Completed
Push — master ( 9cf7be...029c15 )
by Zack
04:07
created

GravityView_Edit_Entry_Render   D

Complexity

Total Complexity 221

Size/Duplication

Total Lines 1705
Duplicated Lines 0 %

Coupling/Cohesion

Components 1
Dependencies 8
Metric Value
wmc 221
lcom 1
cbo 8
dl 0
loc 1705
rs 4.4102

38 Methods

Rating   Name   Duplication   Size   Complexity  
A __construct() 0 3 1
B load() 0 26 1
A prevent_render_form() 0 9 3
A prevent_maybe_process_form() 0 8 3
A is_edit_entry() 0 6 3
A is_edit_entry_submission() 0 3 1
A setup_vars() 0 13 1
B init() 0 24 4
A print_scripts() 0 10 1
B process_save() 0 58 6
A process_save_process_files() 0 10 2
A modify_fileupload_settings() 0 9 2
B form_prepare_for_save() 0 19 5
F maybe_update_post_fields() 0 203 42
A after_update() 0 18 2
A edit_entry_form() 0 50 1
B maybe_print_message() 0 32 3
B render_edit_form() 0 28 1
A render_form_buttons() 0 3 1
A filter_modify_form_fields() 0 18 3
B verify_user_can_edit_post() 0 30 5
C modify_edit_field_input() 0 64 12
C get_field_value() 0 60 19
D gform_pre_validation() 0 97 15
B validate() 0 36 3
F custom_validation() 0 124 21
A get_entry() 0 9 2
A get_configured_edit_fields() 0 19 2
A fix_hidden_fields() 0 13 3
C filter_fields() 0 66 13
B merge_field_properties() 0 23 4
B filter_admin_only_fields() 0 28 6
B filter_conditional_logic() 0 24 3
A manage_conditional_logic() 0 8 2
C user_can_edit_entry() 0 64 14
B user_can_edit_field() 0 22 4
A check_user_cap_edit_field() 0 16 4
B verify_nonce() 0 26 3

How to fix   Complexity   

Complex Class

Complex classes like GravityView_Edit_Entry_Render often do a lot of different things. To break such a class down, we need to identify a cohesive component within that class. A common approach to find such a component is to look for fields/methods that share the same prefixes, or suffixes. You can also have a look at the cohesion graph to spot any un-connected, or weakly-connected components.

Once you have determined the fields that belong together, you can apply the Extract Class refactoring. If the component makes sense as a sub-class, Extract Subclass is also a candidate, and is often faster.

While breaking up the class, it is a good idea to analyze how other classes use GravityView_Edit_Entry_Render, and based on these observations, apply Extract Interface, too.

1
<?php
0 ignored issues
show
Coding Style Compatibility introduced by
For compatibility and reusability of your code, PSR1 recommends that a file should introduce either new symbols (like classes, functions, etc.) or have side-effects (like outputting something, or including other files), but not both at the same time. The first symbol is defined on line 17 and the first side effect is on line 13.

The PSR-1: Basic Coding Standard recommends that a file should either introduce new symbols, that is classes, functions, constants or similar, or have side effects. Side effects are anything that executes logic, like for example printing output, changing ini settings or writing to a file.

The idea behind this recommendation is that merely auto-loading a class should not change the state of an application. It also promotes a cleaner style of programming and makes your code less prone to errors, because the logic is not spread out all over the place.

To learn more about the PSR-1, please see the PHP-FIG site on the PSR-1.

