Completed
Push — master ( 2cfa6f...8927a4 )
by Zack
10:00 queued 06:05
created

GravityView_Entry_Approval::__construct()   A

Complexity

Conditions 1
Paths 1

Size

Total Lines 3
Code Lines 2

Duplication

Lines 0
Ratio 0 %

Importance

Changes 0
Metric Value
cc 1
eloc 2
nc 1
nop 0
dl 0
loc 3
rs 10
c 0
b 0
f 0
1
<?php
0 ignored issues
show
Coding Style Compatibility introduced by
For compatibility and reusability of your code, PSR1 recommends that a file should introduce either new symbols (like classes, functions, etc.) or have side-effects (like outputting something, or including other files), but not both at the same time. The first symbol is defined on line 23 and the first side effect is on line 15.

The PSR-1: Basic Coding Standard recommends that a file should either introduce new symbols, that is classes, functions, constants or similar, or have side effects. Side effects are anything that executes logic, like for example printing output, changing ini settings or writing to a file.

The idea behind this recommendation is that merely auto-loading a class should not change the state of an application. It also promotes a cleaner style of programming and makes your code less prone to errors, because the logic is not spread out all over the place.

To learn more about the PSR-1, please see the PHP-FIG site on the PSR-1.

Loading history...
2
/**
3
 * @file class-gravityview-entry-approval.php
4
 * @package   GravityView
5
 * @license   GPL2+
6
 * @author    Katz Web Services, Inc.
7
 * @link      https://gravityview.co
8
 * @copyright Copyright 2016, Katz Web Services, Inc.
9
 *
10
 * @since 1.18
11
 */
12
13
/** If this file is called directly, abort. */
14
if ( ! defined( 'ABSPATH' ) ) {
15
	die;
16
}
17
18
/**
19
 * Generate linked list output for a list of entries.
20
 *
21
 * @since 1.18
22
 */
23
class GravityView_Entry_Approval {
24
25
	/**
26
	 * @var string Key used to store approval status in the Gravity Forms entry meta table
27
	 */
28
	const meta_key = 'is_approved';
29
30
	public function __construct() {
31
		$this->add_hooks();
32
	}
33
34
	/**
35
	 * Add actions and filters related to entry approval
36
	 *
37
	 * @return void
38
	 */
39
	private function add_hooks() {
40
41
		// in case entry is edited (on admin or frontend)
42
		add_action( 'gform_after_update_entry', array( $this, 'after_update_entry_update_approved_meta' ), 10, 2);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
43
44
		// when using the User opt-in field, check on entry submission
45
		add_action( 'gform_after_submission', array( $this, 'after_submission' ), 10, 2 );
46
47
		// process ajax approve entry requests
48
		add_action('wp_ajax_gv_update_approved', array( $this, 'ajax_update_approved'));
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
introduced by
No space before closing parenthesis of array is bad style
Loading history...
49
50
	}
51
52
	/**
53
	 * Get the approval status for an entry
54
	 *
55
	 * @since 1.18
56
	 * @uses GVCommon::get_entry_id() Accepts entry slug or entry ID
57
	 *
58
	 * @param array|int|string $entry Entry array, entry slug, or entry ID
59
	 * @param string $value_or_label "value" or "label" (default: "label")
60
	 *
61
	 * @return bool|string Return the label or value of entry approval
62
	 */
63
	public static function get_entry_status( $entry, $value_or_label = 'label' ) {
64
65
		$entry_id = is_array( $entry ) ? $entry['id'] : GVCommon::get_entry_id( $entry );
66
67
		$status = gform_get_meta( $entry_id, self::meta_key );
68
69
		$status = GravityView_Entry_Approval_Status::maybe_convert_status( $status );
70
71
		if( 'value' === $value_or_label ) {
72
			return $status;
73
		}
74
75
		return GravityView_Entry_Approval_Status::get_label( $status );
76
	}
77
78
	/**
79
	 * Approve/Disapprove entries using the × or ✓ icons in the GF Entries screen
80
	 *
81
	 * @uses wp_send_json_error()
82
	 * @uses wp_send_json_success()
83
	 *
84
	 * Expects a $_POST request with the following $_POST keys and values:
85
	 *
86
	 * @global array $_POST {
87
	 * @type int $form_id ID of the form connected to the entry being updated
88
	 * @type string|int $entry_slug The ID or slug of the entry being updated
89
	 * @type string $approved The value of the entry approval status {@see GravityView_Entry_Approval_Status::is_valid() }
90
	 * }
91
	 *
92
	 * @return void Prints result using wp_send_json_success() and wp_send_json_error()
93
	 */
94
	public function ajax_update_approved() {
95
96
		$form_id = intval( rgpost('form_id') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
97
98
		$entry_id = GVCommon::get_entry_id( rgpost('entry_slug') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
99
100
		$approval_status = rgpost('approved');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
101
102
		$nonce = rgpost('nonce');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
103
104
		// Valid status
105
		if( ! GravityView_Entry_Approval_Status::is_valid( $approval_status ) ) {
106
107
			do_action( 'gravityview_log_error', __METHOD__ . ': Invalid approval status', $_POST );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
108
109
			$result = new WP_Error( 'invalid_status', __( 'The request was invalid. Refresh the page and try again.', 'gravityview' ) );
110
111
		}
112
113
