Completed
Push — develop ( 618ba8...575665 )
by Gennady
20:12
created

GravityView_Edit_Entry_Render   F

Complexity

Total Complexity 283

Size/Duplication

Total Lines 2185
Duplicated Lines 0 %

Coupling/Cohesion

Components 1
Dependencies 11

Test Coverage

Coverage 72.49%

Importance

Changes 0
Metric Value
dl 0
loc 2185
ccs 490
cts 676
cp 0.7249
rs 0.8
c 0
b 0
f 0
wmc 283
lcom 1
cbo 11

45 Methods

Rating   Name   Duplication   Size   Complexity  
A __construct() 0 3 1
A load() 0 28 1
A prevent_render_form() 0 9 3
A prevent_maybe_process_form() 0 11 3
A is_edit_entry() 0 6 3
A is_edit_entry_submission() 0 3 1
A setup_vars() 0 18 1
A init() 0 32 5
A print_scripts() 0 12 1
B process_save() 0 91 6
B unset_hidden_field_values() 0 47 7
A process_save_process_files() 0 16 2
B save_field_value() 0 23 6
A modify_fileupload_settings() 0 9 2
C form_prepare_for_save() 0 57 12
C update_calculation_fields() 0 59 13
C update_post_image() 0 73 14
F maybe_update_post_fields() 0 115 22
A fill_post_template() 0 19 2
C after_update() 0 54 13
B edit_entry_form() 0 56 1
B maybe_print_message() 0 62 8
A render_edit_form() 0 42 1
A render_form_buttons() 0 3 1
A filter_modify_form_fields() 0 22 3
A verify_user_can_edit_post() 0 31 5
B modify_edit_field_input() 0 42 11
D get_field_value() 0 80 20
C gform_pre_validation() 0 87 14
A validate() 0 36 3
F custom_validation() 0 124 21
A get_entry() 0 9 2
A get_configured_edit_fields() 0 31 4
B filter_fields() 0 47 11
A merge_field_properties() 0 23 4
B filter_admin_only_fields() 0 28 6
A unselect_default_values() 0 17 5
B prefill_conditional_logic() 0 48 11
A filter_conditional_logic() 0 24 3
A manage_conditional_logic() 0 9 2
C user_can_edit_entry() 0 64 14
A user_can_edit_field() 0 22 4
A check_user_cap_edit_field() 0 15 4
A verify_nonce() 0 26 3
A fix_multiselect_value_serialization() 0 13 4

How to fix   Complexity   

Complex Class

Complex classes like GravityView_Edit_Entry_Render often do a lot of different things. To break such a class down, we need to identify a cohesive component within that class. A common approach to find such a component is to look for fields/methods that share the same prefixes, or suffixes. You can also have a look at the cohesion graph to spot any un-connected, or weakly-connected components.

Once you have determined the fields that belong together, you can apply the Extract Class refactoring. If the component makes sense as a sub-class, Extract Subclass is also a candidate, and is often faster.

While breaking up the class, it is a good idea to analyze how other classes use GravityView_Edit_Entry_Render, and based on these observations, apply Extract Interface, too.

1
<?php
0 ignored issues
show
Coding Style Compatibility introduced by
For compatibility and reusability of your code, PSR1 recommends that a file should introduce either new symbols (like classes, functions, etc.) or have side-effects (like outputting something, or including other files), but not both at the same time. The first symbol is defined on line 16 and the first side effect is on line 13.

The PSR-1: Basic Coding Standard recommends that a file should either introduce new symbols, that is classes, functions, constants or similar, or have side effects. Side effects are anything that executes logic, like for example printing output, changing ini settings or writing to a file.

The idea behind this recommendation is that merely auto-loading a class should not change the state of an application. It also promotes a cleaner style of programming and makes your code less prone to errors, because the logic is not spread out all over the place.

To learn more about the PSR-1, please see the PHP-FIG site on the PSR-1.

Loading history...
2
/**
3
 * GravityView Edit Entry - render frontend
4
 *
5
 * @package   GravityView
6
 * @license   GPL2+
7
 * @author    Katz Web Services, Inc.
8
 * @link      http://gravityview.co
9
 * @copyright Copyright 2014, Katz Web Services, Inc.
10
 */
11
12
if ( ! defined( 'WPINC' ) ) {
13
	die;
14
}
15
16
class GravityView_Edit_Entry_Render {
17
18
	/**
19
	 * @var GravityView_Edit_Entry
20
	 */
21
	protected $loader;
22
23
	/**
24
	 * @var string String used to generate unique nonce for the entry/form/view combination. Allows access to edit page.
25
	 */
26
	static $nonce_key;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $nonce_key.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
27
28
	/**
29
	 * @since 1.9
30
	 * @var string String used for check valid edit entry form submission. Allows saving edit form values.
31
	 */
32
	private static $nonce_field = 'is_gv_edit_entry';
33
34
	/**
35
	 * @since 1.9
36
	 * @var bool Whether to allow save and continue functionality
37
	 */
38
	private static $supports_save_and_continue = false;
39
40
	/**
41
	 * Gravity Forms entry array
42
	 *
43
	 * @var array
44
	 */
45
	public $entry;
46
47
	/**
48
	 * The View.
49
	 *
50
	 * @var \GV\View.
51
	 * @since develop
52
	 */
53
	public $view;
54
55
	/**
56
	 * Gravity Forms entry array (it won't get changed during this class lifecycle)
57
	 * @since 1.17.2
58
	 * @var array
59
	 */
60
	private static $original_entry = array();
61
62
	/**
63
	 * Gravity Forms form array (GravityView modifies the content through this class lifecycle)
64
	 *
65
	 * @var array
66
	 */
67
	public $form;
68
69
	/**
70
	 * Gravity Forms form array (it won't get changed during this class lifecycle)
71
	 * @since 1.16.2.1
72
	 * @var array
73
	 */
74
	private static $original_form;
75
76
	/**
77
	 * Gravity Forms form array after the form validation process
78
	 * @since 1.13
79
	 * @var array
80
	 */
81
	public $form_after_validation = null;
82
83
	/**
84
	 * Hold an array of GF field objects that have calculation rules
85
	 * @var array
86
	 */
87
	public $fields_with_calculation = array();
88
89
	/**
90
	 * Gravity Forms form id
91
	 *
92
	 * @var int
93
	 */
94
	public $form_id;
95
96
	/**
97
	 * ID of the current view
98
	 *
99
	 * @var int
100
	 */
101
	public $view_id;
102
103
	/**
104
	 * ID of the current post. May also be ID of the current View.
105
     *
106
     * @since 2.0.13
107
     * 
108
     * @var int
109
	 */
110
	public $post_id;
111 12
112 12
	/**
113 12
	 * Updated entry is valid (GF Validation object)
114
	 *
115 12
	 * @var array
116
	 */
117
	public $is_valid = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
118 12
119
	function __construct( GravityView_Edit_Entry $loader ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
120
		$this->loader = $loader;
121 12
	}
122 12
123
	function load() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
124
125 12
		/** @define "GRAVITYVIEW_DIR" "../../../" */
126
		include_once( GRAVITYVIEW_DIR .'includes/class-admin-approve-entries.php' );
127 12
128
		// Don't display an embedded form when editing an entry
129 12
		add_action( 'wp_head', array( $this, 'prevent_render_form' ) );
130
		add_action( 'wp_footer', array( $this, 'prevent_render_form' ) );
131
132 12
		// Stop Gravity Forms processing what is ours!
133
		add_filter( 'wp', array( $this, 'prevent_maybe_process_form'), 8 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
134
135 12
		add_filter( 'gravityview_is_edit_entry', array( $this, 'is_edit_entry') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
136
137
		add_action( 'gravityview_edit_entry', array( $this, 'init' ), 10, 4 );
138 12
139
		// Disable conditional logic if needed (since 1.9)
140
		add_filter( 'gform_has_conditional_logic', array( $this, 'manage_conditional_logic' ), 10, 2 );
141 12
142 12
		// Make sure GF doesn't validate max files (since 1.9)
143
		add_filter( 'gform_plupload_settings', array( $this, 'modify_fileupload_settings' ), 10, 3 );
144
145
		// Add fields expected by GFFormDisplay::validate()
146
		add_filter( 'gform_pre_validation', array( $this, 'gform_pre_validation') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
147
148
		// Fix multiselect value for GF 2.2
149
		add_filter( 'gravityview/edit_entry/field_value_multiselect', array( $this, 'fix_multiselect_value_serialization' ), 10, 3 );
150
	}
151
152
	/**
153
	 * Don't show any forms embedded on a page when GravityView is in Edit Entry mode
154 1
	 *
155 1
	 * Adds a `__return_empty_string` filter on the Gravity Forms shortcode on the `wp_head` action
156 1
	 * And then removes it on the `wp_footer` action
157 1
	 *
158
	 * @since 1.16.1
159 1
	 *
160
	 * @return void
161
	 */
162 1
	public function prevent_render_form() {
163
		if( $this->is_edit_entry() ) {
164
			if( 'wp_head' === current_filter() ) {
165
				add_filter( 'gform_shortcode_form', '__return_empty_string' );
166
			} else {
167
				remove_filter( 'gform_shortcode_form', '__return_empty_string' );
168
			}
169 1
		}
170
	}
171 1
172
	/**
173
	 * Because we're mimicking being a front-end Gravity Forms form while using a Gravity Forms
174
	 * backend form, we need to prevent them from saving twice.
175 1
	 * @return void
176
	 */
177
	public function prevent_maybe_process_form() {
178
179 1
		if( ! empty( $_POST ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
180
	        gravityview()->log->debug( 'GravityView_Edit_Entry[prevent_maybe_process_form] $_POSTed data (sanitized): ', array( 'data' => esc_html( print_r( $_POST, true ) ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
181
		}
182
183
		if( $this->is_edit_entry_submission() ) {
184
			remove_action( 'wp',  array( 'RGForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
185 15
	        remove_action( 'wp',  array( 'GFForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
186
		}
187 15
	}
188
189 15
	/**
190
	 * Is the current page an Edit Entry page?
191
	 * @return boolean
192
	 */
193
	public function is_edit_entry() {
194
195
		$is_edit_entry = GravityView_frontend::is_single_entry() && ! empty( $_GET['edit'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
196
197 15
		return ( $is_edit_entry || $this->is_edit_entry_submission() );
198 15
	}
199
200
	/**
201
	 * Is the current page an Edit Entry page?
202
	 * @since 1.9
203
	 * @return boolean
204 12
	 */
205 12
	public function is_edit_entry_submission() {
206
		return !empty( $_POST[ self::$nonce_field ] );
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
207 12
	}
208
209
	/**
210 12
	 * When Edit entry view is requested setup the vars
211 12
	 */
212 12
	private function setup_vars() {
213
        global $post;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
214 12
215 12
		$gravityview_view = GravityView_View::getInstance();
216 12
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
217 12
218 12
		$entries = $gravityview_view->getEntries();
219
	    self::$original_entry = $entries[0];
220 12
	    $this->entry = $entries[0];
221 12
222
		self::$original_form = $gravityview_view->getForm();
223
		$this->form = $gravityview_view->getForm();
224
		$this->form_id = $this->entry['form_id'];
225
		$this->view_id = $gravityview_view->getViewId();
226
		$this->post_id = \GV\Utils::get( $post, 'ID', null );
227
228
		self::$nonce_key = GravityView_Edit_Entry::get_nonce_key( $this->view_id, $this->form_id, $this->entry['id'] );
229
	}
230
231
232 13
	/**
233
	 * Load required files and trigger edit flow
234 13
	 *
235 13
	 * Run when the is_edit_entry returns true.
236
	 *
237 13
	 * @param \GravityView_View_Data $gv_data GravityView Data object
238
	 * @param \GV\Entry   $entry   The Entry.
239 13
	 * @param \GV\View    $view    The View.
240
	 * @param \GV\Request $request The Request.
241
	 *
242
	 * @since develop Added $entry, $view, $request adhocs.
243
	 *
244 13
	 * @return void
245
	 */
246
	public function init( $gv_data = null, $entry = null, $view = null, $request = null ) {
247
248
		require_once( GFCommon::get_base_path() . '/form_display.php' );
249
		require_once( GFCommon::get_base_path() . '/entry_detail.php' );
250 13
251 1
		$this->setup_vars();
252 1
253
		if ( ! $gv_data ) {
254
			$gv_data = GravityView_View_Data::getInstance();
255 13
		}
256
257 13
		// Multiple Views embedded, don't proceed if nonce fails
258
		if ( $gv_data->has_multiple_views() && ! $this->verify_nonce() ) {
0 ignored issues
show
Deprecated Code introduced by
The method GravityView_View_Data::has_multiple_views() has been deprecated.

