Completed
Push — develop ( fae07d...25e00b )
by Zack
19:01
created

merge_field_properties()   A

Complexity

Conditions 4
Paths 6

Size

Total Lines 23

Duplication

Lines 0
Ratio 0 %

Code Coverage

Tests 7
CRAP Score 4.432

Importance

Changes 0
Metric Value
cc 4
nc 6
nop 2
dl 0
loc 23
ccs 7
cts 10
cp 0.7
crap 4.432
rs 9.552
c 0
b 0
f 0
1
<?php
0 ignored issues
show
Coding Style Compatibility introduced by
For compatibility and reusability of your code, PSR1 recommends that a file should introduce either new symbols (like classes, functions, etc.) or have side-effects (like outputting something, or including other files), but not both at the same time. The first symbol is defined on line 16 and the first side effect is on line 13.

The PSR-1: Basic Coding Standard recommends that a file should either introduce new symbols, that is classes, functions, constants or similar, or have side effects. Side effects are anything that executes logic, like for example printing output, changing ini settings or writing to a file.

The idea behind this recommendation is that merely auto-loading a class should not change the state of an application. It also promotes a cleaner style of programming and makes your code less prone to errors, because the logic is not spread out all over the place.

To learn more about the PSR-1, please see the PHP-FIG site on the PSR-1.

Loading history...
2
/**
3
 * GravityView Edit Entry - render frontend
4
 *
5
 * @package   GravityView
6
 * @license   GPL2+
7
 * @author    Katz Web Services, Inc.
8
 * @link      http://gravityview.co
9
 * @copyright Copyright 2014, Katz Web Services, Inc.
10
 */
11
12
if ( ! defined( 'WPINC' ) ) {
13
	die;
14
}
15
16
class GravityView_Edit_Entry_Render {
17
18
	/**
19
	 * @var GravityView_Edit_Entry
20
	 */
21
	protected $loader;
22
23
	/**
24
	 * @var string String used to generate unique nonce for the entry/form/view combination. Allows access to edit page.
25
	 */
26
	static $nonce_key;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $nonce_key.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
27
28
	/**
29
	 * @since 1.9
30
	 * @var string String used for check valid edit entry form submission. Allows saving edit form values.
31
	 */
32
	private static $nonce_field = 'is_gv_edit_entry';
33
34
	/**
35
	 * @since 1.9
36
	 * @var bool Whether to allow save and continue functionality
37
	 */
38
	private static $supports_save_and_continue = false;
39
40
	/**
41
	 * Gravity Forms entry array
42
	 *
43
	 * @var array
44
	 */
45
	public $entry;
46
47
	/**
48
	 * Gravity Forms entry array (it won't get changed during this class lifecycle)
49
	 * @since 1.17.2
50
	 * @var array
51
	 */
52
	private static $original_entry = array();
53
54
	/**
55
	 * Gravity Forms form array (GravityView modifies the content through this class lifecycle)
56
	 *
57
	 * @var array
58
	 */
59
	public $form;
60
61
	/**
62
	 * Gravity Forms form array (it won't get changed during this class lifecycle)
63
	 * @since 1.16.2.1
64
	 * @var array
65
	 */
66
	private static $original_form;
67
68
	/**
69
	 * Gravity Forms form array after the form validation process
70
	 * @since 1.13
71
	 * @var array
72
	 */
73
	public $form_after_validation = null;
74
75
	/**
76
	 * Hold an array of GF field objects that have calculation rules
77
	 * @var array
78
	 */
79
	public $fields_with_calculation = array();
80
81
	/**
82
	 * Gravity Forms form id
83
	 *
84
	 * @var int
85
	 */
86
	public $form_id;
87
88
	/**
89
	 * ID of the current view
90
	 *
91
	 * @var int
92
	 */
93
	public $view_id;
94
95
	/**
96
	 * ID of the current post. May also be ID of the current View.
97
     *
98
     * @since 2.0.13
99
     * 
100
     * @var int
101
	 */
102
	public $post_id;
103
104
	/**
105
	 * Updated entry is valid (GF Validation object)
106
	 *
107
	 * @var array
108
	 */
109
	public $is_valid = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
110
111 12
	function __construct( GravityView_Edit_Entry $loader ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
112 12
		$this->loader = $loader;
113 12
	}
114
115 12
	function load() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
116
117
		/** @define "GRAVITYVIEW_DIR" "../../../" */
118 12
		include_once( GRAVITYVIEW_DIR .'includes/class-admin-approve-entries.php' );
119
120
		// Don't display an embedded form when editing an entry
121 12
		add_action( 'wp_head', array( $this, 'prevent_render_form' ) );
122 12
		add_action( 'wp_footer', array( $this, 'prevent_render_form' ) );
123
124
		// Stop Gravity Forms processing what is ours!
125 12
		add_filter( 'wp', array( $this, 'prevent_maybe_process_form'), 8 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
126
127 12
		add_filter( 'gravityview_is_edit_entry', array( $this, 'is_edit_entry') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
128
129 12
		add_action( 'gravityview_edit_entry', array( $this, 'init' ) );
130
131
		// Disable conditional logic if needed (since 1.9)
132 12
		add_filter( 'gform_has_conditional_logic', array( $this, 'manage_conditional_logic' ), 10, 2 );
133
134
		// Make sure GF doesn't validate max files (since 1.9)
135 12
		add_filter( 'gform_plupload_settings', array( $this, 'modify_fileupload_settings' ), 10, 3 );
136
137
		// Add fields expected by GFFormDisplay::validate()
138 12
		add_filter( 'gform_pre_validation', array( $this, 'gform_pre_validation') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
139
140
		// Fix multiselect value for GF 2.2
141 12
		add_filter( 'gravityview/edit_entry/field_value_multiselect', array( $this, 'fix_multiselect_value_serialization' ), 10, 3 );
142 12
	}
143
144
	/**
145
	 * Don't show any forms embedded on a page when GravityView is in Edit Entry mode
146
	 *
147
	 * Adds a `__return_empty_string` filter on the Gravity Forms shortcode on the `wp_head` action
148
	 * And then removes it on the `wp_footer` action
149
	 *
150
	 * @since 1.16.1
151
	 *
152
	 * @return void
153
	 */
154 1
	public function prevent_render_form() {
155 1
		if( $this->is_edit_entry() ) {
156 1
			if( 'wp_head' === current_filter() ) {
157 1
				add_filter( 'gform_shortcode_form', '__return_empty_string' );
158
			} else {
159 1
				remove_filter( 'gform_shortcode_form', '__return_empty_string' );
160
			}
161
		}
162 1
	}
163
164
	/**
165
	 * Because we're mimicking being a front-end Gravity Forms form while using a Gravity Forms
166
	 * backend form, we need to prevent them from saving twice.
167
	 * @return void
168
	 */
169 1
	public function prevent_maybe_process_form() {
170
171 1
		if( ! empty( $_POST ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
172
	        gravityview()->log->debug( 'GravityView_Edit_Entry[prevent_maybe_process_form] $_POSTed data (sanitized): ', array( 'data' => esc_html( print_r( $_POST, true ) ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
173
		}
174
175 1
		if( $this->is_edit_entry_submission() ) {
176
			remove_action( 'wp',  array( 'RGForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
177
	        remove_action( 'wp',  array( 'GFForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
178
		}
179 1
	}
180
181
	/**
182
	 * Is the current page an Edit Entry page?
183
	 * @return boolean
184
	 */
185 13
	public function is_edit_entry() {
186
187 13
		$is_edit_entry = GravityView_frontend::is_single_entry() && ! empty( $_GET['edit'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
188
189 13
		return ( $is_edit_entry || $this->is_edit_entry_submission() );
190
	}
191
192
	/**
193
	 * Is the current page an Edit Entry page?
194
	 * @since 1.9
195
	 * @return boolean
196
	 */
197 13
	public function is_edit_entry_submission() {
198 13
		return !empty( $_POST[ self::$nonce_field ] );
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
199
	}
200
201
	/**
202
	 * When Edit entry view is requested setup the vars
203
	 */
204 12
	private function setup_vars() {
205 12
        global $post;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
206
207 12
		$gravityview_view = GravityView_View::getInstance();
208
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
209
210 12
		$entries = $gravityview_view->getEntries();
211 12
	    self::$original_entry = $entries[0];
212 12
	    $this->entry = $entries[0];
213
214 12
		self::$original_form = $gravityview_view->getForm();
215 12
		$this->form = $gravityview_view->getForm();
216 12
		$this->form_id = $this->entry['form_id'];
217 12
		$this->view_id = $gravityview_view->getViewId();
218 12
		$this->post_id = \GV\Utils::get( $post, 'ID', null );
219
220 12
		self::$nonce_key = GravityView_Edit_Entry::get_nonce_key( $this->view_id, $this->form_id, $this->entry['id'] );
221 12
	}
222
223
224
	/**
225
	 * Load required files and trigger edit flow
226
	 *
227
	 * Run when the is_edit_entry returns true.
228
	 *
229
	 * @param \GravityView_View_Data $gv_data GravityView Data object
230
	 * @return void
231
	 */
232 13
	public function init( $gv_data = null ) {
233
234 13
		require_once( GFCommon::get_base_path() . '/form_display.php' );
235 13
		require_once( GFCommon::get_base_path() . '/entry_detail.php' );
236
237 13
		$this->setup_vars();
238
239 13
		if ( ! $gv_data ) {
240
			$gv_data = GravityView_View_Data::getInstance();
241
		}
242
243
		// Multiple Views embedded, don't proceed if nonce fails
244 13
		if ( $gv_data->has_multiple_views() && ! $this->verify_nonce() ) {
0 ignored issues
show
Deprecated Code introduced by
The method GravityView_View_Data::has_multiple_views() has been deprecated.

This method has been deprecated.

