Completed
Push — master ( c38d6c...15bc19 )
by Zack
14:07 queued 10:41
created

modify_fileupload_settings()   A

Complexity

Conditions 2
Paths 2

Size

Total Lines 9
Code Lines 5

Duplication

Lines 0
Ratio 0 %

Code Coverage

Tests 4
CRAP Score 2.032

Importance

Changes 0
Metric Value
cc 2
eloc 5
nc 2
nop 3
dl 0
loc 9
ccs 4
cts 5
cp 0.8
crap 2.032
rs 9.6666
c 0
b 0
f 0
1
<?php
0 ignored issues
show
Coding Style Compatibility introduced by
For compatibility and reusability of your code, PSR1 recommends that a file should introduce either new symbols (like classes, functions, etc.) or have side-effects (like outputting something, or including other files), but not both at the same time. The first symbol is defined on line 16 and the first side effect is on line 13.

The PSR-1: Basic Coding Standard recommends that a file should either introduce new symbols, that is classes, functions, constants or similar, or have side effects. Side effects are anything that executes logic, like for example printing output, changing ini settings or writing to a file.

The idea behind this recommendation is that merely auto-loading a class should not change the state of an application. It also promotes a cleaner style of programming and makes your code less prone to errors, because the logic is not spread out all over the place.

To learn more about the PSR-1, please see the PHP-FIG site on the PSR-1.

Loading history...
2
/**
3
 * GravityView Edit Entry - render frontend
4
 *
5
 * @package   GravityView
6
 * @license   GPL2+
7
 * @author    Katz Web Services, Inc.
8
 * @link      http://gravityview.co
9
 * @copyright Copyright 2014, Katz Web Services, Inc.
10
 */
11
12
if ( ! defined( 'WPINC' ) ) {
13
    die;
14
}
15
16
class GravityView_Edit_Entry_Render {
17
18
    /**
19
     * @var GravityView_Edit_Entry
20
     */
21
    protected $loader;
22
23
	/**
24
	 * @var string String used to generate unique nonce for the entry/form/view combination. Allows access to edit page.
25
	 */
26
    static $nonce_key;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $nonce_key.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
27
28
	/**
29
	 * @since 1.9
30
	 * @var string String used for check valid edit entry form submission. Allows saving edit form values.
31
	 */
32
	private static $nonce_field = 'is_gv_edit_entry';
33
34
	/**
35
	 * @since 1.9
36
	 * @var bool Whether to allow save and continue functionality
37
	 */
38
	private static $supports_save_and_continue = false;
39
40
    /**
41
     * Gravity Forms entry array
42
     *
43
     * @var array
44
     */
45
    public $entry;
46
47
	/**
48
	 * Gravity Forms entry array (it won't get changed during this class lifecycle)
49
	 * @since 1.17.2
50
	 * @var array
51
	 */
52
	private static $original_entry = array();
53
54
    /**
55
     * Gravity Forms form array (GravityView modifies the content through this class lifecycle)
56
     *
57
     * @var array
58
     */
59
	public $form;
60
61
    /**
62
     * Gravity Forms form array (it won't get changed during this class lifecycle)
63
     * @since 1.16.2.1
64
     * @var array
65
     */
66
    private static $original_form;
67
68
    /**
69
     * Gravity Forms form array after the form validation process
70
     * @since 1.13
71
     * @var array
72
     */
73
	public $form_after_validation = null;
74
75
    /**
76
     * Hold an array of GF field objects that have calculation rules
77
     * @var array
78
     */
79
	public $fields_with_calculation = array();
80
81
    /**
82
     * Gravity Forms form id
83
     *
84
     * @var int
85
     */
86
	public $form_id;
87
88
    /**
89
     * ID of the current view
90
     *
91
     * @var int
92
     */
93
	public $view_id;
94
95
    /**
96
     * Updated entry is valid (GF Validation object)
97
     *
98
     * @var array
99
     */
100
	public $is_valid = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
101
102 3
    function __construct( GravityView_Edit_Entry $loader ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
103 3
        $this->loader = $loader;
104 3
    }
105
106 3
    function load() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
107
108
        /** @define "GRAVITYVIEW_DIR" "../../../" */
109 3
        include_once( GRAVITYVIEW_DIR .'includes/class-admin-approve-entries.php' );
110
111
        // Don't display an embedded form when editing an entry
112 3
        add_action( 'wp_head', array( $this, 'prevent_render_form' ) );
113 3
        add_action( 'wp_footer', array( $this, 'prevent_render_form' ) );
114
115
        // Stop Gravity Forms processing what is ours!
116 3
        add_filter( 'wp', array( $this, 'prevent_maybe_process_form'), 8 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
117
118 3
        add_filter( 'gravityview_is_edit_entry', array( $this, 'is_edit_entry') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
119
120 3
        add_action( 'gravityview_edit_entry', array( $this, 'init' ) );
121
122
        // Disable conditional logic if needed (since 1.9)
123 3
        add_filter( 'gform_has_conditional_logic', array( $this, 'manage_conditional_logic' ), 10, 2 );
124
125
        // Make sure GF doesn't validate max files (since 1.9)
126 3
        add_filter( 'gform_plupload_settings', array( $this, 'modify_fileupload_settings' ), 10, 3 );
127
128
        // Add fields expected by GFFormDisplay::validate()
129 3
        add_filter( 'gform_pre_validation', array( $this, 'gform_pre_validation') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
130
131
		// Fix multiselect value for GF 2.2
132 3
		add_filter( 'gravityview/edit_entry/field_value_multiselect', array( $this, 'fix_multiselect_value_serialization' ), 10, 3 );
133 3
    }
134
135
    /**
136
     * Don't show any forms embedded on a page when GravityView is in Edit Entry mode
137
     *
138
     * Adds a `__return_empty_string` filter on the Gravity Forms shortcode on the `wp_head` action
139
     * And then removes it on the `wp_footer` action
140
     *
141
     * @since 1.16.1
142
     *
143
     * @return void
144
     */
145 1
    public function prevent_render_form() {
146 1
        if( $this->is_edit_entry() ) {
147 1
            if( 'wp_head' === current_filter() ) {
148 1
                add_filter( 'gform_shortcode_form', '__return_empty_string' );
149
            } else {
150 1
                remove_filter( 'gform_shortcode_form', '__return_empty_string' );
151
            }
152
        }
153 1
    }
154
155
    /**
156
     * Because we're mimicking being a front-end Gravity Forms form while using a Gravity Forms
157
     * backend form, we need to prevent them from saving twice.
158
     * @return void
159
     */
160
    public function prevent_maybe_process_form() {
161
162
        if( ! empty( $_POST ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
163
	        do_action( 'gravityview_log_debug', 'GravityView_Edit_Entry[prevent_maybe_process_form] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
164
        }
165
166
        if( $this->is_edit_entry_submission() ) {
167
            remove_action( 'wp',  array( 'RGForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
168
	        remove_action( 'wp',  array( 'GFForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
169
        }
170
    }
171
172
    /**
173
     * Is the current page an Edit Entry page?
174
     * @return boolean
175
     */
176 4
    public function is_edit_entry() {
177
178 4
        $is_edit_entry = GravityView_frontend::is_single_entry() && ! empty( $_GET['edit'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
179
180 4
        return ( $is_edit_entry || $this->is_edit_entry_submission() );
181
    }
182
183
	/**
184
	 * Is the current page an Edit Entry page?
185
	 * @since 1.9
186
	 * @return boolean
187
	 */
188 3
	public function is_edit_entry_submission() {
189 3
		return !empty( $_POST[ self::$nonce_field ] );
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
190
	}
191
192
    /**
193
     * When Edit entry view is requested setup the vars
194
     */
195 3
    private function setup_vars() {
196 3
        $gravityview_view = GravityView_View::getInstance();
197
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
198
199 3
        $entries = $gravityview_view->getEntries();
200 3
	    self::$original_entry = $entries[0];
201 3
	    $this->entry = $entries[0];
202
203 3
        self::$original_form = $gravityview_view->getForm();
204 3
        $this->form = $gravityview_view->getForm();
205 3
        $this->form_id = $gravityview_view->getFormId();
206 3
        $this->view_id = $gravityview_view->getViewId();
207
208 3
        self::$nonce_key = GravityView_Edit_Entry::get_nonce_key( $this->view_id, $this->form_id, $this->entry['id'] );
209 3
    }
210
211
212
    /**
213
     * Load required files and trigger edit flow
214
     *
215
     * Run when the is_edit_entry returns true.
216
     *
217
     * @param GravityView_View_Data $gv_data GravityView Data object
218
     * @return void
219
     */
220 4
    public function init( $gv_data ) {
221
222 4
        require_once( GFCommon::get_base_path() . '/form_display.php' );
223 4
        require_once( GFCommon::get_base_path() . '/entry_detail.php' );
224
225 4
        $this->setup_vars();
226
227
        // Multiple Views embedded, don't proceed if nonce fails
228 4
		$multiple_views = defined( 'GRAVITYVIEW_FUTURE_CORE_LOADED' ) ? gravityview()->views->count() > 1 : $gv_data->has_multiple_views();
0 ignored issues
show
Documentation introduced by
The property views does not exist on object<GV\Core>. Since you implemented __get, maybe consider adding a @property annotation.

Since your code implements the magic getter _get, this function will be called for any read access on an undefined variable. You can add the @property annotation to your class or interface to document the existence of this variable.

<?php

/**
 * @property int $x
 * @property int $y
 * @property string $text
 */
class MyLabel
{
    private $properties;

    private $allowedProperties = array('x', 'y', 'text');

    public function __get($name)
    {
        if (isset($properties[$name]) && in_array($name, $this->allowedProperties)) {
            return $properties[$name];
        } else {
            return null;
        }
    }

    public function __set($name, $value)
    {
        if (in_array($name, $this->allowedProperties)) {
            $properties[$name] = $value;
        } else {
            throw new \LogicException("Property $name is not defined.");
        }
    }

}

If the property has read access only, you can use the @property-read annotation instead.