Loading history...
2
/**
3
 * GravityView Edit Entry - render frontend
4
 *
5
 * @package   GravityView
6
 * @license   GPL2+
7
 * @author    Katz Web Services, Inc.
8
 * @link      http://gravityview.co
9
 * @copyright Copyright 2014, Katz Web Services, Inc.
10
 */
11
12
if ( ! defined( 'WPINC' ) ) {
13
    die;
14
}
15
16
17
class GravityView_Edit_Entry_Render {
18
19
    /**
20
     * @var GravityView_Edit_Entry
21
     */
22
    protected $loader;
23
24
	/**
25
	 * @var string String used to generate unique nonce for the entry/form/view combination. Allows access to edit page.
26
	 */
27
    static $nonce_key;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $nonce_key.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
28
29
	/**
30
	 * @since 1.9
31
	 * @var string String used for check valid edit entry form submission. Allows saving edit form values.
32
	 */
33
	private static $nonce_field = 'is_gv_edit_entry';
34
35
	/**
36
	 * @since 1.9
37
	 * @var bool Whether to allow save and continue functionality
38
	 */
39
	private static $supports_save_and_continue = false;
40
41
	/**
42
	 * @since 1.9
43
	 * @var bool Whether to allow editing product fields
44
	 */
45
	private static $supports_product_fields = false;
46
47
    /**
48
     * Gravity Forms entry array
49
     *
50
     * @var array
51
     */
52
    var $entry;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $entry.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
53
54
    /**
55
     * Gravity Forms form array (GravityView change the content through this class lifecycle)
56
     *
57
     * @var array
58
     */
59
    var $form;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $form.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
60
61
    /**
62
     * Gravity Forms form array (original form)
63
     * @since 1.16.2
64
     * @var array
65
     */
66
    var $fields_with_calculation = array();
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $fields_with_calculation.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
67
68
    /**
69
     * Gravity Forms form array after the form validation process
70
     * @since 1.13
71
     * @var array
72
     */
73
    var $form_after_validation = null;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $form_after_validation.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
74
75
    /**
76
     * Gravity Forms form id
77
     *
78
     * @var int
79
     */
80
    var $form_id;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $form_id.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
81
82
    /**
83
     * ID of the current view
84
     *
85
     * @var int
86
     */
87
    var $view_id;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $view_id.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
88
89
90
    /**
91
     * Updated entry is valid (GF Validation object)
92
     *
93
     * @var array
94
     */
95
    var $is_valid = NULL;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $is_valid.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
96
97
    function __construct( GravityView_Edit_Entry $loader ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
98
        $this->loader = $loader;
99
    }
100
101
    function load() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
102
103
        /** @define "GRAVITYVIEW_DIR" "../../../" */
104
        include_once( GRAVITYVIEW_DIR .'includes/class-admin-approve-entries.php' );
105
106
        // Don't display an embedded form when editing an entry
107
        add_action( 'wp_head', array( $this, 'prevent_render_form' ) );
108
        add_action( 'wp_footer', array( $this, 'prevent_render_form' ) );
109
110
        // Stop Gravity Forms processing what is ours!
111
        add_filter( 'wp', array( $this, 'prevent_maybe_process_form'), 8 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
112
113
        add_filter( 'gravityview_is_edit_entry', array( $this, 'is_edit_entry') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
114
115
        add_action( 'gravityview_edit_entry', array( $this, 'init' ) );
116
117
        // Disable conditional logic if needed (since 1.9)
118
        add_filter( 'gform_has_conditional_logic', array( $this, 'manage_conditional_logic' ), 10, 2 );
119
120
        // Make sure GF doesn't validate max files (since 1.9)
121
        add_filter( 'gform_plupload_settings', array( $this, 'modify_fileupload_settings' ), 10, 3 );
122
123
        // Add fields expected by GFFormDisplay::validate()
124
        add_filter( 'gform_pre_validation', array( $this, 'gform_pre_validation') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
125
126
    }
127
128
    /**
129
     * Don't show any forms embedded on a page when GravityView is in Edit Entry mode
130
     *
131
     * Adds a `__return_empty_string` filter on the Gravity Forms shortcode on the `wp_head` action
132
     * And then removes it on the `wp_footer` action
133
     *
134
     * @since 1.16.1
135
     *
136
     * @return void
137
     */
138
    function prevent_render_form() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
139
        if( $this->is_edit_entry() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
140
            if( 'wp_head' === current_filter() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
141
                add_filter( 'gform_shortcode_form', '__return_empty_string' );
142
            } else {
143
                remove_filter( 'gform_shortcode_form', '__return_empty_string' );
144
            }
145
        }
146
    }
147
148
    /**
149
     * Because we're mimicking being a front-end Gravity Forms form while using a Gravity Forms
150
     * backend form, we need to prevent them from saving twice.
151
     * @return void
152
     */
153
    function prevent_maybe_process_form() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
154
155
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[prevent_maybe_process_form] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
156
157
        if( $this->is_edit_entry_submission() && $this->verify_nonce() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
158
            remove_action( 'wp',  array( 'RGForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
159
        }
160
    }
161
162
    /**
163
     * Is the current page an Edit Entry page?
164
     * @return boolean
165
     */
166
    public function is_edit_entry() {
167
168
        $gf_page = ( 'entry' === RGForms::get( 'view' ) );
169
170
        return ( $gf_page && isset( $_GET['edit'] ) || RGForms::post( 'action' ) === 'update' );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
171
    }
172
173
	/**
174
	 * Is the current page an Edit Entry page?
175
	 * @since 1.9
176
	 * @return boolean
177
	 */
178
	public function is_edit_entry_submission() {
179
		return !empty( $_POST[ self::$nonce_field ] );
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
180
	}
181
182
    /**
183
     * When Edit entry view is requested setup the vars
184
     */
185
    function setup_vars() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
186
        $gravityview_view = GravityView_View::getInstance();
187
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
188
189
        $entries = $gravityview_view->getEntries();
190
        $this->entry = $entries[0];
191
192
        $this->form = $gravityview_view->getForm();
193
        $this->form_id = $gravityview_view->getFormId();
194
        $this->view_id = $gravityview_view->getViewId();
195
196
        self::$nonce_key = GravityView_Edit_Entry::get_nonce_key( $this->view_id, $this->form_id, $this->entry['id'] );
197
    }
198
199
200
    /**
201
     * Load required files and trigger edit flow
202
     *
203
     * Run when the is_edit_entry returns true.
204
     *
205
     * @param GravityView_View_Data $gv_data GravityView Data object
206
     * @return void
207
     */
208
    function init( $gv_data ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
209
210
        require_once( GFCommon::get_base_path() . '/form_display.php' );
211
        require_once( GFCommon::get_base_path() . '/entry_detail.php' );
212
213
        $this->setup_vars();
214
215
        // Multiple Views embedded, don't proceed if nonce fails
216
        if( $gv_data->has_multiple_views() && ! wp_verify_nonce( $_GET['edit'], self::$nonce_key ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
217
            return;
218
        }
219
220
        // Sorry, you're not allowed here.
221
        if( false === $this->user_can_edit_entry( true ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
222
            return;
223
        }
224
225
        $this->print_scripts();
226
227
        $this->process_save();
228
229
        $this->edit_entry_form();
230
231
    }
232
233
234
    /**
235
     * Force Gravity Forms to output scripts as if it were in the admin
236
     * @return void
237
     */
238
    function print_scripts() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
239
        $gravityview_view = GravityView_View::getInstance();
240
241
        wp_register_script( 'gform_gravityforms', GFCommon::get_base_url().'/js/gravityforms.js', array( 'jquery', 'gform_json', 'gform_placeholder', 'sack', 'plupload-all', 'gravityview-fe-view' ) );
242
243
        GFFormDisplay::enqueue_form_scripts($gravityview_view->getForm(), false);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
244
245
        // Sack is required for images
246
        wp_print_scripts( array( 'sack', 'gform_gravityforms' ) );
247
    }
248
249
250
    /**
251
     * Process edit entry form save
252
     */
253
    function process_save() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
254
255
        if( empty( $_POST ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
256
            return;
257
        }
258
259
        // Make sure the entry, view, and form IDs are all correct
260
        $valid = $this->verify_nonce();
261
262
        if( !$valid ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
263
            do_action('gravityview_log_error', __METHOD__ . ' Nonce validation failed.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
264
            return;
265
        }
266
267
        if( $this->entry['id'] !== $_POST['lid'] ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
268
            do_action('gravityview_log_error', __METHOD__ . ' Entry ID did not match posted entry ID.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
269
            return;
270
        }
271
272
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[process_save] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
273
274
        $this->process_save_process_files( $this->form_id );
275
276
        $this->validate();
277
278
        if( $this->is_valid ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using ! empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
introduced by
Space after opening control structure is required
Loading history...
279