Loading history...
245
			gravityview()->log->error( 'Nonce validation failed for the Edit Entry request; returning' );
246
			return;
247
		}
248
249
		// Sorry, you're not allowed here.
250 13
		if ( false === $this->user_can_edit_entry( true ) ) {
251 1
			gravityview()->log->error( 'User is not allowed to edit this entry; returning', array( 'data' => $this->entry ) );
252 1
			return;
253
		}
254
255 13
		$this->print_scripts();
256
257 13
		$this->process_save( $gv_data );
258
259 13
		$this->edit_entry_form();
260
261 13
	}
262
263
264
	/**
265
	 * Force Gravity Forms to output scripts as if it were in the admin
266
	 * @return void
267
	 */
268 12
	private function print_scripts() {
269 12
		$gravityview_view = GravityView_View::getInstance();
270
271 12
		wp_register_script( 'gform_gravityforms', GFCommon::get_base_url().'/js/gravityforms.js', array( 'jquery', 'gform_json', 'gform_placeholder', 'sack', 'plupload-all', 'gravityview-fe-view' ) );
272
273 12
		GFFormDisplay::enqueue_form_scripts( $gravityview_view->getForm(), false);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
274
275 12
		wp_localize_script( 'gravityview-fe-view', 'gvGlobals', array( 'cookiepath' => COOKIEPATH ) );
276
277
		// Sack is required for images
278 12
		wp_print_scripts( array( 'sack', 'gform_gravityforms', 'gravityview-fe-view' ) );
279 12
	}
280
281
282
	/**
283
	 * Process edit entry form save
284
	 *
285
	 * @param array $gv_data The View data.
286
	 */
287 13
	private function process_save( $gv_data ) {
288
289 13
		if ( empty( $_POST ) || ! isset( $_POST['lid'] ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
290 5
			return;
291
		}
292
293
		// Make sure the entry, view, and form IDs are all correct
294 12
		$valid = $this->verify_nonce();
295
296 12
		if ( !$valid ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
297
			gravityview()->log->error( 'Nonce validation failed.' );
298
			return;
299
		}
300
301 12
		if ( $this->entry['id'] !== $_POST['lid'] ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
302
			gravityview()->log->error( 'Entry ID did not match posted entry ID.' );
303
			return;
304
		}
305
306 12
		gravityview()->log->debug( '$_POSTed data (sanitized): ', array( 'data' => esc_html( print_r( $_POST, true ) ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
307
308 12
		$this->process_save_process_files( $this->form_id );
309
310 12
		$this->validate();
311
312 12
		if( $this->is_valid ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using ! empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
313
314 12
			gravityview()->log->debug( 'Submission is valid.' );
315
316
			/**
317
			 * @hack This step is needed to unset the adminOnly from form fields, to add the calculation fields
318
			 */
319 12
			$form = $this->form_prepare_for_save();
320
321
			/**
322
			 * @hack to avoid the capability validation of the method save_lead for GF 1.9+
323
			 */
324 12
			unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
325
326 12
			$date_created = $this->entry['date_created'];
327
328
			/**
329
			 * @hack to force Gravity Forms to use $read_value_from_post in GFFormsModel::save_lead()
330
			 * @since 1.17.2
331
			 */
332 12
			unset( $this->entry['date_created'] );
333
334 12
			GFFormsModel::save_lead( $form, $this->entry );
335
336
	        // Delete the values for hidden inputs
337 12
	        $this->unset_hidden_field_values();
338
			
339 12
			$this->entry['date_created'] = $date_created;
340
341
			// Process calculation fields
342 12
			$this->update_calculation_fields();
343
344
			// Perform actions normally performed after updating a lead
345 12
			$this->after_update();
346
347
	        /**
348
			 * Must be AFTER after_update()!
349
			 * @see https://github.com/gravityview/GravityView/issues/764
350
			 */
351 12
			$this->maybe_update_post_fields( $form );
352
353
			/**
354
			 * @action `gravityview/edit_entry/after_update` Perform an action after the entry has been updated using Edit Entry
355
             * @since 2.1 Added $gv_data parameter
356
			 * @param array $form Gravity Forms form array
357
			 * @param string $entry_id Numeric ID of the entry that was updated
358
			 * @param GravityView_Edit_Entry_Render $this This object
359
			 * @param GravityView_View_Data $gv_data The View data
360
			 */
361 12
			do_action( 'gravityview/edit_entry/after_update', $this->form, $this->entry['id'], $this, $gv_data );
362
363
		} else {
364
			gravityview()->log->error( 'Submission is NOT valid.', array( 'entry' => $this->entry ) );
365
		}
366
367 12
	} // process_save
368
369
	/**
370
	 * Delete the value of fields hidden by conditional logic when the entry is edited
371
	 *
372
	 * @uses GFFormsModel::update_lead_field_value()
373
	 *
374
	 * @since 1.17.4
375
	 *
376
	 * @return void
377
	 */
378 11
	private function unset_hidden_field_values() {
379 11
	    global $wpdb;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
380
381
		/**
382
		 * @filter `gravityview/edit_entry/unset_hidden_field_values` Whether to delete values of fields hidden by conditional logic
383
		 * @since 1.22.2
384
		 * @param bool $unset_hidden_field_values Default: true
385
		 * @param GravityView_Edit_Entry_Render $this This object
386
		 */
387 11
		$unset_hidden_field_values = apply_filters( 'gravityview/edit_entry/unset_hidden_field_values', true, $this );
388
389 11
		if( ! $unset_hidden_field_values ) {
390
			return;
391
		}
392
393 11
		if ( version_compare( GravityView_GFFormsModel::get_database_version(), '2.3-dev-1', '>=' ) && method_exists( 'GFFormsModel', 'get_entry_meta_table_name' ) ) {
394 11
			$entry_meta_table = GFFormsModel::get_entry_meta_table_name();
395 11
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $entry_meta_table WHERE entry_id=%d", $this->entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
396
		} else {
397
			$lead_detail_table = GFFormsModel::get_lead_details_table_name();
398
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $lead_detail_table WHERE lead_id=%d", $this->entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
399
		}
400
401 11
	    foreach ( $this->entry as $input_id => $field_value ) {
402
403 11
		    $field = RGFormsModel::get_field( $this->form, $input_id );
404
405
		    // Reset fields that are hidden
406
		    // Don't pass $entry as fourth parameter; force using $_POST values to calculate conditional logic
407 11
		    if ( GFFormsModel::is_field_hidden( $this->form, $field, array(), NULL ) ) {
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
408
409
				$empty_value = $field->get_value_save_entry(
410
					is_array( $field->get_entry_inputs() ) ? array() : '',
411
					$this->form, '', $this->entry['id'], $this->entry
412
				);
413
414
			    $lead_detail_id = GFFormsModel::get_lead_detail_id( $current_fields, $input_id );
415
416
			    GFFormsModel::update_lead_field_value( $this->form, $this->entry, $field, $lead_detail_id, $input_id, $empty_value );
417
418
			    // Prevent the $_POST values of hidden fields from being used as default values when rendering the form
419
				// after submission
420
			    $post_input_id = 'input_' . str_replace( '.', '_', $input_id );
421 11
			    $_POST[ $post_input_id ] = '';
422
		    }
423
	    }
424 11
	}
425
426
	/**
427
	 * Have GF handle file uploads
428
	 *
429
	 * Copy of code from GFFormDisplay::process_form()
430
	 *
431
	 * @param int $form_id
432
	 */
433 11
	private function process_save_process_files( $form_id ) {
434
435
		//Loading files that have been uploaded to temp folder
436 11
		$files = GFCommon::json_decode( stripslashes( RGForms::post( 'gform_uploaded_files' ) ) );
437 11
		if ( ! is_array( $files ) ) {
438 10
			$files = array();
439
		}
440
441
		/**
442
		 * Make sure the fileuploads are not overwritten if no such request was done.
443
		 * @since 1.20.1
444
		 */
445 11
		add_filter( "gform_save_field_value_$form_id", array( $this, 'save_field_value' ), 99, 5 );
446
447 11
		RGFormsModel::$uploaded_files[ $form_id ] = $files;
448 11
	}
449
450
	/**
451
	 * Make sure the fileuploads are not overwritten if no such request was done.
452
	 *
453
	 * TO ONLY BE USED INTERNALLY; DO NOT DEVELOP ON; MAY BE REMOVED AT ANY TIME.
454
	 *
455
	 * @since 1.20.1
456
	 *
457
	 * @param string $value Field value
458
	 * @param array $entry GF entry array
459
	 * @param GF_Field_FileUpload $field
460
	 * @param array $form GF form array
461
	 * @param string $input_id ID of the input being saved
462
	 *
463
	 * @return string
464
	 */
465 11
	public function save_field_value( $value = '', $entry = array(), $field = null, $form = array(), $input_id = '' ) {
466
467 11
		if ( ! $field || $field->type != 'fileupload' ) {
0 ignored issues
show
introduced by
Found "!= '". Use Yoda Condition checks, you must
Loading history...
468 11
			return $value;
469
		}
470
471 1
		$input_name = 'input_' . str_replace( '.', '_', $input_id );
472
473 1
		if ( $field->multipleFiles ) {
474
			if ( empty( $value ) ) {
475
				return json_decode( $entry[ $input_id ], true );
476
			}
477
			return $value;
478
		}
479
480
		/** No file is being uploaded. */
481 1
		if ( empty( $_FILES[ $input_name ]['name'] ) ) {
482
			/** So return the original upload */
483 1
			return $entry[ $input_id ];
484
		}
485
486 1
		return $value;
487
	}
488
489
	/**
490
	 * Remove max_files validation (done on gravityforms.js) to avoid conflicts with GravityView
491
	 * Late validation done on self::custom_validation
492
	 *
493
	 * @param $plupload_init array Plupload settings
494
	 * @param $form_id
495
	 * @param $instance
496
	 * @return mixed
497
	 */
498 2
	public function modify_fileupload_settings( $plupload_init, $form_id, $instance ) {
0 ignored issues
show
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $instance is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
499 2
		if( ! $this->is_edit_entry() ) {
500
			return $plupload_init;
501
		}
502
503 2
		$plupload_init['gf_vars']['max_files'] = 0;
504
505 2
		return $plupload_init;
506
	}
507
508
509
	/**
510
	 * Set visibility to visible and convert field input key to string
511
	 * @return array $form
512
	 */
513 11
	private function form_prepare_for_save() {
514
515 11
		$form = $this->form;
516
517
	    /** @var GF_Field $field */
518 11
		foreach( $form['fields'] as $k => &$field ) {
519
520
			/**
521
			 * Remove the fields with calculation formulas before save to avoid conflicts with GF logic
522
			 * @since 1.16.3
523
			 * @var GF_Field $field
524
			 */
525 11
			if( $field->has_calculation() ) {
526 3
				unset( $form['fields'][ $k ] );
527
			}
528
529 11
			$field->adminOnly = false;
530
531 11
			if( isset( $field->inputs ) && is_array( $field->inputs ) ) {
532 2
				foreach( $field->inputs as $key => $input ) {
533 11
				    $field->inputs[ $key ][ 'id' ] = (string)$input['id'];
0 ignored issues
show
introduced by
Array keys should NOT be surrounded by spaces if they only contain a string or an integer.
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
534
				}
535
			}
536
		}
537
538 11
		$form['fields'] = array_values( $form['fields'] );
539
540 11
		return $form;
541
	}
542
543 11
	private function update_calculation_fields() {
544 11
		global $wpdb;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
545
546 11
		$form = self::$original_form;
547 11
		$update = false;
548
549
		// get the most up to date entry values
550 11
		$entry = GFAPI::get_entry( $this->entry['id'] );
551
552 11
		if ( version_compare( GravityView_GFFormsModel::get_database_version(), '2.3-dev-1', '>=' ) && method_exists( 'GFFormsModel', 'get_entry_meta_table_name' ) ) {
553 11
			$entry_meta_table = GFFormsModel::get_entry_meta_table_name();
554 11
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $entry_meta_table WHERE entry_id=%d", $entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
555
		} else {
556
			$lead_detail_table = GFFormsModel::get_lead_details_table_name();
557
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $lead_detail_table WHERE lead_id=%d", $entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
558
		}
559
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
560
561 11
		if ( ! empty( $this->fields_with_calculation ) ) {
562 4
			$allowed_fields = $this->get_configured_edit_fields( $form, $this->view_id );
563 4
			$allowed_fields = wp_list_pluck( $allowed_fields, 'id' );
564
565 4
			foreach ( $this->fields_with_calculation as $field ) {
566 4
				$inputs = $field->get_entry_inputs();
567 4
				if ( is_array( $inputs ) ) {
568 3
				    foreach ( $inputs as $input ) {
569 3
						list( $field_id, $input_id ) = rgexplode( '.', $input['id'], 2 );
570
571 3
						if ( 'product' === $field->type ) {
572 3
							$input_name = 'input_' . str_replace( '.', '_', $input['id'] );
573
574
							// Only allow quantity to be set if it's allowed to be edited
575 3
							if ( in_array( $field_id, $allowed_fields ) && $input_id == 3 ) {
0 ignored issues
show
Unused Code introduced by
This if statement is empty and can be removed.

