Completed
Push — develop ( 33756a...0eab66 )
by Zack
07:24
created

manage_conditional_logic()   A

Complexity

Conditions 2
Paths 2

Size

Total Lines 9
Code Lines 4

Duplication

Lines 0
Ratio 0 %

Code Coverage

Tests 3
CRAP Score 2.0625

Importance

Changes 0
Metric Value
cc 2
eloc 4
nc 2
nop 2
dl 0
loc 9
ccs 3
cts 4
cp 0.75
crap 2.0625
rs 9.6666
c 0
b 0
f 0
1
<?php
0 ignored issues
show
Coding Style Compatibility introduced by
For compatibility and reusability of your code, PSR1 recommends that a file should introduce either new symbols (like classes, functions, etc.) or have side-effects (like outputting something, or including other files), but not both at the same time. The first symbol is defined on line 16 and the first side effect is on line 13.

The PSR-1: Basic Coding Standard recommends that a file should either introduce new symbols, that is classes, functions, constants or similar, or have side effects. Side effects are anything that executes logic, like for example printing output, changing ini settings or writing to a file.

The idea behind this recommendation is that merely auto-loading a class should not change the state of an application. It also promotes a cleaner style of programming and makes your code less prone to errors, because the logic is not spread out all over the place.

To learn more about the PSR-1, please see the PHP-FIG site on the PSR-1.

Loading history...
2
/**
3
 * GravityView Edit Entry - render frontend
4
 *
5
 * @package   GravityView
6
 * @license   GPL2+
7
 * @author    Katz Web Services, Inc.
8
 * @link      http://gravityview.co
9
 * @copyright Copyright 2014, Katz Web Services, Inc.
10
 */
11
12
if ( ! defined( 'WPINC' ) ) {
13
    die;
14
}
15
16
class GravityView_Edit_Entry_Render {
17
18
    /**
19
     * @var GravityView_Edit_Entry
20
     */
21
    protected $loader;
22
23
	/**
24
	 * @var string String used to generate unique nonce for the entry/form/view combination. Allows access to edit page.
25
	 */
26
    static $nonce_key;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $nonce_key.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
27
28
	/**
29
	 * @since 1.9
30
	 * @var string String used for check valid edit entry form submission. Allows saving edit form values.
31
	 */
32
	private static $nonce_field = 'is_gv_edit_entry';
33
34
	/**
35
	 * @since 1.9
36
	 * @var bool Whether to allow save and continue functionality
37
	 */
38
	private static $supports_save_and_continue = false;
39
40
    /**
41
     * Gravity Forms entry array
42
     *
43
     * @var array
44
     */
45
    public $entry;
46
47
	/**
48
	 * Gravity Forms entry array (it won't get changed during this class lifecycle)
49
	 * @since 1.17.2
50
	 * @var array
51
	 */
52
	private static $original_entry = array();
53
54
    /**
55
     * Gravity Forms form array (GravityView modifies the content through this class lifecycle)
56
     *
57
     * @var array
58
     */
59
	public $form;
60
61
    /**
62
     * Gravity Forms form array (it won't get changed during this class lifecycle)
63
     * @since 1.16.2.1
64
     * @var array
65
     */
66
    private static $original_form;
67
68
    /**
69
     * Gravity Forms form array after the form validation process
70
     * @since 1.13
71
     * @var array
72
     */
73
	public $form_after_validation = null;
74
75
    /**
76
     * Hold an array of GF field objects that have calculation rules
77
     * @var array
78
     */
79
	public $fields_with_calculation = array();
80
81
    /**
82
     * Gravity Forms form id
83
     *
84
     * @var int
85
     */
86
	public $form_id;
87
88
    /**
89
     * ID of the current view
90
     *
91
     * @var int
92
     */
93
	public $view_id;
94
95
    /**
96
     * Updated entry is valid (GF Validation object)
97
     *
98
     * @var array
99
     */
100
	public $is_valid = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
101
102 2
    function __construct( GravityView_Edit_Entry $loader ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
103 2
        $this->loader = $loader;
104 2
    }
105
106 2
    function load() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
107
108
        /** @define "GRAVITYVIEW_DIR" "../../../" */
109 2
        include_once( GRAVITYVIEW_DIR .'includes/class-admin-approve-entries.php' );
110
111
        // Don't display an embedded form when editing an entry
112 2
        add_action( 'wp_head', array( $this, 'prevent_render_form' ) );
113 2
        add_action( 'wp_footer', array( $this, 'prevent_render_form' ) );
114
115
        // Stop Gravity Forms processing what is ours!
116 2
        add_filter( 'wp', array( $this, 'prevent_maybe_process_form'), 8 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
117
118 2
        add_filter( 'gravityview_is_edit_entry', array( $this, 'is_edit_entry') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
119
120 2
        add_action( 'gravityview_edit_entry', array( $this, 'init' ) );
121
122
        // Disable conditional logic if needed (since 1.9)
123 2
        add_filter( 'gform_has_conditional_logic', array( $this, 'manage_conditional_logic' ), 10, 2 );
124
125
        // Make sure GF doesn't validate max files (since 1.9)
126 2
        add_filter( 'gform_plupload_settings', array( $this, 'modify_fileupload_settings' ), 10, 3 );
127
128
        // Add fields expected by GFFormDisplay::validate()
129 2
        add_filter( 'gform_pre_validation', array( $this, 'gform_pre_validation') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
130
131 2
    }
132
133
    /**
134
     * Don't show any forms embedded on a page when GravityView is in Edit Entry mode
135
     *
136
     * Adds a `__return_empty_string` filter on the Gravity Forms shortcode on the `wp_head` action
137
     * And then removes it on the `wp_footer` action
138
     *
139
     * @since 1.16.1
140
     *
141
     * @return void
142
     */
143 1
    public function prevent_render_form() {
144 1
        if( $this->is_edit_entry() ) {
145 1
            if( 'wp_head' === current_filter() ) {
146 1
                add_filter( 'gform_shortcode_form', '__return_empty_string' );
147
            } else {
148 1
                remove_filter( 'gform_shortcode_form', '__return_empty_string' );
149
            }
150
        }
151 1
    }
152
153
    /**
154
     * Because we're mimicking being a front-end Gravity Forms form while using a Gravity Forms
155
     * backend form, we need to prevent them from saving twice.
156
     * @return void
157
     */
158
    public function prevent_maybe_process_form() {
159
160
        if( ! empty( $_POST ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
161
	        do_action( 'gravityview_log_debug', 'GravityView_Edit_Entry[prevent_maybe_process_form] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
162
        }
163
164
        if( $this->is_edit_entry_submission() ) {
165
            remove_action( 'wp',  array( 'RGForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
166
	        remove_action( 'wp',  array( 'GFForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
167
        }
168
    }
169
170
    /**
171
     * Is the current page an Edit Entry page?
172
     * @return boolean
173
     */
174 3
    public function is_edit_entry() {
175
176 3
        $is_edit_entry = GravityView_frontend::is_single_entry() && ! empty( $_GET['edit'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
177
178 3
        return ( $is_edit_entry || $this->is_edit_entry_submission() );
179
    }
180
181
	/**
182
	 * Is the current page an Edit Entry page?
183
	 * @since 1.9
184
	 * @return boolean
185
	 */
186 2
	public function is_edit_entry_submission() {
187 2
		return !empty( $_POST[ self::$nonce_field ] );
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
188
	}
189
190
    /**
191
     * When Edit entry view is requested setup the vars
192
     */
193 2
    private function setup_vars() {
194 2
        $gravityview_view = GravityView_View::getInstance();
195
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
196
197 2
        $entries = $gravityview_view->getEntries();
198 2
	    self::$original_entry = $entries[0];
199 2
	    $this->entry = $entries[0];
200
201 2
        self::$original_form = $gravityview_view->getForm();
202 2
        $this->form = $gravityview_view->getForm();
203 2
        $this->form_id = $gravityview_view->getFormId();
204 2
        $this->view_id = $gravityview_view->getViewId();
205
206 2
        self::$nonce_key = GravityView_Edit_Entry::get_nonce_key( $this->view_id, $this->form_id, $this->entry['id'] );
207 2
    }
208
209
210
    /**
211
     * Load required files and trigger edit flow
212
     *
213
     * Run when the is_edit_entry returns true.
214
     *
215
     * @param GravityView_View_Data $gv_data GravityView Data object
216
     * @return void
217
     */
218 3
    public function init( $gv_data ) {
219
220 3
        require_once( GFCommon::get_base_path() . '/form_display.php' );
221 3
        require_once( GFCommon::get_base_path() . '/entry_detail.php' );
222
223 3
        $this->setup_vars();
224
225
        // Multiple Views embedded, don't proceed if nonce fails
226 3
        if( $gv_data->has_multiple_views() && ! wp_verify_nonce( $_GET['edit'], self::$nonce_key ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
227
            do_action('gravityview_log_error', __METHOD__ . ': Nonce validation failed for the Edit Entry request; returning' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
228
            return;
229
        }
230
231
        // Sorry, you're not allowed here.
232 3
        if( false === $this->user_can_edit_entry( true ) ) {
233 1
            do_action('gravityview_log_error', __METHOD__ . ': User is not allowed to edit this entry; returning', $this->entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
234 1
            return;
235
        }
236
237 3
        $this->print_scripts();
238
239 3
        $this->process_save();
240
241 3
        $this->edit_entry_form();
242
243 3
    }
244
245
246
    /**
247
     * Force Gravity Forms to output scripts as if it were in the admin
248
     * @return void
249
     */
250 2
    private function print_scripts() {
251 2
        $gravityview_view = GravityView_View::getInstance();
252
253 2
        wp_register_script( 'gform_gravityforms', GFCommon::get_base_url().'/js/gravityforms.js', array( 'jquery', 'gform_json', 'gform_placeholder', 'sack', 'plupload-all', 'gravityview-fe-view' ) );
254
255 2
        GFFormDisplay::enqueue_form_scripts($gravityview_view->getForm(), false);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
256
257
        // Sack is required for images
258 2
        wp_print_scripts( array( 'sack', 'gform_gravityforms' ) );
259 2
    }
260
261
262
    /**
263
     * Process edit entry form save
264
     */
265 3
    private function process_save() {
266
267 3
        if( empty( $_POST ) || ! isset( $_POST['lid'] ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
268 3
            return;
269
        }
270
271
        // Make sure the entry, view, and form IDs are all correct
272 3
        $valid = $this->verify_nonce();
273
274 3
        if( !$valid ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
275
            do_action('gravityview_log_error', __METHOD__ . ' Nonce validation failed.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
276
            return;
277
        }
278
279 3
        if( $this->entry['id'] !== $_POST['lid'] ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
280
            do_action('gravityview_log_error', __METHOD__ . ' Entry ID did not match posted entry ID.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
281
            return;
282
        }
283
284 3
        do_action('gravityview_log_debug', __METHOD__ . ': $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
285
286 3
        $this->process_save_process_files( $this->form_id );
287
288 3
        $this->validate();
289
290 3
        if( $this->is_valid ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using ! empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
291
292 3
            do_action('gravityview_log_debug', __METHOD__ . ': Submission is valid.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
293
294
            /**
295
             * @hack This step is needed to unset the adminOnly from form fields, to add the calculation fields
296
             */
297 3
            $form = $this->form_prepare_for_save();
298
299
            /**
300
             * @hack to avoid the capability validation of the method save_lead for GF 1.9+
301
             */
302 3
            unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
303
304 3
            $date_created = $this->entry['date_created'];
305
306
            /**
307
             * @hack to force Gravity Forms to use $read_value_from_post in GFFormsModel::save_lead()
308
             * @since 1.17.2
309
             */
310 3
            unset( $this->entry['date_created'] );
311
312 3
            GFFormsModel::save_lead( $form, $this->entry );
313
314
	        // Delete the values for hidden inputs
315 3
	        $this->unset_hidden_field_values();
316
            
