Completed
Pull Request — develop (#757)
by Zack
04:33
created

maybe_print_message()   B

Complexity

Conditions 3
Paths 3

Size

Total Lines 32
Code Lines 11

Duplication

Lines 0
Ratio 0 %

Importance

Changes 0
Metric Value
cc 3
eloc 11
nc 3
nop 0
dl 0
loc 32
rs 8.8571
c 0
b 0
f 0
1
<?php
0 ignored issues
show
Coding Style Compatibility introduced by
For compatibility and reusability of your code, PSR1 recommends that a file should introduce either new symbols (like classes, functions, etc.) or have side-effects (like outputting something, or including other files), but not both at the same time. The first symbol is defined on line 17 and the first side effect is on line 13.

The PSR-1: Basic Coding Standard recommends that a file should either introduce new symbols, that is classes, functions, constants or similar, or have side effects. Side effects are anything that executes logic, like for example printing output, changing ini settings or writing to a file.

The idea behind this recommendation is that merely auto-loading a class should not change the state of an application. It also promotes a cleaner style of programming and makes your code less prone to errors, because the logic is not spread out all over the place.

To learn more about the PSR-1, please see the PHP-FIG site on the PSR-1.

Loading history...
2
/**
3
 * GravityView Edit Entry - render frontend
4
 *
5
 * @package   GravityView
6
 * @license   GPL2+
7
 * @author    Katz Web Services, Inc.
8
 * @link      http://gravityview.co
9
 * @copyright Copyright 2014, Katz Web Services, Inc.
10
 */
11
12
if ( ! defined( 'WPINC' ) ) {
13
    die;
14
}
15
16
17
class GravityView_Edit_Entry_Render {
18
19
    /**
20
     * @var GravityView_Edit_Entry
21
     */
22
    protected $loader;
23
24
	/**
25
	 * @var string String used to generate unique nonce for the entry/form/view combination. Allows access to edit page.
26
	 */
27
    static $nonce_key;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $nonce_key.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
28
29
	/**
30
	 * @since 1.9
31
	 * @var string String used for check valid edit entry form submission. Allows saving edit form values.
32
	 */
33
	private static $nonce_field = 'is_gv_edit_entry';
34
35
	/**
36
	 * @since 1.9
37
	 * @var bool Whether to allow save and continue functionality
38
	 */
39
	private static $supports_save_and_continue = false;
40
41
	/**
42
	 * @since 1.9
43
	 * @var bool Whether to allow editing product fields
44
	 */
45
	private static $supports_product_fields = false;
46
47
    /**
48
     * Gravity Forms entry array
49
     *
50
     * @var array
51
     */
52
    public $entry;
53
54
	/**
55
	 * Gravity Forms entry array (it won't get changed during this class lifecycle)
56
	 * @since 1.17.2
57
	 * @var array
58
	 */
59
	private static $original_entry = array();
60
61
    /**
62
     * Gravity Forms form array (GravityView modifies the content through this class lifecycle)
63
     *
64
     * @var array
65
     */
66
	public $form;
67
68
    /**
69
     * Gravity Forms form array (it won't get changed during this class lifecycle)
70
     * @since 1.16.2.1
71
     * @var array
72
     */
73
    private static $original_form;
74
75
    /**
76
     * Gravity Forms form array after the form validation process
77
     * @since 1.13
78
     * @var array
79
     */
80
	public $form_after_validation = null;
81
82
    /**
83
     * Hold an array of GF field objects that have calculation rules
84
     * @var array
85
     */
86
	public $fields_with_calculation = array();
87
88
    /**
89
     * Hold an array of GF field objects with type 'total'
90
     * @var array
91
     */
92
	public $total_fields = array();
93
94
    /**
95
     * Gravity Forms form id
96
     *
97
     * @var int
98
     */
99
	public $form_id;
100
101
    /**
102
     * ID of the current view
103
     *
104
     * @var int
105
     */
106
	public $view_id;
107
108
    /**
109
     * Updated entry is valid (GF Validation object)
110
     *
111
     * @var array
112
     */
113
	public $is_valid = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
114
115
    function __construct( GravityView_Edit_Entry $loader ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
116
        $this->loader = $loader;
117
    }
118
119
    function load() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
120
121
        /** @define "GRAVITYVIEW_DIR" "../../../" */
122
        include_once( GRAVITYVIEW_DIR .'includes/class-admin-approve-entries.php' );
123
124
        // Don't display an embedded form when editing an entry
125
        add_action( 'wp_head', array( $this, 'prevent_render_form' ) );
126
        add_action( 'wp_footer', array( $this, 'prevent_render_form' ) );
127
128
        // Stop Gravity Forms processing what is ours!
129
        add_filter( 'wp', array( $this, 'prevent_maybe_process_form'), 8 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
130
131
        add_filter( 'gravityview_is_edit_entry', array( $this, 'is_edit_entry') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
132
133
        add_action( 'gravityview_edit_entry', array( $this, 'init' ) );
134
135
        // Disable conditional logic if needed (since 1.9)
136
        add_filter( 'gform_has_conditional_logic', array( $this, 'manage_conditional_logic' ), 10, 2 );
137
138
        // Make sure GF doesn't validate max files (since 1.9)
139
        add_filter( 'gform_plupload_settings', array( $this, 'modify_fileupload_settings' ), 10, 3 );
140
141
        // Add fields expected by GFFormDisplay::validate()
142
        add_filter( 'gform_pre_validation', array( $this, 'gform_pre_validation') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
143
144
    }
145
146
    /**
147
     * Don't show any forms embedded on a page when GravityView is in Edit Entry mode
148
     *
149
     * Adds a `__return_empty_string` filter on the Gravity Forms shortcode on the `wp_head` action
150
     * And then removes it on the `wp_footer` action
151
     *
152
     * @since 1.16.1
153
     *
154
     * @return void
155
     */
156
    public function prevent_render_form() {
157
        if( $this->is_edit_entry() ) {
158
            if( 'wp_head' === current_filter() ) {
159
                add_filter( 'gform_shortcode_form', '__return_empty_string' );
160
            } else {
161
                remove_filter( 'gform_shortcode_form', '__return_empty_string' );
162
            }
163
        }
164
    }
165
166
    /**
167
