Completed
Push — develop ( 9fabe4...3699ed )
by Zack
18:16
created

unset_hidden_field_values()   C

Complexity

Conditions 7
Paths 9

Size

Total Lines 45
Code Lines 19

Duplication

Lines 0
Ratio 0 %

Code Coverage

Tests 12
CRAP Score 9.4499

Importance

Changes 0
Metric Value
cc 7
eloc 19
nc 9
nop 0
dl 0
loc 45
ccs 12
cts 19
cp 0.6316
crap 9.4499
rs 6.7272
c 0
b 0
f 0
1
<?php
0 ignored issues
show
Coding Style Compatibility introduced by
For compatibility and reusability of your code, PSR1 recommends that a file should introduce either new symbols (like classes, functions, etc.) or have side-effects (like outputting something, or including other files), but not both at the same time. The first symbol is defined on line 16 and the first side effect is on line 13.

The PSR-1: Basic Coding Standard recommends that a file should either introduce new symbols, that is classes, functions, constants or similar, or have side effects. Side effects are anything that executes logic, like for example printing output, changing ini settings or writing to a file.

The idea behind this recommendation is that merely auto-loading a class should not change the state of an application. It also promotes a cleaner style of programming and makes your code less prone to errors, because the logic is not spread out all over the place.

To learn more about the PSR-1, please see the PHP-FIG site on the PSR-1.

Loading history...
2
/**
3
 * GravityView Edit Entry - render frontend
4
 *
5
 * @package   GravityView
6
 * @license   GPL2+
7
 * @author	Katz Web Services, Inc.
8
 * @link	  http://gravityview.co
9
 * @copyright Copyright 2014, Katz Web Services, Inc.
10
 */
11
12
if ( ! defined( 'WPINC' ) ) {
13
	die;
14
}
15
16
class GravityView_Edit_Entry_Render {
17
18
	/**
19
	 * @var GravityView_Edit_Entry
20
	 */
21
	protected $loader;
22
23
	/**
24
	 * @var string String used to generate unique nonce for the entry/form/view combination. Allows access to edit page.
25
	 */
26
	static $nonce_key;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $nonce_key.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
27
28
	/**
29
	 * @since 1.9
30
	 * @var string String used for check valid edit entry form submission. Allows saving edit form values.
31
	 */
32
	private static $nonce_field = 'is_gv_edit_entry';
33
34
	/**
35
	 * @since 1.9
36
	 * @var bool Whether to allow save and continue functionality
37
	 */
38
	private static $supports_save_and_continue = false;
39
40
	/**
41
	 * Gravity Forms entry array
42
	 *
43
	 * @var array
44
	 */
45
	public $entry;
46
47
	/**
48
	 * Gravity Forms entry array (it won't get changed during this class lifecycle)
49
	 * @since 1.17.2
50
	 * @var array
51
	 */
52
	private static $original_entry = array();
53
54
	/**
55
	 * Gravity Forms form array (GravityView modifies the content through this class lifecycle)
56
	 *
57
	 * @var array
58
	 */
59
	public $form;
60
61
	/**
62
	 * Gravity Forms form array (it won't get changed during this class lifecycle)
63
	 * @since 1.16.2.1
64
	 * @var array
65
	 */
66
	private static $original_form;
67
68
	/**
69
	 * Gravity Forms form array after the form validation process
70
	 * @since 1.13
71
	 * @var array
72
	 */
73
	public $form_after_validation = null;
74
75
	/**
76
	 * Hold an array of GF field objects that have calculation rules
77
	 * @var array
78
	 */
79
	public $fields_with_calculation = array();
80
81
	/**
82
	 * Gravity Forms form id
83
	 *
84
	 * @var int
85
	 */
86
	public $form_id;
87
88
	/**
89
	 * ID of the current view
90
	 *
91
	 * @var int
92
	 */
93
	public $view_id;
94
95
	/**
96
	 * Updated entry is valid (GF Validation object)
97
	 *
98
	 * @var array
99
	 */
100
	public $is_valid = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
101
102 3
	function __construct( GravityView_Edit_Entry $loader ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
103 3
		$this->loader = $loader;
104 3
	}
105
106 3
	function load() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
107
108
		/** @define "GRAVITYVIEW_DIR" "../../../" */
109 3
		include_once( GRAVITYVIEW_DIR .'includes/class-admin-approve-entries.php' );
110
111
		// Don't display an embedded form when editing an entry
112 3
		add_action( 'wp_head', array( $this, 'prevent_render_form' ) );
113 3
		add_action( 'wp_footer', array( $this, 'prevent_render_form' ) );
114
115
		// Stop Gravity Forms processing what is ours!
116 3
		add_filter( 'wp', array( $this, 'prevent_maybe_process_form'), 8 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
117
118 3
		add_filter( 'gravityview_is_edit_entry', array( $this, 'is_edit_entry') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
119
120 3
		add_action( 'gravityview_edit_entry', array( $this, 'init' ) );
121
122
		// Disable conditional logic if needed (since 1.9)
123 3
		add_filter( 'gform_has_conditional_logic', array( $this, 'manage_conditional_logic' ), 10, 2 );
124
125
		// Make sure GF doesn't validate max files (since 1.9)
126 3
		add_filter( 'gform_plupload_settings', array( $this, 'modify_fileupload_settings' ), 10, 3 );
127
128
		// Add fields expected by GFFormDisplay::validate()
129 3
		add_filter( 'gform_pre_validation', array( $this, 'gform_pre_validation') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
130
131
		// Fix multiselect value for GF 2.2
132 3
		add_filter( 'gravityview/edit_entry/field_value_multiselect', array( $this, 'fix_multiselect_value_serialization' ), 10, 3 );
133 3
	}
134
135
	/**
136
	 * Don't show any forms embedded on a page when GravityView is in Edit Entry mode
137
	 *
138
	 * Adds a `__return_empty_string` filter on the Gravity Forms shortcode on the `wp_head` action
139
	 * And then removes it on the `wp_footer` action
140
	 *
141
	 * @since 1.16.1
142
	 *
143
	 * @return void
144
	 */
145 1
	public function prevent_render_form() {
146 1
		if( $this->is_edit_entry() ) {
147 1
			if( 'wp_head' === current_filter() ) {
148 1
				add_filter( 'gform_shortcode_form', '__return_empty_string' );
149
			} else {
150 1
				remove_filter( 'gform_shortcode_form', '__return_empty_string' );
151
			}
152
		}
153 1
	}
154
155
	/**
156
	 * Because we're mimicking being a front-end Gravity Forms form while using a Gravity Forms
157
	 * backend form, we need to prevent them from saving twice.
158
	 * @return void
159
	 */
160
	public function prevent_maybe_process_form() {
161
162
		if( ! empty( $_POST ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
163
			do_action( 'gravityview_log_debug', 'GravityView_Edit_Entry[prevent_maybe_process_form] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
164
		}
165
166
		if( $this->is_edit_entry_submission() ) {
167
			remove_action( 'wp',  array( 'RGForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
168
			remove_action( 'wp',  array( 'GFForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
169
		}
170
	}
171
172
	/**
173
	 * Is the current page an Edit Entry page?
174
	 * @return boolean
175
	 */
176 4
	public function is_edit_entry() {
177
178 4
		$is_edit_entry = GravityView_frontend::is_single_entry() && ! empty( $_GET['edit'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
179
180 4
		return ( $is_edit_entry || $this->is_edit_entry_submission() );
181
	}
182
183
	/**
184
	 * Is the current page an Edit Entry page?
185
	 * @since 1.9
186
	 * @return boolean
187
	 */
188 3
	public function is_edit_entry_submission() {
189 3
		return !empty( $_POST[ self::$nonce_field ] );
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
190
	}
191
192
	/**
193
	 * When Edit entry view is requested setup the vars
194
	 */
195 3
	private function setup_vars() {
196 3
		$gravityview_view = GravityView_View::getInstance();
197
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
198
199 3
		$entries = $gravityview_view->getEntries();
200 3
		self::$original_entry = $entries[0];
201 3
		$this->entry = $entries[0];
202
203 3
		self::$original_form = $gravityview_view->getForm();
204 3
		$this->form = $gravityview_view->getForm();
205 3
		$this->form_id = $gravityview_view->getFormId();
206 3
		$this->view_id = $gravityview_view->getViewId();
207
208 3
		self::$nonce_key = GravityView_Edit_Entry::get_nonce_key( $this->view_id, $this->form_id, $this->entry['id'] );
209 3
	}
210
211
212
	/**
213
	 * Load required files and trigger edit flow
214
	 *
215
	 * Run when the is_edit_entry returns true.
216
	 *
217
	 * @param GravityView_View_Data $gv_data GravityView Data object
218
	 * @return void
219
	 */
220 4
	public function init( $gv_data ) {
221
222 4
		require_once( GFCommon::get_base_path() . '/form_display.php' );
223 4
		require_once( GFCommon::get_base_path() . '/entry_detail.php' );
224
225 4
		$this->setup_vars();
226
227
		// Multiple Views embedded, don't proceed if nonce fails
228 4
		$multiple_views = defined( 'GRAVITYVIEW_FUTURE_CORE_LOADED' ) ? gravityview()->views->count() > 1 : $gv_data->has_multiple_views();
0 ignored issues
show
Documentation introduced by
The property views does not exist on object<GV\Core>. Since you implemented __get, maybe consider adding a @property annotation.

Since your code implements the magic getter _get, this function will be called for any read access on an undefined variable. You can add the @property annotation to your class or interface to document the existence of this variable.

<?php

/**
 * @property int $x
 * @property int $y
 * @property string $text
 */
class MyLabel
{
    private $properties;

    private $allowedProperties = array('x', 'y', 'text');

    public function __get($name)
    {
        if (isset($properties[$name]) && in_array($name, $this->allowedProperties)) {
            return $properties[$name];
        } else {
            return null;
        }
    }

    public function __set($name, $value)
    {
        if (in_array($name, $this->allowedProperties)) {
            $properties[$name] = $value;
        } else {
            throw new \LogicException("Property $name is not defined.");
        }
    }

}

If the property has read access only, you can use the @property-read annotation instead.

Of course, you may also just have mistyped another name, in which case you should fix the error.

See also the PhpDoc documentation for @property.

Loading history...
Deprecated Code introduced by
The method GravityView_View_Data::has_multiple_views() has been deprecated.

This method has been deprecated.

