Completed
Push — develop ( 583dc3...24a577 )
by Gennady
18:12
created

maybe_print_message()   B

Complexity

Conditions 7
Paths 10

Size

Total Lines 50

Duplication

Lines 0
Ratio 0 %

Code Coverage

Tests 21
CRAP Score 7.0957

Importance

Changes 0
Metric Value
cc 7
nc 10
nop 0
dl 0
loc 50
ccs 21
cts 24
cp 0.875
crap 7.0957
rs 8.1575
c 0
b 0
f 0
1
<?php
0 ignored issues
show
Coding Style Compatibility introduced by
For compatibility and reusability of your code, PSR1 recommends that a file should introduce either new symbols (like classes, functions, etc.) or have side-effects (like outputting something, or including other files), but not both at the same time. The first symbol is defined on line 16 and the first side effect is on line 13.

The PSR-1: Basic Coding Standard recommends that a file should either introduce new symbols, that is classes, functions, constants or similar, or have side effects. Side effects are anything that executes logic, like for example printing output, changing ini settings or writing to a file.

The idea behind this recommendation is that merely auto-loading a class should not change the state of an application. It also promotes a cleaner style of programming and makes your code less prone to errors, because the logic is not spread out all over the place.

To learn more about the PSR-1, please see the PHP-FIG site on the PSR-1.

Loading history...
2
/**
3
 * GravityView Edit Entry - render frontend
4
 *
5
 * @package   GravityView
6
 * @license   GPL2+
7
 * @author    Katz Web Services, Inc.
8
 * @link      http://gravityview.co
9
 * @copyright Copyright 2014, Katz Web Services, Inc.
10
 */
11
12
if ( ! defined( 'WPINC' ) ) {
13
	die;
14
}
15
16
class GravityView_Edit_Entry_Render {
17
18
	/**
19
	 * @var GravityView_Edit_Entry
20
	 */
21
	protected $loader;
22
23
	/**
24
	 * @var string String used to generate unique nonce for the entry/form/view combination. Allows access to edit page.
25
	 */
26
	static $nonce_key;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $nonce_key.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
27
28
	/**
29
	 * @since 1.9
30
	 * @var string String used for check valid edit entry form submission. Allows saving edit form values.
31
	 */
32
	private static $nonce_field = 'is_gv_edit_entry';
33
34
	/**
35
	 * @since 1.9
36
	 * @var bool Whether to allow save and continue functionality
37
	 */
38
	private static $supports_save_and_continue = false;
39
40
	/**
41
	 * Gravity Forms entry array
42
	 *
43
	 * @var array
44
	 */
45
	public $entry;
46
47
	/**
48
	 * Gravity Forms entry array (it won't get changed during this class lifecycle)
49
	 * @since 1.17.2
50
	 * @var array
51
	 */
52
	private static $original_entry = array();
53
54
	/**
55
	 * Gravity Forms form array (GravityView modifies the content through this class lifecycle)
56
	 *
57
	 * @var array
58
	 */
59
	public $form;
60
61
	/**
62
	 * Gravity Forms form array (it won't get changed during this class lifecycle)
63
	 * @since 1.16.2.1
64
	 * @var array
65
	 */
66
	private static $original_form;
67
68
	/**
69
	 * Gravity Forms form array after the form validation process
70
	 * @since 1.13
71
	 * @var array
72
	 */
73
	public $form_after_validation = null;
74
75
	/**
76
	 * Hold an array of GF field objects that have calculation rules
77
	 * @var array
78
	 */
79
	public $fields_with_calculation = array();
80
81
	/**
82
	 * Gravity Forms form id
83
	 *
84
	 * @var int
85
	 */
86
	public $form_id;
87
88
	/**
89
	 * ID of the current view
90
	 *
91
	 * @var int
92
	 */
93
	public $view_id;
94
95
	/**
96
	 * ID of the current post. May also be ID of the current View.
97
     *
98
     * @since 2.0.13
99
     * 
100
     * @var int
101
	 */
102
	public $post_id;
103
104
	/**
105
	 * Updated entry is valid (GF Validation object)
106
	 *
107
	 * @var array
108
	 */
109
	public $is_valid = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
110
111 11
	function __construct( GravityView_Edit_Entry $loader ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
112 11
		$this->loader = $loader;
113 11
	}
114
115 11
	function load() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
116
117
		/** @define "GRAVITYVIEW_DIR" "../../../" */
118 11
		include_once( GRAVITYVIEW_DIR .'includes/class-admin-approve-entries.php' );
119
120
		// Don't display an embedded form when editing an entry
121 11
		add_action( 'wp_head', array( $this, 'prevent_render_form' ) );
122 11
		add_action( 'wp_footer', array( $this, 'prevent_render_form' ) );
123
124
		// Stop Gravity Forms processing what is ours!
125 11
		add_filter( 'wp', array( $this, 'prevent_maybe_process_form'), 8 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
126
127 11
		add_filter( 'gravityview_is_edit_entry', array( $this, 'is_edit_entry') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
128
129 11
		add_action( 'gravityview_edit_entry', array( $this, 'init' ) );
130
131
		// Disable conditional logic if needed (since 1.9)
132 11
		add_filter( 'gform_has_conditional_logic', array( $this, 'manage_conditional_logic' ), 10, 2 );
133
134
		// Make sure GF doesn't validate max files (since 1.9)
135 11
		add_filter( 'gform_plupload_settings', array( $this, 'modify_fileupload_settings' ), 10, 3 );
136
137
		// Add fields expected by GFFormDisplay::validate()
138 11
		add_filter( 'gform_pre_validation', array( $this, 'gform_pre_validation') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
139
140
		// Fix multiselect value for GF 2.2
141 11
		add_filter( 'gravityview/edit_entry/field_value_multiselect', array( $this, 'fix_multiselect_value_serialization' ), 10, 3 );
142 11
	}
143
144
	/**
145
	 * Don't show any forms embedded on a page when GravityView is in Edit Entry mode
146
	 *
147
	 * Adds a `__return_empty_string` filter on the Gravity Forms shortcode on the `wp_head` action
148
	 * And then removes it on the `wp_footer` action
149
	 *
150
	 * @since 1.16.1
151
	 *
152
	 * @return void
153
	 */
154 1
	public function prevent_render_form() {
155 1
		if( $this->is_edit_entry() ) {
156 1
			if( 'wp_head' === current_filter() ) {
157 1
				add_filter( 'gform_shortcode_form', '__return_empty_string' );
158
			} else {
159 1
				remove_filter( 'gform_shortcode_form', '__return_empty_string' );
160
			}
161
		}
162 1
	}
163
164
	/**
165
	 * Because we're mimicking being a front-end Gravity Forms form while using a Gravity Forms
166
	 * backend form, we need to prevent them from saving twice.
167
	 * @return void
168
	 */
169 1
	public function prevent_maybe_process_form() {
170
171 1
		if( ! empty( $_POST ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
172
	        gravityview()->log->debug( 'GravityView_Edit_Entry[prevent_maybe_process_form] $_POSTed data (sanitized): ', array( 'data' => esc_html( print_r( $_POST, true ) ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
173
		}
174
175 1
		if( $this->is_edit_entry_submission() ) {
176
			remove_action( 'wp',  array( 'RGForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
177
	        remove_action( 'wp',  array( 'GFForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
178
		}
179 1
	}
180
181
	/**
182
	 * Is the current page an Edit Entry page?
183
	 * @return boolean
184
	 */
185 16
	public function is_edit_entry() {
186
187 16
		$is_edit_entry = GravityView_frontend::is_single_entry() && ! empty( $_GET['edit'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
188
189 16
		return ( $is_edit_entry || $this->is_edit_entry_submission() );
190
	}
191
192
	/**
193
	 * Is the current page an Edit Entry page?
194
	 * @since 1.9
195
	 * @return boolean
196
	 */
197 16
	public function is_edit_entry_submission() {
198 16
		return !empty( $_POST[ self::$nonce_field ] );
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
199
	}
200
201
	/**
202
	 * When Edit entry view is requested setup the vars
203
	 */
204 11
	private function setup_vars() {
205 11
        global $post;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
206
207 11
		$gravityview_view = GravityView_View::getInstance();
208
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
209
210 11
		$entries = $gravityview_view->getEntries();
211 11
	    self::$original_entry = $entries[0];
212 11
	    $this->entry = $entries[0];
213
214 11
		self::$original_form = $gravityview_view->getForm();
215 11
		$this->form = $gravityview_view->getForm();
216 11
		$this->form_id = $gravityview_view->getFormId();
217 11
		$this->view_id = $gravityview_view->getViewId();
218 11
		$this->post_id = \GV\Utils::get( $post, 'ID', null );
219
220 11
		self::$nonce_key = GravityView_Edit_Entry::get_nonce_key( $this->view_id, $this->form_id, $this->entry['id'] );
221 11
	}
222
223
224
	/**
225
	 * Load required files and trigger edit flow
226
	 *
227
	 * Run when the is_edit_entry returns true.
228
	 *
229
	 * @param \GravityView_View_Data $gv_data GravityView Data object
230
	 * @return void
231
	 */
232 12
	public function init( $gv_data = null ) {
233
234 12
		require_once( GFCommon::get_base_path() . '/form_display.php' );
235 12
		require_once( GFCommon::get_base_path() . '/entry_detail.php' );
236
237 12
		$this->setup_vars();
238
239 12
		if ( ! $gv_data ) {
240
			$gv_data = GravityView_View_Data::getInstance();
241
		}
242
243
		// Multiple Views embedded, don't proceed if nonce fails
244 12
		if ( $gv_data->has_multiple_views() && ! $this->verify_nonce() ) {
0 ignored issues
show
Deprecated Code introduced by
The method GravityView_View_Data::has_multiple_views() has been deprecated.

This method has been deprecated.