This check looks for the bodies of if statements that have no statements or where all statements have been commented out. This may be the result of changes for debugging or the code may simply be obsolete.

These if bodies can be removed. If you have an empty if but statements in the else branch, consider inverting the condition.

if (rand(1, 6) > 3) {
//print "Check failed";
} else {
    print "Check succeeded";
}

could be turned into

if (rand(1, 6) <= 3) {
    print "Check succeeded";
}

This is much more concise to read.

Loading history...
introduced by
Found "== 3". Use Yoda Condition checks, you must
Loading history...
576
							} else { // otherwise set to what it previously was
577 3
								$_POST[ $input_name ] = $entry[ $input['id'] ];
578
							}
579
						} else {
580
							// Set to what it previously was if it's not editable
581
							if ( ! in_array( $field_id, $allowed_fields ) ) {
582
								$_POST[ $input_name ] = $entry[ $input['id'] ];
0 ignored issues
show
Bug introduced by
The variable $input_name does not seem to be defined for all execution paths leading up to this point.

If you define a variable conditionally, it can happen that it is not defined for all execution paths.

Let’s take a look at an example:

function myFunction($a) {
    switch ($a) {
        case 'foo':
            $x = 1;
            break;

        case 'bar':
            $x = 2;
            break;
    }

    // $x is potentially undefined here.
    echo $x;
}

In the above example, the variable $x is defined if you pass “foo” or “bar” as argument for $a. However, since the switch statement has no default case statement, if you pass any other value, the variable $x would be undefined.

Available Fixes

  1. Check for existence of the variable explicitly:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        if (isset($x)) { // Make sure it's always set.
            echo $x;
        }
    }
    
  2. Define a default value for the variable:

    function myFunction($a) {
        $x = ''; // Set a default which gets overridden for certain paths.
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        echo $x;
    }
    
  3. Add a value for the missing path:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
    
            // We add support for the missing case.
            default:
                $x = '';
                break;
        }
    
        echo $x;
    }
    
Loading history...
583
							}
584
						}
585
586 3
						GFFormsModel::save_input( $form, $field, $entry, $current_fields, $input['id'] );
587
				    }
588
				} else {
589
					// Set to what it previously was if it's not editable
590 3
					if ( ! in_array( $field->id, $allowed_fields ) ) {
591 2
						$_POST[ 'input_' . $field->id ] = $entry[ $field->id ];
592
					}
593 4
					GFFormsModel::save_input( $form, $field, $entry, $current_fields, $field->id );
594
				}
595
			}
596
597 4
			if ( method_exists( 'GFFormsModel', 'commit_batch_field_operations' ) ) {
598 4
				GFFormsModel::commit_batch_field_operations();
599
			}
600
		}
601 11
	}
602
603
	/**
604
	 * Handle updating the Post Image field
605
	 *
606
	 * Sets a new Featured Image if configured in Gravity Forms; otherwise uploads/updates media
607
	 *
608
	 * @since 1.17
609
	 *
610
	 * @uses GFFormsModel::media_handle_upload
611
	 * @uses set_post_thumbnail
612
	 *
613
	 * @param array $form GF Form array
614
	 * @param GF_Field $field GF Field
615
	 * @param string $field_id Numeric ID of the field
616
	 * @param string $value
617
	 * @param array $entry GF Entry currently being edited
618
	 * @param int $post_id ID of the Post being edited
619
	 *
620
	 * @return mixed|string
621
	 */
622 1
	private function update_post_image( $form, $field, $field_id, $value, $entry, $post_id ) {
623
624 1
		$input_name = 'input_' . $field_id;
625
626 1
		if ( !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
627
628
			// We have a new image
629
630
			$value = RGFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'] );
631
632
			$ary = ! empty( $value ) ? explode( '|:|', $value ) : array();
633
	        $ary = stripslashes_deep( $ary );
634
			$img_url = \GV\Utils::get( $ary, 0 );
635
636
			$img_title       = count( $ary ) > 1 ? $ary[1] : '';
637
			$img_caption     = count( $ary ) > 2 ? $ary[2] : '';
638
			$img_description = count( $ary ) > 3 ? $ary[3] : '';
639
640
			$image_meta = array(
641
				'post_excerpt' => $img_caption,
642
				'post_content' => $img_description,
643
			);
644
645
			//adding title only if it is not empty. It will default to the file name if it is not in the array
646
			if ( ! empty( $img_title ) ) {
647
				$image_meta['post_title'] = $img_title;
648
			}
649
650
			/**
651
			 * todo: As soon as \GFFormsModel::media_handle_upload becomes a public method, move this call to \GFFormsModel::media_handle_upload and remove the hack from this class.
652
			 * Note: the method became public in GF 1.9.17.7, but we don't require that version yet.
653
			 */
654
			require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
655
			$media_id = GravityView_GFFormsModel::media_handle_upload( $img_url, $post_id, $image_meta );
656
657
			// is this field set as featured image?
658
			if ( $media_id && $field->postFeaturedImage ) {
659
				set_post_thumbnail( $post_id, $media_id );
660
			}
661
662 1
		} elseif ( ! empty( $_POST[ $input_name ] ) && is_array( $value ) ) {
663
664 1
			$img_url         = stripslashes_deep( $_POST[ $input_name ] );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
665 1
			$img_title       = stripslashes_deep( \GV\Utils::_POST( $input_name . '_1' ) );
666 1
			$img_caption     = stripslashes_deep( \GV\Utils::_POST( $input_name . '_4' ) );
667 1
			$img_description = stripslashes_deep( \GV\Utils::_POST( $input_name . '_7' ) );
668
669 1
			$value = ! empty( $img_url ) ? $img_url . "|:|" . $img_title . "|:|" . $img_caption . "|:|" . $img_description : '';
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal |:| does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
670
671 1
			if ( $field->postFeaturedImage ) {
672
673
				$image_meta = array(
674 1
					'ID' => get_post_thumbnail_id( $post_id ),
675 1
					'post_title' => $img_title,
676 1
					'post_excerpt' => $img_caption,
677 1
					'post_content' => $img_description,
678
				);
679
680
				// update image title, caption or description
681 1
				wp_update_post( $image_meta );
682
			}
683
		} else {
684
685
			// if we get here, image was removed or not set.
686
			$value = '';
687
688
			if ( $field->postFeaturedImage ) {
689
				delete_post_thumbnail( $post_id );
690
			}
691
		}
692
693 1
		return $value;
694
	}
695
696
	/**
697
	 * Loop through the fields being edited and if they include Post fields, update the Entry's post object
698
	 *
699
	 * @param array $form Gravity Forms form
700
	 *
701
	 * @return void
702
	 */
703 11
	private function maybe_update_post_fields( $form ) {
704
705 11
		if( empty( $this->entry['post_id'] ) ) {
706 10
	        gravityview()->log->debug( 'This entry has no post fields. Continuing...' );
707 10
			return;
708
		}
709
710 1
		$post_id = $this->entry['post_id'];
711
712
		// Security check
713 1
		if( false === GVCommon::has_cap( 'edit_post', $post_id ) ) {
714
			gravityview()->log->error( 'The current user does not have the ability to edit Post #{post_id}', array( 'post_id' => $post_id ) );
715
			return;
716
		}
717
718 1
		$update_entry = false;
719
720 1
		$updated_post = $original_post = get_post( $post_id );
721
722 1
		foreach ( $this->entry as $field_id => $value ) {
723
724 1
			$field = RGFormsModel::get_field( $form, $field_id );
725
726 1
			if( ! $field ) {
727 1
				continue;
728
			}
729
730 1
			if( GFCommon::is_post_field( $field ) && 'post_category' !== $field->type ) {
731
732
				// Get the value of the field, including $_POSTed value
733 1
				$value = RGFormsModel::get_field_value( $field );
734
735
				// Use temporary entry variable, to make values available to fill_post_template() and update_post_image()
736 1
				$entry_tmp = $this->entry;
737 1
				$entry_tmp["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
738
739 1
				switch( $field->type ) {
740
741 1
				    case 'post_title':
742
				        $post_title = $value;
743
				        if ( \GV\Utils::get( $form, 'postTitleTemplateEnabled' ) ) {
744
				            $post_title = $this->fill_post_template( $form['postTitleTemplate'], $form, $entry_tmp );
745
				        }
746
				        $updated_post->post_title = $post_title;
747
				        $updated_post->post_name  = $post_title;
748
				        unset( $post_title );
749
				        break;
750
751 1
				    case 'post_content':
752
				        $post_content = $value;
753
				        if ( \GV\Utils::get( $form, 'postContentTemplateEnabled' ) ) {
754
				            $post_content = $this->fill_post_template( $form['postContentTemplate'], $form, $entry_tmp, true );
755
				        }
756
				        $updated_post->post_content = $post_content;
757
				        unset( $post_content );
758
				        break;
759 1
				    case 'post_excerpt':
760
				        $updated_post->post_excerpt = $value;
761
				        break;
762 1
				    case 'post_tags':
763
				        wp_set_post_tags( $post_id, $value, false );
764
				        break;
765 1
				    case 'post_category':
766
				        break;
767 1
				    case 'post_custom_field':
768
						if ( is_array( $value ) && ( floatval( $field_id ) !== floatval( $field->id ) ) ) {
769
							$value = $value[ $field_id ];
770
						}
771
772
				        if( ! empty( $field->customFieldTemplateEnabled ) ) {
773
				            $value = $this->fill_post_template( $field->customFieldTemplate, $form, $entry_tmp, true );
774
				        }
775
776
						$value = $field->get_value_save_entry( $value, $form, '', $this->entry['id'], $this->entry );
777
778
				        update_post_meta( $post_id, $field->postCustomFieldName, $value );
779
				        break;
780
781 1
				    case 'post_image':
782 1
				        $value = $this->update_post_image( $form, $field, $field_id, $value, $this->entry, $post_id );
783 1
				        break;
784
785
				}
786
787
				// update entry after
788 1
				$this->entry["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
789
790 1
				$update_entry = true;
791
792 1
				unset( $entry_tmp );
793
			}
794
795
		}
796
797 1
		if( $update_entry ) {
798
799 1
			$return_entry = GFAPI::update_entry( $this->entry );
800
801 1
			if( is_wp_error( $return_entry ) ) {
802
				gravityview()->log->error( 'Updating the entry post fields failed', array( 'data' => array( '$this->entry' => $this->entry, '$return_entry' => $return_entry ) ) );
803
			} else {
804 1
				gravityview()->log->debug( 'Updating the entry post fields for post #{post_id} succeeded', array( 'post_id' => $post_id ) );
805
			}
806
807
		}
808
809 1
		$return_post = wp_update_post( $updated_post, true );
810
811 1
		if( is_wp_error( $return_post ) ) {
812
			$return_post->add_data( $updated_post, '$updated_post' );
813
			gravityview()->log->error( 'Updating the post content failed', array( 'data' => compact( 'updated_post', 'return_post' ) ) );
814
		} else {
815 1
			gravityview()->log->debug( 'Updating the post content for post #{post_id} succeeded', array( 'post_id' => $post_id, 'data' => $updated_post ) );
816
		}
817 1
	}
818
819
	/**
820
	 * Convert a field content template into prepared output
821
	 *
822
	 * @uses GravityView_GFFormsModel::get_post_field_images()
823
	 *
824
	 * @since 1.17
825
	 *
826
	 * @param string $template The content template for the field
827
	 * @param array $form Gravity Forms form
828
	 * @param bool $do_shortcode Whether to process shortcode inside content. In GF, only run on Custom Field and Post Content fields
829
	 *
830
	 * @return string
831
	 */
832
	private function fill_post_template( $template, $form, $entry, $do_shortcode = false ) {
833
834
		require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
835
836
		$post_images = GravityView_GFFormsModel::get_post_field_images( $form, $entry );
837
838
		//replacing post image variables
839
		$output = GFCommon::replace_variables_post_image( $template, $post_images, $entry );
840
841
		//replacing all other variables
842
		$output = GFCommon::replace_variables( $output, $form, $entry, false, false, false );
843
844
		// replace conditional shortcodes
845
		if( $do_shortcode ) {
846
			$output = do_shortcode( $output );
847
		}
848
849
		return $output;
850
	}
851
852
853
	/**
854
	 * Perform actions normally performed after updating a lead
855
	 *
856
	 * @since 1.8
857
	 *
858
	 * @see GFEntryDetail::lead_detail_page()
859
	 *
860
	 * @return void
861
	 */
862 11
	private function after_update() {
863
864 11
		do_action( 'gform_after_update_entry', $this->form, $this->entry['id'], self::$original_entry );
865 11
		do_action( "gform_after_update_entry_{$this->form['id']}", $this->form, $this->entry['id'], self::$original_entry );
866
867
		// Re-define the entry now that we've updated it.
868 11
		$entry = RGFormsModel::get_lead( $this->entry['id'] );
869
870 11
		$entry = GFFormsModel::set_entry_meta( $entry, self::$original_form );
871
872 11
		if ( version_compare( GFFormsModel::get_database_version(), '2.3-dev-1', '<' ) ) {
873
			// We need to clear the cache because Gravity Forms caches the field values, which
874
			// we have just updated.
875
			foreach ($this->form['fields'] as $key => $field) {
0 ignored issues
show
introduced by
No space after opening parenthesis is prohibited
Loading history...
introduced by
No space before closing parenthesis is prohibited
Loading history...
876
				GFFormsModel::refresh_lead_field_value( $entry['id'], $field->id );
877
			}
878
		}
879
880 11
		$this->entry = $entry;
881 11
	}
882
883
884
	/**
885
	 * Display the Edit Entry form
886
	 *
887
	 * @return void
888
	 */
889 12
	public function edit_entry_form() {
890
891
		?>
892
893
		<div class="gv-edit-entry-wrapper"><?php
894
895 12
			$javascript = gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/inline-javascript.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
896
897
			/**
898
			 * Fixes weird wpautop() issue
899
			 * @see https://github.com/katzwebservices/GravityView/issues/451
900
			 */
901 12
			echo gravityview_strip_whitespace( $javascript );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'gravityview_strip_whitespace'
Loading history...
902
903
			?><h2 class="gv-edit-entry-title">
904
				<span><?php
905
906
				    /**
907
				     * @filter `gravityview_edit_entry_title` Modify the edit entry title
908
				     * @param string $edit_entry_title Modify the "Edit Entry" title
909
				     * @param GravityView_Edit_Entry_Render $this This object
910
				     */
911 12
				    $edit_entry_title = apply_filters('gravityview_edit_entry_title', __('Edit Entry', 'gravityview'), $this );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
912
913 12
				    echo esc_attr( $edit_entry_title );
914
			?></span>
915
			</h2>
916
917
			<?php $this->maybe_print_message(); ?>
918
919
			<?php // The ID of the form needs to be `gform_{form_id}` for the pluploader ?>
920
921
			<form method="post" id="gform_<?php echo $this->form_id; ?>" enctype="multipart/form-data">
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$this'
Loading history...
922
923
				<?php
924
925 12
				wp_nonce_field( self::$nonce_key, self::$nonce_key );
926
927 12
				wp_nonce_field( self::$nonce_field, self::$nonce_field, false );
928
929
				// Print the actual form HTML
930 12
				$this->render_edit_form();
931
932
				?>
933 12
			</form>
934
935
			<script>
936
				gform.addFilter('gform_reset_pre_conditional_logic_field_action', function ( reset, formId, targetId, defaultValues, isInit ) {
937
				    return false;
938
				});
939
			</script>
940
941
		</div>
942
943
	<?php
944 12
	}
945
946
	/**
947
	 * Display success or error message if the form has been submitted
948
	 *
949
	 * @uses GVCommon::generate_notice
950
	 *
951
	 * @since 1.16.2.2
952
	 *
953
	 * @return void
954
	 */
955 12
	private function maybe_print_message() {
956
957 12
		if ( \GV\Utils::_POST( 'action' ) === 'update' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
958
959 11
			$back_link = remove_query_arg( array( 'page', 'view', 'edit' ) );
960
961 11
			if( ! $this->is_valid ){
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
962
963
				// Keeping this compatible with Gravity Forms.
964
				$validation_message = "<div class='validation_error'>" . __('There was a problem with your submission.', 'gravityview') . " " . __('Errors have been highlighted below.', 'gravityview') . "</div>";
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw '__'
Loading history...
Coding Style Comprehensibility introduced by
The string literal </div> does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
965
				$message = apply_filters("gform_validation_message_{$this->form['id']}", apply_filters("gform_validation_message", $validation_message, $this->form), $this->form);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal gform_validation_message does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
966
967
				echo GVCommon::generate_notice( $message , 'gv-error' );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
968
969
			} else {
970 11
				$view = \GV\View::by_id( $this->view_id );
971 11
				$edit_redirect = $view->settings->get( 'edit_redirect' );
972 11
				$edit_redirect_url = $view->settings->get( 'edit_redirect_url' );
973
974
				switch ( $edit_redirect ) {
975
976 11
                    case '0':
977 1
	                    $redirect_url = $back_link;
978 1
	                    $entry_updated_message = sprintf( esc_attr_x('Entry Updated. %sReturning to Entry%s', 'Replacements are HTML', 'gravityview'), '<a href="'. esc_url( $redirect_url ) .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
979 1
                        break;
980
981 10
                    case '1':
982 1
	                    $redirect_url = $directory_link = GravityView_API::directory_link();
983 1
	                    $entry_updated_message = sprintf( esc_attr_x('Entry Updated. %sReturning to %s%s', 'Replacement 1 is HTML. Replacement 2 is the title of the page where the user will be taken. Replacement 3 is HTML.','gravityview'), '<a href="'. esc_url( $redirect_url ) . '">', esc_html( $view->post_title ), '</a>' );
0 ignored issues
show
Documentation introduced by
The property post_title does not exist on object<GV\View>. Since you implemented __get, maybe consider adding a @property annotation.