Loading history...
229 4
		if( $multiple_views && ! wp_verify_nonce( $_GET['edit'], self::$nonce_key ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
230
			do_action('gravityview_log_error', __METHOD__ . ': Nonce validation failed for the Edit Entry request; returning' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
231
			return;
232
		}
233
234
		// Sorry, you're not allowed here.
235 4
		if( false === $this->user_can_edit_entry( true ) ) {
236 1
			do_action('gravityview_log_error', __METHOD__ . ': User is not allowed to edit this entry; returning', $this->entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
237 1
			return;
238
		}
239
240 4
		$this->print_scripts();
241
242 4
		$this->process_save();
243
244 4
		$this->edit_entry_form();
245
246 4
	}
247
248
249
	/**
250
	 * Force Gravity Forms to output scripts as if it were in the admin
251
	 * @return void
252
	 */
253 3
	private function print_scripts() {
254 3
		$gravityview_view = GravityView_View::getInstance();
255
256 3
		wp_register_script( 'gform_gravityforms', GFCommon::get_base_url().'/js/gravityforms.js', array( 'jquery', 'gform_json', 'gform_placeholder', 'sack', 'plupload-all', 'gravityview-fe-view' ) );
257
258 3
		GFFormDisplay::enqueue_form_scripts($gravityview_view->getForm(), false);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
259
260
		// Sack is required for images
261 3
		wp_print_scripts( array( 'sack', 'gform_gravityforms' ) );
262 3
	}
263
264
265
	/**
266
	 * Process edit entry form save
267
	 */
268 4
	private function process_save() {
269
270 4
		if( empty( $_POST ) || ! isset( $_POST['lid'] ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
271 4
			return;
272
		}
273
274
		// Make sure the entry, view, and form IDs are all correct
275 4
		$valid = $this->verify_nonce();
276
277 4
		if( !$valid ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
278
			do_action('gravityview_log_error', __METHOD__ . ' Nonce validation failed.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
279
			return;
280
		}
281
282 4
		if( $this->entry['id'] !== $_POST['lid'] ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
283
			do_action('gravityview_log_error', __METHOD__ . ' Entry ID did not match posted entry ID.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
284
			return;
285
		}
286
287 4
		do_action('gravityview_log_debug', __METHOD__ . ': $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
288
289 4
		$this->process_save_process_files( $this->form_id );
290
291 4
		$this->validate();
292
293 4
		if( $this->is_valid ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using ! empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
294
295 4
			do_action('gravityview_log_debug', __METHOD__ . ': Submission is valid.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
296
297
			/**
298
			 * @hack This step is needed to unset the adminOnly from form fields, to add the calculation fields
299
			 */
300 4
			$form = $this->form_prepare_for_save();
301
302
			/**
303
			 * @hack to avoid the capability validation of the method save_lead for GF 1.9+
304
			 */
305 4
			unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
306
307 4
			$date_created = $this->entry['date_created'];
308
309
			/**
310
			 * @hack to force Gravity Forms to use $read_value_from_post in GFFormsModel::save_lead()
311
			 * @since 1.17.2
312
			 */
313 4
			unset( $this->entry['date_created'] );
314
315 4
			GFFormsModel::save_lead( $form, $this->entry );
316
317
			// Delete the values for hidden inputs
318 4
			$this->unset_hidden_field_values();
319
			
320 4
			$this->entry['date_created'] = $date_created;
321
322
			// Process calculation fields
323 4
			$this->update_calculation_fields();
324
325
			// Perform actions normally performed after updating a lead
326 4
			$this->after_update();
327
328
			/**
329
			 * Must be AFTER after_update()!
330
			 * @see https://github.com/gravityview/GravityView/issues/764
331
			 */
332 4
			$this->maybe_update_post_fields( $form );
333
334
			/**
335
			 * @action `gravityview/edit_entry/after_update` Perform an action after the entry has been updated using Edit Entry
336
			 * @param array $form Gravity Forms form array
337
			 * @param string $entry_id Numeric ID of the entry that was updated
338
			 * @param GravityView_Edit_Entry_Render $this This object
339
			 */
340 4
			do_action( 'gravityview/edit_entry/after_update', $this->form, $this->entry['id'], $this );
341
342
		} else {
343
			do_action('gravityview_log_error', __METHOD__ . ': Submission is NOT valid.', $this->entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
344
		}
345
346 4
	} // process_save
347
348
	/**
349
	 * Delete the value of fields hidden by conditional logic when the entry is edited
350
	 *
351
	 * @uses GFFormsModel::update_lead_field_value()
352
	 *
353
	 * @since 1.17.4
354
	 *
355
	 * @return void
356
	 */
357 3
	private function unset_hidden_field_values() {
358 3
		global $wpdb;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
359
360
		/**
361
		 * @filter `gravityview/edit_entry/unset_hidden_field_values` Whether to delete values of fields hidden by conditional logic
362
         * @since 1.22.2
363
         * @param bool $unset_hidden_field_values Default: true
364
         * @param GravityView_Edit_Entry_Render $this This object
365
		 */
366 3
		$unset_hidden_field_values = apply_filters( 'gravityview/edit_entry/unset_hidden_field_values', true, $this );
367
368 3
		if( ! $unset_hidden_field_values ) {
369
			return;
370
		}
371
372 3
        if ( version_compare( GravityView_GFFormsModel::get_database_version(), '2.3-dev-1', '>=' ) && method_exists( 'GFFormsModel', 'get_entry_meta_table_name' ) ) {
373
			$entry_meta_table = GFFormsModel::get_entry_meta_table_name();
374
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT meta_key, meta_value FROM $entry_meta_table WHERE entry_id=%d", $this->entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
375
		} else {
376 3
			$lead_detail_table = GFFormsModel::get_lead_details_table_name();
377 3
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT id, field_number FROM $lead_detail_table WHERE lead_id=%d", $this->entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
378
		}
379
380 3
		foreach ( $this->entry as $input_id => $field_value ) {
381
382 3
			$field = RGFormsModel::get_field( $this->form, $input_id );
383
384
			// Reset fields that are hidden
385
			// Don't pass $entry as fourth parameter; force using $_POST values to calculate conditional logic
386 3
			if ( GFFormsModel::is_field_hidden( $this->form, $field, array(), NULL ) ) {
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
387
388
				// List fields are stored as empty arrays when empty
389
				$empty_value = $this->is_field_json_encoded( $field ) ? '[]' : '';
390
391
				$lead_detail_id = GFFormsModel::get_lead_detail_id( $current_fields, $input_id );
392
393
				GFFormsModel::update_lead_field_value( $this->form, $this->entry, $field, $lead_detail_id, $input_id, $empty_value );
394
395
				// Prevent the $_POST values of hidden fields from being used as default values when rendering the form
396
				// after submission
397
				$post_input_id = 'input_' . str_replace( '.', '_', $input_id );
398 3
				$_POST[ $post_input_id ] = '';
399
			}
400
		}
401 3
	}
402
403
	/**
404
	 * Have GF handle file uploads
405
	 *
406
	 * Copy of code from GFFormDisplay::process_form()
407
	 *
408
	 * @param int $form_id
409
	 */
410 3
	private function process_save_process_files( $form_id ) {
411
412
		//Loading files that have been uploaded to temp folder
413 3
		$files = GFCommon::json_decode( stripslashes( RGForms::post( 'gform_uploaded_files' ) ) );
414 3
		if ( ! is_array( $files ) ) {
415 2
			$files = array();
416
		}
417
418
		/**
419
		 * Make sure the fileuploads are not overwritten if no such request was done.
420
		 * @since 1.20.1
421
		 */
422 3
		add_filter( "gform_save_field_value_$form_id", array( $this, 'save_field_value' ), 99, 5 );
423
424 3
		RGFormsModel::$uploaded_files[ $form_id ] = $files;
425 3
	}
426
427
	/**
428
	 * Make sure the fileuploads are not overwritten if no such request was done.
429
	 *
430
	 * TO ONLY BE USED INTERNALLY; DO NOT DEVELOP ON; MAY BE REMOVED AT ANY TIME.
431
	 *
432
	 * @since 1.20.1
433
	 *
434
	 * @param string $value Field value
435
	 * @param array $entry GF entry array
436
	 * @param GF_Field_FileUpload $field
437
	 * @param array $form GF form array
438
	 * @param string $input_id ID of the input being saved
439
	 *
440
	 * @return string
441
	 */
442 3
	public function save_field_value( $value = '', $entry = array(), $field = null, $form = array(), $input_id = '' ) {
443
444 3
		if ( ! $field || $field->type != 'fileupload' ) {
0 ignored issues
show
introduced by
Found "!= '". Use Yoda Condition checks, you must
Loading history...
445 3
			return $value;
446
		}
447
448 1
		$input_name = 'input_' . str_replace( '.', '_', $input_id );
449
450 1
		if ( $field->multipleFiles ) {
451
			if ( empty( $value ) ) {
452
				return json_decode( $entry[ $input_id ], true );
453
			}
454
			return $value;
455
		}
456
457
		/** No file is being uploaded. */
458 1
		if ( empty( $_FILES[ $input_name ]['name'] ) ) {
459
			/** So return the original upload */
460 1
			return $entry[ $input_id ];
461
		}
462
463 1
		return $value;
464
	}
465
466
	/**
467
	 * Remove max_files validation (done on gravityforms.js) to avoid conflicts with GravityView
468
	 * Late validation done on self::custom_validation
469
	 *
470
	 * @param $plupload_init array Plupload settings
471
	 * @param $form_id
472
	 * @param $instance
473
	 * @return mixed
474
	 */
475 1
	public function modify_fileupload_settings( $plupload_init, $form_id, $instance ) {
0 ignored issues
show
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $instance is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
476 1
		if( ! $this->is_edit_entry() ) {
477
			return $plupload_init;
478
		}
479
480 1
		$plupload_init['gf_vars']['max_files'] = 0;
481
482 1
		return $plupload_init;
483
	}
484
485
486
	/**
487
	 * Unset adminOnly and convert field input key to string
488
	 * @return array $form
489
	 */
490 3
	private function form_prepare_for_save() {
491
492 3
		$form = $this->form;
493
494
		/** @var GF_Field $field */
495 3
		foreach( $form['fields'] as $k => &$field ) {
496
497
			/**
498
			 * Remove the fields with calculation formulas before save to avoid conflicts with GF logic
499
			 * @since 1.16.3
500
			 * @var GF_Field $field
501
			 */
502 3
			if( $field->has_calculation() ) {
503
				unset( $form['fields'][ $k ] );
504
			}
505
506 3
			$field->adminOnly = false;
507
508 3
			if( isset( $field->inputs ) && is_array( $field->inputs ) ) {
509
				foreach( $field->inputs as $key => $input ) {
510 3
					$field->inputs[ $key ][ 'id' ] = (string)$input['id'];
0 ignored issues
show
introduced by
Array keys should NOT be surrounded by spaces if they only contain a string or an integer.
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
511
				}
512
			}
513
		}
514
515 3
		return $form;
516
	}
517
518 3
	private function update_calculation_fields() {
519
520 3
		$form = self::$original_form;
521 3
		$update = false;
522
523
		// get the most up to date entry values
524 3
		$entry = GFAPI::get_entry( $this->entry['id'] );
525
526 3
		if( !empty( $this->fields_with_calculation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
527
			$update = true;
528
			foreach ( $this->fields_with_calculation as $calc_field ) {
529
				$inputs = $calc_field->get_entry_inputs();
530
				if ( is_array( $inputs ) ) {
531
					foreach ( $inputs as $input ) {
532
						$input_name = 'input_' . str_replace( '.', '_', $input['id'] );
533
						list( $prefix, $field_id, $input_id ) = rgexplode( '_', $input_name, 3 );
534
535
						switch ( $input_id ) {
536
							case 1:
537
								/** Never void the labels. */
538
								$value = $entry[ $input['id'] ];
539
								break;
540
							case 2:
541
								/** Always recalcualte the final price. */
542
								$value = '';
543
								break;
544
							case 3:
545
								/** Fetch the quantity form the request. */
546
								$value = rgpost( $input_name, $entry[ $input['id'] ] );
547
								break;
548
						}
549
550
						$entry[ strval( $input['id'] ) ] = RGFormsModel::prepare_value( $form, $calc_field, $value, $input_name, $entry['id'], $entry );
0 ignored issues
show
Bug introduced by
The variable $value does not seem to be defined for all execution paths leading up to this point.

