Completed
Push — develop ( cabcaf...ec24a5 )
by Zack
24:31 queued 18:28
created

GravityView_Edit_Entry_Render::setup_vars()   A

Complexity

Conditions 1
Paths 1

Size

Total Lines 15
Code Lines 10

Duplication

Lines 0
Ratio 0 %

Code Coverage

Tests 11
CRAP Score 1

Importance

Changes 0
Metric Value
cc 1
eloc 10
nc 1
nop 0
dl 0
loc 15
ccs 11
cts 11
cp 1
crap 1
rs 9.4285
c 0
b 0
f 0
1
<?php
0 ignored issues
show
Coding Style Compatibility introduced by
For compatibility and reusability of your code, PSR1 recommends that a file should introduce either new symbols (like classes, functions, etc.) or have side-effects (like outputting something, or including other files), but not both at the same time. The first symbol is defined on line 16 and the first side effect is on line 13.

The PSR-1: Basic Coding Standard recommends that a file should either introduce new symbols, that is classes, functions, constants or similar, or have side effects. Side effects are anything that executes logic, like for example printing output, changing ini settings or writing to a file.

The idea behind this recommendation is that merely auto-loading a class should not change the state of an application. It also promotes a cleaner style of programming and makes your code less prone to errors, because the logic is not spread out all over the place.

To learn more about the PSR-1, please see the PHP-FIG site on the PSR-1.

Loading history...
2
/**
3
 * GravityView Edit Entry - render frontend
4
 *
5
 * @package   GravityView
6
 * @license   GPL2+
7
 * @author    Katz Web Services, Inc.
8
 * @link      http://gravityview.co
9
 * @copyright Copyright 2014, Katz Web Services, Inc.
10
 */
11
12
if ( ! defined( 'WPINC' ) ) {
13
    die;
14
}
15
16
class GravityView_Edit_Entry_Render {
17
18
    /**
19
     * @var GravityView_Edit_Entry
20
     */
21
    protected $loader;
22
23
	/**
24
	 * @var string String used to generate unique nonce for the entry/form/view combination. Allows access to edit page.
25
	 */
26
    static $nonce_key;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $nonce_key.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
27
28
	/**
29
	 * @since 1.9
30
	 * @var string String used for check valid edit entry form submission. Allows saving edit form values.
31
	 */
32
	private static $nonce_field = 'is_gv_edit_entry';
33
34
	/**
35
	 * @since 1.9
36
	 * @var bool Whether to allow save and continue functionality
37
	 */
38
	private static $supports_save_and_continue = false;
39
40
    /**
41
     * Gravity Forms entry array
42
     *
43
     * @var array
44
     */
45
    public $entry;
46
47
	/**
48
	 * Gravity Forms entry array (it won't get changed during this class lifecycle)
49
	 * @since 1.17.2
50
	 * @var array
51
	 */
52
	private static $original_entry = array();
53
54
    /**
55
     * Gravity Forms form array (GravityView modifies the content through this class lifecycle)
56
     *
57
     * @var array
58
     */
59
	public $form;
60
61
    /**
62
     * Gravity Forms form array (it won't get changed during this class lifecycle)
63
     * @since 1.16.2.1
64
     * @var array
65
     */
66
    private static $original_form;
67
68
    /**
69
     * Gravity Forms form array after the form validation process
70
     * @since 1.13
71
     * @var array
72
     */
73
	public $form_after_validation = null;
74
75
    /**
76
     * Hold an array of GF field objects that have calculation rules
77
     * @var array
78
     */
79
	public $fields_with_calculation = array();
80
81
    /**
82
     * Gravity Forms form id
83
     *
84
     * @var int
85
     */
86
	public $form_id;
87
88
    /**
89
     * ID of the current view
90
     *
91
     * @var int
92
     */
93
	public $view_id;
94
95
    /**
96
     * Updated entry is valid (GF Validation object)
97
     *
98
     * @var array
99
     */
100
	public $is_valid = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
101
102 1
    function __construct( GravityView_Edit_Entry $loader ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
103 1
        $this->loader = $loader;
104 1
    }
105
106 1
    function load() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
107
108
        /** @define "GRAVITYVIEW_DIR" "../../../" */
109 1
        include_once( GRAVITYVIEW_DIR .'includes/class-admin-approve-entries.php' );
110
111
        // Don't display an embedded form when editing an entry
112 1
        add_action( 'wp_head', array( $this, 'prevent_render_form' ) );
113 1
        add_action( 'wp_footer', array( $this, 'prevent_render_form' ) );
114
115
        // Stop Gravity Forms processing what is ours!
116 1
        add_filter( 'wp', array( $this, 'prevent_maybe_process_form'), 8 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
117
118 1
        add_filter( 'gravityview_is_edit_entry', array( $this, 'is_edit_entry') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
119
120 1
        add_action( 'gravityview_edit_entry', array( $this, 'init' ) );
121
122
        // Disable conditional logic if needed (since 1.9)
123 1
        add_filter( 'gform_has_conditional_logic', array( $this, 'manage_conditional_logic' ), 10, 2 );
124
125
        // Make sure GF doesn't validate max files (since 1.9)
126 1
        add_filter( 'gform_plupload_settings', array( $this, 'modify_fileupload_settings' ), 10, 3 );
127
128
        // Add fields expected by GFFormDisplay::validate()
129 1
        add_filter( 'gform_pre_validation', array( $this, 'gform_pre_validation') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
130
131 1
    }
132
133
    /**
134
     * Don't show any forms embedded on a page when GravityView is in Edit Entry mode
135
     *
136
     * Adds a `__return_empty_string` filter on the Gravity Forms shortcode on the `wp_head` action
137
     * And then removes it on the `wp_footer` action
138
     *
139
     * @since 1.16.1
140
     *
141
     * @return void
142
     */
143 1
    public function prevent_render_form() {
144 1
        if( $this->is_edit_entry() ) {
145 1
            if( 'wp_head' === current_filter() ) {
146 1
                add_filter( 'gform_shortcode_form', '__return_empty_string' );
147
            } else {
148 1
                remove_filter( 'gform_shortcode_form', '__return_empty_string' );
149
            }
150
        }
151 1
    }
152
153
    /**
154
     * Because we're mimicking being a front-end Gravity Forms form while using a Gravity Forms
155
     * backend form, we need to prevent them from saving twice.
156
     * @return void
157
     */
158
    public function prevent_maybe_process_form() {
159
160
        if( ! empty( $_POST ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
161
	        do_action( 'gravityview_log_debug', 'GravityView_Edit_Entry[prevent_maybe_process_form] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
162
        }
163
164
        if( $this->is_edit_entry_submission() ) {
165
            remove_action( 'wp',  array( 'RGForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
166
        }
167
    }
168
169
    /**
170
     * Is the current page an Edit Entry page?
171
     * @return boolean
172
     */
173 2
    public function is_edit_entry() {
174
175 2
        $is_edit_entry = GravityView_frontend::is_single_entry() && ! empty( $_GET['edit'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
176
177 2
        return ( $is_edit_entry || $this->is_edit_entry_submission() );
178
    }
179
180
	/**
181
	 * Is the current page an Edit Entry page?
182
	 * @since 1.9
183
	 * @return boolean
184
	 */
185 1
	public function is_edit_entry_submission() {
186 1
		return !empty( $_POST[ self::$nonce_field ] );
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
187
	}
188
189
    /**
190
     * When Edit entry view is requested setup the vars
191
     */
192 1
    private function setup_vars() {
193 1
        $gravityview_view = GravityView_View::getInstance();
194
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
195
196 1
        $entries = $gravityview_view->getEntries();
197 1
	    self::$original_entry = $entries[0];
198 1
	    $this->entry = $entries[0];
199
200 1
        self::$original_form = $gravityview_view->getForm();
201 1
        $this->form = $gravityview_view->getForm();
202 1
        $this->form_id = $gravityview_view->getFormId();
203 1
        $this->view_id = $gravityview_view->getViewId();
204
205 1
        self::$nonce_key = GravityView_Edit_Entry::get_nonce_key( $this->view_id, $this->form_id, $this->entry['id'] );
206 1
    }
207
208
209
    /**
210
     * Load required files and trigger edit flow
211
     *
212
     * Run when the is_edit_entry returns true.
213
     *
214
     * @param GravityView_View_Data $gv_data GravityView Data object
215
     * @return void
216
     */
217 2
    public function init( $gv_data ) {
218
219 2
        require_once( GFCommon::get_base_path() . '/form_display.php' );
220 2
        require_once( GFCommon::get_base_path() . '/entry_detail.php' );
221
222 2
        $this->setup_vars();
223
224
        // Multiple Views embedded, don't proceed if nonce fails
225 2
        if( $gv_data->has_multiple_views() && ! wp_verify_nonce( $_GET['edit'], self::$nonce_key ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
226
            do_action('gravityview_log_error', __METHOD__ . ': Nonce validation failed for the Edit Entry request; returning' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
227
            return;
228
        }
229
230
        // Sorry, you're not allowed here.
231 2
        if( false === $this->user_can_edit_entry( true ) ) {
232 1
            do_action('gravityview_log_error', __METHOD__ . ': User is not allowed to edit this entry; returning', $this->entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
233 1
            return;
234
        }
235
236 2
        $this->print_scripts();
237
238 2
        $this->process_save();
239
240 2
        $this->edit_entry_form();
241
242 2
    }
243
244
245
    /**
246
     * Force Gravity Forms to output scripts as if it were in the admin
247
     * @return void
248
     */
249 1
    private function print_scripts() {
250 1
        $gravityview_view = GravityView_View::getInstance();
251
252 1
        wp_register_script( 'gform_gravityforms', GFCommon::get_base_url().'/js/gravityforms.js', array( 'jquery', 'gform_json', 'gform_placeholder', 'sack', 'plupload-all', 'gravityview-fe-view' ) );
253
254 1
        GFFormDisplay::enqueue_form_scripts($gravityview_view->getForm(), false);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
255
256
        // Sack is required for images
257 1
        wp_print_scripts( array( 'sack', 'gform_gravityforms' ) );
258 1
    }
259
260
261
    /**
262
     * Process edit entry form save
263
     */
264 2
    private function process_save() {
265
266 2
        if( empty( $_POST ) || ! isset( $_POST['lid'] ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
267 2
            return;
268
        }
269
270
        // Make sure the entry, view, and form IDs are all correct
271 2
        $valid = $this->verify_nonce();
272
273 2
        if( !$valid ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
274
            do_action('gravityview_log_error', __METHOD__ . ' Nonce validation failed.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
275
            return;
276
        }
277
278 2
        if( $this->entry['id'] !== $_POST['lid'] ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
279
            do_action('gravityview_log_error', __METHOD__ . ' Entry ID did not match posted entry ID.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
280
            return;
281
        }
282
283 2
        do_action('gravityview_log_debug', __METHOD__ . ': $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
284
285 2
        $this->process_save_process_files( $this->form_id );
286
287 2
        $this->validate();
288
289 2
        if( $this->is_valid ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using ! empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
290
291 2
            do_action('gravityview_log_debug', __METHOD__ . ': Submission is valid.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
292
293
            /**
294
             * @hack This step is needed to unset the adminOnly from form fields, to add the calculation fields
295
             */
296 2
            $form = $this->form_prepare_for_save();
297
298
            /**
299
             * @hack to avoid the capability validation of the method save_lead for GF 1.9+
300
             */
301 2
            unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
302
303 2
            $date_created = $this->entry['date_created'];
304
305
            /**
306
             * @hack to force Gravity Forms to use $read_value_from_post in GFFormsModel::save_lead()
307
             * @since 1.17.2
308
             */
309 2
            unset( $this->entry['date_created'] );
310
311 2
            GFFormsModel::save_lead( $form, $this->entry );
312
313
	        // Delete the values for hidden inputs
314 2
	        $this->unset_hidden_field_values();
315
            