Loading history...
245
			gravityview()->log->error( 'Nonce validation failed for the Edit Entry request; returning' );
246
			return;
247
		}
248
249
		// Sorry, you're not allowed here.
250 12
		if ( false === $this->user_can_edit_entry( true ) ) {
251 1
			gravityview()->log->error( 'User is not allowed to edit this entry; returning', array( 'data' => $this->entry ) );
252 1
			return;
253
		}
254
255 12
		$this->print_scripts();
256
257 12
		$this->process_save( $gv_data );
258
259 12
		$this->edit_entry_form();
260
261 12
	}
262
263
264
	/**
265
	 * Force Gravity Forms to output scripts as if it were in the admin
266
	 * @return void
267
	 */
268 11
	private function print_scripts() {
269 11
		$gravityview_view = GravityView_View::getInstance();
270
271 11
		wp_register_script( 'gform_gravityforms', GFCommon::get_base_url().'/js/gravityforms.js', array( 'jquery', 'gform_json', 'gform_placeholder', 'sack', 'plupload-all', 'gravityview-fe-view' ) );
272
273 11
		GFFormDisplay::enqueue_form_scripts( $gravityview_view->getForm(), false);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
274
275 11
		wp_localize_script( 'gravityview-fe-view', 'gvGlobals', array( 'cookiepath' => COOKIEPATH ) );
276
277
		// Sack is required for images
278 11
		wp_print_scripts( array( 'sack', 'gform_gravityforms', 'gravityview-fe-view' ) );
279 11
	}
280
281
282
	/**
283
	 * Process edit entry form save
284
	 *
285
	 * @param array $gv_data The View data.
286
	 */
287 12
	private function process_save( $gv_data ) {
288
289 12
		if ( empty( $_POST ) || ! isset( $_POST['lid'] ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
290 5
			return;
291
		}
292
293
		// Make sure the entry, view, and form IDs are all correct
294 11
		$valid = $this->verify_nonce();
295
296 11
		if ( !$valid ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
297
			gravityview()->log->error( 'Nonce validation failed.' );
298
			return;
299
		}
300
301 11
		if ( $this->entry['id'] !== $_POST['lid'] ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
302
			gravityview()->log->error( 'Entry ID did not match posted entry ID.' );
303
			return;
304
		}
305
306 11
		gravityview()->log->debug( '$_POSTed data (sanitized): ', array( 'data' => esc_html( print_r( $_POST, true ) ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
307
308 11
		$this->process_save_process_files( $this->form_id );
309
310 11
		$this->validate();
311
312 11
		if( $this->is_valid ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using ! empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
313
314 11
			gravityview()->log->debug( 'Submission is valid.' );
315
316
			/**
317
			 * @hack This step is needed to unset the adminOnly from form fields, to add the calculation fields
318
			 */
319 11
			$form = $this->form_prepare_for_save();
320
321
			/**
322
			 * @hack to avoid the capability validation of the method save_lead for GF 1.9+
323
			 */
324 11
			unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
325
326 11
			$date_created = $this->entry['date_created'];
327
328
			/**
329
			 * @hack to force Gravity Forms to use $read_value_from_post in GFFormsModel::save_lead()
330
			 * @since 1.17.2
331
			 */
332 11
			unset( $this->entry['date_created'] );
333
334 11
			GFFormsModel::save_lead( $form, $this->entry );
335
336
	        // Delete the values for hidden inputs
337 11
	        $this->unset_hidden_field_values();
338
			