If you define a variable conditionally, it can happen that it is not defined for all execution paths.

Let’s take a look at an example:

function myFunction($a) {
    switch ($a) {
        case 'foo':
            $x = 1;
            break;

        case 'bar':
            $x = 2;
            break;
    }

    // $x is potentially undefined here.
    echo $x;
}

In the above example, the variable $x is defined if you pass “foo” or “bar” as argument for $a. However, since the switch statement has no default case statement, if you pass any other value, the variable $x would be undefined.

Available Fixes

  1. Check for existence of the variable explicitly:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        if (isset($x)) { // Make sure it's always set.
            echo $x;
        }
    }
    
  2. Define a default value for the variable:

    function myFunction($a) {
        $x = ''; // Set a default which gets overridden for certain paths.
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        echo $x;
    }
    
  3. Add a value for the missing path:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
    
            // We add support for the missing case.
            default:
                $x = '';
                break;
        }
    
        echo $x;
    }
    
Loading history...
551
					}
552
				} else {
553
					$input_name = 'input_' . str_replace( '.', '_', $calc_field->id);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
554
					$entry[ strval( $calc_field->id ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
555
				}
556
			}
557
558
		}
559
560 3
		if( $update ) {
561
562
			$return_entry = GFAPI::update_entry( $entry );
563
564
			if( is_wp_error( $return_entry ) ) {
565
				do_action( 'gravityview_log_error', 'Updating the entry calculation fields failed', $return_entry );
566
			} else {
567
				do_action( 'gravityview_log_debug', 'Updating the entry calculation fields succeeded' );
568
			}
569
		}
570 3
	}
571
572
	/**
573
	 * Handle updating the Post Image field
574
	 *
575
	 * Sets a new Featured Image if configured in Gravity Forms; otherwise uploads/updates media
576
	 *
577
	 * @since 1.17
578
	 *
579
	 * @uses GFFormsModel::media_handle_upload
580
	 * @uses set_post_thumbnail
581
	 * 
582
	 * @param array $form GF Form array
583
	 * @param GF_Field $field GF Field
584
	 * @param string $field_id Numeric ID of the field
585
	 * @param string $value
586
	 * @param array $entry GF Entry currently being edited
587
	 * @param int $post_id ID of the Post being edited
588
	 *
589
	 * @return mixed|string
590
	 */
591 1
	private function update_post_image( $form, $field, $field_id, $value, $entry, $post_id ) {
592
593 1
		$input_name = 'input_' . $field_id;
594
595 1
		if ( !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
596
597
			// We have a new image
598
599
			$value = RGFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'] );
600
601
			$ary = ! empty( $value ) ? explode( '|:|', $value ) : array();
602
			$img_url = rgar( $ary, 0 );
603
604
			$img_title	   = count( $ary ) > 1 ? $ary[1] : '';
605
			$img_caption	 = count( $ary ) > 2 ? $ary[2] : '';
606
			$img_description = count( $ary ) > 3 ? $ary[3] : '';
607
608
			$image_meta = array(
609
				'post_excerpt' => $img_caption,
610
				'post_content' => $img_description,
611
			);
612
613
			//adding title only if it is not empty. It will default to the file name if it is not in the array
614
			if ( ! empty( $img_title ) ) {
615
				$image_meta['post_title'] = $img_title;
616
			}
617
618
			/**
619
			 * todo: As soon as \GFFormsModel::media_handle_upload becomes a public method, move this call to \GFFormsModel::media_handle_upload and remove the hack from this class.
620
			 * Note: the method became public in GF 1.9.17.7, but we don't require that version yet.
621
			 */
622
			$media_id = GravityView_GFFormsModel::media_handle_upload( $img_url, $post_id, $image_meta );
623
624
			// is this field set as featured image?
625
			if ( $media_id && $field->postFeaturedImage ) {
626
				set_post_thumbnail( $post_id, $media_id );
627
			}
628
629
		} elseif ( !empty( $_POST[ $input_name ] ) && is_array( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
630 1
631
			$img_url = $_POST[ $input_name ];
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
632 1
633
			$img_title	   = rgar( $_POST, $input_name.'_1' );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
634 1
			$img_caption	 = rgar( $_POST, $input_name .'_4' );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
635 1
			$img_description = rgar( $_POST, $input_name .'_7' );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
636 1
637
			$value = ! empty( $img_url ) ? $img_url . "|:|" . $img_title . "|:|" . $img_caption . "|:|" . $img_description : '';
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal |:| does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
638 1
639
			if ( $field->postFeaturedImage ) {
640 1
641
				$image_meta = array(
642
					'ID' => get_post_thumbnail_id( $post_id ),
643 1
					'post_title' => $img_title,
644 1
					'post_excerpt' => $img_caption,
645 1
					'post_content' => $img_description,
646 1
				);
647
648
				// update image title, caption or description
649
				wp_update_post( $image_meta );
650 1
			}
651
		} else {
652
653
			// if we get here, image was removed or not set.
654
			$value = '';
655
656
			if ( $field->postFeaturedImage ) {
657
				delete_post_thumbnail( $post_id );
658
			}
659
		}
660
661
		return $value;
662 1
	}
663
664
	/**
665
	 * Loop through the fields being edited and if they include Post fields, update the Entry's post object
666
	 *
667
	 * @param array $form Gravity Forms form
668
	 *
669
	 * @return void
670
	 */
671
	private function maybe_update_post_fields( $form ) {
672 3
673
		if( empty( $this->entry['post_id'] ) ) {
674 3
			do_action( 'gravityview_log_debug', __METHOD__ . ': This entry has no post fields. Continuing...' );
675 2
			return;
676 2
		}
677
678
		$post_id = $this->entry['post_id'];
679 1
680
		// Security check
681
		if( false === GVCommon::has_cap( 'edit_post', $post_id ) ) {
682 1
			do_action( 'gravityview_log_error', 'The current user does not have the ability to edit Post #'.$post_id );
683
			return;
684
		}
685
686
		$update_entry = false;
687 1
688
		$updated_post = $original_post = get_post( $post_id );
689 1
690
		foreach ( $this->entry as $field_id => $value ) {
691 1
692
			$field = RGFormsModel::get_field( $form, $field_id );
693 1
694
			if( ! $field ) {
695 1
				continue;
696 1
			}
697
698
			if( GFCommon::is_post_field( $field ) && 'post_category' !== $field->type ) {
699 1
700
				// Get the value of the field, including $_POSTed value
701
				$value = RGFormsModel::get_field_value( $field );
702 1
703
				// Use temporary entry variable, to make values available to fill_post_template() and update_post_image()
704
				$entry_tmp = $this->entry;
705 1
				$entry_tmp["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
706 1
707
				switch( $field->type ) {
708 1
709
					case 'post_title':
710 1
						$post_title = $value;
711
						if( rgar( $form, 'postTitleTemplateEnabled' ) ) {
712
							$post_title = $this->fill_post_template( $form['postTitleTemplate'], $form, $entry_tmp );
713
						}
714
						$updated_post->post_title = $post_title;
715
						$updated_post->post_name  = $post_title;
716
						unset( $post_title );
717
						break;
718
719
					case 'post_content':
720 1
						$post_content = $value;
721
						if( rgar( $form, 'postContentTemplateEnabled' ) ) {
722
							$post_content = $this->fill_post_template( $form['postContentTemplate'], $form, $entry_tmp, true );
723
						}
724
						$updated_post->post_content = $post_content;
725
						unset( $post_content );
726
						break;
727
					case 'post_excerpt':
728 1
						$updated_post->post_excerpt = $value;
729
						break;
730
					case 'post_tags':
731 1
						wp_set_post_tags( $post_id, $value, false );
732
						break;
733
					case 'post_category':
734 1
						break;
735
					case 'post_custom_field':
736 1
						if ( is_array( $value ) && ( floatval( $field_id ) !== floatval( $field->id ) ) ) {
737
							$value = $value[ $field_id ];
738
						}
739
740
						if( ! empty( $field->customFieldTemplateEnabled ) ) {
741
							$value = $this->fill_post_template( $field->customFieldTemplate, $form, $entry_tmp, true );
742
						}
743
744
						if ( $this->is_field_json_encoded( $field ) && ! is_string( $value ) ) {
745
							$value = function_exists('wp_json_encode') ? wp_json_encode( $value ) : json_encode( $value );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
746
						}
747
748
						update_post_meta( $post_id, $field->postCustomFieldName, $value );
749
						break;
750
751
					case 'post_image':
752 1
						$value = $this->update_post_image( $form, $field, $field_id, $value, $this->entry, $post_id );
753 1
						break;
754 1
755
				}
756
757
				// update entry after
758
				$this->entry["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
759 1
760
				$update_entry = true;
761 1
762
				unset( $entry_tmp );
763 1
			}
764
765
		}
766
767
		if( $update_entry ) {
768 1
769
			$return_entry = GFAPI::update_entry( $this->entry );
770 1
771
			if( is_wp_error( $return_entry ) ) {
772 1
			   do_action( 'gravityview_log_error', 'Updating the entry post fields failed', array( '$this->entry' => $this->entry, '$return_entry' => $return_entry ) );
773
			} else {
774
				do_action( 'gravityview_log_debug', 'Updating the entry post fields for post #'.$post_id.' succeeded' );
775 1
			}
776
777
		}
778
779
		$return_post = wp_update_post( $updated_post, true );
780 1
781
		if( is_wp_error( $return_post ) ) {
782 1
			$return_post->add_data( $updated_post, '$updated_post' );
783
			do_action( 'gravityview_log_error', 'Updating the post content failed', compact( 'updated_post', 'return_post' ) );
784
		} else {
785
			do_action( 'gravityview_log_debug', 'Updating the post content for post #'.$post_id.' succeeded', $updated_post );
786 1
		}
787
	}
788 1
789
	/**
790
	 * Is the field stored in a JSON-encoded manner?
791
	 *
792
	 * @param GF_Field $field
793
	 *
794
	 * @return bool True: stored in DB json_encode()'d; False: not encoded
795
	 */
796
	private function is_field_json_encoded( $field ) {
797
798
		$json_encoded = false;
799
800
		$input_type = RGFormsModel::get_input_type( $field );
801
802
		// Only certain custom field types are supported
803
		switch( $input_type ) {
804
			case 'fileupload':
805
			case 'list':
806
			case 'multiselect':
807
				$json_encoded = true;
808
				break;
809
		}
810
811
		return $json_encoded;
812
	}
813
814
	/**
815
	 * Convert a field content template into prepared output
816
	 *
817
	 * @uses GravityView_GFFormsModel::get_post_field_images()
818
	 *
819
	 * @since 1.17
820
	 *
821
	 * @param string $template The content template for the field
822
	 * @param array $form Gravity Forms form
823
	 * @param bool $do_shortcode Whether to process shortcode inside content. In GF, only run on Custom Field and Post Content fields
824
	 *
825
	 * @return string
826
	 */
827
	private function fill_post_template( $template, $form, $entry, $do_shortcode = false ) {
828
829
		require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
830
831
		$post_images = GravityView_GFFormsModel::get_post_field_images( $form, $entry );
832
833
		//replacing post image variables
834
		$output = GFCommon::replace_variables_post_image( $template, $post_images, $entry );
835
836
		//replacing all other variables
837
		$output = GFCommon::replace_variables( $output, $form, $entry, false, false, false );
838
839
		// replace conditional shortcodes
840
		if( $do_shortcode ) {
841
			$output = do_shortcode( $output );
842
		}
843
844
		return $output;
845
	}
846
847
848
	/**
849
	 * Perform actions normally performed after updating a lead
850
	 *
851
	 * @since 1.8
852
	 *
853
	 * @see GFEntryDetail::lead_detail_page()
854
	 *
855
	 * @return void
856
	 */
857
	private function after_update() {
858 3
859
		do_action( 'gform_after_update_entry', $this->form, $this->entry['id'], self::$original_entry );
860 3
		do_action( "gform_after_update_entry_{$this->form['id']}", $this->form, $this->entry['id'], self::$original_entry );
861 3
862
		// Re-define the entry now that we've updated it.
863
		$entry = RGFormsModel::get_lead( $this->entry['id'] );
864 3
865
		$entry = GFFormsModel::set_entry_meta( $entry, $this->form );
866 3
867
		if ( version_compare( GravityView_GFFormsModel::get_database_version(), '2.3-dev-1', '<' ) ) {
868 3
			// We need to clear the cache because Gravity Forms caches the field values, which
869
			// we have just updated.
870
			foreach ($this->form['fields'] as $key => $field) {
0 ignored issues
show
introduced by
No space after opening parenthesis is prohibited
Loading history...
introduced by
No space before closing parenthesis is prohibited
Loading history...
871 3
				GFFormsModel::refresh_lead_field_value( $entry['id'], $field->id );
872 3
			}
873
		}
874
875
		$this->entry = $entry;
876 3
	}
877 3
878
879
	/**
880
	 * Display the Edit Entry form
881
	 *
882
	 * @return void
883
	 */
884
	public function edit_entry_form() {
885 3
886
		?>
887
888
		<div class="gv-edit-entry-wrapper"><?php
889
890
			$javascript = gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/inline-javascript.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
891 3
892
			/**
893
			 * Fixes weird wpautop() issue
894
			 * @see https://github.com/katzwebservices/GravityView/issues/451
895
			 */
896