316 2
            $this->entry['date_created'] = $date_created;
317
318
            // Process calculation fields
319 2
            $this->update_calculation_fields();
320
321
            // Perform actions normally performed after updating a lead
322 2
            $this->after_update();
323
324
	        /**
325
             * Must be AFTER after_update()!
326
             * @see https://github.com/gravityview/GravityView/issues/764
327
             */
328 2
            $this->maybe_update_post_fields( $form );
329
330
            /**
331
             * @action `gravityview/edit_entry/after_update` Perform an action after the entry has been updated using Edit Entry
332
             * @param array $form Gravity Forms form array
333
             * @param string $entry_id Numeric ID of the entry that was updated
334
             * @param GravityView_Edit_Entry_Render $this This object
335
             */
336 2
            do_action( 'gravityview/edit_entry/after_update', $this->form, $this->entry['id'], $this );
337
338
        } else {
339
            do_action('gravityview_log_error', __METHOD__ . ': Submission is NOT valid.', $this->entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
340
        }
341
342 2
    } // process_save
343
344
	/**
345
	 * Delete the value of fields hidden by conditional logic when the entry is edited
346
     *
347
     * @uses GFFormsModel::update_lead_field_value()
348
     *
349
     * @since 1.17.4
350
     *
351
     * @return void
352
	 */
353 1
    private function unset_hidden_field_values() {
354 1
	    global $wpdb;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
355
356 1
	    $lead_detail_table      = GFFormsModel::get_lead_details_table_name();
357 1
	    $current_fields   = $wpdb->get_results( $wpdb->prepare( "SELECT id, field_number FROM $lead_detail_table WHERE lead_id=%d", $this->entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
358
359 1
	    foreach ( $this->entry as $input_id => $field_value ) {
360
361 1
		    $field = RGFormsModel::get_field( $this->form, $input_id );
362
363
		    // Reset fields that are hidden
364
		    // Don't pass $entry as fourth parameter; force using $_POST values to calculate conditional logic
365 1
		    if ( GFFormsModel::is_field_hidden( $this->form, $field, array(), NULL ) ) {
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
366
367
		        // List fields are stored as empty arrays when empty
368
			    $empty_value = $this->is_field_json_encoded( $field ) ? '[]' : '';
369
370
			    $lead_detail_id = GFFormsModel::get_lead_detail_id( $current_fields, $input_id );
371
372
			    GFFormsModel::update_lead_field_value( $this->form, $this->entry, $field, $lead_detail_id, $input_id, $empty_value );
373
374
			    // Prevent the $_POST values of hidden fields from being used as default values when rendering the form
375
                // after submission
376
			    $post_input_id = 'input_' . str_replace( '.', '_', $input_id );
377 1
			    $_POST[ $post_input_id ] = '';
378
		    }
379
	    }
380 1
    }
381
382
    /**
383
     * Have GF handle file uploads
384
     *
385
     * Copy of code from GFFormDisplay::process_form()
386
     *
387
     * @param int $form_id
388
     */
389 1
    private function process_save_process_files( $form_id ) {
390
391
        //Loading files that have been uploaded to temp folder
392 1
        $files = GFCommon::json_decode( stripslashes( RGForms::post( 'gform_uploaded_files' ) ) );
393 1
        if ( ! is_array( $files ) ) {
394 1
            $files = array();
395
        }
396
397 1
        RGFormsModel::$uploaded_files[ $form_id ] = $files;
398 1
    }
399
400
    /**
401
     * Remove max_files validation (done on gravityforms.js) to avoid conflicts with GravityView
402
     * Late validation done on self::custom_validation
403
     *
404
     * @param $plupload_init array Plupload settings
405
     * @param $form_id
406
     * @param $instance
407
     * @return mixed
408
     */
409
    public function modify_fileupload_settings( $plupload_init, $form_id, $instance ) {
0 ignored issues
show
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $instance is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
410
        if( ! $this->is_edit_entry() ) {
411
            return $plupload_init;
412
        }
413
414
        $plupload_init['gf_vars']['max_files'] = 0;
415
416
        return $plupload_init;
417
    }
418
419
420
    /**
421
     * Unset adminOnly and convert field input key to string
422
     * @return array $form
423
     */
424 1
    private function form_prepare_for_save() {
425
426 1
        $form = $this->form;
427
428
	    /** @var GF_Field $field */
429 1
        foreach( $form['fields'] as $k => &$field ) {
430
431
            /**
432
             * Remove the fields with calculation formulas before save to avoid conflicts with GF logic
433
             * @since 1.16.3
434
             * @var GF_Field $field
435
             */
436 1
            if( $field->has_calculation() ) {
437
                unset( $form['fields'][ $k ] );
438
            }
439
440 1
            $field->adminOnly = false;
441
442 1
            if( isset( $field->inputs ) && is_array( $field->inputs ) ) {
443
                foreach( $field->inputs as $key => $input ) {
444 1
                    $field->inputs[ $key ][ 'id' ] = (string)$input['id'];
0 ignored issues
show
introduced by
Array keys should NOT be surrounded by spaces if they only contain a string or an integer.
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
445
                }
446
            }
447
        }
448
449 1
        return $form;
450
    }
451
452 1
    private function update_calculation_fields() {
453
454 1
        $form = self::$original_form;
455 1
        $update = false;
456
457
        // get the most up to date entry values
458 1
        $entry = GFAPI::get_entry( $this->entry['id'] );
459
460 1
        if( !empty( $this->fields_with_calculation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
461
            $update = true;
462
            foreach ( $this->fields_with_calculation as $calc_field ) {
463
                $inputs = $calc_field->get_entry_inputs();
464
                if ( is_array( $inputs ) ) {
465
                    foreach ( $inputs as $input ) {
466
                        $input_name = 'input_' . str_replace( '.', '_', $input['id'] );
467
                        $entry[ strval( $input['id'] ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
468
                    }
469
                } else {
470
                    $input_name = 'input_' . str_replace( '.', '_', $calc_field->id);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
471
                    $entry[ strval( $calc_field->id ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
472
                }
473
            }
474
475
        }
476
477 1
        if( $update ) {
478
479
            $return_entry = GFAPI::update_entry( $entry );
480
481
            if( is_wp_error( $return_entry ) ) {
482
                do_action( 'gravityview_log_error', 'Updating the entry calculation fields failed', $return_entry );
483
            } else {
484
                do_action( 'gravityview_log_debug', 'Updating the entry calculation fields succeeded' );
485
            }
486
        }
487 1
    }
488
489
    /**
490
     * Handle updating the Post Image field
491
     *
492
     * Sets a new Featured Image if configured in Gravity Forms; otherwise uploads/updates media
493
     *
494
     * @since 1.17
495
     *
496
     * @uses GFFormsModel::media_handle_upload
497
     * @uses set_post_thumbnail
498
     * 
499
     * @param array $form GF Form array
500
     * @param GF_Field $field GF Field
501
     * @param string $field_id Numeric ID of the field
502
     * @param string $value
503
     * @param array $entry GF Entry currently being edited
504
     * @param int $post_id ID of the Post being edited
505
     *
506
     * @return mixed|string
507
     */
508
    private function update_post_image( $form, $field, $field_id, $value, $entry, $post_id ) {
509
510
        $input_name = 'input_' . $field_id;
511
512
        if ( !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
513
514
            // We have a new image
515
516
            $value = RGFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'] );
517
518
            $ary = ! empty( $value ) ? explode( '|:|', $value ) : array();
519
            $img_url = rgar( $ary, 0 );
520
521
            $img_title       = count( $ary ) > 1 ? $ary[1] : '';
522
            $img_caption     = count( $ary ) > 2 ? $ary[2] : '';
523
            $img_description = count( $ary ) > 3 ? $ary[3] : '';
524
525
            $image_meta = array(
526
                'post_excerpt' => $img_caption,
527
                'post_content' => $img_description,
528
            );
529
530
            //adding title only if it is not empty. It will default to the file name if it is not in the array
531
            if ( ! empty( $img_title ) ) {
532
                $image_meta['post_title'] = $img_title;
533
            }
534
535
            /**
536
             * todo: As soon as \GFFormsModel::media_handle_upload becomes a public method, move this call to \GFFormsModel::media_handle_upload and remove the hack from this class.
537
             * Note: the method became public in GF 1.9.17.7, but we don't require that version yet.
538
             */
539
            require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
540
            $media_id = GravityView_GFFormsModel::media_handle_upload( $img_url, $post_id, $image_meta );
541
542
            // is this field set as featured image?
543
            if ( $media_id && $field->postFeaturedImage ) {
544
                set_post_thumbnail( $post_id, $media_id );
545
            }
546
547
        } elseif ( !empty( $_POST[ $input_name ] ) && is_array( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
548
549
            // Same image although the image title, caption or description might have changed
550
551
            $ary = array();
552
            if( ! empty( $entry[ $field_id ] ) ) {
553
                $ary = is_array( $entry[ $field_id ] ) ? $entry[ $field_id ] : explode( '|:|', $entry[ $field_id ] );
554
            }
555
            $img_url = rgar( $ary, 0 );
556
557
            // is this really the same image or something went wrong ?
558
            if( $img_url === $_POST[ $input_name ] ) {
559
560
                $img_title       = rgar( $value, $field_id .'.1' );
561
                $img_caption     = rgar( $value, $field_id .'.4' );
562
                $img_description = rgar( $value, $field_id .'.7' );
563
564
                $value = ! empty( $img_url ) ? $img_url . "|:|" . $img_title . "|:|" . $img_caption . "|:|" . $img_description : '';
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal |:| does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
565
566
                if ( $field->postFeaturedImage ) {
567
568
                    $image_meta = array(
569
                        'ID' => get_post_thumbnail_id( $post_id ),
570
                        'post_title' => $img_title,
571
                        'post_excerpt' => $img_caption,
572
                        'post_content' => $img_description,
573
                    );
574
575
                    // update image title, caption or description
576
                    wp_update_post( $image_meta );
577
                }
578
            }
579
580
        } else {
581
582
            // if we get here, image was removed or not set.
583
            $value = '';
584
585
            if ( $field->postFeaturedImage ) {
586
                delete_post_thumbnail( $post_id );
587
            }
588
        }
589
590
        return $value;
591
    }
592
593
    /**
594
     * Loop through the fields being edited and if they include Post fields, update the Entry's post object
595
     *
596
     * @param array $form Gravity Forms form
597
     *
598
     * @return void
599
     */
600 1