Since your code implements the magic getter _get, this function will be called for any read access on an undefined variable. You can add the @property annotation to your class or interface to document the existence of this variable.

<?php

/**
 * @property int $x
 * @property int $y
 * @property string $text
 */
class MyLabel
{
    private $properties;

    private $allowedProperties = array('x', 'y', 'text');

    public function __get($name)
    {
        if (isset($properties[$name]) && in_array($name, $this->allowedProperties)) {
            return $properties[$name];
        } else {
            return null;
        }
    }

    public function __set($name, $value)
    {
        if (in_array($name, $this->allowedProperties)) {
            $properties[$name] = $value;
        } else {
            throw new \LogicException("Property $name is not defined.");
        }
    }

}

If the property has read access only, you can use the @property-read annotation instead.

Of course, you may also just have mistyped another name, in which case you should fix the error.

See also the PhpDoc documentation for @property.

Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
984 1
	                    break;
985
986 9
                    case '2':
987 1
	                    $redirect_url = $edit_redirect_url;
988 1
	                    $redirect_url = GFCommon::replace_variables( $redirect_url, $this->form, $this->entry, false, false, false, 'text' );
989 1
	                    $entry_updated_message = sprintf( esc_attr_x('Entry Updated. %sRedirecting to %s%s', 'Replacement 1 is HTML. Replacement 2 is the URL where the user will be taken. Replacement 3 is HTML.','gravityview'), '<a href="'. esc_url( $redirect_url ) . '">', esc_html( $edit_redirect_url ), '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
990 1
                        break;
991
992 8
                    case '':
993
                    default:
994 8
					    $entry_updated_message = sprintf( esc_attr__('Entry Updated. %sReturn to Entry%s', 'gravityview'), '<a href="'. esc_url( $back_link ) .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
995 8
                        break;
996
				}
997
998 11
				if ( isset( $redirect_url ) ) {
999 3
					$entry_updated_message .= sprintf( '<script>window.location.href = %s;</script><noscript><meta http-equiv="refresh" content="0;URL=%s" /></noscript>', json_encode( $redirect_url ), esc_attr( $redirect_url ) );
1000
				}
1001
1002
				/**
1003
				 * @filter `gravityview/edit_entry/success` Modify the edit entry success message (including the anchor link)
1004
				 * @since 1.5.4
1005
				 * @param string $entry_updated_message Existing message
1006
				 * @param int $view_id View ID
1007
				 * @param array $entry Gravity Forms entry array
1008
				 * @param string $back_link URL to return to the original entry. @since 1.6
1009
				 */
1010 11
				$message = apply_filters( 'gravityview/edit_entry/success', $entry_updated_message , $this->view_id, $this->entry, $back_link );
1011
1012 11
				echo GVCommon::generate_notice( $message );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
1013
			}
1014
1015
		}
1016 12
	}
1017
1018
	/**
1019
	 * Display the Edit Entry form in the original Gravity Forms format
1020
	 *
1021
	 * @since 1.9
1022
	 *
1023
	 * @return void
1024
	 */
1025 12
	private function render_edit_form() {
1026
1027
		/**
1028
		 * @action `gravityview/edit-entry/render/before` Before rendering the Edit Entry form
1029
		 * @since 1.17
1030
		 * @param GravityView_Edit_Entry_Render $this
1031
		 */
1032 12
		do_action( 'gravityview/edit-entry/render/before', $this );
1033
1034 12
		add_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields'), 5000, 3 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
1035 12
		add_filter( 'gform_submit_button', array( $this, 'render_form_buttons') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
1036 12
		add_filter( 'gform_disable_view_counter', '__return_true' );
1037
1038 12
		add_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5, 5 );
1039 12
		add_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10, 5 );
1040
1041
		// We need to remove the fake $_GET['page'] arg to avoid rendering form as if in admin.
1042 12
		unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
1043
1044
		// TODO: Verify multiple-page forms
1045
1046 12
		ob_start(); // Prevent PHP warnings possibly caused by prefilling list fields for conditional logic
1047
1048 12
		$html = GFFormDisplay::get_form( $this->form['id'], false, false, true, $this->entry );
1049
1050 12
		ob_get_clean();
1051
1052 12
	    remove_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields' ), 5000 );
1053 12
		remove_filter( 'gform_submit_button', array( $this, 'render_form_buttons' ) );
1054 12
		remove_filter( 'gform_disable_view_counter', '__return_true' );
1055 12
		remove_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5 );
1056 12
		remove_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10 );
1057
1058 12
		echo $html;
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$html'
Loading history...
1059
1060
		/**
1061
		 * @action `gravityview/edit-entry/render/after` After rendering the Edit Entry form
1062
		 * @since 1.17
1063
		 * @param GravityView_Edit_Entry_Render $this
1064
		 */
1065 12
		do_action( 'gravityview/edit-entry/render/after', $this );
1066 12
	}
1067
1068
	/**
1069
	 * Display the Update/Cancel/Delete buttons for the Edit Entry form
1070
	 * @since 1.8
1071
	 * @return string
1072
	 */
1073 12
	public function render_form_buttons() {
1074 12
		return gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/form-buttons.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
1075
	}
1076
1077
1078
	/**
1079
	 * Modify the form fields that are shown when using GFFormDisplay::get_form()
1080
	 *
1081
	 * By default, all fields will be shown. We only want the Edit Tab configured fields to be shown.
1082
	 *
1083
	 * @param array $form
1084
	 * @param boolean $ajax Whether in AJAX mode
1085
	 * @param array|string $field_values Passed parameters to the form
1086
	 *
1087
	 * @since 1.9
1088
	 *
1089
	 * @return array Modified form array
1090
	 */
1091 12
	public function filter_modify_form_fields( $form, $ajax = false, $field_values = '' ) {
0 ignored issues
show
Unused Code introduced by
The parameter $ajax is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $field_values is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1092
1093
		// In case we have validated the form, use it to inject the validation results into the form render
1094 12
		if( isset( $this->form_after_validation ) ) {
1095 11
			$form = $this->form_after_validation;
1096
		} else {
1097 4
			$form['fields'] = $this->get_configured_edit_fields( $form, $this->view_id );
1098
		}
1099
1100 12
		$form = $this->filter_conditional_logic( $form );
1101
1102 12
		$form = $this->prefill_conditional_logic( $form );
1103
1104
		// for now we don't support Save and Continue feature.
1105 12
		if( ! self::$supports_save_and_continue ) {
1106 12
	        unset( $form['save'] );
1107
		}
1108
1109 12
		$form = $this->unselect_default_values( $form );
1110
1111 12
		return $form;
1112
	}
1113
1114
	/**
1115
	 * When displaying a field, check if it's a Post Field, and if so, make sure the post exists and current user has edit rights.
1116
	 *
1117
	 * @since 1.16.2.2
1118
	 *
1119
	 * @param string $field_content Always empty. Returning not-empty overrides the input.
1120
	 * @param GF_Field $field
1121
	 * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1122
	 * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1123
	 * @param int $form_id Form ID
1124
	 *
1125
	 * @return string If error, the error message. If no error, blank string (modify_edit_field_input() runs next)
1126
	 */
1127 12
	public function verify_user_can_edit_post( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1128
1129 12
		if( ! GFCommon::is_post_field( $field ) ) {
1130 12
			return $field_content;
1131
		}
1132
1133 2
        $message = null;
1134
1135
        // First, make sure they have the capability to edit the post.
1136 2
        if( false === current_user_can( 'edit_post', $this->entry['post_id'] ) ) {
1137
1138
            /**
1139
             * @filter `gravityview/edit_entry/unsupported_post_field_text` Modify the message when someone isn't able to edit a post
1140
             * @param string $message The existing "You don't have permission..." text
1141
             */
1142 1
            $message = apply_filters('gravityview/edit_entry/unsupported_post_field_text', __('You don&rsquo;t have permission to edit this post.', 'gravityview') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1143
1144 1
        } elseif( null === get_post( $this->entry['post_id'] ) ) {
1145
            /**
1146
             * @filter `gravityview/edit_entry/no_post_text` Modify the message when someone is editing an entry attached to a post that no longer exists
1147
             * @param string $message The existing "This field is not editable; the post no longer exists." text
1148
             */
1149
            $message = apply_filters('gravityview/edit_entry/no_post_text', __('This field is not editable; the post no longer exists.', 'gravityview' ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1150
        }
1151
1152 2
        if( $message ) {
1153 1
            $field_content = sprintf('<div class="ginput_container ginput_container_' . $field->type . '">%s</div>', wpautop( $message ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1154
        }
1155
1156 2
        return $field_content;
1157
	}
1158
1159
	/**
1160
	 *
1161
	 * Fill-in the saved values into the form inputs
1162
	 *
1163
	 * @param string $field_content Always empty. Returning not-empty overrides the input.
1164
	 * @param GF_Field $field
1165
	 * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1166
	 * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1167
	 * @param int $form_id Form ID
1168
	 *
1169
	 * @return mixed
1170
	 */
1171 12
	public function modify_edit_field_input( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1172
1173 12
		$gv_field = GravityView_Fields::get_associated_field( $field );
1174
1175
		// If the form has been submitted, then we don't need to pre-fill the values,
1176
		// Except for fileupload type and when a field input is overridden- run always!!
1177
		if(
1178 12
			( $this->is_edit_entry_submission() && !in_array( $field->type, array( 'fileupload', 'post_image' ) ) )
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1179 12
			&& false === ( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) )
1180
			&& ! GFCommon::is_product_field( $field->type )
1181 12
			|| ! empty( $field_content )
1182 12
			|| in_array( $field->type, array( 'honeypot' ) )