339 11
			$this->entry['date_created'] = $date_created;
340
341
			// Process calculation fields
342 11
			$this->update_calculation_fields();
343
344
			// Process Quiz fields
345 11
			$this->update_quiz_fields();
346
347
			// Perform actions normally performed after updating a lead
348 11
			$this->after_update();
349
350
	        /**
351
			 * Must be AFTER after_update()!
352
			 * @see https://github.com/gravityview/GravityView/issues/764
353
			 */
354 11
			$this->maybe_update_post_fields( $form );
355
356
			/**
357
			 * @action `gravityview/edit_entry/after_update` Perform an action after the entry has been updated using Edit Entry
358
             * @since 2.1 Added $gv_data parameter
359
			 * @param array $form Gravity Forms form array
360
			 * @param string $entry_id Numeric ID of the entry that was updated
361
			 * @param GravityView_Edit_Entry_Render $this This object
362
			 * @param GravityView_View_Data $gv_data The View data
363
			 */
364 11
			do_action( 'gravityview/edit_entry/after_update', $this->form, $this->entry['id'], $this, $gv_data );
365
366
		} else {
367
			gravityview()->log->error( 'Submission is NOT valid.', array( 'entry' => $this->entry ) );
368
		}
369
370 11
	} // process_save
371
372
	/**
373
	 * Delete the value of fields hidden by conditional logic when the entry is edited
374
	 *
375
	 * @uses GFFormsModel::update_lead_field_value()
376
	 *
377
	 * @since 1.17.4
378
	 *
379
	 * @return void
380
	 */
381 10
	private function unset_hidden_field_values() {
382 10
	    global $wpdb;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
383
384
		/**
385
		 * @filter `gravityview/edit_entry/unset_hidden_field_values` Whether to delete values of fields hidden by conditional logic
386
		 * @since 1.22.2
387
		 * @param bool $unset_hidden_field_values Default: true
388
		 * @param GravityView_Edit_Entry_Render $this This object
389
		 */
390 10
		$unset_hidden_field_values = apply_filters( 'gravityview/edit_entry/unset_hidden_field_values', true, $this );
391
392 10
		if( ! $unset_hidden_field_values ) {
393
			return;
394
		}
395
396 10
		if ( version_compare( GravityView_GFFormsModel::get_database_version(), '2.3-dev-1', '>=' ) && method_exists( 'GFFormsModel', 'get_entry_meta_table_name' ) ) {
397 10
			$entry_meta_table = GFFormsModel::get_entry_meta_table_name();
398 10
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT meta_key, meta_value FROM $entry_meta_table WHERE entry_id=%d", $this->entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
399
		} else {
400
			$lead_detail_table = GFFormsModel::get_lead_details_table_name();
401
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT id, field_number FROM $lead_detail_table WHERE lead_id=%d", $this->entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
402
		}
403
404 10
	    foreach ( $this->entry as $input_id => $field_value ) {
405
406 10
		    $field = RGFormsModel::get_field( $this->form, $input_id );
407
408
		    // Reset fields that are hidden
409
		    // Don't pass $entry as fourth parameter; force using $_POST values to calculate conditional logic
410 10
		    if ( GFFormsModel::is_field_hidden( $this->form, $field, array(), NULL ) ) {
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
411
412
		        // List fields are stored as empty arrays when empty
413
			    $empty_value = $this->is_field_json_encoded( $field ) ? '[]' : '';
414
415
			    $lead_detail_id = GFFormsModel::get_lead_detail_id( $current_fields, $input_id );
416
417
			    GFFormsModel::update_lead_field_value( $this->form, $this->entry, $field, $lead_detail_id, $input_id, $empty_value );
418
419
			    // Prevent the $_POST values of hidden fields from being used as default values when rendering the form
420
				// after submission
421
			    $post_input_id = 'input_' . str_replace( '.', '_', $input_id );
422 10
			    $_POST[ $post_input_id ] = '';
423
		    }
424
	    }
425 10
	}
426
427
	/**
428
	 * Have GF handle file uploads
429
	 *
430
	 * Copy of code from GFFormDisplay::process_form()
431
	 *
432
	 * @param int $form_id
433
	 */
434 10
	private function process_save_process_files( $form_id ) {
435
436
		//Loading files that have been uploaded to temp folder
437 10
		$files = GFCommon::json_decode( stripslashes( RGForms::post( 'gform_uploaded_files' ) ) );
438 10
		if ( ! is_array( $files ) ) {
439 9
			$files = array();
440
		}
441
442
		/**
443
		 * Make sure the fileuploads are not overwritten if no such request was done.
444
		 * @since 1.20.1
445
		 */
446 10
		add_filter( "gform_save_field_value_$form_id", array( $this, 'save_field_value' ), 99, 5 );
447
448 10
		RGFormsModel::$uploaded_files[ $form_id ] = $files;
449 10
	}
450
451
	/**
452
	 * Make sure the fileuploads are not overwritten if no such request was done.
453
	 *
454
	 * TO ONLY BE USED INTERNALLY; DO NOT DEVELOP ON; MAY BE REMOVED AT ANY TIME.
455
	 *
456
	 * @since 1.20.1
457
	 *
458
	 * @param string $value Field value
459
	 * @param array $entry GF entry array
460
	 * @param GF_Field_FileUpload $field
461
	 * @param array $form GF form array
462
	 * @param string $input_id ID of the input being saved
463
	 *
464
	 * @return string
465
	 */
466 10
	public function save_field_value( $value = '', $entry = array(), $field = null, $form = array(), $input_id = '' ) {
467
468 10
		if ( ! $field || $field->type != 'fileupload' ) {
0 ignored issues
show
introduced by
Found "!= '". Use Yoda Condition checks, you must
Loading history...
469 10
			return $value;
470
		}
471
472 1
		$input_name = 'input_' . str_replace( '.', '_', $input_id );
473
474 1
		if ( $field->multipleFiles ) {
475
			if ( empty( $value ) ) {
476
				return json_decode( $entry[ $input_id ], true );
477
			}
478
			return $value;
479
		}
480
481
		/** No file is being uploaded. */
482 1
		if ( empty( $_FILES[ $input_name ]['name'] ) ) {
483
			/** So return the original upload */
484 1
			return $entry[ $input_id ];
485
		}
486
487 1
		return $value;
488
	}
489
490
	/**
491
	 * Remove max_files validation (done on gravityforms.js) to avoid conflicts with GravityView
492
	 * Late validation done on self::custom_validation
493
	 *
494
	 * @param $plupload_init array Plupload settings
495
	 * @param $form_id
496
	 * @param $instance
497
	 * @return mixed
498
	 */
499 2
	public function modify_fileupload_settings( $plupload_init, $form_id, $instance ) {
0 ignored issues
show
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $instance is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
500 2
		if( ! $this->is_edit_entry() ) {
501
			return $plupload_init;
502
		}
503
504 2
		$plupload_init['gf_vars']['max_files'] = 0;
505
506 2
		return $plupload_init;
507
	}
508
509
510
	/**
511
	 * Set visibility to visible and convert field input key to string
512
	 * @return array $form
513
	 */
514 10
	private function form_prepare_for_save() {
515
516 10
		$form = $this->form;
517
518
	    /** @var GF_Field $field */
519 10
		foreach( $form['fields'] as $k => &$field ) {
520
521
			/**
522
			 * Remove the fields with calculation formulas before save to avoid conflicts with GF logic
523
			 * @since 1.16.3
524
			 * @var GF_Field $field
525
			 */
526 10
			if( $field->has_calculation() ) {
527 3
				unset( $form['fields'][ $k ] );
528
			}
529
530 10
			$field->adminOnly = false;
531
532 10
			if( isset( $field->inputs ) && is_array( $field->inputs ) ) {
533 2
				foreach( $field->inputs as $key => $input ) {
534 10
				    $field->inputs[ $key ][ 'id' ] = (string)$input['id'];
0 ignored issues
show
introduced by
Array keys should NOT be surrounded by spaces if they only contain a string or an integer.
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
535
				}
536
			}
537
		}
538
539 10
		$form['fields'] = array_values( $form['fields'] );
540
541 10
		return $form;
542
	}
543
544 10
	private function update_calculation_fields() {
545 10
		global $wpdb;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
546
547 10
		$form = self::$original_form;
548 10
		$update = false;
549
550
		// get the most up to date entry values
551 10
		$entry = GFAPI::get_entry( $this->entry['id'] );
552
553 10
		if ( version_compare( GravityView_GFFormsModel::get_database_version(), '2.3-dev-1', '>=' ) && method_exists( 'GFFormsModel', 'get_entry_meta_table_name' ) ) {
554 10
			$entry_meta_table = GFFormsModel::get_entry_meta_table_name();
555 10
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT id, meta_key FROM $entry_meta_table WHERE entry_id=%d", $entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
556
		} else {
557
			$lead_detail_table = GFFormsModel::get_lead_details_table_name();
558
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT id, field_number FROM $lead_detail_table WHERE lead_id=%d", $entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
559
		}
560
561 10
		if ( ! empty( $this->fields_with_calculation ) ) {
562 3
			$update = true;
563 3
			foreach ( $this->fields_with_calculation as $field ) {
564 3
				$inputs = $field->get_entry_inputs();
565 3
				if ( is_array( $inputs ) ) {
566 2
				    foreach ( $inputs as $input ) {
567 2
						GFFormsModel::save_input( $form, $field, $entry, $current_fields, $input['id'] );
568
				    }
569
				} else {
570 3
					GFFormsModel::save_input( $form, $field, $entry, $current_fields, $field->id );
571
				}
572
			}
573
574 3
			if ( method_exists( 'GFFormsModel', 'commit_batch_field_operations' ) ) {
575 3
				GFFormsModel::commit_batch_field_operations();
576
			}
577
		}
578 10
	}
579
580
	/**
581
	 * Make sure the quiz is updated accordingly.
582
	 * https://github.com/gravityview/GravityView/issues/1166
583
	 */
584 10
	private function update_quiz_fields() {
585 10
		if ( ! class_exists( 'GFQuiz' ) ) {
586 10
			return;
587
		}
588
589
		$entry = GFAPI::get_entry( $this->entry['id'] );
590
591
		foreach ( array( 'score', 'percent', 'grade', 'is_pass' ) as $meta ) {
592
			GFQuiz::get_instance()->update_entry_meta( "gfquiz_$meta", $entry, self::$original_form );
593
		}
594
	}
595
596
	/**
597
	 * Handle updating the Post Image field
598
	 *
599
	 * Sets a new Featured Image if configured in Gravity Forms; otherwise uploads/updates media
600
	 *
601
	 * @since 1.17
602
	 *
603
	 * @uses GFFormsModel::media_handle_upload
604
	 * @uses set_post_thumbnail
605
	 * 
606
	 * @param array $form GF Form array
607
	 * @param GF_Field $field GF Field
608
	 * @param string $field_id Numeric ID of the field
609
	 * @param string $value
610
	 * @param array $entry GF Entry currently being edited
611
	 * @param int $post_id ID of the Post being edited
612
	 *
613
	 * @return mixed|string
614
	 */
615 1
	private function update_post_image( $form, $field, $field_id, $value, $entry, $post_id ) {
616
617 1
		$input_name = 'input_' . $field_id;
618
619 1
		if ( !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
620
621
			// We have a new image
622
623
			$value = RGFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'] );
624
625
			$ary = ! empty( $value ) ? explode( '|:|', $value ) : array();
626
	        $ary = stripslashes_deep( $ary );
627
			$img_url = \GV\Utils::get( $ary, 0 );
628
629
			$img_title       = count( $ary ) > 1 ? $ary[1] : '';
630
			$img_caption     = count( $ary ) > 2 ? $ary[2] : '';
631
			$img_description = count( $ary ) > 3 ? $ary[3] : '';
632
633
			$image_meta = array(
634
				'post_excerpt' => $img_caption,
635
				'post_content' => $img_description,
636
			);
637
638
			//adding title only if it is not empty. It will default to the file name if it is not in the array
639
			if ( ! empty( $img_title ) ) {
640
				$image_meta['post_title'] = $img_title;
641
			}
642
643
			/**
644
			 * todo: As soon as \GFFormsModel::media_handle_upload becomes a public method, move this call to \GFFormsModel::media_handle_upload and remove the hack from this class.
645
			 * Note: the method became public in GF 1.9.17.7, but we don't require that version yet.
646
			 */
647
			require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
648
			$media_id = GravityView_GFFormsModel::media_handle_upload( $img_url, $post_id, $image_meta );
649
650
			// is this field set as featured image?
651
			if ( $media_id && $field->postFeaturedImage ) {
652
				set_post_thumbnail( $post_id, $media_id );
653
			}
654
655 1
		} elseif ( ! empty( $_POST[ $input_name ] ) && is_array( $value ) ) {
656
657 1
			$img_url         = stripslashes_deep( $_POST[ $input_name ] );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
658 1
			$img_title       = stripslashes_deep( \GV\Utils::_POST( $input_name . '_1' ) );
659 1
			$img_caption     = stripslashes_deep( \GV\Utils::_POST( $input_name . '_4' ) );
660 1
			$img_description = stripslashes_deep( \GV\Utils::_POST( $input_name . '_7' ) );
661
662 1
			$value = ! empty( $img_url ) ? $img_url . "|:|" . $img_title . "|:|" . $img_caption . "|:|" . $img_description : '';
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal |:| does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