This method has been deprecated.

Loading history...
259 13
			gravityview()->log->error( 'Nonce validation failed for the Edit Entry request; returning' );
260
			return;
261 13
		}
262
263
		// Sorry, you're not allowed here.
264
		if ( false === $this->user_can_edit_entry( true ) ) {
265
			gravityview()->log->error( 'User is not allowed to edit this entry; returning', array( 'data' => $this->entry ) );
266
			return;
267
		}
268 12
269 12
		$this->view = $view;
270
271 12
		$this->print_scripts();
272
273 12
		$this->process_save( $gv_data );
274
275 12
		$this->edit_entry_form();
276
277
	}
278 12
279 12
280
	/**
281
	 * Force Gravity Forms to output scripts as if it were in the admin
282
	 * @return void
283
	 */
284
	private function print_scripts() {
285
		$gravityview_view = GravityView_View::getInstance();
286
287 13
		wp_register_script( 'gform_gravityforms', GFCommon::get_base_url().'/js/gravityforms.js', array( 'jquery', 'gform_json', 'gform_placeholder', 'sack', 'plupload-all', 'gravityview-fe-view' ) );
288
289 13
		GFFormDisplay::enqueue_form_scripts( $gravityview_view->getForm(), false);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
290 5
291
		wp_localize_script( 'gravityview-fe-view', 'gvGlobals', array( 'cookiepath' => COOKIEPATH ) );
292
293
		// Sack is required for images
294 12
		wp_print_scripts( array( 'sack', 'gform_gravityforms', 'gravityview-fe-view' ) );
295
	}
296 12
297
298
	/**
299
	 * Process edit entry form save
300
	 *
301 12
	 * @param array $gv_data The View data.
302
	 */
303
	private function process_save( $gv_data ) {
304
305
		if ( empty( $_POST ) || ! isset( $_POST['lid'] ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
306 12
			return;
307
		}
308 12
309
		// Make sure the entry, view, and form IDs are all correct
310 12
		$valid = $this->verify_nonce();
311
312 12
		if ( !$valid ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
313
			gravityview()->log->error( 'Nonce validation failed.' );
314 12
			return;
315
		}
316
317
		if ( $this->entry['id'] !== $_POST['lid'] ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
318
			gravityview()->log->error( 'Entry ID did not match posted entry ID.' );
319 12
			return;
320
		}
321
322
		gravityview()->log->debug( '$_POSTed data (sanitized): ', array( 'data' => esc_html( print_r( $_POST, true ) ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
323
324 12
		$this->process_save_process_files( $this->form_id );
325
326 12
		$this->validate();
327
328
		if( $this->is_valid ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using ! empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
329
330
			gravityview()->log->debug( 'Submission is valid.' );
331
332 12
			/**
333
			 * @hack This step is needed to unset the adminOnly from form fields, to add the calculation fields
334 12
			 */
335
			$form = $this->form_prepare_for_save();
336
337 12
			/**
338
			 * @hack to avoid the capability validation of the method save_lead for GF 1.9+
339 12
			 */
340
			unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
341
342 12
			$date_created = $this->entry['date_created'];
343
344
			/**
345 12
			 * @hack to force Gravity Forms to use $read_value_from_post in GFFormsModel::save_lead()
346
			 * @since 1.17.2
347
			 */
348
			unset( $this->entry['date_created'] );
349
350
			/**
351 12
			 * @action `gravityview/edit_entry/before_update` Perform an action after the entry has been updated using Edit Entry
352
			 * @since develop
353
			 * @param array $form Gravity Forms form array
354
			 * @param string $entry_id Numeric ID of the entry that is being updated
355
			 * @param GravityView_Edit_Entry_Render $this This object
356
			 * @param GravityView_View_Data $gv_data The View data
357
			 */
358
			do_action( 'gravityview/edit_entry/before_update', $form, $this->entry['id'], $this, $gv_data );
359
360
			GFFormsModel::save_lead( $form, $this->entry );
361 12
362
	        // Delete the values for hidden inputs
363
	        $this->unset_hidden_field_values();
364
			
365
			$this->entry['date_created'] = $date_created;
366
367 12
			// Process calculation fields
368
			$this->update_calculation_fields();
369
370
			// Perform actions normally performed after updating a lead
371
			$this->after_update();
372
373
	        /**
374
			 * Must be AFTER after_update()!
375
			 * @see https://github.com/gravityview/GravityView/issues/764
376
			 */
377
			$this->maybe_update_post_fields( $form );
378 11
379 11
			/**
380
			 * @action `gravityview/edit_entry/after_update` Perform an action after the entry has been updated using Edit Entry
381
             * @since 2.1 Added $gv_data parameter
382
			 * @param array $form Gravity Forms form array
383
			 * @param string $entry_id Numeric ID of the entry that was updated
384
			 * @param GravityView_Edit_Entry_Render $this This object
385
			 * @param GravityView_View_Data $gv_data The View data
386
			 */
387 11
			do_action( 'gravityview/edit_entry/after_update', $this->form, $this->entry['id'], $this, $gv_data );
388
389 11
		} else {
390
			gravityview()->log->error( 'Submission is NOT valid.', array( 'entry' => $this->entry ) );
391
		}
392
393 11
	} // process_save
394 11
395 11
	/**
396
	 * Delete the value of fields hidden by conditional logic when the entry is edited
397
	 *
398
	 * @uses GFFormsModel::update_lead_field_value()
399
	 *
400
	 * @since 1.17.4
401 11
	 *
402
	 * @return void
403 11
	 */
404
	private function unset_hidden_field_values() {
405
	    global $wpdb;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
406
407 11
		/**
408
		 * @filter `gravityview/edit_entry/unset_hidden_field_values` Whether to delete values of fields hidden by conditional logic
409
		 * @since 1.22.2
410
		 * @param bool $unset_hidden_field_values Default: true
411
		 * @param GravityView_Edit_Entry_Render $this This object
412
		 */
413
		$unset_hidden_field_values = apply_filters( 'gravityview/edit_entry/unset_hidden_field_values', true, $this );
414
415
		if( ! $unset_hidden_field_values ) {
416
			return;
417
		}
418
419
		if ( version_compare( GravityView_GFFormsModel::get_database_version(), '2.3-dev-1', '>=' ) && method_exists( 'GFFormsModel', 'get_entry_meta_table_name' ) ) {
420
			$entry_meta_table = GFFormsModel::get_entry_meta_table_name();
421 11
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $entry_meta_table WHERE entry_id=%d", $this->entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
422
		} else {
423
			$lead_detail_table = GFFormsModel::get_lead_details_table_name();
424 11
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $lead_detail_table WHERE lead_id=%d", $this->entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
425
		}
426
427
	    foreach ( $this->entry as $input_id => $field_value ) {
428
429
		    $field = RGFormsModel::get_field( $this->form, $input_id );
430
431
		    // Reset fields that are hidden
432
		    // Don't pass $entry as fourth parameter; force using $_POST values to calculate conditional logic
433 11
		    if ( GFFormsModel::is_field_hidden( $this->form, $field, array(), NULL ) ) {
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
434
435
				$empty_value = $field->get_value_save_entry(
436 11
					is_array( $field->get_entry_inputs() ) ? array() : '',
437 11
					$this->form, '', $this->entry['id'], $this->entry
438 10
				);
439
440
			    $lead_detail_id = GFFormsModel::get_lead_detail_id( $current_fields, $input_id );
441
442
			    GFFormsModel::update_lead_field_value( $this->form, $this->entry, $field, $lead_detail_id, $input_id, $empty_value );
443
444
			    // Prevent the $_POST values of hidden fields from being used as default values when rendering the form
445 11
				// after submission
446
			    $post_input_id = 'input_' . str_replace( '.', '_', $input_id );
447 11
			    $_POST[ $post_input_id ] = '';
448 11
		    }
449
	    }
450
	}
451
452
	/**
453
	 * Have GF handle file uploads
454
	 *
455
	 * Copy of code from GFFormDisplay::process_form()
456
	 *
457
	 * @param int $form_id
458
	 */
459
	private function process_save_process_files( $form_id ) {
460
461
		//Loading files that have been uploaded to temp folder
462
		$files = GFCommon::json_decode( stripslashes( RGForms::post( 'gform_uploaded_files' ) ) );
463
		if ( ! is_array( $files ) ) {
464
			$files = array();
465 11
		}
466
467 11
		/**
468 11
		 * Make sure the fileuploads are not overwritten if no such request was done.
469
		 * @since 1.20.1
470
		 */
471 1
		add_filter( "gform_save_field_value_$form_id", array( $this, 'save_field_value' ), 99, 5 );
472
473 1
		RGFormsModel::$uploaded_files[ $form_id ] = $files;
474
	}
475
476
	/**
477
	 * Make sure the fileuploads are not overwritten if no such request was done.
478
	 *
479
	 * TO ONLY BE USED INTERNALLY; DO NOT DEVELOP ON; MAY BE REMOVED AT ANY TIME.
480
	 *
481 1
	 * @since 1.20.1
482
	 *
483 1
	 * @param string $value Field value
484
	 * @param array $entry GF entry array
485
	 * @param GF_Field_FileUpload $field
486 1
	 * @param array $form GF form array
487
	 * @param string $input_id ID of the input being saved
488
	 *
489
	 * @return string
490
	 */
491
	public function save_field_value( $value = '', $entry = array(), $field = null, $form = array(), $input_id = '' ) {
492
493
		if ( ! $field || $field->type != 'fileupload' ) {
0 ignored issues
show
introduced by
Found "!= '". Use Yoda Condition checks, you must
Loading history...
494
			return $value;
495
		}
496
497
		$input_name = 'input_' . str_replace( '.', '_', $input_id );
498 2
499 2
		if ( $field->multipleFiles ) {
500
			if ( empty( $value ) ) {
501
				return json_decode( $entry[ $input_id ], true );
502
			}
503 2
			return $value;
504
		}
505 2
506
		/** No file is being uploaded. */
507
		if ( empty( $_FILES[ $input_name ]['name'] ) ) {
508
			/** So return the original upload */
509
			return $entry[ $input_id ];
510
		}
511
512
		return $value;
513 11
	}
514
515 11
	/**
516
	 * Remove max_files validation (done on gravityforms.js) to avoid conflicts with GravityView
517
	 * Late validation done on self::custom_validation
518 11
	 *
519
	 * @param $plupload_init array Plupload settings
520
	 * @param $form_id
521
	 * @param $instance
522
	 * @return mixed
523
	 */
524
	public function modify_fileupload_settings( $plupload_init, $form_id, $instance ) {
0 ignored issues
show
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $instance is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
525 11
		if( ! $this->is_edit_entry() ) {
526 3
			return $plupload_init;
527
		}
528
529 11
		$plupload_init['gf_vars']['max_files'] = 0;
530
531 11
		return $plupload_init;
532 2
	}
533 11
534
535
	/**
536
	 * Set visibility to visible and convert field input key to string
537
	 * @return array $form
538 11
	 */
539
	private function form_prepare_for_save() {
540 11
541
		$form = $this->form;
542
543 11
		$non_submitted_fields = array();
544 11
545
	    /** @var GF_Field $field */
546 11
		foreach( $form['fields'] as $k => &$field ) {
547 11
548
			/**
549
			 * Remove the fields with calculation formulas before save to avoid conflicts with GF logic
550 11
			 * @since 1.16.3
551
			 * @var GF_Field $field
552 11
			 */
553 11
			if( $field->has_calculation() ) {
554 11
				unset( $form['fields'][ $k ] );
555
			}
556
557
			$field->adminOnly = false;
558
559
			if( isset( $field->inputs ) && is_array( $field->inputs ) ) {
560
				foreach( $field->inputs as $key => $input ) {
561 11
				    $field->inputs[ $key ][ 'id' ] = (string)$input['id'];
0 ignored issues
show
introduced by
Array keys should NOT be surrounded by spaces if they only contain a string or an integer.
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
562 4
				}
563 4
			}
564
565 4
			/**
566 4
			 * Unset fields that are used in conditionals, but only if these fields
567 4
			 * are not present in the edit view fields.
568 3
			 * @since develop
569 3
			 */
570
			if ( ! empty( $field['conditionalLogic'] ) && ! empty( $field['conditionalLogic']['rules'] ) ) {
571 3
				foreach ( wp_list_pluck( $field['conditionalLogic']['rules'], 'fieldId' ) as $conditional_id ) {
572 3
					$post_input_id = 'input_' . str_replace( '.', '_', $conditional_id );
573
					if ( ! isset( $_POST[ $post_input_id ] ) ) {
574
						$non_submitted_fields []= $conditional_id;
0 ignored issues
show
introduced by
Expected 1 space before "="; 0 found
Loading history...
575 3
					}
576
				}
577 3
			}
578
		}
579
580
		/**
581
		 * Remove fields that are not submitted. For now we only do this with
582
		 * fields that are used in conditional logic. In the future we may try
583
		 * (or need) to remove all fields that are not being submitted. Or look
584
		 * at the view edit configuration.
585
		 */
586 3
		foreach ( $form['fields'] as $k => $field ) {
587
			if ( in_array( $field['id'], $non_submitted_fields ) ) {
588
				unset( $form['fields'][ $k ] );
589
			}
590 3
		}
591 2
592
		$form['fields'] = array_values( $form['fields'] );
593 4
594
		return $form;
595
	}
596
597 4
	private function update_calculation_fields() {
598 4
		global $wpdb;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
599
600
		$form = self::$original_form;
601 11
		$update = false;
602
603
		// get the most up to date entry values
604
		$entry = GFAPI::get_entry( $this->entry['id'] );
605
606
		if ( version_compare( GravityView_GFFormsModel::get_database_version(), '2.3-dev-1', '>=' ) && method_exists( 'GFFormsModel', 'get_entry_meta_table_name' ) ) {
607
			$entry_meta_table = GFFormsModel::get_entry_meta_table_name();
608
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $entry_meta_table WHERE entry_id=%d", $entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
609
		} else {
610
			$lead_detail_table = GFFormsModel::get_lead_details_table_name();
611
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM $lead_detail_table WHERE lead_id=%d", $entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
612
		}
613
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
614
615
		if ( ! empty( $this->fields_with_calculation ) ) {
616
			$allowed_fields = $this->get_configured_edit_fields( $form, $this->view_id );
617
			$allowed_fields = wp_list_pluck( $allowed_fields, 'id' );
618
619
			foreach ( $this->fields_with_calculation as $field ) {
620
				$inputs = $field->get_entry_inputs();
621
				if ( is_array( $inputs ) ) {
622 1
				    foreach ( $inputs as $input ) {
623
						list( $field_id, $input_id ) = rgexplode( '.', $input['id'], 2 );
624 1
625
						if ( 'product' === $field->type ) {
626 1
							$input_name = 'input_' . str_replace( '.', '_', $input['id'] );
627
628
							// Only allow quantity to be set if it's allowed to be edited
629
							if ( in_array( $field_id, $allowed_fields ) && $input_id == 3 ) {
0 ignored issues
show
Unused Code introduced by
This if statement is empty and can be removed.