Of course, you may also just have mistyped another name, in which case you should fix the error.

See also the PhpDoc documentation for @property.

Loading history...
Deprecated Code introduced by
The method GravityView_View_Data::has_multiple_views() has been deprecated.

This method has been deprecated.

Loading history...
229 4
        if( $multiple_views && ! wp_verify_nonce( $_GET['edit'], self::$nonce_key ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
230
            do_action('gravityview_log_error', __METHOD__ . ': Nonce validation failed for the Edit Entry request; returning' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
231
            return;
232
        }
233
234
        // Sorry, you're not allowed here.
235 4
        if( false === $this->user_can_edit_entry( true ) ) {
236 1
            do_action('gravityview_log_error', __METHOD__ . ': User is not allowed to edit this entry; returning', $this->entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
237 1
            return;
238
        }
239
240 4
        $this->print_scripts();
241
242 4
        $this->process_save();
243
244 4
        $this->edit_entry_form();
245
246 4
    }
247
248
249
    /**
250
     * Force Gravity Forms to output scripts as if it were in the admin
251
     * @return void
252
     */
253 3
    private function print_scripts() {
254 3
        $gravityview_view = GravityView_View::getInstance();
255
256 3
        wp_register_script( 'gform_gravityforms', GFCommon::get_base_url().'/js/gravityforms.js', array( 'jquery', 'gform_json', 'gform_placeholder', 'sack', 'plupload-all', 'gravityview-fe-view' ) );
257
258 3
        GFFormDisplay::enqueue_form_scripts($gravityview_view->getForm(), false);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
259
260
        // Sack is required for images
261 3
        wp_print_scripts( array( 'sack', 'gform_gravityforms' ) );
262 3
    }
263
264
265
    /**
266
     * Process edit entry form save
267
     */
268 4
    private function process_save() {
269
270 4
        if( empty( $_POST ) || ! isset( $_POST['lid'] ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
271 4
            return;
272
        }
273
274
        // Make sure the entry, view, and form IDs are all correct
275 4
        $valid = $this->verify_nonce();
276
277 4
        if( !$valid ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
278
            do_action('gravityview_log_error', __METHOD__ . ' Nonce validation failed.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
279
            return;
280
        }
281
282 4
        if( $this->entry['id'] !== $_POST['lid'] ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
283
            do_action('gravityview_log_error', __METHOD__ . ' Entry ID did not match posted entry ID.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
284
            return;
285
        }
286
287 4
        do_action('gravityview_log_debug', __METHOD__ . ': $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
288
289 4
        $this->process_save_process_files( $this->form_id );
290
291 4
        $this->validate();
292
293 4
        if( $this->is_valid ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using ! empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
294
295 4
            do_action('gravityview_log_debug', __METHOD__ . ': Submission is valid.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
296
297
            /**
298
             * @hack This step is needed to unset the adminOnly from form fields, to add the calculation fields
299
             */
300 4
            $form = $this->form_prepare_for_save();
301
302
            /**
303
             * @hack to avoid the capability validation of the method save_lead for GF 1.9+
304
             */
305 4
            unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
306
307 4
            $date_created = $this->entry['date_created'];
308
309
            /**
310
             * @hack to force Gravity Forms to use $read_value_from_post in GFFormsModel::save_lead()
311
             * @since 1.17.2
312
             */
313 4
            unset( $this->entry['date_created'] );
314
315 4
            GFFormsModel::save_lead( $form, $this->entry );
316
317
	        // Delete the values for hidden inputs
318 4
	        $this->unset_hidden_field_values();
319
            