    private function maybe_update_post_fields( $form ) {
601
602 1
        if( empty( $this->entry['post_id'] ) ) {
603 1
	        do_action( 'gravityview_log_debug', __METHOD__ . ': This entry has no post fields. Continuing...' );
604 1
            return;
605
        }
606
607
        $post_id = $this->entry['post_id'];
608
609
        // Security check
610
        if( false === GVCommon::has_cap( 'edit_post', $post_id ) ) {
611
            do_action( 'gravityview_log_error', 'The current user does not have the ability to edit Post #'.$post_id );
612
            return;
613
        }
614
615
        $update_entry = false;
616
617
        $updated_post = $original_post = get_post( $post_id );
618
619
        foreach ( $this->entry as $field_id => $value ) {
620
621
            $field = RGFormsModel::get_field( $form, $field_id );
622
623
            if( ! $field ) {
624
                continue;
625
            }
626
627
            if( GFCommon::is_post_field( $field ) && 'post_category' !== $field->type ) {
628
629
                // Get the value of the field, including $_POSTed value
630
                $value = RGFormsModel::get_field_value( $field );
631
632
                // Use temporary entry variable, to make values available to fill_post_template() and update_post_image()
633
                $entry_tmp = $this->entry;
634
                $entry_tmp["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
635
636
                switch( $field->type ) {
637
638
                    case 'post_title':
639
                        $post_title = $value;
640
                        if( rgar( $form, 'postTitleTemplateEnabled' ) ) {
641
                            $post_title = $this->fill_post_template( $form['postTitleTemplate'], $form, $entry_tmp );
642
                        }
643
                        $updated_post->post_title = $post_title;
644
                        $updated_post->post_name  = $post_title;
645
                        unset( $post_title );
646
                        break;
647
648
                    case 'post_content':
649
                        $post_content = $value;
650
                        if( rgar( $form, 'postContentTemplateEnabled' ) ) {
651
                            $post_content = $this->fill_post_template( $form['postContentTemplate'], $form, $entry_tmp, true );
652
                        }
653
                        $updated_post->post_content = $post_content;
654
                        unset( $post_content );
655
                        break;
656
                    case 'post_excerpt':
657
                        $updated_post->post_excerpt = $value;
658
                        break;
659
                    case 'post_tags':
660
                        wp_set_post_tags( $post_id, $value, false );
661
                        break;
662
                    case 'post_category':
663
                        break;
664
                    case 'post_custom_field':
665
                        if( ! empty( $field->customFieldTemplateEnabled ) ) {
666
                            $value = $this->fill_post_template( $field->customFieldTemplate, $form, $entry_tmp, true );
667
                        }
668
669
	                    if ( $this->is_field_json_encoded( $field ) && ! is_string( $value ) ) {
670
		                    $value = function_exists('wp_json_encode') ? wp_json_encode( $value ) : json_encode( $value );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
671
	                    }
672
673
                        update_post_meta( $post_id, $field->postCustomFieldName, $value );
674
                        break;
675
676
                    case 'post_image':
677
                        $value = $this->update_post_image( $form, $field, $field_id, $value, $this->entry, $post_id );
678
                        break;
679
680
                }
681
682
                // update entry after
683
                $this->entry["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
684
685
                $update_entry = true;
686
687
                unset( $entry_tmp );
688
            }
689
690
        }
691
692
        if( $update_entry ) {
693
694
            $return_entry = GFAPI::update_entry( $this->entry );
695
696
            if( is_wp_error( $return_entry ) ) {
697
               do_action( 'gravityview_log_error', 'Updating the entry post fields failed', array( '$this->entry' => $this->entry, '$return_entry' => $return_entry ) );
698
            } else {
699
                do_action( 'gravityview_log_debug', 'Updating the entry post fields for post #'.$post_id.' succeeded' );
700
            }
701
702
        }
703
704
        $return_post = wp_update_post( $updated_post, true );
705
706
        if( is_wp_error( $return_post ) ) {
707
            $return_post->add_data( $updated_post, '$updated_post' );
708
            do_action( 'gravityview_log_error', 'Updating the post content failed', compact( 'updated_post', 'return_post' ) );
709
        } else {
710
            do_action( 'gravityview_log_debug', 'Updating the post content for post #'.$post_id.' succeeded', $updated_post );
711
        }
712
    }
713
714
	/**
715
     * Is the field stored in a JSON-encoded manner?
716
     *
717
	 * @param GF_Field $field
718
	 *
719
	 * @return bool True: stored in DB json_encode()'d; False: not encoded
720
	 */
721
    private function is_field_json_encoded( $field ) {
722
723
	    $json_encoded = false;
724
725
        $input_type = RGFormsModel::get_input_type( $field );
726
727
	    // Only certain custom field types are supported
728
	    switch( $input_type ) {
729
		    case 'fileupload':
730
		    case 'list':
731
		    case 'multiselect':
732
			    $json_encoded = true;
733
			    break;
734
	    }
735
736
	    return $json_encoded;
737
    }
738
739
    /**
740
     * Convert a field content template into prepared output
741
     *
742
     * @uses GravityView_GFFormsModel::get_post_field_images()
743
     *
744
     * @since 1.17
745
     *
746
     * @param string $template The content template for the field
747
     * @param array $form Gravity Forms form
748
     * @param bool $do_shortcode Whether to process shortcode inside content. In GF, only run on Custom Field and Post Content fields
749
     *
750
     * @return string
751
     */
752
    private function fill_post_template( $template, $form, $entry, $do_shortcode = false ) {
753
754
        require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
755
756
        $post_images = GravityView_GFFormsModel::get_post_field_images( $form, $entry );
757
758
        //replacing post image variables
759
        $output = GFCommon::replace_variables_post_image( $template, $post_images, $entry );
760
761
        //replacing all other variables
762
        $output = GFCommon::replace_variables( $output, $form, $entry, false, false, false );
763
764
        // replace conditional shortcodes
765
        if( $do_shortcode ) {
766
            $output = do_shortcode( $output );
767
        }
768
769
        return $output;
770
    }
771
772
773
    /**
774
     * Perform actions normally performed after updating a lead
775
     *
776
     * @since 1.8
777
     *
778
     * @see GFEntryDetail::lead_detail_page()
779
     *
780
     * @return void
781
     */
782 1
    private function after_update() {
783
784 1
        do_action( 'gform_after_update_entry', $this->form, $this->entry['id'], self::$original_entry );
785 1
        do_action( "gform_after_update_entry_{$this->form['id']}", $this->form, $this->entry['id'], self::$original_entry );
786
787
        // Re-define the entry now that we've updated it.
788 1
        $entry = RGFormsModel::get_lead( $this->entry['id'] );
789
790 1
        $entry = GFFormsModel::set_entry_meta( $entry, $this->form );
791
792
        // We need to clear the cache because Gravity Forms caches the field values, which
793
        // we have just updated.
794 1
        foreach ($this->form['fields'] as $key => $field) {
0 ignored issues
show
introduced by
No space after opening parenthesis is prohibited
Loading history...
introduced by
No space before closing parenthesis is prohibited
Loading history...
795 1
            GFFormsModel::refresh_lead_field_value( $entry['id'], $field->id );
796
        }
797
798 1
        $this->entry = $entry;
799 1
    }
800
801
802
    /**
803
     * Display the Edit Entry form
804
     *
805
     * @return void
806
     */
807 1
    public function edit_entry_form() {
808
809
        ?>
810
811
        <div class="gv-edit-entry-wrapper"><?php
812
813 1
            $javascript = gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/inline-javascript.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
814
815
            /**
816
             * Fixes weird wpautop() issue
817
             * @see https://github.com/katzwebservices/GravityView/issues/451
818
             */
819 1
            echo gravityview_strip_whitespace( $javascript );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'gravityview_strip_whitespace'
Loading history...
820
821
            ?><h2 class="gv-edit-entry-title">
822
                <span><?php
823
824
                    /**
825
                     * @filter `gravityview_edit_entry_title` Modify the edit entry title
826
                     * @param string $edit_entry_title Modify the "Edit Entry" title
827
                     * @param GravityView_Edit_Entry_Render $this This object
828
                     */
829 1
                    $edit_entry_title = apply_filters('gravityview_edit_entry_title', __('Edit Entry', 'gravityview'), $this );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
830
831 1
                    echo esc_attr( $edit_entry_title );
832
            ?></span>
833
            </h2>
834
835
            <?php $this->maybe_print_message(); ?>
836
837
            <?php // The ID of the form needs to be `gform_{form_id}` for the pluploader ?>
838
839
            <form method="post" id="gform_<?php echo $this->form_id; ?>" enctype="multipart/form-data">
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$this'
Loading history...
840
841
                <?php
842
843 1
                wp_nonce_field( self::$nonce_key, self::$nonce_key );
844
845 1
                wp_nonce_field( self::$nonce_field, self::$nonce_field, false );
846
847
                // Print the actual form HTML
848 1
                $this->render_edit_form();
849
850
                ?>
851
            </form>
852
853
            <script>
854
                gform.addFilter('gform_reset_pre_conditional_logic_field_action', function ( reset, formId, targetId, defaultValues, isInit ) {
855
                    return false;
856
                });
857
            </script>
858
859
        </div>
860
861
    <?php
862 1
    }
863
864
    /**
865
     * Display success or error message if the form has been submitted
866
     *
867
     * @uses GVCommon::generate_notice
868
     *
869
     * @since 1.16.2.2
870
     *
871
     * @return void
872
     */
873 1
    private function maybe_print_message() {
874
875 1
        if( rgpost('action') === 'update' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
876
877
            $back_link = esc_url( remove_query_arg( array( 'page', 'view', 'edit' ) ) );
878
879
            if( ! $this->is_valid ){
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
880
881
                // Keeping this compatible with Gravity Forms.
882
                $validation_message = "<div class='validation_error'>" . __('There was a problem with your submission.', 'gravityview') . " " . __('Errors have been highlighted below.', 'gravityview') . "</div>";
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw '__'
Loading history...
Coding Style Comprehensibility introduced by
The string literal </div> does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
883