280
            do_action('gravityview_log_debug', 'GravityView_Edit_Entry[process_save] Submission is valid.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
281
282
            /**
283
             * @hack This step is needed to unset the adminOnly from form fields
284
             */
285
            $form = $this->form_prepare_for_save();
286
287
            /**
288
             * @hack to avoid the capability validation of the method save_lead for GF 1.9+
289
             */
290
            unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
291
292
            GFFormsModel::save_lead( $form, $this->entry );
293
294
            // If there's a post associated with the entry, process post fields
295
            if( !empty( $this->entry['post_id'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
296
                $this->maybe_update_post_fields( $form );
297
            }
298
299
            // Perform actions normally performed after updating a lead
300
            $this->after_update();
301
302
            /**
303
             * @action `gravityview/edit_entry/after_update` Perform an action after the entry has been updated using Edit Entry
304
             * @param array $form Gravity Forms form array
305
             * @param string $entry_id Numeric ID of the entry that was updated
306
             */
307
            do_action( 'gravityview/edit_entry/after_update', $this->form, $this->entry['id'] );
308
        }
309
310
    } // process_save
311
312
313
    /**
314
     * Have GF handle file uploads
315
     *
316
     * Copy of code from GFFormDisplay::process_form()
317
     *
318
     * @param int $form_id
319
     */
320
    function process_save_process_files( $form_id ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
321
322
        //Loading files that have been uploaded to temp folder
323
        $files = GFCommon::json_decode( stripslashes( RGForms::post( 'gform_uploaded_files' ) ) );
324
        if ( ! is_array( $files ) ) {
325
            $files = array();
326
        }
327
328
        RGFormsModel::$uploaded_files[ $form_id ] = $files;
329
    }
330
331
    /**
332
     * Remove max_files validation (done on gravityforms.js) to avoid conflicts with GravityView
333
     * Late validation done on self::custom_validation
334
     *
335
     * @param $plupload_init array Plupload settings
336
     * @param $form_id
337
     * @param $instance
338
     * @return mixed
339
     */
340
    public function modify_fileupload_settings( $plupload_init, $form_id, $instance ) {
0 ignored issues
show
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $instance is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
341
        if( ! $this->is_edit_entry() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
342
            return $plupload_init;
343
        }
344
345
        $plupload_init['gf_vars']['max_files'] = 0;
346
347
        return $plupload_init;
348
    }
349
350
351
    /**
352
     * Unset adminOnly and convert field input key to string
353
     * @return array $form
354
     */
355
    private function form_prepare_for_save() {
356
        $form = $this->form;
357
358
        // add the fields with calculation properties so they could be recalculated
359
        $form['fields'] = array_merge( $form['fields'], $this->fields_with_calculation );
360
361
        foreach( $form['fields'] as &$field ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
362
363
            $field->adminOnly = false;
364
365
            if( isset( $field->inputs ) && is_array( $field->inputs ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
366
                foreach( $field->inputs as $key => $input ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
367
                    $field->inputs[ $key ][ 'id' ] = (string)$input['id'];
0 ignored issues
show
introduced by
Array keys should NOT be surrounded by spaces if they only contain a string or an integer.
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
368
                }
369
            }
370
        }
371
372
        return $form;
373
    }
374
375
376
    /**
377
     * Loop through the fields being edited and if they include Post fields, update the Entry's post object
378
     *
379
     * @param array $form Gravity Forms form
380
     *
381
     * @return void
382
     */
383
    function maybe_update_post_fields( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
384
385
        $post_id = $this->entry['post_id'];
386
387
        // Security check
388
        if( false === GVCommon::has_cap( 'edit_post', $post_id ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
389
            do_action( 'gravityview_log_error', 'The current user does not have the ability to edit Post #'.$post_id );
390
            return;
391
        }
392
393
        $update_entry = false;
394
395
        $updated_post = $original_post = get_post( $post_id );
396
397
        foreach ( $this->entry as $field_id => $value ) {
398
399
            //todo: only run through the edit entry configured fields
400
401
            $field = RGFormsModel::get_field( $form, $field_id );
402
403
            if( class_exists('GF_Fields') ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
404
                $field = GF_Fields::create( $field );
405
            }
406
407
            if( GFCommon::is_post_field( $field ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
408
409
                // Get the value of the field, including $_POSTed value
410
                $value = RGFormsModel::get_field_value( $field );
411
412
                switch( $field->type ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
413
414
                    case 'post_title':
415
                    case 'post_content':
416
                    case 'post_excerpt':
417
                        $updated_post->{$field->type} = $value;
418
                        break;
419
                    case 'post_tags':
420
                        wp_set_post_tags( $post_id, $value, false );
421
                        break;
422
                    case 'post_category':
423
424
                        $categories = is_array( $value ) ? array_values( $value ) : (array)$value;
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
425
                        $categories = array_filter( $categories );
426
427
                        wp_set_post_categories( $post_id, $categories, false );
428
429
                        // if post_category is type checkbox, then value is an array of inputs
430
                        if( isset( $value[ strval( $field_id ) ] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
431
                            foreach( $value as $input_id => $val ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
432
                                $input_name = 'input_' . str_replace( '.', '_', $input_id );
433
                                $this->entry[ strval( $input_id ) ] = RGFormsModel::prepare_value( $form, $field, $val, $input_name, $this->entry['id'] );
434
                            }
435
                        } else {
436
                            $input_name = 'input_' . str_replace( '.', '_', $field_id );
437
                            $this->entry[ strval( $field_id ) ] = RGFormsModel::prepare_value( $form, $field, $value, $input_name, $this->entry['id'] );
438
                        }
439
440
                        break;
441
                    case 'post_custom_field':
442
443
                        $input_type = RGFormsModel::get_input_type( $field );
444
                        $custom_field_name = $field->postCustomFieldName;
445
446
                        // Only certain custom field types are supported
447
                        switch( $input_type ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
448
                            case 'fileupload':
449
                            /** @noinspection PhpMissingBreakStatementInspection */
0 ignored issues
show
Coding Style introduced by
Line indented incorrectly; expected at least 8 tabs, found 7
Loading history...
450
                            case 'list':
451
                                if( ! is_string( $value ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
452
                                    $value = function_exists('wp_json_encode') ? wp_json_encode( $value ) : json_encode( $value );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
453
                                }
454
                            // break; left intentionally out
1 ignored issue
show
Coding Style introduced by
Line indented incorrectly; expected at least 8 tabs, found 7
Loading history...
455
                            default:
456
                                update_post_meta( $post_id, $custom_field_name, $value );
457
                        }
458
459
                        break;
460
461
                    case 'post_image':
462
463
                        $input_name = 'input_' . $field_id;
464
465
                        if ( !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
466
467
                            // We have a new image
468
469
                            $value = RGFormsModel::prepare_value( $form, $field, $value, $input_name, $this->entry['id'] );
470
471
                            // is this field set as featured image, if not, leave
472
                            if ( ! $field->postFeaturedImage ) {
473
                                break;
474
                            }
475
476
                            $ary = ! empty( $value ) ? explode( '|:|', $value ) : array();
477
                            $img_url = rgar( $ary, 0 );
478
479
                            $img_title       = count( $ary ) > 1 ? $ary[1] : '';
480
                            $img_caption     = count( $ary ) > 2 ? $ary[2] : '';
481
                            $img_description = count( $ary ) > 3 ? $ary[3] : '';
482
483
                            $image_meta = array(
484
                                'post_excerpt' => $img_caption,
485
                                'post_content' => $img_description,
486
                            );
487
488
                            //adding title only if it is not empty. It will default to the file name if it is not in the array
489
                            if ( ! empty( $img_title ) ) {
490
                                $image_meta['post_title'] = $img_title;
491
                            }
492
493
                            //todo: As soon as \GFFormsModel::media_handle_upload becomes a public method, move this call to \GFFormsModel::media_handle_upload and remove the hack from this class.
494
                            require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
495
                            $media_id = GravityView_GFFormsModel::media_handle_upload( $img_url, $post_id, $image_meta );
496
497
                            if ( $media_id ) {
498
                                set_post_thumbnail( $post_id, $media_id );