320 4
            $this->entry['date_created'] = $date_created;
321
322
            // Process calculation fields
323 4
            $this->update_calculation_fields();
324
325
            // Perform actions normally performed after updating a lead
326 4
            $this->after_update();
327
328
	        /**
329
             * Must be AFTER after_update()!
330
             * @see https://github.com/gravityview/GravityView/issues/764
331
             */
332 4
            $this->maybe_update_post_fields( $form );
333
334
            /**
335
             * @action `gravityview/edit_entry/after_update` Perform an action after the entry has been updated using Edit Entry
336
             * @param array $form Gravity Forms form array
337
             * @param string $entry_id Numeric ID of the entry that was updated
338
             * @param GravityView_Edit_Entry_Render $this This object
339
             */
340 4
            do_action( 'gravityview/edit_entry/after_update', $this->form, $this->entry['id'], $this );
341
342
        } else {
343
            do_action('gravityview_log_error', __METHOD__ . ': Submission is NOT valid.', $this->entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
344
        }
345
346 4
    } // process_save
347
348
	/**
349
	 * Delete the value of fields hidden by conditional logic when the entry is edited
350
     *
351
     * @uses GFFormsModel::update_lead_field_value()
352
     *
353
     * @since 1.17.4
354
     *
355
     * @return void
356
	 */
357 3
    private function unset_hidden_field_values() {
358 3
	    global $wpdb;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
359
360 3
	    $lead_detail_table      = GFFormsModel::get_lead_details_table_name();
361 3
	    $current_fields   = $wpdb->get_results( $wpdb->prepare( "SELECT id, field_number FROM $lead_detail_table WHERE lead_id=%d", $this->entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
362
363 3
	    foreach ( $this->entry as $input_id => $field_value ) {
364
365 3
		    $field = RGFormsModel::get_field( $this->form, $input_id );
366
367
		    // Reset fields that are hidden
368
		    // Don't pass $entry as fourth parameter; force using $_POST values to calculate conditional logic
369 3
		    if ( GFFormsModel::is_field_hidden( $this->form, $field, array(), NULL ) ) {
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
370
371
		        // List fields are stored as empty arrays when empty
372
			    $empty_value = $this->is_field_json_encoded( $field ) ? '[]' : '';
373
374
			    $lead_detail_id = GFFormsModel::get_lead_detail_id( $current_fields, $input_id );
375
376
			    GFFormsModel::update_lead_field_value( $this->form, $this->entry, $field, $lead_detail_id, $input_id, $empty_value );
377
378
			    // Prevent the $_POST values of hidden fields from being used as default values when rendering the form
379
                // after submission
380
			    $post_input_id = 'input_' . str_replace( '.', '_', $input_id );
381 3
			    $_POST[ $post_input_id ] = '';
382
		    }
383
	    }
384 3
    }
385
386
    /**
387
     * Have GF handle file uploads
388
     *
389
     * Copy of code from GFFormDisplay::process_form()
390
     *
391
     * @param int $form_id
392
     */
393 3
    private function process_save_process_files( $form_id ) {
394
395
        //Loading files that have been uploaded to temp folder
396 3
        $files = GFCommon::json_decode( stripslashes( RGForms::post( 'gform_uploaded_files' ) ) );
397 3
        if ( ! is_array( $files ) ) {
398 2
            $files = array();
399
        }
400
401
		/**
402
		 * Make sure the fileuploads are not overwritten if no such request was done.
403
         * @since 1.20.1
404
		 */
405 3
		add_filter( "gform_save_field_value_$form_id", array( $this, 'save_field_value' ), 99, 5 );
406
407 3
        RGFormsModel::$uploaded_files[ $form_id ] = $files;
408 3
    }
409
410
	/**
411
	 * Make sure the fileuploads are not overwritten if no such request was done.
412
	 *
413
     * TO ONLY BE USED INTERNALLY; DO NOT DEVELOP ON; MAY BE REMOVED AT ANY TIME.
414
     *
415
	 * @since 1.20.1
416
	 *
417
	 * @param string $value Field value
418
	 * @param array $entry GF entry array
419
	 * @param GF_Field_FileUpload $field
420
	 * @param array $form GF form array
421
	 * @param string $input_id ID of the input being saved
422
	 *
423
	 * @return string
424
	 */
425 3
	public function save_field_value( $value = '', $entry = array(), $field = null, $form = array(), $input_id = '' ) {
426
427 3
		if ( ! $field || $field->type != 'fileupload' ) {
0 ignored issues
show
introduced by
Found "!= '". Use Yoda Condition checks, you must
Loading history...
428 3
			return $value;
429
		}
430
431 1
		$input_name = 'input_' . str_replace( '.', '_', $input_id );
432
433 1
		if ( $field->multipleFiles ) {
434
			if ( empty( $value ) ) {
435
				return json_decode( $entry[ $input_id ], true );
436
			}
437
			return $value;
438
		}
439
440
		/** No file is being uploaded. */
441 1
		if ( empty( $_FILES[ $input_name ]['name'] ) ) {
442
			/** So return the original upload */
443 1
			return $entry[ $input_id ];
444
		}
445
446 1
		return $value;
447
	}
448
449
    /**
450
     * Remove max_files validation (done on gravityforms.js) to avoid conflicts with GravityView
451
     * Late validation done on self::custom_validation
452
     *
453
     * @param $plupload_init array Plupload settings
454
     * @param $form_id
455
     * @param $instance
456
     * @return mixed
457
     */
458 1
    public function modify_fileupload_settings( $plupload_init, $form_id, $instance ) {
0 ignored issues
show
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $instance is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
459 1
        if( ! $this->is_edit_entry() ) {
460
            return $plupload_init;
461
        }
462
463 1
        $plupload_init['gf_vars']['max_files'] = 0;
464
465 1
        return $plupload_init;
466
    }
467
468
469
    /**
470
     * Unset adminOnly and convert field input key to string
471
     * @return array $form
472
     */
473 3
    private function form_prepare_for_save() {
474
475 3
        $form = $this->form;
476
477
	    /** @var GF_Field $field */
478 3
        foreach( $form['fields'] as $k => &$field ) {
479
480
            /**
481
             * Remove the fields with calculation formulas before save to avoid conflicts with GF logic
482
             * @since 1.16.3
483
             * @var GF_Field $field
484
             */
485 3
            if( $field->has_calculation() ) {
486
                unset( $form['fields'][ $k ] );
487
            }
488
489 3
            $field->adminOnly = false;
490
491 3
            if( isset( $field->inputs ) && is_array( $field->inputs ) ) {
492
                foreach( $field->inputs as $key => $input ) {
493 3
                    $field->inputs[ $key ][ 'id' ] = (string)$input['id'];
0 ignored issues
show
introduced by
Array keys should NOT be surrounded by spaces if they only contain a string or an integer.
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
494
                }
495
            }
496
        }
497
498 3
        return $form;
499
    }
500
501 3
    private function update_calculation_fields() {
502
503 3
        $form = self::$original_form;
504 3
        $update = false;
505
506
        // get the most up to date entry values
507 3
        $entry = GFAPI::get_entry( $this->entry['id'] );
508
509 3
        if( !empty( $this->fields_with_calculation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
510
            $update = true;
511
            foreach ( $this->fields_with_calculation as $calc_field ) {
512
                $inputs = $calc_field->get_entry_inputs();
513
                if ( is_array( $inputs ) ) {
514
                    foreach ( $inputs as $input ) {
515
                        $input_name = 'input_' . str_replace( '.', '_', $input['id'] );
516
                        $entry[ strval( $input['id'] ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
517
                    }
518
                } else {
519
                    $input_name = 'input_' . str_replace( '.', '_', $calc_field->id);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
520
                    $entry[ strval( $calc_field->id ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
521
                }
522
            }
523
524
        }
525
526 3
        if( $update ) {
527
528
            $return_entry = GFAPI::update_entry( $entry );
529
530
            if( is_wp_error( $return_entry ) ) {
531
                do_action( 'gravityview_log_error', 'Updating the entry calculation fields failed', $return_entry );
532
            } else {
533
                do_action( 'gravityview_log_debug', 'Updating the entry calculation fields succeeded' );
534
            }
535
        }
536 3
    }
537
538
    /**
539
     * Handle updating the Post Image field
540
     *
541
     * Sets a new Featured Image if configured in Gravity Forms; otherwise uploads/updates media
542
     *
543
     * @since 1.17
544
     *
545
     * @uses GFFormsModel::media_handle_upload
546
     * @uses set_post_thumbnail
547
     * 
548
     * @param array $form GF Form array
549
     * @param GF_Field $field GF Field
550
     * @param string $field_id Numeric ID of the field
551
     * @param string $value
552
     * @param array $entry GF Entry currently being edited
553
     * @param int $post_id ID of the Post being edited
554
     *
555
     * @return mixed|string
556
     */
557 1
    private function update_post_image( $form, $field, $field_id, $value, $entry, $post_id ) {
558
559 1
        $input_name = 'input_' . $field_id;
560
561 1
        if ( !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
562
563
            // We have a new image
564
565
            $value = RGFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'] );
566
567
            $ary = ! empty( $value ) ? explode( '|:|', $value ) : array();
568
            $img_url = rgar( $ary, 0 );
569
570
            $img_title       = count( $ary ) > 1 ? $ary[1] : '';
571
            $img_caption     = count( $ary ) > 2 ? $ary[2] : '';
572
            $img_description = count( $ary ) > 3 ? $ary[3] : '';
573
574
            $image_meta = array(
575
                'post_excerpt' => $img_caption,
576
                'post_content' => $img_description,
577
            );
578
579
            //adding title only if it is not empty. It will default to the file name if it is not in the array
580
            if ( ! empty( $img_title ) ) {
581
                $image_meta['post_title'] = $img_title;
582
            }
583
584
            /**
585
             * todo: As soon as \GFFormsModel::media_handle_upload becomes a public method, move this call to \GFFormsModel::media_handle_upload and remove the hack from this class.
586
             * Note: the method became public in GF 1.9.17.7, but we don't require that version yet.
587
             */
588
            require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
589
            $media_id = GravityView_GFFormsModel::media_handle_upload( $img_url, $post_id, $image_meta );
590
591
            // is this field set as featured image?
592
            if ( $media_id && $field->postFeaturedImage ) {
593
                set_post_thumbnail( $post_id, $media_id );
594
            }
595
596 1
        } elseif ( !empty( $_POST[ $input_name ] ) && is_array( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
597
598 1
            $img_url = $_POST[ $input_name ];
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
599
600 1
			$img_title       = rgar( $_POST, $input_name.'_1' );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
601 1
			$img_caption     = rgar( $_POST, $input_name .'_4' );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
602 1
			$img_description = rgar( $_POST, $input_name .'_7' );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
603
604 1
			$value = ! empty( $img_url ) ? $img_url . "|:|" . $img_title . "|:|" . $img_caption . "|:|" . $img_description : '';
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal |:| does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
605
606 1
			if ( $field->postFeaturedImage ) {
607
608
				$image_meta = array(
609 1
					'ID' => get_post_thumbnail_id( $post_id ),
610 1
					'post_title' => $img_title,
611 1
					'post_excerpt' => $img_caption,
612 1
					'post_content' => $img_description,
613
				);
614
615