     * Because we're mimicking being a front-end Gravity Forms form while using a Gravity Forms
168
     * backend form, we need to prevent them from saving twice.
169
     * @return void
170
     */
171
    public function prevent_maybe_process_form() {
172
173
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[prevent_maybe_process_form] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
174
175
        if( $this->is_edit_entry_submission() && $this->verify_nonce() ) {
176
            remove_action( 'wp',  array( 'RGForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
177
        }
178
    }
179
180
    /**
181
     * Is the current page an Edit Entry page?
182
     * @return boolean
183
     */
184
    public function is_edit_entry() {
185
186
        $is_edit_entry = GravityView_frontend::is_single_entry() && ! empty( $_GET['edit'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
187
188
        return ( $is_edit_entry || $this->is_edit_entry_submission() );
189
    }
190
191
	/**
192
	 * Is the current page an Edit Entry page?
193
	 * @since 1.9
194
	 * @return boolean
195
	 */
196
	public function is_edit_entry_submission() {
197
		return !empty( $_POST[ self::$nonce_field ] );
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
198
	}
199
200
    /**
201
     * When Edit entry view is requested setup the vars
202
     */
203
    private function setup_vars() {
204
        $gravityview_view = GravityView_View::getInstance();
205
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
206
207
        $entries = $gravityview_view->getEntries();
208
	    self::$original_entry = $entries[0];
209
	    $this->entry = $entries[0];
210
211
        self::$original_form = $gravityview_view->getForm();
212
        $this->form = $gravityview_view->getForm();
213
        $this->form_id = $gravityview_view->getFormId();
214
        $this->view_id = $gravityview_view->getViewId();
215
216
        self::$nonce_key = GravityView_Edit_Entry::get_nonce_key( $this->view_id, $this->form_id, $this->entry['id'] );
217
    }
218
219
220
    /**
221
     * Load required files and trigger edit flow
222
     *
223
     * Run when the is_edit_entry returns true.
224
     *
225
     * @param GravityView_View_Data $gv_data GravityView Data object
226
     * @return void
227
     */
228
    public function init( $gv_data ) {
229
230
        require_once( GFCommon::get_base_path() . '/form_display.php' );
231
        require_once( GFCommon::get_base_path() . '/entry_detail.php' );
232
233
        $this->setup_vars();
234
235
        // Multiple Views embedded, don't proceed if nonce fails
236
        if( $gv_data->has_multiple_views() && ! wp_verify_nonce( $_GET['edit'], self::$nonce_key ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
237
            do_action('gravityview_log_error', __METHOD__ . ': Nonce validation failed for the Edit Entry request; returning' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
238
            return;
239
        }
240
241
        // Sorry, you're not allowed here.
242
        if( false === $this->user_can_edit_entry( true ) ) {
243
            do_action('gravityview_log_error', __METHOD__ . ': User is not allowed to edit this entry; returning', $this->entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
244
            return;
245
        }
246
247
        $this->print_scripts();
248
249
        $this->process_save();
250
251
        $this->edit_entry_form();
252
253
    }
254
255
256
    /**
257
     * Force Gravity Forms to output scripts as if it were in the admin
258
     * @return void
259
     */
260
    private function print_scripts() {
261
        $gravityview_view = GravityView_View::getInstance();
262
263
        wp_register_script( 'gform_gravityforms', GFCommon::get_base_url().'/js/gravityforms.js', array( 'jquery', 'gform_json', 'gform_placeholder', 'sack', 'plupload-all', 'gravityview-fe-view' ) );
264
265
        GFFormDisplay::enqueue_form_scripts($gravityview_view->getForm(), false);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
266
267
        // Sack is required for images
268
        wp_print_scripts( array( 'sack', 'gform_gravityforms' ) );
269
    }
270
271
272
    /**
273
     * Process edit entry form save
274
     */
275
    private function process_save() {
276
277
        if( empty( $_POST ) || ! isset( $_POST['lid'] ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
278
            return;
279
        }
280
281
        // Make sure the entry, view, and form IDs are all correct
282
        $valid = $this->verify_nonce();
283
284
        if( !$valid ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
285
            do_action('gravityview_log_error', __METHOD__ . ' Nonce validation failed.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
286
            return;
287
        }
288
289
        if( $this->entry['id'] !== $_POST['lid'] ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
290
            do_action('gravityview_log_error', __METHOD__ . ' Entry ID did not match posted entry ID.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
291
            return;
292
        }
293
294
        do_action('gravityview_log_debug', __METHOD__ . ': $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
295
296
        $this->process_save_process_files( $this->form_id );
297
298
        $this->validate();
299
300
        if( $this->is_valid ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using ! empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
301
302
            do_action('gravityview_log_debug', __METHOD__ . ': Submission is valid.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
303
304
            /**
305
             * @hack This step is needed to unset the adminOnly from form fields, to add the calculation fields
306
             */
307
            $form = $this->form_prepare_for_save();
308
309
            /**
310
             * @hack to avoid the capability validation of the method save_lead for GF 1.9+
311
             */
312
            unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
313
314
            $date_created = $this->entry['date_created'];
315
316
            /**
317
             * @hack to force Gravity Forms to use $read_value_from_post in GFFormsModel::save_lead()
318
             * @since 1.17.2
319
             */
320
            unset( $this->entry['date_created'] );
321
322
            GFFormsModel::save_lead( $form, $this->entry );
323
324
	        // Delete the values for hidden inputs
325
	        $this->unset_hidden_field_values();
326
            
