Completed
Push — master ( 5d7bd1...022e44 )
by Zack
04:13
created

GravityView_Edit_Entry_Render   D

Complexity

Total Complexity 240

Size/Duplication

Total Lines 1885
Duplicated Lines 0 %

Coupling/Cohesion

Components 1
Dependencies 8

Importance

Changes 26
Bugs 10 Features 0
Metric Value
c 26
b 10
f 0
dl 0
loc 1885
rs 4.4102
wmc 240
lcom 1
cbo 8

43 Methods

Rating   Name   Duplication   Size   Complexity  
A is_edit_entry() 0 6 4
B load() 0 26 1
A prevent_render_form() 0 9 3
A is_edit_entry_submission() 0 3 1
A setup_vars() 0 13 1
B process_save() 0 61 6
A modify_fileupload_settings() 0 9 2
B form_prepare_for_save() 0 23 6
D update_calculation_fields() 0 45 9
D update_post_image() 0 81 16
A get_configured_edit_fields() 0 22 2
A fix_survey_fields() 0 9 2
A __construct() 0 3 1
A prevent_maybe_process_form() 0 8 3
B init() 0 24 4
A print_scripts() 0 10 1
A process_save_process_files() 0 10 2
A render_form_buttons() 0 3 1
A get_entry() 0 9 2
A fix_hidden_fields() 0 13 3
B merge_field_properties() 0 23 4
B filter_conditional_logic() 0 24 3
A manage_conditional_logic() 0 8 2
C user_can_edit_entry() 0 64 14
B user_can_edit_field() 0 22 4
A check_user_cap_edit_field() 0 16 4
B verify_nonce() 0 26 3
B set_post_categories() 0 30 5
F maybe_update_post_fields() 0 110 21
A after_update() 0 18 2
A edit_entry_form() 0 50 1
B maybe_print_message() 0 32 3
B render_edit_form() 0 28 1
B fix_survey_fields_value() 0 29 6
A filter_modify_form_fields() 0 18 3
B verify_user_can_edit_post() 0 30 5
C modify_edit_field_input() 0 65 12
C get_field_value() 0 60 19
D gform_pre_validation() 0 97 15
B validate() 0 36 3
F custom_validation() 0 124 21
C filter_fields() 0 72 13
B filter_admin_only_fields() 0 28 6

How to fix   Complexity   

Complex Class

Complex classes like GravityView_Edit_Entry_Render often do a lot of different things. To break such a class down, we need to identify a cohesive component within that class. A common approach to find such a component is to look for fields/methods that share the same prefixes, or suffixes. You can also have a look at the cohesion graph to spot any un-connected, or weakly-connected components.

Once you have determined the fields that belong together, you can apply the Extract Class refactoring. If the component makes sense as a sub-class, Extract Subclass is also a candidate, and is often faster.

While breaking up the class, it is a good idea to analyze how other classes use GravityView_Edit_Entry_Render, and based on these observations, apply Extract Interface, too.

1
<?php
0 ignored issues
show
Coding Style Compatibility introduced by
For compatibility and reusability of your code, PSR1 recommends that a file should introduce either new symbols (like classes, functions, etc.) or have side-effects (like outputting something, or including other files), but not both at the same time. The first symbol is defined on line 17 and the first side effect is on line 13.

The PSR-1: Basic Coding Standard recommends that a file should either introduce new symbols, that is classes, functions, constants or similar, or have side effects. Side effects are anything that executes logic, like for example printing output, changing ini settings or writing to a file.

The idea behind this recommendation is that merely auto-loading a class should not change the state of an application. It also promotes a cleaner style of programming and makes your code less prone to errors, because the logic is not spread out all over the place.

To learn more about the PSR-1, please see the PHP-FIG site on the PSR-1.