This check looks for the bodies of if statements that have no statements or where all statements have been commented out. This may be the result of changes for debugging or the code may simply be obsolete.

These if bodies can be removed. If you have an empty if but statements in the else branch, consider inverting the condition.

if (rand(1, 6) > 3) {
//print "Check failed";
} else {
    print "Check succeeded";
}

could be turned into

if (rand(1, 6) <= 3) {
    print "Check succeeded";
}

This is much more concise to read.

Loading history...
introduced by
Found "== 3". Use Yoda Condition checks, you must
Loading history...
630
							} else { // otherwise set to what it previously was
631
								$_POST[ $input_name ] = $entry[ $input['id'] ];
632
							}
633
						} else {
634
							// Set to what it previously was if it's not editable
635
							if ( ! in_array( $field_id, $allowed_fields ) ) {
636
								$_POST[ $input_name ] = $entry[ $input['id'] ];
0 ignored issues
show
Bug introduced by
The variable $input_name does not seem to be defined for all execution paths leading up to this point.

If you define a variable conditionally, it can happen that it is not defined for all execution paths.

Let’s take a look at an example:

function myFunction($a) {
    switch ($a) {
        case 'foo':
            $x = 1;
            break;

        case 'bar':
            $x = 2;
            break;
    }

    // $x is potentially undefined here.
    echo $x;
}

In the above example, the variable $x is defined if you pass “foo” or “bar” as argument for $a. However, since the switch statement has no default case statement, if you pass any other value, the variable $x would be undefined.

Available Fixes

  1. Check for existence of the variable explicitly:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        if (isset($x)) { // Make sure it's always set.
            echo $x;
        }
    }
    
  2. Define a default value for the variable:

    function myFunction($a) {
        $x = ''; // Set a default which gets overridden for certain paths.
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        echo $x;
    }
    
  3. Add a value for the missing path:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
    
            // We add support for the missing case.
            default:
                $x = '';
                break;
        }
    