		// Valid values
114
		elseif ( empty( $entry_id ) || empty( $form_id ) ) {
115
116
			do_action( 'gravityview_log_error', __METHOD__ . ' entry_id or form_id are empty.', $_POST );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
117
118
			$result = new WP_Error( 'empty_details', __( 'The request was invalid. Refresh the page and try again.', 'gravityview' ) );
119
120
		}
121
122
		// Valid nonce
123
		else if ( empty( $nonce ) || ! wp_verify_nonce( $nonce, 'gravityview_entry_approval' ) ) {
124
125
			do_action( 'gravityview_log_error', __METHOD__ . ' Security check failed.', $_POST );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
126
127
			$result = new WP_Error( 'invalid_nonce', __( 'The request was invalid. Refresh the page and try again.', 'gravityview' ) );
128
129
		}
130
131
		// Has capability
132
		elseif ( ! GVCommon::has_cap( 'gravityview_moderate_entries', $entry_id ) ) {
133
134
			do_action( 'gravityview_log_error', __METHOD__ . ' User does not have the `gravityview_moderate_entries` capability.' );
135
136
			$result = new WP_Error( 'Missing Cap: gravityview_moderate_entries', __( 'You do not have permission to edit this entry.', 'gravityview') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
137
138
		}
139
140
		// All checks passed
141
		else {
142
143
			$result = self::update_approved( $entry_id, $approval_status, $form_id );
144
145
		}
146
147
		if ( is_wp_error( $result ) ) {
148
			do_action( 'gravityview_log_error', __METHOD__ . ' Error updating approval: ' . $result->get_error_message() );
149
150
			wp_send_json_error( $result );
151
		}
152
153
		$current_status = self::get_entry_status( $entry_id, 'value' );
154
155
		wp_send_json_success( array(
156
			'status' => $current_status
0 ignored issues
show
introduced by
Each line in an array declaration must end in a comma
Loading history...
157
		) );
158
	}
159
160
	/**
161
	 * Update the is_approved meta whenever the entry is submitted (and it contains a User Opt-in field)
162
	 *
163
	 * @since 1.16.6
164
	 *
165
	 * @param $entry array Gravity Forms entry object
166
	 * @param $form array Gravity Forms form object
167
	 */
168
	public function after_submission( $entry, $form ) {
169
		$this->after_update_entry_update_approved_meta( $form , $entry['id'] );
170
	}
171
172
	/**
173
	 * Update the is_approved meta whenever the entry is updated
174
	 *
175
	 * @since 1.7.6.1 Was previously named `update_approved_meta`
176
	 *
177
	 * @param  array $form     Gravity Forms form array
178
	 * @param  int $entry_id ID of the Gravity Forms entry
179
	 * @return void
180
	 */
181
	public function after_update_entry_update_approved_meta( $form, $entry_id = NULL ) {
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
182
183
		$approved_column = self::get_approved_column( $form['id'] );
184
185
		/**
186
		 * If the form doesn't contain the approve field, don't assume anything.
187
		 */
188
		if( empty( $approved_column ) ) {
189
			return;
190
		}
191
192
		$entry = GFAPI::get_entry( $entry_id );
193
194
		self::update_approved_meta( $entry_id, $entry[ (string)$approved_column ], $form['id'] );
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
195
	}
196
197
	/**
198
	 * Process a bulk of entries to update the approve field/property
199
	 *
200
	 * @since 1.18 Moved to GravityView_Entry_Approval
201
	 * @since 1.18 Made public
202
	 *
203
	 * @access public
204
	 * @static
205
	 * @param array|boolean $entries If array, array of entry IDs that are to be updated. If true: update all entries.
206
	 * @param int $approved Approved status. If `0`: unapproved, if not empty, `Approved`
207
	 * @param int $form_id The Gravity Forms Form ID
208
	 * @return boolean|null True: successfully updated all entries. False: there was an error updating at least one entry. NULL: an error occurred (see log)
209
	 */
210
	public static function update_bulk( $entries = array(), $approved, $form_id ) {
211
212
		if ( empty( $entries ) || ( $entries !== true && ! is_array( $entries ) ) ) {
0 ignored issues
show
introduced by
Found "!== true". Use Yoda Condition checks, you must
Loading history...
213
			do_action( 'gravityview_log_error', __METHOD__ . ' Entries were empty or malformed.', $entries );
214
			return NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
215
		}
216
217
		if ( ! GVCommon::has_cap( 'gravityview_moderate_entries' ) ) {
218
			do_action( 'gravityview_log_error', __METHOD__ . ' User does not have the `gravityview_moderate_entries` capability.' );
219
			return NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
220
		}
221
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
222
223
		if ( ! GravityView_Entry_Approval_Status::is_valid( $approved ) ) {
224
			do_action( 'gravityview_log_error', __METHOD__ . ' Invalid approval status', $approved );
225
			return NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
226
		}
227
228
		// calculate approved field id once instead of looping through in the update_approved() method
229
		$approved_column_id = self::get_approved_column( $form_id );
230
231
		$success = true;
232
		foreach ( $entries as $entry_id ) {
0 ignored issues
show
Bug introduced by
The expression $entries of type boolean|array is not guaranteed to be traversable. How about adding an additional type check?