317 3
            $this->entry['date_created'] = $date_created;
318
319
            // Process calculation fields
320 3
            $this->update_calculation_fields();
321
322
            // Perform actions normally performed after updating a lead
323 3
            $this->after_update();
324
325
	        /**
326
             * Must be AFTER after_update()!
327
             * @see https://github.com/gravityview/GravityView/issues/764
328
             */
329 3
            $this->maybe_update_post_fields( $form );
330
331
            /**
332
             * @action `gravityview/edit_entry/after_update` Perform an action after the entry has been updated using Edit Entry
333
             * @param array $form Gravity Forms form array
334
             * @param string $entry_id Numeric ID of the entry that was updated
335
             * @param GravityView_Edit_Entry_Render $this This object
336
             */
337 3
            do_action( 'gravityview/edit_entry/after_update', $this->form, $this->entry['id'], $this );
338
339
        } else {
340
            do_action('gravityview_log_error', __METHOD__ . ': Submission is NOT valid.', $this->entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
341
        }
342
343 3
    } // process_save
344
345
	/**
346
	 * Delete the value of fields hidden by conditional logic when the entry is edited
347
     *
348
     * @uses GFFormsModel::update_lead_field_value()
349
     *
350
     * @since 1.17.4
351
     *
352
     * @return void
353
	 */
354 2
    private function unset_hidden_field_values() {
355 2
	    global $wpdb;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
356
357 2
	    $lead_detail_table      = GFFormsModel::get_lead_details_table_name();
358 2
	    $current_fields   = $wpdb->get_results( $wpdb->prepare( "SELECT id, field_number FROM $lead_detail_table WHERE lead_id=%d", $this->entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
359
360 2
	    foreach ( $this->entry as $input_id => $field_value ) {
361
362 2
		    $field = RGFormsModel::get_field( $this->form, $input_id );
363
364
		    // Reset fields that are hidden
365
		    // Don't pass $entry as fourth parameter; force using $_POST values to calculate conditional logic
366 2
		    if ( GFFormsModel::is_field_hidden( $this->form, $field, array(), NULL ) ) {
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
367
368
		        // List fields are stored as empty arrays when empty
369
			    $empty_value = $this->is_field_json_encoded( $field ) ? '[]' : '';
370
371
			    $lead_detail_id = GFFormsModel::get_lead_detail_id( $current_fields, $input_id );
372
373
			    GFFormsModel::update_lead_field_value( $this->form, $this->entry, $field, $lead_detail_id, $input_id, $empty_value );
374
375
			    // Prevent the $_POST values of hidden fields from being used as default values when rendering the form
376
                // after submission
377
			    $post_input_id = 'input_' . str_replace( '.', '_', $input_id );
378 2
			    $_POST[ $post_input_id ] = '';
379
		    }
380
	    }
381 2
    }
382
383
    /**
384
     * Have GF handle file uploads
385
     *
386
     * Copy of code from GFFormDisplay::process_form()
387
     *
388
     * @param int $form_id
389
     */
390 2
    private function process_save_process_files( $form_id ) {
391
392
        //Loading files that have been uploaded to temp folder
393 2
        $files = GFCommon::json_decode( stripslashes( RGForms::post( 'gform_uploaded_files' ) ) );
394 2
        if ( ! is_array( $files ) ) {
395 2
            $files = array();
396
        }
397
398
		/**
399
		 * Make sure the fileuploads are not overwritten if no such request was done.
400
         * @since 1.20.1
401
		 */
402 2
		add_filter( "gform_save_field_value_$form_id", array( $this, 'save_field_value' ), 99, 5 );
403
404 2
        RGFormsModel::$uploaded_files[ $form_id ] = $files;
405 2
    }
406
407
	/**
408
	 * Make sure the fileuploads are not overwritten if no such request was done.
409
	 *
410
     * TO ONLY BE USED INTERNALLY; DO NOT DEVELOP ON; MAY BE REMOVED AT ANY TIME.
411
     *
412
	 * @since 1.20.1
413
	 *
414
	 * @param string $value Field value
415
	 * @param array $entry GF entry array
416
	 * @param GF_Field_FileUpload $field
417
	 * @param array $form GF form array
418
	 * @param string $input_id ID of the input being saved
419
	 *
420
	 * @return string
421
	 */
422 2
	public function save_field_value( $value = '', $entry = array(), $field = null, $form = array(), $input_id = '' ) {
423
424 2
		if ( ! $field || $field->type != 'fileupload' ) {
0 ignored issues
show
introduced by
Found "!= '". Use Yoda Condition checks, you must
Loading history...
425 2
			return $value;
426
		}
427
428 1
		$input_name = 'input_' . str_replace( '.', '_', $input_id );
429
430 1
		if ( $field->multipleFiles ) {
431
			if ( empty( $value ) ) {
432
				return json_decode( $entry[ $input_id ], true );
433
			}
434
			return $value;
435
		}
436
437
		/** No file is being uploaded. */
438 1
		if ( empty( $_FILES[ $input_name ]['name'] ) ) {
439
			/** So return the original upload */
440 1
			return $entry[ $input_id ];
441
		}
442
443 1
		return $value;
444
	}
445
446
    /**
447
     * Remove max_files validation (done on gravityforms.js) to avoid conflicts with GravityView
448
     * Late validation done on self::custom_validation
449
     *
450
     * @param $plupload_init array Plupload settings
451
     * @param $form_id
452
     * @param $instance
453
     * @return mixed
454
     */
455 1
    public function modify_fileupload_settings( $plupload_init, $form_id, $instance ) {
0 ignored issues
show
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $instance is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
456 1
        if( ! $this->is_edit_entry() ) {
457
            return $plupload_init;
458
        }
459
460 1
        $plupload_init['gf_vars']['max_files'] = 0;
461
462 1
        return $plupload_init;
463
    }
464
465
466
    /**
467
     * Unset adminOnly and convert field input key to string
468
     * @return array $form
469
     */
470 2
    private function form_prepare_for_save() {
471
472 2
        $form = $this->form;
473
474
	    /** @var GF_Field $field */
475 2
        foreach( $form['fields'] as $k => &$field ) {
476
477
            /**
478
             * Remove the fields with calculation formulas before save to avoid conflicts with GF logic
479
             * @since 1.16.3
480
             * @var GF_Field $field
481
             */
482 2
            if( $field->has_calculation() ) {
483
                unset( $form['fields'][ $k ] );
484
            }
485
486 2
            $field->adminOnly = false;
487
488 2
            if( isset( $field->inputs ) && is_array( $field->inputs ) ) {
489
                foreach( $field->inputs as $key => $input ) {
490 2
                    $field->inputs[ $key ][ 'id' ] = (string)$input['id'];
0 ignored issues
show
introduced by
Array keys should NOT be surrounded by spaces if they only contain a string or an integer.
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
491
                }
492
            }
493
        }
494
495 2
        return $form;
496
    }
497
498 2
    private function update_calculation_fields() {
499
500 2
        $form = self::$original_form;
501 2
        $update = false;
502
503
        // get the most up to date entry values
504 2
        $entry = GFAPI::get_entry( $this->entry['id'] );
505
506 2
        if( !empty( $this->fields_with_calculation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
507
            $update = true;
508
            foreach ( $this->fields_with_calculation as $calc_field ) {
509
                $inputs = $calc_field->get_entry_inputs();
510
                if ( is_array( $inputs ) ) {
511
                    foreach ( $inputs as $input ) {
512
                        $input_name = 'input_' . str_replace( '.', '_', $input['id'] );
513
                        $entry[ strval( $input['id'] ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
514
                    }
515
                } else {
516
                    $input_name = 'input_' . str_replace( '.', '_', $calc_field->id);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
517
                    $entry[ strval( $calc_field->id ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
518
                }
519
            }
520
521
        }
522
523 2
        if( $update ) {
524
525
            $return_entry = GFAPI::update_entry( $entry );
526
527
            if( is_wp_error( $return_entry ) ) {
528
                do_action( 'gravityview_log_error', 'Updating the entry calculation fields failed', $return_entry );
529
            } else {
530
                do_action( 'gravityview_log_debug', 'Updating the entry calculation fields succeeded' );
531
            }
532
        }
533 2
    }
534
535
    /**
536
     * Handle updating the Post Image field
537
     *
538
     * Sets a new Featured Image if configured in Gravity Forms; otherwise uploads/updates media
539
     *
540
     * @since 1.17
541
     *
542
     * @uses GFFormsModel::media_handle_upload
543
     * @uses set_post_thumbnail
544
     * 
545
     * @param array $form GF Form array
546
     * @param GF_Field $field GF Field
547
     * @param string $field_id Numeric ID of the field
548
     * @param string $value
549
     * @param array $entry GF Entry currently being edited
550
     * @param int $post_id ID of the Post being edited
551
     *
552
     * @return mixed|string
553
     */
554
    private function update_post_image( $form, $field, $field_id, $value, $entry, $post_id ) {
555
556
        $input_name = 'input_' . $field_id;
557
558
        if ( !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
559
560
            // We have a new image
561
562
            $value = RGFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'] );
563
564
            $ary = ! empty( $value ) ? explode( '|:|', $value ) : array();
565
            $img_url = rgar( $ary, 0 );
566
567
            $img_title       = count( $ary ) > 1 ? $ary[1] : '';
568
            $img_caption     = count( $ary ) > 2 ? $ary[2] : '';
569
            $img_description = count( $ary ) > 3 ? $ary[3] : '';
570
571
            $image_meta = array(
572
                'post_excerpt' => $img_caption,
573
                'post_content' => $img_description,
574
            );
575
576
            //adding title only if it is not empty. It will default to the file name if it is not in the array
577
            if ( ! empty( $img_title ) ) {
578
                $image_meta['post_title'] = $img_title;
579
            }
580
581
            /**
582
             * todo: As soon as \GFFormsModel::media_handle_upload becomes a public method, move this call to \GFFormsModel::media_handle_upload and remove the hack from this class.
583
             * Note: the method became public in GF 1.9.17.7, but we don't require that version yet.
584
             */
585
            require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
586
            $media_id = GravityView_GFFormsModel::media_handle_upload( $img_url, $post_id, $image_meta );
587
588
            // is this field set as featured image?
589
            if ( $media_id && $field->postFeaturedImage ) {
590
                set_post_thumbnail( $post_id, $media_id );
591
            }
592
593
        } elseif ( !empty( $_POST[ $input_name ] ) && is_array( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
594
595
            // Same image although the image title, caption or description might have changed
596
597
            $ary = array();
598
            if( ! empty( $entry[ $field_id ] ) ) {
599
                $ary = is_array( $entry[ $field_id ] ) ? $entry[ $field_id ] : explode( '|:|', $entry[ $field_id ] );
600
            }
601
            $img_url = rgar( $ary, 0 );
602
603
            // is this really the same image or something went wrong ?
604
            if( $img_url === $_POST[ $input_name ] ) {
605
606
                $img_title       = rgar( $value, $field_id .'.1' );
607
                $img_caption     = rgar( $value, $field_id .'.4' );
608
                $img_description = rgar( $value, $field_id .'.7' );
609
610
                $value = ! empty( $img_url ) ? $img_url . "|:|" . $img_title . "|:|" . $img_caption . "|:|" . $img_description : '';
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal |:| does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
611
612
                if ( $field->postFeaturedImage ) {
613
614
                    $image_meta = array(