        echo $x;
    }
    
Loading history...
637
							}
638
						}
639
640
						GFFormsModel::save_input( $form, $field, $entry, $current_fields, $input['id'] );
641
				    }
642
				} else {
643
					// Set to what it previously was if it's not editable
644
					if ( ! in_array( $field->id, $allowed_fields ) ) {
645
						$_POST[ 'input_' . $field->id ] = $entry[ $field->id ];
646
					}
647
					GFFormsModel::save_input( $form, $field, $entry, $current_fields, $field->id );
648
				}
649
			}
650
651
			if ( method_exists( 'GFFormsModel', 'commit_batch_field_operations' ) ) {
652
				GFFormsModel::commit_batch_field_operations();
653
			}
654
		}
655
	}
656
657
	/**
658
	 * Handle updating the Post Image field
659
	 *
660
	 * Sets a new Featured Image if configured in Gravity Forms; otherwise uploads/updates media
661
	 *
662 1
	 * @since 1.17
663
	 *
664 1
	 * @uses GFFormsModel::media_handle_upload
665 1
	 * @uses set_post_thumbnail
666 1
	 *
667 1
	 * @param array $form GF Form array
668
	 * @param GF_Field $field GF Field
669 1
	 * @param string $field_id Numeric ID of the field
670
	 * @param string $value
671 1
	 * @param array $entry GF Entry currently being edited
672
	 * @param int $post_id ID of the Post being edited
673
	 *
674 1
	 * @return mixed|string
675 1
	 */
676 1
	private function update_post_image( $form, $field, $field_id, $value, $entry, $post_id ) {
677 1
678
		$input_name = 'input_' . $field_id;
679
680
		if ( !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
681 1
682
			// We have a new image
683
684
			$value = RGFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'] );
685
686
			$ary = ! empty( $value ) ? explode( '|:|', $value ) : array();
687
	        $ary = stripslashes_deep( $ary );
688
			$img_url = \GV\Utils::get( $ary, 0 );
689
690
			$img_title       = count( $ary ) > 1 ? $ary[1] : '';
691
			$img_caption     = count( $ary ) > 2 ? $ary[2] : '';
692
			$img_description = count( $ary ) > 3 ? $ary[3] : '';
693 1
694
			$image_meta = array(
695
				'post_excerpt' => $img_caption,
696
				'post_content' => $img_description,
697
			);
698
699
			//adding title only if it is not empty. It will default to the file name if it is not in the array
700
			if ( ! empty( $img_title ) ) {
701
				$image_meta['post_title'] = $img_title;
702
			}
703 11
704
			/**
705 11
			 * todo: As soon as \GFFormsModel::media_handle_upload becomes a public method, move this call to \GFFormsModel::media_handle_upload and remove the hack from this class.
706 10
			 * Note: the method became public in GF 1.9.17.7, but we don't require that version yet.
707 10
			 */
708
			require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
709
			$media_id = GravityView_GFFormsModel::media_handle_upload( $img_url, $post_id, $image_meta );
710 1
711
			// is this field set as featured image?
712
			if ( $media_id && $field->postFeaturedImage ) {
713 1
				set_post_thumbnail( $post_id, $media_id );
714
			}
715
716
		} elseif ( ! empty( $_POST[ $input_name ] ) && is_array( $value ) ) {
717
718 1
			$img_url         = stripslashes_deep( $_POST[ $input_name ] );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
719
			$img_title       = stripslashes_deep( \GV\Utils::_POST( $input_name . '_1' ) );
720 1
			$img_caption     = stripslashes_deep( \GV\Utils::_POST( $input_name . '_4' ) );
721
			$img_description = stripslashes_deep( \GV\Utils::_POST( $input_name . '_7' ) );
722 1
723
			$value = ! empty( $img_url ) ? $img_url . "|:|" . $img_title . "|:|" . $img_caption . "|:|" . $img_description : '';
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal |:| does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
724 1
725
			if ( $field->postFeaturedImage ) {
726 1
727 1
				$image_meta = array(
728
					'ID' => get_post_thumbnail_id( $post_id ),
729
					'post_title' => $img_title,
730 1
					'post_excerpt' => $img_caption,
731
					'post_content' => $img_description,
732
				);
733 1
734
				// update image title, caption or description
735
				wp_update_post( $image_meta );
736 1
			}
737 1
		} else {
738
739 1
			// if we get here, image was removed or not set.
740
			$value = '';
741 1
742
			if ( $field->postFeaturedImage ) {
743
				delete_post_thumbnail( $post_id );
744
			}
745
		}
746
747
		return $value;
748
	}
749
750
	/**
751 1
	 * Loop through the fields being edited and if they include Post fields, update the Entry's post object
752
	 *
753
	 * @param array $form Gravity Forms form
754
	 *
755
	 * @return void
756
	 */
757
	private function maybe_update_post_fields( $form ) {
758
759 1
		if( empty( $this->entry['post_id'] ) ) {
760
	        gravityview()->log->debug( 'This entry has no post fields. Continuing...' );
761
			return;
762 1
		}
763
764
		$post_id = $this->entry['post_id'];
765 1
766
		// Security check
767 1
		if( false === GVCommon::has_cap( 'edit_post', $post_id ) ) {
768
			gravityview()->log->error( 'The current user does not have the ability to edit Post #{post_id}', array( 'post_id' => $post_id ) );
769
			return;
770
		}
771
772
		$update_entry = false;
773
774
		$updated_post = $original_post = get_post( $post_id );
775
776
		foreach ( $this->entry as $field_id => $value ) {
777
778
			$field = RGFormsModel::get_field( $form, $field_id );
779
780
			if( ! $field ) {
781 1
				continue;
782 1
			}
783 1
784
			if( GFCommon::is_post_field( $field ) && 'post_category' !== $field->type ) {
785
786
				// Get the value of the field, including $_POSTed value
787
				$value = RGFormsModel::get_field_value( $field );
788 1
789
				// Use temporary entry variable, to make values available to fill_post_template() and update_post_image()
790 1
				$entry_tmp = $this->entry;
791
				$entry_tmp["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
792 1
793
				switch( $field->type ) {
794
795
				    case 'post_title':
796
				        $post_title = $value;
797 1
				        if ( \GV\Utils::get( $form, 'postTitleTemplateEnabled' ) ) {
798
				            $post_title = $this->fill_post_template( $form['postTitleTemplate'], $form, $entry_tmp );
799 1
				        }
800
				        $updated_post->post_title = $post_title;
801 1
				        $updated_post->post_name  = $post_title;
802
				        unset( $post_title );
803
				        break;
804 1
805
				    case 'post_content':
806
				        $post_content = $value;
807
				        if ( \GV\Utils::get( $form, 'postContentTemplateEnabled' ) ) {
808
				            $post_content = $this->fill_post_template( $form['postContentTemplate'], $form, $entry_tmp, true );
809 1
				        }
810
				        $updated_post->post_content = $post_content;
811 1
				        unset( $post_content );
812
				        break;
813
				    case 'post_excerpt':
814
				        $updated_post->post_excerpt = $value;
815 1
				        break;
816
				    case 'post_tags':
817 1
				        wp_set_post_tags( $post_id, $value, false );
818
				        break;
819
				    case 'post_category':
820
				        break;
821
				    case 'post_custom_field':
822
						if ( is_array( $value ) && ( floatval( $field_id ) !== floatval( $field->id ) ) ) {
823
							$value = $value[ $field_id ];
824
						}
825
826
				        if( ! empty( $field->customFieldTemplateEnabled ) ) {
827
				            $value = $this->fill_post_template( $field->customFieldTemplate, $form, $entry_tmp, true );
828
				        }
829
830
						$value = $field->get_value_save_entry( $value, $form, '', $this->entry['id'], $this->entry );
831
832
				        update_post_meta( $post_id, $field->postCustomFieldName, $value );
833
				        break;
834
835
				    case 'post_image':
836
				        $value = $this->update_post_image( $form, $field, $field_id, $value, $this->entry, $post_id );
837
				        break;
838
839
				}
840
841
				// update entry after
842
				$this->entry["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
843
844
				$update_entry = true;
845
846
				unset( $entry_tmp );
847
			}
848
849
		}
850
851
		if( $update_entry ) {
852
853
			$return_entry = GFAPI::update_entry( $this->entry );
854
855
			if( is_wp_error( $return_entry ) ) {
856
				gravityview()->log->error( 'Updating the entry post fields failed', array( 'data' => array( '$this->entry' => $this->entry, '$return_entry' => $return_entry ) ) );
857
			} else {
858
				gravityview()->log->debug( 'Updating the entry post fields for post #{post_id} succeeded', array( 'post_id' => $post_id ) );
859
			}
860
861
		}
862 11
863
		$return_post = wp_update_post( $updated_post, true );
864 11
865 11
		if( is_wp_error( $return_post ) ) {
866
			$return_post->add_data( $updated_post, '$updated_post' );
867
			gravityview()->log->error( 'Updating the post content failed', array( 'data' => compact( 'updated_post', 'return_post' ) ) );
868 11
		} else {
869
			gravityview()->log->debug( 'Updating the post content for post #{post_id} succeeded', array( 'post_id' => $post_id, 'data' => $updated_post ) );
870 11
		}
871
	}
872 11
873
	/**
874
	 * Convert a field content template into prepared output
875
	 *
876
	 * @uses GravityView_GFFormsModel::get_post_field_images()
877
	 *
878
	 * @since 1.17
879
	 *
880 11
	 * @param string $template The content template for the field
881 11
	 * @param array $form Gravity Forms form
882
	 * @param bool $do_shortcode Whether to process shortcode inside content. In GF, only run on Custom Field and Post Content fields
883
	 *
884
	 * @return string
885
	 */
886
	private function fill_post_template( $template, $form, $entry, $do_shortcode = false ) {
887
888
		require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
889 12
890
		$post_images = GravityView_GFFormsModel::get_post_field_images( $form, $entry );
891
892
		//replacing post image variables
893
		$output = GFCommon::replace_variables_post_image( $template, $post_images, $entry );
894
895 12
		//replacing all other variables
896
		$output = GFCommon::replace_variables( $output, $form, $entry, false, false, false );
897
898
		// replace conditional shortcodes
899
		if( $do_shortcode ) {
900
			$output = do_shortcode( $output );
901 12
		}
902
903
		return $output;
904
	}
905
906
907
	/**
908
	 * Perform actions normally performed after updating a lead
909
	 *
910
	 * @since 1.8
911 12
	 *
912
	 * @see GFEntryDetail::lead_detail_page()
913 12
	 *
914
	 * @return void
915
	 */
916
	private function after_update() {
917
918
		do_action( 'gform_after_update_entry', $this->form, $this->entry['id'], self::$original_entry );
919
		do_action( "gform_after_update_entry_{$this->form['id']}", $this->form, $this->entry['id'], self::$original_entry );
920
921
		// Re-define the entry now that we've updated it.
922
		$entry = RGFormsModel::get_lead( $this->entry['id'] );
923
924
		$entry = GFFormsModel::set_entry_meta( $entry, self::$original_form );
925 12
926
		if ( version_compare( GFFormsModel::get_database_version(), '2.3-dev-1', '<' ) ) {
927 12
			// We need to clear the cache because Gravity Forms caches the field values, which
928
			// we have just updated.
929
			foreach ($this->form['fields'] as $key => $field) {
0 ignored issues
show
introduced by
No space after opening parenthesis is prohibited
Loading history...
introduced by
No space before closing parenthesis is prohibited
Loading history...
930 12
				GFFormsModel::refresh_lead_field_value( $entry['id'], $field->id );
931
			}
932
		}
933 12
934
		/**
935
		 * Maybe process feeds.
936
		 *
937
		 * @since develop
938
		 */
939
		if ( $allowed_feeds = $this->view->settings->get( 'edit_feeds', array() ) ) {
940
			$feeds = GFAPI::get_feeds( null, $entry['form_id'] );
941
			if ( ! is_wp_error( $feeds ) ) {
942
				$registered_feeds = array();
943
				foreach ( GFAddOn::get_registered_addons() as $registered_feed ) {
944 12
					if ( is_subclass_of( $registered_feed,  'GFFeedAddOn' ) ) {
945
						if ( method_exists( $registered_feed, 'get_instance' ) ) {
946
							$registered_feed = call_user_func( array( $registered_feed, 'get_instance' ) );
947
							$registered_feeds[ $registered_feed->get_slug() ] = $registered_feed;
948
						}
949
					}
950
				}
951
				foreach ( $feeds as $feed ) {
952
					if ( in_array( $feed['id'], $allowed_feeds ) ) {
953
						if ( $feed_object = \GV\Utils::get( $registered_feeds, $feed['addon_slug'] ) ) {
954
							$returned_entry = $feed_object->process_feed( $feed, $entry, self::$original_form );
955 12
							if ( is_array( $returned_entry ) && rgar( $returned_entry, 'id' ) ) {
956
								$entry = $returned_entry;
957 12
							}
958
959 11
							do_action( 'gform_post_process_feed', $feed, $entry, self::$original_form, $feed_object );
960
							$slug = $feed_object->get_slug();
961 11
							do_action( "gform_{$slug}_post_process_feed", $feed, $entry, self::$original_form, $feed_object );
962
						}
963
					}
964
				}
965
			}
966
		}
967
968
		$this->entry = $entry;
969
	}
970 11
971 11
972 11
	/**
973
	 * Display the Edit Entry form
974
	 *
975
	 * @return void
976 11
	 */
977 1
	public function edit_entry_form() {
978 1
979 1
		?>
980
981 10
		<div class="gv-edit-entry-wrapper"><?php
982 1
983 1
			$javascript = gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/inline-javascript.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
984 1
985
			/**
986 9
			 * Fixes weird wpautop() issue
987 1
			 * @see https://github.com/katzwebservices/GravityView/issues/451
988 1
			 */
989 1
			echo gravityview_strip_whitespace( $javascript );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'gravityview_strip_whitespace'
Loading history...
990 1
991
			?><h2 class="gv-edit-entry-title">
992 8
				<span><?php
993
994 8
				    /**
995 8
				     * @filter `gravityview_edit_entry_title` Modify the edit entry title
996
				     * @param string $edit_entry_title Modify the "Edit Entry" title
997
				     * @param GravityView_Edit_Entry_Render $this This object
998 11
				     */
999 3
				    $edit_entry_title = apply_filters('gravityview_edit_entry_title', __('Edit Entry', 'gravityview'), $this );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1000
1001
				    echo esc_attr( $edit_entry_title );
1002
			?></span>
1003
			</h2>
1004
1005
			<?php $this->maybe_print_message(); ?>
1006
1007
			<?php // The ID of the form needs to be `gform_{form_id}` for the pluploader ?>
1008
1009
			<form method="post" id="gform_<?php echo $this->form_id; ?>" enctype="multipart/form-data">
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$this'
Loading history...
1010 11
1011
				<?php
1012 11
1013
				wp_nonce_field( self::$nonce_key, self::$nonce_key );
1014
1015
				wp_nonce_field( self::$nonce_field, self::$nonce_field, false );
1016 12
1017
				// Print the actual form HTML
1018
				$this->render_edit_form();
1019
1020
				?>
1021
			</form>
1022
1023
			<script>
1024
				gform.addFilter('gform_reset_pre_conditional_logic_field_action', function ( reset, formId, targetId, defaultValues, isInit ) {
1025 12
				    return false;
1026
				});
1027
			</script>
1028
1029
		</div>
1030
1031
	<?php
1032 12
	}
1033
1034 12
	/**
1035 12
	 * Display success or error message if the form has been submitted
1036 12
	 *
1037
	 * @uses GVCommon::generate_notice
1038 12
	 *
1039 12
	 * @since 1.16.2.2
1040
	 *
1041
	 * @return void
1042 12
	 */
1043
	private function maybe_print_message() {
1044
1045
		if ( \GV\Utils::_POST( 'action' ) === 'update' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
1046 12
1047
			$back_link = remove_query_arg( array( 'page', 'view', 'edit' ) );
1048 12
1049
			if( ! $this->is_valid ){
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
1050 12
1051
				// Keeping this compatible with Gravity Forms.
1052 12
				$validation_message = "<div class='validation_error'>" . __('There was a problem with your submission.', 'gravityview') . " " . __('Errors have been highlighted below.', 'gravityview') . "</div>";
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw '__'
Loading history...
Coding Style Comprehensibility introduced by
The string literal </div> does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1053 12
				$message = apply_filters("gform_validation_message_{$this->form['id']}", apply_filters("gform_validation_message", $validation_message, $this->form), $this->form);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal gform_validation_message does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1054 12
1055 12
				echo GVCommon::generate_notice( $message , 'gv-error' );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
1056 12
1057
			} else {
1058 12
				$view = \GV\View::by_id( $this->view_id );
1059
				$edit_redirect = $view->settings->get( 'edit_redirect' );
1060
				$edit_redirect_url = $view->settings->get( 'edit_redirect_url' );
1061
1062
				switch ( $edit_redirect ) {
1063
1064
                    case '0':
1065 12
	                    $redirect_url = $back_link;
1066 12
	                    $entry_updated_message = sprintf( esc_attr_x('Entry Updated. %sReturning to Entry%s', 'Replacements are HTML', 'gravityview'), '<a href="'. esc_url( $redirect_url ) .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1067
                        break;
1068
1069
                    case '1':
1070
	                    $redirect_url = $directory_link = GravityView_API::directory_link();
1071
	                    $entry_updated_message = sprintf( esc_attr_x('Entry Updated. %sReturning to %s%s', 'Replacement 1 is HTML. Replacement 2 is the title of the page where the user will be taken. Replacement 3 is HTML.','gravityview'), '<a href="'. esc_url( $redirect_url ) . '">', esc_html( $view->post_title ), '</a>' );
0 ignored issues
show
Documentation introduced by
The property post_title does not exist on object<GV\View>. Since you implemented __get, maybe consider adding a @property annotation.

