PluginProbe
weForms – Easy Drag & Drop Contact Form Builder For WordPress / 1.6.8
weForms – Easy Drag & Drop Contact Form Builder For WordPress v1.6.8
1.6.7 1.6.8 1.6.9 1.6.12 1.6.13 1.6.14 1.6.15 1.6.16 1.6.17 1.6.18 1.6.19 1.6.2 1.6.20 1.6.21 1.6.22 1.6.23 1.6.24 1.6.25 1.6.26 1.6.27 1.6.28 1.6.3 1.6.4 1.6.5 1.6.6 All 74 releases
weforms / includes / class-ajax.php

class-ajax.php in weForms – Easy Drag & Drop Contact Form Builder For WordPress 1.6.8, at includes/class-ajax.php

1,221 lines 44.0 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 /**
4 * The ajax handler class
5 */
6 class WeForms_Ajax {
7
8 public function __construct() {
9
10 // backend requests
11 add_action( 'wp_ajax_weforms_form_list', [ $this, 'get_contact_forms' ] );
12 add_action( 'wp_ajax_weforms_get_users', [ $this, 'get_all_users' ] );
13 add_action( 'wp_ajax_weforms_form_names', [ $this, 'get_contact_form_names' ] );
14 add_action( 'wp_ajax_weforms_form_create', [ $this, 'create_form' ] );
15 add_action( 'wp_ajax_weforms_form_delete', [ $this, 'delete_form' ] );
16 add_action( 'wp_ajax_weforms_form_delete_bulk', [ $this, 'delete_form_bulk' ] );
17 add_action( 'wp_ajax_weforms_form_duplicate', [ $this, 'duplicate_form' ] );
18
19 // read logs
20 add_action( 'wp_ajax_weforms_read_logs', [ $this, 'get_logs' ] );
21 add_action( 'wp_ajax_weforms_delete_logs', [ $this, 'delete_logs' ] );
22
23 // create from a template
24 add_filter( 'wp_ajax_weforms_contact_form_template', [ $this, 'create_form_from_template' ] );
25
26 // form settings
27 add_action( 'wp_ajax_weforms_save_settings', [ $this, 'save_settings' ] );
28 add_action( 'wp_ajax_weforms_get_settings', [ $this, 'get_settings' ] );
29
30 // import
31 add_action( 'wp_ajax_weforms_import_form', [ $this, 'import_form' ] );
32
33 // form editing
34 add_action( 'wp_ajax_weforms_get_form', [ $this, 'get_form' ] );
35 add_action( 'wp_ajax_wpuf_form_builder_save_form', [ $this, 'save_form' ] );
36
37 // entries
38 add_action( 'wp_ajax_weforms_form_entries', [ $this, 'get_entries' ] );
39
40 add_action( 'wp_ajax_weforms_form_entry_details', [ $this, 'get_entry_detail' ] );
41 add_action( 'wp_ajax_weforms_form_entry_trash', [ $this, 'trash_entry' ] );
42 add_action( 'wp_ajax_weforms_form_entry_delete', [ $this, 'delete_entry' ] );
43 add_action( 'wp_ajax_weforms_form_entry_restore', [ $this, 'restore_entry' ] );
44
45 add_action( 'wp_ajax_weforms_form_entry_trash_bulk', [ $this, 'bulk_delete_entry' ] );
46 add_action( 'wp_ajax_weforms_form_entry_restore_bulk', [ $this, 'bulk_restore_entry' ] );
47
48 // frontend requests
49 add_action( 'wp_ajax_weforms_frontend_submit', [ $this, 'handle_frontend_submission' ] );
50 add_action( 'wp_ajax_nopriv_weforms_frontend_submit', [ $this, 'handle_frontend_submission' ] );
51 }
52
53 /**
54 * Administrator validation
55 *
56 * @return void
57 */
58 public function check_admin() {
59 if ( !current_user_can( weforms_form_access_capability() ) ) {
60 wp_send_json_error( __( 'You do not have sufficient permission.', 'weforms' ) );
61 }
62 }
63
64 /**
65 * Get a form to edit
66 *
67 * @return void
68 */
69 public function get_form() {
70 $this->check_admin();
71
72 $form_id = isset( $_REQUEST['form_id'] ) ? absint( $_REQUEST['form_id'] ) : 0;
73
74 $form = weforms()->form->get( $form_id );
75
76 $data = [
77 'post' => $form->data,
78 'form_fields' => $form->get_fields(),
79 'settings' => $form->get_settings(),
80 'notifications' => $form->get_notifications(),
81 'integrations' => $form->get_integrations(),
82 ];
83
84 wp_send_json_success( $data );
85 }
86
87 /**
88 * Save the form
89 *
90 * @return void
91 */
92 public function save_form() {
93 $post_data = wp_unslash( $_POST );
94 if ( isset( $post_data['form_data'] ) ) {
95 parse_str( sanitize_text_field( wp_unslash( $post_data['form_data'] ) ), $form_data );
96 }
97
98 if ( !wp_verify_nonce( $form_data['wpuf_form_builder_nonce'], 'wpuf_form_builder_save_form' ) ) {
99 wp_send_json_error( __( 'Unauthorized operation', 'weforms' ) );
100 }
101
102 if ( empty( $form_data['wpuf_form_id'] ) ) {
103 wp_send_json_error( __( 'Invalid form id', 'weforms' ) );
104 }
105
106 $form_fields = isset( $post_data['form_fields'] ) ? $post_data['form_fields'] : '';
107 $notifications = isset( $post_data['notifications'] ) ? $post_data['notifications']: '';
108 $settings = array();
109 $integrations = array();
110
111 if ( isset( $post_data['settings'] ) ) {
112 $settings = (array) json_decode( $post_data['settings'] );
113 } else {