				// update image title, caption or description
616 1
				wp_update_post( $image_meta );
617
			}
618
        } else {
619
620
            // if we get here, image was removed or not set.
621
            $value = '';
622
623
            if ( $field->postFeaturedImage ) {
624
                delete_post_thumbnail( $post_id );
625
            }
626
        }
627
628 1
        return $value;
629
    }
630
631
    /**
632
     * Loop through the fields being edited and if they include Post fields, update the Entry's post object
633
     *
634
     * @param array $form Gravity Forms form
635
     *
636
     * @return void
637
     */
638 3
    private function maybe_update_post_fields( $form ) {
639
640 3
        if( empty( $this->entry['post_id'] ) ) {
641 2
	        do_action( 'gravityview_log_debug', __METHOD__ . ': This entry has no post fields. Continuing...' );
642 2
            return;
643
        }
644
645 1
        $post_id = $this->entry['post_id'];
646
647
        // Security check
648 1
        if( false === GVCommon::has_cap( 'edit_post', $post_id ) ) {
649
            do_action( 'gravityview_log_error', 'The current user does not have the ability to edit Post #'.$post_id );
650
            return;
651
        }
652
653 1
        $update_entry = false;
654
655 1
        $updated_post = $original_post = get_post( $post_id );
656
657 1
        foreach ( $this->entry as $field_id => $value ) {
658
659 1
            $field = RGFormsModel::get_field( $form, $field_id );
660
661 1
            if( ! $field ) {
662 1
                continue;
663
            }
664
665 1
            if( GFCommon::is_post_field( $field ) && 'post_category' !== $field->type ) {
666
667
                // Get the value of the field, including $_POSTed value
668 1
                $value = RGFormsModel::get_field_value( $field );
669
670
                // Use temporary entry variable, to make values available to fill_post_template() and update_post_image()
671 1
                $entry_tmp = $this->entry;
672 1
                $entry_tmp["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
673
674 1
                switch( $field->type ) {
675
676 1
                    case 'post_title':
677
                        $post_title = $value;
678
                        if( rgar( $form, 'postTitleTemplateEnabled' ) ) {
679
                            $post_title = $this->fill_post_template( $form['postTitleTemplate'], $form, $entry_tmp );
680
                        }
681
                        $updated_post->post_title = $post_title;
682
                        $updated_post->post_name  = $post_title;
683
                        unset( $post_title );
684
                        break;
685
686 1
                    case 'post_content':
687
                        $post_content = $value;
688
                        if( rgar( $form, 'postContentTemplateEnabled' ) ) {
689
                            $post_content = $this->fill_post_template( $form['postContentTemplate'], $form, $entry_tmp, true );
690
                        }
691
                        $updated_post->post_content = $post_content;
692
                        unset( $post_content );
693
                        break;
694 1
                    case 'post_excerpt':
695
                        $updated_post->post_excerpt = $value;
696
                        break;
697 1
                    case 'post_tags':
698
                        wp_set_post_tags( $post_id, $value, false );
699
                        break;
700 1
                    case 'post_category':
701
                        break;
702 1
                    case 'post_custom_field':
703
						if ( is_array( $value ) && ( floatval( $field_id ) !== floatval( $field->id ) ) ) {
704
							$value = $value[ $field_id ];
705
						}
706
707
                        if( ! empty( $field->customFieldTemplateEnabled ) ) {
708
                            $value = $this->fill_post_template( $field->customFieldTemplate, $form, $entry_tmp, true );
709
                        }
710
711
	                    if ( $this->is_field_json_encoded( $field ) && ! is_string( $value ) ) {
712
		                    $value = function_exists('wp_json_encode') ? wp_json_encode( $value ) : json_encode( $value );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
713
	                    }
714
715
                        update_post_meta( $post_id, $field->postCustomFieldName, $value );
716
                        break;
717
718 1
                    case 'post_image':
719 1
                        $value = $this->update_post_image( $form, $field, $field_id, $value, $this->entry, $post_id );
720 1
                        break;
721
722
                }
723
724
                // update entry after
725 1
                $this->entry["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
726
727 1
                $update_entry = true;
728
729 1
                unset( $entry_tmp );
730
            }
731
732
        }
733
734 1
        if( $update_entry ) {
735
736 1
            $return_entry = GFAPI::update_entry( $this->entry );
737
738 1
            if( is_wp_error( $return_entry ) ) {
739
               do_action( 'gravityview_log_error', 'Updating the entry post fields failed', array( '$this->entry' => $this->entry, '$return_entry' => $return_entry ) );
740
            } else {
741 1
                do_action( 'gravityview_log_debug', 'Updating the entry post fields for post #'.$post_id.' succeeded' );
742
            }
743
744
        }
745
746 1
        $return_post = wp_update_post( $updated_post, true );
747
748 1
        if( is_wp_error( $return_post ) ) {
749
            $return_post->add_data( $updated_post, '$updated_post' );
750
            do_action( 'gravityview_log_error', 'Updating the post content failed', compact( 'updated_post', 'return_post' ) );
751
        } else {
752 1
            do_action( 'gravityview_log_debug', 'Updating the post content for post #'.$post_id.' succeeded', $updated_post );
753
        }
754 1
    }
755
756
	/**
757
     * Is the field stored in a JSON-encoded manner?
758
     *
759
	 * @param GF_Field $field
760
	 *
761
	 * @return bool True: stored in DB json_encode()'d; False: not encoded
762
	 */
763
    private function is_field_json_encoded( $field ) {
764
765
	    $json_encoded = false;
766
767
        $input_type = RGFormsModel::get_input_type( $field );
768
769
	    // Only certain custom field types are supported
770
	    switch( $input_type ) {
771
		    case 'fileupload':
772
		    case 'list':
773
		    case 'multiselect':
774
			    $json_encoded = true;
775
			    break;
776
	    }
777
778
	    return $json_encoded;
779
    }
780
781
    /**
782
     * Convert a field content template into prepared output
783
     *
784
     * @uses GravityView_GFFormsModel::get_post_field_images()
785
     *
786
     * @since 1.17
787
     *
788
     * @param string $template The content template for the field
789
     * @param array $form Gravity Forms form
790
     * @param bool $do_shortcode Whether to process shortcode inside content. In GF, only run on Custom Field and Post Content fields
791
     *
792
     * @return string
793
     */
794
    private function fill_post_template( $template, $form, $entry, $do_shortcode = false ) {
795
796
        require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
797
798
        $post_images = GravityView_GFFormsModel::get_post_field_images( $form, $entry );
799
800
        //replacing post image variables
801
        $output = GFCommon::replace_variables_post_image( $template, $post_images, $entry );
802
803
        //replacing all other variables
804
        $output = GFCommon::replace_variables( $output, $form, $entry, false, false, false );
805
806
        // replace conditional shortcodes
807
        if( $do_shortcode ) {
808
            $output = do_shortcode( $output );
809
        }
810
811
        return $output;
812
    }
813
814
815
    /**
816
     * Perform actions normally performed after updating a lead
817
     *
818
     * @since 1.8
819
     *
820
     * @see GFEntryDetail::lead_detail_page()
821
     *
822
     * @return void
823
     */
824 3
    private function after_update() {
825
826 3
        do_action( 'gform_after_update_entry', $this->form, $this->entry['id'], self::$original_entry );
827 3
        do_action( "gform_after_update_entry_{$this->form['id']}", $this->form, $this->entry['id'], self::$original_entry );
828
829
        // Re-define the entry now that we've updated it.
830 3
        $entry = RGFormsModel::get_lead( $this->entry['id'] );
831
832 3
        $entry = GFFormsModel::set_entry_meta( $entry, $this->form );
833
834
        // We need to clear the cache because Gravity Forms caches the field values, which
835
        // we have just updated.
836 3
        foreach ($this->form['fields'] as $key => $field) {
0 ignored issues
show
introduced by
No space after opening parenthesis is prohibited
Loading history...
introduced by
No space before closing parenthesis is prohibited
Loading history...
837 3
            GFFormsModel::refresh_lead_field_value( $entry['id'], $field->id );
838
        }
839
840 3
        $this->entry = $entry;
841 3
    }
842
843
844
    /**
845
     * Display the Edit Entry form
846
     *
847
     * @return void
848
     */
849 3
    public function edit_entry_form() {
850
851
        ?>
852
853
        <div class="gv-edit-entry-wrapper"><?php
854
855 3
            $javascript = gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/inline-javascript.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
856
857
            /**
858
             * Fixes weird wpautop() issue
859
             * @see https://github.com/katzwebservices/GravityView/issues/451
860
             */
861 3
            echo gravityview_strip_whitespace( $javascript );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'gravityview_strip_whitespace'
Loading history...
862
863
            ?><h2 class="gv-edit-entry-title">
864
                <span><?php
865
866
                    /**
867
                     * @filter `gravityview_edit_entry_title` Modify the edit entry title
868
                     * @param string $edit_entry_title Modify the "Edit Entry" title
869
                     * @param GravityView_Edit_Entry_Render $this This object
870
                     */
871 3
                    $edit_entry_title = apply_filters('gravityview_edit_entry_title', __('Edit Entry', 'gravityview'), $this );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
872
873 3
                    echo esc_attr( $edit_entry_title );
874
            ?></span>
875
            </h2>
876
877
            <?php $this->maybe_print_message(); ?>
878
879
            <?php // The ID of the form needs to be `gform_{form_id}` for the pluploader ?>
880
881
            <form method="post" id="gform_<?php echo $this->form_id; ?>" enctype="multipart/form-data">
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$this'
Loading history...
882
883
                <?php
884
885 3
                wp_nonce_field( self::$nonce_key, self::$nonce_key );
886
887 3
                wp_nonce_field( self::$nonce_field, self::$nonce_field, false );
888
889
                // Print the actual form HTML
890 3
                $this->render_edit_form();
891
892
                ?>
893 3
            </form>
894
895
            <script>
896
                gform.addFilter('gform_reset_pre_conditional_logic_field_action', function ( reset, formId, targetId, defaultValues, isInit ) {
897
                    return false;
898
                });
899
            </script>
900
901
        </div>
902
903
    <?php
904 3
    }
905
906
    /**
907
     * Display success or error message if the form has been submitted
908
     *
909
     * @uses GVCommon::generate_notice
910
     *
911
     * @since 1.16.2.2
912
     *
913
     * @return void
914
     */
915 3
    private function maybe_print_message() {
916
917 3
        if( rgpost('action') === 'update' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
918
919
            $back_link = esc_url( remove_query_arg( array( 'page', 'view', 'edit' ) ) );
920
921
            if( ! $this->is_valid ){
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
922
923
                // Keeping this compatible with Gravity Forms.
924
                $validation_message = "<div class='validation_error'>" . __('There was a problem with your submission.', 'gravityview') . " " . __('Errors have been highlighted below.', 'gravityview') . "</div>";