Loading history...
2
/**
3
 * GravityView Edit Entry - render frontend
4
 *
5
 * @package   GravityView
6
 * @license   GPL2+
7
 * @author    Katz Web Services, Inc.
8
 * @link      http://gravityview.co
9
 * @copyright Copyright 2014, Katz Web Services, Inc.
10
 */
11
12
if ( ! defined( 'WPINC' ) ) {
13
    die;
14
}
15
16
17
class GravityView_Edit_Entry_Render {
18
19
    /**
20
     * @var GravityView_Edit_Entry
21
     */
22
    protected $loader;
23
24
	/**
25
	 * @var string String used to generate unique nonce for the entry/form/view combination. Allows access to edit page.
26
	 */
27
    static $nonce_key;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $nonce_key.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
28
29
	/**
30
	 * @since 1.9
31
	 * @var string String used for check valid edit entry form submission. Allows saving edit form values.
32
	 */
33
	private static $nonce_field = 'is_gv_edit_entry';
34
35
	/**
36
	 * @since 1.9
37
	 * @var bool Whether to allow save and continue functionality
38
	 */
39
	private static $supports_save_and_continue = false;
40
41
	/**
42
	 * @since 1.9
43
	 * @var bool Whether to allow editing product fields
44
	 */
45
	private static $supports_product_fields = false;
46
47
    /**
48
     * Gravity Forms entry array
49
     *
50
     * @var array
51
     */
52
    var $entry;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $entry.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
53
54
    /**
55
     * Gravity Forms form array (GravityView modifies the content through this class lifecycle)
56
     *
57
     * @var array
58
     */
59
    var $form;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $form.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
60
61
    /**
62
     * Gravity Forms form array (it won't get changed during this class lifecycle)
63
     * @since 1.16.2.1
64
     * @var array
65
     */
66
    var $original_form;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $original_form.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
67
68
    /**
69
     * Gravity Forms form array after the form validation process
70
     * @since 1.13
71
     * @var array
72
     */
73
    var $form_after_validation = null;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $form_after_validation.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
74
75
    /**
76
     * Hold an array of GF field objects that have calculation rules
77
     * @var array
78
     */
79
    var $fields_with_calculation = array();
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $fields_with_calculation.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
80
81
    /**
82
     * Hold an array of GF field objects with type 'total'
83
     * @var array
84
     */
85
    var $total_fields = array();
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $total_fields.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
86
87
    /**
88
     * Gravity Forms form id
89
     *
90
     * @var int
91
     */
92
    var $form_id;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $form_id.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
93
94
    /**
95
     * ID of the current view
96
     *
97
     * @var int
98
     */
99
    var $view_id;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $view_id.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
100
101
    /**
102
     * Updated entry is valid (GF Validation object)
103
     *
104
     * @var array
105
     */
106
    var $is_valid = NULL;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $is_valid.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
107
108
    function __construct( GravityView_Edit_Entry $loader ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
109
        $this->loader = $loader;
110
    }
111
112
    function load() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
113
114
        /** @define "GRAVITYVIEW_DIR" "../../../" */
115
        include_once( GRAVITYVIEW_DIR .'includes/class-admin-approve-entries.php' );
116
117
        // Don't display an embedded form when editing an entry
118
        add_action( 'wp_head', array( $this, 'prevent_render_form' ) );
119
        add_action( 'wp_footer', array( $this, 'prevent_render_form' ) );
120
121
        // Stop Gravity Forms processing what is ours!
122
        add_filter( 'wp', array( $this, 'prevent_maybe_process_form'), 8 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
123
124
        add_filter( 'gravityview_is_edit_entry', array( $this, 'is_edit_entry') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
125
126
        add_action( 'gravityview_edit_entry', array( $this, 'init' ) );
127
128
        // Disable conditional logic if needed (since 1.9)
129
        add_filter( 'gform_has_conditional_logic', array( $this, 'manage_conditional_logic' ), 10, 2 );
130
131
        // Make sure GF doesn't validate max files (since 1.9)
132
        add_filter( 'gform_plupload_settings', array( $this, 'modify_fileupload_settings' ), 10, 3 );
133
134
        // Add fields expected by GFFormDisplay::validate()
135
        add_filter( 'gform_pre_validation', array( $this, 'gform_pre_validation') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
136
137
    }
138
139
    /**
140
     * Don't show any forms embedded on a page when GravityView is in Edit Entry mode
141
     *
142
     * Adds a `__return_empty_string` filter on the Gravity Forms shortcode on the `wp_head` action
143
     * And then removes it on the `wp_footer` action
144
     *
145
     * @since 1.16.1
146
     *
147
     * @return void
148
     */
149
    function prevent_render_form() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
150
        if( $this->is_edit_entry() ) {
151
            if( 'wp_head' === current_filter() ) {
152
                add_filter( 'gform_shortcode_form', '__return_empty_string' );
153
            } else {
154
                remove_filter( 'gform_shortcode_form', '__return_empty_string' );
155
            }
156
        }
157
    }
158
159
    /**
160
     * Because we're mimicking being a front-end Gravity Forms form while using a Gravity Forms
161
     * backend form, we need to prevent them from saving twice.
162
     * @return void
163
     */
164
    function prevent_maybe_process_form() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
165
166
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[prevent_maybe_process_form] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
167
168
        if( $this->is_edit_entry_submission() && $this->verify_nonce() ) {
169
            remove_action( 'wp',  array( 'RGForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
170
        }
171
    }
172
173
    /**
174
     * Is the current page an Edit Entry page?
175
     * @return boolean
176
     */
177
    public function is_edit_entry() {
178
179
        $gf_page = function_exists('rgpost') && ( 'entry' === rgget( 'view' ) && isset( $_GET['edit'] ) || rgpost( 'action' ) === 'update' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
180
181
        return $gf_page;
182
    }
183
184
	/**
185
	 * Is the current page an Edit Entry page?
186
	 * @since 1.9
187
	 * @return boolean
188
	 */
189
	public function is_edit_entry_submission() {
190
		return !empty( $_POST[ self::$nonce_field ] );
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
191
	}
192
193
    /**
194
     * When Edit entry view is requested setup the vars
195
     */
196
    function setup_vars() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
197
        $gravityview_view = GravityView_View::getInstance();
198
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
199
200
        $entries = $gravityview_view->getEntries();
201
        $this->entry = $entries[0];
202
203
        $this->original_form = $this->form = $gravityview_view->getForm();
204
        $this->form_id = $gravityview_view->getFormId();
205
        $this->view_id = $gravityview_view->getViewId();
206
207
        self::$nonce_key = GravityView_Edit_Entry::get_nonce_key( $this->view_id, $this->form_id, $this->entry['id'] );
208
    }
209
210
211
    /**
212
     * Load required files and trigger edit flow
213
     *
214
     * Run when the is_edit_entry returns true.
215
     *
216
     * @param GravityView_View_Data $gv_data GravityView Data object
217
     * @return void
218
     */
219
    function init( $gv_data ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
220
221
        require_once( GFCommon::get_base_path() . '/form_display.php' );
222
        require_once( GFCommon::get_base_path() . '/entry_detail.php' );
223
224
        $this->setup_vars();
225
226
        // Multiple Views embedded, don't proceed if nonce fails
227
        if( $gv_data->has_multiple_views() && ! wp_verify_nonce( $_GET['edit'], self::$nonce_key ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
228
            return;
229
        }
230
231
        // Sorry, you're not allowed here.
232
        if( false === $this->user_can_edit_entry( true ) ) {
233
            return;
234
        }
235
236
        $this->print_scripts();
237
238
        $this->process_save();
239
240
        $this->edit_entry_form();
241
242
    }
243
244
245
    /**
246
     * Force Gravity Forms to output scripts as if it were in the admin
247
     * @return void
248
     */
249
    function print_scripts() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
250
        $gravityview_view = GravityView_View::getInstance();
251
252
        wp_register_script( 'gform_gravityforms', GFCommon::get_base_url().'/js/gravityforms.js', array( 'jquery', 'gform_json', 'gform_placeholder', 'sack', 'plupload-all', 'gravityview-fe-view' ) );
253
254
        GFFormDisplay::enqueue_form_scripts($gravityview_view->getForm(), false);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
255
256
        // Sack is required for images
257
        wp_print_scripts( array( 'sack', 'gform_gravityforms' ) );
258
    }
259
260
261
    /**
262
     * Process edit entry form save
263
     */
264
    function process_save() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
265
266
        if( empty( $_POST ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
267
            return;
268
        }
269
270
        // Make sure the entry, view, and form IDs are all correct
271
        $valid = $this->verify_nonce();
272
273
        if( !$valid ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
274
            do_action('gravityview_log_error', __METHOD__ . ' Nonce validation failed.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
275
            return;
276
        }
277
278
        if( $this->entry['id'] !== $_POST['lid'] ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
279
            do_action('gravityview_log_error', __METHOD__ . ' Entry ID did not match posted entry ID.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
280
            return;
281
        }
282
283
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[process_save] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
284
285
        $this->process_save_process_files( $this->form_id );
286
287
        $this->validate();
288
289
        if( $this->is_valid ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using ! empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
290
291
            do_action('gravityview_log_debug', 'GravityView_Edit_Entry[process_save] Submission is valid.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
292
293
            /**
294
             * @hack This step is needed to unset the adminOnly from form fields, to add the calculation fields
295
             */
296
            $form = $this->form_prepare_for_save();
297
298
            /**
299
             * @hack to avoid the capability validation of the method save_lead for GF 1.9+
300
             */
301
            unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
302
303
            GFFormsModel::save_lead( $form, $this->entry );
304
305
            // If there's a post associated with the entry, process post fields
306
            if( !empty( $this->entry['post_id'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
307
                $this->maybe_update_post_fields( $form );
308
            }
309
310
            // Process calculation fields
311
            $this->update_calculation_fields();
312
313
            // Perform actions normally performed after updating a lead
314
            $this->after_update();
315
316
            /**
317
             * @action `gravityview/edit_entry/after_update` Perform an action after the entry has been updated using Edit Entry
318
             * @param array $form Gravity Forms form array
319
             * @param string $entry_id Numeric ID of the entry that was updated
320
             */
321
            do_action( 'gravityview/edit_entry/after_update', $this->form, $this->entry['id'] );
322
        }
323
324
    } // process_save
325
326
327
    /**
328
     * Have GF handle file uploads
329
     *
330
     * Copy of code from GFFormDisplay::process_form()
331
     *
332
     * @param int $form_id
333
     */
334
    function process_save_process_files( $form_id ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
335
336
        //Loading files that have been uploaded to temp folder
337
        $files = GFCommon::json_decode( stripslashes( RGForms::post( 'gform_uploaded_files' ) ) );
338
        if ( ! is_array( $files ) ) {
339
            $files = array();
340
        }
341
342
        RGFormsModel::$uploaded_files[ $form_id ] = $files;
343
    }
344
345
    /**
346
     * Remove max_files validation (done on gravityforms.js) to avoid conflicts with GravityView
347
     * Late validation done on self::custom_validation
348
     *
349
     * @param $plupload_init array Plupload settings
350
     * @param $form_id
351
     * @param $instance
352
     * @return mixed
353
     */
354
    public function modify_fileupload_settings( $plupload_init, $form_id, $instance ) {
0 ignored issues
show
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $instance is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
355
        if( ! $this->is_edit_entry() ) {
356
            return $plupload_init;
357
        }
358
359
        $plupload_init['gf_vars']['max_files'] = 0;
360
361
        return $plupload_init;
362
    }
363
364
365
    /**
366
     * Unset adminOnly and convert field input key to string
367
     * @return array $form
368
     */
369
    private function form_prepare_for_save() {
370
371
        $form = $this->form;
372
373
        foreach( $form['fields'] as $k => &$field ) {
374
375
            // Remove the fields with calculation formulas before save to avoid conflicts with GF logic
376
            // @since 1.16.3
377
            if( $field->has_calculation() ) {
378
                unset( $form['fields'][ $k ] );
379
            }
380
381
            $field->adminOnly = false;
382
383
            if( isset( $field->inputs ) && is_array( $field->inputs ) ) {
384
                foreach( $field->inputs as $key => $input ) {
385
                    $field->inputs[ $key ][ 'id' ] = (string)$input['id'];
0 ignored issues
show
introduced by
Array keys should NOT be surrounded by spaces if they only contain a string or an integer.
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
386
                }
387
            }
388
        }
389
390
        return $form;
391
    }
392
393
    private function update_calculation_fields() {
394
395
        $form = $this->original_form;
396
        $update = false;
397
398
        // get the most up to date entry values
399
        $entry = GFAPI::get_entry( $this->entry['id'] );
400
401
        if( !empty( $this->fields_with_calculation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
402
            $update = true;
403
            foreach ( $this->fields_with_calculation as $calc_field ) {
404
                $inputs = $calc_field->get_entry_inputs();
405
                if ( is_array( $inputs ) ) {
406
                    foreach ( $inputs as $input ) {
407
                        $input_name = 'input_' . str_replace( '.', '_', $input['id'] );
408
                        $entry[ strval( $input['id'] ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
409
                    }
410
                } else {
411
                    $input_name = 'input_' . str_replace( '.', '_', $calc_field->id);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
412
                    $entry[ strval( $calc_field->id ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
413
                }
414
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
415
416
        }
417
418
        //saving total field as the last field of the form.
419
        if ( ! empty( $this->total_fields ) ) {
420
            $update = true;
421
            foreach ( $this->total_fields as $total_field ) {
422
                $input_name = 'input_' . str_replace( '.', '_', $total_field->id);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
423
                $entry[ strval( $total_field->id ) ] = RGFormsModel::prepare_value( $form, $total_field, '', $input_name, $entry['id'], $entry );
424
            }
425
        }
426
427
        if( $update ) {
428
429
            $return_entry = GFAPI::update_entry( $entry );
430
431
            if( is_wp_error( $return_entry ) ) {
432
                do_action( 'gravityview_log_error', 'Updating the entry calculation and total fields failed', $return_entry );
433
            } else {
434
                do_action( 'gravityview_log_debug', 'Updating the entry calculation and total fields succeeded' );
435
            }
436
        }
437
    }
438
439
    /**
440
     * Update the post categories based on all post category fields
441
     *
442
     * @since 1.17
443
     *
444
     * @param WP_Post &$updated_post Post to be updated (passed by reference)
445
     * @param array $form Form to check post fields
446
     * @param array $entry
447
     *
448
     * @return mixed
449
     */
450
    private function set_post_categories( &$updated_post, $form, $entry ) {
0 ignored issues
show
Unused Code introduced by
The parameter $entry is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
451
452
        $post_category_fields = GFAPI::get_fields_by_type( $form, 'post_category' );
453
        