499
                            }
500
501
                            break;
502
503
                        } elseif ( !empty( $_POST[ $input_name ] ) && is_array( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
504
505
                            // Same image although the image title, caption or description might have changed
506
507
                            $ary = ! empty( $this->entry[ $field_id ] ) ? explode( '|:|', $this->entry[ $field_id ] ) : array();
508
                            $img_url = rgar( $ary, 0 );
509
510
                            // is this really the same image or something went wrong ?
511
                            if( $img_url === $_POST[ $input_name ] ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
512
513
                                $img_title       = isset( $value[ $field_id .'.1' ] ) ? $value[ $field_id .'.1' ] : '';
514
                                $img_caption     = isset( $value[ $field_id .'.4' ] ) ? $value[ $field_id .'.4' ] : '';
515
                                $img_description = isset( $value[ $field_id .'.7' ] ) ? $value[ $field_id .'.7' ] : '';
516
517
                                $value = ! empty( $img_url ) ? $img_url . "|:|" . $img_title . "|:|" . $img_caption . "|:|" . $img_description : '';
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal |:| does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
518
519
                                if ( $field->postFeaturedImage ) {
520
521
                                    $image_meta = array(
522
                                        'ID' => get_post_thumbnail_id( $post_id ),
523
                                        'post_title' => $img_title,
524
                                        'post_excerpt' => $img_caption,
525
                                        'post_content' => $img_description,
526
                                    );
527
528
                                    // update image title, caption or description
529
                                    wp_update_post( $image_meta );
530
                                }
531
532
                                break;
533
                            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
534
535
                        }
536
537
                        // if we get here, image was removed or not set.
538
539
                        $value = '';
540
                        if ( $field->postFeaturedImage ) {
541
                            delete_post_thumbnail( $post_id );
542
                        }
543
544
                        break;
545
546
                }
547
548
                //ignore fields that have not changed
549
                if ( $value === rgget( (string) $field_id, $this->entry ) ) {
550
                    continue;
551
                }
552
553
                // update entry
554
                if( 'post_category' !== $field->type ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
555
                    $this->entry[ strval( $field_id ) ] = $value;
556
                }
557
558
                $update_entry = true;
559
560
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
561
562
        }
563
564
        if( $update_entry ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
565
566
            $return_entry = GFAPI::update_entry( $this->entry );
567
568
            if( is_wp_error( $return_entry ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
569
                do_action( 'gravityview_log_error', 'Updating the entry post fields failed', $return_entry );
570
            } else {
571
                do_action( 'gravityview_log_debug', 'Updating the entry post fields for post #'.$post_id.' succeeded' );
572
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
573
574
        }
575
576
        $return_post = wp_update_post( $updated_post, true );
577
578
        if( is_wp_error( $return_post ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
579
            $return_post->add_data( $updated_post, '$updated_post' );
580
            do_action( 'gravityview_log_error', 'Updating the post content failed', $return_post );
581
        } else {
582
            do_action( 'gravityview_log_debug', 'Updating the post content for post #'.$post_id.' succeeded', $updated_post );
583
        }
584
585
    }
586
587
588
    /**
589
     * Perform actions normally performed after updating a lead
590
     *
591
     * @since 1.8
592
     *
593
     * @see GFEntryDetail::lead_detail_page()
594
     *
595
     * @return void
596
     */
597
    function after_update() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
598
599
        do_action( 'gform_after_update_entry', $this->form, $this->entry['id'] );
600
        do_action( "gform_after_update_entry_{$this->form['id']}", $this->form, $this->entry['id'] );
601
602
        // Re-define the entry now that we've updated it.
603
        $entry = RGFormsModel::get_lead( $this->entry['id'] );
604
605
        $entry = GFFormsModel::set_entry_meta( $entry, $this->form );
606
607
        // We need to clear the cache because Gravity Forms caches the field values, which
608
        // we have just updated.
609
        foreach ($this->form['fields'] as $key => $field) {
0 ignored issues
show
introduced by
No space after opening parenthesis is prohibited
Loading history...
introduced by
No space before closing parenthesis is prohibited
Loading history...
610
            GFFormsModel::refresh_lead_field_value( $entry['id'], $field->id );
611
        }
612
613
        $this->entry = $entry;
614
    }
615
616
617
    /**
618
     * Display the Edit Entry form
619
     *
620
     * @return [type] [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
621
     */
622
    public function edit_entry_form() {
623
624
        ?>
625
626
        <div class="gv-edit-entry-wrapper"><?php
627
628
            $javascript = gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/inline-javascript.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
629
630
            /**
631
             * Fixes weird wpautop() issue
632
             * @see https://github.com/katzwebservices/GravityView/issues/451
633
             */
634
            echo gravityview_strip_whitespace( $javascript );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'gravityview_strip_whitespace'
Loading history...
635
636
            ?><h2 class="gv-edit-entry-title">
637
                <span><?php
638
639
                    /**
640
                     * @filter `gravityview_edit_entry_title` Modify the edit entry title
641
                     * @param string $edit_entry_title Modify the "Edit Entry" title
642
                     * @param GravityView_Edit_Entry_Render $this This object
643
                     */
644
                    $edit_entry_title = apply_filters('gravityview_edit_entry_title', __('Edit Entry', 'gravityview'), $this );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
645
646
                    echo esc_attr( $edit_entry_title );
647
            ?></span>
648
            </h2>
649
650
            <?php $this->maybe_print_message(); ?>
651
652
            <?php // The ID of the form needs to be `gform_{form_id}` for the pluploader ?>
653
654
            <form method="post" id="gform_<?php echo $this->form_id; ?>" enctype="multipart/form-data">
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$this'
Loading history...
655
656
                <?php
657
658
                wp_nonce_field( self::$nonce_key, self::$nonce_key );
659
660
                wp_nonce_field( self::$nonce_field, self::$nonce_field, false );
661
662
                // Print the actual form HTML
663
                $this->render_edit_form();
664
665
                ?>
666
            </form>
667
668
        </div>
669
670
    <?php
671
    }
672
673
    /**
674
     * Display success or error message if the form has been submitted
675
     *
676
     * @uses GVCommon::generate_notice
677
     *
678
     * @since TODO
679
     *
680
     * @return void
681
     */
682
    private function maybe_print_message() {
683
684
        if( rgpost('action') === 'update' ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
685
686
            $back_link = esc_url( remove_query_arg( array( 'page', 'view', 'edit' ) ) );
687
688
            if( ! $this->is_valid ){
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
introduced by
Space after opening control structure is required
Loading history...
689
690
                // Keeping this compatible with Gravity Forms.
691
                $validation_message = "<div class='validation_error'>" . __('There was a problem with your submission.', 'gravityview') . " " . __('Errors have been highlighted below.', 'gravityview') . "</div>";
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw '__'
Loading history...
Coding Style Comprehensibility introduced by
The string literal </div> does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
692
                $message = apply_filters("gform_validation_message_{$this->form['id']}", apply_filters("gform_validation_message", $validation_message, $this->form), $this->form);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal gform_validation_message does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
693
694
                echo GVCommon::generate_notice( $message , 'gv-error' );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
695
696
            } else {
697
                $entry_updated_message = sprintf( esc_attr__('Entry Updated. %sReturn to Entry%s', 'gravityview'), '<a href="'. $back_link .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
698
699
                /**
700
                 * @filter `gravityview/edit_entry/success` Modify the edit entry success message (including the anchor link)
701
                 * @since 1.5.4
702
                 * @param string $entry_updated_message Existing message
703
                 * @param int $view_id View ID
704
                 * @param array $entry Gravity Forms entry array
705
                 * @param string $back_link URL to return to the original entry. @since 1.6
706
                 */
707
                $message = apply_filters( 'gravityview/edit_entry/success', $entry_updated_message , $this->view_id, $this->entry, $back_link );
708
709
                echo GVCommon::generate_notice( $message );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
710
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
711
712
        }
713
    }
714
715
    /**
716
     * Display the Edit Entry form in the original Gravity Forms format
717
     *
718
     * @since 1.9
719
     *
720
     * @param $form
721
     * @param $lead
722
     * @param $view_id
723
     *
724
     * @return void
725
     */
726
    private function render_edit_form() {
727
728
        add_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields'), 5000, 3 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
729