Since your code implements the magic getter _get, this function will be called for any read access on an undefined variable. You can add the @property annotation to your class or interface to document the existence of this variable.

<?php

/**
 * @property int $x
 * @property int $y
 * @property string $text
 */
class MyLabel
{
    private $properties;

    private $allowedProperties = array('x', 'y', 'text');

    public function __get($name)
    {
        if (isset($properties[$name]) && in_array($name, $this->allowedProperties)) {
            return $properties[$name];
        } else {
            return null;
        }
    }

    public function __set($name, $value)
    {
        if (in_array($name, $this->allowedProperties)) {
            $properties[$name] = $value;
        } else {
            throw new \LogicException("Property $name is not defined.");
        }
    }

}

If the property has read access only, you can use the @property-read annotation instead.

Of course, you may also just have mistyped another name, in which case you should fix the error.

See also the PhpDoc documentation for @property.

Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1072
	                    break;
1073 12
1074 12
                    case '2':
1075
	                    $redirect_url = $edit_redirect_url;
1076
	                    $redirect_url = GFCommon::replace_variables( $redirect_url, $this->form, $this->entry, false, false, false, 'text' );
1077
	                    $entry_updated_message = sprintf( esc_attr_x('Entry Updated. %sRedirecting to %s%s', 'Replacement 1 is HTML. Replacement 2 is the URL where the user will be taken. Replacement 3 is HTML.','gravityview'), '<a href="'. esc_url( $redirect_url ) . '">', esc_html( $edit_redirect_url ), '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1078
                        break;
1079
1080
                    case '':
1081
                    default:
1082
					    $entry_updated_message = sprintf( esc_attr__('Entry Updated. %sReturn to Entry%s', 'gravityview'), '<a href="'. esc_url( $back_link ) .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1083
                        break;
1084
				}
1085
1086
				if ( isset( $redirect_url ) ) {
1087
					$entry_updated_message .= sprintf( '<script>window.location.href = %s;</script><noscript><meta http-equiv="refresh" content="0;URL=%s" /></noscript>', json_encode( $redirect_url ), esc_attr( $redirect_url ) );
1088
				}
1089
1090
				/**
1091 12
				 * @filter `gravityview/edit_entry/success` Modify the edit entry success message (including the anchor link)
1092
				 * @since 1.5.4
1093
				 * @param string $entry_updated_message Existing message
1094 12
				 * @param int $view_id View ID
1095 11
				 * @param array $entry Gravity Forms entry array
1096
				 * @param string $back_link URL to return to the original entry. @since 1.6
1097 4
				 */
1098
				$message = apply_filters( 'gravityview/edit_entry/success', $entry_updated_message , $this->view_id, $this->entry, $back_link );
1099
1100 12
				echo GVCommon::generate_notice( $message );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
1101
			}
1102 12
1103
		}
1104
	}
1105 12
1106 12
	/**
1107
	 * Display the Edit Entry form in the original Gravity Forms format
1108
	 *
1109 12
	 * @since 1.9
1110
	 *
1111 12
	 * @return void
1112
	 */
1113
	private function render_edit_form() {
1114
1115
		/**
1116
		 * @action `gravityview/edit-entry/render/before` Before rendering the Edit Entry form
1117
		 * @since 1.17
1118
		 * @param GravityView_Edit_Entry_Render $this
1119
		 */
1120
		do_action( 'gravityview/edit-entry/render/before', $this );
1121
1122
		add_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields'), 5000, 3 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
1123
		add_filter( 'gform_submit_button', array( $this, 'render_form_buttons') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
1124
		add_filter( 'gform_disable_view_counter', '__return_true' );
1125
1126
		add_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5, 5 );
1127 12
		add_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10, 5 );
1128
1129 12
		// We need to remove the fake $_GET['page'] arg to avoid rendering form as if in admin.
1130 12
		unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
1131
1132
		// TODO: Verify multiple-page forms
1133 2
1134
		ob_start(); // Prevent PHP warnings possibly caused by prefilling list fields for conditional logic
1135
1136 2
		$html = GFFormDisplay::get_form( $this->form['id'], false, false, true, $this->entry );
1137
1138
		ob_get_clean();
1139
1140
	    remove_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields' ), 5000 );
1141
		remove_filter( 'gform_submit_button', array( $this, 'render_form_buttons' ) );
1142 1
		remove_filter( 'gform_disable_view_counter', '__return_true' );
1143
		remove_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5 );
1144 1
		remove_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10 );
1145
1146
		echo $html;
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$html'
Loading history...
1147
1148
		/**
1149
		 * @action `gravityview/edit-entry/render/after` After rendering the Edit Entry form
1150
		 * @since 1.17
1151
		 * @param GravityView_Edit_Entry_Render $this
1152 2
		 */
1153 1
		do_action( 'gravityview/edit-entry/render/after', $this );
1154
	}
1155
1156 2
	/**
1157
	 * Display the Update/Cancel/Delete buttons for the Edit Entry form
1158
	 * @since 1.8
1159
	 * @return string
1160
	 */
1161
	public function render_form_buttons() {
1162
		return gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/form-buttons.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
1163
	}
1164
1165
1166
	/**
1167
	 * Modify the form fields that are shown when using GFFormDisplay::get_form()
1168
	 *
1169
	 * By default, all fields will be shown. We only want the Edit Tab configured fields to be shown.
1170
	 *
1171 12
	 * @param array $form
1172
	 * @param boolean $ajax Whether in AJAX mode
1173 12
	 * @param array|string $field_values Passed parameters to the form
1174
	 *
1175
	 * @since 1.9
1176
	 *
1177
	 * @return array Modified form array
1178 12
	 */
1179 12
	public function filter_modify_form_fields( $form, $ajax = false, $field_values = '' ) {
0 ignored issues
show
Unused Code introduced by
The parameter $ajax is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $field_values is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1180
1181 12
		// In case we have validated the form, use it to inject the validation results into the form render
1182 12
		if( isset( $this->form_after_validation ) ) {
1183
			$form = $this->form_after_validation;
1184 1
		} else {
1185
			$form['fields'] = $this->get_configured_edit_fields( $form, $this->view_id );
1186
		}
1187
1188 12
		$form = $this->filter_conditional_logic( $form );
1189
1190 12
		$form = $this->prefill_conditional_logic( $form );
1191
1192
		// for now we don't support Save and Continue feature.
1193 12
		if( ! self::$supports_save_and_continue ) {
1194
	        unset( $form['save'] );
1195 12
		}
1196
1197
		$form = $this->unselect_default_values( $form );
1198 12
1199 3
		return $form;
1200
	}
1201 12
1202
	/**
1203
	 * When displaying a field, check if it's a Post Field, and if so, make sure the post exists and current user has edit rights.
1204
	 *
1205 12
	 * @since 1.16.2.2
1206
	 *
1207 12
	 * @param string $field_content Always empty. Returning not-empty overrides the input.
1208
	 * @param GF_Field $field
1209
	 * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1210
	 * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1211 12
	 * @param int $form_id Form ID
1212
	 *
1213
	 * @return string If error, the error message. If no error, blank string (modify_edit_field_input() runs next)
1214
	 */
1215
	public function verify_user_can_edit_post( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1216
1217
		if( ! GFCommon::is_post_field( $field ) ) {
1218
			return $field_content;
1219
		}
1220
1221 12
        $message = null;
1222
1223
        // First, make sure they have the capability to edit the post.
1224
        if( false === current_user_can( 'edit_post', $this->entry['post_id'] ) ) {
1225
1226
            /**
1227
             * @filter `gravityview/edit_entry/unsupported_post_field_text` Modify the message when someone isn't able to edit a post
1228
             * @param string $message The existing "You don't have permission..." text
1229 12
             */
1230
            $message = apply_filters('gravityview/edit_entry/unsupported_post_field_text', __('You don&rsquo;t have permission to edit this post.', 'gravityview') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1231
1232 12
        } elseif( null === get_post( $this->entry['post_id'] ) ) {
1233
            /**
1234 3
             * @filter `gravityview/edit_entry/no_post_text` Modify the message when someone is editing an entry attached to a post that no longer exists
1235
             * @param string $message The existing "This field is not editable; the post no longer exists." text
1236
             */
1237 3
            $message = apply_filters('gravityview/edit_entry/no_post_text', __('This field is not editable; the post no longer exists.', 'gravityview' ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1238
        }
1239 3
1240
        if( $message ) {
1241 3
            $field_content = sprintf('<div class="ginput_container ginput_container_' . $field->type . '">%s</div>', wpautop( $message ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1242
        }
1243 3
1244 3
        return $field_content;
1245 3
	}
1246
1247
	/**
1248
	 *
1249
	 * Fill-in the saved values into the form inputs
1250 3
	 *
1251
	 * @param string $field_content Always empty. Returning not-empty overrides the input.
1252 3
	 * @param GF_Field $field
1253
	 * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1254
	 * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1255
	 * @param int $form_id Form ID
1256 12
	 *
1257
	 * @return mixed
1258
	 */
1259 12
	public function modify_edit_field_input( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1260
1261
		$gv_field = GravityView_Fields::get_associated_field( $field );
1262
1263 12
		// If the form has been submitted, then we don't need to pre-fill the values,
1264
		// Except for fileupload type and when a field input is overridden- run always!!
1265
		if(
1266 12
			( $this->is_edit_entry_submission() && !in_array( $field->type, array( 'fileupload', 'post_image' ) ) )
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1267
			&& false === ( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) )
1268
			&& ! GFCommon::is_product_field( $field->type )
1269
			|| ! empty( $field_content )
1270
			|| in_array( $field->type, array( 'honeypot' ) )
1271
		) {
1272
	        return $field_content;
1273
		}
1274
1275
		// SET SOME FIELD DEFAULTS TO PREVENT ISSUES
1276
		$field->adminOnly = false; /** @see GFFormDisplay::get_counter_init_script() need to prevent adminOnly */
1277 12
1278
		$field_value = $this->get_field_value( $field );
1279
1280
	    // Prevent any PHP warnings, like undefined index
1281
	    ob_start();
1282
1283
	    $return = null;
1284
1285
		/** @var GravityView_Field $gv_field */
1286
		if( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) ) {
1287 12
			$return = $gv_field->get_field_input( $this->form, $field_value, $this->entry, $field );
1288
		} else {
1289
	        $return = $field->get_field_input( $this->form, $field_value, $this->entry );
1290
	    }
1291
1292
	    // If there was output, it's an error
1293
	    $warnings = ob_get_clean();
1294
1295
	    if( !empty( $warnings ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1296
		    gravityview()->log->error( '{warning}', array( 'warning' => $warnings, 'data' => $field_value ) );
1297 12
	    }
1298
1299 12
		return $return;
1300
	}
1301
1302
	/**
1303
	 * Modify the value for the current field input
1304
	 *
1305
	 * @param GF_Field $field
1306
	 *
1307
	 * @return array|mixed|string
1308
	 */
1309
	private function get_field_value( $field ) {
1310
1311
		/**
1312 11
		 * @filter `gravityview/edit_entry/pre_populate/override` Allow the pre-populated value to override saved value in Edit Entry form. By default, pre-populate mechanism only kicks on empty fields.
1313
		 * @param boolean True: override saved values; False: don't override (default)
1314 11
		 * @param $field GF_Field object Gravity Forms field object
1315
		 * @since 1.13
1316
		 */
1317
		$override_saved_value = apply_filters( 'gravityview/edit_entry/pre_populate/override', false, $field );
1318
1319 11
		// We're dealing with multiple inputs (e.g. checkbox) but not time or date (as it doesn't store data in input IDs)
1320
		if( isset( $field->inputs ) && is_array( $field->inputs ) && !in_array( $field->type, array( 'time', 'date' ) ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1321
1322
			$field_value = array();
1323 11
1324 11
			// only accept pre-populated values if the field doesn't have any choice selected.
1325
			$allow_pre_populated = $field->allowsPrepopulate;
1326
1327 11
			foreach ( (array)$field->inputs as $input ) {
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1328
1329
				$input_id = strval( $input['id'] );
1330
1331
				if ( isset( $this->entry[ $input_id ] ) && ! gv_empty( $this->entry[ $input_id ], false, false ) ) {
1332
				    $field_value[ $input_id ] =  'post_category' === $field->type ? GFCommon::format_post_category( $this->entry[ $input_id ], true ) : $this->entry[ $input_id ];
0 ignored issues
show
introduced by
Expected 1 space after "="; 2 found
Loading history...
1333
				    $allow_pre_populated = false;
1334
				}
1335
1336 11
			}
1337
1338
			$pre_value = $field->get_value_submission( array(), false );
1339 1
1340
			$field_value = ! $allow_pre_populated && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $field_value : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1341 1
1342 1
		} else {
1343
1344 1
			$id = intval( $field->id );
1345
1346
			// get pre-populated value if exists
1347 1
			$pre_value = $field->allowsPrepopulate ? GFFormsModel::get_parameter_value( $field->inputName, array(), $field ) : '';
1348 1
1349
			// saved field entry value (if empty, fallback to the pre-populated value, if exists)
1350
			// or pre-populated value if not empty and set to override saved value
1351