			echo gravityview_strip_whitespace( $javascript );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'gravityview_strip_whitespace'
Loading history...
897 3
898
			?><h2 class="gv-edit-entry-title">
899
				<span><?php
900
901
					/**
902
					 * @filter `gravityview_edit_entry_title` Modify the edit entry title
903
					 * @param string $edit_entry_title Modify the "Edit Entry" title
904
					 * @param GravityView_Edit_Entry_Render $this This object
905
					 */
906
					$edit_entry_title = apply_filters('gravityview_edit_entry_title', __('Edit Entry', 'gravityview'), $this );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
907 3
908
					echo esc_attr( $edit_entry_title );
909 3
			?></span>
910
			</h2>
911
912
			<?php $this->maybe_print_message(); ?>
913
914
			<?php // The ID of the form needs to be `gform_{form_id}` for the pluploader ?>
915
916
			<form method="post" id="gform_<?php echo $this->form_id; ?>" enctype="multipart/form-data">
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$this'
Loading history...
917
918
				<?php
919
920
				wp_nonce_field( self::$nonce_key, self::$nonce_key );
921 3
922
				wp_nonce_field( self::$nonce_field, self::$nonce_field, false );
923 3
924
				// Print the actual form HTML
925
				$this->render_edit_form();
926 3
927
				?>
928
			</form>
929 3
930
			<script>
931
				gform.addFilter('gform_reset_pre_conditional_logic_field_action', function ( reset, formId, targetId, defaultValues, isInit ) {
932
					return false;
933
				});
934
			</script>
935
936
		</div>
937
938
	<?php
939
	}
940 3
941
	/**
942
	 * Display success or error message if the form has been submitted
943
	 *
944
	 * @uses GVCommon::generate_notice
945
	 *
946
	 * @since 1.16.2.2
947
	 *
948
	 * @return void
949
	 */
950
	private function maybe_print_message() {
951 3
952
		if( rgpost('action') === 'update' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
953 3
954
			$back_link = esc_url( remove_query_arg( array( 'page', 'view', 'edit' ) ) );
955
956
			if( ! $this->is_valid ){
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
957
958
				// Keeping this compatible with Gravity Forms.
959
				$validation_message = "<div class='validation_error'>" . __('There was a problem with your submission.', 'gravityview') . " " . __('Errors have been highlighted below.', 'gravityview') . "</div>";
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw '__'
Loading history...
Coding Style Comprehensibility introduced by
The string literal </div> does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
960
				$message = apply_filters("gform_validation_message_{$this->form['id']}", apply_filters("gform_validation_message", $validation_message, $this->form), $this->form);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal gform_validation_message does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
961
962
				echo GVCommon::generate_notice( $message , 'gv-error' );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
963
964
			} else {
965
				$entry_updated_message = sprintf( esc_attr__('Entry Updated. %sReturn to Entry%s', 'gravityview'), '<a href="'. $back_link .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
966
967
				/**
968
				 * @filter `gravityview/edit_entry/success` Modify the edit entry success message (including the anchor link)
969
				 * @since 1.5.4
970
				 * @param string $entry_updated_message Existing message
971
				 * @param int $view_id View ID
972
				 * @param array $entry Gravity Forms entry array
973
				 * @param string $back_link URL to return to the original entry. @since 1.6
974
				 */
975
				$message = apply_filters( 'gravityview/edit_entry/success', $entry_updated_message , $this->view_id, $this->entry, $back_link );
976
977
				echo GVCommon::generate_notice( $message );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
978
			}
979
980
		}
981
	}
982 3
983
	/**
984
	 * Display the Edit Entry form in the original Gravity Forms format
985
	 *
986
	 * @since 1.9
987
	 *
988
	 * @return void
989
	 */
990
	private function render_edit_form() {
991 3
992
		/**
993
		 * @action `gravityview/edit-entry/render/before` Before rendering the Edit Entry form
994
		 * @since 1.17
995
		 * @param GravityView_Edit_Entry_Render $this
996
		 */
997
		do_action( 'gravityview/edit-entry/render/before', $this );
998 3
999
		add_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields'), 5000, 3 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
1000 3
		add_filter( 'gform_submit_button', array( $this, 'render_form_buttons') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
1001 3
		add_filter( 'gform_disable_view_counter', '__return_true' );
1002 3
1003
		add_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5, 5 );
1004 3
		add_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10, 5 );
1005 3
1006
		// We need to remove the fake $_GET['page'] arg to avoid rendering form as if in admin.
1007
		unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
1008 3
1009
		// TODO: Verify multiple-page forms
1010
1011
		ob_start(); // Prevent PHP warnings possibly caused by prefilling list fields for conditional logic
1012 3
1013
		$html = GFFormDisplay::get_form( $this->form['id'], false, false, true, $this->entry );
1014 3
1015
		ob_get_clean();
1016 3
1017
		remove_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields' ), 5000 );
1018 3
		remove_filter( 'gform_submit_button', array( $this, 'render_form_buttons' ) );
1019 3
		remove_filter( 'gform_disable_view_counter', '__return_true' );
1020 3
		remove_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5 );
1021 3
		remove_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10 );
1022 3
1023
		echo $html;
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$html'
Loading history...
1024 3
1025
		/**
1026
		 * @action `gravityview/edit-entry/render/after` After rendering the Edit Entry form
1027
		 * @since 1.17
1028
		 * @param GravityView_Edit_Entry_Render $this
1029
		 */
1030
		do_action( 'gravityview/edit-entry/render/after', $this );
1031 3
	}
1032 3
1033
	/**
1034
	 * Display the Update/Cancel/Delete buttons for the Edit Entry form
1035
	 * @since 1.8
1036
	 * @return string
1037
	 */
1038
	public function render_form_buttons() {
1039 3
		return gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/form-buttons.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
1040 3
	}
1041
1042
1043
	/**
1044
	 * Modify the form fields that are shown when using GFFormDisplay::get_form()
1045
	 *
1046
	 * By default, all fields will be shown. We only want the Edit Tab configured fields to be shown.
1047
	 *
1048
	 * @param array $form
1049
	 * @param boolean $ajax Whether in AJAX mode
1050
	 * @param array|string $field_values Passed parameters to the form
1051
	 *
1052
	 * @since 1.9
1053
	 *
1054
	 * @return array Modified form array
1055
	 */
1056
	public function filter_modify_form_fields( $form, $ajax = false, $field_values = '' ) {
0 ignored issues
show
Unused Code introduced by
The parameter $ajax is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $field_values is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1057 3
1058
		// In case we have validated the form, use it to inject the validation results into the form render
1059
		if( isset( $this->form_after_validation ) ) {
1060 3
			$form = $this->form_after_validation;
1061 3
		} else {
1062
			$form['fields'] = $this->get_configured_edit_fields( $form, $this->view_id );
1063 3
		}
1064
1065
		$form = $this->filter_conditional_logic( $form );
1066 3
1067
		$form = $this->prefill_conditional_logic( $form );
1068 3
1069
		// for now we don't support Save and Continue feature.
1070
		if( ! self::$supports_save_and_continue ) {
1071 3
			unset( $form['save'] );
1072 3
		}
1073
1074
		return $form;
1075 3
	}
1076
1077
	/**
1078
	 * When displaying a field, check if it's a Post Field, and if so, make sure the post exists and current user has edit rights.
1079
	 *
1080
	 * @since 1.16.2.2
1081
	 *
1082
	 * @param string $field_content Always empty. Returning not-empty overrides the input.
1083
	 * @param GF_Field $field
1084
	 * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1085
	 * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1086
	 * @param int $form_id Form ID
1087
	 *
1088
	 * @return string If error, the error message. If no error, blank string (modify_edit_field_input() runs next)
1089
	 */
1090
	public function verify_user_can_edit_post( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1091 3
1092
		if( GFCommon::is_post_field( $field ) ) {
1093 3
1094
			$message = null;
1095 1
1096
			// First, make sure they have the capability to edit the post.
1097
			if( false === current_user_can( 'edit_post', $this->entry['post_id'] ) ) {
1098 1
1099
				/**
1100
				 * @filter `gravityview/edit_entry/unsupported_post_field_text` Modify the message when someone isn't able to edit a post
1101
				 * @param string $message The existing "You don't have permission..." text
1102
				 */
1103
				$message = apply_filters('gravityview/edit_entry/unsupported_post_field_text', __('You don&rsquo;t have permission to edit this post.', 'gravityview') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1104
1105
			} elseif( null === get_post( $this->entry['post_id'] ) ) {
1106 1
				/**
1107
				 * @filter `gravityview/edit_entry/no_post_text` Modify the message when someone is editing an entry attached to a post that no longer exists
1108
				 * @param string $message The existing "This field is not editable; the post no longer exists." text
1109
				 */
1110
				$message = apply_filters('gravityview/edit_entry/no_post_text', __('This field is not editable; the post no longer exists.', 'gravityview' ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1111
			}
1112
1113
			if( $message ) {
1114 1
				$field_content = sprintf('<div class="ginput_container ginput_container_' . $field->type . '">%s</div>', wpautop( $message ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1115
			}
1116
		}
1117
1118
		return $field_content;
1119 3
	}
1120
1121
	/**
1122
	 *
1123
	 * Fill-in the saved values into the form inputs
1124
	 *
1125
	 * @param string $field_content Always empty. Returning not-empty overrides the input.
1126
	 * @param GF_Field $field
1127
	 * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1128
	 * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1129
	 * @param int $form_id Form ID
1130
	 *
1131
	 * @return mixed
1132
	 */
1133
	public function modify_edit_field_input( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1134 3
1135
		$gv_field = GravityView_Fields::get_associated_field( $field );
1136 3
1137
		// If the form has been submitted, then we don't need to pre-fill the values,
1138
		// Except for fileupload type and when a field input is overridden- run always!!
1139
		if(
1140
			( $this->is_edit_entry_submission() && !in_array( $field->type, array( 'fileupload', 'post_image' ) ) )
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1141 3
			&& false === ( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) )
1142 3
			&& ! GFCommon::is_product_field( $field->type )
1143
			|| ! empty( $field_content )
1144 3
			|| in_array( $field->type, array( 'honeypot' ) )
1145 3
		) {
1146
			return $field_content;
1147
		}
1148
1149
		// SET SOME FIELD DEFAULTS TO PREVENT ISSUES
1150
		$field->adminOnly = false; /** @see GFFormDisplay::get_counter_init_script() need to prevent adminOnly */
1151 3
1152
		$field_value = $this->get_field_value( $field );
1153 3
1154
		// Prevent any PHP warnings, like undefined index
1155
		ob_start();
1156 3
1157
		$return = null;
1158 3
1159
		/** @var GravityView_Field $gv_field */
1160
		if( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) ) {
1161 3
			$return = $gv_field->get_field_input( $this->form, $field_value, $this->entry, $field );
1162 2
		} else {
1163
			$return = $field->get_field_input( $this->form, $field_value, $this->entry );
1164 3
		}
1165
1166
		// If there was output, it's an error
1167
		$warnings = ob_get_clean();
1168 3
1169
		if( !empty( $warnings ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1170 3
			do_action( 'gravityview_log_error', __METHOD__ . $warnings, $field_value );
1171
		}
1172
1173
		return $return;
1174 3
	}
1175
1176
	/**
1177
	 * Modify the value for the current field input
1178
	 *
1179
	 * @param GF_Field $field
1180
	 *
1181
	 * @return array|mixed|string
1182
	 */
1183
	private function get_field_value( $field ) {
1184 3
1185
		/**
1186
		 * @filter `gravityview/edit_entry/pre_populate/override` Allow the pre-populated value to override saved value in Edit Entry form. By default, pre-populate mechanism only kicks on empty fields.
1187
		 * @param boolean True: override saved values; False: don't override (default)
1188
		 * @param $field GF_Field object Gravity Forms field object
1189
		 * @since 1.13
1190
		 */
1191
		$override_saved_value = apply_filters( 'gravityview/edit_entry/pre_populate/override', false, $field );
1192 3
1193
		// We're dealing with multiple inputs (e.g. checkbox) but not time or date (as it doesn't store data in input IDs)
1194
		if( isset( $field->inputs ) && is_array( $field->inputs ) && !in_array( $field->type, array( 'time', 'date' ) ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1195 3
1196
			$field_value = array();
1197
1198
			// only accept pre-populated values if the field doesn't have any choice selected.
1199
			$allow_pre_populated = $field->allowsPrepopulate;
1200
1201
			foreach ( (array)$field->inputs as $input ) {
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1202
1203
				$input_id = strval( $input['id'] );
1204
				