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw '__'
Loading history...
Coding Style Comprehensibility introduced by
The string literal </div> does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
925
                $message = apply_filters("gform_validation_message_{$this->form['id']}", apply_filters("gform_validation_message", $validation_message, $this->form), $this->form);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal gform_validation_message does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
926
927
                echo GVCommon::generate_notice( $message , 'gv-error' );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
928
929
            } else {
930
                $entry_updated_message = sprintf( esc_attr__('Entry Updated. %sReturn to Entry%s', 'gravityview'), '<a href="'. $back_link .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
931
932
                /**
933
                 * @filter `gravityview/edit_entry/success` Modify the edit entry success message (including the anchor link)
934
                 * @since 1.5.4
935
                 * @param string $entry_updated_message Existing message
936
                 * @param int $view_id View ID
937
                 * @param array $entry Gravity Forms entry array
938
                 * @param string $back_link URL to return to the original entry. @since 1.6
939
                 */
940
                $message = apply_filters( 'gravityview/edit_entry/success', $entry_updated_message , $this->view_id, $this->entry, $back_link );
941
942
                echo GVCommon::generate_notice( $message );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
943
            }
944
945
        }
946 3
    }
947
948
    /**
949
     * Display the Edit Entry form in the original Gravity Forms format
950
     *
951
     * @since 1.9
952
     *
953
     * @return void
954
     */
955 3
    private function render_edit_form() {
956
957
        /**
958
         * @action `gravityview/edit-entry/render/before` Before rendering the Edit Entry form
959
         * @since 1.17
960
         * @param GravityView_Edit_Entry_Render $this
961
         */
962 3
        do_action( 'gravityview/edit-entry/render/before', $this );
963
964 3
        add_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields'), 5000, 3 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
965 3
        add_filter( 'gform_submit_button', array( $this, 'render_form_buttons') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
966 3
        add_filter( 'gform_disable_view_counter', '__return_true' );
967
968 3
        add_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5, 5 );
969 3
        add_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10, 5 );
970
971
        // We need to remove the fake $_GET['page'] arg to avoid rendering form as if in admin.
972 3
        unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
973
974
        // TODO: Verify multiple-page forms
975
976 3
        ob_start(); // Prevent PHP warnings possibly caused by prefilling list fields for conditional logic
977
978 3
        $html = GFFormDisplay::get_form( $this->form['id'], false, false, true, $this->entry );
979
980 3
        ob_get_clean();
981
982 3
	    remove_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields' ), 5000 );
983 3
        remove_filter( 'gform_submit_button', array( $this, 'render_form_buttons' ) );
984 3
        remove_filter( 'gform_disable_view_counter', '__return_true' );
985 3
        remove_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5 );
986 3
        remove_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10 );
987
988 3
        echo $html;
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$html'
Loading history...
989
990
        /**
991
         * @action `gravityview/edit-entry/render/after` After rendering the Edit Entry form
992
         * @since 1.17
993
         * @param GravityView_Edit_Entry_Render $this
994
         */
995 3
        do_action( 'gravityview/edit-entry/render/after', $this );
996 3
    }
997
998
    /**
999
     * Display the Update/Cancel/Delete buttons for the Edit Entry form
1000
     * @since 1.8
1001
     * @return string
1002
     */
1003 3
    public function render_form_buttons() {
1004 3
        return gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/form-buttons.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
1005
    }
1006
1007
1008
    /**
1009
     * Modify the form fields that are shown when using GFFormDisplay::get_form()
1010
     *
1011
     * By default, all fields will be shown. We only want the Edit Tab configured fields to be shown.
1012
     *
1013
     * @param array $form
1014
     * @param boolean $ajax Whether in AJAX mode
1015
     * @param array|string $field_values Passed parameters to the form
1016
     *
1017
     * @since 1.9
1018
     *
1019
     * @return array Modified form array
1020
     */
1021 3
    public function filter_modify_form_fields( $form, $ajax = false, $field_values = '' ) {
0 ignored issues
show
Unused Code introduced by
The parameter $ajax is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $field_values is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1022
1023
        // In case we have validated the form, use it to inject the validation results into the form render
1024 3
        if( isset( $this->form_after_validation ) ) {
1025 3
            $form = $this->form_after_validation;
1026
        } else {
1027 3
            $form['fields'] = $this->get_configured_edit_fields( $form, $this->view_id );
1028
        }
1029
1030 3
        $form = $this->filter_conditional_logic( $form );
1031
1032 3
        $form = $this->prefill_conditional_logic( $form );
1033
1034
        // for now we don't support Save and Continue feature.
1035 3
        if( ! self::$supports_save_and_continue ) {
1036 3
	        unset( $form['save'] );
1037
        }
1038
1039 3
        return $form;
1040
    }
1041
1042
    /**
1043
     * When displaying a field, check if it's a Post Field, and if so, make sure the post exists and current user has edit rights.
1044
     *
1045
     * @since 1.16.2.2
1046
     *
1047
     * @param string $field_content Always empty. Returning not-empty overrides the input.
1048
     * @param GF_Field $field
1049
     * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1050
     * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1051
     * @param int $form_id Form ID
1052
     *
1053
     * @return string If error, the error message. If no error, blank string (modify_edit_field_input() runs next)
1054
     */
1055 3
    public function verify_user_can_edit_post( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1056
1057 3
        if( GFCommon::is_post_field( $field ) ) {
1058
1059 1
            $message = null;
1060
1061
            // First, make sure they have the capability to edit the post.
1062 1
            if( false === current_user_can( 'edit_post', $this->entry['post_id'] ) ) {
1063
1064
                /**
1065
                 * @filter `gravityview/edit_entry/unsupported_post_field_text` Modify the message when someone isn't able to edit a post
1066
                 * @param string $message The existing "You don't have permission..." text
1067
                 */
1068
                $message = apply_filters('gravityview/edit_entry/unsupported_post_field_text', __('You don&rsquo;t have permission to edit this post.', 'gravityview') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1069
1070 1
            } elseif( null === get_post( $this->entry['post_id'] ) ) {
1071
                /**
1072
                 * @filter `gravityview/edit_entry/no_post_text` Modify the message when someone is editing an entry attached to a post that no longer exists
1073
                 * @param string $message The existing "This field is not editable; the post no longer exists." text
1074
                 */
1075
                $message = apply_filters('gravityview/edit_entry/no_post_text', __('This field is not editable; the post no longer exists.', 'gravityview' ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1076
            }
1077
1078 1
            if( $message ) {
1079
                $field_content = sprintf('<div class="ginput_container ginput_container_' . $field->type . '">%s</div>', wpautop( $message ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1080
            }
1081
        }
1082
1083 3
        return $field_content;
1084
    }
1085
1086
    /**
1087
     *
1088
     * Fill-in the saved values into the form inputs
1089
     *
1090
     * @param string $field_content Always empty. Returning not-empty overrides the input.
1091
     * @param GF_Field $field
1092
     * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1093
     * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1094
     * @param int $form_id Form ID
1095
     *
1096
     * @return mixed
1097
     */
1098 3
    public function modify_edit_field_input( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1099
1100 3
        $gv_field = GravityView_Fields::get_associated_field( $field );
1101
1102
        // If the form has been submitted, then we don't need to pre-fill the values,
1103
        // Except for fileupload type and when a field input is overridden- run always!!
1104
        if(
1105 3
            ( $this->is_edit_entry_submission() && !in_array( $field->type, array( 'fileupload', 'post_image' ) ) )
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1106 3
            && false === ( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) )
1107
            && ! GFCommon::is_product_field( $field->type )
1108 3
            || ! empty( $field_content )
1109 3
            || in_array( $field->type, array( 'honeypot' ) )
1110
        ) {
1111
	        return $field_content;
1112
        }
1113
1114
        // SET SOME FIELD DEFAULTS TO PREVENT ISSUES
1115 3
        $field->adminOnly = false; /** @see GFFormDisplay::get_counter_init_script() need to prevent adminOnly */
1116
1117 3
        $field_value = $this->get_field_value( $field );
1118
1119
	    // Prevent any PHP warnings, like undefined index
1120 3
	    ob_start();
1121
1122 3
	    $return = null;
1123
1124
        /** @var GravityView_Field $gv_field */
1125 3
        if( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) ) {
1126 2
            $return = $gv_field->get_field_input( $this->form, $field_value, $this->entry, $field );
1127
        } else {
1128 3
	        $return = $field->get_field_input( $this->form, $field_value, $this->entry );
1129
	    }
1130
1131
	    // If there was output, it's an error
1132 3
	    $warnings = ob_get_clean();
1133
1134 3
	    if( !empty( $warnings ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1135
		    do_action( 'gravityview_log_error', __METHOD__ . $warnings, $field_value );
1136
	    }
1137
1138 3
        return $return;
1139
    }
1140
1141
    /**
1142
     * Modify the value for the current field input
1143
     *
1144
     * @param GF_Field $field
1145
     *
1146
     * @return array|mixed|string
1147
     */
1148 3
    private function get_field_value( $field ) {
1149
1150
        /**
1151
         * @filter `gravityview/edit_entry/pre_populate/override` Allow the pre-populated value to override saved value in Edit Entry form. By default, pre-populate mechanism only kicks on empty fields.
1152
         * @param boolean True: override saved values; False: don't override (default)
1153
         * @param $field GF_Field object Gravity Forms field object
1154
         * @since 1.13
1155
         */
1156 3
        $override_saved_value = apply_filters( 'gravityview/edit_entry/pre_populate/override', false, $field );
1157
1158
        // We're dealing with multiple inputs (e.g. checkbox) but not time or date (as it doesn't store data in input IDs)
1159 3
        if( isset( $field->inputs ) && is_array( $field->inputs ) && !in_array( $field->type, array( 'time', 'date' ) ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1160
1161
            $field_value = array();
1162
1163
            // only accept pre-populated values if the field doesn't have any choice selected.
1164
            $allow_pre_populated = $field->allowsPrepopulate;
1165
1166
            foreach ( (array)$field->inputs as $input ) {
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1167
1168
                $input_id = strval( $input['id'] );
1169
                