615
                        'ID' => get_post_thumbnail_id( $post_id ),
616
                        'post_title' => $img_title,
617
                        'post_excerpt' => $img_caption,
618
                        'post_content' => $img_description,
619
                    );
620
621
                    // update image title, caption or description
622
                    wp_update_post( $image_meta );
623
                }
624
            }
625
626
        } else {
627
628
            // if we get here, image was removed or not set.
629
            $value = '';
630
631
            if ( $field->postFeaturedImage ) {
632
                delete_post_thumbnail( $post_id );
633
            }
634
        }
635
636
        return $value;
637
    }
638
639
    /**
640
     * Loop through the fields being edited and if they include Post fields, update the Entry's post object
641
     *
642
     * @param array $form Gravity Forms form
643
     *
644
     * @return void
645
     */
646 2
    private function maybe_update_post_fields( $form ) {
647
648 2
        if( empty( $this->entry['post_id'] ) ) {
649 2
	        do_action( 'gravityview_log_debug', __METHOD__ . ': This entry has no post fields. Continuing...' );
650 2
            return;
651
        }
652
653
        $post_id = $this->entry['post_id'];
654
655
        // Security check
656
        if( false === GVCommon::has_cap( 'edit_post', $post_id ) ) {
657
            do_action( 'gravityview_log_error', 'The current user does not have the ability to edit Post #'.$post_id );
658
            return;
659
        }
660
661
        $update_entry = false;
662
663
        $updated_post = $original_post = get_post( $post_id );
664
665
        foreach ( $this->entry as $field_id => $value ) {
666
667
            $field = RGFormsModel::get_field( $form, $field_id );
668
669
            if( ! $field ) {
670
                continue;
671
            }
672
673
            if( GFCommon::is_post_field( $field ) && 'post_category' !== $field->type ) {
674
675
                // Get the value of the field, including $_POSTed value
676
                $value = RGFormsModel::get_field_value( $field );
677
678
                // Use temporary entry variable, to make values available to fill_post_template() and update_post_image()
679
                $entry_tmp = $this->entry;
680
                $entry_tmp["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
681
682
                switch( $field->type ) {
683
684
                    case 'post_title':
685
                        $post_title = $value;
686
                        if( rgar( $form, 'postTitleTemplateEnabled' ) ) {
687
                            $post_title = $this->fill_post_template( $form['postTitleTemplate'], $form, $entry_tmp );
688
                        }
689
                        $updated_post->post_title = $post_title;
690
                        $updated_post->post_name  = $post_title;
691
                        unset( $post_title );
692
                        break;
693
694
                    case 'post_content':
695
                        $post_content = $value;
696
                        if( rgar( $form, 'postContentTemplateEnabled' ) ) {
697
                            $post_content = $this->fill_post_template( $form['postContentTemplate'], $form, $entry_tmp, true );
698
                        }
699
                        $updated_post->post_content = $post_content;
700
                        unset( $post_content );
701
                        break;
702
                    case 'post_excerpt':
703
                        $updated_post->post_excerpt = $value;
704
                        break;
705
                    case 'post_tags':
706
                        wp_set_post_tags( $post_id, $value, false );
707
                        break;
708
                    case 'post_category':
709
                        break;
710
                    case 'post_custom_field':
711
                        if( ! empty( $field->customFieldTemplateEnabled ) ) {
712
                            $value = $this->fill_post_template( $field->customFieldTemplate, $form, $entry_tmp, true );
713
                        }
714
715
	                    if ( $this->is_field_json_encoded( $field ) && ! is_string( $value ) ) {
716
		                    $value = function_exists('wp_json_encode') ? wp_json_encode( $value ) : json_encode( $value );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
717
	                    }
718
719
                        update_post_meta( $post_id, $field->postCustomFieldName, $value );
720
                        break;
721
722
                    case 'post_image':
723
                        $value = $this->update_post_image( $form, $field, $field_id, $value, $this->entry, $post_id );
724
                        break;
725
726
                }
727
728
                // update entry after
729
                $this->entry["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
730
731
                $update_entry = true;
732
733
                unset( $entry_tmp );
734
            }
735
736
        }
737
738
        if( $update_entry ) {
739
740
            $return_entry = GFAPI::update_entry( $this->entry );
741
742
            if( is_wp_error( $return_entry ) ) {
743
               do_action( 'gravityview_log_error', 'Updating the entry post fields failed', array( '$this->entry' => $this->entry, '$return_entry' => $return_entry ) );
744
            } else {
745
                do_action( 'gravityview_log_debug', 'Updating the entry post fields for post #'.$post_id.' succeeded' );
746
            }
747
748
        }
749
750
        $return_post = wp_update_post( $updated_post, true );
751
752
        if( is_wp_error( $return_post ) ) {
753
            $return_post->add_data( $updated_post, '$updated_post' );
754
            do_action( 'gravityview_log_error', 'Updating the post content failed', compact( 'updated_post', 'return_post' ) );
755
        } else {
756
            do_action( 'gravityview_log_debug', 'Updating the post content for post #'.$post_id.' succeeded', $updated_post );
757
        }
758
    }
759
760
	/**
761
     * Is the field stored in a JSON-encoded manner?
762
     *
763
	 * @param GF_Field $field
764
	 *
765
	 * @return bool True: stored in DB json_encode()'d; False: not encoded
766
	 */
767
    private function is_field_json_encoded( $field ) {
768
769
	    $json_encoded = false;
770
771
        $input_type = RGFormsModel::get_input_type( $field );
772
773
	    // Only certain custom field types are supported
774
	    switch( $input_type ) {
775
		    case 'fileupload':
776
		    case 'list':
777
		    case 'multiselect':
778
			    $json_encoded = true;
779
			    break;
780
	    }
781
782
	    return $json_encoded;
783
    }
784
785
    /**
786
     * Convert a field content template into prepared output
787
     *
788
     * @uses GravityView_GFFormsModel::get_post_field_images()
789
     *
790
     * @since 1.17
791
     *
792
     * @param string $template The content template for the field
793
     * @param array $form Gravity Forms form
794
     * @param bool $do_shortcode Whether to process shortcode inside content. In GF, only run on Custom Field and Post Content fields
795
     *
796
     * @return string
797
     */
798
    private function fill_post_template( $template, $form, $entry, $do_shortcode = false ) {
799
800
        require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
801
802
        $post_images = GravityView_GFFormsModel::get_post_field_images( $form, $entry );
803
804
        //replacing post image variables
805
        $output = GFCommon::replace_variables_post_image( $template, $post_images, $entry );
806
807
        //replacing all other variables
808
        $output = GFCommon::replace_variables( $output, $form, $entry, false, false, false );
809
810
        // replace conditional shortcodes
811
        if( $do_shortcode ) {
812
            $output = do_shortcode( $output );
813
        }
814
815
        return $output;
816
    }
817
818
819
    /**
820
     * Perform actions normally performed after updating a lead
821
     *
822
     * @since 1.8
823
     *
824
     * @see GFEntryDetail::lead_detail_page()
825
     *
826
     * @return void
827
     */
828 2
    private function after_update() {
829
830 2
        do_action( 'gform_after_update_entry', $this->form, $this->entry['id'], self::$original_entry );
831 2
        do_action( "gform_after_update_entry_{$this->form['id']}", $this->form, $this->entry['id'], self::$original_entry );
832
833
        // Re-define the entry now that we've updated it.
834 2
        $entry = RGFormsModel::get_lead( $this->entry['id'] );
835
836 2
        $entry = GFFormsModel::set_entry_meta( $entry, $this->form );
837
838
        // We need to clear the cache because Gravity Forms caches the field values, which
839
        // we have just updated.
840 2
        foreach ($this->form['fields'] as $key => $field) {
0 ignored issues
show
introduced by
No space after opening parenthesis is prohibited
Loading history...
introduced by
No space before closing parenthesis is prohibited
Loading history...
841 2
            GFFormsModel::refresh_lead_field_value( $entry['id'], $field->id );
842
        }
843
844 2
        $this->entry = $entry;
845 2
    }
846
847
848
    /**
849
     * Display the Edit Entry form
850
     *
851
     * @return void
852
     */
853 2
    public function edit_entry_form() {
854
855
        ?>
856
857
        <div class="gv-edit-entry-wrapper"><?php
858
859 2
            $javascript = gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/inline-javascript.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
860
861
            /**
862
             * Fixes weird wpautop() issue
863
             * @see https://github.com/katzwebservices/GravityView/issues/451
864
             */
865 2
            echo gravityview_strip_whitespace( $javascript );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'gravityview_strip_whitespace'
Loading history...
866
867
            ?><h2 class="gv-edit-entry-title">
868
                <span><?php
869
870
                    /**
871
                     * @filter `gravityview_edit_entry_title` Modify the edit entry title
872
                     * @param string $edit_entry_title Modify the "Edit Entry" title
873
                     * @param GravityView_Edit_Entry_Render $this This object
874
                     */
875 2
                    $edit_entry_title = apply_filters('gravityview_edit_entry_title', __('Edit Entry', 'gravityview'), $this );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
876
877 2
                    echo esc_attr( $edit_entry_title );
878
            ?></span>
879
            </h2>
880
881
            <?php $this->maybe_print_message(); ?>
882
883
            <?php // The ID of the form needs to be `gform_{form_id}` for the pluploader ?>
884
885
            <form method="post" id="gform_<?php echo $this->form_id; ?>" enctype="multipart/form-data">
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$this'
Loading history...
886
887
                <?php
888
889 2
                wp_nonce_field( self::$nonce_key, self::$nonce_key );
890
891 2
                wp_nonce_field( self::$nonce_field, self::$nonce_field, false );
892
893
                // Print the actual form HTML
894 2
                $this->render_edit_form();
895
896
                ?>
897
            </form>
898
899
            <script>
900
                gform.addFilter('gform_reset_pre_conditional_logic_field_action', function ( reset, formId, targetId, defaultValues, isInit ) {
901
                    return false;
902
                });
903
            </script>
904
905
        </div>
906
907
    <?php
908 2
    }
909
910
    /**
911
     * Display success or error message if the form has been submitted
912
     *
913
     * @uses GVCommon::generate_notice
914
     *
915
     * @since 1.16.2.2
916
     *
917
     * @return void
918
     */
919 2
    private function maybe_print_message() {
920
921 2
        if( rgpost('action') === 'update' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
922
923
            $back_link = esc_url( remove_query_arg( array( 'page', 'view', 'edit' ) ) );
924
925
            if( ! $this->is_valid ){
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
926
927
                // Keeping this compatible with Gravity Forms.
928