114 $settings = isset( $form_data['wpuf_settings'] ) ? $form_data['wpuf_settings'] : [];
115 }
116
117 if ( isset( $post_data['integrations'] ) ) {
118 $integrations = (array) json_decode( $post_data['integrations'] );
119 }
120
121 $form_fields = json_decode( $form_fields, true );
122 $notifications = json_decode( $notifications, true );
123 $data = [
124 'form_id' => absint( $form_data['wpuf_form_id'] ),
125 'post_title' => $form_data['post_title'],
126 'form_fields' => $form_fields,
127 'form_settings' => $settings,
128 'form_settings_key' => isset( $form_data['form_settings_key'] ) ? $form_data['form_settings_key'] : '',
129 'notifications' => $notifications,
130 'integrations' => $integrations,
131 ];
132
133 $form_fields = weforms()->form->save( $data );
134
135 do_action( 'weforms_update_form', $form_data['wpuf_form_id'], $form_fields, $settings );
136
137 wp_send_json_success( [ 'form_fields' => $form_fields ] );
138 }
139
140 /**
141 * Get all contact forms
142 *
143 * @return void
144 */
145 public function get_contact_forms() {
146 check_ajax_referer( 'weforms' );
147
148 $this->check_admin();
149
150 $args = [
151 'posts_per_page' => isset( $_POST['posts_per_page'] ) ? intval( $_POST['posts_per_page'] ) : 10,
152 'paged' => isset( $_POST['page'] ) ? absint( $_POST['page'] ) : 1,
153 'order' => 'DESC',
154 'orderby' => 'post_date',
155 ];
156
157 $args = apply_filters( 'weforms_ajax_get_contact_forms_args', $args );
158
159 $contact_forms = weforms()->form->get_forms( $args );
160
161 array_map(
162 function ( $form ) {
163 $form->entries = $form->num_form_entries();
164 $form->settings = $form->get_settings();
165 $form->views = $form->num_form_views();
166 $form->payments = $form->num_form_payments();
167 $form->author = $form->get_form_author_details();
168 }, $contact_forms['forms']
169 );
170
171 $contact_forms = $this->filter_contact_forms( $contact_forms );
172 $contact_forms = apply_filters( 'weforms_ajax_get_contact_forms', $contact_forms );
173
174 wp_send_json_success( $contact_forms );
175 }
176
177 /**
178 * Get all users
179 *
180 * @return array
181 */
182 public function get_all_users() {
183 check_ajax_referer( 'weforms' );
184
185 $this->check_admin();
186
187 $users_meta = [];
188 $users = get_users( [ 'fields' => [ 'ID' ] ] );
189
190 foreach ( $users as $user ) {
191 $users_meta[] = [
192 'id' => $user->ID,
193 'data' => get_user_meta( $user->ID ),
194 ];
195 }
196
197 wp_send_json_success( $users_meta );
198 }
199
200 /**
201 * Filter
202 *
203 * @return void
204 */
205 public function filter_contact_forms( &$contact_forms ) {
206 if ( isset( $_REQUEST['filter'] ) && $_REQUEST['filter'] == 'entries' ) {
207 foreach ( $contact_forms['forms'] as $key => &$form ) {
208 if ( isset( $form->entries ) && !$form->entries ) {
209 unset( $contact_forms['forms'][ $key ] );
210 }
211 }
212
213 $contact_forms['meta']['total'] = count( $contact_forms['forms'] );
214 }
215
216 return $contact_forms;
217 }
218
219 /**
220 * Get the names of contact forms for generating dropdown
221 *
222 * @return void
223 */
224 public function get_contact_form_names() {
225 check_ajax_referer( 'weforms' );
226
227 $this->check_admin();
228
229 $contact_forms = weforms()->form->all();
230 $response = [];
231
232 foreach ( $contact_forms['forms'] as $form ) {
233 $response[] = [
234 'id' => $form->get_id(),
235 'title' => $form->get_name() . ' (#' . $form->get_id() . ')',
236 ];
237 }
238
239 wp_send_json_success( $response );
240 }
241
242 /**
243 * Create a form
244 *
245 * @return void
246 */
247 public function create_form() {
248 check_ajax_referer( 'weforms' );
249
250 $this->check_admin();
251
252 $form_name = isset( $_POST['form_name'] ) ? sanitize_text_field( wp_unslash( $_POST['form_name'] ) ) : '';
253
254 if ( empty( $form_name ) ) {
255 wp_send_json_error( __( 'Please provide a form name', 'weforms' ) );
256 }
257
258 $form_id = weforms()->form->create( $form_name );
259
260 if ( is_wp_error( $form_id ) ) {
261 wp_send_json_error( $form_id->get_error_message() );
262 }
263
264 wp_send_json_success( [
265 'form_id' => $form_id,
266 'form_name' => $form_name,
267 ] );
268 }
269
270 /**
271 * Delete a form
272 *
273 * @return void
274 */
275 public function delete_form() {
276 check_ajax_referer( 'weforms' );
277
278 $this->check_admin();
279
280 $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
281
282 if ( !$form_id ) {
283 wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
284 }
285
286 weforms()->form->delete( $form_id );
287
288 wp_send_json_success();