327
            $this->entry['date_created'] = $date_created;
328
329
            // If there's a post associated with the entry, process post fields
330
            if( !empty( $this->entry['post_id'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
331
                $this->maybe_update_post_fields( $form );
332
            }
333
334
            // Process calculation fields
335
            $this->update_calculation_fields();
336
337
            // Perform actions normally performed after updating a lead
338
            $this->after_update();
339
340
            /**
341
             * @action `gravityview/edit_entry/after_update` Perform an action after the entry has been updated using Edit Entry
342
             * @param array $form Gravity Forms form array
343
             * @param string $entry_id Numeric ID of the entry that was updated
344
             */
345
            do_action( 'gravityview/edit_entry/after_update', $this->form, $this->entry['id'] );
346
347
        } else {
348
            do_action('gravityview_log_error', __METHOD__ . ': Submission is NOT valid.', $this->entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
349
        }
350
351
    } // process_save
352
353
	/**
354
	 * Delete the value of fields hidden by conditional logic when the entry is edited
355
     *
356
     * @uses GFFormsModel::update_lead_field_value()
357
     *
358
     * @since 1.17.4
359
     *
360
     * @return void
361
	 */
362
    private function unset_hidden_field_values() {
363
	    global $wpdb;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
364
365
	    $lead_detail_table      = GFFormsModel::get_lead_details_table_name();
366
	    $current_fields   = $wpdb->get_results( $wpdb->prepare( "SELECT id, field_number FROM $lead_detail_table WHERE lead_id=%d", $this->entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
367
368
	    foreach ( $this->entry as $input_id => $field_value ) {
369
370
		    $field = RGFormsModel::get_field( $this->form, $input_id );
371
372
		    // Reset fields that are hidden
373
		    // Don't pass $entry as fourth parameter; force using $_POST values to calculate conditional logic
374
		    if ( GFFormsModel::is_field_hidden( $this->form, $field, array(), NULL ) ) {
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
375
376
		        // List fields are stored as empty arrays when empty
377
			    $empty_value = $this->is_field_json_encoded( $field ) ? '[]' : '';
378
379
			    $lead_detail_id = GFFormsModel::get_lead_detail_id( $current_fields, $input_id );
380
381
			    GFFormsModel::update_lead_field_value( $this->form, $this->entry, $field, $lead_detail_id, $input_id, $empty_value );
382
383
			    // Prevent the $_POST values of hidden fields from being used as default values when rendering the form
384
                // after submission
385
			    $post_input_id = 'input_' . str_replace( '.', '_', $input_id );
386
			    $_POST[ $post_input_id ] = '';
387
		    }
388
	    }
389
    }
390
391
    /**
392
     * Have GF handle file uploads
393
     *
394
     * Copy of code from GFFormDisplay::process_form()
395
     *
396
     * @param int $form_id
397
     */
398
    private function process_save_process_files( $form_id ) {
399
400
        //Loading files that have been uploaded to temp folder
401
        $files = GFCommon::json_decode( stripslashes( RGForms::post( 'gform_uploaded_files' ) ) );
402
        if ( ! is_array( $files ) ) {
403
            $files = array();
404
        }
405
406
        RGFormsModel::$uploaded_files[ $form_id ] = $files;
407
    }
408
409
    /**
410
     * Remove max_files validation (done on gravityforms.js) to avoid conflicts with GravityView
411
     * Late validation done on self::custom_validation
412
     *
413
     * @param $plupload_init array Plupload settings
414
     * @param $form_id
415
     * @param $instance
416
     * @return mixed
417
     */
418
    public function modify_fileupload_settings( $plupload_init, $form_id, $instance ) {
0 ignored issues
show
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $instance is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
419
        if( ! $this->is_edit_entry() ) {
420
            return $plupload_init;
421
        }
422
423
        $plupload_init['gf_vars']['max_files'] = 0;
424
425
        return $plupload_init;
426
    }
427
428
429
    /**
430
     * Unset adminOnly and convert field input key to string
431
     * @return array $form
432
     */
433
    private function form_prepare_for_save() {
434
435
        $form = $this->form;
436
437
	    /** @var GF_Field $field */
438
        foreach( $form['fields'] as $k => &$field ) {
439
440
            /**
441
             * Remove the fields with calculation formulas before save to avoid conflicts with GF logic
442
             * @since 1.16.3
443
             */
444
            if( $field->has_calculation() ) {
445
                unset( $form['fields'][ $k ] );
446
            }
447
448
            $field->adminOnly = false;
449
450
            if( isset( $field->inputs ) && is_array( $field->inputs ) ) {
451
                foreach( $field->inputs as $key => $input ) {
452
                    $field->inputs[ $key ][ 'id' ] = (string)$input['id'];
0 ignored issues
show
introduced by
Array keys should NOT be surrounded by spaces if they only contain a string or an integer.
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
453
                }
454
            }
455
        }
456
457
        return $form;
458
    }
459
460
    private function update_calculation_fields() {
461
462
        $form = self::$original_form;
463
        $update = false;
464
465
        // get the most up to date entry values
466
        $entry = GFAPI::get_entry( $this->entry['id'] );
467
468
        if( !empty( $this->fields_with_calculation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
469
            $update = true;
470
            foreach ( $this->fields_with_calculation as $calc_field ) {
471
                $inputs = $calc_field->get_entry_inputs();
472
                if ( is_array( $inputs ) ) {
473
                    foreach ( $inputs as $input ) {
474
                        $input_name = 'input_' . str_replace( '.', '_', $input['id'] );
475
                        $entry[ strval( $input['id'] ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
476
                    }
477
                } else {
478
                    $input_name = 'input_' . str_replace( '.', '_', $calc_field->id);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
479
                    $entry[ strval( $calc_field->id ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
480
                }
481
            }
482
483
        }
484
485
        //saving total field as the last field of the form.
486
        if ( ! empty( $this->total_fields ) ) {
487
            $update = true;
488
            foreach ( $this->total_fields as $total_field ) {
489
                $input_name = 'input_' . str_replace( '.', '_', $total_field->id);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
490
                $entry[ strval( $total_field->id ) ] = RGFormsModel::prepare_value( $form, $total_field, '', $input_name, $entry['id'], $entry );
491
            }
492
        }
493
494
        if( $update ) {
495
496
            $return_entry = GFAPI::update_entry( $entry );
497
498
            if( is_wp_error( $return_entry ) ) {
499
                do_action( 'gravityview_log_error', 'Updating the entry calculation and total fields failed', $return_entry );
500
            } else {
501
                do_action( 'gravityview_log_debug', 'Updating the entry calculation and total fields succeeded' );
502
            }
503
        }
504
    }
505
506
    /**
507
     * Handle updating the Post Image field
508
     *
509
     * Sets a new Featured Image if configured in Gravity Forms; otherwise uploads/updates media
510
     *
511
     * @since 1.17
512
     *
513
     * @uses GFFormsModel::media_handle_upload
514
     * @uses set_post_thumbnail
515
     * 
516
     * @param array $form GF Form array
517
     * @param GF_Field $field GF Field
518
     * @param string $field_id Numeric ID of the field
519
     * @param string $value
520
     * @param array $entry GF Entry currently being edited
521
     * @param int $post_id ID of the Post being edited
522
     *
523
     * @return mixed|string
524
     */
525
    private function update_post_image( $form, $field, $field_id, $value, $entry, $post_id ) {
526
527
        $input_name = 'input_' . $field_id;
528
529
        if ( !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
530
531
            // We have a new image
532
533
            $value = RGFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'] );
534
535
            $ary = ! empty( $value ) ? explode( '|:|', $value ) : array();
536
            $img_url = rgar( $ary, 0 );
537
538
            $img_title       = count( $ary ) > 1 ? $ary[1] : '';
539
            $img_caption     = count( $ary ) > 2 ? $ary[2] : '';
540
            $img_description = count( $ary ) > 3 ? $ary[3] : '';
541
542
            $image_meta = array(
543
                'post_excerpt' => $img_caption,
544
                'post_content' => $img_description,
545
            );
546
547
            //adding title only if it is not empty. It will default to the file name if it is not in the array
548
            if ( ! empty( $img_title ) ) {
549
                $image_meta['post_title'] = $img_title;