                $validation_message = "<div class='validation_error'>" . __('There was a problem with your submission.', 'gravityview') . " " . __('Errors have been highlighted below.', 'gravityview') . "</div>";
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw '__'
Loading history...
Coding Style Comprehensibility introduced by
The string literal </div> does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
929
                $message = apply_filters("gform_validation_message_{$this->form['id']}", apply_filters("gform_validation_message", $validation_message, $this->form), $this->form);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal gform_validation_message does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
930
931
                echo GVCommon::generate_notice( $message , 'gv-error' );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
932
933
            } else {
934
                $entry_updated_message = sprintf( esc_attr__('Entry Updated. %sReturn to Entry%s', 'gravityview'), '<a href="'. $back_link .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
935
936
                /**
937
                 * @filter `gravityview/edit_entry/success` Modify the edit entry success message (including the anchor link)
938
                 * @since 1.5.4
939
                 * @param string $entry_updated_message Existing message
940
                 * @param int $view_id View ID
941
                 * @param array $entry Gravity Forms entry array
942
                 * @param string $back_link URL to return to the original entry. @since 1.6
943
                 */
944
                $message = apply_filters( 'gravityview/edit_entry/success', $entry_updated_message , $this->view_id, $this->entry, $back_link );
945
946
                echo GVCommon::generate_notice( $message );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
947
            }
948
949
        }
950 2
    }
951
952
    /**
953
     * Display the Edit Entry form in the original Gravity Forms format
954
     *
955
     * @since 1.9
956
     *
957
     * @return void
958
     */
959 2
    private function render_edit_form() {
960
961
        /**
962
         * @action `gravityview/edit-entry/render/before` Before rendering the Edit Entry form
963
         * @since 1.17
964
         * @param GravityView_Edit_Entry_Render $this
965
         */
966 2
        do_action( 'gravityview/edit-entry/render/before', $this );
967
968 2
        add_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields'), 5000, 3 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
969 2
        add_filter( 'gform_submit_button', array( $this, 'render_form_buttons') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
970 2
        add_filter( 'gform_disable_view_counter', '__return_true' );
971
972 2
        add_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5, 5 );
973 2
        add_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10, 5 );
974
975
        // We need to remove the fake $_GET['page'] arg to avoid rendering form as if in admin.
976 2
        unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
977
978
        // TODO: Verify multiple-page forms
979
980 2
        ob_start(); // Prevent PHP warnings possibly caused by prefilling list fields for conditional logic
981
982 2
        $html = GFFormDisplay::get_form( $this->form['id'], false, false, true, $this->entry );
983
984 2
        ob_get_clean();
985
986 2
	    remove_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields' ), 5000 );
987 2
        remove_filter( 'gform_submit_button', array( $this, 'render_form_buttons' ) );
988 2
        remove_filter( 'gform_disable_view_counter', '__return_true' );
989 2
        remove_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5 );
990 2
        remove_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10 );
991
992 2
        echo $html;
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$html'
Loading history...
993
994
        /**
995
         * @action `gravityview/edit-entry/render/after` After rendering the Edit Entry form
996
         * @since 1.17
997
         * @param GravityView_Edit_Entry_Render $this
998
         */
999 2
        do_action( 'gravityview/edit-entry/render/after', $this );
1000 2
    }
1001
1002
    /**
1003
     * Display the Update/Cancel/Delete buttons for the Edit Entry form
1004
     * @since 1.8
1005
     * @return string
1006
     */
1007 2
    public function render_form_buttons() {
1008 2
        return gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/form-buttons.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
1009
    }
1010
1011
1012
    /**
1013
     * Modify the form fields that are shown when using GFFormDisplay::get_form()
1014
     *
1015
     * By default, all fields will be shown. We only want the Edit Tab configured fields to be shown.
1016
     *
1017
     * @param array $form
1018
     * @param boolean $ajax Whether in AJAX mode
1019
     * @param array|string $field_values Passed parameters to the form
1020
     *
1021
     * @since 1.9
1022
     *
1023
     * @return array Modified form array
1024
     */
1025 2
    public function filter_modify_form_fields( $form, $ajax = false, $field_values = '' ) {
0 ignored issues
show
Unused Code introduced by
The parameter $ajax is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $field_values is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1026
1027
        // In case we have validated the form, use it to inject the validation results into the form render
1028 2
        if( isset( $this->form_after_validation ) ) {
1029 2
            $form = $this->form_after_validation;
1030
        } else {
1031 2
            $form['fields'] = $this->get_configured_edit_fields( $form, $this->view_id );
1032
        }
1033
1034 2
        $form = $this->filter_conditional_logic( $form );
1035
1036 2
        $form = $this->prefill_conditional_logic( $form );
1037
1038
        // for now we don't support Save and Continue feature.
1039 2
        if( ! self::$supports_save_and_continue ) {
1040 2
	        unset( $form['save'] );
1041
        }
1042
1043 2
        return $form;
1044
    }
1045
1046
    /**
1047
     * When displaying a field, check if it's a Post Field, and if so, make sure the post exists and current user has edit rights.
1048
     *
1049
     * @since 1.16.2.2
1050
     *
1051
     * @param string $field_content Always empty. Returning not-empty overrides the input.
1052
     * @param GF_Field $field
1053
     * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1054
     * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1055
     * @param int $form_id Form ID
1056
     *
1057
     * @return string If error, the error message. If no error, blank string (modify_edit_field_input() runs next)
1058
     */
1059 2
    public function verify_user_can_edit_post( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1060
1061 2
        if( GFCommon::is_post_field( $field ) ) {
1062
1063
            $message = null;
1064
1065
            // First, make sure they have the capability to edit the post.
1066
            if( false === current_user_can( 'edit_post', $this->entry['post_id'] ) ) {
1067
1068
                /**
1069
                 * @filter `gravityview/edit_entry/unsupported_post_field_text` Modify the message when someone isn't able to edit a post
1070
                 * @param string $message The existing "You don't have permission..." text
1071
                 */
1072
                $message = apply_filters('gravityview/edit_entry/unsupported_post_field_text', __('You don&rsquo;t have permission to edit this post.', 'gravityview') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1073
1074
            } elseif( null === get_post( $this->entry['post_id'] ) ) {
1075
                /**
1076
                 * @filter `gravityview/edit_entry/no_post_text` Modify the message when someone is editing an entry attached to a post that no longer exists
1077
                 * @param string $message The existing "This field is not editable; the post no longer exists." text
1078
                 */
1079
                $message = apply_filters('gravityview/edit_entry/no_post_text', __('This field is not editable; the post no longer exists.', 'gravityview' ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1080
            }
1081
1082
            if( $message ) {
1083
                $field_content = sprintf('<div class="ginput_container ginput_container_' . $field->type . '">%s</div>', wpautop( $message ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1084
            }
1085
        }
1086
1087 2
        return $field_content;
1088
    }
1089
1090
    /**
1091
     *
1092
     * Fill-in the saved values into the form inputs
1093
     *
1094
     * @param string $field_content Always empty. Returning not-empty overrides the input.
1095
     * @param GF_Field $field
1096
     * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1097
     * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1098
     * @param int $form_id Form ID
1099
     *
1100
     * @return mixed
1101
     */
1102 2
    public function modify_edit_field_input( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1103
1104 2
        $gv_field = GravityView_Fields::get_associated_field( $field );
1105
1106
        // If the form has been submitted, then we don't need to pre-fill the values,
1107
        // Except for fileupload type and when a field input is overridden- run always!!
1108
        if(
1109 2
            ( $this->is_edit_entry_submission() && !in_array( $field->type, array( 'fileupload', 'post_image' ) ) )
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1110 2
            && false === ( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) )
1111
            && ! GFCommon::is_product_field( $field->type )
1112 2
            || ! empty( $field_content )
1113 2
            || in_array( $field->type, array( 'honeypot' ) )
1114
        ) {
1115
	        return $field_content;
1116
        }
1117
1118
        // SET SOME FIELD DEFAULTS TO PREVENT ISSUES
1119 2
        $field->adminOnly = false; /** @see GFFormDisplay::get_counter_init_script() need to prevent adminOnly */
1120
1121 2
        $field_value = $this->get_field_value( $field );
1122
1123
	    // Prevent any PHP warnings, like undefined index
1124 2
	    ob_start();
1125
1126 2
	    $return = null;
1127
1128
        /** @var GravityView_Field $gv_field */
1129 2
        if( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) ) {
1130 1
            $return = $gv_field->get_field_input( $this->form, $field_value, $this->entry, $field );
1131
        } else {
1132 2
	        $return = $field->get_field_input( $this->form, $field_value, $this->entry );
1133
	    }
1134
1135
	    // If there was output, it's an error
1136 2
	    $warnings = ob_get_clean();
1137
1138 2
	    if( !empty( $warnings ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1139
		    do_action( 'gravityview_log_error', __METHOD__ . $warnings, $field_value );
1140
	    }
1141
1142 2
        return $return;
1143
    }
1144
1145
    /**
1146
     * Modify the value for the current field input
1147
     *
1148
     * @param GF_Field $field
1149
     *
1150
     * @return array|mixed|string
1151
     */
1152 2
    private function get_field_value( $field ) {
1153
1154
        /**
1155
         * @filter `gravityview/edit_entry/pre_populate/override` Allow the pre-populated value to override saved value in Edit Entry form. By default, pre-populate mechanism only kicks on empty fields.
1156
         * @param boolean True: override saved values; False: don't override (default)
1157
         * @param $field GF_Field object Gravity Forms field object
1158
         * @since 1.13
1159
         */
1160 2
        $override_saved_value = apply_filters( 'gravityview/edit_entry/pre_populate/override', false, $field );
1161
1162
        // We're dealing with multiple inputs (e.g. checkbox) but not time or date (as it doesn't store data in input IDs)
1163 2
        if( isset( $field->inputs ) && is_array( $field->inputs ) && !in_array( $field->type, array( 'time', 'date' ) ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1164
1165
            $field_value = array();
1166
1167
            // only accept pre-populated values if the field doesn't have any choice selected.
1168
            $allow_pre_populated = $field->allowsPrepopulate;
1169
1170
            foreach ( (array)$field->inputs as $input ) {
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1171
1172
                $input_id = strval( $input['id'] );
1173
                