289 }
290
291 public function delete_form_bulk() {
292 check_ajax_referer( 'weforms' );
293
294 $this->check_admin();
295
296 $form_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : [];
297
298 if ( !$form_ids ) {
299 wp_send_json_error( __( 'No form ids provided!', 'weforms' ) );
300 }
301
302 foreach ( $form_ids as $form_id ) {
303 weforms()->form->delete( $form_id );
304 }
305
306 wp_send_json_success();
307 }
308
309 /**
310 * Duplicate a form
311 *
312 * @return voiud
313 */
314 public function duplicate_form() {
315 check_ajax_referer( 'weforms' );
316
317 $this->check_admin();
318
319 $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
320
321 $form = weforms()->form->duplicate( $form_id );
322 $form->settings = $form->get_settings();
323
324 wp_send_json_success( $form );
325 }
326
327 /**
328 * Create form from a template
329 *
330 * @return void
331 */
332 public function create_form_from_template() {
333 check_ajax_referer( 'weforms' );
334
335 $template = isset( $_REQUEST['template'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['template'] ) ) : '';
336
337 $form_id = weforms()->templates->create( $template );
338
339 if ( is_wp_error( $form_id ) ) {
340 wp_send_json_error( __( 'Could not create the form', 'weforms' ) );
341 }
342
343 wp_send_json_success( [
344 'id' => $form_id,
345 ] );
346 }
347
348 /**
349 * Save the weForms settings
350 *
351 * @return void
352 */
353 public function save_settings() {
354 check_ajax_referer( 'weforms' );
355 $this->check_admin();
356
357 $requires_wpuf_update = false;
358 $wpuf_update_array = array();
359 $settings = isset( $_POST['settings'] ) ? (array) json_decode( wp_unslash( $_POST['settings'] ) ) : [];
360 update_option( 'weforms_settings', $settings );
361
362 // wpuf settings sync
363 if ( isset( $settings['gmap_api'] ) ) {
364 $requires_wpuf_update = true;
365 $wpuf_update_array['gmap_api_key'] = $settings['gmap_api'];
366 }
367
368 if ( isset( $settings['recaptcha'] ) ) {
369 $requires_wpuf_update = true;
370 $wpuf_update_array['recaptcha_public'] = $settings['recaptcha']->key;
371 $wpuf_update_array['recaptcha_private'] = $settings['recaptcha']->secret;
372 $wpuf_update_array['recaptcha_type'] = $settings['recaptcha']->type;
373 }
374
375 if ( isset( $settings['no_conflict'] ) ) {
376 $requires_wpuf_update = true;
377 $wpuf_update_array['no_conflict'] = $settings['no_conflict'];
378 }
379
380 if ( isset( $settings['email_footer'] ) ) {
381 $requires_wpuf_update = true;
382 $wpuf_update_array['email_footer'] = $settings['email_footer'];
383 }
384
385 if ( $requires_wpuf_update ) {
386 $wpuf_settings = get_option( 'wpuf_general', [] );
387
388 $wpuf_settings = array_merge( $wpuf_settings, $wpuf_update_array );
389 update_option( 'wpuf_general', $wpuf_settings );
390 }
391
392 do_action( 'weforms_save_settings', $settings );
393
394 $settings = apply_filters( 'weforms_after_save_settings', $settings );
395 wp_send_json_success( $settings );
396 }
397
398 /**
399 * Get the weForms Settings
400 *
401 * @return void
402 */
403 public function get_settings() {
404 check_ajax_referer( 'weforms' );
405
406 $this->check_admin();
407
408 $settings = weforms_get_settings();
409 // checking to prevent js error, will be removed in future
410 if ( !isset( $settings['credit'] ) ) {
411 $settings['credit'] = false;
412 }
413
414 if ( !isset( $settings['permission'] ) ) {
415 $settings['permission'] = 'manage_options';
416 }
417
418 wp_send_json_success( $settings );
419 }
420
421 /**
422 * Get all entries
423 *
424 * @return void
425 */
426 public function get_entries() {
427 check_ajax_referer( 'weforms' );
428
429 $this->check_admin();
430
431 $form_id = isset( $_REQUEST['id'] ) ? intval( $_REQUEST['id'] ) : 0;
432 $current_page = isset( $_REQUEST['page'] ) ? intval( $_REQUEST['page'] ) : 1;
433 $status = isset( $_REQUEST['status'] ) ? sanitize_text_field( wp_unslash( $_REQUEST['status'] ) ) : 'publish';
434 $per_page = 20;
435 $offset = ( $current_page - 1 ) * $per_page;
436
437 if ( !$form_id ) {
438 wp_send_json_error( __( 'No form id provided!', 'weforms' ) );
439 }
440
441 $entries = weforms_get_form_entries(
442 $form_id, [
443 'number' => $per_page,
444 'offset' => $offset,
445 'status' => $status,
446 ]
447 );
448
449 $columns = weforms_get_entry_columns( $form_id );
450 $total_entries = weforms_count_form_entries( $form_id, $status );
451
452 array_map(
453 function ( $entry ) use ( $columns ) {
454 $entry_id = $entry->id;
455 $entry->fields = [];
456
457 foreach ( $columns as $meta_key => $label ) {