454
        /**
455
         * @filter `gravityview/edit_entry/post_content/append_categories` Should post categories be added to or replaced?
456
         * @since 1.17
457
         * @param bool $append If `true`, don't delete existing categories, just add on. If `false`, replace the categories with the submitted categories. Default: `false`
458
         */
459
        $append = apply_filters( 'gravityview/edit_entry/post_content/append_categories', false );
460
461
        $updated_categories = array();
462
463
        if( $append ) {
464
            $updated_categories = wp_get_post_categories( $updated_post->ID );
465
        }
466
467
        if( $post_category_fields ) {
468
469
            foreach ( $post_category_fields as $field ) {
470
                // Get the value of the field, including $_POSTed value
471
                $field_cats = RGFormsModel::get_field_value( $field );
472
                $field_cats = is_array( $field_cats ) ? array_values( $field_cats ) : (array)$field_cats;
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
473
                $field_cats = gv_map_deep( $field_cats, 'intval' );
474
                $updated_categories = array_merge( $updated_categories, array_values( $field_cats ) );
475
            }
476
        }
477
478
        $updated_post->post_category = $updated_categories;
479
    }
480
481
    /**
482
     * Handle updating the Post Image field
483
     *
484
     * Sets a new Featured Image if configured in Gravity Forms; otherwise uploads/updates media
485
     *
486
     * @since 1.17
487
     *
488
     * @uses GFFormsModel::media_handle_upload
489
     * @uses set_post_thumbnail
490
     * 
491
     * @param array $form GF Form array
492
     * @param GF_Field $field GF Field
493
     * @param string $field_id Numeric ID of the field
494
     * @param string $value
495
     * @param array $entry GF Entry currently being edited
496
     * @param int $post_id ID of the Post being edited
497
     *
498
     * @return mixed|string
499
     */
500
    private function update_post_image( $form, $field, $field_id, $value, $entry, $post_id ) {
501
502
        $input_name = 'input_' . $field_id;
503
504
        if ( !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
505
506
            // We have a new image
507
508
            $value = RGFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'] );
509
510
            $ary = ! empty( $value ) ? explode( '|:|', $value ) : array();
511
            $img_url = rgar( $ary, 0 );
512
513
            $img_title       = count( $ary ) > 1 ? $ary[1] : '';
514
            $img_caption     = count( $ary ) > 2 ? $ary[2] : '';
515
            $img_description = count( $ary ) > 3 ? $ary[3] : '';
516
517
            $image_meta = array(
518
                'post_excerpt' => $img_caption,
519
                'post_content' => $img_description,
520
            );
521
522
            //adding title only if it is not empty. It will default to the file name if it is not in the array
523
            if ( ! empty( $img_title ) ) {
524
                $image_meta['post_title'] = $img_title;
525
            }
526
527
            /**
528
             * todo: As soon as \GFFormsModel::media_handle_upload becomes a public method, move this call to \GFFormsModel::media_handle_upload and remove the hack from this class.
529
             * Note: the method became public in GF 1.9.17.7, but we don't require that version yet.
530
             */
531
            require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
532
            $media_id = GravityView_GFFormsModel::media_handle_upload( $img_url, $post_id, $image_meta );
533
534
            // is this field set as featured image?
535
            if ( $media_id && $field->postFeaturedImage ) {
536
                set_post_thumbnail( $post_id, $media_id );
537
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
538
539
        } elseif ( !empty( $_POST[ $input_name ] ) && is_array( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
540
541
            // Same image although the image title, caption or description might have changed
542
543
            $ary = ! empty( $entry[ $field_id ] ) ? explode( '|:|', $entry[ $field_id ] ) : array();
544
            $img_url = rgar( $ary, 0 );
545
546
            // is this really the same image or something went wrong ?
547
            if( $img_url === $_POST[ $input_name ] ) {
548
549
                $img_title       = rgar( $value, $field_id .'.1' );
550
                $img_caption     = rgar( $value, $field_id .'.4' );
551
                $img_description = rgar( $value, $field_id .'.7' );
552
553
                $value = ! empty( $img_url ) ? $img_url . "|:|" . $img_title . "|:|" . $img_caption . "|:|" . $img_description : '';
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal |:| does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
554
555
                if ( $field->postFeaturedImage ) {
556
557
                    $image_meta = array(
558
                        'ID' => get_post_thumbnail_id( $post_id ),
559
                        'post_title' => $img_title,
560
                        'post_excerpt' => $img_caption,
561
                        'post_content' => $img_description,
562
                    );
563
564
                    // update image title, caption or description
565
                    wp_update_post( $image_meta );
566
                }
567
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
568
569
        } else {
570
571
            // if we get here, image was removed or not set.
572
            $value = '';
573
574
            if ( $field->postFeaturedImage ) {
575
                delete_post_thumbnail( $post_id );
576
            }
577
        }
578
579
        return $value;
580
    }
581
582
    /**
583
     * Loop through the fields being edited and if they include Post fields, update the Entry's post object
584
     *
585
     * @param array $form Gravity Forms form
586
     *
587
     * @return void
588
     */
589
    private function maybe_update_post_fields( $form ) {
590
591
        $post_id = $this->entry['post_id'];
592
593
        // Security check
594
        if( false === GVCommon::has_cap( 'edit_post', $post_id ) ) {
595
            do_action( 'gravityview_log_error', 'The current user does not have the ability to edit Post #'.$post_id );
596
            return;
597
        }
598
599
        $update_entry = false;
600
601
        $updated_post = $original_post = get_post( $post_id );
602
603
        // get the most up to date entry values
604
        $entry = GFAPI::get_entry( $this->entry['id'] );
605
606
        foreach ( $entry as $field_id => $value ) {
607
608
            //todo: only run through the edit entry configured fields
609
610
            $field = RGFormsModel::get_field( $form, $field_id );
611
612
            if( class_exists('GF_Fields') ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
613
                $field = GF_Fields::create( $field );
614
            }
615
616
            if( GFCommon::is_post_field( $field ) ) {
617
618
                // Get the value of the field, including $_POSTed value
619
                $value = RGFormsModel::get_field_value( $field );
620
621
                switch( $field->type ) {
622
623
                    case 'post_title':
624
                    case 'post_content':
625
                    case 'post_excerpt':
626
                        $updated_post->{$field->type} = $value;
627
                        break;
628
                    case 'post_tags':
629
                        wp_set_post_tags( $post_id, $value, false );
630
                        break;
631
                    case 'post_category':
632
                        break;
633
                    case 'post_custom_field':
634
635
                        $input_type = RGFormsModel::get_input_type( $field );
636
                        $custom_field_name = $field->postCustomFieldName;
637
638
                        // Only certain custom field types are supported
639
                        switch( $input_type ) {
640
                            case 'fileupload':
641
                            /** @noinspection PhpMissingBreakStatementInspection */
0 ignored issues
show
Coding Style introduced by
Line indented incorrectly; expected at least 8 tabs, found 7
Loading history...
642
                            case 'list':
643
                                if( ! is_string( $value ) ) {
644
                                    $value = function_exists('wp_json_encode') ? wp_json_encode( $value ) : json_encode( $value );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
645
                                }
646
                            // break; left intentionally out
1 ignored issue
show
Coding Style introduced by
Line indented incorrectly; expected at least 8 tabs, found 7
Loading history...
647
                            default:
648
                                update_post_meta( $post_id, $custom_field_name, $value );
649
                        }
650
651
                        break;
652
653
                    case 'post_image':
654
                        $value = $this->update_post_image( $form, $field, $field_id, $value, $entry, $post_id );
655
                        break;
656
657
                }
658
659
                //ignore fields that have not changed
660
                if ( $value === rgget( (string) $field_id, $entry ) ) {
661
                    continue;
662
                }
663
664
                // update entry
665
                if( 'post_category' !== $field->type ) {
666
                    $entry[ strval( $field_id ) ] = $value;
667
                }
668
669
                $update_entry = true;
670
671
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
672
673
        }
674
675
        if( $update_entry ) {
676
677
            $return_entry = GFAPI::update_entry( $entry );
678
679
            if( is_wp_error( $return_entry ) ) {
680
                do_action( 'gravityview_log_error', 'Updating the entry post fields failed', $return_entry );
681
            } else {
682
                do_action( 'gravityview_log_debug', 'Updating the entry post fields for post #'.$post_id.' succeeded' );
683
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
684
685
        }
686
687
        $this->set_post_categories( $updated_post, $form, $entry );
688
689
        $return_post = wp_update_post( $updated_post, true );
690
691
        if( is_wp_error( $return_post ) ) {
692
            $return_post->add_data( $updated_post, '$updated_post' );
693
            do_action( 'gravityview_log_error', 'Updating the post content failed', $return_post );
694
        } else {
695
            do_action( 'gravityview_log_debug', 'Updating the post content for post #'.$post_id.' succeeded', $updated_post );
696
        }
697
698
    }
699
700
701
    /**
702
     * Perform actions normally performed after updating a lead
703
     *
704
     * @since 1.8
705
     *
706
     * @see GFEntryDetail::lead_detail_page()
707
     *
708
     * @return void
709
     */
710
    function after_update() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
711
712
        do_action( 'gform_after_update_entry', $this->form, $this->entry['id'] );
713
        do_action( "gform_after_update_entry_{$this->form['id']}", $this->form, $this->entry['id'] );
714
715
        // Re-define the entry now that we've updated it.
716
        $entry = RGFormsModel::get_lead( $this->entry['id'] );
717
718
        $entry = GFFormsModel::set_entry_meta( $entry, $this->form );
719
720
        // We need to clear the cache because Gravity Forms caches the field values, which
721
        // we have just updated.
722
        foreach ($this->form['fields'] as $key => $field) {
0 ignored issues
show
introduced by
No space after opening parenthesis is prohibited
Loading history...
introduced by
No space before closing parenthesis is prohibited
Loading history...
723
            GFFormsModel::refresh_lead_field_value( $entry['id'], $field->id );
724
        }
725
726
        $this->entry = $entry;
727
    }
728
729
730
    /**
731
     * Display the Edit Entry form
732
     *
733
     * @return [type] [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
734
     */
735
    public function edit_entry_form() {
736
737
        ?>
738
739
        <div class="gv-edit-entry-wrapper"><?php
740
741
            $javascript = gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/inline-javascript.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
742
743
            /**
744
             * Fixes weird wpautop() issue
745
             * @see https://github.com/katzwebservices/GravityView/issues/451
746
             */
747
            echo gravityview_strip_whitespace( $javascript );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'gravityview_strip_whitespace'
Loading history...
748
749
            ?><h2 class="gv-edit-entry-title">
750
                <span><?php
751
752
                    /**
753
                     * @filter `gravityview_edit_entry_title` Modify the edit entry title
754
                     * @param string $edit_entry_title Modify the "Edit Entry" title
755
                     * @param GravityView_Edit_Entry_Render $this This object
756
                     */
757
                    $edit_entry_title = apply_filters('gravityview_edit_entry_title', __('Edit Entry', 'gravityview'), $this );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
758
759
                    echo esc_attr( $edit_entry_title );
760
            ?></span>
761
            </h2>
762
763
            <?php $this->maybe_print_message(); ?>
764
765
            <?php // The ID of the form needs to be `gform_{form_id}` for the pluploader ?>
766
767
            <form method="post" id="gform_<?php echo $this->form_id; ?>" enctype="multipart/form-data">
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$this'
Loading history...
768
769
                <?php
770
771
                wp_nonce_field( self::$nonce_key, self::$nonce_key );
772
773
                wp_nonce_field( self::$nonce_field, self::$nonce_field, false );
774
775
                // Print the actual form HTML
776
                $this->render_edit_form();
777
778
                ?>
779
            </form>
780
781
        </div>
782
783
    <?php
784
    }
785
786
    /**
787
     * Display success or error message if the form has been submitted
788
     *
789
     * @uses GVCommon::generate_notice
790
     *
791
     * @since 1.16.2.2
792
     *
793
     * @return void
794
     */
795
    private function maybe_print_message() {
796
797
        if( rgpost('action') === 'update' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
798
799
            $back_link = esc_url( remove_query_arg( array( 'page', 'view', 'edit' ) ) );
800
801
            if( ! $this->is_valid ){
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
802
803
                // Keeping this compatible with Gravity Forms.
804
                $validation_message = "<div class='validation_error'>" . __('There was a problem with your submission.', 'gravityview') . " " . __('Errors have been highlighted below.', 'gravityview') . "</div>";
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw '__'
Loading history...
Coding Style Comprehensibility introduced by
The string literal </div> does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
805
                $message = apply_filters("gform_validation_message_{$this->form['id']}", apply_filters("gform_validation_message", $validation_message, $this->form), $this->form);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal gform_validation_message does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
806
807
                echo GVCommon::generate_notice( $message , 'gv-error' );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
808
809
            } else {
810
                $entry_updated_message = sprintf( esc_attr__('Entry Updated. %sReturn to Entry%s', 'gravityview'), '<a href="'. $back_link .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
811
812
                /**
813
                 * @filter `gravityview/edit_entry/success` Modify the edit entry success message (including the anchor link)
814
                 * @since 1.5.4
815
                 * @param string $entry_updated_message Existing message
816
                 * @param int $view_id View ID
817
                 * @param array $entry Gravity Forms entry array
818
                 * @param string $back_link URL to return to the original entry. @since 1.6
819
                 */
820
                $message = apply_filters( 'gravityview/edit_entry/success', $entry_updated_message , $this->view_id, $this->entry, $back_link );
821
822
                echo GVCommon::generate_notice( $message );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
823
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
824
825
        }
826
    }
827
828
    /**
829
     * Display the Edit Entry form in the original Gravity Forms format
830
     *
831
     * @since 1.9
832
     *
833
     * @return void
834
     */
835
    private function render_edit_form() {
836
837
        add_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields'), 5000, 3 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
838
        add_filter( 'gform_submit_button', array( $this, 'render_form_buttons') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
839
        add_filter( 'gform_disable_view_counter', '__return_true' );
840
841
        add_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5, 5 );
842
        add_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10, 5 );
843
844
        add_filter( 'gform_field_value', array( $this, 'fix_survey_fields_value'), 10, 3 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
845
846
        // We need to remove the fake $_GET['page'] arg to avoid rendering form as if in admin.
847
        unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
848
849
        // TODO: Verify multiple-page forms
850
        // TODO: Product fields are not editable
851
852
        $html = GFFormDisplay::get_form( $this->form['id'], false, false, true, $this->entry );
853
854
        remove_filter( 'gform_field_value', array( $this, 'fix_survey_fields_value'), 10 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
855
	    remove_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields' ), 5000 );
856
        remove_filter( 'gform_submit_button', array( $this, 'render_form_buttons' ) );
857
        remove_filter( 'gform_disable_view_counter', '__return_true' );
858
        remove_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5 );
859
        remove_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10 );
860
861
        echo $html;
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$html'
Loading history...
862
    }
863
864
    /**
865
     * Survey fields inject their output using `gform_field_input` filter, but in Edit Entry, the values were empty.
866
     * We filter the values here because it was the easiest access point: tell the survey field the correct value, GF outputs it.
867
     *
868
     * @since 1.16.4
869
     *
870
     * @param string $value Existing value
871
     * @param GF_Field $field
872
     * @param string $name Field custom parameter name, normally blank.
873
     *
874
     * @return mixed
875
     */
876
    function fix_survey_fields_value( $value, $field, $name ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
877
        