                $message = apply_filters("gform_validation_message_{$this->form['id']}", apply_filters("gform_validation_message", $validation_message, $this->form), $this->form);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal gform_validation_message does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
884
885
                echo GVCommon::generate_notice( $message , 'gv-error' );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
886
887
            } else {
888
                $entry_updated_message = sprintf( esc_attr__('Entry Updated. %sReturn to Entry%s', 'gravityview'), '<a href="'. $back_link .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
889
890
                /**
891
                 * @filter `gravityview/edit_entry/success` Modify the edit entry success message (including the anchor link)
892
                 * @since 1.5.4
893
                 * @param string $entry_updated_message Existing message
894
                 * @param int $view_id View ID
895
                 * @param array $entry Gravity Forms entry array
896
                 * @param string $back_link URL to return to the original entry. @since 1.6
897
                 */
898
                $message = apply_filters( 'gravityview/edit_entry/success', $entry_updated_message , $this->view_id, $this->entry, $back_link );
899
900
                echo GVCommon::generate_notice( $message );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
901
            }
902
903
        }
904 1
    }
905
906
    /**
907
     * Display the Edit Entry form in the original Gravity Forms format
908
     *
909
     * @since 1.9
910
     *
911
     * @return void
912
     */
913 1
    private function render_edit_form() {
914
915
        /**
916
         * @action `gravityview/edit-entry/render/before` Before rendering the Edit Entry form
917
         * @since 1.17
918
         * @param GravityView_Edit_Entry_Render $this
919
         */
920 1
        do_action( 'gravityview/edit-entry/render/before', $this );
921
922 1
        add_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields'), 5000, 3 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
923 1
        add_filter( 'gform_submit_button', array( $this, 'render_form_buttons') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
924 1
        add_filter( 'gform_disable_view_counter', '__return_true' );
925
926 1
        add_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5, 5 );
927 1
        add_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10, 5 );
928
929
        // We need to remove the fake $_GET['page'] arg to avoid rendering form as if in admin.
930 1
        unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
931
932
        // TODO: Verify multiple-page forms
933
934 1
        ob_start(); // Prevent PHP warnings possibly caused by prefilling list fields for conditional logic
935
936 1
        $html = GFFormDisplay::get_form( $this->form['id'], false, false, true, $this->entry );
937
938 1
        ob_get_clean();
939
940 1
	    remove_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields' ), 5000 );
941 1
        remove_filter( 'gform_submit_button', array( $this, 'render_form_buttons' ) );
942 1
        remove_filter( 'gform_disable_view_counter', '__return_true' );
943 1
        remove_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5 );
944 1
        remove_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10 );
945
946 1
        echo $html;
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$html'
Loading history...
947
948
        /**
949
         * @action `gravityview/edit-entry/render/after` After rendering the Edit Entry form
950
         * @since 1.17
951
         * @param GravityView_Edit_Entry_Render $this
952
         */
953 1
        do_action( 'gravityview/edit-entry/render/after', $this );
954 1
    }
955
956
    /**
957
     * Display the Update/Cancel/Delete buttons for the Edit Entry form
958
     * @since 1.8
959
     * @return string
960
     */
961 1
    public function render_form_buttons() {
962 1
        return gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/form-buttons.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
963
    }
964
965
966
    /**
967
     * Modify the form fields that are shown when using GFFormDisplay::get_form()
968
     *
969
     * By default, all fields will be shown. We only want the Edit Tab configured fields to be shown.
970
     *
971
     * @param array $form
972
     * @param boolean $ajax Whether in AJAX mode
973
     * @param array|string $field_values Passed parameters to the form
974
     *
975
     * @since 1.9
976
     *
977
     * @return array Modified form array
978
     */
979 1
    public function filter_modify_form_fields( $form, $ajax = false, $field_values = '' ) {
0 ignored issues
show
Unused Code introduced by
The parameter $ajax is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $field_values is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
980
981
        // In case we have validated the form, use it to inject the validation results into the form render
982 1
        if( isset( $this->form_after_validation ) ) {
983 1
            $form = $this->form_after_validation;
984
        } else {
985 1
            $form['fields'] = $this->get_configured_edit_fields( $form, $this->view_id );
986
        }
987
988 1
        $form = $this->filter_conditional_logic( $form );
989
990 1
        $form = $this->prefill_conditional_logic( $form );
991
992
        // for now we don't support Save and Continue feature.
993 1
        if( ! self::$supports_save_and_continue ) {
994 1
	        unset( $form['save'] );
995
        }
996
997 1
        return $form;
998
    }
999
1000
    /**
1001
     * When displaying a field, check if it's a Post Field, and if so, make sure the post exists and current user has edit rights.
1002
     *
1003
     * @since 1.16.2.2
1004
     *
1005
     * @param string $field_content Always empty. Returning not-empty overrides the input.
1006
     * @param GF_Field $field
1007
     * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1008
     * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1009
     * @param int $form_id Form ID
1010
     *
1011
     * @return string If error, the error message. If no error, blank string (modify_edit_field_input() runs next)
1012
     */
1013 1
    public function verify_user_can_edit_post( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1014
1015 1
        if( GFCommon::is_post_field( $field ) ) {
1016
1017
            $message = null;
1018
1019
            // First, make sure they have the capability to edit the post.
1020
            if( false === current_user_can( 'edit_post', $this->entry['post_id'] ) ) {
1021
1022
                /**
1023
                 * @filter `gravityview/edit_entry/unsupported_post_field_text` Modify the message when someone isn't able to edit a post
1024
                 * @param string $message The existing "You don't have permission..." text
1025
                 */
1026
                $message = apply_filters('gravityview/edit_entry/unsupported_post_field_text', __('You don&rsquo;t have permission to edit this post.', 'gravityview') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1027
1028
            } elseif( null === get_post( $this->entry['post_id'] ) ) {
1029
                /**
1030
                 * @filter `gravityview/edit_entry/no_post_text` Modify the message when someone is editing an entry attached to a post that no longer exists
1031
                 * @param string $message The existing "This field is not editable; the post no longer exists." text
1032
                 */
1033
                $message = apply_filters('gravityview/edit_entry/no_post_text', __('This field is not editable; the post no longer exists.', 'gravityview' ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1034
            }
1035
1036
            if( $message ) {
1037
                $field_content = sprintf('<div class="ginput_container ginput_container_' . $field->type . '">%s</div>', wpautop( $message ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1038
            }
1039
        }
1040
1041 1
        return $field_content;
1042
    }
1043
1044
    /**
1045
     *
1046
     * Fill-in the saved values into the form inputs
1047
     *
1048
     * @param string $field_content Always empty. Returning not-empty overrides the input.
1049
     * @param GF_Field $field
1050
     * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1051
     * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1052
     * @param int $form_id Form ID
1053
     *
1054
     * @return mixed
1055
     */
1056 1
    public function modify_edit_field_input( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1057
1058 1
        $gv_field = GravityView_Fields::get_associated_field( $field );
1059
1060
        // If the form has been submitted, then we don't need to pre-fill the values,
1061
        // Except for fileupload type and when a field input is overridden- run always!!
1062
        if(
1063 1
            ( $this->is_edit_entry_submission() && !in_array( $field->type, array( 'fileupload', 'post_image' ) ) )
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1064 1
            && false === ( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) )
1065
            && ! GFCommon::is_product_field( $field->type )
1066 1
            || ! empty( $field_content )
1067 1
            || in_array( $field->type, array( 'honeypot' ) )
1068
        ) {
1069
	        return $field_content;
1070
        }
1071
1072
        // SET SOME FIELD DEFAULTS TO PREVENT ISSUES
1073 1
        $field->adminOnly = false; /** @see GFFormDisplay::get_counter_init_script() need to prevent adminOnly */
1074
1075 1
        $field_value = $this->get_field_value( $field );
1076
1077
	    // Prevent any PHP warnings, like undefined index
1078 1
	    ob_start();
1079
1080 1
	    $return = null;
1081
1082
        /** @var GravityView_Field $gv_field */
1083 1
        if( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) ) {
1084
            $return = $gv_field->get_field_input( $this->form, $field_value, $this->entry, $field );
1085
        } else {
1086 1
	        $return = $field->get_field_input( $this->form, $field_value, $this->entry );
1087
	    }
1088
1089
	    // If there was output, it's an error
1090 1
	    $warnings = ob_get_clean();
1091
1092 1
	    if( !empty( $warnings ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1093
		    do_action( 'gravityview_log_error', __METHOD__ . $warnings, $field_value );
1094
	    }
1095
1096 1
        return $return;
1097
    }
1098
1099
    /**
1100
     * Modify the value for the current field input
1101
     *
1102
     * @param GF_Field $field
1103
     *
1104
     * @return array|mixed|string
1105
     */
1106 1
    private function get_field_value( $field ) {
1107
1108
        /**
1109
         * @filter `gravityview/edit_entry/pre_populate/override` Allow the pre-populated value to override saved value in Edit Entry form. By default, pre-populate mechanism only kicks on empty fields.
1110
         * @param boolean True: override saved values; False: don't override (default)
1111
         * @param $field GF_Field object Gravity Forms field object
1112
         * @since 1.13
1113
         */
1114 1
        $override_saved_value = apply_filters( 'gravityview/edit_entry/pre_populate/override', false, $field );
1115
1116
        // We're dealing with multiple inputs (e.g. checkbox) but not time or date (as it doesn't store data in input IDs)
1117 1
        if( isset( $field->inputs ) && is_array( $field->inputs ) && !in_array( $field->type, array( 'time', 'date' ) ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1118
1119
            $field_value = array();
1120
1121
            // only accept pre-populated values if the field doesn't have any choice selected.
1122
            $allow_pre_populated = $field->allowsPrepopulate;
1123
1124
            foreach ( (array)$field->inputs as $input ) {
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1125
1126
                $input_id = strval( $input['id'] );
1127
                