			$field_value = isset( $this->entry[ $id ] ) && ! gv_empty( $this->entry[ $id ], false, false ) && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $this->entry[ $id ] : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1352 1
1353 1
			// in case field is post_category but inputType is select, multi-select or radio, convert value into array of category IDs.
1354 1
			if ( 'post_category' === $field->type && !gv_empty( $field_value, false, false ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1355
				$categories = array();
1356
				foreach ( explode( ',', $field_value ) as $cat_string ) {
1357
				    $categories[] = GFCommon::format_post_category( $cat_string, true );
1358
				}
1359
				$field_value = 'multiselect' === $field->get_input_type() ? $categories : implode( '', $categories );
1360 1
			}
1361
1362
		}
1363
1364 1
		// if value is empty get the default value if defined
1365
		$field_value = $field->get_value_default_if_empty( $field_value );
1366
1367
	    /**
1368 1
	     * @filter `gravityview/edit_entry/field_value` Change the value of an Edit Entry field, if needed
1369
	     * @since 1.11
1370
	     * @since 1.20 Added third param
1371 1
	     * @param mixed $field_value field value used to populate the input
1372
	     * @param object $field Gravity Forms field object ( Class GF_Field )
1373
	     * @param GravityView_Edit_Entry_Render $this Current object
1374
	     */
1375
	    $field_value = apply_filters( 'gravityview/edit_entry/field_value', $field_value, $field, $this );
1376
1377
	    /**
1378 1
	     * @filter `gravityview/edit_entry/field_value_{field_type}` Change the value of an Edit Entry field for a specific field type
1379
	     * @since 1.17
1380
	     * @since 1.20 Added third param
1381
	     * @param mixed $field_value field value used to populate the input
1382 1
	     * @param GF_Field $field Gravity Forms field object
1383 1
	     * @param GravityView_Edit_Entry_Render $this Current object
1384
	     */
1385 1
	    $field_value = apply_filters( 'gravityview/edit_entry/field_value_' . $field->type , $field_value, $field, $this );
1386
1387 11
		return $field_value;
1388
	}
1389 8
1390 5
1391
	// ---- Entry validation
1392 11
1393
	/**
1394
	 * Add field keys that Gravity Forms expects.
1395
	 *
1396
	 * @see GFFormDisplay::validate()
1397 11
	 * @param  array $form GF Form
1398
	 * @return array       Modified GF Form
1399
	 */
1400
	public function gform_pre_validation( $form ) {
1401
1402
		if( ! $this->verify_nonce() ) {
1403
			return $form;
1404
		}
1405
1406
		// Fix PHP warning regarding undefined index.
1407
		foreach ( $form['fields'] as &$field) {
0 ignored issues
show
introduced by
No space before closing parenthesis is prohibited
Loading history...
1408 12
1409
			// This is because we're doing admin form pretending to be front-end, so Gravity Forms
1410
			// expects certain field array items to be set.
1411
			foreach ( array( 'noDuplicates', 'adminOnly', 'inputType', 'isRequired', 'enablePrice', 'inputs', 'allowedExtensions' ) as $key ) {
1412
	            $field->{$key} = isset( $field->{$key} ) ? $field->{$key} : NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1413
			}
1414
1415 12
			switch( RGFormsModel::get_input_type( $field ) ) {
1416 12
1417
				/**
1418
				 * this whole fileupload hack is because in the admin, Gravity Forms simply doesn't update any fileupload field if it's empty, but it DOES in the frontend.
1419
				 *
1420
				 * What we have to do is set the value so that it doesn't get overwritten as empty on save and appears immediately in the Edit Entry screen again.
1421
				 *
1422
				 * @hack
1423
				 */
1424
				case 'fileupload':
1425
1426
				    // Set the previous value
1427 12
				    $entry = $this->get_entry();
1428
1429
				    $input_name = 'input_'.$field->id;
1430 12
				    $form_id = $form['id'];
1431 12
1432
				    $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1433
1434
				    // Use the previous entry value as the default.
1435 12
				    if( isset( $entry[ $field->id ] ) ) {
1436
				        $value = $entry[ $field->id ];
1437
				    }
1438 12
1439
				    // If this is a single upload file
1440 12
				    if( !empty( $_FILES[ $input_name ] ) && !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1441
				        $file_path = GFFormsModel::get_file_upload_path( $form['id'], $_FILES[ $input_name ]['name'] );
1442 12
				        $value = $file_path['url'];
1443 12
1444
				    } else {
1445
1446
				        // Fix PHP warning on line 1498 of form_display.php for post_image fields
1447
				        // Fix PHP Notice:  Undefined index:  size in form_display.php on line 1511
1448
				        $_FILES[ $input_name ] = array('name' => '', 'size' => '' );
0 ignored issues
show
introduced by
No space after opening parenthesis of array is bad style
Loading history...
1449
1450
				    }
1451
1452
				    if ( \GV\Utils::get( $field, "multipleFiles" ) ) {
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal multipleFiles does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1453
1454
				        // If there are fresh uploads, process and merge them.
1455
				        // Otherwise, use the passed values, which should be json-encoded array of URLs
1456
				        if( isset( GFFormsModel::$uploaded_files[$form_id][$input_name] ) ) {
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1457 12
				            $value = empty( $value ) ? '[]' : $value;
1458
				            $value = stripslashes_deep( $value );
1459 12
				            $value = GFFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'], array());
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1460
				        }
1461 12
1462
				    } else {
1463 12
1464
				        // A file already exists when editing an entry
1465 12
				        // We set this to solve issue when file upload fields are required.
1466
				        GFFormsModel::$uploaded_files[ $form_id ][ $input_name ] = $value;
1467 12
1468 12
				    }
1469
1470
				    $this->entry[ $input_name ] = $value;
1471 12
				    $_POST[ $input_name ] = $value;
1472
1473
				    break;
1474 12
1475 12
				case 'number':
1476
				    // Fix "undefined index" issue at line 1286 in form_display.php
1477
				    if( !isset( $_POST['input_'.$field->id ] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1478 2
				        $_POST['input_'.$field->id ] = NULL;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1479
				    }
1480
				    break;
1481
			}
1482
1483
		}
1484 2
1485
		return $form;
1486
	}
1487
1488
1489
	/**
1490
	 * Process validation for a edit entry submission
1491
	 *
1492
	 * Sets the `is_valid` object var
1493
	 *
1494
	 * @return void
1495
	 */
1496
	private function validate() {
1497
1498
		/**
1499
		 * If using GF User Registration Add-on, remove the validation step, otherwise generates error when updating the entry
1500
		 * GF User Registration Add-on version > 3.x has a different class name
1501
		 * @since 1.16.2
1502
		 */
1503
		if ( class_exists( 'GF_User_Registration' ) ) {
1504
			remove_filter( 'gform_validation', array( GF_User_Registration::get_instance(), 'validate' ) );
1505
		} else  if ( class_exists( 'GFUser' ) ) {
1506
			remove_filter( 'gform_validation', array( 'GFUser', 'user_registration_validation' ) );
1507
		}
1508
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1509
1510
		/**
1511
		 * For some crazy reason, Gravity Forms doesn't validate Edit Entry form submissions.
1512 2
		 * You can enter whatever you want!
1513
		 * We try validating, and customize the results using `self::custom_validation()`
1514
		 */
1515
		add_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10, 4);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1516
1517 12
		// Needed by the validate funtion
1518
		$failed_validation_page = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1519 1
		$field_values = RGForms::post( 'gform_field_values' );
1520
1521 1
		// Prevent entry limit from running when editing an entry, also
1522
		// prevent form scheduling from preventing editing
1523
		unset( $this->form['limitEntries'], $this->form['scheduleForm'] );
1524 1
1525
		// Hide fields depending on Edit Entry settings
1526
		$this->form['fields'] = $this->get_configured_edit_fields( $this->form, $this->view_id );
1527 1
1528
		$this->is_valid = GFFormDisplay::validate( $this->form, $field_values, 1, $failed_validation_page );
1529
1530
		remove_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10 );
1531
	}
1532
1533
1534
	/**
1535 1
	 * Make validation work for Edit Entry
1536
	 *
1537
	 * Because we're calling the GFFormDisplay::validate() in an unusual way (as a front-end
1538
	 * form pretending to be a back-end form), validate() doesn't know we _can't_ edit post
1539
	 * fields. This goes through all the fields and if they're an invalid post field, we
1540
	 * set them as valid. If there are still issues, we'll return false.
1541 1
	 *
1542
	 * @param  [type] $validation_results [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1543
	 * @return [type]                     [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1544
	 */
1545
	public function custom_validation( $validation_results ) {
1546
1547
		gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Validation results: ', array( 'data' => $validation_results ) );
1548
1549
		gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] $_POSTed data (sanitized): ', array( 'data' => esc_html( print_r( $_POST, true ) ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
1550
1551
		$gv_valid = true;
1552
1553
		foreach ( $validation_results['form']['fields'] as $key => &$field ) {
1554
1555
			$value = RGFormsModel::get_field_value( $field );
1556
			$field_type = RGFormsModel::get_input_type( $field );
1557
1558
			// Validate always
1559
			switch ( $field_type ) {
1560 1
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1561
1562
				case 'fileupload' :
1563
				case 'post_image':
1564
1565
				    // in case nothing is uploaded but there are already files saved
1566 12
				    if( !empty( $field->failed_validation ) && !empty( $field->isRequired ) && !empty( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1567
				        $field->failed_validation = false;
1568
				        unset( $field->validation_message );
1569
				    }
1570
1571
				    // validate if multi file upload reached max number of files [maxFiles] => 2
1572 12
				    if( \GV\Utils::get( $field, 'maxFiles') && \GV\Utils::get( $field, 'multipleFiles') ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1573
1574 12
				        $input_name = 'input_' . $field->id;
1575
				        //uploaded
1576
				        $file_names = isset( GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] ) ? GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] : array();
1577 12
1578
				        //existent
1579 12
				        $entry = $this->get_entry();
1580
				        $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1581
				        if( isset( $entry[ $field->id ] ) ) {
1582
				            $value = json_decode( $entry[ $field->id ], true );
1583
				        }
1584
1585
				        // count uploaded files and existent entry files
1586
				        $count_files = count( $file_names ) + count( $value );
1587
1588 2
				        if( $count_files > $field->maxFiles ) {
1589
				            $field->validation_message = __( 'Maximum number of files reached', 'gravityview' );
1590 2
				            $field->failed_validation = 1;
1591
				            $gv_valid = false;
1592 1
1593
				            // in case of error make sure the newest upload files are removed from the upload input
1594
				            GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ] = null;
1595 2
				        }
1596
1597
				    }
1598
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1599
1600
				    break;
1601
1602
			}
1603
1604
			// This field has failed validation.
1605
			if( !empty( $field->failed_validation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1606
1607
				gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Field is invalid.', array( 'data' => array( 'field' => $field, 'value' => $value ) ) );
1608
1609
				switch ( $field_type ) {
1610
1611 13
				    // Captchas don't need to be re-entered.
1612
				    case 'captcha':
1613
1614 13
				        // Post Image fields aren't editable, so we un-fail them.
1615 13
				    case 'post_image':
1616 13
				        $field->failed_validation = false;
1617
				        unset( $field->validation_message );
1618
				        break;
1619
1620
				}
1621
1622 13
				// You can't continue inside a switch, so we do it after.
1623
				if( empty( $field->failed_validation ) ) {
1624
				    continue;
1625 13
				}
1626
1627
				// checks if the No Duplicates option is not validating entry against itself, since
1628 13
				// we're editing a stored entry, it would also assume it's a duplicate.
1629
				if( !empty( $field->noDuplicates ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1630
1631
				    $entry = $this->get_entry();
1632
1633
				    // If the value of the entry is the same as the stored value
1634
				    // Then we can assume it's not a duplicate, it's the same.
1635
				    if( !empty( $entry ) && $value == $entry[ $field->id ] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1636
				        //if value submitted was not changed, then don't validate
1637
				        $field->failed_validation = false;
1638 13
1639
				        unset( $field->validation_message );
1640 13
1641
				        gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Field not a duplicate; it is the same entry.', array( 'data' => $entry ) );
1642
1643
				        continue;
1644
				    }
1645
				}
1646
1647
				// if here then probably we are facing the validation 'At least one field must be filled out'
1648
				if( GFFormDisplay::is_empty( $field, $this->form_id  ) && empty( $field->isRequired ) ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 2 found
Loading history...
1649
				    unset( $field->validation_message );
1650
	                $field->validation_message = false;
1651
				    continue;
1652
				}
1653
1654
				$gv_valid = false;
1655 12
1656
			}
1657 12
1658
		}
1659
1660
		$validation_results['is_valid'] = $gv_valid;
1661 12
1662
		gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Validation results.', array( 'data' => $validation_results ) );
1663 12
1664