878
        if( 'survey' === $field->type ) {
879
880
	        // We need to run through each survey row until we find a match for expected values
881
	        foreach ( $this->entry as $field_id => $field_value ) {
882
883
		        if ( floor( $field_id ) !== floor( $field->id ) ) {
884
			        continue;
885
		        }
886
887
		        if( rgar( $field, 'gsurveyLikertEnableMultipleRows' ) ) {
888
			        list( $row_val, $col_val ) = explode( ':', $field_value, 2 );
889
890
		            // If the $name matches the $row_val, we are processing the correct row
891
			        if( $row_val === $name ) {
892
				        $value = $field_value;
893
				        break;
894
			        }
895
		        } else {
896
			        // When not processing multiple rows, the value is the $entry[ $field_id ] value.
897
			        $value = $field_value;
898
				    break;
899
		        }
900
			}
901
        }
902
903
        return $value;
904
    }
905
906
    /**
907
     * Display the Update/Cancel/Delete buttons for the Edit Entry form
908
     * @since 1.8
909
     * @return string
910
     */
911
    public function render_form_buttons() {
912
        return gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/form-buttons.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
913
    }
914
915
916
    /**
917
     * Modify the form fields that are shown when using GFFormDisplay::get_form()
918
     *
919
     * By default, all fields will be shown. We only want the Edit Tab configured fields to be shown.
920
     *
921
     * @param array $form
922
     * @param boolean $ajax Whether in AJAX mode
923
     * @param array|string $field_values Passed parameters to the form
924
     *
925
     * @since 1.9
926
     *
927
     * @return array Modified form array
928
     */
929
    public function filter_modify_form_fields( $form, $ajax = false, $field_values = '' ) {
0 ignored issues
show
Unused Code introduced by
The parameter $ajax is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $field_values is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
930
931
        // In case we have validated the form, use it to inject the validation results into the form render
932
        if( isset( $this->form_after_validation ) ) {
933
            $form = $this->form_after_validation;
934
        } else {
935
            $form['fields'] = $this->get_configured_edit_fields( $form, $this->view_id );
936
        }
937
938
        $form = $this->filter_conditional_logic( $form );
939
940
        // for now we don't support Save and Continue feature.
941
        if( ! self::$supports_save_and_continue ) {
942
	        unset( $form['save'] );
943
        }
944
945
        return $form;
946
    }
947
948
    /**
949
     * When displaying a field, check if it's a Post Field, and if so, make sure the post exists and current user has edit rights.
950
     *
951
     * @since 1.16.2.2
952
     *
953
     * @param string $field_content Always empty. Returning not-empty overrides the input.
954
     * @param GF_Field $field
955
     * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
956
     * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
957
     * @param int $form_id Form ID
958
     *
959
     * @return string If error, the error message. If no error, blank string (modify_edit_field_input() runs next)
960
     */
961
    function verify_user_can_edit_post( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
962
963
        if( GFCommon::is_post_field( $field ) ) {
964
965
            $message = null;
966
967
            // First, make sure they have the capability to edit the post.
968
            if( false === current_user_can( 'edit_post', $this->entry['post_id'] ) ) {
969
970
                /**
971
                 * @filter `gravityview/edit_entry/unsupported_post_field_text` Modify the message when someone isn't able to edit a post
972
                 * @param string $message The existing "You don't have permission..." text
973
                 */
974
                $message = apply_filters('gravityview/edit_entry/unsupported_post_field_text', __('You don&rsquo;t have permission to edit this post.', 'gravityview') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
975
976
            } elseif( null === get_post( $this->entry['post_id'] ) ) {
977
                /**
978
                 * @filter `gravityview/edit_entry/no_post_text` Modify the message when someone is editing an entry attached to a post that no longer exists
979
                 * @param string $message The existing "This field is not editable; the post no longer exists." text
980
                 */
981
                $message = apply_filters('gravityview/edit_entry/no_post_text', __('This field is not editable; the post no longer exists.', 'gravityview' ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
982
            }
983
984
            if( $message ) {
985
                $field_content = sprintf('<div class="ginput_container ginput_container_' . $field->type . '">%s</div>', wpautop( $message ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
986
            }
987
        }
988
989
        return $field_content;
990
    }
991
992
    /**
993
     *
994
     * Fill-in the saved values into the form inputs
995
     *
996
     * @param string $field_content Always empty. Returning not-empty overrides the input.
997
     * @param GF_Field $field
998
     * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
999
     * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1000
     * @param int $form_id Form ID
1001
     *
1002
     * @return mixed
1003
     */
1004
    function modify_edit_field_input( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1005
1006
        $gv_field = GravityView_Fields::get_associated_field( $field );
1007
1008
        // If the form has been submitted, then we don't need to pre-fill the values,
1009
        // Except for fileupload type and when a field input is overridden- run always!!
1010
        if(
1011
            ( $this->is_edit_entry_submission() && !in_array( $field->type, array( 'fileupload', 'post_image' ) ) )
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1012
            && false === ( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) )
1013
            || ! empty( $field_content )
1014
            || GFCommon::is_product_field( $field->type ) // Prevent product fields from appearing editable
1015
        ) {
1016
	        return $field_content;
1017
        }
1018
1019
        // Turn on Admin-style display for file upload fields only
1020
        if( 'fileupload' === $field->type ) {
1021
            $_GET['page'] = 'gf_entries';
1022
        }
1023
1024
        // SET SOME FIELD DEFAULTS TO PREVENT ISSUES
1025
        $field->adminOnly = false; /** @see GFFormDisplay::get_counter_init_script() need to prevent adminOnly */
1026
1027
        // add categories as choices for Post Category field
1028
        if ( 'post_category' === $field->type ) {
1029
            $field = GFCommon::add_categories_as_choices( $field, $value );
1030
        }
1031
1032
        $field_value = $this->get_field_value( $field );
1033
1034
        /**
1035
         * @filter `gravityview/edit_entry/field_value` Change the value of an Edit Entry field, if needed
1036
         * @since 1.11
1037
         * @param mixed $field_value field value used to populate the input
1038
         * @param object $field Gravity Forms field object ( Class GF_Field )
1039
         */
1040
        $field_value = apply_filters( 'gravityview/edit_entry/field_value', $field_value, $field );
1041
1042
	    // Prevent any PHP warnings, like undefined index
1043
	    ob_start();
1044
1045
        if( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) ) {
1046
            /** @var GF_Field $gv_field */
1047
            $return = $gv_field->get_field_input( $this->form, $field_value, $this->entry, $field );
1048
        } else {
1049
	        $return = $field->get_field_input( $this->form, $field_value, $this->entry );
1050
        }
1051
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1052
1053
	    // If there was output, it's an error
1054
	    $warnings = ob_get_clean();
1055
1056
	    if( !empty( $warnings ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1057
		    do_action( 'gravityview_log_error', __METHOD__ . $warnings, $field_value );
1058
	    }
1059
1060
        /**
1061
         * Unset hack $_GET['page'] = 'gf_entries'
1062
         * We need the fileupload html field to render with the proper id
1063
         *  ( <li id="field_80_16" ... > )
1064
         */
1065
        unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
1066
1067
        return $return;
1068
    }
1069
1070
    /**
1071
     * Modify the value for the current field input
1072
     *
1073
     * @param GF_Field $field
1074
     *
1075
     * @return array|mixed|string|void
1076
     */
1077
    private function get_field_value( $field ) {
1078
1079
        /**
1080
         * @filter `gravityview/edit_entry/pre_populate/override` Allow the pre-populated value to override saved value in Edit Entry form. By default, pre-populate mechanism only kicks on empty fields.
1081
         * @param boolean True: override saved values; False: don't override (default)
1082
         * @param $field GF_Field object Gravity Forms field object
1083
         * @since 1.13
1084
         */
1085
        $override_saved_value = apply_filters( 'gravityview/edit_entry/pre_populate/override', false, $field );
1086
1087
        // We're dealing with multiple inputs (e.g. checkbox) but not time or date (as it doesn't store data in input IDs)
1088
        if( isset( $field->inputs ) && is_array( $field->inputs ) && !in_array( $field->type, array( 'time', 'date' ) ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1089
1090
            $field_value = array();
1091
1092
            // only accept pre-populated values if the field doesn't have any choice selected.
1093
            $allow_pre_populated = $field->allowsPrepopulate;
1094
1095
            foreach ( (array)$field->inputs as $input ) {
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1096
1097
                $input_id = strval( $input['id'] );
1098
                