1174
                if ( isset( $this->entry[ $input_id ] ) && ! gv_empty( $this->entry[ $input_id ], false, false ) ) {
1175
                    $field_value[ $input_id ] =  'post_category' === $field->type ? GFCommon::format_post_category( $this->entry[ $input_id ], true ) : $this->entry[ $input_id ];
0 ignored issues
show
introduced by
Expected 1 space after "="; 2 found
Loading history...
1176
                    $allow_pre_populated = false;
1177
                }
1178
1179
            }
1180
1181
            $pre_value = $field->get_value_submission( array(), false );
1182
1183
            $field_value = ! $allow_pre_populated && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $field_value : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1184
1185
        } else {
1186
1187 2
            $id = intval( $field->id );
1188
1189
            // get pre-populated value if exists
1190 2
            $pre_value = $field->allowsPrepopulate ? GFFormsModel::get_parameter_value( $field->inputName, array(), $field ) : '';
1191
1192
            // saved field entry value (if empty, fallback to the pre-populated value, if exists)
1193
            // or pre-populated value if not empty and set to override saved value
1194 2
            $field_value = !gv_empty( $this->entry[ $id ], false, false ) && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $this->entry[ $id ] : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1195
1196
            // in case field is post_category but inputType is select, multi-select or radio, convert value into array of category IDs.
1197 2
            if ( 'post_category' === $field->type && !gv_empty( $field_value, false, false ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1198
                $categories = array();
1199
                foreach ( explode( ',', $field_value ) as $cat_string ) {
1200
                    $categories[] = GFCommon::format_post_category( $cat_string, true );
1201
                }
1202
                $field_value = 'multiselect' === $field->get_input_type() ? $categories : implode( '', $categories );
1203
            }
1204
1205
        }
1206
1207
        // if value is empty get the default value if defined
1208 2
        $field_value = $field->get_value_default_if_empty( $field_value );
1209
1210
	    /**
1211
	     * @filter `gravityview/edit_entry/field_value` Change the value of an Edit Entry field, if needed
1212
	     * @since 1.11
1213
	     * @since 1.20 Added third param
1214
	     * @param mixed $field_value field value used to populate the input
1215
	     * @param object $field Gravity Forms field object ( Class GF_Field )
1216
	     * @param GravityView_Edit_Entry_Render $this Current object
1217
	     */
1218 2
	    $field_value = apply_filters( 'gravityview/edit_entry/field_value', $field_value, $field, $this );
1219
1220
	    /**
1221
	     * @filter `gravityview/edit_entry/field_value_{field_type}` Change the value of an Edit Entry field for a specific field type
1222
	     * @since 1.17
1223
	     * @since 1.20 Added third param
1224
	     * @param mixed $field_value field value used to populate the input
1225
	     * @param GF_Field $field Gravity Forms field object
1226
	     * @param GravityView_Edit_Entry_Render $this Current object
1227
	     */
1228 2
	    $field_value = apply_filters( 'gravityview/edit_entry/field_value_' . $field->type , $field_value, $field, $this );
1229
1230 2
        return $field_value;
1231
    }
1232
1233
1234
    // ---- Entry validation
1235
1236
    /**
1237
     * Add field keys that Gravity Forms expects.
1238
     *
1239
     * @see GFFormDisplay::validate()
1240
     * @param  array $form GF Form
1241
     * @return array       Modified GF Form
1242
     */
1243 2
    public function gform_pre_validation( $form ) {
1244
1245 2
        if( ! $this->verify_nonce() ) {
1246
            return $form;
1247
        }
1248
1249
        // Fix PHP warning regarding undefined index.
1250 2
        foreach ( $form['fields'] as &$field) {
0 ignored issues
show
introduced by
No space before closing parenthesis is prohibited
Loading history...
1251
1252
            // This is because we're doing admin form pretending to be front-end, so Gravity Forms
1253
            // expects certain field array items to be set.
1254 2
            foreach ( array( 'noDuplicates', 'adminOnly', 'inputType', 'isRequired', 'enablePrice', 'inputs', 'allowedExtensions' ) as $key ) {
1255 2
	            $field->{$key} = isset( $field->{$key} ) ? $field->{$key} : NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1256
            }
1257
1258 2
            switch( RGFormsModel::get_input_type( $field ) ) {
1259
1260
                /**
1261
                 * this whole fileupload hack is because in the admin, Gravity Forms simply doesn't update any fileupload field if it's empty, but it DOES in the frontend.
1262
                 *
1263
                 * What we have to do is set the value so that it doesn't get overwritten as empty on save and appears immediately in the Edit Entry screen again.
1264
                 *
1265
                 * @hack
1266
                 */
1267 2
                case 'fileupload':
1268
1269
                    // Set the previous value
1270 1
                    $entry = $this->get_entry();
1271
1272 1
                    $input_name = 'input_'.$field->id;
1273 1
                    $form_id = $form['id'];
1274
1275 1
                    $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1276
1277
                    // Use the previous entry value as the default.
1278 1
                    if( isset( $entry[ $field->id ] ) ) {
1279 1
                        $value = $entry[ $field->id ];
1280
                    }
1281
1282
                    // If this is a single upload file
1283 1
                    if( !empty( $_FILES[ $input_name ] ) && !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1284 1
                        $file_path = GFFormsModel::get_file_upload_path( $form['id'], $_FILES[ $input_name ]['name'] );
1285 1
                        $value = $file_path['url'];
1286
1287
                    } else {
1288
1289
                        // Fix PHP warning on line 1498 of form_display.php for post_image fields
1290
                        // Fix PHP Notice:  Undefined index:  size in form_display.php on line 1511
1291 1
                        $_FILES[ $input_name ] = array('name' => '', 'size' => '' );
0 ignored issues
show
introduced by
No space after opening parenthesis of array is bad style
Loading history...
1292
1293
                    }
1294
1295 1
                    if( rgar($field, "multipleFiles") ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal multipleFiles does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1296
1297
                        // If there are fresh uploads, process and merge them.
1298
                        // Otherwise, use the passed values, which should be json-encoded array of URLs
1299 1
                        if( isset( GFFormsModel::$uploaded_files[$form_id][$input_name] ) ) {
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1300
                            $value = empty( $value ) ? '[]' : $value;
1301
                            $value = stripslashes_deep( $value );
1302 1
                            $value = GFFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'], array());
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1303
                        }
1304
1305
                    } else {
1306
1307
                        // A file already exists when editing an entry
1308
                        // We set this to solve issue when file upload fields are required.
1309 1
                        GFFormsModel::$uploaded_files[ $form_id ][ $input_name ] = $value;
1310
1311
                    }
1312
1313 1
                    $this->entry[ $input_name ] = $value;
1314 1
                    $_POST[ $input_name ] = $value;
1315
1316 1
                    break;
1317
1318 2
                case 'number':
1319
                    // Fix "undefined index" issue at line 1286 in form_display.php
1320 1
                    if( !isset( $_POST['input_'.$field->id ] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1321
                        $_POST['input_'.$field->id ] = NULL;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1322
                    }
1323 2
                    break;
1324
            }
1325
1326
        }
1327
1328 2
        return $form;
1329
    }
1330
1331
1332
    /**
1333
     * Process validation for a edit entry submission
1334
     *
1335
     * Sets the `is_valid` object var
1336
     *
1337
     * @return void
1338
     */
1339 3
    private function validate() {
1340
1341
        /**
1342
         * If using GF User Registration Add-on, remove the validation step, otherwise generates error when updating the entry
1343
         * GF User Registration Add-on version > 3.x has a different class name
1344
         * @since 1.16.2
1345
         */
1346 3
        if ( class_exists( 'GF_User_Registration' ) ) {
1347 3
            remove_filter( 'gform_validation', array( GF_User_Registration::get_instance(), 'validate' ) );
1348
        } else  if ( class_exists( 'GFUser' ) ) {
1349
            remove_filter( 'gform_validation', array( 'GFUser', 'user_registration_validation' ) );
1350
        }
1351
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1352
1353
        /**
1354
         * For some crazy reason, Gravity Forms doesn't validate Edit Entry form submissions.
1355
         * You can enter whatever you want!
1356
         * We try validating, and customize the results using `self::custom_validation()`
1357
         */
1358 3
        add_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10, 4);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1359
1360
        // Needed by the validate funtion
1361 3
        $failed_validation_page = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1362 3
        $field_values = RGForms::post( 'gform_field_values' );
1363
1364
        // Prevent entry limit from running when editing an entry, also
1365
        // prevent form scheduling from preventing editing
1366 3
        unset( $this->form['limitEntries'], $this->form['scheduleForm'] );
1367
1368
        // Hide fields depending on Edit Entry settings
1369 3
        $this->form['fields'] = $this->get_configured_edit_fields( $this->form, $this->view_id );
1370
1371 3
        $this->is_valid = GFFormDisplay::validate( $this->form, $field_values, 1, $failed_validation_page );
1372
1373 3
        remove_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10 );
1374 3
    }
1375
1376
1377
    /**
1378
     * Make validation work for Edit Entry
1379
     *