663
664 1
			if ( $field->postFeaturedImage ) {
665
666
				$image_meta = array(
667 1
					'ID' => get_post_thumbnail_id( $post_id ),
668 1
					'post_title' => $img_title,
669 1
					'post_excerpt' => $img_caption,
670 1
					'post_content' => $img_description,
671
				);
672
673
				// update image title, caption or description
674 1
				wp_update_post( $image_meta );
675
			}
676
		} else {
677
678
			// if we get here, image was removed or not set.
679
			$value = '';
680
681
			if ( $field->postFeaturedImage ) {
682
				delete_post_thumbnail( $post_id );
683
			}
684
		}
685
686 1
		return $value;
687
	}
688
689
	/**
690
	 * Loop through the fields being edited and if they include Post fields, update the Entry's post object
691
	 *
692
	 * @param array $form Gravity Forms form
693
	 *
694
	 * @return void
695
	 */
696 10
	private function maybe_update_post_fields( $form ) {
697
698 10
		if( empty( $this->entry['post_id'] ) ) {
699 9
	        gravityview()->log->debug( 'This entry has no post fields. Continuing...' );
700 9
			return;
701
		}
702
703 1
		$post_id = $this->entry['post_id'];
704
705
		// Security check
706 1
		if( false === GVCommon::has_cap( 'edit_post', $post_id ) ) {
707
			gravityview()->log->error( 'The current user does not have the ability to edit Post #{post_id}', array( 'post_id' => $post_id ) );
708
			return;
709
		}
710
711 1
		$update_entry = false;
712
713 1
		$updated_post = $original_post = get_post( $post_id );
714
715 1
		foreach ( $this->entry as $field_id => $value ) {
716
717 1
			$field = RGFormsModel::get_field( $form, $field_id );
718
719 1
			if( ! $field ) {
720 1
				continue;
721
			}
722
723 1
			if( GFCommon::is_post_field( $field ) && 'post_category' !== $field->type ) {
724
725
				// Get the value of the field, including $_POSTed value
726 1
				$value = RGFormsModel::get_field_value( $field );
727
728
				// Use temporary entry variable, to make values available to fill_post_template() and update_post_image()
729 1
				$entry_tmp = $this->entry;
730 1
				$entry_tmp["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
731
732 1
				switch( $field->type ) {
733
734 1
				    case 'post_title':
735
				        $post_title = $value;
736
				        if ( \GV\Utils::get( $form, 'postTitleTemplateEnabled' ) ) {
737
				            $post_title = $this->fill_post_template( $form['postTitleTemplate'], $form, $entry_tmp );
738
				        }
739
				        $updated_post->post_title = $post_title;
740
				        $updated_post->post_name  = $post_title;
741
				        unset( $post_title );
742
				        break;
743
744 1
				    case 'post_content':
745
				        $post_content = $value;
746
				        if ( \GV\Utils::get( $form, 'postContentTemplateEnabled' ) ) {
747
				            $post_content = $this->fill_post_template( $form['postContentTemplate'], $form, $entry_tmp, true );
748
				        }
749
				        $updated_post->post_content = $post_content;
750
				        unset( $post_content );
751
				        break;
752 1
				    case 'post_excerpt':
753
				        $updated_post->post_excerpt = $value;
754
				        break;
755 1
				    case 'post_tags':
756
				        wp_set_post_tags( $post_id, $value, false );
757
				        break;
758 1
				    case 'post_category':
759
				        break;
760 1
				    case 'post_custom_field':
761
						if ( is_array( $value ) && ( floatval( $field_id ) !== floatval( $field->id ) ) ) {
762
							$value = $value[ $field_id ];
763
						}
764
765
				        if( ! empty( $field->customFieldTemplateEnabled ) ) {
766
				            $value = $this->fill_post_template( $field->customFieldTemplate, $form, $entry_tmp, true );
767
				        }
768
769
	                    if ( $this->is_field_json_encoded( $field ) && ! is_string( $value ) ) {
770
		                    $value = wp_json_encode( $value );
771
	                    }
772
773
				        update_post_meta( $post_id, $field->postCustomFieldName, $value );
774
				        break;
775
776 1
				    case 'post_image':
777 1
				        $value = $this->update_post_image( $form, $field, $field_id, $value, $this->entry, $post_id );
778 1
				        break;
779
780
				}
781
782
				// update entry after
783 1
				$this->entry["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
784
785 1
				$update_entry = true;
786
787 1
				unset( $entry_tmp );
788
			}
789
790
		}
791
792 1
		if( $update_entry ) {
793
794 1
			$return_entry = GFAPI::update_entry( $this->entry );
795
796 1
			if( is_wp_error( $return_entry ) ) {
797
				gravityview()->log->error( 'Updating the entry post fields failed', array( 'data' => array( '$this->entry' => $this->entry, '$return_entry' => $return_entry ) ) );
798
			} else {
799 1
				gravityview()->log->debug( 'Updating the entry post fields for post #{post_id} succeeded', array( 'post_id' => $post_id ) );
800
			}
801
802
		}
803
804 1
		$return_post = wp_update_post( $updated_post, true );
805
806 1
		if( is_wp_error( $return_post ) ) {
807
			$return_post->add_data( $updated_post, '$updated_post' );
808
			gravityview()->log->error( 'Updating the post content failed', array( 'data' => compact( 'updated_post', 'return_post' ) ) );
809
		} else {
810 1
			gravityview()->log->debug( 'Updating the post content for post #{post_id} succeeded', array( 'post_id' => $post_id, 'data' => $updated_post ) );
811
		}
812 1
	}
813
814
	/**
815
	 * Is the field stored in a JSON-encoded manner?
816
	 *
817
	 * @param GF_Field $field
818
	 *
819
	 * @return bool True: stored in DB json_encode()'d; False: not encoded
820
	 */
821
	private function is_field_json_encoded( $field ) {
822
823
	    $json_encoded = false;
824
825
		$input_type = RGFormsModel::get_input_type( $field );
826
827
	    // Only certain custom field types are supported
828
	    switch( $input_type ) {
829
		    case 'fileupload':
830
		    case 'list':
831
		    case 'multiselect':
832
			    $json_encoded = true;
833
			    break;
834
	    }
835
836
	    return $json_encoded;
837
	}
838
839
	/**
840
	 * Convert a field content template into prepared output
841
	 *
842
	 * @uses GravityView_GFFormsModel::get_post_field_images()
843
	 *
844
	 * @since 1.17
845
	 *
846
	 * @param string $template The content template for the field
847
	 * @param array $form Gravity Forms form
848
	 * @param bool $do_shortcode Whether to process shortcode inside content. In GF, only run on Custom Field and Post Content fields
849
	 *
850
	 * @return string
851
	 */
852
	private function fill_post_template( $template, $form, $entry, $do_shortcode = false ) {
853
854
		require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
855
856
		$post_images = GravityView_GFFormsModel::get_post_field_images( $form, $entry );
857
858
		//replacing post image variables
859
		$output = GFCommon::replace_variables_post_image( $template, $post_images, $entry );
860
861
		//replacing all other variables
862
		$output = GFCommon::replace_variables( $output, $form, $entry, false, false, false );
863
864
		// replace conditional shortcodes
865
		if( $do_shortcode ) {
866
			$output = do_shortcode( $output );
867
		}
868
869
		return $output;
870
	}
871
872
873
	/**
874
	 * Perform actions normally performed after updating a lead
875
	 *
876
	 * @since 1.8
877
	 *
878
	 * @see GFEntryDetail::lead_detail_page()
879
	 *
880
	 * @return void
881
	 */
882 10
	private function after_update() {
883
884 10
		do_action( 'gform_after_update_entry', $this->form, $this->entry['id'], self::$original_entry );
885 10
		do_action( "gform_after_update_entry_{$this->form['id']}", $this->form, $this->entry['id'], self::$original_entry );
886
887
		// Re-define the entry now that we've updated it.
888 10
		$entry = RGFormsModel::get_lead( $this->entry['id'] );
889
890 10
		$entry = GFFormsModel::set_entry_meta( $entry, $this->form );
891
892 10
		if ( version_compare( GFFormsModel::get_database_version(), '2.3-dev-1', '<' ) ) {
893
			// We need to clear the cache because Gravity Forms caches the field values, which
894
			// we have just updated.
895
			foreach ($this->form['fields'] as $key => $field) {
0 ignored issues
show
introduced by
No space after opening parenthesis is prohibited
Loading history...
introduced by
No space before closing parenthesis is prohibited
Loading history...
896
				GFFormsModel::refresh_lead_field_value( $entry['id'], $field->id );
897
			}
898
		}
899
900 10
		$this->entry = $entry;
901 10
	}
902
903
904
	/**
905
	 * Display the Edit Entry form
906
	 *
907
	 * @return void
908
	 */
909 11
	public function edit_entry_form() {
910
911
		?>
912
913
		<div class="gv-edit-entry-wrapper"><?php
914
915 11
			$javascript = gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/inline-javascript.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
916
917
			/**
918
			 * Fixes weird wpautop() issue
919
			 * @see https://github.com/katzwebservices/GravityView/issues/451
920
			 */
921 11
			echo gravityview_strip_whitespace( $javascript );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'gravityview_strip_whitespace'
Loading history...
922
923
			?><h2 class="gv-edit-entry-title">
924
				<span><?php
925
926
				    /**
927
				     * @filter `gravityview_edit_entry_title` Modify the edit entry title
928
				     * @param string $edit_entry_title Modify the "Edit Entry" title
929
				     * @param GravityView_Edit_Entry_Render $this This object
930
				     */
931 11
				    $edit_entry_title = apply_filters('gravityview_edit_entry_title', __('Edit Entry', 'gravityview'), $this );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
932
933 11
				    echo esc_attr( $edit_entry_title );
934
			?></span>
935
			</h2>
936
937
			<?php $this->maybe_print_message(); ?>
938
939
			<?php // The ID of the form needs to be `gform_{form_id}` for the pluploader ?>
940
941
			<form method="post" id="gform_<?php echo $this->form_id; ?>" enctype="multipart/form-data">
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$this'
Loading history...
942
943
				<?php
944
945 11
				wp_nonce_field( self::$nonce_key, self::$nonce_key );
946
947 11
				wp_nonce_field( self::$nonce_field, self::$nonce_field, false );
948
949
				// Print the actual form HTML
950 11
				$this->render_edit_form();
951
952
				?>
953 11
			</form>
954
955
			<script>
956
				gform.addFilter('gform_reset_pre_conditional_logic_field_action', function ( reset, formId, targetId, defaultValues, isInit ) {
957
				    return false;
958
				});
959
			</script>
960
961
		</div>
962
963
	<?php
964 11
	}
965
966
	/**
967
	 * Display success or error message if the form has been submitted
968
	 *
969
	 * @uses GVCommon::generate_notice
970
	 *
971
	 * @since 1.16.2.2
972
	 *
973
	 * @return void
974
	 */
975 11
	private function maybe_print_message() {
976
977 11
		if ( \GV\Utils::_POST( 'action' ) === 'update' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
978
979 10
			$back_link = remove_query_arg( array( 'page', 'view', 'edit' ) );
980
981 10
			if( ! $this->is_valid ){
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
982
983
				// Keeping this compatible with Gravity Forms.
984
				$validation_message = "<div class='validation_error'>" . __('There was a problem with your submission.', 'gravityview') . " " . __('Errors have been highlighted below.', 'gravityview') . "</div>";
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw '__'
Loading history...
Coding Style Comprehensibility introduced by
The string literal </div> does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
985
				$message = apply_filters("gform_validation_message_{$this->form['id']}", apply_filters("gform_validation_message", $validation_message, $this->form), $this->form);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal gform_validation_message does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
986
987
				echo GVCommon::generate_notice( $message , 'gv-error' );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
988
989
			} else {
990 10
				$view = \GV\View::by_id( $this->view_id );
991 10
				$edit_redirect = $view->settings->get( 'edit_redirect' );
992
993 10
				if ( '0' === $edit_redirect ) {
994 1
					$redirect_url = $back_link;
995 1
					$entry_updated_message = sprintf( esc_attr__('Entry Updated. %sReturning to Entry%s', 'gravityview'), '<a href="'. esc_url( $redirect_url ) .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
996 9
				} else if ( '1' === $edit_redirect ) {
997 1
					$redirect_url = $directory_link = GravityView_API::directory_link();
998 1
					$entry_updated_message = sprintf( esc_attr__('Entry Updated. %sReturning to %s%s', 'gravityview'), '<a href="'. esc_url( $redirect_url ) . '">', esc_html( $view->post_title ), '</a>' );
0 ignored issues
show
Documentation introduced by
The property post_title does not exist on object<GV\View>. Since you implemented __get, maybe consider adding a @property annotation.