1099
                if ( isset( $this->entry[ $input_id ] ) && ! gv_empty( $this->entry[ $input_id ], false, false ) ) {
1100
                    $field_value[ $input_id ] =  'post_category' === $field->type ? GFCommon::format_post_category( $this->entry[ $input_id ], true ) : $this->entry[ $input_id ];
0 ignored issues
show
introduced by
Expected 1 space after "="; 2 found
Loading history...
1101
                    $allow_pre_populated = false;
1102
                }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1103
1104
            }
1105
1106
            $pre_value = $field->get_value_submission( array(), false );
1107
1108
            $field_value = ! $allow_pre_populated && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $field_value : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1109
1110
        } else {
1111
1112
            $id = intval( $field->id );
1113
1114
            // get pre-populated value if exists
1115
            $pre_value = $field->allowsPrepopulate ? GFFormsModel::get_parameter_value( $field->inputName, array(), $field ) : '';
1116
1117
            // saved field entry value (if empty, fallback to the pre-populated value, if exists)
1118
            // or pre-populated value if not empty and set to override saved value
1119
            $field_value = !gv_empty( $this->entry[ $id ], false, false ) && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $this->entry[ $id ] : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1120
1121
            // in case field is post_category but inputType is select, multi-select or radio, convert value into array of category IDs.
1122
            if ( 'post_category' === $field->type && !gv_empty( $field_value, false, false ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1123
                $categories = array();
1124
                foreach ( explode( ',', $field_value ) as $cat_string ) {
1125
                    $categories[] = GFCommon::format_post_category( $cat_string, true );
1126
                }
1127
                $field_value = 'multiselect' === $field->get_input_type() ? $categories : implode( '', $categories );
1128
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1129
1130
        }
1131
1132
        // if value is empty get the default value if defined
1133
        $field_value = $field->get_value_default_if_empty( $field_value );
1134
1135
        return $field_value;
1136
    }
1137
1138
1139
    // ---- Entry validation
1140
1141
    /**
1142
     * Add field keys that Gravity Forms expects.
1143
     *
1144
     * @see GFFormDisplay::validate()
1145
     * @param  array $form GF Form
1146
     * @return array       Modified GF Form
1147
     */
1148
    function gform_pre_validation( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1149
1150
        if( ! $this->verify_nonce() ) {
1151
            return $form;
1152
        }
1153
1154
        // Fix PHP warning regarding undefined index.
1155
        foreach ( $form['fields'] as &$field) {
0 ignored issues
show
introduced by
No space before closing parenthesis is prohibited
Loading history...
1156
1157
            // This is because we're doing admin form pretending to be front-end, so Gravity Forms
1158
            // expects certain field array items to be set.
1159
            foreach ( array( 'noDuplicates', 'adminOnly', 'inputType', 'isRequired', 'enablePrice', 'inputs', 'allowedExtensions' ) as $key ) {
1160
	            $field->{$key} = isset( $field->{$key} ) ? $field->{$key} : NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1161
            }
1162
1163
            // unset emailConfirmEnabled for email type fields
1164
           /* if( 'email' === $field['type'] && !empty( $field['emailConfirmEnabled'] ) ) {
1 ignored issue
show
Unused Code Comprehensibility introduced by
61% of this comment could be valid code. Did you maybe forget this after debugging?

Sometimes obsolete code just ends up commented out instead of removed. In this case it is better to remove the code once you have checked you do not need it.

The code might also have been commented out for debugging purposes. In this case it is vital that someone uncomments it again or your project may behave in very unexpected ways in production.

This check looks for comments that seem to be mostly valid code and reports them.