1170
                if ( isset( $this->entry[ $input_id ] ) && ! gv_empty( $this->entry[ $input_id ], false, false ) ) {
1171
                    $field_value[ $input_id ] =  'post_category' === $field->type ? GFCommon::format_post_category( $this->entry[ $input_id ], true ) : $this->entry[ $input_id ];
0 ignored issues
show
introduced by
Expected 1 space after "="; 2 found
Loading history...
1172
                    $allow_pre_populated = false;
1173
                }
1174
1175
            }
1176
1177
            $pre_value = $field->get_value_submission( array(), false );
1178
1179
            $field_value = ! $allow_pre_populated && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $field_value : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1180
1181
        } else {
1182
1183 3
            $id = intval( $field->id );
1184
1185
            // get pre-populated value if exists
1186 3
            $pre_value = $field->allowsPrepopulate ? GFFormsModel::get_parameter_value( $field->inputName, array(), $field ) : '';
1187
1188
            // saved field entry value (if empty, fallback to the pre-populated value, if exists)
1189
            // or pre-populated value if not empty and set to override saved value
1190 3
            $field_value = !gv_empty( $this->entry[ $id ], false, false ) && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $this->entry[ $id ] : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1191
1192
            // in case field is post_category but inputType is select, multi-select or radio, convert value into array of category IDs.
1193 3
            if ( 'post_category' === $field->type && !gv_empty( $field_value, false, false ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1194
                $categories = array();
1195
                foreach ( explode( ',', $field_value ) as $cat_string ) {
1196
                    $categories[] = GFCommon::format_post_category( $cat_string, true );
1197
                }
1198
                $field_value = 'multiselect' === $field->get_input_type() ? $categories : implode( '', $categories );
1199
            }
1200
1201
        }
1202
1203
        // if value is empty get the default value if defined
1204 3
        $field_value = $field->get_value_default_if_empty( $field_value );
1205
1206
	    /**
1207
	     * @filter `gravityview/edit_entry/field_value` Change the value of an Edit Entry field, if needed
1208
	     * @since 1.11
1209
	     * @since 1.20 Added third param
1210
	     * @param mixed $field_value field value used to populate the input
1211
	     * @param object $field Gravity Forms field object ( Class GF_Field )
1212
	     * @param GravityView_Edit_Entry_Render $this Current object
1213
	     */
1214 3
	    $field_value = apply_filters( 'gravityview/edit_entry/field_value', $field_value, $field, $this );
1215
1216
	    /**
1217
	     * @filter `gravityview/edit_entry/field_value_{field_type}` Change the value of an Edit Entry field for a specific field type
1218
	     * @since 1.17
1219
	     * @since 1.20 Added third param
1220
	     * @param mixed $field_value field value used to populate the input
1221
	     * @param GF_Field $field Gravity Forms field object
1222
	     * @param GravityView_Edit_Entry_Render $this Current object
1223
	     */
1224 3
	    $field_value = apply_filters( 'gravityview/edit_entry/field_value_' . $field->type , $field_value, $field, $this );
1225
1226 3
        return $field_value;
1227
    }
1228
1229
1230
    // ---- Entry validation
1231
1232
    /**
1233
     * Add field keys that Gravity Forms expects.
1234
     *
1235
     * @see GFFormDisplay::validate()
1236
     * @param  array $form GF Form
1237
     * @return array       Modified GF Form
1238
     */
1239 3
    public function gform_pre_validation( $form ) {
1240
1241 3
        if( ! $this->verify_nonce() ) {
1242
            return $form;
1243
        }
1244
1245
        // Fix PHP warning regarding undefined index.
1246 3
        foreach ( $form['fields'] as &$field) {
0 ignored issues
show
introduced by
No space before closing parenthesis is prohibited
Loading history...
1247
1248
            // This is because we're doing admin form pretending to be front-end, so Gravity Forms
1249
            // expects certain field array items to be set.
1250 3
            foreach ( array( 'noDuplicates', 'adminOnly', 'inputType', 'isRequired', 'enablePrice', 'inputs', 'allowedExtensions' ) as $key ) {
1251 3
	            $field->{$key} = isset( $field->{$key} ) ? $field->{$key} : NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1252
            }
1253
1254 3
            switch( RGFormsModel::get_input_type( $field ) ) {
1255
1256
                /**
1257
                 * this whole fileupload hack is because in the admin, Gravity Forms simply doesn't update any fileupload field if it's empty, but it DOES in the frontend.
1258
                 *
1259
                 * What we have to do is set the value so that it doesn't get overwritten as empty on save and appears immediately in the Edit Entry screen again.
1260
                 *
1261
                 * @hack
1262
                 */
1263 3
                case 'fileupload':
1264
1265
                    // Set the previous value
1266 1
                    $entry = $this->get_entry();
1267
1268 1
                    $input_name = 'input_'.$field->id;
1269 1
                    $form_id = $form['id'];
1270
1271 1
                    $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1272
1273
                    // Use the previous entry value as the default.
1274 1
                    if( isset( $entry[ $field->id ] ) ) {
1275 1
                        $value = $entry[ $field->id ];
1276
                    }
1277
1278
                    // If this is a single upload file
1279 1
                    if( !empty( $_FILES[ $input_name ] ) && !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1280 1
                        $file_path = GFFormsModel::get_file_upload_path( $form['id'], $_FILES[ $input_name ]['name'] );
1281 1
                        $value = $file_path['url'];
1282
1283
                    } else {
1284
1285
                        // Fix PHP warning on line 1498 of form_display.php for post_image fields
1286
                        // Fix PHP Notice:  Undefined index:  size in form_display.php on line 1511
1287 1
                        $_FILES[ $input_name ] = array('name' => '', 'size' => '' );
0 ignored issues
show
introduced by
No space after opening parenthesis of array is bad style
Loading history...
1288
1289
                    }
1290
1291 1
                    if( rgar($field, "multipleFiles") ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal multipleFiles does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1292
1293
                        // If there are fresh uploads, process and merge them.
1294
                        // Otherwise, use the passed values, which should be json-encoded array of URLs
1295 1
                        if( isset( GFFormsModel::$uploaded_files[$form_id][$input_name] ) ) {
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1296
                            $value = empty( $value ) ? '[]' : $value;
1297
                            $value = stripslashes_deep( $value );
1298 1
                            $value = GFFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'], array());
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1299
                        }
1300
1301
                    } else {
1302
1303
                        // A file already exists when editing an entry
1304
                        // We set this to solve issue when file upload fields are required.
1305 1
                        GFFormsModel::$uploaded_files[ $form_id ][ $input_name ] = $value;
1306
1307
                    }
1308
1309 1
                    $this->entry[ $input_name ] = $value;
1310 1
                    $_POST[ $input_name ] = $value;
1311
1312 1
                    break;
1313
1314 3
                case 'number':
1315
                    // Fix "undefined index" issue at line 1286 in form_display.php
1316 1
                    if( !isset( $_POST['input_'.$field->id ] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1317
                        $_POST['input_'.$field->id ] = NULL;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1318
                    }
1319 3
                    break;
1320
            }
1321
1322
        }
1323
1324 3
        return $form;
1325
    }
1326
1327
1328
    /**
1329
     * Process validation for a edit entry submission
1330
     *
1331
     * Sets the `is_valid` object var
1332
     *
1333
     * @return void
1334
     */
1335 4
    private function validate() {
1336
1337
        /**
1338
         * If using GF User Registration Add-on, remove the validation step, otherwise generates error when updating the entry
1339
         * GF User Registration Add-on version > 3.x has a different class name
1340
         * @since 1.16.2
1341
         */
1342 4
        if ( class_exists( 'GF_User_Registration' ) ) {
1343 4
            remove_filter( 'gform_validation', array( GF_User_Registration::get_instance(), 'validate' ) );
1344
        } else  if ( class_exists( 'GFUser' ) ) {
1345
            remove_filter( 'gform_validation', array( 'GFUser', 'user_registration_validation' ) );
1346
        }
1347
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1348
1349
        /**
1350
         * For some crazy reason, Gravity Forms doesn't validate Edit Entry form submissions.
1351
         * You can enter whatever you want!
1352
         * We try validating, and customize the results using `self::custom_validation()`
1353
         */
1354 4
        add_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10, 4);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1355
1356
        // Needed by the validate funtion
1357 4
        $failed_validation_page = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1358 4
        $field_values = RGForms::post( 'gform_field_values' );
1359
1360
        // Prevent entry limit from running when editing an entry, also
1361
        // prevent form scheduling from preventing editing
1362 4
        unset( $this->form['limitEntries'], $this->form['scheduleForm'] );
1363
1364
        // Hide fields depending on Edit Entry settings
1365 4
        $this->form['fields'] = $this->get_configured_edit_fields( $this->form, $this->view_id );
1366
1367 4
        $this->is_valid = GFFormDisplay::validate( $this->form, $field_values, 1, $failed_validation_page );
1368
1369 4
        remove_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10 );
1370 4
    }
1371
1372
1373
    /**
1374
     * Make validation work for Edit Entry
1375
     *
1376
     * Because we're calling the GFFormDisplay::validate() in an unusual way (as a front-end
1377
     * form pretending to be a back-end form), validate() doesn't know we _can't_ edit post
1378
     * fields. This goes through all the fields and if they're an invalid post field, we
1379
     * set them as valid. If there are still issues, we'll return false.
1380
     *
1381
     * @param  [type] $validation_results [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1382
     * @return [type]                     [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1383
     */
1384 4
    public function custom_validation( $validation_results ) {
1385
1386 4
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results: ', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1387
1388 4
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
1389
1390 4
        $gv_valid = true;
1391
1392 4
        foreach ( $validation_results['form']['fields'] as $key => &$field ) {
1393
1394 4
            $value = RGFormsModel::get_field_value( $field );
1395 4
            $field_type = RGFormsModel::get_input_type( $field );
1396
1397
            // Validate always
1398
            switch ( $field_type ) {
1399
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1400
1401 4
                case 'fileupload' :
1402 4
                case 'post_image':
1403
1404
                    // in case nothing is uploaded but there are already files saved
1405 2
                    if( !empty( $field->failed_validation ) && !empty( $field->isRequired ) && !empty( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1406
                        $field->failed_validation = false;
1407
                        unset( $field->validation_message );
1408
                    }
1409
1410
                    // validate if multi file upload reached max number of files [maxFiles] => 2
1411 2
                    if( rgobj( $field, 'maxFiles') && rgobj( $field, 'multipleFiles') ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1412
1413
                        $input_name = 'input_' . $field->id;
1414
                        //uploaded
1415
                        $file_names = isset( GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] ) ? GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] : array();
1416
1417
                        //existent
1418
                        $entry = $this->get_entry();
1419
                        $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1420
                        if( isset( $entry[ $field->id ] ) ) {
1421
                            $value = json_decode( $entry[ $field->id ], true );
1422
                        }
1423
1424
                        // count uploaded files and existent entry files
1425
                        $count_files = count( $file_names ) + count( $value );
1426
1427
                        if( $count_files > $field->maxFiles ) {
1428
                            $field->validation_message = __( 'Maximum number of files reached', 'gravityview' );
1429
                            $field->failed_validation = 1;
1430
                            $gv_valid = false;
1431
1432
                            // in case of error make sure the newest upload files are removed from the upload input
1433
                            GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ] = null;
1434
                        }
1435
1436
                    }
1437
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1438
1439 2
                    break;
1440
1441
            }
1442
1443
            // This field has failed validation.
1444 4
            if( !empty( $field->failed_validation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1445
1446 1
                do_action( 'gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field is invalid.', array( 'field' => $field, 'value' => $value ) );
1447
1448
                switch ( $field_type ) {
1449
1450
                    // Captchas don't need to be re-entered.
1451 1
                    case 'captcha':
1452
1453
                        // Post Image fields aren't editable, so we un-fail them.
1454 1
                    case 'post_image':
1455
                        $field->failed_validation = false;
1456
                        unset( $field->validation_message );
1457
                        break;
1458
1459
                }
1460
1461
                // You can't continue inside a switch, so we do it after.
1462 1
                if( empty( $field->failed_validation ) ) {
1463
                    continue;
1464
                }
1465
1466
                // checks if the No Duplicates option is not validating entry against itself, since
1467
                // we're editing a stored entry, it would also assume it's a duplicate.
1468 1
                if( !empty( $field->noDuplicates ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1469
1470
                    $entry = $this->get_entry();
1471
1472
                    // If the value of the entry is the same as the stored value
1473
                    // Then we can assume it's not a duplicate, it's the same.
1474
                    if( !empty( $entry ) && $value == $entry[ $field->id ] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1475
                        //if value submitted was not changed, then don't validate
1476
                        $field->failed_validation = false;
1477
1478
                        unset( $field->validation_message );
1479
1480
                        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field not a duplicate; it is the same entry.', $entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1481
1482
                        continue;
1483
                    }
1484
                }
1485
1486
                // if here then probably we are facing the validation 'At least one field must be filled out'
1487 1
                if( GFFormDisplay::is_empty( $field, $this->form_id  ) && empty( $field->isRequired ) ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 2 found
Loading history...
1488
                    unset( $field->validation_message );
1489
	                $field->validation_message = false;
1490
                    continue;
1491
                }
1492
1493 4
                $gv_valid = false;
1494
1495
            }
1496
1497
        }
1498
1499 4
        $validation_results['is_valid'] = $gv_valid;
1500
1501 4
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results.', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1502
1503
        // We'll need this result when rendering the form ( on GFFormDisplay::get_form )
1504 4
        $this->form_after_validation = $validation_results['form'];
1505
1506 4
        return $validation_results;
1507
    }
1508
1509
1510
    /**
1511
     * TODO: This seems to be hacky... we should remove it. Entry is set when updating the form using setup_vars()!
1512
     * Get the current entry and set it if it's not yet set.
1513
     * @return array Gravity Forms entry array
1514
     */
1515 1
    public function get_entry() {
1516
1517 1
        if( empty( $this->entry ) ) {
1518
            // Get the database value of the entry that's being edited
1519 1
            $this->entry = gravityview_get_entry( GravityView_frontend::is_single_entry() );
1520
        }
1521
1522 1
        return $this->entry;
1523
    }
1524
1525
1526
1527
    // --- Filters
1528
1529
    /**
1530
     * Get the Edit Entry fields as configured in the View
1531
     *
1532
     * @since 1.8
1533
     *
1534
     * @param int $view_id
1535
     *
1536
     * @return array Array of fields that are configured in the Edit tab in the Admin
1537
     */
1538 4
    private function get_configured_edit_fields( $form, $view_id ) {
1539
1540
        // Get all fields for form
1541 4
		if ( defined( 'GRAVITYVIEW_FUTURE_CORE_LOADED' ) ) {
1542 4
			if ( \GV\View::exists( $view_id ) ) {
1543 4
				$view = \GV\View::by_id( $view_id );
1544 4
				$properties = $view->fields->as_configuration();
1545
			}
1546
		} else {
1547
			/** GravityView_View_Data is deprecated. */
1548
			$properties = GravityView_View_Data::getInstance()->get_fields( $view_id );
0 ignored issues
show
Deprecated Code introduced by
The method GravityView_View_Data::get_fields() has been deprecated.