550
            }
551
552
            /**
553
             * todo: As soon as \GFFormsModel::media_handle_upload becomes a public method, move this call to \GFFormsModel::media_handle_upload and remove the hack from this class.
554
             * Note: the method became public in GF 1.9.17.7, but we don't require that version yet.
555
             */
556
            require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
557
            $media_id = GravityView_GFFormsModel::media_handle_upload( $img_url, $post_id, $image_meta );
558
559
            // is this field set as featured image?
560
            if ( $media_id && $field->postFeaturedImage ) {
561
                set_post_thumbnail( $post_id, $media_id );
562
            }
563
564
        } elseif ( !empty( $_POST[ $input_name ] ) && is_array( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
565
566
            // Same image although the image title, caption or description might have changed
567
568
            $ary = array();
569
            if( ! empty( $entry[ $field_id ] ) ) {
570
                $ary = is_array( $entry[ $field_id ] ) ? $entry[ $field_id ] : explode( '|:|', $entry[ $field_id ] );
571
            }
572
            $img_url = rgar( $ary, 0 );
573
574
            // is this really the same image or something went wrong ?
575
            if( $img_url === $_POST[ $input_name ] ) {
576
577
                $img_title       = rgar( $value, $field_id .'.1' );
578
                $img_caption     = rgar( $value, $field_id .'.4' );
579
                $img_description = rgar( $value, $field_id .'.7' );
580
581
                $value = ! empty( $img_url ) ? $img_url . "|:|" . $img_title . "|:|" . $img_caption . "|:|" . $img_description : '';
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal |:| does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
582
583
                if ( $field->postFeaturedImage ) {
584
585
                    $image_meta = array(
586
                        'ID' => get_post_thumbnail_id( $post_id ),
587
                        'post_title' => $img_title,
588
                        'post_excerpt' => $img_caption,
589
                        'post_content' => $img_description,
590
                    );
591
592
                    // update image title, caption or description
593
                    wp_update_post( $image_meta );
594
                }
595
            }
596
597
        } else {
598
599
            // if we get here, image was removed or not set.
600
            $value = '';
601
602
            if ( $field->postFeaturedImage ) {
603
                delete_post_thumbnail( $post_id );
604
            }
605
        }
606
607
        return $value;
608
    }
609
610
    /**
611
     * Loop through the fields being edited and if they include Post fields, update the Entry's post object
612
     *
613
     * @param array $form Gravity Forms form
614
     *
615
     * @return void
616
     */
617
    private function maybe_update_post_fields( $form ) {
618
619
        $post_id = $this->entry['post_id'];
620
621
        // Security check
622
        if( false === GVCommon::has_cap( 'edit_post', $post_id ) ) {
623
            do_action( 'gravityview_log_error', 'The current user does not have the ability to edit Post #'.$post_id );
624
            return;
625
        }
626
627
        $update_entry = false;
628
629
        $updated_post = $original_post = get_post( $post_id );
630
631
        foreach ( $this->entry as $field_id => $value ) {
632
633
            $field = RGFormsModel::get_field( $form, $field_id );
634
635
            if( ! $field ) {
636
                continue;
637
            }
638
639
            if( GFCommon::is_post_field( $field ) && 'post_category' !== $field->type ) {
640
641
                // Get the value of the field, including $_POSTed value
642
                $value = RGFormsModel::get_field_value( $field );
643
644
                // Use temporary entry variable, to make values available to fill_post_template() and update_post_image()
645
                $entry_tmp = $this->entry;
646
                $entry_tmp["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
647
648
                switch( $field->type ) {
649
650
                    case 'post_title':
651
                        $post_title = $value;
652
                        if( rgar( $form, 'postTitleTemplateEnabled' ) ) {
653
                            $post_title = $this->fill_post_template( $form['postTitleTemplate'], $form, $entry_tmp );
654
                        }
655
                        $updated_post->post_title = $post_title;
656
                        $updated_post->post_name  = $post_title;
657
                        unset( $post_title );
658
                        break;
659
660
                    case 'post_content':
661
                        $post_content = $value;
662
                        if( rgar( $form, 'postContentTemplateEnabled' ) ) {
663
                            $post_content = $this->fill_post_template( $form['postContentTemplate'], $form, $entry_tmp, true );
664
                        }
665
                        $updated_post->post_content = $post_content;
666
                        unset( $post_content );
667
                        break;
668
                    case 'post_excerpt':
669
                        $updated_post->post_excerpt = $value;
670
                        break;
671
                    case 'post_tags':
672
                        wp_set_post_tags( $post_id, $value, false );
673
                        break;
674
                    case 'post_category':
675
                        break;
676
                    case 'post_custom_field':
677
                        if( ! empty( $field->customFieldTemplateEnabled ) ) {
678
                            $value = $this->fill_post_template( $field->customFieldTemplate, $form, $entry_tmp, true );
679
                        }
680
681
	                    if ( $this->is_field_json_encoded( $field ) && ! is_string( $value ) ) {
682
		                    $value = function_exists('wp_json_encode') ? wp_json_encode( $value ) : json_encode( $value );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
683
	                    }
684
685
                        update_post_meta( $post_id, $field->postCustomFieldName, $value );
686
687
                        break;
688
689
                    case 'post_image':
690
                        $value = $this->update_post_image( $form, $field, $field_id, $value, $this->entry, $post_id );
691
                        break;
692
693
                }
694
695
                // update entry after
696
                $this->entry["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
697
698
                $update_entry = true;
699
700
                unset( $entry_tmp );
701
            }
702
703
        }
704
705
        if( $update_entry ) {
706
707
            $return_entry = GFAPI::update_entry( $this->entry );
708
709
            if( is_wp_error( $return_entry ) ) {
710
               do_action( 'gravityview_log_error', 'Updating the entry post fields failed', array( '$this->entry' => $this->entry, '$return_entry' => $return_entry ) );
711
            } else {
712
                do_action( 'gravityview_log_debug', 'Updating the entry post fields for post #'.$post_id.' succeeded' );
713
            }
714
715
        }
716
717
        $return_post = wp_update_post( $updated_post, true );
718
719
        if( is_wp_error( $return_post ) ) {
720
            $return_post->add_data( $updated_post, '$updated_post' );
721
            do_action( 'gravityview_log_error', 'Updating the post content failed', compact( 'updated_post', 'return_post' ) );
722
        } else {
723
            do_action( 'gravityview_log_debug', 'Updating the post content for post #'.$post_id.' succeeded', $updated_post );
724
        }
725
    }
726
727
	/**
728
     * Is the field stored in a JSON-encoded manner?
729
     *
730
	 * @param GF_Field $field
731
	 *
732
	 * @return bool True: stored in DB json_encode()'d; False: not encoded
733
	 */
734
    private function is_field_json_encoded( $field ) {
735
736
	    $json_encoded = false;
737
738
        $input_type = RGFormsModel::get_input_type( $field );
739
740
	    // Only certain custom field types are supported
741
	    switch( $input_type ) {
742
		    case 'fileupload':
743
		    case 'list':
744
		    case 'multiselect':
745
			    $json_encoded = true;
746
			    break;
747
	    }
748
749
	    return $json_encoded;
750
    }
751
752
    /**
753
     * Convert a field content template into prepared output
754
     *
755
     * @uses GravityView_GFFormsModel::get_post_field_images()
756
     *
757
     * @since 1.17
758
     *
759
     * @param string $template The content template for the field
760
     * @param array $form Gravity Forms form
761
     * @param bool $do_shortcode Whether to process shortcode inside content. In GF, only run on Custom Field and Post Content fields
762
     *
763
     * @return mixed|string|void
764
     */
765
    private function fill_post_template( $template, $form, $entry, $do_shortcode = false ) {
766
767
        require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
768
769
        $post_images = GravityView_GFFormsModel::get_post_field_images( $form, $entry );
770
771
        //replacing post image variables
772
        $output = GFCommon::replace_variables_post_image( $template, $post_images, $entry );