		// We'll need this result when rendering the form ( on GFFormDisplay::get_form )
1665
		$this->form_after_validation = $validation_results['form'];
1666 12
1667
		return $validation_results;
1668
	}
1669
1670 12
1671 4
	/**
1672
	 * TODO: This seems to be hacky... we should remove it. Entry is set when updating the form using setup_vars()!
1673
	 * Get the current entry and set it if it's not yet set.
1674
	 * @return array Gravity Forms entry array
1675 12
	 */
1676 12
	public function get_entry() {
1677
1678
		if( empty( $this->entry ) ) {
1679
			// Get the database value of the entry that's being edited
1680
			$this->entry = gravityview_get_entry( GravityView_frontend::is_single_entry() );
1681 12
		}
1682 11
1683
		return $this->entry;
1684
	}
1685
1686 1
1687
1688
	// --- Filters
1689 1
1690 1
	/**
1691 1
	 * Get the Edit Entry fields as configured in the View
1692 1
	 *
1693
	 * @since 1.8
1694
	 *
1695
	 * @param int $view_id
1696
	 *
1697
	 * @return array Array of fields that are configured in the Edit tab in the Admin
1698
	 */
1699 1
	private function get_configured_edit_fields( $form, $view_id ) {
1700
1701
		// Get all fields for form
1702
		if ( \GV\View::exists( $view_id ) ) {
1703
			$view = \GV\View::by_id( $view_id );
1704
			$properties = $view->fields ? $view->fields->as_configuration() : array();
1705
		} else {
1706
			$properties = null;
1707
		}
1708
1709
		// If edit tab not yet configured, show all fields
1710 1
		$edit_fields = !empty( $properties['edit_edit-fields'] ) ? $properties['edit_edit-fields'] : NULL;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1711
1712 1
		// Hide fields depending on admin settings
1713
		$fields = $this->filter_fields( $form['fields'], $edit_fields );
1714 1
1715
	    // If Edit Entry fields are configured, remove adminOnly field settings. Otherwise, don't.
1716 1
	    $fields = $this->filter_admin_only_fields( $fields, $edit_fields, $form, $view_id );
1717
1718
		/**
1719
		 * @filter `gravityview/edit_entry/form_fields` Modify the fields displayed in Edit Entry form
1720 1
		 * @since 1.17
1721
		 * @param GF_Field[] $fields Gravity Forms form fields
1722
		 * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1723
		 * @param array $form GF Form array (`fields` key modified to have only fields configured to show in Edit Entry)
1724
		 * @param int $view_id View ID
1725
		 */
1726
		$fields = apply_filters( 'gravityview/edit_entry/form_fields', $fields, $edit_fields, $form, $view_id );
1727
1728 1
		return $fields;
1729
	}
1730 1
1731
1732
	/**
1733
	 * Filter area fields based on specified conditions
1734
	 *  - This filter removes the fields that have calculation configured
1735
	 *
1736
	 * @uses GravityView_Edit_Entry::user_can_edit_field() Check caps
1737
	 * @access private
1738
	 * @param GF_Field[] $fields
1739
	 * @param array $configured_fields
1740
	 * @since  1.5
1741
	 * @return array $fields
1742
	 */
1743
	private function filter_fields( $fields, $configured_fields ) {
1744
1745
		if( empty( $fields ) || !is_array( $fields ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1746 12
			return $fields;
1747
		}
1748
1749
		$edit_fields = array();
1750
1751
		$field_type_blacklist = $this->loader->get_field_blacklist( $this->entry );
1752
1753
		// First, remove blacklist or calculation fields
1754
		foreach ( $fields as $key => $field ) {
1755
1756
			// Remove the fields that have calculation properties and keep them to be used later
1757 12
			// @since 1.16.2
1758
			if( $field->has_calculation() ) {
1759 12
				$this->fields_with_calculation[] = $field;
1760
				// don't remove the calculation fields on form render.
1761
			}
1762
1763
			if( in_array( $field->type, $field_type_blacklist ) ) {
1764
				unset( $fields[ $key ] );
1765
			}
1766
		}
1767
1768 12
		// The Edit tab has not been configured, so we return all fields by default.
1769 12
		if( empty( $configured_fields ) ) {
1770
			return array_values( $fields );
1771
		}
1772 12
1773
		// The edit tab has been configured, so we loop through to configured settings
1774
		foreach ( $configured_fields as $configured_field ) {
1775
1776
	        /** @var GF_Field $field */
1777
	        foreach ( $fields as $field ) {
1778
				if( intval( $configured_field['id'] ) === intval( $field->id ) && $this->user_can_edit_field( $configured_field, false ) ) {
1779
				    $edit_fields[] = $this->merge_field_properties( $field, $configured_field );
1780
				    break;
1781
				}
1782
1783
			}
1784
1785
		}
1786
1787 12
		return $edit_fields;
1788
1789 12
	}
1790
1791 12
	/**
1792 12
	 * Override GF Form field properties with the ones defined on the View
1793
	 * @param  GF_Field $field GF Form field object
1794
	 * @param  array $field_setting  GV field options
1795 2
	 * @since  1.5
1796 2
	 * @return array|GF_Field
1797 2
	 */
1798
	private function merge_field_properties( $field, $field_setting ) {
1799
1800
		$return_field = $field;
1801
1802 12
		if( empty( $field_setting['show_label'] ) ) {
1803
			$return_field->label = '';
1804
		} elseif ( !empty( $field_setting['custom_label'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1805
			$return_field->label = $field_setting['custom_label'];
1806
		}
1807
1808
		if( !empty( $field_setting['custom_class'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1809
			$return_field->cssClass .= ' '. gravityview_sanitize_html_class( $field_setting['custom_class'] );
1810
		}
1811
1812
		/**
1813
		 * Normalize page numbers - avoid conflicts with page validation
1814
		 * @since 1.6
1815
		 */
1816
		$return_field->pageNumber = 1;
1817
1818
		return $return_field;
1819
1820 12
	}
1821
1822 12
	/**
1823 12
	 * Remove fields that shouldn't be visible based on the Gravity Forms adminOnly field property
1824
	 *
1825
	 * @since 1.9.1
1826
	 *
1827
	 * @param array|GF_Field[] $fields Gravity Forms form fields
1828
	 * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1829
	 * @param array $form GF Form array
1830
	 * @param int $view_id View ID
1831
	 *
1832
	 * @return array Possibly modified form array
1833
	 */
1834
	private function filter_admin_only_fields( $fields = array(), $edit_fields = null, $form = array(), $view_id = 0 ) {
1835
1836
	    /**
1837
		 * @filter `gravityview/edit_entry/use_gf_admin_only_setting` When Edit tab isn't configured, should the Gravity Forms "Admin Only" field settings be used to control field display to non-admins? Default: true
1838
	     * If the Edit Entry tab is not configured, adminOnly fields will not be shown to non-administrators.
1839
	     * If the Edit Entry tab *is* configured, adminOnly fields will be shown to non-administrators, using the configured GV permissions
1840
	     * @since 1.9.1
1841
	     * @param boolean $use_gf_adminonly_setting True: Hide field if set to Admin Only in GF and the user is not an admin. False: show field based on GV permissions, ignoring GF permissions.
1842
	     * @param array $form GF Form array
1843
	     * @param int $view_id View ID
1844
	     */
1845
	    $use_gf_adminonly_setting = apply_filters( 'gravityview/edit_entry/use_gf_admin_only_setting', empty( $edit_fields ), $form, $view_id );
1846
1847
	    if( $use_gf_adminonly_setting && false === GVCommon::has_cap( 'gravityforms_edit_entries', $this->entry['id'] ) ) {
1848
			foreach( $fields as $k => $field ) {
1849
				if( $field->adminOnly ) {
1850
				    unset( $fields[ $k ] );
1851
				}
1852
			}
1853
			return array_values( $fields );
1854
		}
1855
1856
	    foreach( $fields as &$field ) {
1857
		    $field->adminOnly = false;
1858
		}
1859
1860
		return $fields;
1861
	}
1862
1863
	/**
1864
	 * Checkboxes and other checkbox-based controls should not
1865
	 * display default checks in edit mode.
1866
	 *
1867
	 * https://github.com/gravityview/GravityView/1149
1868
	 *
1869
	 * @since 2.1
1870
	 *
1871
	 * @param array $form Gravity Forms array object
1872
	 *
1873
	 * @return array $form, modified to default checkboxes, radios from showing up.
1874
	 */
1875
	private function unselect_default_values( $form ) {
1876
1877
	    foreach ( $form['fields'] as &$field ) {
1878 12
1879
			if ( empty( $field->choices ) ) {
1880
                continue;
1881
			}
1882
1883
            foreach ( $field->choices as &$choice ) {
1884
				if ( \GV\Utils::get( $choice, 'isSelected' ) ) {
1885
					$choice['isSelected'] = false;
1886 12
				}
1887
			}
1888 12
		}
1889 12
1890
		return $form;
1891
	}
1892
1893
	// --- Conditional Logic
1894
1895
	/**
1896
	 * Conditional logic isn't designed to work with forms that already have content. When switching input values,
1897
	 * the dependent fields will be blank.
1898
	 *
1899
	 * Note: This is because GF populates a JavaScript variable with the input values. This is tough to filter at the input level;
1900
	 * via the `gform_field_value` filter; it requires lots of legwork. Doing it at the form level is easier.
1901
	 *
1902
	 * @since 1.17.4
1903
	 *
1904
	 * @param array $form Gravity Forms array object
1905
	 *
1906
	 * @return array $form, modified to fix conditional
1907
	 */
1908
	function prefill_conditional_logic( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1909
1910
		if( ! GFFormDisplay::has_conditional_logic( $form ) ) {
1911
			return $form;
1912 12
		}
1913
1914 12
		// Have Conditional Logic pre-fill fields as if the data were default values
1915
		/** @var GF_Field $field */
1916
		foreach ( $form['fields'] as &$field ) {
1917
1918
			if( 'checkbox' === $field->type ) {
1919 12
				foreach ( $field->get_entry_inputs() as $key => $input ) {
1920
				    $input_id = $input['id'];
1921
				    $choice = $field->choices[ $key ];
1922
				    $value = \GV\Utils::get( $this->entry, $input_id );
1923
				    $match = RGFormsModel::choice_value_match( $field, $choice, $value );
1924
				    if( $match ) {
1925
				        $field->choices[ $key ]['isSelected'] = true;
1926
				    }
1927
				}
1928
			} else {
1929
1930
				// We need to run through each field to set the default values
1931
				foreach ( $this->entry as $field_id => $field_value ) {
1932
1933
				    if( floatval( $field_id ) === floatval( $field->id ) ) {
1934
1935
				        if( 'list' === $field->type ) {
1936
				            $list_rows = maybe_unserialize( $field_value );
1937 13
1938
				            $list_field_value = array();
1939 13
				            foreach ( (array) $list_rows as $row ) {
1940
				                foreach ( (array) $row as $column ) {
1941
				                    $list_field_value[] = $column;
1942
				                }
1943
				            }
1944
1945
				            $field->defaultValue = serialize( $list_field_value );
1946 13
				        } else {
1947
				            $field->defaultValue = $field_value;
1948
				        }
1949
				    }
1950
				}
1951
			}
1952 13
		}
1953
1954
		return $form;
1955
	}
1956 13
1957
	/**
1958
	 * Remove the conditional logic rules from the form button and the form fields, if needed.
1959
	 *
1960
	 * @todo Merge with caller method
1961
	 * @since 1.9
1962
	 *
1963
	 * @param array $form Gravity Forms form
1964
	 * @return array Modified form, if not using Conditional Logic
1965
	 */
1966
	private function filter_conditional_logic( $form ) {
1967
1968
		/**
1969
		 * @filter `gravityview/edit_entry/conditional_logic` Should the Edit Entry form use Gravity Forms conditional logic showing/hiding of fields?
1970 13
		 * @since 1.9
1971 1
		 * @param bool $use_conditional_logic True: Gravity Forms will show/hide fields just like in the original form; False: conditional logic will be disabled and fields will be shown based on configuration. Default: true
1972
		 * @param array $form Gravity Forms form
1973
		 */
1974 13
		$use_conditional_logic = apply_filters( 'gravityview/edit_entry/conditional_logic', true, $form );
1975
1976
		if( $use_conditional_logic ) {
1977
			return $form;
1978
		}
1979 13
1980 13
		foreach( $form['fields'] as &$field ) {
1981
			/* @var GF_Field $field */
1982
			$field->conditionalLogic = null;
1983 1
		}
1984
1985 1
		unset( $form['button']['conditionalLogic'] );
1986
1987
		return $form;
1988
1989
	}
1990 1
1991 1
	/**
1992
	 * Disable the Gravity Forms conditional logic script and features on the Edit Entry screen
1993
	 *
1994 1
	 * @since 1.9
1995
	 *
1996
	 * @param $has_conditional_logic
1997 1
	 * @param $form
1998
	 * @return mixed
1999 1
	 */
2000
	public function manage_conditional_logic( $has_conditional_logic, $form ) {
2001
2002
		if( ! $this->is_edit_entry() ) {
2003
			return $has_conditional_logic;
2004
		}
2005
2006
	    /** @see GravityView_Edit_Entry_Render::filter_conditional_logic for filter documentation */
2007
		return apply_filters( 'gravityview/edit_entry/conditional_logic', $has_conditional_logic, $form );
2008
	}
2009
2010 1
2011
	// --- User checks and nonces
2012 1
2013
	/**
2014 1
	 * Check if the user can edit the entry
2015
	 *
2016
	 * - Is the nonce valid?
2017
	 * - Does the user have the right caps for the entry
2018
	 * - Is the entry in the trash?
2019 1
	 *
2020 1
	 * @todo Move to GVCommon
2021
	 *
2022
	 * @param  boolean $echo Show error messages in the form?
2023
	 * @return boolean        True: can edit form. False: nope.
2024
	 */
2025
	private function user_can_edit_entry( $echo = false ) {
2026
2027
		$error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
2028
2029
		/**
2030
		 *  1. Permalinks are turned off
2031
		 *  2. There are two entries embedded using oEmbed
2032
		 *  3. One of the entries has just been saved
2033
		 */
2034
		if( !empty( $_POST['lid'] ) && !empty( $_GET['entry'] ) && ( $_POST['lid'] !== $_GET['entry'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
2035
2036
			$error = true;
2037
2038
		}
2039
2040
		if( !empty( $_GET['entry'] ) && (string)$this->entry['id'] !== $_GET['entry'] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
2041
2042 1
			$error = true;
2043
2044
		} elseif( ! $this->verify_nonce() ) {
2045 1
2046 1
			/**
2047
			 * If the Entry is embedded, there may be two entries on the same page.
2048
			 * If that's the case, and one is being edited, the other should fail gracefully and not display an error.
2049
			 */
2050
			if( GravityView_oEmbed::getInstance()->get_entry_id() ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression \GravityView_oEmbed::get...tance()->get_entry_id() of type integer|null is loosely compared to true; this is ambiguous if the integer can be zero. You might want to explicitly use !== null instead.