Loading history...
Coding Style introduced by
Line indented incorrectly; expected at least 3 tabs, found 2
Loading history...
1165
                $field['emailConfirmEnabled'] = '';
1166
            }*/
1167
1168
            switch( RGFormsModel::get_input_type( $field ) ) {
1169
1170
                /**
1171
                 * this whole fileupload hack is because in the admin, Gravity Forms simply doesn't update any fileupload field if it's empty, but it DOES in the frontend.
1172
                 *
1173
                 * What we have to do is set the value so that it doesn't get overwritten as empty on save and appears immediately in the Edit Entry screen again.
1174
                 *
1175
                 * @hack
1176
                 */
1177
                case 'fileupload':
1178
1179
                    // Set the previous value
1180
                    $entry = $this->get_entry();
1181
1182
                    $input_name = 'input_'.$field->id;
1183
                    $form_id = $form['id'];
1184
1185
                    $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1186
1187
                    // Use the previous entry value as the default.
1188
                    if( isset( $entry[ $field->id ] ) ) {
1189
                        $value = $entry[ $field->id ];
1190
                    }
1191
1192
                    // If this is a single upload file
1193
                    if( !empty( $_FILES[ $input_name ] ) && !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1194
                        $file_path = GFFormsModel::get_file_upload_path( $form['id'], $_FILES[ $input_name ]['name'] );
1195
                        $value = $file_path['url'];
1196
1197
                    } else {
1198
1199
                        // Fix PHP warning on line 1498 of form_display.php for post_image fields
1200
                        // Fix PHP Notice:  Undefined index:  size in form_display.php on line 1511
1201
                        $_FILES[ $input_name ] = array('name' => '', 'size' => '' );
0 ignored issues
show
introduced by
No space after opening parenthesis of array is bad style
Loading history...
1202
1203
                    }
1204
1205
                    if( rgar($field, "multipleFiles") ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal multipleFiles does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1206
1207
                        // If there are fresh uploads, process and merge them.
1208
                        // Otherwise, use the passed values, which should be json-encoded array of URLs
1209
                        if( isset( GFFormsModel::$uploaded_files[$form_id][$input_name] ) ) {
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1210
                            $value = empty( $value ) ? '[]' : $value;
1211
                            $value = stripslashes_deep( $value );
1212
                            $value = GFFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'], array());
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1213
                        }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1214
1215
                    } else {
1216
1217
                        // A file already exists when editing an entry
1218
                        // We set this to solve issue when file upload fields are required.
1219
                        GFFormsModel::$uploaded_files[ $form_id ][ $input_name ] = $value;
1220
1221
                    }
1222
1223
                    $this->entry[ $input_name ] = $value;
1224
                    $_POST[ $input_name ] = $value;
1225
1226
                    break;
1227
1228
                case 'number':
1229
                    // Fix "undefined index" issue at line 1286 in form_display.php
1230
                    if( !isset( $_POST['input_'.$field->id ] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1231
                        $_POST['input_'.$field->id ] = NULL;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1232
                    }
1233
                    break;
1234
                case 'captcha':
1235
                    // Fix issue with recaptcha_check_answer() on line 1458 in form_display.php
1236
                    $_POST['recaptcha_challenge_field'] = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1237
                    $_POST['recaptcha_response_field'] = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1238
                    break;
1239
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1240
1241
        }
1242
1243
        return $form;
1244
    }
1245
1246
1247
    /**
1248
     * Process validation for a edit entry submission
1249
     *
1250
     * Sets the `is_valid` object var
1251
     *
1252
     * @return void
1253
     */
1254
    function validate() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1255
1256
        /**
1257
         * If using GF User Registration Add-on, remove the validation step, otherwise generates error when updating the entry
1258
         * GF User Registration Add-on version > 3.x has a different class name
1259
         * @since 1.16.2
1260
         */
1261
        if ( class_exists( 'GF_User_Registration' ) ) {
1262
            remove_filter( 'gform_validation', array( GF_User_Registration::get_instance(), 'validate' ) );
1263
        } else  if ( class_exists( 'GFUser' ) ) {
1264
            remove_filter( 'gform_validation', array( 'GFUser', 'user_registration_validation' ) );
1265
        }
1266
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1267
1268
        /**
1269
         * For some crazy reason, Gravity Forms doesn't validate Edit Entry form submissions.
1270
         * You can enter whatever you want!
1271
         * We try validating, and customize the results using `self::custom_validation()`
1272
         */
1273
        add_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10, 4);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1274
1275
        // Needed by the validate funtion
1276
        $failed_validation_page = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1277
        $field_values = RGForms::post( 'gform_field_values' );
1278
1279
        // Prevent entry limit from running when editing an entry, also
1280
        // prevent form scheduling from preventing editing
1281
        unset( $this->form['limitEntries'], $this->form['scheduleForm'] );
1282
1283
        // Hide fields depending on Edit Entry settings
1284
        $this->form['fields'] = $this->get_configured_edit_fields( $this->form, $this->view_id );
1285
1286
        $this->is_valid = GFFormDisplay::validate( $this->form, $field_values, 1, $failed_validation_page );
1287
1288
        remove_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10 );
1289
    }
1290
1291
1292
    /**
1293
     * Make validation work for Edit Entry
1294
     *
1295
     * Because we're calling the GFFormDisplay::validate() in an unusual way (as a front-end
1296
     * form pretending to be a back-end form), validate() doesn't know we _can't_ edit post
1297
     * fields. This goes through all the fields and if they're an invalid post field, we
1298
     * set them as valid. If there are still issues, we'll return false.
1299
     *
1300
     * @param  [type] $validation_results [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1301
     * @return [type]                     [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1302
     */
1303
    function custom_validation( $validation_results ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1304
1305
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results: ', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1306
1307
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
1308
1309
        $gv_valid = true;
1310
1311
        foreach ( $validation_results['form']['fields'] as $key => &$field ) {
1312
1313
            $value = RGFormsModel::get_field_value( $field );
1314
            $field_type = RGFormsModel::get_input_type( $field );
1315
1316
            // Validate always
1317
            switch ( $field_type ) {
1318
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1319
1320
                case 'fileupload' :
1321
                case 'post_image':
1322
1323
                    // in case nothing is uploaded but there are already files saved
1324
                    if( !empty( $field->failed_validation ) && !empty( $field->isRequired ) && !empty( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1325
                        $field->failed_validation = false;
1326
                        unset( $field->validation_message );
1327
                    }
1328
1329
                    // validate if multi file upload reached max number of files [maxFiles] => 2
1330
                    if( rgobj( $field, 'maxFiles') && rgobj( $field, 'multipleFiles') ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1331
1332
                        $input_name = 'input_' . $field->id;
1333
                        //uploaded
1334
                        $file_names = isset( GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] ) ? GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] : array();
1335
1336
                        //existent
1337
                        $entry = $this->get_entry();
1338
                        $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1339
                        if( isset( $entry[ $field->id ] ) ) {
1340
                            $value = json_decode( $entry[ $field->id ], true );
1341
                        }
1342
1343
                        // count uploaded files and existent entry files
1344
                        $count_files = count( $file_names ) + count( $value );
1345
1346
                        if( $count_files > $field->maxFiles ) {
1347
                            $field->validation_message = __( 'Maximum number of files reached', 'gravityview' );
1348
                            $field->failed_validation = 1;
1349
                            $gv_valid = false;
1350
1351
                            // in case of error make sure the newest upload files are removed from the upload input
1352
                            GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ] = null;
1353
                        }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1354