1183
		) {
1184 1
	        return $field_content;
1185
		}
1186
1187
		// SET SOME FIELD DEFAULTS TO PREVENT ISSUES
1188 12
		$field->adminOnly = false; /** @see GFFormDisplay::get_counter_init_script() need to prevent adminOnly */
1189
1190 12
		$field_value = $this->get_field_value( $field );
1191
1192
	    // Prevent any PHP warnings, like undefined index
1193 12
	    ob_start();
1194
1195 12
	    $return = null;
1196
1197
		/** @var GravityView_Field $gv_field */
1198 12
		if( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) ) {
1199 3
			$return = $gv_field->get_field_input( $this->form, $field_value, $this->entry, $field );
1200
		} else {
1201 12
	        $return = $field->get_field_input( $this->form, $field_value, $this->entry );
1202
	    }
1203
1204
	    // If there was output, it's an error
1205 12
	    $warnings = ob_get_clean();
1206
1207 12
	    if( !empty( $warnings ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1208
		    gravityview()->log->error( '{warning}', array( 'warning' => $warnings, 'data' => $field_value ) );
1209
	    }
1210
1211 12
		return $return;
1212
	}
1213
1214
	/**
1215
	 * Modify the value for the current field input
1216
	 *
1217
	 * @param GF_Field $field
1218
	 *
1219
	 * @return array|mixed|string
1220
	 */
1221 12
	private function get_field_value( $field ) {
1222
1223
		/**
1224
		 * @filter `gravityview/edit_entry/pre_populate/override` Allow the pre-populated value to override saved value in Edit Entry form. By default, pre-populate mechanism only kicks on empty fields.
1225
		 * @param boolean True: override saved values; False: don't override (default)
1226
		 * @param $field GF_Field object Gravity Forms field object
1227
		 * @since 1.13
1228
		 */
1229 12
		$override_saved_value = apply_filters( 'gravityview/edit_entry/pre_populate/override', false, $field );
1230
1231
		// We're dealing with multiple inputs (e.g. checkbox) but not time or date (as it doesn't store data in input IDs)
1232 12
		if( isset( $field->inputs ) && is_array( $field->inputs ) && !in_array( $field->type, array( 'time', 'date' ) ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1233
1234 3
			$field_value = array();
1235
1236
			// only accept pre-populated values if the field doesn't have any choice selected.
1237 3
			$allow_pre_populated = $field->allowsPrepopulate;
1238
1239 3
			foreach ( (array)$field->inputs as $input ) {
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1240
1241 3
				$input_id = strval( $input['id'] );
1242
1243 3
				if ( isset( $this->entry[ $input_id ] ) && ! gv_empty( $this->entry[ $input_id ], false, false ) ) {
1244 3
				    $field_value[ $input_id ] =  'post_category' === $field->type ? GFCommon::format_post_category( $this->entry[ $input_id ], true ) : $this->entry[ $input_id ];
0 ignored issues
show
introduced by
Expected 1 space after "="; 2 found
Loading history...
1245 3
				    $allow_pre_populated = false;
1246
				}
1247
1248
			}
1249
1250 3
			$pre_value = $field->get_value_submission( array(), false );
1251
1252 3
			$field_value = ! $allow_pre_populated && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $field_value : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1253
1254
		} else {
1255
1256 12
			$id = intval( $field->id );
1257
1258
			// get pre-populated value if exists
1259 12
			$pre_value = $field->allowsPrepopulate ? GFFormsModel::get_parameter_value( $field->inputName, array(), $field ) : '';
1260
1261
			// saved field entry value (if empty, fallback to the pre-populated value, if exists)
1262
			// or pre-populated value if not empty and set to override saved value
1263 12
			$field_value = isset( $this->entry[ $id ] ) && ! gv_empty( $this->entry[ $id ], false, false ) && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $this->entry[ $id ] : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1264
1265
			// in case field is post_category but inputType is select, multi-select or radio, convert value into array of category IDs.
1266 12
			if ( 'post_category' === $field->type && !gv_empty( $field_value, false, false ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1267
				$categories = array();
1268
				foreach ( explode( ',', $field_value ) as $cat_string ) {
1269
				    $categories[] = GFCommon::format_post_category( $cat_string, true );
1270
				}
1271
				$field_value = 'multiselect' === $field->get_input_type() ? $categories : implode( '', $categories );
1272
			}
1273
1274
		}
1275
1276
		// if value is empty get the default value if defined
1277 12
		$field_value = $field->get_value_default_if_empty( $field_value );
1278
1279
	    /**
1280
	     * @filter `gravityview/edit_entry/field_value` Change the value of an Edit Entry field, if needed
1281
	     * @since 1.11
1282
	     * @since 1.20 Added third param
1283
	     * @param mixed $field_value field value used to populate the input
1284
	     * @param object $field Gravity Forms field object ( Class GF_Field )
1285
	     * @param GravityView_Edit_Entry_Render $this Current object
1286
	     */
1287 12
	    $field_value = apply_filters( 'gravityview/edit_entry/field_value', $field_value, $field, $this );
1288
1289
	    /**
1290
	     * @filter `gravityview/edit_entry/field_value_{field_type}` Change the value of an Edit Entry field for a specific field type
1291
	     * @since 1.17
1292
	     * @since 1.20 Added third param
1293
	     * @param mixed $field_value field value used to populate the input
1294
	     * @param GF_Field $field Gravity Forms field object
1295
	     * @param GravityView_Edit_Entry_Render $this Current object
1296
	     */
1297 12
	    $field_value = apply_filters( 'gravityview/edit_entry/field_value_' . $field->type , $field_value, $field, $this );
1298
1299 12
		return $field_value;
1300
	}
1301
1302
1303
	// ---- Entry validation
1304
1305
	/**
1306
	 * Add field keys that Gravity Forms expects.
1307
	 *
1308
	 * @see GFFormDisplay::validate()
1309
	 * @param  array $form GF Form
1310
	 * @return array       Modified GF Form
1311
	 */
1312 11
	public function gform_pre_validation( $form ) {
1313
1314 11
		if( ! $this->verify_nonce() ) {
1315
			return $form;
1316
		}
1317
1318
		// Fix PHP warning regarding undefined index.
1319 11
		foreach ( $form['fields'] as &$field) {
0 ignored issues
show
introduced by
No space before closing parenthesis is prohibited
Loading history...
1320
1321
			// This is because we're doing admin form pretending to be front-end, so Gravity Forms
1322
			// expects certain field array items to be set.
1323 11
			foreach ( array( 'noDuplicates', 'adminOnly', 'inputType', 'isRequired', 'enablePrice', 'inputs', 'allowedExtensions' ) as $key ) {
1324 11
	            $field->{$key} = isset( $field->{$key} ) ? $field->{$key} : NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1325
			}
1326
1327 11
			switch( RGFormsModel::get_input_type( $field ) ) {
1328
1329
				/**
1330
				 * this whole fileupload hack is because in the admin, Gravity Forms simply doesn't update any fileupload field if it's empty, but it DOES in the frontend.
1331
				 *
1332
				 * What we have to do is set the value so that it doesn't get overwritten as empty on save and appears immediately in the Edit Entry screen again.
1333
				 *
1334
				 * @hack
1335
				 */
1336 11
				case 'fileupload':
1337
1338
				    // Set the previous value
1339 1
				    $entry = $this->get_entry();
1340
1341 1
				    $input_name = 'input_'.$field->id;
1342 1
				    $form_id = $form['id'];
1343
1344 1
				    $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1345
1346
				    // Use the previous entry value as the default.
1347 1
				    if( isset( $entry[ $field->id ] ) ) {
1348 1
				        $value = $entry[ $field->id ];
1349
				    }
1350
1351
				    // If this is a single upload file
1352 1
				    if( !empty( $_FILES[ $input_name ] ) && !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1353 1
				        $file_path = GFFormsModel::get_file_upload_path( $form['id'], $_FILES[ $input_name ]['name'] );
1354 1
				        $value = $file_path['url'];
1355
1356
				    } else {
1357
1358
				        // Fix PHP warning on line 1498 of form_display.php for post_image fields
1359
				        // Fix PHP Notice:  Undefined index:  size in form_display.php on line 1511
1360 1
				        $_FILES[ $input_name ] = array('name' => '', 'size' => '' );
0 ignored issues
show
introduced by
No space after opening parenthesis of array is bad style
Loading history...
1361
1362
				    }
1363
1364 1
				    if ( \GV\Utils::get( $field, "multipleFiles" ) ) {
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal multipleFiles does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1365
1366
				        // If there are fresh uploads, process and merge them.
1367
				        // Otherwise, use the passed values, which should be json-encoded array of URLs
1368 1
				        if( isset( GFFormsModel::$uploaded_files[$form_id][$input_name] ) ) {
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1369
				            $value = empty( $value ) ? '[]' : $value;
1370
				            $value = stripslashes_deep( $value );
1371 1
				            $value = GFFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'], array());
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1372
				        }
1373
1374
				    } else {
1375
1376
				        // A file already exists when editing an entry
1377
				        // We set this to solve issue when file upload fields are required.
1378 1
				        GFFormsModel::$uploaded_files[ $form_id ][ $input_name ] = $value;
1379
1380
				    }
1381
1382 1
				    $this->entry[ $input_name ] = $value;
1383 1
				    $_POST[ $input_name ] = $value;
1384
1385 1
				    break;
1386
1387 11
				case 'number':
1388
				    // Fix "undefined index" issue at line 1286 in form_display.php
1389 8
				    if( !isset( $_POST['input_'.$field->id ] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1390 5
				        $_POST['input_'.$field->id ] = NULL;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1391
				    }
1392 11
				    break;
1393
			}
1394
1395
		}
1396
1397 11
		return $form;
1398
	}
1399
1400
1401
	/**
1402
	 * Process validation for a edit entry submission
1403
	 *
1404
	 * Sets the `is_valid` object var
1405
	 *
1406
	 * @return void
1407
	 */
1408 12
	private function validate() {
1409
1410
		/**
1411
		 * If using GF User Registration Add-on, remove the validation step, otherwise generates error when updating the entry
1412
		 * GF User Registration Add-on version > 3.x has a different class name
1413
		 * @since 1.16.2
1414
		 */
1415 12
		if ( class_exists( 'GF_User_Registration' ) ) {
1416 12
			remove_filter( 'gform_validation', array( GF_User_Registration::get_instance(), 'validate' ) );
1417
		} else  if ( class_exists( 'GFUser' ) ) {
1418
