832 | 797 | $field_replace[] = isset( $entry_fields[ $r_field['name'] ] ) ? $entry_fields[ $r_field['name'] ] : ''; |
| 833 | 798 | } |
| 834 | 799 | } |
| 835 | 800 | $message = str_replace( $field_search, $field_replace, $form_settings['message'] ); |
| 801 | + | |
| 836 | 802 | // send the response |
| 837 | 803 | $response = apply_filters( 'weforms_entry_submission_response', [ |
| 838 | - 'success' => true, | |
| 839 | - 'redirect_to' => $redirect_to, | |
| 804 | + 'success' => true, | |
| 805 | + 'redirect_to' => $redirect_to, | |
| 840 | 806 | 'show_message' => $show_message, |
| 841 | - 'message' => $message, | |
| 842 | - 'data' => $_POST, | |
| 843 | - 'form_id' => $form_id, | |
| 844 | - 'entry_id' => $entry_id, | |
| 845 | - 'entry_fields' =>$entry_fields, | |
| 807 | + 'message' => $message, | |
| 808 | + 'data' => $_POST, | |
| 809 | + 'form_id' => $form_id, | |
| 810 | + 'entry_id' => $entry_id, | |
| 846 | 811 | ] ); |
| 847 | 812 | |
| 813 | + $notification = new WeForms_Notification( [ | |
| 814 | + 'form_id' => $form_id, | |
| 815 | + 'page_id' => $page_id, | |
| 816 | + 'entry_id' => $entry_id, | |
| 817 | + ] ); | |
| 818 | + | |
| 819 | + $notification->send_notifications(); | |
| 820 | + | |
| 848 | 821 | weforms_clear_buffer(); |
| 849 | 822 | wp_send_json( $response ); |
| 850 | - } | |
| 823 | + } | |
| 851 | 824 | |
| 852 | - function validate_reCaptchav3( $secret ) { | |
| 853 | - check_ajax_referer( 'wpuf_form_add' ); | |
| 825 | + function validate_reCaptchav3( $secret ) { | |
| 826 | + check_ajax_referer( 'wpuf_form_add' ); | |
| 854 | 827 | |
| 855 | - $post_data = wp_unslash($_POST); | |
| 856 | - $token = $post_data['g-recaptcha-response']; | |
| 857 | - $action = $post_data['g-action']; | |
| 858 | - $google_captcha_url = esc_url( 'https://www.google.com/recaptcha/api/siteverify' ); | |
| 828 | + $post_data = wp_unslash($_POST); | |
| 829 | + $token = $post_data['g-recaptcha-response']; | |
| 830 | + $action = $post_data['g-action']; | |
| 831 | + $google_captcha_url = esc_url( 'https://www.google.com/recaptcha/api/siteverify' ); | |
| 859 | 832 | |
| 860 | - $response = wp_remote_post( $google_captcha_url, | |
| 861 | - array( | |
| 862 | - 'method' => 'POST', | |
| 863 | - 'body' => array( | |
| 864 | - 'secret' => $secret, | |
| 865 | - 'response' => $token | |
| 866 | - ) | |
| 833 | + $response = wp_remote_post( $google_captcha_url, | |
| 834 | + array( | |
| 835 | + 'method' => 'POST', | |
| 836 | + 'body' => array( | |
| 837 | + 'secret' => $secret, | |
| 838 | + 'response' => $token | |
| 867 | 839 | ) |
| 868 | - ); | |
| 840 | + ) | |
| 841 | + ); | |
| 869 | 842 | |
| 870 | 843 | |
| 871 | - if ( is_wp_error( $response ) ) { | |
| 844 | + if ( is_wp_error( $response ) ) { | |
| 845 | + wp_send_json( [ | |
| 846 | + 'success' => false, | |
| 847 | + 'error' => __( 'reCAPTCHA validation failed', 'weforms' ), | |
| 848 | + ] ); | |
| 849 | + } else { | |
| 850 | + $api_response = json_decode( wp_remote_retrieve_body( $response ), true ); | |
| 851 | + if( $api_response["success"] == '1' && $api_response["action"] == $action ) { | |
| 852 | + return true; | |
| 853 | + } else { | |
| 872 | 854 | wp_send_json( [ |
| 873 | 855 | 'success' => false, |
| 874 | 856 | 'error' => __( 'reCAPTCHA validation failed', 'weforms' ), |
| 875 | 857 | ] ); |
| 876 | - } else { | |
| 877 | - $api_response = json_decode( wp_remote_retrieve_body( $response ), true ); | |
| 878 | - if( $api_response["success"] == '1' && $api_response["action"] == $action ) { | |
| 879 | - return true; | |
| 880 | - } else { | |
| 881 | - wp_send_json( [ | |
| 882 | - 'success' => false, | |
| 883 | - 'error' => __( 'reCAPTCHA validation failed', 'weforms' ), | |
| 884 | - ] ); | |
| 885 | - } | |
| 886 | 858 | } |
| 887 | 859 | } |
| 860 | + } | |
| 888 | 861 | /** |
| 889 | 862 | * reCaptcha Validation |
| 890 | 863 | * |
| 891 | 864 | * @return void |