        add_filter( 'gform_submit_button', array( $this, 'render_form_buttons') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
730
        add_filter( 'gform_disable_view_counter', '__return_true' );
731
732
        add_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5, 5 );
733
        add_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10, 5 );
734
735
        // We need to remove the fake $_GET['page'] arg to avoid rendering form as if in admin.
736
        unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
737
738
        // TODO: Make sure validation isn't handled by GF
739
        // TODO: Include CSS for file upload fields
740
        // TODO: Verify multiple-page forms
741
        // TODO: Product fields are not editable
742
        // TODO: Check Updated and Error messages
743
744
        $html = GFFormDisplay::get_form( $this->form['id'], false, false, true, $this->entry );
745
746
	    remove_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields' ), 5000 );
747
        remove_filter( 'gform_submit_button', array( $this, 'render_form_buttons' ) );
748
        remove_filter( 'gform_disable_view_counter', '__return_true' );
749
        remove_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5 );
750
        remove_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10 );
751
752
        echo $html;
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$html'
Loading history...
753
    }
754
755
    /**
756
     * Display the Update/Cancel/Delete buttons for the Edit Entry form
757
     * @since 1.8
758
     * @return string
759
     */
760
    public function render_form_buttons() {
761
        return gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/form-buttons.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
762
    }
763
764
765
    /**
766
     * Modify the form fields that are shown when using GFFormDisplay::get_form()
767
     *
768
     * By default, all fields will be shown. We only want the Edit Tab configured fields to be shown.
769
     *
770
     * @param array $form
771
     * @param boolean $ajax Whether in AJAX mode
772
     * @param array|string $field_values Passed parameters to the form
773
     *
774
     * @since 1.9
775
     *
776
     * @return array Modified form array
777
     */
778
    public function filter_modify_form_fields( $form, $ajax = false, $field_values = '' ) {
0 ignored issues
show
Unused Code introduced by
The parameter $ajax is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $field_values is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
779
780
        // In case we have validated the form, use it to inject the validation results into the form render
781
        if( isset( $this->form_after_validation ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
782
            $form = $this->form_after_validation;
783
        } else {
784
            $form['fields'] = $this->get_configured_edit_fields( $form, $this->view_id );
785
        }
786
787
        $form = $this->filter_conditional_logic( $form );
788
789
        // for now we don't support Save and Continue feature.
790
        if( ! self::$supports_save_and_continue ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
791
	        unset( $form['save'] );
792
        }
793
794
        return $form;
795
    }
796
797
    /**
798
     * When displaying a field, check if it's a Post Field, and if so, make sure the post exists and current user has edit rights.
799
     *
800
     * @since TODO
801
     *
802
     * @param string $field_content Always empty. Returning not-empty overrides the input.
803
     * @param GF_Field $field
804
     * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
805
     * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
806
     * @param int $form_id Form ID
807
     *
808
     * @return string If error, the error message. If no error, blank string (modify_edit_field_input() runs next)
809
     */
810
    function verify_user_can_edit_post( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
811
812
        if( GFCommon::is_post_field( $field ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
813
814
            $message = null;
815
816
            // First, make sure they have the capability to edit the post.
817
            if( false === current_user_can( 'edit_post', $this->entry['post_id'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
818
819
                /**
820
                 * @filter `gravityview/edit_entry/unsupported_post_field_text` Modify the message when someone isn't able to edit a post
821
                 * @param string $message The existing "You don't have permission..." text
822
                 */
823
                $message = apply_filters('gravityview/edit_entry/unsupported_post_field_text', __('You don&rsquo;t have permission to edit this post.', 'gravityview') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
824
825
            } elseif( null === get_post( $this->entry['post_id'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
826
                /**
827
                 * @filter `gravityview/edit_entry/no_post_text` Modify the message when someone is editing an entry attached to a post that no longer exists
828
                 * @param string $message The existing "This field is not editable; the post no longer exists." text
829
                 */
830
                $message = apply_filters('gravityview/edit_entry/no_post_text', __('This field is not editable; the post no longer exists.', 'gravityview' ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
831
            }
832
833
            if( $message ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
834
                $field_content = sprintf('<div class="ginput_container ginput_container_' . $field->type . '">%s</div>', wpautop( $message ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
835
            }
836
        }
837
838
        return $field_content;
839
    }
840
841
    /**
842
     *
843
     * Fill-in the saved values into the form inputs
844
     *
845
     * @param string $field_content Always empty. Returning not-empty overrides the input.
846
     * @param GF_Field $field
847
     * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
848
     * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
849
     * @param int $form_id Form ID
850
     *
851
     * @return mixed
852
     */
853
    function modify_edit_field_input( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
854
855
        $gv_field = GravityView_Fields::get_associated_field( $field );
856
857
        // If the form has been submitted, then we don't need to pre-fill the values,
858
        // Except for fileupload type and when a field input is overridden- run always!!
859
        if(
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
860
            ( $this->is_edit_entry_submission() && !in_array( $field->type, array( 'fileupload', 'post_image' ) ) )
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
861
            && false === ( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) )
862
            || ! empty( $field_content )
863
            || GFCommon::is_product_field( $field->type ) // Prevent product fields from appearing editable
864
        ) {
865
	        return $field_content;
866
        }
867
868
        // Turn on Admin-style display for file upload fields only
869
        if( 'fileupload' === $field->type ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
870
            $_GET['page'] = 'gf_entries';
871
        }
872
873
        // SET SOME FIELD DEFAULTS TO PREVENT ISSUES
874
        $field->adminOnly = false; /** @see GFFormDisplay::get_counter_init_script() need to prevent adminOnly */
875
876
        // add categories as choices for Post Category field
877
        if ( 'post_category' === $field->type ) {
878
            $field = GFCommon::add_categories_as_choices( $field, $value );
879
        }
880
881
        $field_value = $this->get_field_value( $field );
882
883
        /**
884
         * @filter `gravityview/edit_entry/field_value` Change the value of an Edit Entry field, if needed
885
         * @since 1.11
886
         * @param mixed $field_value field value used to populate the input
887
         * @param object $field Gravity Forms field object ( Class GF_Field )
888
         */
889
        $field_value = apply_filters( 'gravityview/edit_entry/field_value', $field_value, $field );
890
891
	    // Prevent any PHP warnings, like undefined index
892
	    ob_start();
893
894
        if( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
895
            $return = $gv_field->get_field_input( $this->form, $field_value, $this->entry, $field );
896
        } else {
897
	        $return = $field->get_field_input( $this->form, $field_value, $this->entry );
898
        }
899
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
900
901
	    // If there was output, it's an error
902
	    $warnings = ob_get_clean();
903
904
	    if( !empty( $warnings ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
905
		    do_action( 'gravityview_log_error', __METHOD__ . $warnings, $field_value );
906
	    }
907
908
        /**
909
         * Unset hack $_GET['page'] = 'gf_entries'
910
         * We need the fileupload html field to render with the proper id
911
         *  ( <li id="field_80_16" ... > )
912
         */
913
        unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
914
915
        return $return;
916
    }
917
918
    /**
919
     * Modify the value for the current field input
920
     *
921
     * @param GF_Field $field
922
     *
923
     * @return array|mixed|string|void
924
     */
925
    private function get_field_value( $field ) {
926
927
        /**
928
         * @filter `gravityview/edit_entry/pre_populate/override` Allow the pre-populated value to override saved value in Edit Entry form. By default, pre-populate mechanism only kicks on empty fields.
929
         * @param boolean True: override saved values; False: don't override (default)
930
         * @param $field GF_Field object Gravity Forms field object
931
         * @since 1.13
932
         */
933
        $override_saved_value = apply_filters( 'gravityview/edit_entry/pre_populate/override', false, $field );
934
935
        // We're dealing with multiple inputs (e.g. checkbox) but not time or date (as it doesn't store data in input IDs)
936
        if( isset( $field->inputs ) && is_array( $field->inputs ) && !in_array( $field->type, array( 'time', 'date' ) ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
937
938
            $field_value = array();
939
940
            // only accept pre-populated values if the field doesn't have any choice selected.
941
            $allow_pre_populated = $field->allowsPrepopulate;
942
943
            foreach ( (array)$field->inputs as $input ) {
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
944
945
                $input_id = strval( $input['id'] );
946
                