Since your code implements the magic getter _get, this function will be called for any read access on an undefined variable. You can add the @property annotation to your class or interface to document the existence of this variable.

<?php

/**
 * @property int $x
 * @property int $y
 * @property string $text
 */
class MyLabel
{
    private $properties;

    private $allowedProperties = array('x', 'y', 'text');

    public function __get($name)
    {
        if (isset($properties[$name]) && in_array($name, $this->allowedProperties)) {
            return $properties[$name];
        } else {
            return null;
        }
    }

    public function __set($name, $value)
    {
        if (in_array($name, $this->allowedProperties)) {
            $properties[$name] = $value;
        } else {
            throw new \LogicException("Property $name is not defined.");
        }
    }

}

If the property has read access only, you can use the @property-read annotation instead.

Of course, you may also just have mistyped another name, in which case you should fix the error.

See also the PhpDoc documentation for @property.

Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
999 8
				} else if ( '' == $edit_redirect ) {
1000 7
					$entry_updated_message = sprintf( esc_attr__('Entry Updated. %sReturn to Entry%s', 'gravityview'), '<a href="'. esc_url( $back_link ) .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1001
				} else {
1002 1
					$redirect_url = $edit_redirect;
1003 1
					$entry_updated_message = sprintf( esc_attr__('Entry Updated. %sRedirecting to %s%s', 'gravityview'), '<a href="'. esc_url( $redirect_url ) . '">', esc_html( $edit_redirect ), '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1004
				}
1005
1006 10
				if ( isset( $redirect_url ) ) {
1007 3
					$entry_updated_message .= sprintf( '<script type="text/javascript">window.location.href = %s;</script>', json_encode( $redirect_url ) );
1008
				}
1009
1010
				/**
1011
				 * @filter `gravityview/edit_entry/success` Modify the edit entry success message (including the anchor link)
1012
				 * @since 1.5.4
1013
				 * @param string $entry_updated_message Existing message
1014
				 * @param int $view_id View ID
1015
				 * @param array $entry Gravity Forms entry array
1016
				 * @param string $back_link URL to return to the original entry. @since 1.6
1017
				 */
1018 10
				$message = apply_filters( 'gravityview/edit_entry/success', $entry_updated_message , $this->view_id, $this->entry, $back_link );
1019
1020 10
				echo GVCommon::generate_notice( $message );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
1021
			}
1022
1023
		}
1024 11
	}
1025
1026
	/**
1027
	 * Display the Edit Entry form in the original Gravity Forms format
1028
	 *
1029
	 * @since 1.9
1030
	 *
1031
	 * @return void
1032
	 */
1033 11
	private function render_edit_form() {
1034
1035
		/**
1036
		 * @action `gravityview/edit-entry/render/before` Before rendering the Edit Entry form
1037
		 * @since 1.17
1038
		 * @param GravityView_Edit_Entry_Render $this
1039
		 */
1040 11
		do_action( 'gravityview/edit-entry/render/before', $this );
1041
1042 11
		add_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields'), 5000, 3 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
1043 11
		add_filter( 'gform_submit_button', array( $this, 'render_form_buttons') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
1044 11
		add_filter( 'gform_disable_view_counter', '__return_true' );
1045
1046 11
		add_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5, 5 );
1047 11
		add_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10, 5 );
1048
1049
		// We need to remove the fake $_GET['page'] arg to avoid rendering form as if in admin.
1050 11
		unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
1051
1052
		// TODO: Verify multiple-page forms
1053
1054 11
		ob_start(); // Prevent PHP warnings possibly caused by prefilling list fields for conditional logic
1055
1056 11
		$html = GFFormDisplay::get_form( $this->form['id'], false, false, true, $this->entry );
1057
1058 11
		ob_get_clean();
1059
1060 11
	    remove_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields' ), 5000 );
1061 11
		remove_filter( 'gform_submit_button', array( $this, 'render_form_buttons' ) );
1062 11
		remove_filter( 'gform_disable_view_counter', '__return_true' );
1063 11
		remove_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5 );
1064 11
		remove_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10 );
1065
1066 11
		echo $html;
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$html'
Loading history...
1067
1068
		/**
1069
		 * @action `gravityview/edit-entry/render/after` After rendering the Edit Entry form
1070
		 * @since 1.17
1071
		 * @param GravityView_Edit_Entry_Render $this
1072
		 */
1073 11
		do_action( 'gravityview/edit-entry/render/after', $this );
1074 11
	}
1075
1076
	/**
1077
	 * Display the Update/Cancel/Delete buttons for the Edit Entry form
1078
	 * @since 1.8
1079
	 * @return string
1080
	 */
1081 11
	public function render_form_buttons() {
1082 11
		return gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/form-buttons.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
1083
	}
1084
1085
1086
	/**
1087
	 * Modify the form fields that are shown when using GFFormDisplay::get_form()
1088
	 *
1089
	 * By default, all fields will be shown. We only want the Edit Tab configured fields to be shown.
1090
	 *
1091
	 * @param array $form
1092
	 * @param boolean $ajax Whether in AJAX mode
1093
	 * @param array|string $field_values Passed parameters to the form
1094
	 *
1095
	 * @since 1.9
1096
	 *
1097
	 * @return array Modified form array
1098
	 */
1099 11
	public function filter_modify_form_fields( $form, $ajax = false, $field_values = '' ) {
0 ignored issues
show
Unused Code introduced by
The parameter $ajax is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $field_values is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1100
1101
		// In case we have validated the form, use it to inject the validation results into the form render
1102 11
		if( isset( $this->form_after_validation ) ) {
1103 10
			$form = $this->form_after_validation;
1104
		} else {
1105 4
			$form['fields'] = $this->get_configured_edit_fields( $form, $this->view_id );
1106
		}
1107
1108 11
		$form = $this->filter_conditional_logic( $form );
1109
1110 11
		$form = $this->prefill_conditional_logic( $form );
1111
1112
		// for now we don't support Save and Continue feature.
1113 11
		if( ! self::$supports_save_and_continue ) {
1114 11
	        unset( $form['save'] );
1115
		}
1116
1117 11
		$form = $this->unselect_default_values( $form );
1118
1119 11
		return $form;
1120
	}
1121
1122
	/**
1123
	 * When displaying a field, check if it's a Post Field, and if so, make sure the post exists and current user has edit rights.
1124
	 *
1125
	 * @since 1.16.2.2
1126
	 *
1127
	 * @param string $field_content Always empty. Returning not-empty overrides the input.
1128
	 * @param GF_Field $field
1129
	 * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1130
	 * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1131
	 * @param int $form_id Form ID
1132
	 *
1133
	 * @return string If error, the error message. If no error, blank string (modify_edit_field_input() runs next)
1134
	 */
1135 11
	public function verify_user_can_edit_post( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1136
1137 11
		if( ! GFCommon::is_post_field( $field ) ) {
1138 11
			return $field_content;
1139
		}
1140
1141 2
        $message = null;
1142
1143
        // First, make sure they have the capability to edit the post.
1144 2
        if( false === current_user_can( 'edit_post', $this->entry['post_id'] ) ) {
1145
1146
            /**
1147
             * @filter `gravityview/edit_entry/unsupported_post_field_text` Modify the message when someone isn't able to edit a post
1148
             * @param string $message The existing "You don't have permission..." text
1149
             */
1150 1
            $message = apply_filters('gravityview/edit_entry/unsupported_post_field_text', __('You don&rsquo;t have permission to edit this post.', 'gravityview') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1151
1152 1
        } elseif( null === get_post( $this->entry['post_id'] ) ) {
1153
            /**
1154
             * @filter `gravityview/edit_entry/no_post_text` Modify the message when someone is editing an entry attached to a post that no longer exists
1155
             * @param string $message The existing "This field is not editable; the post no longer exists." text
1156
             */
1157
            $message = apply_filters('gravityview/edit_entry/no_post_text', __('This field is not editable; the post no longer exists.', 'gravityview' ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1158
        }
1159
1160 2
        if( $message ) {
1161 1
            $field_content = sprintf('<div class="ginput_container ginput_container_' . $field->type . '">%s</div>', wpautop( $message ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1162
        }
1163
1164 2
        return $field_content;
1165
	}
1166
1167
	/**
1168
	 *
1169
	 * Fill-in the saved values into the form inputs
1170
	 *
1171
	 * @param string $field_content Always empty. Returning not-empty overrides the input.
1172
	 * @param GF_Field $field
1173
	 * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1174
	 * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1175
	 * @param int $form_id Form ID
1176
	 *
1177
	 * @return mixed
1178
	 */
1179 11
	public function modify_edit_field_input( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1180
1181 11
		$gv_field = GravityView_Fields::get_associated_field( $field );
1182
1183
		// If the form has been submitted, then we don't need to pre-fill the values,
1184
		// Except for fileupload type and when a field input is overridden- run always!!
1185
		if(
1186 11
			( $this->is_edit_entry_submission() && !in_array( $field->type, array( 'fileupload', 'post_image' ) ) )
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1187 11
			&& false === ( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) )
1188
			&& ! GFCommon::is_product_field( $field->type )
1189 11
			|| ! empty( $field_content )
1190 11
			|| in_array( $field->type, array( 'honeypot' ) )
1191
		) {
1192 1
	        return $field_content;
1193
		}
1194
1195
		// SET SOME FIELD DEFAULTS TO PREVENT ISSUES
1196 11
		$field->adminOnly = false; /** @see GFFormDisplay::get_counter_init_script() need to prevent adminOnly */
1197
1198 11
		$field_value = $this->get_field_value( $field );
1199
1200
	    // Prevent any PHP warnings, like undefined index
1201 11
	    ob_start();
1202
1203 11
	    $return = null;
1204
1205
		/** @var GravityView_Field $gv_field */
1206 11
		if( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) ) {
1207 3
			$return = $gv_field->get_field_input( $this->form, $field_value, $this->entry, $field );
1208
		} else {
1209 11
	        $return = $field->get_field_input( $this->form, $field_value, $this->entry );
1210
	    }
1211
1212
	    // If there was output, it's an error
1213 11
	    $warnings = ob_get_clean();
1214
1215 11
	    if( !empty( $warnings ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1216
		    gravityview()->log->error( '{warning}', array( 'warning' => $warnings, 'data' => $field_value ) );
1217
	    }
1218
1219 11
		return $return;
1220
	}
1221
1222
	/**
1223
	 * Modify the value for the current field input
1224
	 *
1225
	 * @param GF_Field $field
1226
	 *
1227
	 * @return array|mixed|string
1228
	 */
1229 11
	private function get_field_value( $field ) {
1230
1231
		/**
1232
		 * @filter `gravityview/edit_entry/pre_populate/override` Allow the pre-populated value to override saved value in Edit Entry form. By default, pre-populate mechanism only kicks on empty fields.
1233
		 * @param boolean True: override saved values; False: don't override (default)
1234
		 * @param $field GF_Field object Gravity Forms field object
1235
		 * @since 1.13
1236
		 */
1237 11
		$override_saved_value = apply_filters( 'gravityview/edit_entry/pre_populate/override', false, $field );
1238
1239
		// We're dealing with multiple inputs (e.g. checkbox) but not time or date (as it doesn't store data in input IDs)
1240 11
		if( isset( $field->inputs ) && is_array( $field->inputs ) && !in_array( $field->type, array( 'time', 'date' ) ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1241
1242 3
			$field_value = array();
1243
1244
			// only accept pre-populated values if the field doesn't have any choice selected.
1245 3
			$allow_pre_populated = $field->allowsPrepopulate;
1246
1247 3
			foreach ( (array)$field->inputs as $input ) {
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1248
1249 3
				$input_id = strval( $input['id'] );
1250
				