1355
                    }
1356
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1357
1358
                    break;
1359
1360
            }
1361
1362
            // This field has failed validation.
1363
            if( !empty( $field->failed_validation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1364
1365
                do_action( 'gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field is invalid.', array( 'field' => $field, 'value' => $value ) );
1366
1367
                switch ( $field_type ) {
1368
1369
                    // Captchas don't need to be re-entered.
1370
                    case 'captcha':
1371
1372
                        // Post Image fields aren't editable, so we un-fail them.
1373
                    case 'post_image':
1374
                        $field->failed_validation = false;
1375
                        unset( $field->validation_message );
1376
                        break;
1377
1378
                }
1379
1380
                // You can't continue inside a switch, so we do it after.
1381
                if( empty( $field->failed_validation ) ) {
1382
                    continue;
1383
                }
1384
1385
                // checks if the No Duplicates option is not validating entry against itself, since
1386
                // we're editing a stored entry, it would also assume it's a duplicate.
1387
                if( !empty( $field->noDuplicates ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1388
1389
                    $entry = $this->get_entry();
1390
1391
                    // If the value of the entry is the same as the stored value
1392
                    // Then we can assume it's not a duplicate, it's the same.
1393
                    if( !empty( $entry ) && $value == $entry[ $field->id ] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1394
                        //if value submitted was not changed, then don't validate
1395
                        $field->failed_validation = false;
1396
1397
                        unset( $field->validation_message );
1398
1399
                        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field not a duplicate; it is the same entry.', $entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1400
1401
                        continue;
1402
                    }
1403
                }
1404
1405
                // if here then probably we are facing the validation 'At least one field must be filled out'
1406
                if( GFFormDisplay::is_empty( $field, $this->form_id  ) && empty( $field->isRequired ) ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 2 found
Loading history...
1407
                    unset( $field->validation_message );
1408
	                $field->validation_message = false;
1409
                    continue;
1410
                }
1411
1412
                $gv_valid = false;
1413
1414
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1415
1416
        }
1417
1418
        $validation_results['is_valid'] = $gv_valid;
1419
1420
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results.', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1421
1422
        // We'll need this result when rendering the form ( on GFFormDisplay::get_form )
1423
        $this->form_after_validation = $validation_results['form'];
1424
1425
        return $validation_results;
1426
    }
1427
1428
1429
    /**
1430
     * TODO: This seems to be hacky... we should remove it. Entry is set when updating the form using setup_vars()!
1431
     * Get the current entry and set it if it's not yet set.
1432
     * @return array Gravity Forms entry array
1433
     */
1434
    private function get_entry() {
1435
1436
        if( empty( $this->entry ) ) {
1437
            // Get the database value of the entry that's being edited
1438
            $this->entry = gravityview_get_entry( GravityView_frontend::is_single_entry() );
1439
        }
1440
1441
        return $this->entry;
1442
    }
1443
1444
1445
1446
    // --- Filters
1447
1448
    /**
1449
     * Get the Edit Entry fields as configured in the View
1450
     *
1451
     * @since 1.8
1452
     *
1453
     * @param int $view_id
1454
     *
1455
     * @return array Array of fields that are configured in the Edit tab in the Admin
1456
     */
1457
    private function get_configured_edit_fields( $form, $view_id ) {
1458
1459
        // Get all fields for form
1460
        $properties = GravityView_View_Data::getInstance()->get_fields( $view_id );
1461
1462
        // If edit tab not yet configured, show all fields
1463
        $edit_fields = !empty( $properties['edit_edit-fields'] ) ? $properties['edit_edit-fields'] : NULL;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1464
1465
	    // Show hidden fields as text fields
1466
	    $form = $this->fix_hidden_fields( $form );
1467
1468
        // Show hidden fields as text fields
1469
        $form = $this->fix_survey_fields( $form );
1470
1471
        // Hide fields depending on admin settings
1472
        $fields = $this->filter_fields( $form['fields'], $edit_fields );
1473
1474
	    // If Edit Entry fields are configured, remove adminOnly field settings. Otherwise, don't.
1475
	    $fields = $this->filter_admin_only_fields( $fields, $edit_fields, $form, $view_id );
1476
1477
        return $fields;
1478
    }
1479
1480
    /**
1481
     * Make sure Survey fields accept pre-populating values; otherwise existing values won't be filled-in
1482
     *
1483
     * @since 1.16.4
1484
     *
1485
     * @param array $form
1486
     *
1487
     * @return array Form, with all fields set to `allowsPrepopulate => true`
1488
     */
1489
    private function fix_survey_fields( $form ) {
1490
1491
        /** @var GF_Field $field */
1492
        foreach( $form['fields'] as &$field ) {
1493
            $field->allowsPrepopulate = true;
1494
        }
1495
1496
        return $form;
1497
    }
1498
1499
	/**
1500
	 * @since 1.9.2
1501
	 *
1502
	 * @param $fields
1503
	 *
1504
	 * @return mixed
1505
	 */
1506
	private function fix_hidden_fields( $form ) {
1507
1508
		/** @var GF_Field $field */
1509
		foreach( $form['fields'] as $key => $field ) {
1510
			if( 'hidden' === $field->type ) {
1511
				$text_field = new GF_Field_Text( $field );
1512
				$text_field->type = 'text';
1513
				$form['fields'][ $key ] = $text_field;
1514
			}
1515
		}
1516
1517
		return $form;
1518
	}
1519
1520
1521
    /**
1522
     * Filter area fields based on specified conditions
1523
     *  - This filter removes the fields that have calculation configured
1524
     *
1525
     * @uses GravityView_Edit_Entry::user_can_edit_field() Check caps
1526
     * @access private
1527
     * @param GF_Field[] $fields
1528
     * @param array $configured_fields
1529
     * @since  1.5
1530
     * @return array $fields
1531
     */
1532
    private function filter_fields( $fields, $configured_fields ) {
1533
1534
        if( empty( $fields ) || !is_array( $fields ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1535
            return $fields;
1536
        }
1537
1538
        $edit_fields = array();
1539
1540
        $field_type_blacklist = array(
1541
            'page',
1542
        );
1543
1544
	    /**
1545
	     * @filter `gravityview/edit_entry/hide-product-fields` Hide product fields from being editable.
1546
	     * @since 1.9.1
1547
         * @param boolean $hide_product_fields Whether to hide product fields in the editor.  Default: false
1548
	     */
1549
	    $hide_product_fields = apply_filters( 'gravityview/edit_entry/hide-product-fields', empty( self::$supports_product_fields ) );
1550
1551
	    if( $hide_product_fields ) {
1552
		    $field_type_blacklist[] = 'option';
1553
		    $field_type_blacklist[] = 'quantity';
1554
            $field_type_blacklist[] = 'product';
1555
            $field_type_blacklist[] = 'total';
1556
            $field_type_blacklist[] = 'shipping';
1557
            $field_type_blacklist[] = 'calculation';
1558
	    }
1559
1560
        // First, remove blacklist or calculation fields
1561
        foreach ( $fields as $key => $field ) {
1562
1563
            // Remove the fields that have calculation properties and keep them to be used later
1564
            // @since 1.16.2
1565
            if( $field->has_calculation() ) {
1566
                $this->fields_with_calculation[] = $field;
1567
                // don't remove the calculation fields on form render.
1568
            }
1569
1570
            // process total field after all fields have been saved
1571
            if ( $field->type == 'total' ) {
0 ignored issues
show
introduced by
Found "== '". Use Yoda Condition checks, you must
Loading history...
1572
                $this->total_fields[] = $field;
1573
                unset( $fields[ $key ] );
1574
            }
1575
1576
            if( in_array( $field->type, $field_type_blacklist ) ) {
1577
                unset( $fields[ $key ] );
1578
            }
1579
        }
1580
1581
        // The Edit tab has not been configured, so we return all fields by default.
1582
        if( empty( $configured_fields ) ) {
1583
            return $fields;
1584
        }
1585
1586
        // The edit tab has been configured, so we loop through to configured settings
1587
        foreach ( $configured_fields as $configured_field ) {
1588
1589
	        /** @var GF_Field $field */
1590
	        foreach ( $fields as $field ) {
1591
1592
                if( intval( $configured_field['id'] ) === intval( $field->id ) && $this->user_can_edit_field( $configured_field, false ) ) {
1593
                    $edit_fields[] = $this->merge_field_properties( $field, $configured_field );
1594
                    break;
1595
                }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1596
1597
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1598
1599
        }
1600
1601
        return $edit_fields;
1602
1603
    }
1604
1605
    /**
1606
     * Override GF Form field properties with the ones defined on the View
1607
     * @param  GF_Field $field GF Form field object
1608
     * @param  array $setting  GV field options
0 ignored issues
show
Documentation introduced by
There is no parameter named $setting. Did you maybe mean $field_setting?