In PHP, under loose comparison (like ==, or !=, or switch conditions), values of different types might be equal.

For integer values, zero is a special case, in particular the following results might be unexpected:

0   == false // true
0   == null  // true
123 == false // false
123 == null  // false

// It is often better to use strict comparison
0 === false // false
0 === null  // false
Loading history...
Deprecated Code introduced by
The method GravityView_oEmbed::getInstance() has been deprecated with message: Use \GV\oEmbed instead.

This method has been deprecated. The supplier of the class has supplied an explanatory message.

The explanatory message should give you some clue as to whether and when the method will be removed from the class and what other method or class to use instead.

Loading history...
Deprecated Code introduced by
The method GravityView_oEmbed::get_entry_id() has been deprecated with message: Use \GV\oEmbed instead.

This method has been deprecated. The supplier of the class has supplied an explanatory message.

The explanatory message should give you some clue as to whether and when the method will be removed from the class and what other method or class to use instead.

Loading history...
2051
				$error = true;
2052
			} else {
2053
				$error = __( 'The link to edit this entry is not valid; it may have expired.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
2054
			}
2055
2056
		}
2057
2058
		if( ! GravityView_Edit_Entry::check_user_cap_edit_entry( $this->entry ) ) {
2059
			$error = __( 'You do not have permission to edit this entry.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
2060
		}
2061
2062
		if( $this->entry['status'] === 'trash' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
2063 12
			$error = __('You cannot edit the entry; it is in the trash.', 'gravityview' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
2064
		}
2065
2066 12
		// No errors; everything's fine here!
2067
		if( empty( $error ) ) {
2068
			return true;
2069
		}
2070
2071 12
		if( $echo && $error !== true ) {
0 ignored issues
show
introduced by
Found "!== true". Use Yoda Condition checks, you must
Loading history...
2072
2073
	        $error = esc_html( $error );
2074
2075
	        /**
2076 12
	         * @since 1.9
2077
	         */
2078
	        if ( ! empty( $this->entry ) ) {
2079
		        $error .= ' ' . gravityview_get_link( '#', _x('Go back.', 'Link shown when invalid Edit Entry link is clicked', 'gravityview' ), array( 'onclick' => "window.history.go(-1); return false;" ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal window.history.go(-1); return false; does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
2080
	        }
2081
2082
			echo GVCommon::generate_notice( wpautop( $error ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
2083
		}
2084
2085 12
		gravityview()->log->error( '{error}', array( 'error' => $error ) );
2086
2087 12
		return false;
2088
	}
2089
2090
2091
	/**
2092
	 * Check whether a field is editable by the current user, and optionally display an error message
2093
	 * @uses  GravityView_Edit_Entry->check_user_cap_edit_field() Check user capabilities
2094
	 * @param  array  $field Field or field settings array
2095
	 * @param  boolean $echo  Whether to show error message telling user they aren't allowed
2096
	 * @return boolean         True: user can edit the current field; False: nope, they can't.
2097
	 */
2098
	private function user_can_edit_field( $field, $echo = false ) {
2099
2100
		$error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
2101
2102
		if( ! $this->check_user_cap_edit_field( $field ) ) {
2103
			$error = __( 'You do not have permission to edit this field.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
2104
		}
2105
2106
		// No errors; everything's fine here!
2107
		if( empty( $error ) ) {
2108
			return true;
2109
		}
2110
2111
		if( $echo ) {
2112
			echo GVCommon::generate_notice( wpautop( esc_html( $error ) ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
2113
		}
2114
2115
		gravityview()->log->error( '{error}', array( 'error' => $error ) );
2116
2117
		return false;
2118
2119
	}
2120
2121
2122
	/**
2123
	 * checks if user has permissions to edit a specific field
2124
	 *
2125
	 * Needs to be used combined with GravityView_Edit_Entry::user_can_edit_field for maximum security!!
2126
	 *
2127
	 * @param  [type] $field [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
2128
	 * @return bool
2129
	 */
2130
	private function check_user_cap_edit_field( $field ) {
2131
2132
		// If they can edit any entries (as defined in Gravity Forms), we're good.
2133
		if( GVCommon::has_cap( array( 'gravityforms_edit_entries', 'gravityview_edit_others_entries' ) ) ) {
2134
			return true;
2135
		}
2136
2137
		$field_cap = isset( $field['allow_edit_cap'] ) ? $field['allow_edit_cap'] : false;
2138
2139
		if( $field_cap ) {
2140
			return GVCommon::has_cap( $field['allow_edit_cap'] );
2141
		}
2142
2143
		return false;
2144
	}
2145
2146
2147
	/**
2148
	 * Is the current nonce valid for editing the entry?
2149
	 * @return boolean
2150
	 */
2151
	public function verify_nonce() {
2152
2153
		// Verify form submitted for editing single
2154
		if( $this->is_edit_entry_submission() ) {
2155
			$valid = wp_verify_nonce( $_POST[ self::$nonce_field ], self::$nonce_field );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
2156
		}
2157
2158
		// Verify
2159
		else if( ! $this->is_edit_entry() ) {
2160
			$valid = false;
2161
		}
2162
2163
		else {
2164
			$valid = wp_verify_nonce( $_GET['edit'], self::$nonce_key );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
2165
		}
2166
2167
		/**
2168
		 * @filter `gravityview/edit_entry/verify_nonce` Override Edit Entry nonce validation. Return true to declare nonce valid.
2169
		 * @since 1.13
2170
		 * @param int|boolean $valid False if invalid; 1 or 2 when nonce was generated
2171
		 * @param string $nonce_field Key used when validating submissions. Default: is_gv_edit_entry
2172
		 */
2173
		$valid = apply_filters( 'gravityview/edit_entry/verify_nonce', $valid, self::$nonce_field );
2174
2175
		return $valid;
2176
	}
2177
2178
2179
	/**
2180
	 * Multiselect in GF 2.2 became a json_encoded value. Fix it.
2181
	 *
2182
	 * As a hack for now we'll implode it back.
2183
	 */
2184
	public function fix_multiselect_value_serialization( $field_value, $field, $_this ) {
0 ignored issues
show
Unused Code introduced by
The parameter $_this is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
2185
		if ( empty ( $field->storageType ) || $field->storageType != 'json' ) {
0 ignored issues
show
introduced by
Found "!= '". Use Yoda Condition checks, you must
Loading history...
Coding Style introduced by
Space before opening parenthesis of function call prohibited
Loading history...
2186
			return $field_value;
2187
		}
2188
2189
		$maybe_json = @json_decode( $field_value, true );
0 ignored issues
show
Coding Style introduced by
Silencing errors is discouraged
Loading history...
2190
2191
		if ( $maybe_json ) {
2192
			return implode( ',', $maybe_json );
2193
		}
2194
2195
		return $field_value;
2196
	}
2197
2198
2199
2200
} //end class
2201