1251 3
				if ( isset( $this->entry[ $input_id ] ) && ! gv_empty( $this->entry[ $input_id ], false, false ) ) {
1252 3
				    $field_value[ $input_id ] =  'post_category' === $field->type ? GFCommon::format_post_category( $this->entry[ $input_id ], true ) : $this->entry[ $input_id ];
0 ignored issues
show
introduced by
Expected 1 space after "="; 2 found
Loading history...
1253 3
				    $allow_pre_populated = false;
1254
				}
1255
1256
			}
1257
1258 3
			$pre_value = $field->get_value_submission( array(), false );
1259
1260 3
			$field_value = ! $allow_pre_populated && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $field_value : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1261
1262
		} else {
1263
1264 11
			$id = intval( $field->id );
1265
1266
			// get pre-populated value if exists
1267 11
			$pre_value = $field->allowsPrepopulate ? GFFormsModel::get_parameter_value( $field->inputName, array(), $field ) : '';
1268
1269
			// saved field entry value (if empty, fallback to the pre-populated value, if exists)
1270
			// or pre-populated value if not empty and set to override saved value
1271 11
			$field_value = isset( $this->entry[ $id ] ) && ! gv_empty( $this->entry[ $id ], false, false ) && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $this->entry[ $id ] : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1272
1273
			// in case field is post_category but inputType is select, multi-select or radio, convert value into array of category IDs.
1274 11
			if ( 'post_category' === $field->type && !gv_empty( $field_value, false, false ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1275
				$categories = array();
1276
				foreach ( explode( ',', $field_value ) as $cat_string ) {
1277
				    $categories[] = GFCommon::format_post_category( $cat_string, true );
1278
				}
1279
				$field_value = 'multiselect' === $field->get_input_type() ? $categories : implode( '', $categories );
1280
			}
1281
1282
		}
1283
1284
		// if value is empty get the default value if defined
1285 11
		$field_value = $field->get_value_default_if_empty( $field_value );
1286
1287
	    /**
1288
	     * @filter `gravityview/edit_entry/field_value` Change the value of an Edit Entry field, if needed
1289
	     * @since 1.11
1290
	     * @since 1.20 Added third param
1291
	     * @param mixed $field_value field value used to populate the input
1292
	     * @param object $field Gravity Forms field object ( Class GF_Field )
1293
	     * @param GravityView_Edit_Entry_Render $this Current object
1294
	     */
1295 11
	    $field_value = apply_filters( 'gravityview/edit_entry/field_value', $field_value, $field, $this );
1296
1297
	    /**
1298
	     * @filter `gravityview/edit_entry/field_value_{field_type}` Change the value of an Edit Entry field for a specific field type
1299
	     * @since 1.17
1300
	     * @since 1.20 Added third param
1301
	     * @param mixed $field_value field value used to populate the input
1302
	     * @param GF_Field $field Gravity Forms field object
1303
	     * @param GravityView_Edit_Entry_Render $this Current object
1304
	     */
1305 11
	    $field_value = apply_filters( 'gravityview/edit_entry/field_value_' . $field->type , $field_value, $field, $this );
1306
1307 11
		return $field_value;
1308
	}
1309
1310
1311
	// ---- Entry validation
1312
1313
	/**
1314
	 * Add field keys that Gravity Forms expects.
1315
	 *
1316
	 * @see GFFormDisplay::validate()
1317
	 * @param  array $form GF Form
1318
	 * @return array       Modified GF Form
1319
	 */
1320 10
	public function gform_pre_validation( $form ) {
1321
1322 10
		if( ! $this->verify_nonce() ) {
1323
			return $form;
1324
		}
1325
1326
		// Fix PHP warning regarding undefined index.
1327 10
		foreach ( $form['fields'] as &$field) {
0 ignored issues
show
introduced by
No space before closing parenthesis is prohibited
Loading history...
1328
1329
			// This is because we're doing admin form pretending to be front-end, so Gravity Forms
1330
			// expects certain field array items to be set.
1331 10
			foreach ( array( 'noDuplicates', 'adminOnly', 'inputType', 'isRequired', 'enablePrice', 'inputs', 'allowedExtensions' ) as $key ) {
1332 10
	            $field->{$key} = isset( $field->{$key} ) ? $field->{$key} : NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1333
			}
1334
1335 10
			switch( RGFormsModel::get_input_type( $field ) ) {
1336
1337
				/**
1338
				 * this whole fileupload hack is because in the admin, Gravity Forms simply doesn't update any fileupload field if it's empty, but it DOES in the frontend.
1339
				 *
1340
				 * What we have to do is set the value so that it doesn't get overwritten as empty on save and appears immediately in the Edit Entry screen again.
1341
				 *
1342
				 * @hack
1343
				 */
1344 10
				case 'fileupload':
1345
1346
				    // Set the previous value
1347 1
				    $entry = $this->get_entry();
1348
1349 1
				    $input_name = 'input_'.$field->id;
1350 1
				    $form_id = $form['id'];
1351
1352 1
				    $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1353
1354
				    // Use the previous entry value as the default.
1355 1
				    if( isset( $entry[ $field->id ] ) ) {
1356 1
				        $value = $entry[ $field->id ];
1357
				    }
1358
1359
				    // If this is a single upload file
1360 1
				    if( !empty( $_FILES[ $input_name ] ) && !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1361 1
				        $file_path = GFFormsModel::get_file_upload_path( $form['id'], $_FILES[ $input_name ]['name'] );
1362 1
				        $value = $file_path['url'];
1363
1364
				    } else {
1365
1366
				        // Fix PHP warning on line 1498 of form_display.php for post_image fields
1367
				        // Fix PHP Notice:  Undefined index:  size in form_display.php on line 1511
1368 1
				        $_FILES[ $input_name ] = array('name' => '', 'size' => '' );
0 ignored issues
show
introduced by
No space after opening parenthesis of array is bad style
Loading history...
1369
1370
				    }
1371
1372 1
				    if ( \GV\Utils::get( $field, "multipleFiles" ) ) {
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal multipleFiles does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1373
1374
				        // If there are fresh uploads, process and merge them.
1375
				        // Otherwise, use the passed values, which should be json-encoded array of URLs
1376 1
				        if( isset( GFFormsModel::$uploaded_files[$form_id][$input_name] ) ) {
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1377
				            $value = empty( $value ) ? '[]' : $value;
1378
				            $value = stripslashes_deep( $value );
1379 1
				            $value = GFFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'], array());
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1380
				        }
1381
1382
				    } else {
1383
1384
				        // A file already exists when editing an entry
1385
				        // We set this to solve issue when file upload fields are required.
1386 1
				        GFFormsModel::$uploaded_files[ $form_id ][ $input_name ] = $value;
1387
1388
				    }
1389
1390 1
				    $this->entry[ $input_name ] = $value;
1391 1
				    $_POST[ $input_name ] = $value;
1392
1393 1
				    break;
1394
1395 10
				case 'number':
1396
				    // Fix "undefined index" issue at line 1286 in form_display.php
1397 8
				    if( !isset( $_POST['input_'.$field->id ] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1398 5
				        $_POST['input_'.$field->id ] = NULL;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1399
				    }
1400 10
				    break;
1401
			}
1402
1403
		}
1404
1405 10
		return $form;
1406
	}
1407
1408
1409
	/**
1410
	 * Process validation for a edit entry submission
1411
	 *
1412
	 * Sets the `is_valid` object var
1413
	 *
1414
	 * @return void
1415
	 */
1416 11
	private function validate() {
1417
1418
		/**
1419
		 * If using GF User Registration Add-on, remove the validation step, otherwise generates error when updating the entry
1420
		 * GF User Registration Add-on version > 3.x has a different class name
1421
		 * @since 1.16.2
1422
		 */
1423 11
		if ( class_exists( 'GF_User_Registration' ) ) {
1424 11
			remove_filter( 'gform_validation', array( GF_User_Registration::get_instance(), 'validate' ) );
1425
		} else  if ( class_exists( 'GFUser' ) ) {
1426
			remove_filter( 'gform_validation', array( 'GFUser', 'user_registration_validation' ) );
1427
		}
1428
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1429
1430
		/**
1431
		 * For some crazy reason, Gravity Forms doesn't validate Edit Entry form submissions.
1432
		 * You can enter whatever you want!
1433
		 * We try validating, and customize the results using `self::custom_validation()`
1434
		 */
1435 11
		add_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10, 4);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1436
1437
		// Needed by the validate funtion
1438 11
		$failed_validation_page = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1439 11
		$field_values = RGForms::post( 'gform_field_values' );
1440
1441
		// Prevent entry limit from running when editing an entry, also
1442
		// prevent form scheduling from preventing editing
1443 11
		unset( $this->form['limitEntries'], $this->form['scheduleForm'] );
1444
1445
		// Hide fields depending on Edit Entry settings
1446 11
		$this->form['fields'] = $this->get_configured_edit_fields( $this->form, $this->view_id );
1447
1448 11
		$this->is_valid = GFFormDisplay::validate( $this->form, $field_values, 1, $failed_validation_page );
1449
1450 11
		remove_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10 );
1451 11
	}
1452
1453
1454
	/**
1455
	 * Make validation work for Edit Entry
1456
	 *
1457
	 * Because we're calling the GFFormDisplay::validate() in an unusual way (as a front-end
1458
	 * form pretending to be a back-end form), validate() doesn't know we _can't_ edit post
1459
	 * fields. This goes through all the fields and if they're an invalid post field, we
1460
	 * set them as valid. If there are still issues, we'll return false.
1461
	 *
1462
	 * @param  [type] $validation_results [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1463
	 * @return [type]                     [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1464
	 */
1465 11
	public function custom_validation( $validation_results ) {
1466
1467 11
		gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Validation results: ', array( 'data' => $validation_results ) );
1468
1469 11
		gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] $_POSTed data (sanitized): ', array( 'data' => esc_html( print_r( $_POST, true ) ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
1470
1471 11
		$gv_valid = true;
1472
1473 11
		foreach ( $validation_results['form']['fields'] as $key => &$field ) {
1474
1475 11
			$value = RGFormsModel::get_field_value( $field );
1476 11
			$field_type = RGFormsModel::get_input_type( $field );
1477
1478
			// Validate always
1479 11
			switch ( $field_type ) {
1480
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1481
1482 11
				case 'fileupload' :
1483 11
				case 'post_image':
1484
1485
				    // in case nothing is uploaded but there are already files saved
1486 2
				    if( !empty( $field->failed_validation ) && !empty( $field->isRequired ) && !empty( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1487
				        $field->failed_validation = false;
1488
				        unset( $field->validation_message );
1489
				    }
1490
1491
				    // validate if multi file upload reached max number of files [maxFiles] => 2
1492 2
				    if( \GV\Utils::get( $field, 'maxFiles') && \GV\Utils::get( $field, 'multipleFiles') ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1493
1494
				        $input_name = 'input_' . $field->id;
1495
				        //uploaded
1496
				        $file_names = isset( GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] ) ? GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] : array();
1497
1498
				        //existent
1499
				        $entry = $this->get_entry();
1500
				        $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1501
				        if( isset( $entry[ $field->id ] ) ) {
1502
				            $value = json_decode( $entry[ $field->id ], true );
1503
				        }
1504
1505
				        // count uploaded files and existent entry files
1506
				        $count_files = count( $file_names ) + count( $value );
1507
1508
				        if( $count_files > $field->maxFiles ) {
1509
				            $field->validation_message = __( 'Maximum number of files reached', 'gravityview' );
1510
				            $field->failed_validation = 1;
1511
				            $gv_valid = false;
1512
1513
				            // in case of error make sure the newest upload files are removed from the upload input
1514
				            GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ] = null;
1515
				        }
1516
1517
				    }
1518
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1519
1520 2
				    break;
1521
1522
			}
1523
1524
			// This field has failed validation.
1525 11
			if( !empty( $field->failed_validation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1526
1527 1
				gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Field is invalid.', array( 'data' => array( 'field' => $field, 'value' => $value ) ) );
1528
1529 1
				switch ( $field_type ) {
1530
1531
				    // Captchas don't need to be re-entered.
1532 1
				    case 'captcha':
1533
1534
				        // Post Image fields aren't editable, so we un-fail them.
1535 1
				    case 'post_image':
1536
				        $field->failed_validation = false;
1537
				        unset( $field->validation_message );
1538
				        break;
1539
1540
				}
1541
1542
				// You can't continue inside a switch, so we do it after.
1543 1
				if( empty( $field->failed_validation ) ) {
1544
				    continue;
1545
				}
1546
1547
				// checks if the No Duplicates option is not validating entry against itself, since
1548
				// we're editing a stored entry, it would also assume it's a duplicate.
1549 1
				if( !empty( $field->noDuplicates ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1550
1551
				    $entry = $this->get_entry();
1552
1553
				    // If the value of the entry is the same as the stored value
1554
				    // Then we can assume it's not a duplicate, it's the same.
1555
				    if( !empty( $entry ) && $value == $entry[ $field->id ] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1556
				        //if value submitted was not changed, then don't validate
1557
				        $field->failed_validation = false;
1558
1559
				        unset( $field->validation_message );
1560
1561
				        gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Field not a duplicate; it is the same entry.', array( 'data' => $entry ) );
1562
1563
				        continue;
1564
				    }
1565
				}
1566
1567
				// if here then probably we are facing the validation 'At least one field must be filled out'
1568 1