1205
				if ( isset( $this->entry[ $input_id ] ) && ! gv_empty( $this->entry[ $input_id ], false, false ) ) {
1206
					$field_value[ $input_id ] =  'post_category' === $field->type ? GFCommon::format_post_category( $this->entry[ $input_id ], true ) : $this->entry[ $input_id ];
0 ignored issues
show
introduced by
Expected 1 space after "="; 2 found
Loading history...
1207
					$allow_pre_populated = false;
1208
				}
1209
1210
			}
1211
1212
			$pre_value = $field->get_value_submission( array(), false );
1213
1214
			$field_value = ! $allow_pre_populated && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $field_value : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1215
1216
		} else {
1217
1218
			$id = intval( $field->id );
1219 3
1220
			// get pre-populated value if exists
1221
			$pre_value = $field->allowsPrepopulate ? GFFormsModel::get_parameter_value( $field->inputName, array(), $field ) : '';
1222 3
1223
			// saved field entry value (if empty, fallback to the pre-populated value, if exists)
1224
			// or pre-populated value if not empty and set to override saved value
1225
			$field_value = !gv_empty( $this->entry[ $id ], false, false ) && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $this->entry[ $id ] : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1226 3
1227
			// in case field is post_category but inputType is select, multi-select or radio, convert value into array of category IDs.
1228
			if ( 'post_category' === $field->type && !gv_empty( $field_value, false, false ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1229 3
				$categories = array();
1230
				foreach ( explode( ',', $field_value ) as $cat_string ) {
1231
					$categories[] = GFCommon::format_post_category( $cat_string, true );
1232
				}
1233
				$field_value = 'multiselect' === $field->get_input_type() ? $categories : implode( '', $categories );
1234
			}
1235
1236
		}
1237
1238
		// if value is empty get the default value if defined
1239
		$field_value = $field->get_value_default_if_empty( $field_value );
1240 3
1241
		/**
1242
		 * @filter `gravityview/edit_entry/field_value` Change the value of an Edit Entry field, if needed
1243
		 * @since 1.11
1244
		 * @since 1.20 Added third param
1245
		 * @param mixed $field_value field value used to populate the input
1246
		 * @param object $field Gravity Forms field object ( Class GF_Field )
1247
		 * @param GravityView_Edit_Entry_Render $this Current object
1248
		 */
1249
		$field_value = apply_filters( 'gravityview/edit_entry/field_value', $field_value, $field, $this );
1250 3
1251
		/**
1252
		 * @filter `gravityview/edit_entry/field_value_{field_type}` Change the value of an Edit Entry field for a specific field type
1253
		 * @since 1.17
1254
		 * @since 1.20 Added third param
1255
		 * @param mixed $field_value field value used to populate the input
1256
		 * @param GF_Field $field Gravity Forms field object
1257
		 * @param GravityView_Edit_Entry_Render $this Current object
1258
		 */
1259
		$field_value = apply_filters( 'gravityview/edit_entry/field_value_' . $field->type , $field_value, $field, $this );
1260 3
1261
		return $field_value;
1262 3
	}
1263
1264
1265
	// ---- Entry validation
1266
1267
	/**
1268
	 * Add field keys that Gravity Forms expects.
1269
	 *
1270
	 * @see GFFormDisplay::validate()
1271
	 * @param  array $form GF Form
1272
	 * @return array	   Modified GF Form
1273
	 */
1274
	public function gform_pre_validation( $form ) {
1275 3
1276
		if( ! $this->verify_nonce() ) {
1277 3
			return $form;
1278
		}
1279
1280
		// Fix PHP warning regarding undefined index.
1281
		foreach ( $form['fields'] as &$field) {
0 ignored issues
show
introduced by
No space before closing parenthesis is prohibited
Loading history...
1282 3
1283
			// This is because we're doing admin form pretending to be front-end, so Gravity Forms
1284
			// expects certain field array items to be set.
1285
			foreach ( array( 'noDuplicates', 'adminOnly', 'inputType', 'isRequired', 'enablePrice', 'inputs', 'allowedExtensions' ) as $key ) {
1286 3
				$field->{$key} = isset( $field->{$key} ) ? $field->{$key} : NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1287 3
			}
1288
1289
			switch( RGFormsModel::get_input_type( $field ) ) {
1290 3
1291
				/**
1292
				 * this whole fileupload hack is because in the admin, Gravity Forms simply doesn't update any fileupload field if it's empty, but it DOES in the frontend.
1293
				 *
1294
				 * What we have to do is set the value so that it doesn't get overwritten as empty on save and appears immediately in the Edit Entry screen again.
1295
				 *
1296
				 * @hack
1297
				 */
1298
				case 'fileupload':
1299 3
1300
					// Set the previous value
1301
					$entry = $this->get_entry();
1302 1
1303
					$input_name = 'input_'.$field->id;
1304 1
					$form_id = $form['id'];
1305 1
1306
					$value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1307 1
1308
					// Use the previous entry value as the default.
1309
					if( isset( $entry[ $field->id ] ) ) {
1310 1
						$value = $entry[ $field->id ];
1311 1
					}
1312
1313
					// If this is a single upload file
1314
					if( !empty( $_FILES[ $input_name ] ) && !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1315 1
						$file_path = GFFormsModel::get_file_upload_path( $form['id'], $_FILES[ $input_name ]['name'] );
1316 1
						$value = $file_path['url'];
1317 1
1318
					} else {
1319
1320
						// Fix PHP warning on line 1498 of form_display.php for post_image fields
1321
						// Fix PHP Notice:  Undefined index:  size in form_display.php on line 1511
1322
						$_FILES[ $input_name ] = array('name' => '', 'size' => '' );
0 ignored issues
show
introduced by
No space after opening parenthesis of array is bad style
Loading history...
1323 1
1324
					}
1325
1326
					if( rgar($field, "multipleFiles") ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal multipleFiles does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1327 1
1328
						// If there are fresh uploads, process and merge them.
1329
						// Otherwise, use the passed values, which should be json-encoded array of URLs
1330
						if( isset( GFFormsModel::$uploaded_files[$form_id][$input_name] ) ) {
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1331 1
							$value = empty( $value ) ? '[]' : $value;
1332
							$value = stripslashes_deep( $value );
1333
							$value = GFFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'], array());
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1334 1
						}
1335
1336
					} else {
1337
1338
						// A file already exists when editing an entry
1339
						// We set this to solve issue when file upload fields are required.
1340
						GFFormsModel::$uploaded_files[ $form_id ][ $input_name ] = $value;
1341 1
1342
					}
1343
1344
					$this->entry[ $input_name ] = $value;
1345 1
					$_POST[ $input_name ] = $value;
1346 1
1347
					break;
1348 1
1349
				case 'number':
1350 3
					// Fix "undefined index" issue at line 1286 in form_display.php
1351
					if( !isset( $_POST['input_'.$field->id ] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1352 1
						$_POST['input_'.$field->id ] = NULL;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1353
					}
1354
					break;
1355 3
			}
1356
1357
		}
1358
1359
		return $form;
1360 3
	}
1361
1362
1363
	/**
1364
	 * Process validation for a edit entry submission
1365
	 *
1366
	 * Sets the `is_valid` object var
1367
	 *
1368
	 * @return void
1369
	 */
1370
	private function validate() {
1371 4
1372
		/**
1373
		 * If using GF User Registration Add-on, remove the validation step, otherwise generates error when updating the entry
1374
		 * GF User Registration Add-on version > 3.x has a different class name
1375
		 * @since 1.16.2
1376
		 */
1377
		if ( class_exists( 'GF_User_Registration' ) ) {
1378 4
			remove_filter( 'gform_validation', array( GF_User_Registration::get_instance(), 'validate' ) );
1379 4
			/**
1380
			 * Add some custom validation either way.
1381
			 * https://secure.helpscout.net/conversation/430858351/10957/?folderId=1210164
1382
			 */
1383
			add_filter( 'gform_validation_' . $this->form_id, array( $this, 'user_registration_validation' ), 10, 4 );
1384 4
		} else  if ( class_exists( 'GFUser' ) ) {
1385
			remove_filter( 'gform_validation', array( 'GFUser', 'user_registration_validation' ) );
1386
		}
1387
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1388
1389
		/**
1390
		 * For some crazy reason, Gravity Forms doesn't validate Edit Entry form submissions.
1391
		 * You can enter whatever you want!
1392
		 * We try validating, and customize the results using `self::custom_validation()`
1393
		 */
1394
		add_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10, 4);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1395 4
1396
		// Needed by the validate funtion
1397
		$failed_validation_page = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1398 4
		$field_values = RGForms::post( 'gform_field_values' );
1399 4
1400
		// Prevent entry limit from running when editing an entry, also
1401
		// prevent form scheduling from preventing editing
1402
		unset( $this->form['limitEntries'], $this->form['scheduleForm'] );
1403 4
1404
		// Hide fields depending on Edit Entry settings
1405
		$this->form['fields'] = $this->get_configured_edit_fields( $this->form, $this->view_id );
1406 4
1407