1380
     * Because we're calling the GFFormDisplay::validate() in an unusual way (as a front-end
1381
     * form pretending to be a back-end form), validate() doesn't know we _can't_ edit post
1382
     * fields. This goes through all the fields and if they're an invalid post field, we
1383
     * set them as valid. If there are still issues, we'll return false.
1384
     *
1385
     * @param  [type] $validation_results [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1386
     * @return [type]                     [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1387
     */
1388 3
    public function custom_validation( $validation_results ) {
1389
1390 3
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results: ', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1391
1392 3
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
1393
1394 3
        $gv_valid = true;
1395
1396 3
        foreach ( $validation_results['form']['fields'] as $key => &$field ) {
1397
1398 3
            $value = RGFormsModel::get_field_value( $field );
1399 3
            $field_type = RGFormsModel::get_input_type( $field );
1400
1401
            // Validate always
1402
            switch ( $field_type ) {
1403
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1404
1405 3
                case 'fileupload' :
1406 3
                case 'post_image':
1407
1408
                    // in case nothing is uploaded but there are already files saved
1409 1
                    if( !empty( $field->failed_validation ) && !empty( $field->isRequired ) && !empty( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1410
                        $field->failed_validation = false;
1411
                        unset( $field->validation_message );
1412
                    }
1413
1414
                    // validate if multi file upload reached max number of files [maxFiles] => 2
1415 1
                    if( rgobj( $field, 'maxFiles') && rgobj( $field, 'multipleFiles') ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1416
1417
                        $input_name = 'input_' . $field->id;
1418
                        //uploaded
1419
                        $file_names = isset( GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] ) ? GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] : array();
1420
1421
                        //existent
1422
                        $entry = $this->get_entry();
1423
                        $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1424
                        if( isset( $entry[ $field->id ] ) ) {
1425
                            $value = json_decode( $entry[ $field->id ], true );
1426
                        }
1427
1428
                        // count uploaded files and existent entry files
1429
                        $count_files = count( $file_names ) + count( $value );
1430
1431
                        if( $count_files > $field->maxFiles ) {
1432
                            $field->validation_message = __( 'Maximum number of files reached', 'gravityview' );
1433
                            $field->failed_validation = 1;
1434
                            $gv_valid = false;
1435
1436
                            // in case of error make sure the newest upload files are removed from the upload input
1437
                            GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ] = null;
1438
                        }
1439
1440
                    }
1441
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1442
1443 1
                    break;
1444
1445
            }
1446
1447
            // This field has failed validation.
1448 3
            if( !empty( $field->failed_validation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1449
1450 1
                do_action( 'gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field is invalid.', array( 'field' => $field, 'value' => $value ) );
1451
1452
                switch ( $field_type ) {
1453
1454
                    // Captchas don't need to be re-entered.
1455 1
                    case 'captcha':
1456
1457
                        // Post Image fields aren't editable, so we un-fail them.
1458 1
                    case 'post_image':
1459
                        $field->failed_validation = false;
1460
                        unset( $field->validation_message );
1461
                        break;
1462
1463
                }
1464
1465
                // You can't continue inside a switch, so we do it after.
1466 1
                if( empty( $field->failed_validation ) ) {
1467
                    continue;
1468
                }
1469
1470
                // checks if the No Duplicates option is not validating entry against itself, since
1471
                // we're editing a stored entry, it would also assume it's a duplicate.
1472 1
                if( !empty( $field->noDuplicates ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1473
1474
                    $entry = $this->get_entry();
1475
1476
                    // If the value of the entry is the same as the stored value
1477
                    // Then we can assume it's not a duplicate, it's the same.
1478
                    if( !empty( $entry ) && $value == $entry[ $field->id ] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1479
                        //if value submitted was not changed, then don't validate
1480
                        $field->failed_validation = false;
1481
1482
                        unset( $field->validation_message );
1483
1484
                        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field not a duplicate; it is the same entry.', $entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1485
1486
                        continue;
1487
                    }
1488
                }
1489
1490
                // if here then probably we are facing the validation 'At least one field must be filled out'
1491 1
                if( GFFormDisplay::is_empty( $field, $this->form_id  ) && empty( $field->isRequired ) ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 2 found
Loading history...
1492
                    unset( $field->validation_message );
1493
	                $field->validation_message = false;
1494
                    continue;
1495
                }
1496
1497 3
                $gv_valid = false;
1498
1499
            }
1500
1501
        }
1502
1503 3
        $validation_results['is_valid'] = $gv_valid;
1504
1505 3
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results.', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1506
1507
        // We'll need this result when rendering the form ( on GFFormDisplay::get_form )
1508 3
        $this->form_after_validation = $validation_results['form'];
1509
1510 3
        return $validation_results;
1511
    }
1512
1513
1514
    /**
1515
     * TODO: This seems to be hacky... we should remove it. Entry is set when updating the form using setup_vars()!
1516
     * Get the current entry and set it if it's not yet set.
1517
     * @return array Gravity Forms entry array
1518
     */
1519 1
    public function get_entry() {
1520
1521 1
        if( empty( $this->entry ) ) {
1522
            // Get the database value of the entry that's being edited
1523 1
            $this->entry = gravityview_get_entry( GravityView_frontend::is_single_entry() );
1524
        }
1525
1526 1
        return $this->entry;
1527
    }
1528
1529
1530
1531
    // --- Filters
1532
1533
    /**
1534
     * Get the Edit Entry fields as configured in the View
1535
     *
1536
     * @since 1.8
1537
     *
1538
     * @param int $view_id
1539
     *
1540
     * @return array Array of fields that are configured in the Edit tab in the Admin
1541
     */
1542 3
    private function get_configured_edit_fields( $form, $view_id ) {
1543
1544
        // Get all fields for form
1545 3
        $properties = GravityView_View_Data::getInstance()->get_fields( $view_id );
1546
1547
        // If edit tab not yet configured, show all fields
1548 3
        $edit_fields = !empty( $properties['edit_edit-fields'] ) ? $properties['edit_edit-fields'] : NULL;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1549
1550
        // Hide fields depending on admin settings
1551 3
        $fields = $this->filter_fields( $form['fields'], $edit_fields );
1552
1553
	    // If Edit Entry fields are configured, remove adminOnly field settings. Otherwise, don't.
1554 3
	    $fields = $this->filter_admin_only_fields( $fields, $edit_fields, $form, $view_id );
1555
1556
        /**
1557
         * @filter `gravityview/edit_entry/form_fields` Modify the fields displayed in Edit Entry form
1558
         * @since 1.17
1559
         * @param GF_Field[] $fields Gravity Forms form fields
1560
         * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1561
         * @param array $form GF Form array (`fields` key modified to have only fields configured to show in Edit Entry)
1562
         * @param int $view_id View ID
1563
         */
1564 3
        $fields = apply_filters( 'gravityview/edit_entry/form_fields', $fields, $edit_fields, $form, $view_id );
1565
1566 3
        return $fields;
1567
    }
1568
1569
1570
    /**
1571
     * Filter area fields based on specified conditions
1572
     *  - This filter removes the fields that have calculation configured
1573
     *
1574
     * @uses GravityView_Edit_Entry::user_can_edit_field() Check caps
1575
     * @access private
1576
     * @param GF_Field[] $fields
1577
     * @param array $configured_fields
1578
     * @since  1.5
1579
     * @return array $fields
1580
     */
1581 2
    private function filter_fields( $fields, $configured_fields ) {
1582
1583 2
        if( empty( $fields ) || !is_array( $fields ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1584
            return $fields;
1585
        }
1586
1587 2
        $edit_fields = array();
1588
1589 2
        $field_type_blacklist = $this->loader->get_field_blacklist( $this->entry );
1590
1591
        // First, remove blacklist or calculation fields
1592 2
        foreach ( $fields as $key => $field ) {
1593
1594
            // Remove the fields that have calculation properties and keep them to be used later
1595
            // @since 1.16.2
1596 2
            if( $field->has_calculation() ) {
1597
                $this->fields_with_calculation[] = $field;
1598
                // don't remove the calculation fields on form render.
1599
            }
1600
1601 2
            if( in_array( $field->type, $field_type_blacklist ) ) {
1602 2
                unset( $fields[ $key ] );
1603
            }
1604
        }
1605
1606
        // The Edit tab has not been configured, so we return all fields by default.
1607 2
        if( empty( $configured_fields ) ) {
1608 2
            return $fields;