There are different options of fixing this problem.

  1. If you want to be on the safe side, you can add an additional type-check:

    $collection = json_decode($data, true);
    if ( ! is_array($collection)) {
        throw new \RuntimeException('$collection must be an array.');
    }
    
    foreach ($collection as $item) { /** ... */ }
    
  2. If you are sure that the expression is traversable, you might want to add a doc comment cast to improve IDE auto-completion and static analysis:

    /** @var array $collection */
    $collection = json_decode($data, true);
    
    foreach ($collection as $item) { /** .. */ }
    
  3. Mark the issue as a false-positive: Just hover the remove button, in the top-right corner of this issue for more options.

Loading history...
233
			$update_success = self::update_approved( (int) $entry_id, $approved, $form_id, $approved_column_id );
234
235
			if ( ! $update_success ) {
236
				$success = false;
237
			}
238
		}
239
240
		return $success;
241
	}
242
243
	/**
244
	 * update_approved function.
245
	 *
246
	 * @since 1.18 Moved to GravityView_Entry_Approval class
247
	 *
248
	 * @access public
249
	 * @static
250
	 * @param int $entry_id (default: 0)
251
	 * @param int $approved (default: 0)
252
	 * @param int $form_id (default: 0)
253
	 * @param int $approvedcolumn (default: 0)
254
	 *
255
	 * @return boolean True: It worked; False: it failed
256
	 */
257
	public static function update_approved( $entry_id = 0, $approved = 0, $form_id = 0, $approvedcolumn = 0 ) {
258
259
		if( !class_exists( 'GFAPI' ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
260
			do_action( 'gravityview_log_error', __METHOD__ . 'GFAPI does not exist' );
261
			return false;
262
		}
263
264
		if( ! GravityView_Entry_Approval_Status::is_valid( $approved ) ) {
265
			do_action( 'gravityview_log_error', __METHOD__ . ': Not a valid approval value.' );
266
			return false;
267
		}
268
269
		$approved = GravityView_Entry_Approval_Status::maybe_convert_status( $approved );
270
271
		$entry = GFAPI::get_entry( $entry_id );
272
273
		if ( is_wp_error( $entry ) ) {
274
			do_action( 'gravityview_log_error', __METHOD__ . ': Entry does not exist' );
275
			return false;
276
		}
277
278
		// If the form has an Approve/Reject field, update that value
279
		$result = self::update_approved_column( $entry_id, $approved, $form_id, $approvedcolumn );
280
281
		if( is_wp_error( $result ) ) {
282
			do_action( 'gravityview_log_error', __METHOD__ . sprintf( ' - Entry approval not updated: %s', $result->get_error_message() ) );
283
			return false;
284
		}
285
286
		$form_id = intval( $form_id );
287
288
		// Update the entry meta
289
		self::update_approved_meta( $entry_id, $approved, $form_id );
290
291
		// add note to entry if approval field updating worked or there was no approved field
292
		// There's no validation for the meta
293
		if( true === $result ) {
294
295
			// Add an entry note
296
			self::add_approval_status_updated_note( $entry_id, $approved );
297
298
			/**
299
			 * Destroy the cache for this form
300
			 * @see class-cache.php
301
			 * @since 1.5.1
302
			 */
303
			do_action( 'gravityview_clear_form_cache', $form_id );
304
305
		}
306
307
		return $result;
308
	}
309
310
	/**
311
	 * Add a note when an entry is approved
312
	 *
313
	 * @see GravityView_Entry_Approval::update_approved
314
	 *
315
	 * @since 1.18
316
	 *
317
	 * @param int $entry_id Gravity Forms entry ID
318
	 * @param int $approved Approval status
319
	 *
320
	 * @return false|int|WP_Error Note ID if successful; WP_Error if error when adding note, FALSE if note not updated because of `gravityview/approve_entries/add-note` filter or `GravityView_Entry_Notes` class not existing