		$this->is_valid = GFFormDisplay::validate( $this->form, $field_values, 1, $failed_validation_page );
1408 4
1409
		remove_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10 );
1410 4
		remove_filter( 'gform_validation_' . $this->form_id, array( $this, 'user_registration_validation' ), 10 );
1411 4
	}
1412 4
1413
	/**
1414
	 * Make validation work for User Registration feeds.
1415
	 *
1416
	 * The default validation does a bit too much for our liking.
1417
	 * Email, username validation should work. Called on the `gform_validation` filter.
1418
	 *
1419
	 * @param array $validation_results The validation results.
1420
	 * @return array The modified validation results.
1421
	 */
1422
	public function user_registration_validation( $validation_results ) {
1423 3
		$user_registration = GF_User_Registration::get_instance();
1424 3
1425
		$entry = $this->get_entry();
1426 3
		$form = $validation_results['form'];
1427 3
1428
		if ( ! $feed = $user_registration->get_single_submission_feed( $entry, $form ) ) {
1429 3
			return $validation_results;
1430
		}
1431
1432
		$username_field = GFFormsModel::get_field( $form, rgars( $feed, 'meta/username' ) );
1433 3
		$email_field    = GFFormsModel::get_field( $form, rgars( $feed, 'meta/email' ) );
1434 3
1435
		$username   = $user_registration->get_meta_value( 'username', $feed, $form, $entry );
1436 3
		$user_email = $user_registration->get_meta_value( 'email', $feed, $form, $entry );
1437 3
1438
		$value = RGFormsModel::get_field_value( $email_field );
1439 3
		if ( $user_email != $value && email_exists( $value ) ) {
1440 3
			$email_field->failed_validation = 1;
1441
			$email_field->validation_message = __( 'This email is already in use', 'gravityview' );
1442
			$validation_results['is_valid'] = false;
1443
		}
1444
1445
		$value = RGFormsModel::get_field_value( $username_field );
1446 3
		if ( $username != $value ) {
1447 3
			$username_field->failed_validation = 1;
1448
			$username_field->validation_message = __( 'Usernames cannot be changed', 'gravityview' );
1449
			$validation_results['is_valid'] = false;
1450
		}
1451
1452
		// We'll need this result when rendering the form ( on GFFormDisplay::get_form )
1453
		$this->form_after_validation = $validation_results['form'];
1454 3
1455
		return $validation_results;
1456 3
	}
1457
1458
	/**
1459
	 * Make validation work for Edit Entry
1460
	 *
1461
	 * Because we're calling the GFFormDisplay::validate() in an unusual way (as a front-end
1462
	 * form pretending to be a back-end form), validate() doesn't know we _can't_ edit post
1463
	 * fields. This goes through all the fields and if they're an invalid post field, we
1464
	 * set them as valid. If there are still issues, we'll return false.
1465
	 *
1466
	 * @param  [type] $validation_results [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1467
	 * @return [type]					 [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1468
	 */
1469
	public function custom_validation( $validation_results ) {
1470 4
1471
		do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results: ', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1472 4
1473
		do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
1474 4
1475
		$gv_valid = true;
1476 4
1477
		foreach ( $validation_results['form']['fields'] as $key => &$field ) {
1478 4
1479
			$value = RGFormsModel::get_field_value( $field );
1480 4
			$field_type = RGFormsModel::get_input_type( $field );
1481 4
1482
			// Validate always
1483
			switch ( $field_type ) {
1484
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1485
1486
				case 'fileupload' :
1487 4
				case 'post_image':
1488 4
1489
					// in case nothing is uploaded but there are already files saved
1490
					if( !empty( $field->failed_validation ) && !empty( $field->isRequired ) && !empty( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1491 2
						$field->failed_validation = false;
1492
						unset( $field->validation_message );
1493
					}
1494
1495
					// validate if multi file upload reached max number of files [maxFiles] => 2
1496
					if( rgobj( $field, 'maxFiles') && rgobj( $field, 'multipleFiles') ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1497 2
1498
						$input_name = 'input_' . $field->id;
1499
						//uploaded
1500
						$file_names = isset( GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] ) ? GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] : array();
1501
1502
						//existent
1503
						$entry = $this->get_entry();
1504
						$value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1505
						if( isset( $entry[ $field->id ] ) ) {
1506
							$value = json_decode( $entry[ $field->id ], true );
1507
						}
1508
1509
						// count uploaded files and existent entry files
1510
						$count_files = count( $file_names ) + count( $value );
1511
1512
						if( $count_files > $field->maxFiles ) {
1513
							$field->validation_message = __( 'Maximum number of files reached', 'gravityview' );
1514
							$field->failed_validation = 1;
1515
							$gv_valid = false;
1516
1517
							// in case of error make sure the newest upload files are removed from the upload input
1518
							GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ] = null;
1519
						}
1520
1521
					}
1522
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1523
1524
					break;
1525 2
1526
			}
1527
1528
			// This field has failed validation.
1529
			if( !empty( $field->failed_validation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1530 4
1531
				do_action( 'gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field is invalid.', array( 'field' => $field, 'value' => $value ) );
1532 1
1533
				switch ( $field_type ) {
1534
1535
					// Captchas don't need to be re-entered.
1536
					case 'captcha':
1537 1
1538
						// Post Image fields aren't editable, so we un-fail them.
1539
					case 'post_image':
1540 1
						$field->failed_validation = false;
1541
						unset( $field->validation_message );
1542
						break;
1543
1544
				}
1545
1546
				// You can't continue inside a switch, so we do it after.
1547
				if( empty( $field->failed_validation ) ) {
1548 1
					continue;
1549
				}
1550
1551
				// checks if the No Duplicates option is not validating entry against itself, since
1552
				// we're editing a stored entry, it would also assume it's a duplicate.
1553
				if( !empty( $field->noDuplicates ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1554 1
1555
					$entry = $this->get_entry();
1556
1557
					// If the value of the entry is the same as the stored value
1558
					// Then we can assume it's not a duplicate, it's the same.
1559
					if( !empty( $entry ) && $value == $entry[ $field->id ] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1560
						//if value submitted was not changed, then don't validate
1561
						$field->failed_validation = false;
1562
1563
						unset( $field->validation_message );
1564
1565
						do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field not a duplicate; it is the same entry.', $entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1566
1567
						continue;
1568
					}
1569
				}
1570
1571
				// if here then probably we are facing the validation 'At least one field must be filled out'
1572
				if( GFFormDisplay::is_empty( $field, $this->form_id  ) && empty( $field->isRequired ) ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 2 found
Loading history...
1573 1
					unset( $field->validation_message );
1574
					$field->validation_message = false;
1575
					continue;
1576
				}
1577
1578
				$gv_valid = false;
1579 4
1580
			}
1581
1582
		}
1583
1584
		$validation_results['is_valid'] = $gv_valid;
1585 4
1586
		do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results.', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1587 4
1588
		// We'll need this result when rendering the form ( on GFFormDisplay::get_form )
1589
		$this->form_after_validation = $validation_results['form'];
1590 4
1591
		return $validation_results;
1592 4
	}
1593
1594
1595
	/**
1596
	 * TODO: This seems to be hacky... we should remove it. Entry is set when updating the form using setup_vars()!
1597
	 * Get the current entry and set it if it's not yet set.
1598
	 * @return array Gravity Forms entry array
1599
	 */
1600
	public function get_entry() {
1601 3
1602
		if( empty( $this->entry ) ) {
1603 3
			// Get the database value of the entry that's being edited
1604
			$this->entry = gravityview_get_entry( GravityView_frontend::is_single_entry() );
1605 1
		}
1606
1607
		return $this->entry;
1608 3
	}
1609
1610
1611
1612
	// --- Filters
1613
1614
	/**
1615
	 * Get the Edit Entry fields as configured in the View
1616
	 *
1617
	 * @since 1.8
1618
	 *
1619
	 * @param int $view_id
1620
	 *
1621
	 * @return array Array of fields that are configured in the Edit tab in the Admin
1622
	 */
1623
	private function get_configured_edit_fields( $form, $view_id ) {
1624 4
1625
		// Get all fields for form
1626
		if ( defined( 'GRAVITYVIEW_FUTURE_CORE_LOADED' ) ) {
1627 4
			if ( \GV\View::exists( $view_id ) ) {
1628 4
				$view = \GV\View::by_id( $view_id );
1629 4
				$properties = $view->fields->as_configuration();
1630 4
			}
1631
		} else {
1632
			/** GravityView_View_Data is deprecated. */
1633
			$properties = GravityView_View_Data::getInstance()->get_fields( $view_id );
0 ignored issues
show
Deprecated Code introduced by
The method GravityView_View_Data::get_fields() has been deprecated.