1609
        }
1610
1611
        // The edit tab has been configured, so we loop through to configured settings
1612
        foreach ( $configured_fields as $configured_field ) {
1613
1614
	        /** @var GF_Field $field */
1615
	        foreach ( $fields as $field ) {
1616
1617
                if( intval( $configured_field['id'] ) === intval( $field->id ) && $this->user_can_edit_field( $configured_field, false ) ) {
1618
                    $edit_fields[] = $this->merge_field_properties( $field, $configured_field );
1619
                    break;
1620
                }
1621
1622
            }
1623
1624
        }
1625
1626
        return $edit_fields;
1627
1628
    }
1629
1630
    /**
1631
     * Override GF Form field properties with the ones defined on the View
1632
     * @param  GF_Field $field GF Form field object
1633
     * @param  array $field_setting  GV field options
1634
     * @since  1.5
1635
     * @return array|GF_Field
1636
     */
1637
    private function merge_field_properties( $field, $field_setting ) {
1638
1639
        $return_field = $field;
1640
1641
        if( empty( $field_setting['show_label'] ) ) {
1642
            $return_field->label = '';
1643
        } elseif ( !empty( $field_setting['custom_label'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1644
            $return_field->label = $field_setting['custom_label'];
1645
        }
1646
1647
        if( !empty( $field_setting['custom_class'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1648
            $return_field->cssClass .= ' '. gravityview_sanitize_html_class( $field_setting['custom_class'] );
1649
        }
1650
1651
        /**
1652
         * Normalize page numbers - avoid conflicts with page validation
1653
         * @since 1.6
1654
         */
1655
        $return_field->pageNumber = 1;
1656
1657
        return $return_field;
1658
1659
    }
1660
1661
    /**
1662
     * Remove fields that shouldn't be visible based on the Gravity Forms adminOnly field property
1663
     *
1664
     * @since 1.9.1
1665
     *
1666
     * @param array|GF_Field[] $fields Gravity Forms form fields
1667
     * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1668
     * @param array $form GF Form array
1669
     * @param int $view_id View ID
1670
     *
1671
     * @return array Possibly modified form array
1672
     */
1673 2
    private function filter_admin_only_fields( $fields = array(), $edit_fields = null, $form = array(), $view_id = 0 ) {
1674
1675
	    /**
1676
         * @filter `gravityview/edit_entry/use_gf_admin_only_setting` When Edit tab isn't configured, should the Gravity Forms "Admin Only" field settings be used to control field display to non-admins? Default: true
1677
	     * If the Edit Entry tab is not configured, adminOnly fields will not be shown to non-administrators.
1678
	     * If the Edit Entry tab *is* configured, adminOnly fields will be shown to non-administrators, using the configured GV permissions
1679
	     * @since 1.9.1
1680
	     * @param boolean $use_gf_adminonly_setting True: Hide field if set to Admin Only in GF and the user is not an admin. False: show field based on GV permissions, ignoring GF permissions.
1681
	     * @param array $form GF Form array
1682
	     * @param int $view_id View ID
1683
	     */
1684 2
	    $use_gf_adminonly_setting = apply_filters( 'gravityview/edit_entry/use_gf_admin_only_setting', empty( $edit_fields ), $form, $view_id );
1685
1686 2
	    if( $use_gf_adminonly_setting && false === GVCommon::has_cap( 'gravityforms_edit_entries', $this->entry['id'] ) ) {
1687
            foreach( $fields as $k => $field ) {
1688
                if( $field->adminOnly ) {
1689
                    unset( $fields[ $k ] );
1690
                }
1691
            }
1692
            return $fields;
1693
        }
1694
1695 2
	    foreach( $fields as &$field ) {
1696 2
		    $field->adminOnly = false;
1697
        }
1698
1699 2
        return $fields;
1700
    }
1701
1702
    // --- Conditional Logic
1703
1704
    /**
1705
     * Conditional logic isn't designed to work with forms that already have content. When switching input values,
1706
     * the dependent fields will be blank.
1707
     *
1708
     * Note: This is because GF populates a JavaScript variable with the input values. This is tough to filter at the input level;
1709
     * via the `gform_field_value` filter; it requires lots of legwork. Doing it at the form level is easier.
1710
     *
1711
     * @since 1.17.4
1712
     *
1713
     * @param array $form Gravity Forms array object
1714
     *
1715
     * @return array $form, modified to fix conditional
1716
     */
1717 2
    function prefill_conditional_logic( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1718
1719 2
        if( ! GFFormDisplay::has_conditional_logic( $form ) ) {
1720 2
            return $form;
1721
        }
1722
1723
        // Have Conditional Logic pre-fill fields as if the data were default values
1724
        /** @var GF_Field $field */
1725
        foreach ( $form['fields'] as &$field ) {
1726
1727
            if( 'checkbox' === $field->type ) {
1728
                foreach ( $field->get_entry_inputs() as $key => $input ) {
1729
                    $input_id = $input['id'];
1730
                    $choice = $field->choices[ $key ];
1731
                    $value = rgar( $this->entry, $input_id );
1732
                    $match = RGFormsModel::choice_value_match( $field, $choice, $value );
1733
                    if( $match ) {
1734
                        $field->choices[ $key ]['isSelected'] = true;
1735
                    }
1736
                }
1737
            } else {
1738
1739
                // We need to run through each field to set the default values
1740
                foreach ( $this->entry as $field_id => $field_value ) {
1741
1742
                    if( floatval( $field_id ) === floatval( $field->id ) ) {
1743
1744
                        if( 'list' === $field->type ) {
1745
                            $list_rows = maybe_unserialize( $field_value );
1746
1747
                            $list_field_value = array();
1748
                            foreach ( (array) $list_rows as $row ) {
1749
                                foreach ( (array) $row as $column ) {
1750
                                    $list_field_value[] = $column;
1751
                                }
1752
                            }
1753
1754
                            $field->defaultValue = serialize( $list_field_value );
1755
                        } else {
1756
                            $field->defaultValue = $field_value;
1757
                        }
1758
                    }
1759
                }
1760
            }
1761
        }
1762
1763
        return $form;
1764
    }
1765
1766
    /**
1767
     * Remove the conditional logic rules from the form button and the form fields, if needed.
1768
     *
1769
     * @todo Merge with caller method
1770
     * @since 1.9
1771
     *
1772
     * @param array $form Gravity Forms form
1773
     * @return array Modified form, if not using Conditional Logic
1774
     */
1775 2
    private function filter_conditional_logic( $form ) {
1776
1777
        /**
1778
         * @filter `gravityview/edit_entry/conditional_logic` Should the Edit Entry form use Gravity Forms conditional logic showing/hiding of fields?
1779
         * @since 1.9
1780
         * @param bool $use_conditional_logic True: Gravity Forms will show/hide fields just like in the original form; False: conditional logic will be disabled and fields will be shown based on configuration. Default: true
1781
         * @param array $form Gravity Forms form
1782
         */
1783 2
        $use_conditional_logic = apply_filters( 'gravityview/edit_entry/conditional_logic', true, $form );
1784
1785 2
        if( $use_conditional_logic ) {
1786 2
            return $form;
1787
        }
1788
1789
        foreach( $form['fields'] as &$field ) {
1790
            /* @var GF_Field $field */
1791
            $field->conditionalLogic = null;
1792
        }
1793
1794
        unset( $form['button']['conditionalLogic'] );
1795
1796
        return $form;
1797
1798
    }
1799
1800
    /**
1801
     * Disable the Gravity Forms conditional logic script and features on the Edit Entry screen
1802
     *
1803
     * @since 1.9
1804
     *
1805
     * @param $has_conditional_logic
1806
     * @param $form
1807
     * @return mixed
1808
     */
1809 2
    public function manage_conditional_logic( $has_conditional_logic, $form ) {
1810
1811 2
        if( ! $this->is_edit_entry() ) {
1812
            return $has_conditional_logic;
1813
        }
1814
1815
	    /** @see GravityView_Edit_Entry_Render::filter_conditional_logic for filter documentation */
1816 2
        return apply_filters( 'gravityview/edit_entry/conditional_logic', $has_conditional_logic, $form );
1817
    }
1818
1819
1820
    // --- User checks and nonces
1821
1822
    /**
1823
     * Check if the user can edit the entry
1824
     *
1825
     * - Is the nonce valid?
1826
     * - Does the user have the right caps for the entry
1827
     * - Is the entry in the trash?
1828
     *
1829
     * @todo Move to GVCommon
1830
     *
1831
     * @param  boolean $echo Show error messages in the form?
1832
     * @return boolean        True: can edit form. False: nope.
1833
     */
1834 3
    private function user_can_edit_entry( $echo = false ) {
1835
1836 3
        $error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1837
1838
        /**
1839
         *  1. Permalinks are turned off
1840
         *  2. There are two entries embedded using oEmbed
1841
         *  3. One of the entries has just been saved
1842
         */
1843 3
        if( !empty( $_POST['lid'] ) && !empty( $_GET['entry'] ) && ( $_POST['lid'] !== $_GET['entry'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1844
1845
            $error = true;
1846
1847
        }
1848
1849 3
        if( !empty( $_GET['entry'] ) && (string)$this->entry['id'] !== $_GET['entry'] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1850
1851
            $error = true;
1852
1853 3
        } elseif( ! $this->verify_nonce() ) {
1854
1855
            /**
1856
             * If the Entry is embedded, there may be two entries on the same page.
1857
             * If that's the case, and one is being edited, the other should fail gracefully and not display an error.
1858
             */
1859
            if( GravityView_oEmbed::getInstance()->get_entry_id() ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression \GravityView_oEmbed::get...tance()->get_entry_id() of type integer|null is loosely compared to true; this is ambiguous if the integer can be zero. You might want to explicitly use !== null instead.