			remove_filter( 'gform_validation', array( 'GFUser', 'user_registration_validation' ) );
1419
		}
1420
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1421
1422
		/**
1423
		 * For some crazy reason, Gravity Forms doesn't validate Edit Entry form submissions.
1424
		 * You can enter whatever you want!
1425
		 * We try validating, and customize the results using `self::custom_validation()`
1426
		 */
1427 12
		add_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10, 4);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1428
1429
		// Needed by the validate funtion
1430 12
		$failed_validation_page = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1431 12
		$field_values = RGForms::post( 'gform_field_values' );
1432
1433
		// Prevent entry limit from running when editing an entry, also
1434
		// prevent form scheduling from preventing editing
1435 12
		unset( $this->form['limitEntries'], $this->form['scheduleForm'] );
1436
1437
		// Hide fields depending on Edit Entry settings
1438 12
		$this->form['fields'] = $this->get_configured_edit_fields( $this->form, $this->view_id );
1439
1440 12
		$this->is_valid = GFFormDisplay::validate( $this->form, $field_values, 1, $failed_validation_page );
1441
1442 12
		remove_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10 );
1443 12
	}
1444
1445
1446
	/**
1447
	 * Make validation work for Edit Entry
1448
	 *
1449
	 * Because we're calling the GFFormDisplay::validate() in an unusual way (as a front-end
1450
	 * form pretending to be a back-end form), validate() doesn't know we _can't_ edit post
1451
	 * fields. This goes through all the fields and if they're an invalid post field, we
1452
	 * set them as valid. If there are still issues, we'll return false.
1453
	 *
1454
	 * @param  [type] $validation_results [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1455
	 * @return [type]                     [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1456
	 */
1457 12
	public function custom_validation( $validation_results ) {
1458
1459 12
		gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Validation results: ', array( 'data' => $validation_results ) );
1460
1461 12
		gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] $_POSTed data (sanitized): ', array( 'data' => esc_html( print_r( $_POST, true ) ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
1462
1463 12
		$gv_valid = true;
1464
1465 12
		foreach ( $validation_results['form']['fields'] as $key => &$field ) {
1466
1467 12
			$value = RGFormsModel::get_field_value( $field );
1468 12
			$field_type = RGFormsModel::get_input_type( $field );
1469
1470
			// Validate always
1471 12
			switch ( $field_type ) {
1472
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1473
1474 12
				case 'fileupload' :
1475 12
				case 'post_image':
1476
1477
				    // in case nothing is uploaded but there are already files saved
1478 2
				    if( !empty( $field->failed_validation ) && !empty( $field->isRequired ) && !empty( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1479
				        $field->failed_validation = false;
1480
				        unset( $field->validation_message );
1481
				    }
1482
1483
				    // validate if multi file upload reached max number of files [maxFiles] => 2
1484 2
				    if( \GV\Utils::get( $field, 'maxFiles') && \GV\Utils::get( $field, 'multipleFiles') ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1485
1486
				        $input_name = 'input_' . $field->id;
1487
				        //uploaded
1488
				        $file_names = isset( GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] ) ? GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] : array();
1489
1490
				        //existent
1491
				        $entry = $this->get_entry();
1492
				        $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1493
				        if( isset( $entry[ $field->id ] ) ) {
1494
				            $value = json_decode( $entry[ $field->id ], true );
1495
				        }
1496
1497
				        // count uploaded files and existent entry files
1498
				        $count_files = count( $file_names ) + count( $value );
1499
1500
				        if( $count_files > $field->maxFiles ) {
1501
				            $field->validation_message = __( 'Maximum number of files reached', 'gravityview' );
1502
				            $field->failed_validation = 1;
1503
				            $gv_valid = false;
1504
1505
				            // in case of error make sure the newest upload files are removed from the upload input
1506
				            GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ] = null;
1507
				        }
1508
1509
				    }
1510
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1511
1512 2
				    break;
1513
1514
			}
1515
1516
			// This field has failed validation.
1517 12
			if( !empty( $field->failed_validation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1518
1519 1
				gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Field is invalid.', array( 'data' => array( 'field' => $field, 'value' => $value ) ) );
1520
1521 1
				switch ( $field_type ) {
1522
1523
				    // Captchas don't need to be re-entered.
1524 1
				    case 'captcha':
1525
1526
				        // Post Image fields aren't editable, so we un-fail them.
1527 1
				    case 'post_image':
1528
				        $field->failed_validation = false;
1529
				        unset( $field->validation_message );
1530
				        break;
1531
1532
				}
1533
1534
				// You can't continue inside a switch, so we do it after.
1535 1
				if( empty( $field->failed_validation ) ) {
1536
				    continue;
1537
				}
1538
1539
				// checks if the No Duplicates option is not validating entry against itself, since
1540
				// we're editing a stored entry, it would also assume it's a duplicate.
1541 1
				if( !empty( $field->noDuplicates ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1542
1543
				    $entry = $this->get_entry();
1544
1545
				    // If the value of the entry is the same as the stored value
1546
				    // Then we can assume it's not a duplicate, it's the same.
1547
				    if( !empty( $entry ) && $value == $entry[ $field->id ] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1548
				        //if value submitted was not changed, then don't validate
1549
				        $field->failed_validation = false;
1550
1551
				        unset( $field->validation_message );
1552
1553
				        gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Field not a duplicate; it is the same entry.', array( 'data' => $entry ) );
1554
1555
				        continue;
1556
				    }
1557
				}
1558
1559
				// if here then probably we are facing the validation 'At least one field must be filled out'
1560 1
				if( GFFormDisplay::is_empty( $field, $this->form_id  ) && empty( $field->isRequired ) ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 2 found
Loading history...
1561
				    unset( $field->validation_message );
1562
	                $field->validation_message = false;
1563
				    continue;
1564
				}
1565
1566 12
				$gv_valid = false;
1567
1568
			}
1569
1570
		}
1571
1572 12
		$validation_results['is_valid'] = $gv_valid;
1573
1574 12
		gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Validation results.', array( 'data' => $validation_results ) );
1575
1576
		// We'll need this result when rendering the form ( on GFFormDisplay::get_form )
1577 12
		$this->form_after_validation = $validation_results['form'];
1578
1579 12
		return $validation_results;
1580
	}
1581
1582
1583
	/**
1584
	 * TODO: This seems to be hacky... we should remove it. Entry is set when updating the form using setup_vars()!
1585
	 * Get the current entry and set it if it's not yet set.
1586
	 * @return array Gravity Forms entry array
1587
	 */
1588 2
	public function get_entry() {
1589
1590 2
		if( empty( $this->entry ) ) {
1591
			// Get the database value of the entry that's being edited
1592 1
			$this->entry = gravityview_get_entry( GravityView_frontend::is_single_entry() );
1593
		}
1594
1595 2
		return $this->entry;
1596
	}
1597
1598
1599
1600
	// --- Filters
1601
1602
	/**
1603
	 * Get the Edit Entry fields as configured in the View
1604
	 *
1605
	 * @since 1.8
1606
	 *
1607
	 * @param int $view_id
1608
	 *
1609
	 * @return array Array of fields that are configured in the Edit tab in the Admin
1610
	 */
1611 13
	private function get_configured_edit_fields( $form, $view_id ) {
1612
1613
		// Get all fields for form
1614 13
		if ( \GV\View::exists( $view_id ) ) {
1615 13
			$view = \GV\View::by_id( $view_id );
1616 13
			$properties = $view->fields ? $view->fields->as_configuration() : array();
1617
		} else {
1618
			$properties = null;
1619
		}
1620
1621
		// If edit tab not yet configured, show all fields
1622 13
		$edit_fields = !empty( $properties['edit_edit-fields'] ) ? $properties['edit_edit-fields'] : NULL;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1623
1624
		// Hide fields depending on admin settings
1625 13
		$fields = $this->filter_fields( $form['fields'], $edit_fields );
1626
1627
	    // If Edit Entry fields are configured, remove adminOnly field settings. Otherwise, don't.
1628 13
	    $fields = $this->filter_admin_only_fields( $fields, $edit_fields, $form, $view_id );
1629
1630
		/**
1631
		 * @filter `gravityview/edit_entry/form_fields` Modify the fields displayed in Edit Entry form
1632
		 * @since 1.17
1633
		 * @param GF_Field[] $fields Gravity Forms form fields
1634
		 * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1635
		 * @param array $form GF Form array (`fields` key modified to have only fields configured to show in Edit Entry)
1636
		 * @param int $view_id View ID
1637
		 */
1638 13
		$fields = apply_filters( 'gravityview/edit_entry/form_fields', $fields, $edit_fields, $form, $view_id );
1639
1640 13
		return $fields;
1641
	}
1642
1643
1644
	/**
1645
	 * Filter area fields based on specified conditions
1646
	 *  - This filter removes the fields that have calculation configured
1647
	 *
1648
	 * @uses GravityView_Edit_Entry::user_can_edit_field() Check caps
1649
	 * @access private
1650
	 * @param GF_Field[] $fields
1651
	 * @param array $configured_fields
1652
	 * @since  1.5
1653
	 * @return array $fields
1654
	 */
1655 12
	private function filter_fields( $fields, $configured_fields ) {
1656
1657 12
		if( empty( $fields ) || !is_array( $fields ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1658
			return $fields;
1659
		}
1660
1661 12
		$edit_fields = array();
1662
1663 12
		$field_type_blacklist = $this->loader->get_field_blacklist( $this->entry );
1664
1665
		// First, remove blacklist or calculation fields
1666 12
		foreach ( $fields as $key => $field ) {
1667
1668
			// Remove the fields that have calculation properties and keep them to be used later
1669
			// @since 1.16.2
1670 12
			if( $field->has_calculation() ) {
1671 4
				$this->fields_with_calculation[] = $field;
1672
				// don't remove the calculation fields on form render.