				if( GFFormDisplay::is_empty( $field, $this->form_id  ) && empty( $field->isRequired ) ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 2 found
Loading history...
1569
				    unset( $field->validation_message );
1570
	                $field->validation_message = false;
1571
				    continue;
1572
				}
1573
1574 11
				$gv_valid = false;
1575
1576
			}
1577
1578
		}
1579
1580 11
		$validation_results['is_valid'] = $gv_valid;
1581
1582 11
		gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Validation results.', array( 'data' => $validation_results ) );
1583
1584
		// We'll need this result when rendering the form ( on GFFormDisplay::get_form )
1585 11
		$this->form_after_validation = $validation_results['form'];
1586
1587 11
		return $validation_results;
1588
	}
1589
1590
1591
	/**
1592
	 * TODO: This seems to be hacky... we should remove it. Entry is set when updating the form using setup_vars()!
1593
	 * Get the current entry and set it if it's not yet set.
1594
	 * @return array Gravity Forms entry array
1595
	 */
1596 2
	public function get_entry() {
1597
1598 2
		if( empty( $this->entry ) ) {
1599
			// Get the database value of the entry that's being edited
1600 1
			$this->entry = gravityview_get_entry( GravityView_frontend::is_single_entry() );
1601
		}
1602
1603 2
		return $this->entry;
1604
	}
1605
1606
1607
1608
	// --- Filters
1609
1610
	/**
1611
	 * Get the Edit Entry fields as configured in the View
1612
	 *
1613
	 * @since 1.8
1614
	 *
1615
	 * @param int $view_id
1616
	 *
1617
	 * @return array Array of fields that are configured in the Edit tab in the Admin
1618
	 */
1619 12
	private function get_configured_edit_fields( $form, $view_id ) {
1620
1621
		// Get all fields for form
1622 12
		if ( \GV\View::exists( $view_id ) ) {
1623 12
			$view = \GV\View::by_id( $view_id );
1624 12
			$properties = $view->fields ? $view->fields->as_configuration() : array();
1625
		} else {
1626
			$properties = null;
1627
		}
1628
1629
		// If edit tab not yet configured, show all fields
1630 12
		$edit_fields = !empty( $properties['edit_edit-fields'] ) ? $properties['edit_edit-fields'] : NULL;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1631
1632
		// Hide fields depending on admin settings
1633 12
		$fields = $this->filter_fields( $form['fields'], $edit_fields );
1634
1635
	    // If Edit Entry fields are configured, remove adminOnly field settings. Otherwise, don't.
1636 12
	    $fields = $this->filter_admin_only_fields( $fields, $edit_fields, $form, $view_id );
1637
1638
		/**
1639
		 * @filter `gravityview/edit_entry/form_fields` Modify the fields displayed in Edit Entry form
1640
		 * @since 1.17
1641
		 * @param GF_Field[] $fields Gravity Forms form fields
1642
		 * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1643
		 * @param array $form GF Form array (`fields` key modified to have only fields configured to show in Edit Entry)
1644
		 * @param int $view_id View ID
1645
		 */
1646 12
		$fields = apply_filters( 'gravityview/edit_entry/form_fields', $fields, $edit_fields, $form, $view_id );
1647
1648 12
		return $fields;
1649
	}
1650
1651
1652
	/**
1653
	 * Filter area fields based on specified conditions
1654
	 *  - This filter removes the fields that have calculation configured
1655
	 *
1656
	 * @uses GravityView_Edit_Entry::user_can_edit_field() Check caps
1657
	 * @access private
1658
	 * @param GF_Field[] $fields
1659
	 * @param array $configured_fields
1660
	 * @since  1.5
1661
	 * @return array $fields
1662
	 */
1663 11
	private function filter_fields( $fields, $configured_fields ) {
1664
1665 11
		if( empty( $fields ) || !is_array( $fields ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1666
			return $fields;
1667
		}
1668
1669 11
		$edit_fields = array();
1670
1671 11
		$field_type_blacklist = $this->loader->get_field_blacklist( $this->entry );
1672
1673
		// First, remove blacklist or calculation fields
1674 11
		foreach ( $fields as $key => $field ) {
1675
1676
			// Remove the fields that have calculation properties and keep them to be used later
1677
			// @since 1.16.2
1678 11
			if( $field->has_calculation() ) {
1679 3
				$this->fields_with_calculation[] = $field;
1680
				// don't remove the calculation fields on form render.
1681
			}
1682
1683 11
			if( in_array( $field->type, $field_type_blacklist ) ) {
1684 11
				unset( $fields[ $key ] );
1685
			}
1686
		}
1687
1688
		// The Edit tab has not been configured, so we return all fields by default.
1689 11
		if( empty( $configured_fields ) ) {
1690 11
			return array_values( $fields );
1691
		}
1692
1693
		// The edit tab has been configured, so we loop through to configured settings
1694
		foreach ( $configured_fields as $configured_field ) {
1695
1696
	        /** @var GF_Field $field */
1697
	        foreach ( $fields as $field ) {
1698
				if( intval( $configured_field['id'] ) === intval( $field->id ) && $this->user_can_edit_field( $configured_field, false ) ) {
1699
				    $edit_fields[] = $this->merge_field_properties( $field, $configured_field );
1700
				    break;
1701
				}
1702
1703
			}
1704
1705
		}
1706
1707
		return $edit_fields;
1708
1709
	}
1710
1711
	/**
1712
	 * Override GF Form field properties with the ones defined on the View
1713
	 * @param  GF_Field $field GF Form field object
1714
	 * @param  array $field_setting  GV field options
1715
	 * @since  1.5
1716
	 * @return array|GF_Field
1717
	 */
1718
	private function merge_field_properties( $field, $field_setting ) {
1719
1720
		$return_field = $field;
1721
1722
		if( empty( $field_setting['show_label'] ) ) {
1723
			$return_field->label = '';
1724
		} elseif ( !empty( $field_setting['custom_label'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1725
			$return_field->label = $field_setting['custom_label'];
1726
		}
1727
1728
		if( !empty( $field_setting['custom_class'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1729
			$return_field->cssClass .= ' '. gravityview_sanitize_html_class( $field_setting['custom_class'] );
1730
		}
1731
1732
		/**
1733
		 * Normalize page numbers - avoid conflicts with page validation
1734
		 * @since 1.6
1735
		 */
1736
		$return_field->pageNumber = 1;
1737
1738
		return $return_field;
1739
1740
	}
1741
1742
	/**
1743
	 * Remove fields that shouldn't be visible based on the Gravity Forms adminOnly field property
1744
	 *
1745
	 * @since 1.9.1
1746
	 *
1747
	 * @param array|GF_Field[] $fields Gravity Forms form fields
1748
	 * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1749
	 * @param array $form GF Form array
1750
	 * @param int $view_id View ID
1751
	 *
1752
	 * @return array Possibly modified form array
1753
	 */
1754 11
	private function filter_admin_only_fields( $fields = array(), $edit_fields = null, $form = array(), $view_id = 0 ) {
1755
1756
	    /**
1757
		 * @filter `gravityview/edit_entry/use_gf_admin_only_setting` When Edit tab isn't configured, should the Gravity Forms "Admin Only" field settings be used to control field display to non-admins? Default: true
1758
	     * If the Edit Entry tab is not configured, adminOnly fields will not be shown to non-administrators.
1759
	     * If the Edit Entry tab *is* configured, adminOnly fields will be shown to non-administrators, using the configured GV permissions
1760
	     * @since 1.9.1
1761
	     * @param boolean $use_gf_adminonly_setting True: Hide field if set to Admin Only in GF and the user is not an admin. False: show field based on GV permissions, ignoring GF permissions.
1762
	     * @param array $form GF Form array
1763
	     * @param int $view_id View ID
1764
	     */
1765 11
	    $use_gf_adminonly_setting = apply_filters( 'gravityview/edit_entry/use_gf_admin_only_setting', empty( $edit_fields ), $form, $view_id );
1766
1767 11
	    if( $use_gf_adminonly_setting && false === GVCommon::has_cap( 'gravityforms_edit_entries', $this->entry['id'] ) ) {
1768
			foreach( $fields as $k => $field ) {
1769
				if( $field->adminOnly ) {
1770
				    unset( $fields[ $k ] );
1771
				}
1772
			}
1773
			return array_values( $fields );
1774
		}
1775
1776 11
	    foreach( $fields as &$field ) {
1777 11
		    $field->adminOnly = false;
1778
		}
1779
1780 11
		return $fields;
1781
	}
1782
1783
	/**
1784
	 * Checkboxes and other checkbox-based controls should not
1785
	 * display default checks in edit mode.
1786
	 *
1787
	 * https://github.com/gravityview/GravityView/1149
1788
	 *
1789
	 * @since 2.1
1790
	 *
1791
	 * @param array $form Gravity Forms array object
1792
	 *
1793
	 * @return array $form, modified to default checkboxes, radios from showing up.
1794
	 */
1795 11
	private function unselect_default_values( $form ) {
1796
1797 11
	    foreach ( $form['fields'] as &$field ) {
1798
1799 11
			if ( empty( $field->choices ) ) {
1800 11
                continue;
1801
			}
1802
1803 2
            foreach ( $field->choices as &$choice ) {
1804 2
				if ( \GV\Utils::get( $choice, 'isSelected' ) ) {
1805 2
					$choice['isSelected'] = false;
1806
				}
1807
			}
1808
		}
1809
1810 11
		return $form;
1811
	}
1812
1813
	// --- Conditional Logic
1814
1815
	/**
1816
	 * Conditional logic isn't designed to work with forms that already have content. When switching input values,
1817
	 * the dependent fields will be blank.
1818
	 *
1819
	 * Note: This is because GF populates a JavaScript variable with the input values. This is tough to filter at the input level;
1820
	 * via the `gform_field_value` filter; it requires lots of legwork. Doing it at the form level is easier.
1821
	 *
1822
	 * @since 1.17.4
1823
	 *
1824
	 * @param array $form Gravity Forms array object
1825
	 *
1826
	 * @return array $form, modified to fix conditional
1827
	 */
1828 11
	function prefill_conditional_logic( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1829
1830 11
		if( ! GFFormDisplay::has_conditional_logic( $form ) ) {
1831 11
			return $form;
1832
		}
1833
1834
		// Have Conditional Logic pre-fill fields as if the data were default values
1835
		/** @var GF_Field $field */
1836
		foreach ( $form['fields'] as &$field ) {
1837
1838
			if( 'checkbox' === $field->type ) {
1839
				foreach ( $field->get_entry_inputs() as $key => $input ) {
1840
				    $input_id = $input['id'];
1841
				    $choice = $field->choices[ $key ];
1842
				    $value = \GV\Utils::get( $this->entry, $input_id );
1843
				    $match = RGFormsModel::choice_value_match( $field, $choice, $value );
1844
				    if( $match ) {
1845
				        $field->choices[ $key ]['isSelected'] = true;
1846
				    }
1847
				}
1848
			} else {
1849
1850
				// We need to run through each field to set the default values
1851
				foreach ( $this->entry as $field_id => $field_value ) {
1852
1853
				    if( floatval( $field_id ) === floatval( $field->id ) ) {
1854
1855
				        if( 'list' === $field->type ) {
1856
				            $list_rows = maybe_unserialize( $field_value );
1857
1858
				            $list_field_value = array();
1859
				            foreach ( (array) $list_rows as $row ) {
1860
				                foreach ( (array) $row as $column ) {
1861
				                    $list_field_value[] = $column;
1862
				                }
1863
				            }
1864
1865
				            $field->defaultValue = serialize( $list_field_value );
1866
				        } else {
1867
				            $field->defaultValue = $field_value;
1868
				        }
1869
				    }
1870
				}
1871
			}
1872
		}
1873
1874
		return $form;
1875
	}
1876
1877
	/**
1878
	 * Remove the conditional logic rules from the form button and the form fields, if needed.
1879
	 *
1880
	 * @todo Merge with caller method
1881
	 * @since 1.9
1882
	 *
1883
	 * @param array $form Gravity Forms form
1884
	 * @return array Modified form, if not using Conditional Logic
1885
	 */
1886 11
	private function filter_conditional_logic( $form ) {
1887
1888
		/**
1889
		 * @filter `gravityview/edit_entry/conditional_logic` Should the Edit Entry form use Gravity Forms conditional logic showing/hiding of fields?
1890
		 * @since 1.9
1891
		 * @param bool $use_conditional_logic True: Gravity Forms will show/hide fields just like in the original form; False: conditional logic will be disabled and fields will be shown based on configuration. Default: true
1892
		 * @param array $form Gravity Forms form
1893
		 */
1894 11
		$use_conditional_logic = apply_filters( 'gravityview/edit_entry/conditional_logic', true, $form );
1895
1896 11
		if( $use_conditional_logic ) {
1897 11
			return $form;
1898
		}
1899
1900
		foreach( $form['fields'] as &$field ) {
1901
			/* @var GF_Field $field */
1902
			$field->conditionalLogic = null;
1903
		}
1904
1905
		unset( $form['button']['conditionalLogic'] );
1906
1907
		return $form;
1908
1909
	}
1910
1911
	/**
1912
	 * Disable the Gravity Forms conditional logic script and features on the Edit Entry screen
1913
	 *
1914
	 * @since 1.9
1915
	 *
1916
	 * @param $has_conditional_logic
1917
	 * @param $form
1918
	 * @return mixed
1919
	 */
1920 11
	public function manage_conditional_logic( $has_conditional_logic, $form ) {
1921
1922 11
		if( ! $this->is_edit_entry() ) {
1923
			return $has_conditional_logic;
1924
		}
1925
1926
	    /** @see GravityView_Edit_Entry_Render::filter_conditional_logic for filter documentation */
1927 11
		return apply_filters( 'gravityview/edit_entry/conditional_logic', $has_conditional_logic, $form );
1928
	}
1929
1930
1931
	// --- User checks and nonces
1932
1933
	/**
1934
	 * Check if the user can edit the entry
1935
	 *
1936
	 * - Is the nonce valid?
1937
	 * - Does the user have the right caps for the entry
1938
	 * - Is the entry in the trash?
1939
	 *
1940
	 * @todo Move to GVCommon
1941
	 *
1942
	 * @param  boolean $echo Show error messages in the form?
1943
	 * @return boolean        True: can edit form. False: nope.
1944
	 */
1945 12
	private function user_can_edit_entry( $echo = false ) {
1946
1947 12
		$error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1948
1949
		/**
1950
		 *  1. Permalinks are turned off
1951
		 *  2. There are two entries embedded using oEmbed
1952
		 *  3. One of the entries has just been saved
1953
		 */
1954 12
		if( !empty( $_POST['lid'] ) && !empty( $_GET['entry'] ) && ( $_POST['lid'] !== $_GET['entry'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1955
1956
			$error = true;
1957
1958
		}
1959
1960 12
		if( !empty( $_GET['entry'] ) && (string)$this->entry['id'] !== $_GET['entry'] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1961
1962
			$error = true;
1963
1964 12
		} elseif( ! $this->verify_nonce() ) {
1965
1966
			/**
1967
			 * If the Entry is embedded, there may be two entries on the same page.
1968
			 * If that's the case, and one is being edited, the other should fail gracefully and not display an error.
1969
			 */
1970
			if( GravityView_oEmbed::getInstance()->get_entry_id() ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression \GravityView_oEmbed::get...tance()->get_entry_id() of type integer|null is loosely compared to true; this is ambiguous if the integer can be zero. You might want to explicitly use !== null instead.