773
774
        //replacing all other variables
775
        $output = GFCommon::replace_variables( $output, $form, $entry, false, false, false );
776
777
        // replace conditional shortcodes
778
        if( $do_shortcode ) {
779
            $output = do_shortcode( $output );
780
        }
781
782
        return $output;
783
    }
784
785
786
    /**
787
     * Perform actions normally performed after updating a lead
788
     *
789
     * @since 1.8
790
     *
791
     * @see GFEntryDetail::lead_detail_page()
792
     *
793
     * @return void
794
     */
795
    private function after_update() {
796
797
        do_action( 'gform_after_update_entry', $this->form, $this->entry['id'], self::$original_entry );
798
        do_action( "gform_after_update_entry_{$this->form['id']}", $this->form, $this->entry['id'] );
799
800
        // Re-define the entry now that we've updated it.
801
        $entry = RGFormsModel::get_lead( $this->entry['id'] );
802
803
        $entry = GFFormsModel::set_entry_meta( $entry, $this->form );
804
805
        // We need to clear the cache because Gravity Forms caches the field values, which
806
        // we have just updated.
807
        foreach ($this->form['fields'] as $key => $field) {
0 ignored issues
show
introduced by
No space after opening parenthesis is prohibited
Loading history...
introduced by
No space before closing parenthesis is prohibited
Loading history...
808
            GFFormsModel::refresh_lead_field_value( $entry['id'], $field->id );
809
        }
810
811
        $this->entry = $entry;
812
    }
813
814
815
    /**
816
     * Display the Edit Entry form
817
     *
818
     * @return void
819
     */
820
    public function edit_entry_form() {
821
822
        ?>
823
824
        <div class="gv-edit-entry-wrapper"><?php
825
826
            $javascript = gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/inline-javascript.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
827
828
            /**
829
             * Fixes weird wpautop() issue
830
             * @see https://github.com/katzwebservices/GravityView/issues/451
831
             */
832
            echo gravityview_strip_whitespace( $javascript );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'gravityview_strip_whitespace'
Loading history...
833
834
            ?><h2 class="gv-edit-entry-title">
835
                <span><?php
836
837
                    /**
838
                     * @filter `gravityview_edit_entry_title` Modify the edit entry title
839
                     * @param string $edit_entry_title Modify the "Edit Entry" title
840
                     * @param GravityView_Edit_Entry_Render $this This object
841
                     */
842
                    $edit_entry_title = apply_filters('gravityview_edit_entry_title', __('Edit Entry', 'gravityview'), $this );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
843
844
                    echo esc_attr( $edit_entry_title );
845
            ?></span>
846
            </h2>
847
848
            <?php $this->maybe_print_message(); ?>
849
850
            <?php // The ID of the form needs to be `gform_{form_id}` for the pluploader ?>
851
852
            <form method="post" id="gform_<?php echo $this->form_id; ?>" enctype="multipart/form-data">
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$this'
Loading history...
853
854
                <?php
855
856
                wp_nonce_field( self::$nonce_key, self::$nonce_key );
857
858
                wp_nonce_field( self::$nonce_field, self::$nonce_field, false );
859
860
                // Print the actual form HTML
861
                $this->render_edit_form();
862
863
                ?>
864
            </form>
865
866
            <script>
867
                gform.addFilter('gform_reset_pre_conditional_logic_field_action', function ( reset, formId, targetId, defaultValues, isInit ) {
868
                    return false;
869
                });
870
            </script>
871
872
        </div>
873
874
    <?php
875
    }
876
877
    /**
878
     * Display success or error message if the form has been submitted
879
     *
880
     * @uses GVCommon::generate_notice
881
     *
882
     * @since 1.16.2.2
883
     *
884
     * @return void
885
     */
886
    private function maybe_print_message() {
887
888
        if( rgpost('action') === 'update' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
889
890
            $back_link = esc_url( remove_query_arg( array( 'page', 'view', 'edit' ) ) );
891
892
            if( ! $this->is_valid ){
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
893
894
                // Keeping this compatible with Gravity Forms.
895
                $validation_message = "<div class='validation_error'>" . __('There was a problem with your submission.', 'gravityview') . " " . __('Errors have been highlighted below.', 'gravityview') . "</div>";
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw '__'
Loading history...
Coding Style Comprehensibility introduced by
The string literal </div> does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
896
                $message = apply_filters("gform_validation_message_{$this->form['id']}", apply_filters("gform_validation_message", $validation_message, $this->form), $this->form);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal gform_validation_message does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
897
898
                echo GVCommon::generate_notice( $message , 'gv-error' );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
899
900
            } else {
901
                $entry_updated_message = sprintf( esc_attr__('Entry Updated. %sReturn to Entry%s', 'gravityview'), '<a href="'. $back_link .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
902
903
                /**
904
                 * @filter `gravityview/edit_entry/success` Modify the edit entry success message (including the anchor link)
905
                 * @since 1.5.4
906
                 * @param string $entry_updated_message Existing message
907
                 * @param int $view_id View ID
908
                 * @param array $entry Gravity Forms entry array
909
                 * @param string $back_link URL to return to the original entry. @since 1.6
910
                 */
911
                $message = apply_filters( 'gravityview/edit_entry/success', $entry_updated_message , $this->view_id, $this->entry, $back_link );
912
913
                echo GVCommon::generate_notice( $message );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
914
            }
915
916
        }
917
    }
918
919
    /**
920
     * Display the Edit Entry form in the original Gravity Forms format
921
     *
922
     * @since 1.9
923
     *
924
     * @return void
925
     */
926
    private function render_edit_form() {
927
928
        /**
929
         * @action `gravityview/edit-entry/render/before` Before rendering the Edit Entry form
930
         * @since 1.17
931
         * @param GravityView_Edit_Entry_Render $this
932
         */
933
        do_action( 'gravityview/edit-entry/render/before', $this );
934
935
        add_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields'), 5000, 3 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
936
        add_filter( 'gform_submit_button', array( $this, 'render_form_buttons') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
937
        add_filter( 'gform_disable_view_counter', '__return_true' );
938
939
        add_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5, 5 );
940
        add_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10, 5 );
941
942
        // We need to remove the fake $_GET['page'] arg to avoid rendering form as if in admin.
943
        unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
944
945
        // TODO: Verify multiple-page forms
946
        // TODO: Product fields are not editable
947
948
        ob_start(); // Prevent PHP warnings possibly caused by prefilling list fields for conditional logic
949
950
        $html = GFFormDisplay::get_form( $this->form['id'], false, false, true, $this->entry );
951
952
        ob_get_clean();
953
954
	    remove_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields' ), 5000 );
955
        remove_filter( 'gform_submit_button', array( $this, 'render_form_buttons' ) );
956
        remove_filter( 'gform_disable_view_counter', '__return_true' );
957
        remove_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5 );
958
        remove_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10 );
959
960
        echo $html;
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$html'
Loading history...
961
962
        /**
963
         * @action `gravityview/edit-entry/render/after` After rendering the Edit Entry form
964
         * @since 1.17
965
         * @param GravityView_Edit_Entry_Render $this
966
         */
967
        do_action( 'gravityview/edit-entry/render/after', $this );
968
    }
969
970
    /**
971
     * Display the Update/Cancel/Delete buttons for the Edit Entry form
972
     * @since 1.8
973
     * @return string
974
     */
975
    public function render_form_buttons() {
976
        return gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/form-buttons.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
977
    }
978
979
980
    /**
981
     * Modify the form fields that are shown when using GFFormDisplay::get_form()
982
     *
983