458 if ( empty( $meta_key ) ) {
459 continue;
460 }
461 $value = weforms_get_entry_meta( $entry_id, $meta_key, true );
462 $entry->fields[ $meta_key ] = str_replace( WeForms::$field_separator, ' ', $value );
463 }
464 }, $entries
465 );
466
467 $entries = apply_filters( 'weforms_get_entries', $entries, $form_id );
468
469 $response = [
470 'columns' => $columns,
471 'entries' => $entries,
472 'form_title' => get_post_field( 'post_title', $form_id ),
473 'pagination' => [
474 'total' => $total_entries,
475 'per_page' => $per_page,
476 'pages' => ceil( $total_entries / $per_page ),
477 'current' => $current_page,
478 ],
479 'meta' => [
480 'total' => weforms_count_form_entries( $form_id ),
481 'totalTrash' => weforms_count_form_entries( $form_id, 'trash' ),
482 ],
483 ];
484
485 wp_send_json_success( $response );
486 }
487
488 /**
489 * Get an entry details
490 *
491 * @return void
492 */
493 public function get_entry_detail() {
494 check_ajax_referer( 'weforms' );
495
496 $this->check_admin();
497
498 $form_id = isset( $_REQUEST['form_id'] ) ? intval( $_REQUEST['form_id'] ) : 0;
499 $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
500
501 $form = weforms()->form->get( $form_id );
502 $form_settings = $form->get_settings();
503 $entry = $form->entries()->get( $entry_id );
504 $fields = $entry->get_fields();
505 $metadata = $entry->get_metadata();
506 $payment = $entry->get_payment_data();
507
508 if ( isset( $payment->payment_data ) && is_serialized( $payment->payment_data ) ) {
509 $payment->payment_data = unserialize( $payment->payment_data );
510 }
511
512 if ( false === $fields ) {
513 wp_send_json_error( __( 'No form fields found!', 'weforms' ) );
514 }
515
516 if ( sizeof( $fields ) < 1 ) {
517 $fields[] = [
518 'label' => __( 'No form fields found!', 'weforms' ),
519 ];
520 }
521
522 $has_empty = false;
523 $answers = [];
524 $respondentPoints = isset( $form_settings['total_points'] ) ? floatval( $form_settings['total_points'] ) : 0;
525
526 foreach ( $fields as $key => $field ) {
527 if ( $form_settings['quiz_form'] == 'yes' ) {
528 $selectedAnswers = isset( $field['selected_answers'] ) ? $field['selected_answers'] : '';
529 $givenAnswer = isset( $field['value'] ) ? $field['value'] : '';
530 $options = isset( $field['options'] ) ? $field['options'] : '';
531 $template = $field['template'];
532 $fieldPoints = isset( $field['points'] ) ? floatval( $field['points'] ) : 0;
533
534 if ( $template == 'radio_field' || $template == 'dropdown_field' ) {
535 $answers[$field['name']] = true;
536
537 if ( empty( $givenAnswer ) ) {
538 $answers[$field['name']] = false;
539 $respondentPoints -= $fieldPoints;
540 } else {
541 foreach ( $options as $key => $value ) {
542 if ( $givenAnswer == $value ) {
543 if ( $key != $selectedAnswers ) {
544 $answers[$field['name']] = false;
545 $respondentPoints -= $fieldPoints;
546 }
547 }
548 }
549 }
550 } elseif ( $template == 'checkbox_field' || $template == 'multiple_select' ) {
551 $answers[$field['name']] = true;
552 $userAnswer = [];
553
554 foreach ( $options as $key => $value ) {
555 foreach ( $givenAnswer as $answer ) {
556 if ( $value == $answer ) {
557 $userAnswer[] = $key;
558 }
559 }
560 }
561
562 $userAnswer = implode( '|', $userAnswer );
563 $rightAnswers = implode( '|', $selectedAnswers );
564
565 if ( $userAnswer != $rightAnswers || empty( $userAnswer ) ) {
566 $answers[$field['name']] = false;
567 $respondentPoints -= $fieldPoints;
568 }
569 }
570 } elseif ( empty( $field['value'] ) ) {
571 $has_empty = true;
572 break;
573 }
574 }
575
576 $response = [
577 'form_fields' => $fields,
578 'form_settings' => $form_settings,
579 'meta_data' => $metadata,
580 'payment_data' => $payment,
581 'has_empty' => $has_empty,
582 'respondent_points' => $respondentPoints,
583 'answers' => $answers,
584 ];
585
586 wp_send_json_success( $response );
587 }
588
589 /**
590 * Trash an entry
591 *
592 * @return void
593 */
594 public function trash_entry() {
595 check_ajax_referer( 'weforms' );
596
597 $this->check_admin();
598
599 $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
600
601 weforms_change_entry_status( $entry_id, 'trash' );
602 wp_send_json_success();
603 }
604
605 /**
606 * Trash an entry
607 *
608 * @return void
609 */
610 public function delete_entry() {
611 check_ajax_referer( 'weforms' );
612
613 $this->check_admin();
614
615 $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
616
617 weforms_delete_entry( $entry_id );
618
619 wp_send_json_success();
620 }
621
622 /**