This method has been deprecated.

Loading history...
1549
		}
1550
1551
        // If edit tab not yet configured, show all fields
1552 4
        $edit_fields = !empty( $properties['edit_edit-fields'] ) ? $properties['edit_edit-fields'] : NULL;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1553
1554
        // Hide fields depending on admin settings
1555 4
        $fields = $this->filter_fields( $form['fields'], $edit_fields );
1556
1557
	    // If Edit Entry fields are configured, remove adminOnly field settings. Otherwise, don't.
1558 4
	    $fields = $this->filter_admin_only_fields( $fields, $edit_fields, $form, $view_id );
1559
1560
        /**
1561
         * @filter `gravityview/edit_entry/form_fields` Modify the fields displayed in Edit Entry form
1562
         * @since 1.17
1563
         * @param GF_Field[] $fields Gravity Forms form fields
1564
         * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1565
         * @param array $form GF Form array (`fields` key modified to have only fields configured to show in Edit Entry)
1566
         * @param int $view_id View ID
1567
         */
1568 4
        $fields = apply_filters( 'gravityview/edit_entry/form_fields', $fields, $edit_fields, $form, $view_id );
1569
1570 4
        return $fields;
1571
    }
1572
1573
1574
    /**
1575
     * Filter area fields based on specified conditions
1576
     *  - This filter removes the fields that have calculation configured
1577
     *
1578
     * @uses GravityView_Edit_Entry::user_can_edit_field() Check caps
1579
     * @access private
1580
     * @param GF_Field[] $fields
1581
     * @param array $configured_fields
1582
     * @since  1.5
1583
     * @return array $fields
1584
     */
1585 3
    private function filter_fields( $fields, $configured_fields ) {
1586
1587 3
        if( empty( $fields ) || !is_array( $fields ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1588
            return $fields;
1589
        }
1590
1591 3
        $edit_fields = array();
1592
1593 3
        $field_type_blacklist = $this->loader->get_field_blacklist( $this->entry );
1594
1595
        // First, remove blacklist or calculation fields
1596 3
        foreach ( $fields as $key => $field ) {
1597
1598
            // Remove the fields that have calculation properties and keep them to be used later
1599
            // @since 1.16.2
1600 3
            if( $field->has_calculation() ) {
1601
                $this->fields_with_calculation[] = $field;
1602
                // don't remove the calculation fields on form render.
1603
            }
1604
1605 3
            if( in_array( $field->type, $field_type_blacklist ) ) {
1606 3
                unset( $fields[ $key ] );
1607
            }
1608
        }
1609
1610
        // The Edit tab has not been configured, so we return all fields by default.
1611 3
        if( empty( $configured_fields ) ) {
1612 3
            return $fields;
1613
        }
1614
1615
        // The edit tab has been configured, so we loop through to configured settings
1616
        foreach ( $configured_fields as $configured_field ) {
1617
1618
	        /** @var GF_Field $field */
1619
	        foreach ( $fields as $field ) {
1620
1621
                if( intval( $configured_field['id'] ) === intval( $field->id ) && $this->user_can_edit_field( $configured_field, false ) ) {
1622
                    $edit_fields[] = $this->merge_field_properties( $field, $configured_field );
1623
                    break;
1624
                }
1625
1626
            }
1627
1628
        }
1629
1630
        return $edit_fields;
1631
1632
    }
1633
1634
    /**
1635
     * Override GF Form field properties with the ones defined on the View
1636
     * @param  GF_Field $field GF Form field object
1637
     * @param  array $field_setting  GV field options
1638
     * @since  1.5
1639
     * @return array|GF_Field
1640
     */
1641
    private function merge_field_properties( $field, $field_setting ) {
1642
1643
        $return_field = $field;
1644
1645
        if( empty( $field_setting['show_label'] ) ) {
1646
            $return_field->label = '';
1647
        } elseif ( !empty( $field_setting['custom_label'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1648
            $return_field->label = $field_setting['custom_label'];
1649
        }
1650
1651
        if( !empty( $field_setting['custom_class'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1652
            $return_field->cssClass .= ' '. gravityview_sanitize_html_class( $field_setting['custom_class'] );
1653
        }
1654
1655
        /**
1656
         * Normalize page numbers - avoid conflicts with page validation
1657
         * @since 1.6
1658
         */
1659
        $return_field->pageNumber = 1;
1660
1661
        return $return_field;
1662
1663
    }
1664
1665
    /**
1666
     * Remove fields that shouldn't be visible based on the Gravity Forms adminOnly field property
1667
     *
1668
     * @since 1.9.1
1669
     *
1670
     * @param array|GF_Field[] $fields Gravity Forms form fields
1671
     * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1672
     * @param array $form GF Form array
1673
     * @param int $view_id View ID
1674
     *
1675
     * @return array Possibly modified form array
1676
     */
1677 3
    private function filter_admin_only_fields( $fields = array(), $edit_fields = null, $form = array(), $view_id = 0 ) {
1678
1679
	    /**
1680
         * @filter `gravityview/edit_entry/use_gf_admin_only_setting` When Edit tab isn't configured, should the Gravity Forms "Admin Only" field settings be used to control field display to non-admins? Default: true
1681
	     * If the Edit Entry tab is not configured, adminOnly fields will not be shown to non-administrators.
1682
	     * If the Edit Entry tab *is* configured, adminOnly fields will be shown to non-administrators, using the configured GV permissions
1683
	     * @since 1.9.1
1684
	     * @param boolean $use_gf_adminonly_setting True: Hide field if set to Admin Only in GF and the user is not an admin. False: show field based on GV permissions, ignoring GF permissions.
1685
	     * @param array $form GF Form array
1686
	     * @param int $view_id View ID
1687
	     */
1688 3
	    $use_gf_adminonly_setting = apply_filters( 'gravityview/edit_entry/use_gf_admin_only_setting', empty( $edit_fields ), $form, $view_id );
1689
1690 3
	    if( $use_gf_adminonly_setting && false === GVCommon::has_cap( 'gravityforms_edit_entries', $this->entry['id'] ) ) {
1691
            foreach( $fields as $k => $field ) {
1692
                if( $field->adminOnly ) {
1693
                    unset( $fields[ $k ] );
1694
                }
1695
            }
1696
            return $fields;
1697
        }
1698
1699 3
	    foreach( $fields as &$field ) {
1700 3
		    $field->adminOnly = false;
1701
        }
1702
1703 3
        return $fields;
1704
    }
1705
1706
    // --- Conditional Logic
1707
1708
    /**
1709
     * Conditional logic isn't designed to work with forms that already have content. When switching input values,
1710
     * the dependent fields will be blank.
1711
     *
1712
     * Note: This is because GF populates a JavaScript variable with the input values. This is tough to filter at the input level;
1713
     * via the `gform_field_value` filter; it requires lots of legwork. Doing it at the form level is easier.
1714
     *
1715
     * @since 1.17.4
1716
     *
1717
     * @param array $form Gravity Forms array object
1718
     *
1719
     * @return array $form, modified to fix conditional
1720
     */
1721 3
    function prefill_conditional_logic( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1722
1723 3
        if( ! GFFormDisplay::has_conditional_logic( $form ) ) {
1724 3
            return $form;
1725
        }
1726
1727
        // Have Conditional Logic pre-fill fields as if the data were default values
1728
        /** @var GF_Field $field */
1729
        foreach ( $form['fields'] as &$field ) {
1730
1731
            if( 'checkbox' === $field->type ) {
1732
                foreach ( $field->get_entry_inputs() as $key => $input ) {
1733
                    $input_id = $input['id'];
1734
                    $choice = $field->choices[ $key ];
1735
                    $value = rgar( $this->entry, $input_id );
1736
                    $match = RGFormsModel::choice_value_match( $field, $choice, $value );
1737
                    if( $match ) {
1738
                        $field->choices[ $key ]['isSelected'] = true;
1739
                    }
1740
                }
1741
            } else {
1742
1743
                // We need to run through each field to set the default values
1744
                foreach ( $this->entry as $field_id => $field_value ) {
1745
1746
                    if( floatval( $field_id ) === floatval( $field->id ) ) {
1747
1748
                        if( 'list' === $field->type ) {
1749
                            $list_rows = maybe_unserialize( $field_value );
1750
1751
                            $list_field_value = array();
1752
                            foreach ( (array) $list_rows as $row ) {
1753
                                foreach ( (array) $row as $column ) {
1754
                                    $list_field_value[] = $column;
1755
                                }
1756
                            }
1757
1758
                            $field->defaultValue = serialize( $list_field_value );
1759
                        } else {
1760
                            $field->defaultValue = $field_value;
1761
                        }
1762
                    }
1763
                }
1764
            }
1765
        }
1766
1767
        return $form;
1768
    }
1769
1770
    /**
1771
     * Remove the conditional logic rules from the form button and the form fields, if needed.
1772
     *
1773
     * @todo Merge with caller method
1774
     * @since 1.9
1775
     *
1776
     * @param array $form Gravity Forms form
1777
     * @return array Modified form, if not using Conditional Logic
1778
     */
1779 3
    private function filter_conditional_logic( $form ) {
1780
1781
        /**
1782
         * @filter `gravityview/edit_entry/conditional_logic` Should the Edit Entry form use Gravity Forms conditional logic showing/hiding of fields?
1783
         * @since 1.9
1784
         * @param bool $use_conditional_logic True: Gravity Forms will show/hide fields just like in the original form; False: conditional logic will be disabled and fields will be shown based on configuration. Default: true
1785
         * @param array $form Gravity Forms form
1786
         */
1787 3
        $use_conditional_logic = apply_filters( 'gravityview/edit_entry/conditional_logic', true, $form );
1788
1789 3
        if( $use_conditional_logic ) {
1790 3
            return $form;
1791
        }
1792
1793
        foreach( $form['fields'] as &$field ) {
1794
            /* @var GF_Field $field */
1795
            $field->conditionalLogic = null;
1796
        }
1797
1798
        unset( $form['button']['conditionalLogic'] );
1799
1800
        return $form;
1801
1802
    }
1803
1804
    /**
1805
     * Disable the Gravity Forms conditional logic script and features on the Edit Entry screen
1806
     *
1807
     * @since 1.9
1808
     *
1809
     * @param $has_conditional_logic
1810
     * @param $form
1811
     * @return mixed
1812
     */
1813 3
    public function manage_conditional_logic( $has_conditional_logic, $form ) {
1814
1815 3
        if( ! $this->is_edit_entry() ) {
1816
            return $has_conditional_logic;
1817
        }
1818
1819
	    /** @see GravityView_Edit_Entry_Render::filter_conditional_logic for filter documentation */
1820 3
        return apply_filters( 'gravityview/edit_entry/conditional_logic', $has_conditional_logic, $form );
1821
    }
1822
1823
1824
    // --- User checks and nonces
1825
1826
    /**
1827
     * Check if the user can edit the entry
1828
     *
1829
     * - Is the nonce valid?
1830
     * - Does the user have the right caps for the entry
1831
     * - Is the entry in the trash?
1832
     *
1833
     * @todo Move to GVCommon
1834
     *
1835
     * @param  boolean $echo Show error messages in the form?
1836
     * @return boolean        True: can edit form. False: nope.
1837
     */
1838 4
    private function user_can_edit_entry( $echo = false ) {
1839
1840 4
        $error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1841
1842
        /**
1843
         *  1. Permalinks are turned off
1844
         *  2. There are two entries embedded using oEmbed
1845
         *  3. One of the entries has just been saved
1846
         */
1847 4
        if( !empty( $_POST['lid'] ) && !empty( $_GET['entry'] ) && ( $_POST['lid'] !== $_GET['entry'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1848
1849
            $error = true;
1850
1851
        }
1852
1853 4
        if( !empty( $_GET['entry'] ) && (string)$this->entry['id'] !== $_GET['entry'] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1854
1855
            $error = true;
1856
1857 4
        } elseif( ! $this->verify_nonce() ) {
1858
1859
            /**
1860
             * If the Entry is embedded, there may be two entries on the same page.
1861
             * If that's the case, and one is being edited, the other should fail gracefully and not display an error.
1862
             */
1863
            if( GravityView_oEmbed::getInstance()->get_entry_id() ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression \GravityView_oEmbed::get...tance()->get_entry_id() of type integer|null is loosely compared to true; this is ambiguous if the integer can be zero. You might want to explicitly use !== null instead.