1128
                if ( isset( $this->entry[ $input_id ] ) && ! gv_empty( $this->entry[ $input_id ], false, false ) ) {
1129
                    $field_value[ $input_id ] =  'post_category' === $field->type ? GFCommon::format_post_category( $this->entry[ $input_id ], true ) : $this->entry[ $input_id ];
0 ignored issues
show
introduced by
Expected 1 space after "="; 2 found
Loading history...
1130
                    $allow_pre_populated = false;
1131
                }
1132
1133
            }
1134
1135
            $pre_value = $field->get_value_submission( array(), false );
1136
1137
            $field_value = ! $allow_pre_populated && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $field_value : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1138
1139
        } else {
1140
1141 1
            $id = intval( $field->id );
1142
1143
            // get pre-populated value if exists
1144 1
            $pre_value = $field->allowsPrepopulate ? GFFormsModel::get_parameter_value( $field->inputName, array(), $field ) : '';
1145
1146
            // saved field entry value (if empty, fallback to the pre-populated value, if exists)
1147
            // or pre-populated value if not empty and set to override saved value
1148 1
            $field_value = !gv_empty( $this->entry[ $id ], false, false ) && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $this->entry[ $id ] : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1149
1150
            // in case field is post_category but inputType is select, multi-select or radio, convert value into array of category IDs.
1151 1
            if ( 'post_category' === $field->type && !gv_empty( $field_value, false, false ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1152
                $categories = array();
1153
                foreach ( explode( ',', $field_value ) as $cat_string ) {
1154
                    $categories[] = GFCommon::format_post_category( $cat_string, true );
1155
                }
1156
                $field_value = 'multiselect' === $field->get_input_type() ? $categories : implode( '', $categories );
1157
            }
1158
1159
        }
1160
1161
        // if value is empty get the default value if defined
1162 1
        $field_value = $field->get_value_default_if_empty( $field_value );
1163
1164
	    /**
1165
	     * @filter `gravityview/edit_entry/field_value` Change the value of an Edit Entry field, if needed
1166
	     * @since 1.11
1167
	     * @since 1.20 Added third param
1168
	     * @param mixed $field_value field value used to populate the input
1169
	     * @param object $field Gravity Forms field object ( Class GF_Field )
1170
	     * @param GravityView_Edit_Entry_Render $this Current object
1171
	     */
1172 1
	    $field_value = apply_filters( 'gravityview/edit_entry/field_value', $field_value, $field, $this );
1173
1174
	    /**
1175
	     * @filter `gravityview/edit_entry/field_value_{field_type}` Change the value of an Edit Entry field for a specific field type
1176
	     * @since 1.17
1177
	     * @since 1.20 Added third param
1178
	     * @param mixed $field_value field value used to populate the input
1179
	     * @param GF_Field $field Gravity Forms field object
1180
	     * @param GravityView_Edit_Entry_Render $this Current object
1181
	     */
1182 1
	    $field_value = apply_filters( 'gravityview/edit_entry/field_value_' . $field->type , $field_value, $field, $this );
1183
1184 1
        return $field_value;
1185
    }
1186
1187
1188
    // ---- Entry validation
1189
1190
    /**
1191
     * Add field keys that Gravity Forms expects.
1192
     *
1193
     * @see GFFormDisplay::validate()
1194
     * @param  array $form GF Form
1195
     * @return array       Modified GF Form
1196
     */
1197 1
    public function gform_pre_validation( $form ) {
1198
1199 1
        if( ! $this->verify_nonce() ) {
1200
            return $form;
1201
        }
1202
1203
        // Fix PHP warning regarding undefined index.
1204 1
        foreach ( $form['fields'] as &$field) {
0 ignored issues
show
introduced by
No space before closing parenthesis is prohibited
Loading history...
1205
1206
            // This is because we're doing admin form pretending to be front-end, so Gravity Forms
1207
            // expects certain field array items to be set.
1208 1
            foreach ( array( 'noDuplicates', 'adminOnly', 'inputType', 'isRequired', 'enablePrice', 'inputs', 'allowedExtensions' ) as $key ) {
1209 1
	            $field->{$key} = isset( $field->{$key} ) ? $field->{$key} : NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1210
            }
1211
1212 1
            switch( RGFormsModel::get_input_type( $field ) ) {
1213
1214
                /**
1215
                 * this whole fileupload hack is because in the admin, Gravity Forms simply doesn't update any fileupload field if it's empty, but it DOES in the frontend.
1216
                 *
1217
                 * What we have to do is set the value so that it doesn't get overwritten as empty on save and appears immediately in the Edit Entry screen again.
1218
                 *
1219
                 * @hack
1220
                 */
1221 1
                case 'fileupload':
1222
1223
                    // Set the previous value
1224
                    $entry = $this->get_entry();
1225
1226
                    $input_name = 'input_'.$field->id;
1227
                    $form_id = $form['id'];
1228
1229
                    $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1230
1231
                    // Use the previous entry value as the default.
1232
                    if( isset( $entry[ $field->id ] ) ) {
1233
                        $value = $entry[ $field->id ];
1234
                    }
1235
1236
                    // If this is a single upload file
1237
                    if( !empty( $_FILES[ $input_name ] ) && !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1238
                        $file_path = GFFormsModel::get_file_upload_path( $form['id'], $_FILES[ $input_name ]['name'] );
1239
                        $value = $file_path['url'];
1240
1241
                    } else {
1242
1243
                        // Fix PHP warning on line 1498 of form_display.php for post_image fields
1244
                        // Fix PHP Notice:  Undefined index:  size in form_display.php on line 1511
1245
                        $_FILES[ $input_name ] = array('name' => '', 'size' => '' );
0 ignored issues
show
introduced by
No space after opening parenthesis of array is bad style
Loading history...
1246
1247
                    }
1248
1249
                    if( rgar($field, "multipleFiles") ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal multipleFiles does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1250
1251
                        // If there are fresh uploads, process and merge them.
1252
                        // Otherwise, use the passed values, which should be json-encoded array of URLs
1253
                        if( isset( GFFormsModel::$uploaded_files[$form_id][$input_name] ) ) {
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1254
                            $value = empty( $value ) ? '[]' : $value;
1255
                            $value = stripslashes_deep( $value );
1256
                            $value = GFFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'], array());
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1257
                        }
1258
1259
                    } else {
1260
1261
                        // A file already exists when editing an entry
1262
                        // We set this to solve issue when file upload fields are required.
1263
                        GFFormsModel::$uploaded_files[ $form_id ][ $input_name ] = $value;
1264
1265
                    }
1266
1267
                    $this->entry[ $input_name ] = $value;
1268
                    $_POST[ $input_name ] = $value;
1269
1270
                    break;
1271
1272 1
                case 'number':
1273
                    // Fix "undefined index" issue at line 1286 in form_display.php
1274 1
                    if( !isset( $_POST['input_'.$field->id ] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1275
                        $_POST['input_'.$field->id ] = NULL;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1276
                    }
1277 1
                    break;
1278
            }
1279
1280
        }
1281
1282 1
        return $form;
1283
    }
1284
1285
1286
    /**
1287
     * Process validation for a edit entry submission
1288
     *
1289
     * Sets the `is_valid` object var
1290
     *
1291
     * @return void
1292
     */
1293 2
    private function validate() {
1294
1295
        /**
1296
         * If using GF User Registration Add-on, remove the validation step, otherwise generates error when updating the entry
1297
         * GF User Registration Add-on version > 3.x has a different class name
1298
         * @since 1.16.2
1299
         */
1300 2
        if ( class_exists( 'GF_User_Registration' ) ) {
1301 2
            remove_filter( 'gform_validation', array( GF_User_Registration::get_instance(), 'validate' ) );
1302
        } else  if ( class_exists( 'GFUser' ) ) {
1303
            remove_filter( 'gform_validation', array( 'GFUser', 'user_registration_validation' ) );
1304
        }
1305
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1306
1307
        /**
1308
         * For some crazy reason, Gravity Forms doesn't validate Edit Entry form submissions.
1309
         * You can enter whatever you want!
1310
         * We try validating, and customize the results using `self::custom_validation()`
1311
         */
1312 2
        add_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10, 4);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1313
1314
        // Needed by the validate funtion
1315 2
        $failed_validation_page = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1316 2
        $field_values = RGForms::post( 'gform_field_values' );
1317
1318
        // Prevent entry limit from running when editing an entry, also
1319
        // prevent form scheduling from preventing editing
1320 2
        unset( $this->form['limitEntries'], $this->form['scheduleForm'] );
1321
1322
        // Hide fields depending on Edit Entry settings
1323 2
        $this->form['fields'] = $this->get_configured_edit_fields( $this->form, $this->view_id );
1324
1325 2
        $this->is_valid = GFFormDisplay::validate( $this->form, $field_values, 1, $failed_validation_page );
1326
1327 2
        remove_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10 );
1328 2
    }
1329
1330
1331
    /**
1332
     * Make validation work for Edit Entry
1333
     *
1334