623 * Restore Entry
624 *
625 * @return void
626 */
627 public function restore_entry() {
628 check_ajax_referer( 'weforms' );
629
630 $this->check_admin();
631
632 $entry_id = isset( $_REQUEST['entry_id'] ) ? intval( $_REQUEST['entry_id'] ) : 0;
633
634 weforms_change_entry_status( $entry_id, 'publish' );
635 wp_send_json_success();
636 }
637
638 /**
639 * Bulk trash entries
640 *
641 * @return void
642 */
643 public function bulk_delete_entry() {
644 check_ajax_referer( 'weforms' );
645
646 $this->check_admin();
647
648 $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : array();
649 $permanent = isset( $_POST['permanent'] ) && ( sanitize_text_field( wp_unslash ( $_POST['permanent'] ) ) ) ? true : false;
650
651 if ( !$entry_ids ) {
652 wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
653 }
654
655 foreach ( $entry_ids as $entry_id ) {
656 if ( $permanent ) {
657 weforms_delete_entry( $entry_id );
658 } else {
659 weforms_change_entry_status( $entry_id, 'trash' );
660 }
661 }
662
663 wp_send_json_success();
664 }
665
666 /**
667 * Bulk trash entries
668 *
669 * @return void
670 */
671 public function bulk_restore_entry() {
672 check_ajax_referer( 'weforms' );
673
674 $this->check_admin();
675
676 $entry_ids = isset( $_POST['ids'] ) ? array_map( 'absint', $_POST['ids'] ) : [];
677
678 if ( !$entry_ids ) {
679 wp_send_json_error( __( 'No entry ids provided!', 'weforms' ) );
680 }
681
682 foreach ( $entry_ids as $entry_id ) {
683 weforms_change_entry_status( $entry_id, 'publish' );
684 }
685
686 wp_send_json_success();
687 }
688
689 /**
690 * Handle the frontend submission
691 *
692 * @return void
693 */
694 public function handle_frontend_submission() {
695 check_ajax_referer( 'wpuf_form_add' );
696
697 $form_id = isset( $_POST['form_id'] ) ? intval( $_POST['form_id'] ) : 0;
698 $page_id = isset( $_POST['page_id'] ) ? intval( $_POST['page_id'] ) : 0;
699
700 $form = weforms()->form->get( $form_id );
701 $form_settings = $form->get_settings();
702 $form_fields = $form->get_fields();
703 $entry_fields = $form->prepare_entries();
704 $form_entries = weforms_get_form_entries( $form_id, [ 'number' => '', 'offset' => '' ] );
705
706 if ( $form_fields && count( $form_entries ) && count( $entry_fields ) ) {
707 foreach ( $entry_fields as $field_key => $field_value ) {
708 $duplicate_check = false;
709 $field_label = 'This';
710
711 foreach ( $form_fields as $form_field ) {
712 if ( in_array( $form_field['template'], [ 'text_field', 'website_url', 'numeric_text_field', 'email_address' ] ) && $form_field['name'] == $field_key && isset( $form_field['duplicate'] ) && 'no' == $form_field['duplicate'] ) {
713 $duplicate_check = true;
714 $field_label = $form_field['label'];
715 }
716 }
717
718 if ( $duplicate_check ) {
719 foreach ( $form_entries as $entry ) {
720 $existing = weforms_get_entry_meta( $entry->id, $field_key, true );
721
722 if ( $existing && $field_value == $existing ) {
723 wp_send_json( [
724 'success' => false,
725 'error' => sprintf( __( '"%s" field requires a unique entry and "%s" has already been used.', 'weforms' ), $field_label, $field_value ),
726 ] );
727 }
728 }
729 }
730 }
731 }
732
733 if ( !$form_fields ) {
734 wp_send_json( [
735 'success' => false,
736 'error' => __( 'No form field was found.', 'weforms' ),
737 ] );
738 }
739
740 if ( $form->has_field( 'recaptcha' ) ) {
741 $settings = weforms_get_settings( 'recaptcha' );
742 $type = isset( $settings->type ) ? $settings->type : '';
743 $secret = isset( $settings->secret ) ? $settings->secret : '';
744 if( $type == 'v3' ) {
745 $this->validate_reCaptchav3( $secret );
746 } else {
747 $this->validate_reCaptcha();
748 }
749 }
750
751 // vaidate submission
752 $this->validate_submission( $entry_fields, $form, $form_settings, $form_fields );
753
754 $entry_fields = apply_filters( 'weforms_before_entry_submission', $entry_fields, $form, $form_settings, $form_fields );
755
756 $entry_id = 1;
757 $global_settings = weforms_get_settings();
758 if ( empty( $global_settings['after_submission'] ) ) {
759 $entry_id = weforms_insert_entry( [
760 'form_id' => $form_id,
761 ], $entry_fields );
762 if ( is_wp_error( $entry_id ) ) {
763 wp_send_json( [
764 'success' => false,
765 'error' => $entry_id->get_error_message(),
766 ] );
767 }
768 // Fire a hook for integration
769 do_action( 'weforms_entry_submission', $entry_id, $form_id, $page_id, $form_settings );
770 $notification = new WeForms_Notification( [
771 'form_id' => $form_id,
772 'page_id' => $page_id,
773 'entry_id' => $entry_id,