This method has been deprecated.

Loading history...
1634
		}
1635
1636
		// If edit tab not yet configured, show all fields
1637
		$edit_fields = !empty( $properties['edit_edit-fields'] ) ? $properties['edit_edit-fields'] : NULL;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1638 4
1639
		// Hide fields depending on admin settings
1640
		$fields = $this->filter_fields( $form['fields'], $edit_fields );
1641 4
1642
		// If Edit Entry fields are configured, remove adminOnly field settings. Otherwise, don't.
1643
		$fields = $this->filter_admin_only_fields( $fields, $edit_fields, $form, $view_id );
1644 4
1645
		/**
1646
		 * @filter `gravityview/edit_entry/form_fields` Modify the fields displayed in Edit Entry form
1647
		 * @since 1.17
1648
		 * @param GF_Field[] $fields Gravity Forms form fields
1649
		 * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1650
		 * @param array $form GF Form array (`fields` key modified to have only fields configured to show in Edit Entry)
1651
		 * @param int $view_id View ID
1652
		 */
1653
		$fields = apply_filters( 'gravityview/edit_entry/form_fields', $fields, $edit_fields, $form, $view_id );
1654 4
1655
		return $fields;
1656 4
	}
1657
1658
1659
	/**
1660
	 * Filter area fields based on specified conditions
1661
	 *  - This filter removes the fields that have calculation configured
1662
	 *
1663
	 * @uses GravityView_Edit_Entry::user_can_edit_field() Check caps
1664
	 * @access private
1665
	 * @param GF_Field[] $fields
1666
	 * @param array $configured_fields
1667
	 * @since  1.5
1668
	 * @return array $fields
1669
	 */
1670
	private function filter_fields( $fields, $configured_fields ) {
1671 3
1672
		if( empty( $fields ) || !is_array( $fields ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1673 3
			return $fields;
1674
		}
1675
1676
		$edit_fields = array();
1677 3
1678
		$field_type_blacklist = $this->loader->get_field_blacklist( $this->entry );
1679 3
1680
		// First, remove blacklist or calculation fields
1681
		foreach ( $fields as $key => $field ) {
1682 3
1683
			// Remove the fields that have calculation properties and keep them to be used later
1684
			// @since 1.16.2
1685
			if( $field->has_calculation() ) {
1686 3
				$this->fields_with_calculation[] = $field;
1687
				// don't remove the calculation fields on form render.
1688
			}
1689
1690
			if( in_array( $field->type, $field_type_blacklist ) ) {
1691 3
				unset( $fields[ $key ] );
1692 3
			}
1693
		}
1694
1695
		// The Edit tab has not been configured, so we return all fields by default.
1696
		if( empty( $configured_fields ) ) {
1697 3
			return $fields;
1698 3
		}
1699
1700
		// The edit tab has been configured, so we loop through to configured settings
1701
		foreach ( $configured_fields as $configured_field ) {
1702
1703
			/** @var GF_Field $field */
1704
			foreach ( $fields as $field ) {
1705
1706
				if( intval( $configured_field['id'] ) === intval( $field->id ) && $this->user_can_edit_field( $configured_field, false ) ) {
1707
					$edit_fields[] = $this->merge_field_properties( $field, $configured_field );
1708
					break;
1709
				}
1710
1711
			}
1712
1713
		}
1714
1715
		return $edit_fields;
1716
1717
	}
1718
1719
	/**
1720
	 * Override GF Form field properties with the ones defined on the View
1721
	 * @param  GF_Field $field GF Form field object
1722
	 * @param  array $field_setting  GV field options
1723
	 * @since  1.5
1724
	 * @return array|GF_Field
1725
	 */
1726
	private function merge_field_properties( $field, $field_setting ) {
1727
1728
		$return_field = $field;
1729
1730
		if( empty( $field_setting['show_label'] ) ) {
1731
			$return_field->label = '';
1732
		} elseif ( !empty( $field_setting['custom_label'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1733
			$return_field->label = $field_setting['custom_label'];
1734
		}
1735
1736
		if( !empty( $field_setting['custom_class'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1737
			$return_field->cssClass .= ' '. gravityview_sanitize_html_class( $field_setting['custom_class'] );
1738
		}
1739
1740
		/**
1741
		 * Normalize page numbers - avoid conflicts with page validation
1742
		 * @since 1.6
1743
		 */
1744
		$return_field->pageNumber = 1;
1745
1746
		return $return_field;
1747
1748
	}
1749
1750
	/**
1751
	 * Remove fields that shouldn't be visible based on the Gravity Forms adminOnly field property
1752
	 *
1753
	 * @since 1.9.1
1754
	 *
1755
	 * @param array|GF_Field[] $fields Gravity Forms form fields
1756
	 * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1757
	 * @param array $form GF Form array
1758
	 * @param int $view_id View ID
1759
	 *
1760
	 * @return array Possibly modified form array
1761
	 */
1762
	private function filter_admin_only_fields( $fields = array(), $edit_fields = null, $form = array(), $view_id = 0 ) {
1763 3
1764
		/**
1765
		 * @filter `gravityview/edit_entry/use_gf_admin_only_setting` When Edit tab isn't configured, should the Gravity Forms "Admin Only" field settings be used to control field display to non-admins? Default: true
1766
		 * If the Edit Entry tab is not configured, adminOnly fields will not be shown to non-administrators.
1767
		 * If the Edit Entry tab *is* configured, adminOnly fields will be shown to non-administrators, using the configured GV permissions
1768
		 * @since 1.9.1
1769
		 * @param boolean $use_gf_adminonly_setting True: Hide field if set to Admin Only in GF and the user is not an admin. False: show field based on GV permissions, ignoring GF permissions.
1770
		 * @param array $form GF Form array
1771
		 * @param int $view_id View ID
1772
		 */
1773
		$use_gf_adminonly_setting = apply_filters( 'gravityview/edit_entry/use_gf_admin_only_setting', empty( $edit_fields ), $form, $view_id );
1774 3
1775
		if( $use_gf_adminonly_setting && false === GVCommon::has_cap( 'gravityforms_edit_entries', $this->entry['id'] ) ) {
1776 3
			foreach( $fields as $k => $field ) {
1777
				if( $field->adminOnly ) {
1778
					unset( $fields[ $k ] );
1779
				}
1780
			}
1781
			return $fields;
1782
		}
1783
1784
		foreach( $fields as &$field ) {
1785 3
			$field->adminOnly = false;
1786 3
		}
1787
1788
		return $fields;
1789 3
	}
1790
1791
	// --- Conditional Logic
1792
1793
	/**
1794
	 * Conditional logic isn't designed to work with forms that already have content. When switching input values,
1795
	 * the dependent fields will be blank.
1796
	 *
1797
	 * Note: This is because GF populates a JavaScript variable with the input values. This is tough to filter at the input level;
1798
	 * via the `gform_field_value` filter; it requires lots of legwork. Doing it at the form level is easier.
1799
	 *
1800
	 * @since 1.17.4
1801
	 *
1802
	 * @param array $form Gravity Forms array object
1803
	 *
1804
	 * @return array $form, modified to fix conditional
1805
	 */
1806
	function prefill_conditional_logic( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1807 3
1808
		if( ! GFFormDisplay::has_conditional_logic( $form ) ) {
1809 3
			return $form;
1810 3
		}
1811
1812
		// Have Conditional Logic pre-fill fields as if the data were default values
1813
		/** @var GF_Field $field */
1814
		foreach ( $form['fields'] as &$field ) {
1815
1816
			if( 'checkbox' === $field->type ) {
1817
				foreach ( $field->get_entry_inputs() as $key => $input ) {
1818
					$input_id = $input['id'];
1819
					$choice = $field->choices[ $key ];
1820
					$value = rgar( $this->entry, $input_id );
1821
					$match = RGFormsModel::choice_value_match( $field, $choice, $value );
1822
					if( $match ) {
1823
						$field->choices[ $key ]['isSelected'] = true;
1824
					}
1825
				}
1826
			} else {
1827
1828
				// We need to run through each field to set the default values
1829
				foreach ( $this->entry as $field_id => $field_value ) {
1830
1831
					if( floatval( $field_id ) === floatval( $field->id ) ) {
1832
1833
						if( 'list' === $field->type ) {
1834
							$list_rows = maybe_unserialize( $field_value );
1835
1836
							$list_field_value = array();
1837
							foreach ( (array) $list_rows as $row ) {
1838
								foreach ( (array) $row as $column ) {
1839
									$list_field_value[] = $column;
1840
								}
1841
							}
1842
1843
							$field->defaultValue = serialize( $list_field_value );
1844
						} else {
1845
							$field->defaultValue = $field_value;
1846
						}
1847
					}
1848
				}
1849
			}
1850
		}
1851
1852
		return $form;
1853
	}
1854
1855
	/**
1856
	 * Remove the conditional logic rules from the form button and the form fields, if needed.
1857
	 *
1858
	 * @todo Merge with caller method
1859
	 * @since 1.9
1860
	 *
1861
	 * @param array $form Gravity Forms form
1862
	 * @return array Modified form, if not using Conditional Logic
1863
	 */
1864
	private function filter_conditional_logic( $form ) {
1865 3
1866
		/**
1867
		 * @filter `gravityview/edit_entry/conditional_logic` Should the Edit Entry form use Gravity Forms conditional logic showing/hiding of fields?
1868
		 * @since 1.9
1869
		 * @param bool $use_conditional_logic True: Gravity Forms will show/hide fields just like in the original form; False: conditional logic will be disabled and fields will be shown based on configuration. Default: true
1870
		 * @param array $form Gravity Forms form
1871
		 */
1872
		$use_conditional_logic = apply_filters( 'gravityview/edit_entry/conditional_logic', true, $form );
1873 3
1874
		if( $use_conditional_logic ) {
1875 3
			return $form;
1876 3
		}
1877
1878
		foreach( $form['fields'] as &$field ) {
1879
			/* @var GF_Field $field */
1880
			$field->conditionalLogic = null;
1881
		}
1882
1883
		unset( $form['button']['conditionalLogic'] );
1884
1885
		return $form;
1886
1887
	}
1888
1889
	/**
1890
	 * Disable the Gravity Forms conditional logic script and features on the Edit Entry screen
1891
	 *
1892
	 * @since 1.9
1893
	 *
1894
	 * @param $has_conditional_logic
1895
	 * @param $form
1896
	 * @return mixed
1897
	 */
1898
	public function manage_conditional_logic( $has_conditional_logic, $form ) {
1899 3
1900
		if( ! $this->is_edit_entry() ) {
1901 3
			return $has_conditional_logic;
1902
		}
1903
1904
		/** @see GravityView_Edit_Entry_Render::filter_conditional_logic for filter documentation */
1905
		return apply_filters( 'gravityview/edit_entry/conditional_logic', $has_conditional_logic, $form );
1906 3
	}
1907
1908
1909
	// --- User checks and nonces
1910
1911
	/**
1912
	 * Check if the user can edit the entry
1913
	 *
1914
	 * - Is the nonce valid?
1915
	 * - Does the user have the right caps for the entry
1916
	 * - Is the entry in the trash?
1917
	 *
1918
	 * @todo Move to GVCommon
1919
	 *
1920
	 * @param  boolean $echo Show error messages in the form?
1921
	 * @return boolean		True: can edit form. False: nope.
1922
	 */
1923
	private function user_can_edit_entry( $echo = false ) {
1924 4
1925
		$error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1926 4
1927
		/**
1928
		 *  1. Permalinks are turned off
1929
		 *  2. There are two entries embedded using oEmbed
1930
		 *  3. One of the entries has just been saved
1931
		 */
1932
		if( !empty( $_POST['lid'] ) && !empty( $_GET['entry'] ) && ( $_POST['lid'] !== $_GET['entry'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1933 4
1934
			$error = true;
1935
1936
		}
1937
1938
		if( !empty( $_GET['entry'] ) && (string)$this->entry['id'] !== $_GET['entry'] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1939 4
1940
			$error = true;
1941
1942
		} elseif( ! $this->verify_nonce() ) {
1943 4
1944
			/**
1945
			 * If the Entry is embedded, there may be two entries on the same page.
1946
			 * If that's the case, and one is being edited, the other should fail gracefully and not display an error.
1947
			 */
1948
			if( GravityView_oEmbed::getInstance()->get_entry_id() ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression \GravityView_oEmbed::get...tance()->get_entry_id() of type integer|null is loosely compared to true; this is ambiguous if the integer can be zero. You might want to explicitly use !== null instead.