This check looks for PHPDoc comments describing methods or function parameters that do not exist on the corresponding method or function. It has, however, found a similar but not annotated parameter which might be a good fit.

Consider the following example. The parameter $ireland is not defined by the method finale(...).

/**
 * @param array $germany
 * @param array $ireland
 */
function finale($germany, $island) {
    return "2:1";
}

The most likely cause is that the parameter was changed, but the annotation was not.

Loading history...
1609
     * @since  1.5
1610
     * @return array
1611
     */
1612
    private function merge_field_properties( $field, $field_setting ) {
1613
1614
        $return_field = $field;
1615
1616
        if( empty( $field_setting['show_label'] ) ) {
1617
            $return_field->label = '';
1618
        } elseif ( !empty( $field_setting['custom_label'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1619
            $return_field->label = $field_setting['custom_label'];
1620
        }
1621
1622
        if( !empty( $field_setting['custom_class'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1623
            $return_field->cssClass .= ' '. gravityview_sanitize_html_class( $field_setting['custom_class'] );
1624
        }
1625
1626
        /**
1627
         * Normalize page numbers - avoid conflicts with page validation
1628
         * @since 1.6
1629
         */
1630
        $return_field->pageNumber = 1;
1631
1632
        return $return_field;
1633
1634
    }
1635
1636
    /**
1637
     * Remove fields that shouldn't be visible based on the Gravity Forms adminOnly field property
1638
     *
1639
     * @since 1.9.1
1640
     *
1641
     * @param array|GF_Field[] $fields Gravity Forms form fields
1642
     * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1643
     * @param array $form GF Form array
1644
     * @param int $view_id View ID
1645
     *
1646
     * @return array Possibly modified form array
1647
     */
1648
    function filter_admin_only_fields( $fields = array(), $edit_fields = null, $form = array(), $view_id = 0 ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1649
1650
	    /**
1651
         * @filter `gravityview/edit_entry/use_gf_admin_only_setting` When Edit tab isn't configured, should the Gravity Forms "Admin Only" field settings be used to control field display to non-admins? Default: true
1652
	     * If the Edit Entry tab is not configured, adminOnly fields will not be shown to non-administrators.
1653
	     * If the Edit Entry tab *is* configured, adminOnly fields will be shown to non-administrators, using the configured GV permissions
1654
	     * @since 1.9.1
1655
	     * @param boolean $use_gf_adminonly_setting True: Hide field if set to Admin Only in GF and the user is not an admin. False: show field based on GV permissions, ignoring GF permissions.
1656
	     * @param array $form GF Form array
1657
	     * @param int $view_id View ID
1658
	     */
1659
	    $use_gf_adminonly_setting = apply_filters( 'gravityview/edit_entry/use_gf_admin_only_setting', empty( $edit_fields ), $form, $view_id );
1660
1661
	    if( $use_gf_adminonly_setting && false === GVCommon::has_cap( 'gravityforms_edit_entries', $this->entry['id'] ) ) {
1662
            foreach( $fields as $k => $field ) {
1663
                if( $field->adminOnly ) {
1664
                    unset( $fields[ $k ] );
1665
                }
1666
            }
1667
            return $fields;
1668
        }
1669
1670
	    foreach( $fields as &$field ) {
1671
		    $field->adminOnly = false;
1672
        }
1673
1674
        return $fields;
1675
    }
1676
1677
    // --- Conditional Logic
1678
1679
    /**
1680
     * Remove the conditional logic rules from the form button and the form fields, if needed.
1681
     *
1682
     * @since 1.9
1683
     *
1684
     * @param array $form Gravity Forms form
1685
     * @return array Modified form, if not using Conditional Logic
1686
     */
1687
    function filter_conditional_logic( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1688
1689
        /**
1690
         * @filter `gravityview/edit_entry/conditional_logic` Should the Edit Entry form use Gravity Forms conditional logic showing/hiding of fields?
1691
         * @since 1.9
1692
         * @param bool $use_conditional_logic True: Gravity Forms will show/hide fields just like in the original form; False: conditional logic will be disabled and fields will be shown based on configuration. Default: true
1693
         * @param array $form Gravity Forms form
1694
         */
1695
        $use_conditional_logic = apply_filters( 'gravityview/edit_entry/conditional_logic', true, $form );
1696
1697
        if( $use_conditional_logic ) {
1698
            return $form;
1699
        }
1700
1701
        foreach( $form['fields'] as &$field ) {
1702
            /* @var GF_Field $field */
1703
            $field->conditionalLogic = null;
1704
        }
1705
1706
        unset( $form['button']['conditionalLogic'] );
1707
1708
        return $form;
1709
1710
    }
1711
1712
    /**
1713
     * Disable the Gravity Forms conditional logic script and features on the Edit Entry screen
1714
     *
1715
     * @since 1.9
1716
     *
1717
     * @param $has_conditional_logic
1718
     * @param $form
1719
     * @return mixed|void
1720
     */
1721
    function manage_conditional_logic( $has_conditional_logic, $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1722
1723
        if( ! $this->is_edit_entry() ) {
1724
            return $has_conditional_logic;
1725
        }
1726
1727
        return apply_filters( 'gravityview/edit_entry/conditional_logic', $has_conditional_logic, $form );
1728
    }
1729
1730
1731
    // --- User checks and nonces
1732
1733
    /**
1734
     * Check if the user can edit the entry
1735
     *
1736
     * - Is the nonce valid?
1737
     * - Does the user have the right caps for the entry
1738
     * - Is the entry in the trash?
1739
     *
1740
     * @todo Move to GVCommon
1741
     *
1742
     * @param  boolean $echo Show error messages in the form?
1743
     * @return boolean        True: can edit form. False: nope.
1744
     */
1745
    function user_can_edit_entry( $echo = false ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1746
1747
        $error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1748
1749
        /**
1750
         *  1. Permalinks are turned off
1751
         *  2. There are two entries embedded using oEmbed
1752
         *  3. One of the entries has just been saved
1753
         */
1754
        if( !empty( $_POST['lid'] ) && !empty( $_GET['entry'] ) && ( $_POST['lid'] !== $_GET['entry'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1755
1756
            $error = true;
1757
1758
        }
1759
1760
        if( !empty( $_GET['entry'] ) && (string)$this->entry['id'] !== $_GET['entry'] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1761
1762
            $error = true;
1763
1764
        } elseif( ! $this->verify_nonce() ) {
1765
1766
            /**
1767
             * If the Entry is embedded, there may be two entries on the same page.
1768
             * If that's the case, and one is being edited, the other should fail gracefully and not display an error.
1769
             */
1770
            if( GravityView_oEmbed::getInstance()->get_entry_id() ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression \GravityView_oEmbed::get...tance()->get_entry_id() of type integer|null is loosely compared to true; this is ambiguous if the integer can be zero. You might want to explicitly use !== null instead.

In PHP, under loose comparison (like ==, or !=, or switch conditions), values of different types might be equal.

For integer values, zero is a special case, in particular the following results might be unexpected:

0   == false // true
0   == null  // true
123 == false // false
123 == null  // false

// It is often better to use strict comparison
0 === false // false
0 === null  // false
Loading history...
1771
                $error = true;
1772
            } else {
1773
                $error = __( 'The link to edit this entry is not valid; it may have expired.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1774
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1775
1776
        }
1777
1778
        if( ! GravityView_Edit_Entry::check_user_cap_edit_entry( $this->entry ) ) {
1779
            $error = __( 'You do not have permission to edit this entry.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1780
        }
1781
1782
        if( $this->entry['status'] === 'trash' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
1783
            $error = __('You cannot edit the entry; it is in the trash.', 'gravityview' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1784
        }
1785
1786
        // No errors; everything's fine here!
1787
        if( empty( $error ) ) {
1788
            return true;
1789
        }
1790
1791
        if( $echo && $error !== true ) {
0 ignored issues
show
introduced by
Found "!== true". Use Yoda Condition checks, you must
Loading history...
1792
1793
	        $error = esc_html( $error );
1794
1795
	        /**
1796
	         * @since 1.9
1797
	         */
1798
	        if ( ! empty( $this->entry ) ) {
1799
		        $error .= ' ' . gravityview_get_link( '#', _x('Go back.', 'Link shown when invalid Edit Entry link is clicked', 'gravityview' ), array( 'onclick' => "window.history.go(-1); return false;" ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal window.history.go(-1); return false; does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1800
	        }
1801
1802
            echo GVCommon::generate_notice( wpautop( $error ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1803
        }
1804
1805
        do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_entry]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1806
1807
        return false;
1808
    }
1809
1810
1811
    /**
1812
     * Check whether a field is editable by the current user, and optionally display an error message
1813
     * @uses  GravityView_Edit_Entry->check_user_cap_edit_field() Check user capabilities
1814
     * @param  array  $field Field or field settings array
1815
     * @param  boolean $echo  Whether to show error message telling user they aren't allowed
1816
     * @return boolean         True: user can edit the current field; False: nope, they can't.
1817
     */
1818
    private function user_can_edit_field( $field, $echo = false ) {
1819
1820
        $error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1821
1822
        if( ! $this->check_user_cap_edit_field( $field ) ) {
1823
            $error = __( 'You do not have permission to edit this field.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1824
        }
1825
1826
        // No errors; everything's fine here!
1827
        if( empty( $error ) ) {
1828
            return true;
1829
        }
1830
1831
        if( $echo ) {
1832
            echo GVCommon::generate_notice( wpautop( esc_html( $error ) ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1833
        }
1834
1835
        do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_field]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1836
1837
        return false;
1838
1839
    }
1840
1841
1842
    /**
1843
     * checks if user has permissions to edit a specific field
1844
     *
1845
     * Needs to be used combined with GravityView_Edit_Entry::user_can_edit_field for maximum security!!
1846
     *
1847
     * @param  [type] $field [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1848
     * @return bool
1849
     */
1850
    private function check_user_cap_edit_field( $field ) {
1851
1852
        // If they can edit any entries (as defined in Gravity Forms), we're good.
1853
        if( GVCommon::has_cap( array( 'gravityforms_edit_entries', 'gravityview_edit_others_entries' ) ) ) {
1854
            return true;
1855
        }
1856
1857
        $field_cap = isset( $field['allow_edit_cap'] ) ? $field['allow_edit_cap'] : false;
1858
1859
        // If the field has custom editing capaibilities set, check those
1860
        if( $field_cap ) {
1861
            return GVCommon::has_cap( $field['allow_edit_cap'] );
1862
        }
1863
1864
        return false;
1865
    }
1866
1867
1868
    /**
1869
     * Is the current nonce valid for editing the entry?
1870
     * @return boolean
1871
     */
1872
    public function verify_nonce() {
1873
1874
        // Verify form submitted for editing single
1875
        if( $this->is_edit_entry_submission() ) {
1876
            $valid = wp_verify_nonce( $_POST[ self::$nonce_field ], self::$nonce_field );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
1877
        }
1878
1879
        // Verify
1880
        else if( ! $this->is_edit_entry() ) {
1881
            $valid = false;
1882
        }
1883
1884
        else {
1885
            $valid = wp_verify_nonce( $_GET['edit'], self::$nonce_key );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
1886
        }
1887
1888
        /**
1889
         * @filter `gravityview/edit_entry/verify_nonce` Override Edit Entry nonce validation. Return true to declare nonce valid.
1890
         * @since 1.13
1891
         * @param int|boolean $valid False if invalid; 1 or 2 when nonce was generated
1892
         * @param string $nonce_field Key used when validating submissions. Default: is_gv_edit_entry
1893
         */
1894
        $valid = apply_filters( 'gravityview/edit_entry/verify_nonce', $valid, self::$nonce_field );
1895
1896
        return $valid;
1897
    }
1898
1899
1900
1901
} //end class