947
                if ( isset( $this->entry[ $input_id ] ) && ! gv_empty( $this->entry[ $input_id ], false, false ) ) {
948
                    $field_value[ $input_id ] =  'post_category' === $field->type ? GFCommon::format_post_category( $this->entry[ $input_id ], true ) : $this->entry[ $input_id ];
0 ignored issues
show
introduced by
Expected 1 space after "="; 2 found
Loading history...
949
                    $allow_pre_populated = false;
950
                }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
951
952
            }
953
954
            $pre_value = $field->get_value_submission( array(), false );
955
956
            $field_value = ! $allow_pre_populated && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $field_value : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
957
958
        } else {
959
960
            $id = intval( $field->id );
961
962
            // get pre-populated value if exists
963
            $pre_value = $field->allowsPrepopulate ? GFFormsModel::get_parameter_value( $field->inputName, array(), $field ) : '';
964
965
            // saved field entry value (if empty, fallback to the pre-populated value, if exists)
966
            // or pre-populated value if not empty and set to override saved value
967
            $field_value = !gv_empty( $this->entry[ $id ], false, false ) && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $this->entry[ $id ] : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
968
969
            // in case field is post_category but inputType is select, multi-select or radio, convert value into array of category IDs.
970
            if ( 'post_category' === $field->type && !gv_empty( $field_value, false, false ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
971
                $categories = array();
972
                foreach ( explode( ',', $field_value ) as $cat_string ) {
973
                    $categories[] = GFCommon::format_post_category( $cat_string, true );
974
                }
975
                $field_value = 'multiselect' === $field->get_input_type() ? $categories : implode( '', $categories );
976
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
977
978
        }
979
980
        // if value is empty get the default value if defined
981
        $field_value = $field->get_value_default_if_empty( $field_value );
982
983
        return $field_value;
984
    }
985
986
987
    // ---- Entry validation
988
989
    /**
990
     * Add field keys that Gravity Forms expects.
991
     *
992
     * @see GFFormDisplay::validate()
993
     * @param  array $form GF Form
994
     * @return array       Modified GF Form
995
     */
996
    function gform_pre_validation( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
997
998
        if( ! $this->verify_nonce() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
999
            return $form;
1000
        }
1001
1002
        // Fix PHP warning regarding undefined index.
1003
        foreach ( $form['fields'] as &$field) {
0 ignored issues
show
introduced by
No space before closing parenthesis is prohibited
Loading history...
1004
1005
            // This is because we're doing admin form pretending to be front-end, so Gravity Forms
1006
            // expects certain field array items to be set.
1007
            foreach ( array( 'noDuplicates', 'adminOnly', 'inputType', 'isRequired', 'enablePrice', 'inputs', 'allowedExtensions' ) as $key ) {
1008
	            $field->{$key} = isset( $field->{$key} ) ? $field->{$key} : NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1009
            }
1010
1011
            // unset emailConfirmEnabled for email type fields
1012
           /* if( 'email' === $field['type'] && !empty( $field['emailConfirmEnabled'] ) ) {
1 ignored issue
show
Unused Code Comprehensibility introduced by
61% of this comment could be valid code. Did you maybe forget this after debugging?