     * Because we're calling the GFFormDisplay::validate() in an unusual way (as a front-end
1335
     * form pretending to be a back-end form), validate() doesn't know we _can't_ edit post
1336
     * fields. This goes through all the fields and if they're an invalid post field, we
1337
     * set them as valid. If there are still issues, we'll return false.
1338
     *
1339
     * @param  [type] $validation_results [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1340
     * @return [type]                     [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1341
     */
1342 2
    public function custom_validation( $validation_results ) {
1343
1344 2
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results: ', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1345
1346 2
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
1347
1348 2
        $gv_valid = true;
1349
1350 2
        foreach ( $validation_results['form']['fields'] as $key => &$field ) {
1351
1352 2
            $value = RGFormsModel::get_field_value( $field );
1353 2
            $field_type = RGFormsModel::get_input_type( $field );
1354
1355
            // Validate always
1356
            switch ( $field_type ) {
1357
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1358
1359 2
                case 'fileupload' :
1360 2
                case 'post_image':
1361
1362
                    // in case nothing is uploaded but there are already files saved
1363
                    if( !empty( $field->failed_validation ) && !empty( $field->isRequired ) && !empty( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1364
                        $field->failed_validation = false;
1365
                        unset( $field->validation_message );
1366
                    }
1367
1368
                    // validate if multi file upload reached max number of files [maxFiles] => 2
1369
                    if( rgobj( $field, 'maxFiles') && rgobj( $field, 'multipleFiles') ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1370
1371
                        $input_name = 'input_' . $field->id;
1372
                        //uploaded
1373
                        $file_names = isset( GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] ) ? GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] : array();
1374
1375
                        //existent
1376
                        $entry = $this->get_entry();
1377
                        $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1378
                        if( isset( $entry[ $field->id ] ) ) {
1379
                            $value = json_decode( $entry[ $field->id ], true );
1380
                        }
1381
1382
                        // count uploaded files and existent entry files
1383
                        $count_files = count( $file_names ) + count( $value );
1384
1385
                        if( $count_files > $field->maxFiles ) {
1386
                            $field->validation_message = __( 'Maximum number of files reached', 'gravityview' );
1387
                            $field->failed_validation = 1;
1388
                            $gv_valid = false;
1389
1390
                            // in case of error make sure the newest upload files are removed from the upload input
1391
                            GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ] = null;
1392
                        }
1393
1394
                    }
1395
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1396
1397
                    break;
1398
1399
            }
1400
1401
            // This field has failed validation.
1402 2
            if( !empty( $field->failed_validation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1403
1404 1
                do_action( 'gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field is invalid.', array( 'field' => $field, 'value' => $value ) );
1405
1406
                switch ( $field_type ) {
1407
1408
                    // Captchas don't need to be re-entered.
1409 1
                    case 'captcha':
1410
1411
                        // Post Image fields aren't editable, so we un-fail them.
1412 1
                    case 'post_image':
1413
                        $field->failed_validation = false;
1414
                        unset( $field->validation_message );
1415
                        break;
1416
1417
                }
1418
1419
                // You can't continue inside a switch, so we do it after.
1420 1
                if( empty( $field->failed_validation ) ) {
1421
                    continue;
1422
                }
1423
1424
                // checks if the No Duplicates option is not validating entry against itself, since
1425
                // we're editing a stored entry, it would also assume it's a duplicate.
1426 1
                if( !empty( $field->noDuplicates ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1427
1428
                    $entry = $this->get_entry();
1429
1430
                    // If the value of the entry is the same as the stored value
1431
                    // Then we can assume it's not a duplicate, it's the same.
1432
                    if( !empty( $entry ) && $value == $entry[ $field->id ] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1433
                        //if value submitted was not changed, then don't validate
1434
                        $field->failed_validation = false;
1435
1436
                        unset( $field->validation_message );
1437
1438
                        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field not a duplicate; it is the same entry.', $entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1439
1440
                        continue;
1441
                    }
1442
                }
1443
1444
                // if here then probably we are facing the validation 'At least one field must be filled out'
1445 1
                if( GFFormDisplay::is_empty( $field, $this->form_id  ) && empty( $field->isRequired ) ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 2 found
Loading history...
1446
                    unset( $field->validation_message );
1447
	                $field->validation_message = false;
1448
                    continue;
1449
                }
1450
1451 2
                $gv_valid = false;
1452
1453
            }
1454
1455
        }
1456
1457 2
        $validation_results['is_valid'] = $gv_valid;
1458
1459 2
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results.', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1460
1461
        // We'll need this result when rendering the form ( on GFFormDisplay::get_form )
1462 2
        $this->form_after_validation = $validation_results['form'];
1463
1464 2
        return $validation_results;
1465
    }
1466
1467
1468
    /**
1469
     * TODO: This seems to be hacky... we should remove it. Entry is set when updating the form using setup_vars()!
1470
     * Get the current entry and set it if it's not yet set.
1471
     * @return array Gravity Forms entry array
1472
     */
1473
    public function get_entry() {
1474
1475
        if( empty( $this->entry ) ) {
1476
            // Get the database value of the entry that's being edited
1477
            $this->entry = gravityview_get_entry( GravityView_frontend::is_single_entry() );
1478
        }
1479
1480
        return $this->entry;
1481
    }
1482
1483
1484
1485
    // --- Filters
1486
1487
    /**
1488
     * Get the Edit Entry fields as configured in the View
1489
     *
1490
     * @since 1.8
1491
     *
1492
     * @param int $view_id
1493
     *
1494
     * @return array Array of fields that are configured in the Edit tab in the Admin
1495
     */
1496 2
    private function get_configured_edit_fields( $form, $view_id ) {
1497
1498
        // Get all fields for form
1499 2
        $properties = GravityView_View_Data::getInstance()->get_fields( $view_id );
1500
1501
        // If edit tab not yet configured, show all fields
1502 2
        $edit_fields = !empty( $properties['edit_edit-fields'] ) ? $properties['edit_edit-fields'] : NULL;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1503
1504
        // Hide fields depending on admin settings
1505 2
        $fields = $this->filter_fields( $form['fields'], $edit_fields );
1506
1507
	    // If Edit Entry fields are configured, remove adminOnly field settings. Otherwise, don't.
1508 2
	    $fields = $this->filter_admin_only_fields( $fields, $edit_fields, $form, $view_id );
1509
1510
        /**
1511
         * @filter `gravityview/edit_entry/form_fields` Modify the fields displayed in Edit Entry form
1512
         * @since 1.17
1513
         * @param GF_Field[] $fields Gravity Forms form fields
1514
         * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1515
         * @param array $form GF Form array (`fields` key modified to have only fields configured to show in Edit Entry)
1516
         * @param int $view_id View ID
1517
         */
1518 2
        $fields = apply_filters( 'gravityview/edit_entry/form_fields', $fields, $edit_fields, $form, $view_id );
1519
1520 2
        return $fields;
1521
    }
1522
1523
1524
    /**
1525
     * Filter area fields based on specified conditions
1526
     *  - This filter removes the fields that have calculation configured
1527
     *
1528
     * @uses GravityView_Edit_Entry::user_can_edit_field() Check caps
1529
     * @access private
1530
     * @param GF_Field[] $fields
1531
     * @param array $configured_fields
1532
     * @since  1.5
1533
     * @return array $fields
1534
     */
1535 1
    private function filter_fields( $fields, $configured_fields ) {
1536
1537 1
        if( empty( $fields ) || !is_array( $fields ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1538
            return $fields;
1539
        }
1540
1541 1
        $edit_fields = array();
1542
1543 1
        $field_type_blacklist = $this->loader->get_field_blacklist( $this->entry );
1544
1545
        // First, remove blacklist or calculation fields
1546 1
        foreach ( $fields as $key => $field ) {
1547
1548
            // Remove the fields that have calculation properties and keep them to be used later
1549
            // @since 1.16.2
1550 1
            if( $field->has_calculation() ) {
1551
                $this->fields_with_calculation[] = $field;
1552
                // don't remove the calculation fields on form render.
1553
            }
1554
1555 1
            if( in_array( $field->type, $field_type_blacklist ) ) {
1556 1
                unset( $fields[ $key ] );
1557
            }
1558
        }
1559
1560
        // The Edit tab has not been configured, so we return all fields by default.
1561 1
        if( empty( $configured_fields ) ) {
1562 1
            return $fields;
1563