In PHP, under loose comparison (like ==, or !=, or switch conditions), values of different types might be equal.

For integer values, zero is a special case, in particular the following results might be unexpected:

0   == false // true
0   == null  // true
123 == false // false
123 == null  // false

// It is often better to use strict comparison
0 === false // false
0 === null  // false
Loading history...
1949
				$error = true;
1950
			} else {
1951
				$error = __( 'The link to edit this entry is not valid; it may have expired.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1952
			}
1953
1954
		}
1955
1956
		if( ! GravityView_Edit_Entry::check_user_cap_edit_entry( $this->entry ) ) {
1957 4
			$error = __( 'You do not have permission to edit this entry.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1958 1
		}
1959
1960
		if( $this->entry['status'] === 'trash' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
1961 4
			$error = __('You cannot edit the entry; it is in the trash.', 'gravityview' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1962
		}
1963
1964
		// No errors; everything's fine here!
1965
		if( empty( $error ) ) {
1966 4
			return true;
1967 4
		}
1968
1969
		if( $echo && $error !== true ) {
0 ignored issues
show
introduced by
Found "!== true". Use Yoda Condition checks, you must
Loading history...
1970 1
1971
			$error = esc_html( $error );
1972 1
1973
			/**
1974
			 * @since 1.9
1975
			 */
1976
			if ( ! empty( $this->entry ) ) {
1977 1
				$error .= ' ' . gravityview_get_link( '#', _x('Go back.', 'Link shown when invalid Edit Entry link is clicked', 'gravityview' ), array( 'onclick' => "window.history.go(-1); return false;" ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal window.history.go(-1); return false; does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1978 1
			}
1979
1980
			echo GVCommon::generate_notice( wpautop( $error ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1981 1
		}
1982
1983
		do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_entry]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1984 1
1985
		return false;
1986 1
	}
1987
1988
1989
	/**
1990
	 * Check whether a field is editable by the current user, and optionally display an error message
1991
	 * @uses  GravityView_Edit_Entry->check_user_cap_edit_field() Check user capabilities
1992
	 * @param  array  $field Field or field settings array
1993
	 * @param  boolean $echo  Whether to show error message telling user they aren't allowed
1994
	 * @return boolean		 True: user can edit the current field; False: nope, they can't.
1995
	 */
1996
	private function user_can_edit_field( $field, $echo = false ) {
1997
1998
		$error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1999
2000
		if( ! $this->check_user_cap_edit_field( $field ) ) {
2001
			$error = __( 'You do not have permission to edit this field.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
2002
		}
2003
2004
		// No errors; everything's fine here!
2005
		if( empty( $error ) ) {
2006
			return true;
2007
		}
2008
2009
		if( $echo ) {
2010
			echo GVCommon::generate_notice( wpautop( esc_html( $error ) ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
2011
		}
2012
2013
		do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_field]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
2014
2015
		return false;
2016
2017
	}
2018
2019
2020
	/**
2021
	 * checks if user has permissions to edit a specific field
2022
	 *
2023
	 * Needs to be used combined with GravityView_Edit_Entry::user_can_edit_field for maximum security!!
2024
	 *
2025
	 * @param  [type] $field [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
2026
	 * @return bool
2027
	 */
2028
	private function check_user_cap_edit_field( $field ) {
2029
2030
		// If they can edit any entries (as defined in Gravity Forms), we're good.
2031
		if( GVCommon::has_cap( array( 'gravityforms_edit_entries', 'gravityview_edit_others_entries' ) ) ) {
2032
			return true;
2033
		}
2034
2035
		$field_cap = isset( $field['allow_edit_cap'] ) ? $field['allow_edit_cap'] : false;
2036
2037
		// If the field has custom editing capaibilities set, check those
2038
		if( $field_cap ) {
2039
			return GVCommon::has_cap( $field['allow_edit_cap'] );
2040
		}
2041
2042
		return false;
2043
	}
2044
2045
2046
	/**
2047
	 * Is the current nonce valid for editing the entry?
2048
	 * @return boolean
2049
	 */
2050
	public function verify_nonce() {
2051 3
2052
		// Verify form submitted for editing single
2053
		if( $this->is_edit_entry_submission() ) {
2054 3
			$valid = wp_verify_nonce( $_POST[ self::$nonce_field ], self::$nonce_field );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
2055
		}
2056
2057
		// Verify
2058
		else if( ! $this->is_edit_entry() ) {
2059 3
			$valid = false;
2060
		}
2061
2062
		else {
2063
			$valid = wp_verify_nonce( $_GET['edit'], self::$nonce_key );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
2064 3
		}
2065
2066
		/**
2067
		 * @filter `gravityview/edit_entry/verify_nonce` Override Edit Entry nonce validation. Return true to declare nonce valid.
2068
		 * @since 1.13
2069
		 * @param int|boolean $valid False if invalid; 1 or 2 when nonce was generated
2070
		 * @param string $nonce_field Key used when validating submissions. Default: is_gv_edit_entry
2071
		 */
2072
		$valid = apply_filters( 'gravityview/edit_entry/verify_nonce', $valid, self::$nonce_field );
2073 3
2074
		return $valid;
2075 3
	}
2076
2077
2078
	/**
2079
	 * Multiselect in GF 2.2 became a json_encoded value. Fix it.
2080
	 *
2081
	 * As a hack for now we'll implode it back.
2082
	 */
2083
	public function fix_multiselect_value_serialization( $field_value, $field, $_this ) {
0 ignored issues
show
Unused Code introduced by
The parameter $_this is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
2084
		if ( empty ( $field->storageType ) || $field->storageType != 'json' ) {
0 ignored issues
show
introduced by
Found "!= '". Use Yoda Condition checks, you must
Loading history...
Coding Style introduced by
Space before opening parenthesis of function call prohibited
Loading history...
2085
			return $field_value;
2086
		}
2087
2088
		$maybe_json = @json_decode( $field_value, true );
0 ignored issues
show
Coding Style introduced by
Silencing errors is discouraged
Loading history...
2089
2090
		if ( $maybe_json ) {
2091
			return implode( ',', $maybe_json );
2092
		}
2093
2094
		return $field_value;
2095
	}
2096
2097
2098
2099
} //end class
2100