Sometimes obsolete code just ends up commented out instead of removed. In this case it is better to remove the code once you have checked you do not need it.

The code might also have been commented out for debugging purposes. In this case it is vital that someone uncomments it again or your project may behave in very unexpected ways in production.

This check looks for comments that seem to be mostly valid code and reports them.

Loading history...
Coding Style introduced by
Line indented incorrectly; expected at least 3 tabs, found 2
Loading history...
1013
                $field['emailConfirmEnabled'] = '';
1014
            }*/
1015
1016
            switch( RGFormsModel::get_input_type( $field ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1017
1018
                /**
1019
                 * this whole fileupload hack is because in the admin, Gravity Forms simply doesn't update any fileupload field if it's empty, but it DOES in the frontend.
1020
                 *
1021
                 * What we have to do is set the value so that it doesn't get overwritten as empty on save and appears immediately in the Edit Entry screen again.
1022
                 *
1023
                 * @hack
1024
                 */
1025
                case 'fileupload':
1026
1027
                    // Set the previous value
1028
                    $entry = $this->get_entry();
1029
1030
                    $input_name = 'input_'.$field->id;
1031
                    $form_id = $form['id'];
1032
1033
                    $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1034
1035
                    // Use the previous entry value as the default.
1036
                    if( isset( $entry[ $field->id ] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1037
                        $value = $entry[ $field->id ];
1038
                    }
1039
1040
                    // If this is a single upload file
1041
                    if( !empty( $_FILES[ $input_name ] ) && !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1042
                        $file_path = GFFormsModel::get_file_upload_path( $form['id'], $_FILES[ $input_name ]['name'] );
1043
                        $value = $file_path['url'];
1044
1045
                    } else {
1046
1047
                        // Fix PHP warning on line 1498 of form_display.php for post_image fields
1048
                        // Fix PHP Notice:  Undefined index:  size in form_display.php on line 1511
1049
                        $_FILES[ $input_name ] = array('name' => '', 'size' => '' );
0 ignored issues
show
introduced by
No space after opening parenthesis of array is bad style
Loading history...
1050
1051
                    }
1052
1053
                    if( rgar($field, "multipleFiles") ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal multipleFiles does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1054
1055
                        // If there are fresh uploads, process and merge them.
1056
                        // Otherwise, use the passed values, which should be json-encoded array of URLs
1057
                        if( isset( GFFormsModel::$uploaded_files[$form_id][$input_name] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1058
                            $value = empty( $value ) ? '[]' : $value;
1059
                            $value = stripslashes_deep( $value );
1060
                            $value = GFFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'], array());
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1061
                        }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1062
1063
                    } else {
1064
1065
                        // A file already exists when editing an entry
1066
                        // We set this to solve issue when file upload fields are required.
1067
                        GFFormsModel::$uploaded_files[ $form_id ][ $input_name ] = $value;
1068
1069
                    }
1070
1071
                    $this->entry[ $input_name ] = $value;
1072
                    $_POST[ $input_name ] = $value;
1073
1074
                    break;
1075
1076
                case 'number':
1077
                    // Fix "undefined index" issue at line 1286 in form_display.php
1078
                    if( !isset( $_POST['input_'.$field->id ] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1079
                        $_POST['input_'.$field->id ] = NULL;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1080
                    }
1081
                    break;
1082
                case 'captcha':
1083
                    // Fix issue with recaptcha_check_answer() on line 1458 in form_display.php
1084
                    $_POST['recaptcha_challenge_field'] = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1085
                    $_POST['recaptcha_response_field'] = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1086
                    break;
1087
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1088
1089
        }
1090
1091
        return $form;
1092
    }
1093
1094
1095
    /**
1096
     * Process validation for a edit entry submission
1097
     *
1098
     * Sets the `is_valid` object var
1099
     *
1100
     * @return void
1101
     */
1102
    function validate() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1103
1104
        /**
1105
         * If using GF User Registration Add-on, remove the validation step, otherwise generates error when updating the entry
1106
         * GF User Registration Add-on version > 3.x has a different class name
1107
         * @since 1.16.2
1108
         */
1109
        if ( class_exists( 'GF_User_Registration' ) ) {
1110
            remove_filter( 'gform_validation', array( GF_User_Registration::get_instance(), 'validate' ) );
1111
        } else  if ( class_exists( 'GFUser' ) ) {
1112
            remove_filter( 'gform_validation', array( 'GFUser', 'user_registration_validation' ) );
1113
        }
1114
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1115
1116
        /**
1117
         * For some crazy reason, Gravity Forms doesn't validate Edit Entry form submissions.
1118
         * You can enter whatever you want!
1119
         * We try validating, and customize the results using `self::custom_validation()`
1120
         */
1121
        add_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10, 4);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1122
1123
        // Needed by the validate funtion
1124
        $failed_validation_page = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1125
        $field_values = RGForms::post( 'gform_field_values' );
1126
1127
        // Prevent entry limit from running when editing an entry, also
1128
        // prevent form scheduling from preventing editing
1129
        unset( $this->form['limitEntries'], $this->form['scheduleForm'] );
1130
1131
        // Hide fields depending on Edit Entry settings
1132
        $this->form['fields'] = $this->get_configured_edit_fields( $this->form, $this->view_id );
1133
1134
        $this->is_valid = GFFormDisplay::validate( $this->form, $field_values, 1, $failed_validation_page );
1135
1136
        remove_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10 );
1137
    }
1138
1139
1140
    /**
1141
     * Make validation work for Edit Entry
1142
     *
1143
     * Because we're calling the GFFormDisplay::validate() in an unusual way (as a front-end
1144
     * form pretending to be a back-end form), validate() doesn't know we _can't_ edit post
1145
     * fields. This goes through all the fields and if they're an invalid post field, we
1146
     * set them as valid. If there are still issues, we'll return false.
1147
     *
1148
     * @param  [type] $validation_results [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1149
     * @return [type]                     [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1150
     */
1151
    function custom_validation( $validation_results ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1152
1153
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results: ', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1154
1155
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
1156
1157
        $gv_valid = true;
1158
1159
        foreach ( $validation_results['form']['fields'] as $key => &$field ) {
1160
1161
            $value = RGFormsModel::get_field_value( $field );
1162
            $field_type = RGFormsModel::get_input_type( $field );
1163
1164
            // Validate always
1165
            switch ( $field_type ) {
1166
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1167
1168
                case 'fileupload' :
1169
                case 'post_image':
1170
1171
                    // in case nothing is uploaded but there are already files saved
1172
                    if( !empty( $field->failed_validation ) && !empty( $field->isRequired ) && !empty( $value ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1173
                        $field->failed_validation = false;
1174
                        unset( $field->validation_message );
1175
                    }
1176
1177
                    // validate if multi file upload reached max number of files [maxFiles] => 2
1178
                    if( rgobj( $field, 'maxFiles') && rgobj( $field, 'multipleFiles') ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1179
1180
                        $input_name = 'input_' . $field->id;
1181
                        //uploaded
1182
                        $file_names = isset( GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] ) ? GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] : array();
1183
1184
                        //existent
1185
                        $entry = $this->get_entry();
1186
                        $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1187
                        if( isset( $entry[ $field->id ] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1188
                            $value = json_decode( $entry[ $field->id ], true );
1189
                        }
1190
1191
                        // count uploaded files and existent entry files
1192
                        $count_files = count( $file_names ) + count( $value );
1193
1194
                        if( $count_files > $field->maxFiles ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1195
                            $field->validation_message = __( 'Maximum number of files reached', 'gravityview' );
1196
                            $field->failed_validation = 1;
1197
                            $gv_valid = false;
1198
1199
                            // in case of error make sure the newest upload files are removed from the upload input
1200
                            GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ] = null;
1201
                        }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1202
1203
                    }
1204
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1205
1206
                    break;
1207
1208
            }
1209
1210
            // This field has failed validation.
1211
            if( !empty( $field->failed_validation ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1212
1213
                do_action( 'gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field is invalid.', array( 'field' => $field, 'value' => $value ) );
1214
1215
                switch ( $field_type ) {
1216
1217
                    // Captchas don't need to be re-entered.
1218
                    case 'captcha':
1219
1220
                        // Post Image fields aren't editable, so we un-fail them.
1221
                    case 'post_image':
1222
                        $field->failed_validation = false;
1223
                        unset( $field->validation_message );
1224
                        break;
1225
1226
                }
1227
1228
                // You can't continue inside a switch, so we do it after.
1229
                if( empty( $field->failed_validation ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1230
                    continue;
1231
                }
1232
1233
                // checks if the No Duplicates option is not validating entry against itself, since
1234
                // we're editing a stored entry, it would also assume it's a duplicate.
1235
                if( !empty( $field->noDuplicates ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1236
1237
                    $entry = $this->get_entry();
1238
1239
                    // If the value of the entry is the same as the stored value
1240
                    // Then we can assume it's not a duplicate, it's the same.
1241
                    if( !empty( $entry ) && $value == $entry[ $field->id ] ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1242
                        //if value submitted was not changed, then don't validate
1243
                        $field->failed_validation = false;
1244
1245
                        unset( $field->validation_message );
1246
1247
                        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field not a duplicate; it is the same entry.', $entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1248
1249
                        continue;
1250
                    }
1251
                }
1252
1253
                // if here then probably we are facing the validation 'At least one field must be filled out'
1254
                if( GFFormDisplay::is_empty( $field, $this->form_id  ) && empty( $field->isRequired ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 2 found
Loading history...
1255
                    unset( $field->validation_message );
1256
	                $field->validation_message = false;
1257
                    continue;
1258
                }
1259
1260
                $gv_valid = false;
1261
1262
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1263
1264
        }
1265
1266
        $validation_results['is_valid'] = $gv_valid;
1267
1268
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results.', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1269
1270
        // We'll need this result when rendering the form ( on GFFormDisplay::get_form )
1271
        $this->form_after_validation = $validation_results['form'];
1272
1273
        return $validation_results;
1274
    }
1275
1276
1277
    /**
1278
     * TODO: This seems to be hacky... we should remove it. Entry is set when updating the form using setup_vars()!
1279
     * Get the current entry and set it if it's not yet set.
1280
     * @return array Gravity Forms entry array
1281
     */
1282
    private function get_entry() {
1283
1284
        if( empty( $this->entry ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1285
            // Get the database value of the entry that's being edited
1286
            $this->entry = gravityview_get_entry( GravityView_frontend::is_single_entry() );
1287
        }
1288
1289
        return $this->entry;
1290
    }
1291
1292
1293
1294
    // --- Filters
1295
1296
    /**
1297
     * Get the Edit Entry fields as configured in the View
1298
     *
1299
     * @since 1.8
1300
     *
1301
     * @param int $view_id
1302
     *
1303
     * @return array Array of fields that are configured in the Edit tab in the Admin
1304
     */
1305
    private function get_configured_edit_fields( $form, $view_id ) {
1306
1307
        // Get all fields for form
1308
        $properties = GravityView_View_Data::getInstance()->get_fields( $view_id );
1309
1310
        // If edit tab not yet configured, show all fields
1311
        $edit_fields = !empty( $properties['edit_edit-fields'] ) ? $properties['edit_edit-fields'] : NULL;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1312
1313
	    // Show hidden fields as text fields
1314
	    $form = $this->fix_hidden_fields( $form );
1315
1316
        // Hide fields depending on admin settings
1317
        $fields = $this->filter_fields( $form['fields'], $edit_fields );
1318
1319
	    // If Edit Entry fields are configured, remove adminOnly field settings. Otherwise, don't.
1320
	    $fields = $this->filter_admin_only_fields( $fields, $edit_fields, $form, $view_id );
1321
1322
        return $fields;
1323
    }
1324
1325
	/**
1326
	 * @since 1.9.2
1327
	 *
1328
	 * @param $fields
1329
	 *
1330
	 * @return mixed
1331
	 */
1332
	private function fix_hidden_fields( $form ) {
1333
1334
		/** @var GF_Field $field */
1335
		foreach( $form['fields'] as $key => $field ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1336
			if( 'hidden' === $field->type ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1337
				$text_field = new GF_Field_Text( $field );
1338
				$text_field->type = 'text';
1339
				$form['fields'][ $key ] = $text_field;
1340
			}
1341
		}
1342
1343
		return $form;
1344
	}
1345
1346
1347
    /**
1348
     * Filter area fields based on specified conditions
1349
     *  - This filter removes the fields that have calculation configured
1350
     *
1351
     * @uses GravityView_Edit_Entry::user_can_edit_field() Check caps
1352
     * @access private
1353
     * @param GF_Field[] $fields
1354
     * @param array $configured_fields
1355
     * @since  1.5
1356
     * @return array $fields
1357
     */
1358
    private function filter_fields( $fields, $configured_fields ) {
1359
1360
        if( empty( $fields ) || !is_array( $fields ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1361
            return $fields;
1362
        }
1363
1364
        $edit_fields = array();
1365
1366
        $field_type_blacklist = array(
1367
            'page',
1368
        );
1369
1370
	    /**
1371
	     * @filter `gravityview/edit_entry/hide-product-fields` Hide product fields from being editable.
1372
	     * @since 1.9.1
1373
         * @param boolean $hide_product_fields Whether to hide product fields in the editor.  Default: false
1374
	     */
1375
	    $hide_product_fields = apply_filters( 'gravityview/edit_entry/hide-product-fields', empty( self::$supports_product_fields ) );
1376
1377
	    if( $hide_product_fields ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1378
		    $field_type_blacklist[] = 'option';
1379
		    $field_type_blacklist[] = 'quantity';
1380
            $field_type_blacklist[] = 'product';
1381
            $field_type_blacklist[] = 'total';
1382
            $field_type_blacklist[] = 'shipping';
1383
            $field_type_blacklist[] = 'calculation';
1384
	    }
1385
1386
        // First, remove blacklist or calculation fields
1387
        foreach ( $fields as $key => $field ) {
1388
1389
            // Remove the fields that have calculation properties and keep them to be used later
1390
            // @since 1.16.2
1391
            if( $field->has_calculation() || 'number' === $field->type ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1392
                $this->fields_with_calculation[] = $field;
1393
                unset( $fields[ $key ] );
1394
            }
1395
1396
            if( in_array( $field->type, $field_type_blacklist ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1397
                unset( $fields[ $key ] );
1398
            }
1399
        }
1400
1401
        // The Edit tab has not been configured, so we return all fields by default.
1402
        if( empty( $configured_fields ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1403
            return $fields;
1404
        }
1405
1406
        // The edit tab has been configured, so we loop through to configured settings
1407
        foreach ( $configured_fields as $configured_field ) {
1408
1409
	        /** @var GF_Field $field */
1410
	        foreach ( $fields as $field ) {
1411
1412
                if( intval( $configured_field['id'] ) === intval( $field->id ) && $this->user_can_edit_field( $configured_field, false ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1413
                    $edit_fields[] = $this->merge_field_properties( $field, $configured_field );
1414
                    break;
1415
                }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1416
1417
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1418
1419
        }
1420
1421
        return $edit_fields;
1422
1423
    }
1424
1425
    /**
1426
     * Override GF Form field properties with the ones defined on the View
1427
     * @param  GF_Field $field GF Form field object
1428
     * @param  array $setting  GV field options
0 ignored issues
show
Documentation introduced by
There is no parameter named $setting. Did you maybe mean $field_setting?