1673
			}
1674
1675 12
			if( in_array( $field->type, $field_type_blacklist ) ) {
1676 12
				unset( $fields[ $key ] );
1677
			}
1678
		}
1679
1680
		// The Edit tab has not been configured, so we return all fields by default.
1681 12
		if( empty( $configured_fields ) ) {
1682 11
			return array_values( $fields );
1683
		}
1684
1685
		// The edit tab has been configured, so we loop through to configured settings
1686 1
		foreach ( $configured_fields as $configured_field ) {
1687
1688
	        /** @var GF_Field $field */
1689 1
	        foreach ( $fields as $field ) {
1690 1
				if( intval( $configured_field['id'] ) === intval( $field->id ) && $this->user_can_edit_field( $configured_field, false ) ) {
1691 1
				    $edit_fields[] = $this->merge_field_properties( $field, $configured_field );
1692 1
				    break;
1693
				}
1694
1695
			}
1696
1697
		}
1698
1699 1
		return $edit_fields;
1700
1701
	}
1702
1703
	/**
1704
	 * Override GF Form field properties with the ones defined on the View
1705
	 * @param  GF_Field $field GF Form field object
1706
	 * @param  array $field_setting  GV field options
1707
	 * @since  1.5
1708
	 * @return array|GF_Field
1709
	 */
1710 1
	private function merge_field_properties( $field, $field_setting ) {
1711
1712 1
		$return_field = $field;
1713
1714 1
		if( empty( $field_setting['show_label'] ) ) {
1715
			$return_field->label = '';
1716 1
		} elseif ( !empty( $field_setting['custom_label'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1717
			$return_field->label = $field_setting['custom_label'];
1718
		}
1719
1720 1
		if( !empty( $field_setting['custom_class'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1721
			$return_field->cssClass .= ' '. gravityview_sanitize_html_class( $field_setting['custom_class'] );
1722
		}
1723
1724
		/**
1725
		 * Normalize page numbers - avoid conflicts with page validation
1726
		 * @since 1.6
1727
		 */
1728 1
		$return_field->pageNumber = 1;
1729
1730 1
		return $return_field;
1731
1732
	}
1733
1734
	/**
1735
	 * Remove fields that shouldn't be visible based on the Gravity Forms adminOnly field property
1736
	 *
1737
	 * @since 1.9.1
1738
	 *
1739
	 * @param array|GF_Field[] $fields Gravity Forms form fields
1740
	 * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1741
	 * @param array $form GF Form array
1742
	 * @param int $view_id View ID
1743
	 *
1744
	 * @return array Possibly modified form array
1745
	 */
1746 12
	private function filter_admin_only_fields( $fields = array(), $edit_fields = null, $form = array(), $view_id = 0 ) {
1747
1748
	    /**
1749
		 * @filter `gravityview/edit_entry/use_gf_admin_only_setting` When Edit tab isn't configured, should the Gravity Forms "Admin Only" field settings be used to control field display to non-admins? Default: true
1750
	     * If the Edit Entry tab is not configured, adminOnly fields will not be shown to non-administrators.
1751
	     * If the Edit Entry tab *is* configured, adminOnly fields will be shown to non-administrators, using the configured GV permissions
1752
	     * @since 1.9.1
1753
	     * @param boolean $use_gf_adminonly_setting True: Hide field if set to Admin Only in GF and the user is not an admin. False: show field based on GV permissions, ignoring GF permissions.
1754
	     * @param array $form GF Form array
1755
	     * @param int $view_id View ID
1756
	     */
1757 12
	    $use_gf_adminonly_setting = apply_filters( 'gravityview/edit_entry/use_gf_admin_only_setting', empty( $edit_fields ), $form, $view_id );
1758
1759 12
	    if( $use_gf_adminonly_setting && false === GVCommon::has_cap( 'gravityforms_edit_entries', $this->entry['id'] ) ) {
1760
			foreach( $fields as $k => $field ) {
1761
				if( $field->adminOnly ) {
1762
				    unset( $fields[ $k ] );
1763
				}
1764
			}
1765
			return array_values( $fields );
1766
		}
1767
1768 12
	    foreach( $fields as &$field ) {
1769 12
		    $field->adminOnly = false;
1770
		}
1771
1772 12
		return $fields;
1773
	}
1774
1775
	/**
1776
	 * Checkboxes and other checkbox-based controls should not
1777
	 * display default checks in edit mode.
1778
	 *
1779
	 * https://github.com/gravityview/GravityView/1149
1780
	 *
1781
	 * @since 2.1
1782
	 *
1783
	 * @param array $form Gravity Forms array object
1784
	 *
1785
	 * @return array $form, modified to default checkboxes, radios from showing up.
1786
	 */
1787 12
	private function unselect_default_values( $form ) {
1788
1789 12
	    foreach ( $form['fields'] as &$field ) {
1790
1791 12
			if ( empty( $field->choices ) ) {
1792 12
                continue;
1793
			}
1794
1795 2
            foreach ( $field->choices as &$choice ) {
1796 2
				if ( \GV\Utils::get( $choice, 'isSelected' ) ) {
1797 2
					$choice['isSelected'] = false;
1798
				}
1799
			}
1800
		}
1801
1802 12
		return $form;
1803
	}
1804
1805
	// --- Conditional Logic
1806
1807
	/**
1808
	 * Conditional logic isn't designed to work with forms that already have content. When switching input values,
1809
	 * the dependent fields will be blank.
1810
	 *
1811
	 * Note: This is because GF populates a JavaScript variable with the input values. This is tough to filter at the input level;
1812
	 * via the `gform_field_value` filter; it requires lots of legwork. Doing it at the form level is easier.
1813
	 *
1814
	 * @since 1.17.4
1815
	 *
1816
	 * @param array $form Gravity Forms array object
1817
	 *
1818
	 * @return array $form, modified to fix conditional
1819
	 */
1820 12
	function prefill_conditional_logic( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1821
1822 12
		if( ! GFFormDisplay::has_conditional_logic( $form ) ) {
1823 12
			return $form;
1824
		}
1825
1826
		// Have Conditional Logic pre-fill fields as if the data were default values
1827
		/** @var GF_Field $field */
1828
		foreach ( $form['fields'] as &$field ) {
1829
1830
			if( 'checkbox' === $field->type ) {
1831
				foreach ( $field->get_entry_inputs() as $key => $input ) {
1832
				    $input_id = $input['id'];
1833
				    $choice = $field->choices[ $key ];
1834
				    $value = \GV\Utils::get( $this->entry, $input_id );
1835
				    $match = RGFormsModel::choice_value_match( $field, $choice, $value );
1836
				    if( $match ) {
1837
				        $field->choices[ $key ]['isSelected'] = true;
1838
				    }
1839
				}
1840
			} else {
1841
1842
				// We need to run through each field to set the default values
1843
				foreach ( $this->entry as $field_id => $field_value ) {
1844
1845
				    if( floatval( $field_id ) === floatval( $field->id ) ) {
1846
1847
				        if( 'list' === $field->type ) {
1848
				            $list_rows = maybe_unserialize( $field_value );
1849
1850
				            $list_field_value = array();
1851
				            foreach ( (array) $list_rows as $row ) {
1852
				                foreach ( (array) $row as $column ) {
1853
				                    $list_field_value[] = $column;
1854
				                }
1855
				            }
1856
1857
				            $field->defaultValue = serialize( $list_field_value );
1858
				        } else {
1859
				            $field->defaultValue = $field_value;
1860
				        }
1861
				    }
1862
				}
1863
			}
1864
		}
1865
1866
		return $form;
1867
	}
1868
1869
	/**
1870
	 * Remove the conditional logic rules from the form button and the form fields, if needed.
1871
	 *
1872
	 * @todo Merge with caller method
1873
	 * @since 1.9
1874
	 *
1875
	 * @param array $form Gravity Forms form
1876
	 * @return array Modified form, if not using Conditional Logic
1877
	 */
1878 12
	private function filter_conditional_logic( $form ) {
1879
1880
		/**
1881
		 * @filter `gravityview/edit_entry/conditional_logic` Should the Edit Entry form use Gravity Forms conditional logic showing/hiding of fields?
1882
		 * @since 1.9
1883
		 * @param bool $use_conditional_logic True: Gravity Forms will show/hide fields just like in the original form; False: conditional logic will be disabled and fields will be shown based on configuration. Default: true
1884
		 * @param array $form Gravity Forms form
1885
		 */
1886 12
		$use_conditional_logic = apply_filters( 'gravityview/edit_entry/conditional_logic', true, $form );
1887
1888 12
		if( $use_conditional_logic ) {
1889 12
			return $form;
1890
		}
1891
1892
		foreach( $form['fields'] as &$field ) {
1893
			/* @var GF_Field $field */
1894
			$field->conditionalLogic = null;
1895
		}
1896
1897
		unset( $form['button']['conditionalLogic'] );
1898
1899
		return $form;
1900
1901
	}
1902
1903
	/**
1904
	 * Disable the Gravity Forms conditional logic script and features on the Edit Entry screen
1905
	 *
1906
	 * @since 1.9
1907
	 *
1908
	 * @param $has_conditional_logic
1909
	 * @param $form
1910
	 * @return mixed
1911
	 */
1912 12
	public function manage_conditional_logic( $has_conditional_logic, $form ) {
1913
1914 12
		if( ! $this->is_edit_entry() ) {
1915
			return $has_conditional_logic;
1916
		}
1917
1918
	    /** @see GravityView_Edit_Entry_Render::filter_conditional_logic for filter documentation */
1919 12
		return apply_filters( 'gravityview/edit_entry/conditional_logic', $has_conditional_logic, $form );
1920
	}
1921
1922
1923
	// --- User checks and nonces
1924
1925
	/**
1926
	 * Check if the user can edit the entry
1927
	 *
1928
	 * - Is the nonce valid?
1929
	 * - Does the user have the right caps for the entry
1930
	 * - Is the entry in the trash?
1931
	 *
1932
	 * @todo Move to GVCommon
1933
	 *
1934
	 * @param  boolean $echo Show error messages in the form?
1935
	 * @return boolean        True: can edit form. False: nope.
1936
	 */
1937 13
	private function user_can_edit_entry( $echo = false ) {
1938
1939 13
		$error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1940
1941
		/**
1942
		 *  1. Permalinks are turned off
1943
		 *  2. There are two entries embedded using oEmbed
1944
		 *  3. One of the entries has just been saved
1945
		 */
1946 13
		if( !empty( $_POST['lid'] ) && !empty( $_GET['entry'] ) && ( $_POST['lid'] !== $_GET['entry'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1947
1948
			$error = true;
1949
1950
		}
1951
1952 13
		if( !empty( $_GET['entry'] ) && (string)$this->entry['id'] !== $_GET['entry'] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1953
1954
			$error = true;
1955
1956 13
		} elseif( ! $this->verify_nonce() ) {
1957
1958
			/**
1959
			 * If the Entry is embedded, there may be two entries on the same page.
1960
			 * If that's the case, and one is being edited, the other should fail gracefully and not display an error.
1961
			 */
1962
			if( GravityView_oEmbed::getInstance()->get_entry_id() ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression \GravityView_oEmbed::get...tance()->get_entry_id() of type integer|null is loosely compared to true; this is ambiguous if the integer can be zero. You might want to explicitly use !== null instead.