     * By default, all fields will be shown. We only want the Edit Tab configured fields to be shown.
984
     *
985
     * @param array $form
986
     * @param boolean $ajax Whether in AJAX mode
987
     * @param array|string $field_values Passed parameters to the form
988
     *
989
     * @since 1.9
990
     *
991
     * @return array Modified form array
992
     */
993
    public function filter_modify_form_fields( $form, $ajax = false, $field_values = '' ) {
0 ignored issues
show
Unused Code introduced by
The parameter $ajax is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $field_values is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
994
995
        // In case we have validated the form, use it to inject the validation results into the form render
996
        if( isset( $this->form_after_validation ) ) {
997
            $form = $this->form_after_validation;
998
        } else {
999
            $form['fields'] = $this->get_configured_edit_fields( $form, $this->view_id );
1000
        }
1001
1002
        $form = $this->filter_conditional_logic( $form );
1003
1004
        $form = $this->prefill_conditional_logic( $form );
1005
1006
        // for now we don't support Save and Continue feature.
1007
        if( ! self::$supports_save_and_continue ) {
1008
	        unset( $form['save'] );
1009
        }
1010
1011
        return $form;
1012
    }
1013
1014
    /**
1015
     * When displaying a field, check if it's a Post Field, and if so, make sure the post exists and current user has edit rights.
1016
     *
1017
     * @since 1.16.2.2
1018
     *
1019
     * @param string $field_content Always empty. Returning not-empty overrides the input.
1020
     * @param GF_Field $field
1021
     * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1022
     * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1023
     * @param int $form_id Form ID
1024
     *
1025
     * @return string If error, the error message. If no error, blank string (modify_edit_field_input() runs next)
1026
     */
1027
    public function verify_user_can_edit_post( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1028
1029
        if( GFCommon::is_post_field( $field ) ) {
1030
1031
            $message = null;
1032
1033
            // First, make sure they have the capability to edit the post.
1034
            if( false === current_user_can( 'edit_post', $this->entry['post_id'] ) ) {
1035
1036
                /**
1037
                 * @filter `gravityview/edit_entry/unsupported_post_field_text` Modify the message when someone isn't able to edit a post
1038
                 * @param string $message The existing "You don't have permission..." text
1039
                 */
1040
                $message = apply_filters('gravityview/edit_entry/unsupported_post_field_text', __('You don&rsquo;t have permission to edit this post.', 'gravityview') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1041
1042
            } elseif( null === get_post( $this->entry['post_id'] ) ) {
1043
                /**
1044
                 * @filter `gravityview/edit_entry/no_post_text` Modify the message when someone is editing an entry attached to a post that no longer exists
1045
                 * @param string $message The existing "This field is not editable; the post no longer exists." text
1046
                 */
1047
                $message = apply_filters('gravityview/edit_entry/no_post_text', __('This field is not editable; the post no longer exists.', 'gravityview' ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1048
            }
1049
1050
            if( $message ) {
1051
                $field_content = sprintf('<div class="ginput_container ginput_container_' . $field->type . '">%s</div>', wpautop( $message ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1052
            }
1053
        }
1054
1055
        return $field_content;
1056
    }
1057
1058
    /**
1059
     *
1060
     * Fill-in the saved values into the form inputs
1061
     *
1062
     * @param string $field_content Always empty. Returning not-empty overrides the input.
1063
     * @param GF_Field $field
1064
     * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1065
     * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1066
     * @param int $form_id Form ID
1067
     *
1068
     * @return mixed
1069
     */
1070
    public function modify_edit_field_input( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1071
1072
        $gv_field = GravityView_Fields::get_associated_field( $field );
1073
1074
        // If the form has been submitted, then we don't need to pre-fill the values,
1075
        // Except for fileupload type and when a field input is overridden- run always!!
1076
        if(
1077
            ( $this->is_edit_entry_submission() && !in_array( $field->type, array( 'fileupload', 'post_image' ) ) )
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1078
            && false === ( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) )
1079
            || ! empty( $field_content )
1080
            || in_array( $field->type, array( 'honeypot' ) )
1081
            || GFCommon::is_product_field( $field->type ) // Prevent product fields from appearing editable
1082
        ) {
1083
	        return $field_content;
1084
        }
1085
1086
        // Turn on Admin-style display for file upload fields only
1087
        if( 'fileupload' === $field->type ) {
1088
            $_GET['page'] = 'gf_entries';
1089
        }
1090
1091
        // SET SOME FIELD DEFAULTS TO PREVENT ISSUES
1092
        $field->adminOnly = false; /** @see GFFormDisplay::get_counter_init_script() need to prevent adminOnly */
1093
1094
        // add categories as choices for Post Category field
1095
        if ( 'post_category' === $field->type ) {
1096
            $field = GFCommon::add_categories_as_choices( $field, $value );
1097
        }
1098
1099
        $field_value = $this->get_field_value( $field );
1100
1101
        /**
1102
         * @filter `gravityview/edit_entry/field_value` Change the value of an Edit Entry field, if needed
1103
         * @since 1.11
1104
         * @param mixed $field_value field value used to populate the input
1105
         * @param object $field Gravity Forms field object ( Class GF_Field )
1106
         */
1107
        $field_value = apply_filters( 'gravityview/edit_entry/field_value', $field_value, $field );
1108
1109
        /**
1110
         * @filter `gravityview/edit_entry/field_value_{field_type}` Change the value of an Edit Entry field for a specific field type
1111
         * @since 1.17
1112
         * @param mixed $field_value field value used to populate the input
1113
         * @param GF_Field $field Gravity Forms field object
1114
         */
1115
        $field_value = apply_filters( 'gravityview/edit_entry/field_value_' . $field->type , $field_value, $field );
1116
1117
	    // Prevent any PHP warnings, like undefined index
1118
	    ob_start();
1119
1120
        if( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) ) {
1121
            /** @var GF_Field $gv_field */
1122
            $return = $gv_field->get_field_input( $this->form, $field_value, $this->entry, $field );
1123
        } else {
1124
	        $return = $field->get_field_input( $this->form, $field_value, $this->entry );
1125
        }
1126
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1127
1128
	    // If there was output, it's an error
1129
	    $warnings = ob_get_clean();
1130
1131
	    if( !empty( $warnings ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1132
		    do_action( 'gravityview_log_error', __METHOD__ . $warnings, $field_value );
1133
	    }
1134
1135
        /**
1136
         * Unset hack $_GET['page'] = 'gf_entries'
1137
         * We need the fileupload html field to render with the proper id
1138
         *  ( <li id="field_80_16" ... > )
1139
         */
1140
        unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
1141
1142
        return $return;
1143
    }
1144
1145
    /**
1146
     * Modify the value for the current field input
1147
     *
1148
     * @param GF_Field $field
1149
     *
1150
     * @return array|mixed|string|void
1151
     */
1152
    private function get_field_value( $field ) {
1153
1154
        /**
1155
         * @filter `gravityview/edit_entry/pre_populate/override` Allow the pre-populated value to override saved value in Edit Entry form. By default, pre-populate mechanism only kicks on empty fields.
1156
         * @param boolean True: override saved values; False: don't override (default)
1157
         * @param $field GF_Field object Gravity Forms field object
1158
         * @since 1.13
1159
         */
1160
        $override_saved_value = apply_filters( 'gravityview/edit_entry/pre_populate/override', false, $field );
1161
1162
        // We're dealing with multiple inputs (e.g. checkbox) but not time or date (as it doesn't store data in input IDs)
1163
        if( isset( $field->inputs ) && is_array( $field->inputs ) && !in_array( $field->type, array( 'time', 'date' ) ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1164
1165
            $field_value = array();
1166
1167
            // only accept pre-populated values if the field doesn't have any choice selected.
1168
            $allow_pre_populated = $field->allowsPrepopulate;
1169
1170
            foreach ( (array)$field->inputs as $input ) {
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1171
1172
                $input_id = strval( $input['id'] );
1173
                