774 ] );
775 $notification->send_notifications();
776 }
777 // redirect URL
778 $show_message = false;
779 $redirect_to = false;
780 if ( $form_settings['redirect_to'] == 'page' ) {
781 $redirect_to = get_permalink( $form_settings['page_id'] );
782 } elseif ( $form_settings['redirect_to'] == 'url' ) {
783 $redirect_to = $form_settings['url'];
784 } elseif ( $form_settings['redirect_to'] == 'same' ) {
785 $show_message = true;
786 } else {
787 $show_message = true;
788 }
789 $field_search = $field_replace = [];
790 foreach ( $form_fields as $r_field ) {
791 $field_search[] = '{' . $r_field['name'] . '}';
792 if ( $r_field['template'] == 'name_field' ) {
793 $field_replace[] = implode( ' ', explode( '|', $entry_fields[ $r_field['name'] ] ) );
794 } else if ( $r_field['template'] == 'address_field' ) {
795 $field_replace[] = implode( ', ', $entry_fields[ $r_field['name'] ] );
796 } else {
797 $field_replace[] = isset( $entry_fields[ $r_field['name'] ] ) ? $entry_fields[ $r_field['name'] ] : '';
798 }
799 }
800 $message = str_replace( $field_search, $field_replace, $form_settings['message'] );
801 // send the response
802 $response = apply_filters( 'weforms_entry_submission_response', [
803 'success' => true,
804 'redirect_to' => $redirect_to,
805 'show_message' => $show_message,
806 'message' => $message,
807 'data' => $_POST,
808 'form_id' => $form_id,
809 'entry_id' => $entry_id,
810 'entry_fields' =>$entry_fields,
811 ] );
812 weforms_clear_buffer();
813 wp_send_json( $response );
814 }
815
816 function validate_reCaptchav3( $secret ) {
817 check_ajax_referer( 'wpuf_form_add' );
818
819 $post_data = wp_unslash($_POST);
820 $token = $post_data['g-recaptcha-response'];
821 $action = $post_data['g-action'];
822 $google_captcha_url = esc_url( 'https://www.google.com/recaptcha/api/siteverify' );
823
824 $response = wp_remote_post( $google_captcha_url,
825 array(
826 'method' => 'POST',
827 'body' => array(
828 'secret' => $secret,
829 'response' => $token
830 )
831 )
832 );
833
834
835 if ( is_wp_error( $response ) ) {
836 wp_send_json( [
837 'success' => false,
838 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
839 ] );
840 } else {
841 $api_response = json_decode( wp_remote_retrieve_body( $response ), true );
842 if( $api_response["success"] == '1' && $api_response["action"] == $action ) {
843 return true;
844 } else {
845 wp_send_json( [
846 'success' => false,
847 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
848 ] );
849 }
850 }
851 }
852 /**
853 * reCaptcha Validation
854 *
855 * @return void
856 */
857 function validate_reCaptcha() {
858 check_ajax_referer( 'wpuf_form_add' );
859 if ( class_exists( 'WPUF_ReCaptcha' ) ) {
860 $recaptcha_class = 'WPUF_ReCaptcha';
861 } else {
862 if ( !function_exists( 'recaptcha_get_html' ) ) {
863 require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib.php';
864 }
865
866 require_once WEFORMS_INCLUDES . '/library/reCaptcha/recaptchalib_noCaptcha.php';
867 $recaptcha_class = 'Weforms_ReCaptcha';
868 }
869
870 $invisible = isset( $_POST['g-recaptcha-response'] ) ? false : true;
871
872 $recaptcha_settings = weforms_get_settings( 'recaptcha' );
873 $secret = isset( $recaptcha_settings->secret ) ? $recaptcha_settings->secret : '';
874
875 if ( ! $invisible ) {
876 $response = null;
877 $reCaptcha = new $recaptcha_class( $secret );
878 $remote_ADDR = isset( $_SERVER['REMOTE_ADDR'] ) ? sanitize_text_field( wp_unslash( $_SERVER['REMOTE_ADDR'] ) ) : '';
879 $recaptcha_response = isset( $_POST['g-recaptcha-response'] ) ? sanitize_text_field( wp_unslash( $_POST['g-recaptcha-response'] ) ) : '';
880 $resp = $reCaptcha->verifyResponse(
881 $remote_ADDR,
882 $recaptcha_response
883 );
884
885 if ( !$resp->success ) {
886 wp_send_json( [
887 'success' => false,
888 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
889 ] );
890 }
891
892 } else {
893
894 $recap_challenge = isset( $_POST['recaptcha_challenge_field'] ) ? sanitize_text_field( wp_unslash( $_POST['recaptcha_challenge_field'] ) ) : '';
895 $recap_response = isset( $_POST['recaptcha_response_field'] ) ? sanitize_text_field( wp_unslash( $_POST['recaptcha_response_field'] ) ) : '';
896 $resp = recaptcha_check_answer( $secret, $remote_ADDR, $recap_challenge, $recap_response );
897
898 if ( !$resp->is_valid ) {
899 ob_clean();
900
901 wp_send_json( [
902 'success' => false,
903 'error' => __( 'reCAPTCHA validation failed', 'weforms' ),
904 ] );
905 }
906 }
907 }
908
909 /**
910 * Validate submission
911 *
912 * @param array $entry_fields