In PHP, under loose comparison (like ==, or !=, or switch conditions), values of different types might be equal.

For integer values, zero is a special case, in particular the following results might be unexpected:

0   == false // true
0   == null  // true
123 == false // false
123 == null  // false

// It is often better to use strict comparison
0 === false // false
0 === null  // false
Loading history...
1860
                $error = true;
1861
            } else {
1862
                $error = __( 'The link to edit this entry is not valid; it may have expired.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1863
            }
1864
1865
        }
1866
1867 3
        if( ! GravityView_Edit_Entry::check_user_cap_edit_entry( $this->entry ) ) {
1868 1
            $error = __( 'You do not have permission to edit this entry.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1869
        }
1870
1871 3
        if( $this->entry['status'] === 'trash' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
1872
            $error = __('You cannot edit the entry; it is in the trash.', 'gravityview' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1873
        }
1874
1875
        // No errors; everything's fine here!
1876 3
        if( empty( $error ) ) {
1877 3
            return true;
1878
        }
1879
1880 1
        if( $echo && $error !== true ) {
0 ignored issues
show
introduced by
Found "!== true". Use Yoda Condition checks, you must
Loading history...
1881
1882 1
	        $error = esc_html( $error );
1883
1884
	        /**
1885
	         * @since 1.9
1886
	         */
1887 1
	        if ( ! empty( $this->entry ) ) {
1888 1
		        $error .= ' ' . gravityview_get_link( '#', _x('Go back.', 'Link shown when invalid Edit Entry link is clicked', 'gravityview' ), array( 'onclick' => "window.history.go(-1); return false;" ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal window.history.go(-1); return false; does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1889
	        }
1890
1891 1
            echo GVCommon::generate_notice( wpautop( $error ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1892
        }
1893
1894 1
        do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_entry]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1895
1896 1
        return false;
1897
    }
1898
1899
1900
    /**
1901
     * Check whether a field is editable by the current user, and optionally display an error message
1902
     * @uses  GravityView_Edit_Entry->check_user_cap_edit_field() Check user capabilities
1903
     * @param  array  $field Field or field settings array
1904
     * @param  boolean $echo  Whether to show error message telling user they aren't allowed
1905
     * @return boolean         True: user can edit the current field; False: nope, they can't.
1906
     */
1907
    private function user_can_edit_field( $field, $echo = false ) {
1908
1909
        $error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1910
1911
        if( ! $this->check_user_cap_edit_field( $field ) ) {
1912
            $error = __( 'You do not have permission to edit this field.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1913
        }
1914
1915
        // No errors; everything's fine here!
1916
        if( empty( $error ) ) {
1917
            return true;
1918
        }
1919
1920
        if( $echo ) {
1921
            echo GVCommon::generate_notice( wpautop( esc_html( $error ) ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1922
        }
1923
1924
        do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_field]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1925
1926
        return false;
1927
1928
    }
1929
1930
1931
    /**
1932
     * checks if user has permissions to edit a specific field
1933
     *
1934
     * Needs to be used combined with GravityView_Edit_Entry::user_can_edit_field for maximum security!!
1935
     *
1936
     * @param  [type] $field [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1937
     * @return bool
1938
     */
1939
    private function check_user_cap_edit_field( $field ) {
1940
1941
        // If they can edit any entries (as defined in Gravity Forms), we're good.
1942
        if( GVCommon::has_cap( array( 'gravityforms_edit_entries', 'gravityview_edit_others_entries' ) ) ) {
1943
            return true;
1944
        }
1945
1946
        $field_cap = isset( $field['allow_edit_cap'] ) ? $field['allow_edit_cap'] : false;
1947
1948
        // If the field has custom editing capaibilities set, check those
1949
        if( $field_cap ) {
1950
            return GVCommon::has_cap( $field['allow_edit_cap'] );
1951
        }
1952
1953
        return false;
1954
    }
1955
1956
1957
    /**
1958
     * Is the current nonce valid for editing the entry?
1959
     * @return boolean
1960
     */
1961 2
    public function verify_nonce() {
1962
1963
        // Verify form submitted for editing single
1964 2
        if( $this->is_edit_entry_submission() ) {
1965
            $valid = wp_verify_nonce( $_POST[ self::$nonce_field ], self::$nonce_field );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
1966
        }
1967
1968
        // Verify
1969 2
        else if( ! $this->is_edit_entry() ) {
1970
            $valid = false;
1971
        }
1972
1973
        else {
1974 2
            $valid = wp_verify_nonce( $_GET['edit'], self::$nonce_key );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
1975
        }
1976
1977
        /**
1978
         * @filter `gravityview/edit_entry/verify_nonce` Override Edit Entry nonce validation. Return true to declare nonce valid.
1979
         * @since 1.13
1980
         * @param int|boolean $valid False if invalid; 1 or 2 when nonce was generated
1981
         * @param string $nonce_field Key used when validating submissions. Default: is_gv_edit_entry
1982
         */
1983 2
        $valid = apply_filters( 'gravityview/edit_entry/verify_nonce', $valid, self::$nonce_field );
1984
1985 2
        return $valid;
1986
    }
1987
1988
1989
1990
} //end class