1174
                if ( isset( $this->entry[ $input_id ] ) && ! gv_empty( $this->entry[ $input_id ], false, false ) ) {
1175
                    $field_value[ $input_id ] =  'post_category' === $field->type ? GFCommon::format_post_category( $this->entry[ $input_id ], true ) : $this->entry[ $input_id ];
0 ignored issues
show
introduced by
Expected 1 space after "="; 2 found
Loading history...
1176
                    $allow_pre_populated = false;
1177
                }
1178
1179
            }
1180
1181
            $pre_value = $field->get_value_submission( array(), false );
1182
1183
            $field_value = ! $allow_pre_populated && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $field_value : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1184
1185
        } else {
1186
1187
            $id = intval( $field->id );
1188
1189
            // get pre-populated value if exists
1190
            $pre_value = $field->allowsPrepopulate ? GFFormsModel::get_parameter_value( $field->inputName, array(), $field ) : '';
1191
1192
            // saved field entry value (if empty, fallback to the pre-populated value, if exists)
1193
            // or pre-populated value if not empty and set to override saved value
1194
            $field_value = !gv_empty( $this->entry[ $id ], false, false ) && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $this->entry[ $id ] : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1195
1196
            // in case field is post_category but inputType is select, multi-select or radio, convert value into array of category IDs.
1197
            if ( 'post_category' === $field->type && !gv_empty( $field_value, false, false ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1198
                $categories = array();
1199
                foreach ( explode( ',', $field_value ) as $cat_string ) {
1200
                    $categories[] = GFCommon::format_post_category( $cat_string, true );
1201
                }
1202
                $field_value = 'multiselect' === $field->get_input_type() ? $categories : implode( '', $categories );
1203
            }
1204
1205
        }
1206
1207
        // if value is empty get the default value if defined
1208
        $field_value = $field->get_value_default_if_empty( $field_value );
1209
1210
        return $field_value;
1211
    }
1212
1213
1214
    // ---- Entry validation
1215
1216
    /**
1217
     * Add field keys that Gravity Forms expects.
1218
     *
1219
     * @see GFFormDisplay::validate()
1220
     * @param  array $form GF Form
1221
     * @return array       Modified GF Form
1222
     */
1223
    public function gform_pre_validation( $form ) {
1224
1225
        if( ! $this->verify_nonce() ) {
1226
            return $form;
1227
        }
1228
1229
        // Fix PHP warning regarding undefined index.
1230
        foreach ( $form['fields'] as &$field) {
0 ignored issues
show
introduced by
No space before closing parenthesis is prohibited
Loading history...
1231
1232
            // This is because we're doing admin form pretending to be front-end, so Gravity Forms
1233
            // expects certain field array items to be set.
1234
            foreach ( array( 'noDuplicates', 'adminOnly', 'inputType', 'isRequired', 'enablePrice', 'inputs', 'allowedExtensions' ) as $key ) {
1235
	            $field->{$key} = isset( $field->{$key} ) ? $field->{$key} : NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1236
            }
1237
1238
            // unset emailConfirmEnabled for email type fields
1239
           /* if( 'email' === $field['type'] && !empty( $field['emailConfirmEnabled'] ) ) {
0 ignored issues
show
Unused Code Comprehensibility introduced by
61% of this comment could be valid code. Did you maybe forget this after debugging?