913 * @param object $form
914 * @param array $form_settings
915 * @param array $form_fields
916 *
917 * @return bool|json
918 */
919 public function validate_submission( $entry_fields, $form, $form_settings, $form_fields ) {
920 foreach ( $form_fields as $key => $field ) {
921
922 //skip custom html field as it is not saved
923 if ( 'custom_html' == $field['name'] ) {
924 continue;
925 }
926
927 //skip recaptcha field as it is not saved
928 if ( 'recaptcha' == $field['name'] ) {
929 continue;
930 }
931
932 $value = $entry_fields[ $field['name'] ];
933
934 if ( 'single_product' === $field['template'] ) {
935 if ( !$value ) {
936 $value = [];
937 }
938
939 $value['price'] = isset( $value['price'] ) ? floatval( $value['price'] ) : 0;
940 $value['quantity'] = isset( $value['quantity'] ) ? floatval( $value['quantity'] ) : 0;
941 $quantity = isset( $field['quantity'] ) ? $field['quantity'] : [];
942 $price = isset( $field['price'] ) ? $field['price'] : [];
943
944 if ( isset( $price['is_flexible'] ) && $price['is_flexible'] ) {
945 $min = isset( $price['min'] ) ? floatval( $price['min'] ) : 0;
946 $max = isset( $price['max'] ) ? floatval( $price['max'] ) : 0;
947
948 if ( $value['price'] < $min ) {
949 wp_send_json( [
950 'success' => false,
951 'error' => __( sprintf(
952 '%s price must be equal or greater than %s',
953 $field['weforms'],
954 $min ),
955 'weforms' ),
956 ] );
957 }
958
959 if ( $max && $value['price'] > $max ) {
960 wp_send_json( [
961 'success' => false,
962 'error' => __( sprintf(
963 '%s price must be equal or less than %s',
964 $field['weforms'],
965 $max ),
966 'weforms' ),
967 ] );
968 }
969 }
970
971 if ( isset( $quantity['status'] ) && $quantity['status'] ) {
972 $min = isset( $quantity['min'] ) ? floatval( $quantity['min'] ) : 0;
973 $max = isset( $quantity['max'] ) ? floatval( $quantity['max'] ) : 0;
974
975 if ( $value['quantity'] < $min ) {
976 wp_send_json( [
977 'success' => false,
978 'error' => __( sprintf(
979 '%s quantity must be equal or greater than %s',
980 $field['weforms'],
981 $min ),
982 'weforms' ),
983 ] );
984 }
985
986 if ( $max && $value['quantity'] > $max ) {
987 wp_send_json( [
988 'success' => false,
989 'error' => __( sprintf(
990 '%s quantity must be equal or less than %s',
991 $field['weforms'],
992 $max ),
993 'weforms' ),
994 ] );
995 }
996 }
997 }
998 }
999 }
1000
1001 public static function prepare_meta_fields( $meta_vars ) {
1002 check_ajax_referer( 'wpuf_form_add' );
1003 // loop through custom fields
1004 // skip files, put in a key => value paired array for later executation
1005 // process repeatable fields separately
1006 // if the input is array type, implode with separator in a field
1007 $files = [];
1008 $meta_key_value = [];
1009 $multi_repeated = []; // multi repeated fields will in sotre duplicated meta key
1010
1011 foreach ( $meta_vars as $key => $value ) {
1012 switch ( $value['template'] ) {
1013
1014 // put files in a separate array, we'll process it later
1015 case 'file_upload':
1016 case 'image_upload':
1017 $files[] = [
1018 'name' => $value['name'],
1019 'value' => isset( $_POST['wpuf_files'][ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST['wpuf_files'][ $value['name'] ] ) ) : array(),
1020 'count' => $value['count']
1021 ];
1022 break;
1023
1024 case 'repeat_field':
1025 // if it is a multi column repeat field
1026 if ( isset( $value['multiple'] ) && $value['multiple'] == 'true' ) {
1027
1028 // if there's any items in the array, process it
1029 if ( isset( $_POST[ $value['name'] ] ) ) {
1030 $ref_arr = [];
1031 $cols = count( $value['columns'] );
1032 $first = array_shift( array_values( sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) ) ); // first element
1033 $rows = count( $first );
1034
1035 // loop through columns
1036 for ( $i = 0; $i < $rows; $i++ ) {
1037
1038 // loop through the rows and store in a temp array
1039 $temp = [];
1040 for ( $j = 0; $j < $cols; $j++ ) {
1041 $temp[] = isset( $_POST[ $value['name'] ][ $j ][ $i ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ][ $j ][ $i ] ) ) : '';
1042 }
1043
1044 // store all fields in a row with WeForms::$field_separator separated
1045 $ref_arr[] = implode( WeForms::$field_separator, $temp );
1046 }
1047
1048 // now, if we found anything in $ref_arr, store to $multi_repeated
1049 if ( $ref_arr ) {
1050 $multi_repeated[ $value['name'] ] = array_slice( $ref_arr, 0, $rows );
1051 }
1052 }
1053 } else {
1054 $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) );
1055 }
1056
1057 break;
1058
1059 case 'address_field':