321
	 */
322
	private static function add_approval_status_updated_note( $entry_id, $approved = 0 ) {
323
		$note = '';
324
325
		switch ( $approved ) {
326
			case GravityView_Entry_Approval_Status::APPROVED:
327
				$note = __( 'Approved the Entry for GravityView', 'gravityview' );
328
				break;
329
			case GravityView_Entry_Approval_Status::UNAPPROVED:
330
				$note = __( 'Reset Entry approval for GravityView', 'gravityview' );
331
				break;
332
			case GravityView_Entry_Approval_Status::DISAPPROVED:
333
				$note = __( 'Disapproved the Entry for GravityView', 'gravityview' );
334
				break;
335
		}
336
337
		/**
338
		 * @filter `gravityview/approve_entries/add-note` Add a note when the entry has been approved or disapproved?
339
		 * @since 1.16.3
340
		 * @param bool $add_note True: Yep, add that note! False: Do not, under any circumstances, add that note!
341
		 */
342
		$add_note = apply_filters( 'gravityview/approve_entries/add-note', true );
343
344
		$note_id = false;
345
346
		if( $add_note && class_exists( 'GravityView_Entry_Notes' ) ) {
347
348
			$current_user = wp_get_current_user();
349
350
			$note_id = GravityView_Entry_Notes::add_note( $entry_id, $current_user->ID, $current_user->display_name, $note );
351
		}
352
353
		return $note_id;
354
	}
355
356
	/**
357
	 * Update the Approve/Disapproved field value
358
	 *
359
	 * @param  int $entry_id ID of the Gravity Forms entry
360
	 * @param  string $status String whether entry is approved or not. `0` for not approved, `Approved` for approved.
361
	 * @param int $form_id ID of the form of the entry being updated. Improves query performance.
362
	 * @param string $approvedcolumn Gravity Forms Field ID
363
	 *
364
	 * @return true|WP_Error Returns true if there is no approval column or updating entry succeeded. WP_Error if status is invalid or entry doesn't exist.
365
	 */
366
	private static function update_approved_column( $entry_id = 0, $status = '0', $form_id = 0, $approvedcolumn = 0 ) {
367
368
		if( empty( $approvedcolumn ) ) {
369
			$approvedcolumn = self::get_approved_column( $form_id );
370
		}
371
372
		if ( empty( $approvedcolumn ) ) {
373
			return true;
374
		}
375
376
		if ( ! GravityView_Entry_Approval_Status::is_valid( $status ) ) {
377
			return new WP_Error( 'invalid_status', 'Invalid entry approval status', $status );
378
		}
379
380
		//get the entry
381
		$entry = GFAPI::get_entry( $entry_id );
382
383
		// Entry doesn't exist
384
		if ( is_wp_error( $entry ) ) {
385
			return $entry;
386
		}
387
388
		//update entry
389
		$entry[ (string)$approvedcolumn ] = $status;
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
390
391
		/**
392
		 * Note: GFAPI::update_entry() doesn't trigger `gform_after_update_entry`, so we trigger updating the meta ourselves
393
		 * @see GravityView_Entry_Approval::after_update_entry_update_approved_meta
394
		 * @var true|WP_Error $result
395
		 */
396
		$result = GFAPI::update_entry( $entry );
397
398
		return $result;
399
	}
400
401
	/**
402
	 * Update the `is_approved` entry meta value
403
	 *
404
	 * @since 1.7.6.1 `after_update_entry_update_approved_meta` was previously to be named `update_approved_meta`
405
	 * @since 1.17.1 Added $form_id parameter
406
	 *
407
	 * @param  int $entry_id ID of the Gravity Forms entry
408
	 * @param  string $status String whether entry is approved or not. `0` for not approved, `Approved` for approved.
409
	 * @param int $form_id ID of the form of the entry being updated. Improves query performance.
410