In PHP, under loose comparison (like ==, or !=, or switch conditions), values of different types might be equal.

For integer values, zero is a special case, in particular the following results might be unexpected:

0   == false // true
0   == null  // true
123 == false // false
123 == null  // false

// It is often better to use strict comparison
0 === false // false
0 === null  // false
Loading history...
Deprecated Code introduced by
The method GravityView_oEmbed::getInstance() has been deprecated with message: Use \GV\oEmbed instead.

This method has been deprecated. The supplier of the class has supplied an explanatory message.

The explanatory message should give you some clue as to whether and when the method will be removed from the class and what other method or class to use instead.

Loading history...
Deprecated Code introduced by
The method GravityView_oEmbed::get_entry_id() has been deprecated with message: Use \GV\oEmbed instead.

This method has been deprecated. The supplier of the class has supplied an explanatory message.

The explanatory message should give you some clue as to whether and when the method will be removed from the class and what other method or class to use instead.

Loading history...
1971
				$error = true;
1972
			} else {
1973
				$error = __( 'The link to edit this entry is not valid; it may have expired.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1974
			}
1975
1976
		}
1977
1978 12
		if( ! GravityView_Edit_Entry::check_user_cap_edit_entry( $this->entry ) ) {
1979 1
			$error = __( 'You do not have permission to edit this entry.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1980
		}
1981
1982 12
		if( $this->entry['status'] === 'trash' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
1983
			$error = __('You cannot edit the entry; it is in the trash.', 'gravityview' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1984
		}
1985
1986
		// No errors; everything's fine here!
1987 12
		if( empty( $error ) ) {
1988 12
			return true;
1989
		}
1990
1991 1
		if( $echo && $error !== true ) {
0 ignored issues
show
introduced by
Found "!== true". Use Yoda Condition checks, you must
Loading history...
1992
1993 1
	        $error = esc_html( $error );
1994
1995
	        /**
1996
	         * @since 1.9
1997
	         */
1998 1
	        if ( ! empty( $this->entry ) ) {
1999 1
		        $error .= ' ' . gravityview_get_link( '#', _x('Go back.', 'Link shown when invalid Edit Entry link is clicked', 'gravityview' ), array( 'onclick' => "window.history.go(-1); return false;" ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal window.history.go(-1); return false; does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
2000
	        }
2001
2002 1
			echo GVCommon::generate_notice( wpautop( $error ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
2003
		}
2004
2005 1
		gravityview()->log->error( '{error}', array( 'error' => $error ) );
2006
2007 1
		return false;
2008
	}
2009
2010
2011
	/**
2012
	 * Check whether a field is editable by the current user, and optionally display an error message
2013
	 * @uses  GravityView_Edit_Entry->check_user_cap_edit_field() Check user capabilities
2014
	 * @param  array  $field Field or field settings array
2015
	 * @param  boolean $echo  Whether to show error message telling user they aren't allowed
2016
	 * @return boolean         True: user can edit the current field; False: nope, they can't.
2017
	 */
2018
	private function user_can_edit_field( $field, $echo = false ) {
2019
2020
		$error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
2021
2022
		if( ! $this->check_user_cap_edit_field( $field ) ) {
2023
			$error = __( 'You do not have permission to edit this field.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
2024
		}
2025
2026
		// No errors; everything's fine here!
2027
		if( empty( $error ) ) {
2028
			return true;
2029
		}
2030
2031
		if( $echo ) {
2032
			echo GVCommon::generate_notice( wpautop( esc_html( $error ) ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
2033
		}
2034
2035
		gravityview()->log->error( '{error}', array( 'error' => $error ) );
2036
2037
		return false;
2038
2039
	}
2040
2041
2042
	/**
2043
	 * checks if user has permissions to edit a specific field
2044
	 *
2045
	 * Needs to be used combined with GravityView_Edit_Entry::user_can_edit_field for maximum security!!
2046
	 *
2047
	 * @param  [type] $field [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
2048
	 * @return bool
2049
	 */
2050
	private function check_user_cap_edit_field( $field ) {
2051
2052
		// If they can edit any entries (as defined in Gravity Forms), we're good.
2053
		if( GVCommon::has_cap( array( 'gravityforms_edit_entries', 'gravityview_edit_others_entries' ) ) ) {
2054
			return true;
2055
		}
2056
2057
		$field_cap = isset( $field['allow_edit_cap'] ) ? $field['allow_edit_cap'] : false;
2058
2059
		if( $field_cap ) {
2060
			return GVCommon::has_cap( $field['allow_edit_cap'] );
2061
		}
2062
2063
		return false;
2064
	}
2065
2066
2067
	/**
2068
	 * Is the current nonce valid for editing the entry?
2069
	 * @return boolean
2070
	 */
2071 11
	public function verify_nonce() {
2072
2073
		// Verify form submitted for editing single
2074 11
		if( $this->is_edit_entry_submission() ) {
2075
			$valid = wp_verify_nonce( $_POST[ self::$nonce_field ], self::$nonce_field );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
2076
		}
2077
2078
		// Verify
2079 11
		else if( ! $this->is_edit_entry() ) {
2080
			$valid = false;
2081
		}
2082
2083
		else {
2084 11
			$valid = wp_verify_nonce( $_GET['edit'], self::$nonce_key );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
2085
		}
2086
2087
		/**
2088
		 * @filter `gravityview/edit_entry/verify_nonce` Override Edit Entry nonce validation. Return true to declare nonce valid.
2089
		 * @since 1.13
2090
		 * @param int|boolean $valid False if invalid; 1 or 2 when nonce was generated
2091
		 * @param string $nonce_field Key used when validating submissions. Default: is_gv_edit_entry
2092
		 */
2093 11
		$valid = apply_filters( 'gravityview/edit_entry/verify_nonce', $valid, self::$nonce_field );
2094
2095 11
		return $valid;
2096
	}
2097
2098
2099
	/**
2100
	 * Multiselect in GF 2.2 became a json_encoded value. Fix it.
2101
	 *
2102
	 * As a hack for now we'll implode it back.
2103
	 */
2104
	public function fix_multiselect_value_serialization( $field_value, $field, $_this ) {
0 ignored issues
show
Unused Code introduced by
The parameter $_this is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
2105
		if ( empty ( $field->storageType ) || $field->storageType != 'json' ) {
0 ignored issues
show
introduced by
Found "!= '". Use Yoda Condition checks, you must
Loading history...
Coding Style introduced by
Space before opening parenthesis of function call prohibited
Loading history...
2106
			return $field_value;
2107
		}
2108
2109
		$maybe_json = @json_decode( $field_value, true );
0 ignored issues
show
Coding Style introduced by
Silencing errors is discouraged
Loading history...
2110
2111
		if ( $maybe_json ) {
2112
			return implode( ',', $maybe_json );
2113
		}
2114
2115
		return $field_value;
2116
	}
2117
2118
2119
2120
} //end class
2121