        }
1564
1565
        // The edit tab has been configured, so we loop through to configured settings
1566
        foreach ( $configured_fields as $configured_field ) {
1567
1568
	        /** @var GF_Field $field */
1569
	        foreach ( $fields as $field ) {
1570
1571
                if( intval( $configured_field['id'] ) === intval( $field->id ) && $this->user_can_edit_field( $configured_field, false ) ) {
1572
                    $edit_fields[] = $this->merge_field_properties( $field, $configured_field );
1573
                    break;
1574
                }
1575
1576
            }
1577
1578
        }
1579
1580
        return $edit_fields;
1581
1582
    }
1583
1584
    /**
1585
     * Override GF Form field properties with the ones defined on the View
1586
     * @param  GF_Field $field GF Form field object
1587
     * @param  array $field_setting  GV field options
1588
     * @since  1.5
1589
     * @return array|GF_Field
1590
     */
1591
    private function merge_field_properties( $field, $field_setting ) {
1592
1593
        $return_field = $field;
1594
1595
        if( empty( $field_setting['show_label'] ) ) {
1596
            $return_field->label = '';
1597
        } elseif ( !empty( $field_setting['custom_label'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1598
            $return_field->label = $field_setting['custom_label'];
1599
        }
1600
1601
        if( !empty( $field_setting['custom_class'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1602
            $return_field->cssClass .= ' '. gravityview_sanitize_html_class( $field_setting['custom_class'] );
1603
        }
1604
1605
        /**
1606
         * Normalize page numbers - avoid conflicts with page validation
1607
         * @since 1.6
1608
         */
1609
        $return_field->pageNumber = 1;
1610
1611
        return $return_field;
1612
1613
    }
1614
1615
    /**
1616
     * Remove fields that shouldn't be visible based on the Gravity Forms adminOnly field property
1617
     *
1618
     * @since 1.9.1
1619
     *
1620
     * @param array|GF_Field[] $fields Gravity Forms form fields
1621
     * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1622
     * @param array $form GF Form array
1623
     * @param int $view_id View ID
1624
     *
1625
     * @return array Possibly modified form array
1626
     */
1627 1
    private function filter_admin_only_fields( $fields = array(), $edit_fields = null, $form = array(), $view_id = 0 ) {
1628
1629
	    /**
1630
         * @filter `gravityview/edit_entry/use_gf_admin_only_setting` When Edit tab isn't configured, should the Gravity Forms "Admin Only" field settings be used to control field display to non-admins? Default: true
1631
	     * If the Edit Entry tab is not configured, adminOnly fields will not be shown to non-administrators.
1632
	     * If the Edit Entry tab *is* configured, adminOnly fields will be shown to non-administrators, using the configured GV permissions
1633
	     * @since 1.9.1
1634
	     * @param boolean $use_gf_adminonly_setting True: Hide field if set to Admin Only in GF and the user is not an admin. False: show field based on GV permissions, ignoring GF permissions.
1635
	     * @param array $form GF Form array
1636
	     * @param int $view_id View ID
1637
	     */
1638 1
	    $use_gf_adminonly_setting = apply_filters( 'gravityview/edit_entry/use_gf_admin_only_setting', empty( $edit_fields ), $form, $view_id );
1639
1640 1
	    if( $use_gf_adminonly_setting && false === GVCommon::has_cap( 'gravityforms_edit_entries', $this->entry['id'] ) ) {
1641
            foreach( $fields as $k => $field ) {
1642
                if( $field->adminOnly ) {
1643
                    unset( $fields[ $k ] );
1644
                }
1645
            }
1646
            return $fields;
1647
        }
1648
1649 1
	    foreach( $fields as &$field ) {
1650 1
		    $field->adminOnly = false;
1651
        }
1652
1653 1
        return $fields;
1654
    }
1655
1656
    // --- Conditional Logic
1657
1658
    /**
1659
     * Conditional logic isn't designed to work with forms that already have content. When switching input values,
1660
     * the dependent fields will be blank.
1661
     *
1662
     * Note: This is because GF populates a JavaScript variable with the input values. This is tough to filter at the input level;
1663
     * via the `gform_field_value` filter; it requires lots of legwork. Doing it at the form level is easier.
1664
     *
1665
     * @since 1.17.4
1666
     *
1667
     * @param array $form Gravity Forms array object
1668
     *
1669
     * @return array $form, modified to fix conditional
1670
     */
1671 1
    function prefill_conditional_logic( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1672
1673 1
        if( ! GFFormDisplay::has_conditional_logic( $form ) ) {
1674 1
            return $form;
1675
        }
1676
1677
        // Have Conditional Logic pre-fill fields as if the data were default values
1678
        /** @var GF_Field $field */
1679
        foreach ( $form['fields'] as &$field ) {
1680
1681
            if( 'checkbox' === $field->type ) {
1682
                foreach ( $field->get_entry_inputs() as $key => $input ) {
1683
                    $input_id = $input['id'];
1684
                    $choice = $field->choices[ $key ];
1685
                    $value = rgar( $this->entry, $input_id );
1686
                    $match = RGFormsModel::choice_value_match( $field, $choice, $value );
1687
                    if( $match ) {
1688
                        $field->choices[ $key ]['isSelected'] = true;
1689
                    }
1690
                }
1691
            } else {
1692
1693
                // We need to run through each field to set the default values
1694
                foreach ( $this->entry as $field_id => $field_value ) {
1695
1696
                    if( floatval( $field_id ) === floatval( $field->id ) ) {
1697
1698
                        if( 'list' === $field->type ) {
1699
                            $list_rows = maybe_unserialize( $field_value );
1700
1701
                            $list_field_value = array();
1702
                            foreach ( (array) $list_rows as $row ) {
1703
                                foreach ( (array) $row as $column ) {
1704
                                    $list_field_value[] = $column;
1705
                                }
1706
                            }
1707
1708
                            $field->defaultValue = serialize( $list_field_value );
1709
                        } else {
1710
                            $field->defaultValue = $field_value;
1711
                        }
1712
                    }
1713
                }
1714
            }
1715
        }
1716
1717
        return $form;
1718
    }
1719
1720
    /**
1721
     * Remove the conditional logic rules from the form button and the form fields, if needed.
1722
     *
1723
     * @todo Merge with caller method
1724
     * @since 1.9
1725
     *
1726
     * @param array $form Gravity Forms form
1727
     * @return array Modified form, if not using Conditional Logic
1728
     */
1729 1
    private function filter_conditional_logic( $form ) {
1730
1731
        /**
1732
         * @filter `gravityview/edit_entry/conditional_logic` Should the Edit Entry form use Gravity Forms conditional logic showing/hiding of fields?
1733
         * @since 1.9
1734
         * @param bool $use_conditional_logic True: Gravity Forms will show/hide fields just like in the original form; False: conditional logic will be disabled and fields will be shown based on configuration. Default: true
1735
         * @param array $form Gravity Forms form
1736
         */
1737 1
        $use_conditional_logic = apply_filters( 'gravityview/edit_entry/conditional_logic', true, $form );
1738
1739 1
        if( $use_conditional_logic ) {
1740 1
            return $form;
1741
        }
1742
1743
        foreach( $form['fields'] as &$field ) {
1744
            /* @var GF_Field $field */
1745
            $field->conditionalLogic = null;
1746
        }
1747
1748
        unset( $form['button']['conditionalLogic'] );
1749
1750
        return $form;
1751
1752
    }
1753
1754
    /**
1755
     * Disable the Gravity Forms conditional logic script and features on the Edit Entry screen
1756
     *
1757
     * @since 1.9
1758
     *
1759
     * @param $has_conditional_logic
1760
     * @param $form
1761
     * @return mixed
1762
     */
1763 1
    public function manage_conditional_logic( $has_conditional_logic, $form ) {
1764
1765 1
        if( ! $this->is_edit_entry() ) {
1766
            return $has_conditional_logic;
1767
        }
1768
1769
	    /** @see GravityView_Edit_Entry_Render::filter_conditional_logic for filter documentation */
1770 1
        return apply_filters( 'gravityview/edit_entry/conditional_logic', $has_conditional_logic, $form );
1771
    }
1772
1773
1774
    // --- User checks and nonces
1775
1776
    /**
1777
     * Check if the user can edit the entry
1778
     *
1779
     * - Is the nonce valid?
1780
     * - Does the user have the right caps for the entry
1781
     * - Is the entry in the trash?
1782
     *
1783
     * @todo Move to GVCommon
1784
     *
1785
     * @param  boolean $echo Show error messages in the form?
1786
     * @return boolean        True: can edit form. False: nope.
1787
     */
1788 2
    private function user_can_edit_entry( $echo = false ) {
1789
1790 2
        $error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1791
1792
        /**
1793
         *  1. Permalinks are turned off
1794
         *  2. There are two entries embedded using oEmbed
1795
         *  3. One of the entries has just been saved
1796
         */
1797 2
        if( !empty( $_POST['lid'] ) && !empty( $_GET['entry'] ) && ( $_POST['lid'] !== $_GET['entry'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1798
1799
            $error = true;
1800
1801
        }
1802
1803 2
        if( !empty( $_GET['entry'] ) && (string)$this->entry['id'] !== $_GET['entry'] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1804
1805
            $error = true;
1806
1807 2
        } elseif( ! $this->verify_nonce() ) {
1808
1809
            /**
1810
             * If the Entry is embedded, there may be two entries on the same page.
1811
             * If that's the case, and one is being edited, the other should fail gracefully and not display an error.
1812
             */
1813
            if( GravityView_oEmbed::getInstance()->get_entry_id() ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression \GravityView_oEmbed::get...tance()->get_entry_id() of type integer|null is loosely compared to true; this is ambiguous if the integer can be zero. You might want to explicitly use !== null instead.