In PHP, under loose comparison (like ==, or !=, or switch conditions), values of different types might be equal.

For integer values, zero is a special case, in particular the following results might be unexpected:

0   == false // true
0   == null  // true
123 == false // false
123 == null  // false

// It is often better to use strict comparison
0 === false // false
0 === null  // false
Loading history...
1864
                $error = true;
1865
            } else {
1866
                $error = __( 'The link to edit this entry is not valid; it may have expired.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1867
            }
1868
1869
        }
1870
1871 4
        if( ! GravityView_Edit_Entry::check_user_cap_edit_entry( $this->entry ) ) {
1872 1
            $error = __( 'You do not have permission to edit this entry.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1873
        }
1874
1875 4
        if( $this->entry['status'] === 'trash' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
1876
            $error = __('You cannot edit the entry; it is in the trash.', 'gravityview' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1877
        }
1878
1879
        // No errors; everything's fine here!
1880 4
        if( empty( $error ) ) {
1881 4
            return true;
1882
        }
1883
1884 1
        if( $echo && $error !== true ) {
0 ignored issues
show
introduced by
Found "!== true". Use Yoda Condition checks, you must
Loading history...
1885
1886 1
	        $error = esc_html( $error );
1887
1888
	        /**
1889
	         * @since 1.9
1890
	         */
1891 1
	        if ( ! empty( $this->entry ) ) {
1892 1
		        $error .= ' ' . gravityview_get_link( '#', _x('Go back.', 'Link shown when invalid Edit Entry link is clicked', 'gravityview' ), array( 'onclick' => "window.history.go(-1); return false;" ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal window.history.go(-1); return false; does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1893
	        }
1894
1895 1
            echo GVCommon::generate_notice( wpautop( $error ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1896
        }
1897
1898 1
        do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_entry]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1899
1900 1
        return false;
1901
    }
1902
1903
1904
    /**
1905
     * Check whether a field is editable by the current user, and optionally display an error message
1906
     * @uses  GravityView_Edit_Entry->check_user_cap_edit_field() Check user capabilities
1907
     * @param  array  $field Field or field settings array
1908
     * @param  boolean $echo  Whether to show error message telling user they aren't allowed
1909
     * @return boolean         True: user can edit the current field; False: nope, they can't.
1910
     */
1911
    private function user_can_edit_field( $field, $echo = false ) {
1912
1913
        $error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1914
1915
        if( ! $this->check_user_cap_edit_field( $field ) ) {
1916
            $error = __( 'You do not have permission to edit this field.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1917
        }
1918
1919
        // No errors; everything's fine here!
1920
        if( empty( $error ) ) {
1921
            return true;
1922
        }
1923
1924
        if( $echo ) {
1925
            echo GVCommon::generate_notice( wpautop( esc_html( $error ) ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1926
        }
1927
1928
        do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_field]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1929
1930
        return false;
1931
1932
    }
1933
1934
1935
    /**
1936
     * checks if user has permissions to edit a specific field
1937
     *
1938
     * Needs to be used combined with GravityView_Edit_Entry::user_can_edit_field for maximum security!!
1939
     *
1940
     * @param  [type] $field [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1941
     * @return bool
1942
     */
1943
    private function check_user_cap_edit_field( $field ) {
1944
1945
        // If they can edit any entries (as defined in Gravity Forms), we're good.
1946
        if( GVCommon::has_cap( array( 'gravityforms_edit_entries', 'gravityview_edit_others_entries' ) ) ) {
1947
            return true;
1948
        }
1949
1950
        $field_cap = isset( $field['allow_edit_cap'] ) ? $field['allow_edit_cap'] : false;
1951
1952
        // If the field has custom editing capaibilities set, check those
1953
        if( $field_cap ) {
1954
            return GVCommon::has_cap( $field['allow_edit_cap'] );
1955
        }
1956
1957
        return false;
1958
    }
1959
1960
1961
    /**
1962
     * Is the current nonce valid for editing the entry?
1963
     * @return boolean
1964
     */
1965 3
    public function verify_nonce() {
1966
1967
        // Verify form submitted for editing single
1968 3
        if( $this->is_edit_entry_submission() ) {
1969
            $valid = wp_verify_nonce( $_POST[ self::$nonce_field ], self::$nonce_field );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
1970
        }
1971
1972
        // Verify
1973 3
        else if( ! $this->is_edit_entry() ) {
1974
            $valid = false;
1975
        }
1976
1977
        else {
1978 3
            $valid = wp_verify_nonce( $_GET['edit'], self::$nonce_key );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
1979
        }
1980
1981
        /**
1982
         * @filter `gravityview/edit_entry/verify_nonce` Override Edit Entry nonce validation. Return true to declare nonce valid.
1983
         * @since 1.13
1984
         * @param int|boolean $valid False if invalid; 1 or 2 when nonce was generated
1985
         * @param string $nonce_field Key used when validating submissions. Default: is_gv_edit_entry
1986
         */
1987 3
        $valid = apply_filters( 'gravityview/edit_entry/verify_nonce', $valid, self::$nonce_field );
1988
1989 3
        return $valid;
1990
    }
1991
1992
1993
	/**
1994
	 * Multiselect in GF 2.2 became a json_encoded value. Fix it.
1995
	 *
1996
	 * As a hack for now we'll implode it back.
1997
	 */
1998
	public function fix_multiselect_value_serialization( $field_value, $field, $_this ) {
0 ignored issues
show
Unused Code introduced by
The parameter $_this is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1999
		if ( empty ( $field->storageType ) || $field->storageType != 'json' ) {
0 ignored issues
show
introduced by
Found "!= '". Use Yoda Condition checks, you must
Loading history...
Coding Style introduced by
Space before opening parenthesis of function call prohibited
Loading history...
2000
			return $field_value;
2001
		}
2002
2003
		$maybe_json = @json_decode( $field_value, true );
0 ignored issues
show
Coding Style introduced by
Silencing errors is discouraged
Loading history...
2004
2005
		if ( $maybe_json ) {
2006
			return implode( ',', $maybe_json );
2007
		}
2008
2009
		return $field_value;
2010
	}
2011
2012
2013
2014
} //end class
2015