In PHP, under loose comparison (like ==, or !=, or switch conditions), values of different types might be equal.

For integer values, zero is a special case, in particular the following results might be unexpected:

0   == false // true
0   == null  // true
123 == false // false
123 == null  // false

// It is often better to use strict comparison
0 === false // false
0 === null  // false
Loading history...
Deprecated Code introduced by
The method GravityView_oEmbed::getInstance() has been deprecated with message: Use \GV\oEmbed instead.

This method has been deprecated. The supplier of the class has supplied an explanatory message.

The explanatory message should give you some clue as to whether and when the method will be removed from the class and what other method or class to use instead.

Loading history...
Deprecated Code introduced by
The method GravityView_oEmbed::get_entry_id() has been deprecated with message: Use \GV\oEmbed instead.

This method has been deprecated. The supplier of the class has supplied an explanatory message.

The explanatory message should give you some clue as to whether and when the method will be removed from the class and what other method or class to use instead.

Loading history...
1963
				$error = true;
1964
			} else {
1965
				$error = __( 'The link to edit this entry is not valid; it may have expired.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1966
			}
1967
1968
		}
1969
1970 13
		if( ! GravityView_Edit_Entry::check_user_cap_edit_entry( $this->entry ) ) {
1971 1
			$error = __( 'You do not have permission to edit this entry.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1972
		}
1973
1974 13
		if( $this->entry['status'] === 'trash' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
1975
			$error = __('You cannot edit the entry; it is in the trash.', 'gravityview' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1976
		}
1977
1978
		// No errors; everything's fine here!
1979 13
		if( empty( $error ) ) {
1980 13
			return true;
1981
		}
1982
1983 1
		if( $echo && $error !== true ) {
0 ignored issues
show
introduced by
Found "!== true". Use Yoda Condition checks, you must
Loading history...
1984
1985 1
	        $error = esc_html( $error );
1986
1987
	        /**
1988
	         * @since 1.9
1989
	         */
1990 1
	        if ( ! empty( $this->entry ) ) {
1991 1
		        $error .= ' ' . gravityview_get_link( '#', _x('Go back.', 'Link shown when invalid Edit Entry link is clicked', 'gravityview' ), array( 'onclick' => "window.history.go(-1); return false;" ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal window.history.go(-1); return false; does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1992
	        }
1993
1994 1
			echo GVCommon::generate_notice( wpautop( $error ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1995
		}
1996
1997 1
		gravityview()->log->error( '{error}', array( 'error' => $error ) );
1998
1999 1
		return false;
2000
	}
2001
2002
2003
	/**
2004
	 * Check whether a field is editable by the current user, and optionally display an error message
2005
	 * @uses  GravityView_Edit_Entry->check_user_cap_edit_field() Check user capabilities
2006
	 * @param  array  $field Field or field settings array
2007
	 * @param  boolean $echo  Whether to show error message telling user they aren't allowed
2008
	 * @return boolean         True: user can edit the current field; False: nope, they can't.
2009
	 */
2010 1
	private function user_can_edit_field( $field, $echo = false ) {
2011
2012 1
		$error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
2013
2014 1
		if( ! $this->check_user_cap_edit_field( $field ) ) {
2015
			$error = __( 'You do not have permission to edit this field.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
2016
		}
2017
2018
		// No errors; everything's fine here!
2019 1
		if( empty( $error ) ) {
2020 1
			return true;
2021
		}
2022
2023
		if( $echo ) {
2024
			echo GVCommon::generate_notice( wpautop( esc_html( $error ) ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
2025
		}
2026
2027
		gravityview()->log->error( '{error}', array( 'error' => $error ) );
2028
2029
		return false;
2030
2031
	}
2032
2033
2034
	/**
2035
	 * checks if user has permissions to edit a specific field
2036
	 *
2037
	 * Needs to be used combined with GravityView_Edit_Entry::user_can_edit_field for maximum security!!
2038
	 *
2039
	 * @param  [type] $field [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
2040
	 * @return bool
2041
	 */
2042 1
	private function check_user_cap_edit_field( $field ) {
2043
2044
		// If they can edit any entries (as defined in Gravity Forms), we're good.
2045 1
		if( GVCommon::has_cap( array( 'gravityforms_edit_entries', 'gravityview_edit_others_entries' ) ) ) {
2046 1
			return true;
2047
		}
2048
2049
		$field_cap = isset( $field['allow_edit_cap'] ) ? $field['allow_edit_cap'] : false;
2050
2051
		if( $field_cap ) {
2052
			return GVCommon::has_cap( $field['allow_edit_cap'] );
2053
		}
2054
2055
		return false;
2056
	}
2057
2058
2059
	/**
2060
	 * Is the current nonce valid for editing the entry?
2061
	 * @return boolean
2062
	 */
2063 12
	public function verify_nonce() {
2064
2065
		// Verify form submitted for editing single
2066 12
		if( $this->is_edit_entry_submission() ) {
2067
			$valid = wp_verify_nonce( $_POST[ self::$nonce_field ], self::$nonce_field );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
2068
		}
2069
2070
		// Verify
2071 12
		else if( ! $this->is_edit_entry() ) {
2072
			$valid = false;
2073
		}
2074
2075
		else {
2076 12
			$valid = wp_verify_nonce( $_GET['edit'], self::$nonce_key );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
2077
		}
2078
2079
		/**
2080
		 * @filter `gravityview/edit_entry/verify_nonce` Override Edit Entry nonce validation. Return true to declare nonce valid.
2081
		 * @since 1.13
2082
		 * @param int|boolean $valid False if invalid; 1 or 2 when nonce was generated
2083
		 * @param string $nonce_field Key used when validating submissions. Default: is_gv_edit_entry
2084
		 */
2085 12
		$valid = apply_filters( 'gravityview/edit_entry/verify_nonce', $valid, self::$nonce_field );
2086
2087 12
		return $valid;
2088
	}
2089
2090
2091
	/**
2092
	 * Multiselect in GF 2.2 became a json_encoded value. Fix it.
2093
	 *
2094
	 * As a hack for now we'll implode it back.
2095
	 */
2096
	public function fix_multiselect_value_serialization( $field_value, $field, $_this ) {
0 ignored issues
show
Unused Code introduced by
The parameter $_this is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
2097
		if ( empty ( $field->storageType ) || $field->storageType != 'json' ) {
0 ignored issues
show
introduced by
Found "!= '". Use Yoda Condition checks, you must
Loading history...
Coding Style introduced by
Space before opening parenthesis of function call prohibited
Loading history...
2098
			return $field_value;
2099
		}
2100
2101
		$maybe_json = @json_decode( $field_value, true );
0 ignored issues
show
Coding Style introduced by
Silencing errors is discouraged
Loading history...
2102
2103
		if ( $maybe_json ) {
2104
			return implode( ',', $maybe_json );
2105
		}
2106
2107
		return $field_value;
2108
	}
2109
2110
2111
2112
} //end class
2113