	 *
411
	 * @return void
412
	 */
413
	private static function update_approved_meta( $entry_id, $status, $form_id = 0 ) {
414
415
		if ( ! GravityView_Entry_Approval_Status::is_valid( $status ) ) {
416
			do_action('gravityview_log_error', __METHOD__ . ': $is_approved not valid value', $status );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
417
			return;
418
		}
419
420
		$status = GravityView_Entry_Approval_Status::maybe_convert_status( $status );
421
422
		// update entry meta
423
		if( function_exists('gform_update_meta') ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
424
425
			if( GravityView_Entry_Approval_Status::is_unapproved( $status ) ) {
426
				gform_delete_meta( $entry_id, self::meta_key );
427
			} else {
428
				gform_update_meta( $entry_id, self::meta_key, $status, $form_id );
429
			}
430
431
			/**
432
			 * @action `gravityview/approve_entries/updated` Triggered when an entry approval is updated
433
			 * @since 1.7.6.1
434
			 * @param  int $entry_id ID of the Gravity Forms entry
435
			 * @param  string|int $status String whether entry is approved or not. See GravityView_Entry_Approval_Status for valid statuses.
436
			 */
437
			do_action( 'gravityview/approve_entries/updated', $entry_id, $status );
438
439
			$action = GravityView_Entry_Approval_Status::get_key( $status );
440
441
			/**
442
			 * @action `gravityview/approve_entries/{$action}` Triggered when an entry approval is reset.
443
			 * $action can be 'approved', 'unapproved', or 'disapproved'
444
			 * @since 1.7.6.1
445
			 * @since 1.18 Added "unapproved"
446
			 * @param  int $entry_id ID of the Gravity Forms entry
447
			 */
448
			do_action( 'gravityview/approve_entries/' . $action , $entry_id );
449
450
		} else {
451
452
			do_action('gravityview_log_error', __METHOD__ . ' - `gform_update_meta` does not exist.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
453
454
		}
455
	}
456
457
	/**
458
	 * Calculate the approve field.input id
459
	 *
460
	 * @access public
461
	 * @static
462
	 * @param mixed $form GF Form or Form ID
463
	 * @return false|null|string Returns the input ID of the approved field. Returns NULL if no approved fields were found. Returns false if $form_id wasn't set.
464
	 */
465
	static public function get_approved_column( $form ) {
0 ignored issues
show
Coding Style introduced by
As per PSR2, the static declaration should come after the visibility declaration.
Loading history...
466
467
		if( empty( $form ) ) {
468
			return null;
469
		}
470
471
		if( !is_array( $form ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
472
			$form = GVCommon::get_form( $form );
473
		}
474
475
		foreach( $form['fields'] as $key => $field ) {
476
477
			$field = (array) $field;
478
479
			if( !empty( $field['gravityview_approved'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
480
				if( !empty($field['inputs'][0]['id']) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
481
					return $field['inputs'][0]['id'];
482
				}
483
			}
484
485
			// Note: This is just for backward compatibility from GF Directory plugin and old GV versions - when using i18n it may not work..
486
			if( 'checkbox' == $field['type'] && isset( $field['inputs'] ) && is_array( $field['inputs'] ) ) {
487
				foreach ( $field['inputs'] as $key2 => $input ) {
488
					if ( strtolower( $input['label'] ) == 'approved' ) {
0 ignored issues
show
introduced by
Found "== '". Use Yoda Condition checks, you must
Loading history...
489
						return $input['id'];
490
					}
491
				}
492
			}
493
		}
494
495
		return null;
496
	}
497
498
}
499
500
new GravityView_Entry_Approval;