This check looks for PHPDoc comments describing methods or function parameters that do not exist on the corresponding method or function. It has, however, found a similar but not annotated parameter which might be a good fit.

Consider the following example. The parameter $ireland is not defined by the method finale(...).

/**
 * @param array $germany
 * @param array $ireland
 */
function finale($germany, $island) {
    return "2:1";
}

The most likely cause is that the parameter was changed, but the annotation was not.

Loading history...
1429
     * @since  1.5
1430
     * @return array
1431
     */
1432
    private function merge_field_properties( $field, $field_setting ) {
1433
1434
        $return_field = $field;
1435
1436
        if( empty( $field_setting['show_label'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1437
            $return_field->label = '';
1438
        } elseif ( !empty( $field_setting['custom_label'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1439
            $return_field->label = $field_setting['custom_label'];
1440
        }
1441
1442
        if( !empty( $field_setting['custom_class'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1443
            $return_field->cssClass .= ' '. gravityview_sanitize_html_class( $field_setting['custom_class'] );
1444
        }
1445
1446
        /**
1447
         * Normalize page numbers - avoid conflicts with page validation
1448
         * @since 1.6
1449
         */
1450
        $return_field->pageNumber = 1;
1451
1452
        return $return_field;
1453
1454
    }
1455
1456
    /**
1457
     * Remove fields that shouldn't be visible based on the Gravity Forms adminOnly field property
1458
     *
1459
     * @since 1.9.1
1460
     *
1461
     * @param array|GF_Field[] $fields Gravity Forms form fields
1462
     * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1463
     * @param array $form GF Form array
1464
     * @param int $view_id View ID
1465
     *
1466
     * @return array Possibly modified form array
1467
     */
1468
    function filter_admin_only_fields( $fields = array(), $edit_fields = null, $form = array(), $view_id = 0 ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1469
1470
	    /**
1471
         * @filter `gravityview/edit_entry/use_gf_admin_only_setting` When Edit tab isn't configured, should the Gravity Forms "Admin Only" field settings be used to control field display to non-admins? Default: true
1472
	     * If the Edit Entry tab is not configured, adminOnly fields will not be shown to non-administrators.
1473
	     * If the Edit Entry tab *is* configured, adminOnly fields will be shown to non-administrators, using the configured GV permissions
1474
	     * @since 1.9.1
1475
	     * @param boolean $use_gf_adminonly_setting True: Hide field if set to Admin Only in GF and the user is not an admin. False: show field based on GV permissions, ignoring GF permissions.
1476
	     * @param array $form GF Form array
1477
	     * @param int $view_id View ID
1478
	     */
1479
	    $use_gf_adminonly_setting = apply_filters( 'gravityview/edit_entry/use_gf_admin_only_setting', empty( $edit_fields ), $form, $view_id );
1480
1481
	    if( $use_gf_adminonly_setting && false === GVCommon::has_cap( 'gravityforms_edit_entries', $this->entry['id'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1482
            foreach( $fields as $k => $field ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1483
                if( $field->adminOnly ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1484
                    unset( $fields[ $k ] );
1485
                }
1486
            }
1487
            return $fields;
1488
        }
1489
1490
	    foreach( $fields as &$field ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1491
		    $field->adminOnly = false;
1492
        }
1493
1494
        return $fields;
1495
    }
1496
1497
    // --- Conditional Logic
1498
1499
    /**
1500
     * Remove the conditional logic rules from the form button and the form fields, if needed.
1501
     *
1502
     * @since 1.9
1503
     *
1504
     * @param array $form Gravity Forms form
1505
     * @return array Modified form, if not using Conditional Logic
1506
     */
1507
    function filter_conditional_logic( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1508
1509
        /**
1510
         * @filter `gravityview/edit_entry/conditional_logic` Should the Edit Entry form use Gravity Forms conditional logic showing/hiding of fields?
1511
         * @since 1.9
1512
         * @param bool $use_conditional_logic True: Gravity Forms will show/hide fields just like in the original form; False: conditional logic will be disabled and fields will be shown based on configuration. Default: true
1513
         * @param array $form Gravity Forms form
1514
         */
1515
        $use_conditional_logic = apply_filters( 'gravityview/edit_entry/conditional_logic', true, $form );
1516
1517
        if( $use_conditional_logic ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1518
            return $form;
1519
        }
1520
1521
        foreach( $form['fields'] as &$field ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1522
            /* @var GF_Field $field */
1523
            $field->conditionalLogic = null;
1524
        }
1525
1526
        unset( $form['button']['conditionalLogic'] );
1527
1528
        return $form;
1529
1530
    }
1531
1532
    /**
1533
     * Disable the Gravity Forms conditional logic script and features on the Edit Entry screen
1534
     *
1535
     * @since 1.9
1536
     *
1537
     * @param $has_conditional_logic
1538
     * @param $form
1539
     * @return mixed|void
1540
     */
1541
    function manage_conditional_logic( $has_conditional_logic, $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1542
1543
        if( ! $this->is_edit_entry() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1544
            return $has_conditional_logic;
1545
        }
1546
1547
        return apply_filters( 'gravityview/edit_entry/conditional_logic', $has_conditional_logic, $form );
1548
    }
1549
1550
1551
    // --- User checks and nonces
1552
1553
    /**
1554
     * Check if the user can edit the entry
1555
     *
1556
     * - Is the nonce valid?
1557
     * - Does the user have the right caps for the entry
1558
     * - Is the entry in the trash?
1559
     *
1560
     * @todo Move to GVCommon
1561
     *
1562
     * @param  boolean $echo Show error messages in the form?
1563
     * @return boolean        True: can edit form. False: nope.
1564
     */
1565
    function user_can_edit_entry( $echo = false ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1566
1567
        $error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1568
1569
        /**
1570
         *  1. Permalinks are turned off
1571
         *  2. There are two entries embedded using oEmbed
1572
         *  3. One of the entries has just been saved
1573
         */
1574
        if( !empty( $_POST['lid'] ) && !empty( $_GET['entry'] ) && ( $_POST['lid'] !== $_GET['entry'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1575
1576
            $error = true;
1577
1578
        }
1579
1580
        if( !empty( $_GET['entry'] ) && (string)$this->entry['id'] !== $_GET['entry'] ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1581
1582
            $error = true;
1583
1584
        } elseif( ! $this->verify_nonce() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1585
1586
            /**
1587
             * If the Entry is embedded, there may be two entries on the same page.
1588
             * If that's the case, and one is being edited, the other should fail gracefully and not display an error.
1589
             */
1590
            if( GravityView_oEmbed::getInstance()->get_entry_id() ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression \GravityView_oEmbed::get...tance()->get_entry_id() of type integer|null is loosely compared to true; this is ambiguous if the integer can be zero. You might want to explicitly use !== null instead.

In PHP, under loose comparison (like ==, or !=, or switch conditions), values of different types might be equal.

For integer values, zero is a special case, in particular the following results might be unexpected:

0   == false // true
0   == null  // true
123 == false // false
123 == null  // false

// It is often better to use strict comparison
0 === false // false
0 === null  // false
Loading history...
introduced by
Space after opening control structure is required
Loading history...
1591
                $error = true;
1592
            } else {
1593
                $error = __( 'The link to edit this entry is not valid; it may have expired.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1594
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1595
1596
        }
1597
1598
        if( ! GravityView_Edit_Entry::check_user_cap_edit_entry( $this->entry ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1599
            $error = __( 'You do not have permission to edit this entry.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1600
        }
1601
1602
        if( $this->entry['status'] === 'trash' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
introduced by
Space after opening control structure is required
Loading history...
1603
            $error = __('You cannot edit the entry; it is in the trash.', 'gravityview' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1604
        }
1605
1606
        // No errors; everything's fine here!
1607
        if( empty( $error ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1608
            return true;
1609
        }
1610
1611
        if( $echo && $error !== true ) {
0 ignored issues
show
introduced by
Found "!== true". Use Yoda Condition checks, you must
Loading history...
introduced by
Space after opening control structure is required
Loading history...
1612
1613
	        $error = esc_html( $error );
1614
1615
	        /**
1616
	         * @since 1.9
1617
	         */
1618
	        if ( ! empty( $this->entry ) ) {
1619
		        $error .= ' ' . gravityview_get_link( '#', _x('Go back.', 'Link shown when invalid Edit Entry link is clicked', 'gravityview' ), array( 'onclick' => "window.history.go(-1); return false;" ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal window.history.go(-1); return false; does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1620
	        }
1621
1622
            echo GVCommon::generate_notice( wpautop( $error ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1623
        }
1624
1625
        do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_entry]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1626
1627
        return false;
1628
    }
1629
1630
1631
    /**
1632
     * Check whether a field is editable by the current user, and optionally display an error message
1633
     * @uses  GravityView_Edit_Entry->check_user_cap_edit_field() Check user capabilities
1634
     * @param  array  $field Field or field settings array
1635
     * @param  boolean $echo  Whether to show error message telling user they aren't allowed
1636
     * @return boolean         True: user can edit the current field; False: nope, they can't.
1637
     */
1638
    private function user_can_edit_field( $field, $echo = false ) {
1639
1640
        $error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1641
1642
        if( ! $this->check_user_cap_edit_field( $field ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1643
            $error = __( 'You do not have permission to edit this field.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1644
        }
1645
1646
        // No errors; everything's fine here!
1647
        if( empty( $error ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1648
            return true;
1649
        }
1650
1651
        if( $echo ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1652
            echo GVCommon::generate_notice( wpautop( esc_html( $error ) ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1653
        }
1654
1655
        do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_field]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1656
1657
        return false;
1658
1659
    }
1660
1661
1662
    /**
1663
     * checks if user has permissions to edit a specific field
1664
     *
1665
     * Needs to be used combined with GravityView_Edit_Entry::user_can_edit_field for maximum security!!
1666
     *
1667
     * @param  [type] $field [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1668
     * @return bool
1669
     */
1670
    private function check_user_cap_edit_field( $field ) {
1671
1672
        // If they can edit any entries (as defined in Gravity Forms), we're good.
1673
        if( GVCommon::has_cap( array( 'gravityforms_edit_entries', 'gravityview_edit_others_entries' ) ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1674
            return true;
1675
        }
1676
1677
        $field_cap = isset( $field['allow_edit_cap'] ) ? $field['allow_edit_cap'] : false;
1678
1679
        // If the field has custom editing capaibilities set, check those
1680
        if( $field_cap ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1681
            return GVCommon::has_cap( $field['allow_edit_cap'] );
1682
        }
1683
1684
        return false;
1685
    }
1686
1687
1688
    /**
1689
     * Is the current nonce valid for editing the entry?
1690
     * @return boolean
1691
     */
1692
    public function verify_nonce() {
1693
1694
        // Verify form submitted for editing single
1695
        if( $this->is_edit_entry_submission() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1696
            $valid = wp_verify_nonce( $_POST[ self::$nonce_field ], self::$nonce_field );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
1697
        }
1698
1699
        // Verify
1700
        else if( ! $this->is_edit_entry() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1701
            $valid = false;
1702
        }
1703
1704
        else {
1705
            $valid = wp_verify_nonce( $_GET['edit'], self::$nonce_key );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
1706
        }
1707
1708
        /**
1709
         * @filter `gravityview/edit_entry/verify_nonce` Override Edit Entry nonce validation. Return true to declare nonce valid.
1710
         * @since 1.13
1711
         * @param int|boolean $valid False if invalid; 1 or 2 when nonce was generated
1712
         * @param string $nonce_field Key used when validating submissions. Default: is_gv_edit_entry
1713
         */
1714
        $valid = apply_filters( 'gravityview/edit_entry/verify_nonce', $valid, self::$nonce_field );
1715
1716
        return $valid;
1717
    }
1718
1719
1720
1721
} //end class