In PHP, under loose comparison (like ==, or !=, or switch conditions), values of different types might be equal.

For integer values, zero is a special case, in particular the following results might be unexpected:

0   == false // true
0   == null  // true
123 == false // false
123 == null  // false

// It is often better to use strict comparison
0 === false // false
0 === null  // false
Loading history...
1814
                $error = true;
1815
            } else {
1816
                $error = __( 'The link to edit this entry is not valid; it may have expired.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1817
            }
1818
1819
        }
1820
1821 2
        if( ! GravityView_Edit_Entry::check_user_cap_edit_entry( $this->entry ) ) {
1822 1
            $error = __( 'You do not have permission to edit this entry.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1823
        }
1824
1825 2
        if( $this->entry['status'] === 'trash' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
1826
            $error = __('You cannot edit the entry; it is in the trash.', 'gravityview' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1827
        }
1828
1829
        // No errors; everything's fine here!
1830 2
        if( empty( $error ) ) {
1831 2
            return true;
1832
        }
1833
1834 1
        if( $echo && $error !== true ) {
0 ignored issues
show
introduced by
Found "!== true". Use Yoda Condition checks, you must
Loading history...
1835
1836 1
	        $error = esc_html( $error );
1837
1838
	        /**
1839
	         * @since 1.9
1840
	         */
1841 1
	        if ( ! empty( $this->entry ) ) {
1842 1
		        $error .= ' ' . gravityview_get_link( '#', _x('Go back.', 'Link shown when invalid Edit Entry link is clicked', 'gravityview' ), array( 'onclick' => "window.history.go(-1); return false;" ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal window.history.go(-1); return false; does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1843
	        }
1844
1845 1
            echo GVCommon::generate_notice( wpautop( $error ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1846
        }
1847
1848 1
        do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_entry]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1849
1850 1
        return false;
1851
    }
1852
1853
1854
    /**
1855
     * Check whether a field is editable by the current user, and optionally display an error message
1856
     * @uses  GravityView_Edit_Entry->check_user_cap_edit_field() Check user capabilities
1857
     * @param  array  $field Field or field settings array
1858
     * @param  boolean $echo  Whether to show error message telling user they aren't allowed
1859
     * @return boolean         True: user can edit the current field; False: nope, they can't.
1860
     */
1861
    private function user_can_edit_field( $field, $echo = false ) {
1862
1863
        $error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1864
1865
        if( ! $this->check_user_cap_edit_field( $field ) ) {
1866
            $error = __( 'You do not have permission to edit this field.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1867
        }
1868
1869
        // No errors; everything's fine here!
1870
        if( empty( $error ) ) {
1871
            return true;
1872
        }
1873
1874
        if( $echo ) {
1875
            echo GVCommon::generate_notice( wpautop( esc_html( $error ) ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1876
        }
1877
1878
        do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_field]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1879
1880
        return false;
1881
1882
    }
1883
1884
1885
    /**
1886
     * checks if user has permissions to edit a specific field
1887
     *
1888
     * Needs to be used combined with GravityView_Edit_Entry::user_can_edit_field for maximum security!!
1889
     *
1890
     * @param  [type] $field [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1891
     * @return bool
1892
     */
1893
    private function check_user_cap_edit_field( $field ) {
1894
1895
        // If they can edit any entries (as defined in Gravity Forms), we're good.
1896
        if( GVCommon::has_cap( array( 'gravityforms_edit_entries', 'gravityview_edit_others_entries' ) ) ) {
1897
            return true;
1898
        }
1899
1900
        $field_cap = isset( $field['allow_edit_cap'] ) ? $field['allow_edit_cap'] : false;
1901
1902
        // If the field has custom editing capaibilities set, check those
1903
        if( $field_cap ) {
1904
            return GVCommon::has_cap( $field['allow_edit_cap'] );
1905
        }
1906
1907
        return false;
1908
    }
1909
1910
1911
    /**
1912
     * Is the current nonce valid for editing the entry?
1913
     * @return boolean
1914
     */
1915 1
    public function verify_nonce() {
1916
1917
        // Verify form submitted for editing single
1918 1
        if( $this->is_edit_entry_submission() ) {
1919
            $valid = wp_verify_nonce( $_POST[ self::$nonce_field ], self::$nonce_field );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
1920
        }
1921
1922
        // Verify
1923 1
        else if( ! $this->is_edit_entry() ) {
1924
            $valid = false;
1925
        }
1926
1927
        else {
1928 1
            $valid = wp_verify_nonce( $_GET['edit'], self::$nonce_key );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
1929
        }
1930
1931
        /**
1932
         * @filter `gravityview/edit_entry/verify_nonce` Override Edit Entry nonce validation. Return true to declare nonce valid.
1933
         * @since 1.13
1934
         * @param int|boolean $valid False if invalid; 1 or 2 when nonce was generated
1935
         * @param string $nonce_field Key used when validating submissions. Default: is_gv_edit_entry
1936
         */
1937 1
        $valid = apply_filters( 'gravityview/edit_entry/verify_nonce', $valid, self::$nonce_field );
1938
1939 1
        return $valid;
1940
    }
1941
1942
1943
1944
} //end class