1060 if ( isset( $_POST[ $value['name'] ] ) && is_array( $_POST[ $value['name'] ] ) ) {
1061 $post_value = sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) );
1062 foreach ( $post_value as $address_field => $field_value ) {
1063 $meta_key_value[ $value['name'] ][ $address_field ] = sanitize_text_field( $field_value );
1064 }
1065 }
1066
1067 break;
1068
1069 case 'text_field':
1070 case 'email_address':
1071 case 'numeric_text_field':
1072 case 'date_field':
1073 $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : '';
1074
1075 break;
1076
1077 case 'textarea_field':
1078 $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : '';
1079
1080 break;
1081
1082 case 'dropdown_field':
1083 case 'radio_field':
1084 $val = sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) );
1085 $meta_key_value[ $value['name'] ] = isset( $value['options'][ $val ] ) ? $value['options'][ $val ] : '';
1086 break;
1087
1088 case 'multiple_select':
1089 case 'checkbox_field':
1090 $val = ( is_array( $_POST[ $value['name'] ] ) && sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) : array();
1091 $meta_key_value[ $value['name'] ] = $val;
1092
1093 if ( $val ) {
1094 $new_val = [];
1095
1096 foreach ( $val as $option_key ) {
1097 $new_val[] = isset( $value['options'][ $option_key ] ) ? $value['options'][ $option_key ] : '';
1098 }
1099
1100 $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, $new_val );
1101 }
1102 break;
1103
1104 default:
1105 // if it's an array, implode with this->separator
1106 if ( is_array( $_POST[ $value['name'] ] ) ) {
1107 $meta_key_value[ $value['name'] ] = implode( WeForms::$field_separator, sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ) );
1108 } else {
1109 $meta_key_value[ $value['name'] ] = isset( $_POST[ $value['name'] ] ) ? sanitize_text_field( wp_unslash( $_POST[ $value['name'] ] ) ): '';
1110 }
1111
1112 break;
1113 }
1114 } //end foreach
1115
1116 return [ $meta_key_value, $multi_repeated, $files ];
1117 }
1118
1119 /**
1120 * Import a form from a JSON file
1121 *
1122 * @return void
1123 */
1124 public function import_form() {
1125 check_ajax_referer( 'weforms' );
1126
1127 $this->check_admin();
1128
1129 $the_file = isset( $_FILES['importFile'] ) ? $_FILES['importFile'] : false;
1130
1131 if ( !$the_file ) {
1132 wp_send_json_error( __( 'No file found to import.', 'weforms' ) );
1133 }
1134
1135 $file_ext = pathinfo( $the_file['name'], PATHINFO_EXTENSION );
1136
1137 if ( !class_exists( 'WeForms_Admin_Tools' ) ) {
1138 require_once __DIR__ . '/admin/class-admin-tools.php';
1139 }
1140
1141 if ( ( $file_ext == 'json' ) && ( $the_file['size'] < 500000 ) ) {
1142 $status = WeForms_Admin_Tools::import_json_file( $the_file['tmp_name'] );
1143
1144 if ( $status ) {
1145 wp_send_json_success( __( 'The forms have been imported successfully!', 'weforms' ) );
1146 } else {
1147 wp_send_json_error( __( 'Something went wrong importing the file.', 'weforms' ) );
1148 }
1149 } else {
1150 wp_send_json_error( __( 'Invalid file or file size too big.', 'weforms' ) );
1151 }
1152 }
1153
1154 /**
1155 * Read Log file
1156 *
1157 * @return json
1158 **/
1159 public function get_logs() {
1160 check_ajax_referer( 'weforms' );
1161
1162 $this->check_admin();
1163
1164 $file = weforms_log_file_path();
1165
1166 if ( !file_exists( $file ) ) {
1167 return;
1168 }
1169
1170 $data = file_get_contents( $file );
1171 $data = explode( "\n", $data );
1172 $data = array_reverse( $data );
1173 $data = array_filter( $data );
1174
1175 if ( empty( $data ) ) {
1176 return;
1177 }
1178
1179 $logs = [];
1180
1181 foreach ( $data as $key => $row ) {
1182 preg_match( '/\[(?<time>.+?)\]\[(?<type>.+?)\](?<message>.+)/im', $row, $log );
1183
1184 if ( empty( $log['message'] ) ) {
1185 $log = [];
1186 $log['message'] = !empty( $log['message'] ) ? $log['message'] : $row;
1187 }
1188
1189 if ( !empty( $log['time'] ) ) {
1190 $human_time = human_time_diff( strtotime( $log['time'] ), current_time( 'timestamp' ) );
1191 $log['time'] = $human_time ? $human_time . ' ' . __( 'ago', 'weforms' ) : $log['time'];
1192 }
1193
1194 $logs[] = $log;
1195 }
1196
1197 wp_send_json_success( $logs );
1198 }
1199
1200 /**
1201 * Read Log file
1202 *
1203 * @return json
1204 **/
1205 public function delete_logs() {
1206 check_ajax_referer( 'weforms' );
1207
1208 $this->check_admin();
1209
1210 $file = weforms_log_file_path();
1211
1212 if ( !file_exists( $file ) ) {
1213 return;
1214 }
1215
1216 @unlink( $file );
1217
1218 wp_send_json_success();
1219 }
1220 }
1221