Sometimes obsolete code just ends up commented out instead of removed. In this case it is better to remove the code once you have checked you do not need it.

The code might also have been commented out for debugging purposes. In this case it is vital that someone uncomments it again or your project may behave in very unexpected ways in production.

This check looks for comments that seem to be mostly valid code and reports them.

Loading history...
1240
                $field['emailConfirmEnabled'] = '';
1241
            }*/
1242
1243
            switch( RGFormsModel::get_input_type( $field ) ) {
1244
1245
                /**
1246
                 * this whole fileupload hack is because in the admin, Gravity Forms simply doesn't update any fileupload field if it's empty, but it DOES in the frontend.
1247
                 *
1248
                 * What we have to do is set the value so that it doesn't get overwritten as empty on save and appears immediately in the Edit Entry screen again.
1249
                 *
1250
                 * @hack
1251
                 */
1252
                case 'fileupload':
1253
1254
                    // Set the previous value
1255
                    $entry = $this->get_entry();
1256
1257
                    $input_name = 'input_'.$field->id;
1258
                    $form_id = $form['id'];
1259
1260
                    $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1261
1262
                    // Use the previous entry value as the default.
1263
                    if( isset( $entry[ $field->id ] ) ) {
1264
                        $value = $entry[ $field->id ];
1265
                    }
1266
1267
                    // If this is a single upload file
1268
                    if( !empty( $_FILES[ $input_name ] ) && !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1269
                        $file_path = GFFormsModel::get_file_upload_path( $form['id'], $_FILES[ $input_name ]['name'] );
1270
                        $value = $file_path['url'];
1271
1272
                    } else {
1273
1274
                        // Fix PHP warning on line 1498 of form_display.php for post_image fields
1275
                        // Fix PHP Notice:  Undefined index:  size in form_display.php on line 1511
1276
                        $_FILES[ $input_name ] = array('name' => '', 'size' => '' );
0 ignored issues
show
introduced by
No space after opening parenthesis of array is bad style
Loading history...
1277
1278
                    }
1279
1280
                    if( rgar($field, "multipleFiles") ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal multipleFiles does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1281
1282
                        // If there are fresh uploads, process and merge them.
1283
                        // Otherwise, use the passed values, which should be json-encoded array of URLs
1284
                        if( isset( GFFormsModel::$uploaded_files[$form_id][$input_name] ) ) {
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1285
                            $value = empty( $value ) ? '[]' : $value;
1286
                            $value = stripslashes_deep( $value );
1287
                            $value = GFFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'], array());
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1288
                        }
1289
1290
                    } else {
1291
1292
                        // A file already exists when editing an entry
1293
                        // We set this to solve issue when file upload fields are required.
1294
                        GFFormsModel::$uploaded_files[ $form_id ][ $input_name ] = $value;
1295
1296
                    }
1297
1298
                    $this->entry[ $input_name ] = $value;
1299
                    $_POST[ $input_name ] = $value;
1300
1301
                    break;
1302
1303
                case 'number':
1304
                    // Fix "undefined index" issue at line 1286 in form_display.php
1305
                    if( !isset( $_POST['input_'.$field->id ] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1306
                        $_POST['input_'.$field->id ] = NULL;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1307
                    }
1308
                    break;
1309
                case 'captcha':
1310
                    // Fix issue with recaptcha_check_answer() on line 1458 in form_display.php
1311
                    $_POST['recaptcha_challenge_field'] = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1312
                    $_POST['recaptcha_response_field'] = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1313
                    break;
1314
            }
1315
1316
        }
1317
1318
        return $form;
1319
    }
1320
1321
1322
    /**
1323
     * Process validation for a edit entry submission
1324
     *
1325
     * Sets the `is_valid` object var
1326
     *
1327
     * @return void
1328
     */
1329
    private function validate() {
1330
1331
        /**
1332
         * If using GF User Registration Add-on, remove the validation step, otherwise generates error when updating the entry
1333
         * GF User Registration Add-on version > 3.x has a different class name
1334
         * @since 1.16.2
1335
         */
1336
        if ( class_exists( 'GF_User_Registration' ) ) {
1337
            remove_filter( 'gform_validation', array( GF_User_Registration::get_instance(), 'validate' ) );
1338
        } else  if ( class_exists( 'GFUser' ) ) {
1339
            remove_filter( 'gform_validation', array( 'GFUser', 'user_registration_validation' ) );
1340
        }
1341
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1342
1343
        /**
1344
         * For some crazy reason, Gravity Forms doesn't validate Edit Entry form submissions.
1345
         * You can enter whatever you want!
1346
         * We try validating, and customize the results using `self::custom_validation()`
1347
         */
1348
        add_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10, 4);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1349
1350
        // Needed by the validate funtion
1351
        $failed_validation_page = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1352
        $field_values = RGForms::post( 'gform_field_values' );
1353
1354
        // Prevent entry limit from running when editing an entry, also
1355
        // prevent form scheduling from preventing editing
1356
        unset( $this->form['limitEntries'], $this->form['scheduleForm'] );
1357
1358
        // Hide fields depending on Edit Entry settings
1359
        $this->form['fields'] = $this->get_configured_edit_fields( $this->form, $this->view_id );
1360
1361
        $this->is_valid = GFFormDisplay::validate( $this->form, $field_values, 1, $failed_validation_page );
1362
1363
        remove_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10 );
1364
    }
1365
1366
1367
    /**
1368
     * Make validation work for Edit Entry
1369
     *
1370
     * Because we're calling the GFFormDisplay::validate() in an unusual way (as a front-end
1371
     * form pretending to be a back-end form), validate() doesn't know we _can't_ edit post
1372
     * fields. This goes through all the fields and if they're an invalid post field, we
1373
     * set them as valid. If there are still issues, we'll return false.
1374
     *
1375
     * @param  [type] $validation_results [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1376
     * @return [type]                     [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1377
     */
1378
    public function custom_validation( $validation_results ) {
1379
1380
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results: ', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1381
1382
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
1383
1384
        $gv_valid = true;
1385
1386
        foreach ( $validation_results['form']['fields'] as $key => &$field ) {
1387
1388
            $value = RGFormsModel::get_field_value( $field );
1389
            $field_type = RGFormsModel::get_input_type( $field );
1390
1391
            // Validate always
1392
            switch ( $field_type ) {
1393
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1394
1395
                case 'fileupload' :
1396
                case 'post_image':
1397
1398
                    // in case nothing is uploaded but there are already files saved
1399
                    if( !empty( $field->failed_validation ) && !empty( $field->isRequired ) && !empty( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1400
                        $field->failed_validation = false;
1401
                        unset( $field->validation_message );
1402
                    }
1403
1404
                    // validate if multi file upload reached max number of files [maxFiles] => 2
1405
                    if( rgobj( $field, 'maxFiles') && rgobj( $field, 'multipleFiles') ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1406
1407
                        $input_name = 'input_' . $field->id;
1408
                        //uploaded
1409
                        $file_names = isset( GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] ) ? GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] : array();
1410
1411
                        //existent
1412
                        $entry = $this->get_entry();
1413
                        $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1414
                        if( isset( $entry[ $field->id ] ) ) {
1415
                            $value = json_decode( $entry[ $field->id ], true );
1416
                        }
1417
1418
                        // count uploaded files and existent entry files
1419
                        $count_files = count( $file_names ) + count( $value );
1420
1421
                        if( $count_files > $field->maxFiles ) {
1422
                            $field->validation_message = __( 'Maximum number of files reached', 'gravityview' );
1423
                            $field->failed_validation = 1;
1424
                            $gv_valid = false;
1425
1426
                            // in case of error make sure the newest upload files are removed from the upload input
1427
                            GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ] = null;
1428
                        }
1429
1430
                    }
1431
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1432
1433
                    break;
1434
1435
            }
1436
1437
            // This field has failed validation.
1438
            if( !empty( $field->failed_validation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1439
1440
                do_action( 'gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field is invalid.', array( 'field' => $field, 'value' => $value ) );
1441
1442
                switch ( $field_type ) {
1443
1444
                    // Captchas don't need to be re-entered.
1445
                    case 'captcha':
1446
1447
                        // Post Image fields aren't editable, so we un-fail them.
1448
                    case 'post_image':
1449
                        $field->failed_validation = false;
1450
                        unset( $field->validation_message );
1451
                        break;
1452
1453
                }
1454
1455
                // You can't continue inside a switch, so we do it after.
1456
                if( empty( $field->failed_validation ) ) {
1457
                    continue;
1458
                }
1459
1460
                // checks if the No Duplicates option is not validating entry against itself, since
1461
                // we're editing a stored entry, it would also assume it's a duplicate.
1462
                if( !empty( $field->noDuplicates ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1463
1464
                    $entry = $this->get_entry();
1465
1466
                    // If the value of the entry is the same as the stored value
1467
                    // Then we can assume it's not a duplicate, it's the same.
1468
                    if( !empty( $entry ) && $value == $entry[ $field->id ] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1469
                        //if value submitted was not changed, then don't validate
1470
                        $field->failed_validation = false;
1471
1472
                        unset( $field->validation_message );
1473
1474
                        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field not a duplicate; it is the same entry.', $entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1475
1476
                        continue;
1477
                    }
1478
                }
1479
1480
                // if here then probably we are facing the validation 'At least one field must be filled out'
1481
                if( GFFormDisplay::is_empty( $field, $this->form_id  ) && empty( $field->isRequired ) ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 2 found
Loading history...
1482
                    unset( $field->validation_message );
1483
	                $field->validation_message = false;
1484
                    continue;
1485
                }
1486
1487
                $gv_valid = false;
1488
1489
            }
1490
1491
        }
1492
1493
        $validation_results['is_valid'] = $gv_valid;
1494
1495
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results.', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1496
1497
        // We'll need this result when rendering the form ( on GFFormDisplay::get_form )
1498
        $this->form_after_validation = $validation_results['form'];
1499
1500
        return $validation_results;
1501
    }
1502
1503
1504
    /**
1505
     * TODO: This seems to be hacky... we should remove it. Entry is set when updating the form using setup_vars()!
1506
     * Get the current entry and set it if it's not yet set.
1507
     * @return array Gravity Forms entry array
1508
     */
1509
    public function get_entry() {
1510
1511
        if( empty( $this->entry ) ) {
1512
            // Get the database value of the entry that's being edited
1513
            $this->entry = gravityview_get_entry( GravityView_frontend::is_single_entry() );
1514
        }
1515
1516
        return $this->entry;
1517
    }
1518
1519
1520
1521
    // --- Filters
1522
1523
    /**
1524
     * Get the Edit Entry fields as configured in the View
1525
     *
1526
     * @since 1.8
1527
     *
1528
     * @param int $view_id
1529
     *
1530
     * @return array Array of fields that are configured in the Edit tab in the Admin
1531
     */
1532
    private function get_configured_edit_fields( $form, $view_id ) {
1533
1534
        // Get all fields for form
1535
        $properties = GravityView_View_Data::getInstance()->get_fields( $view_id );
1536
1537
        // If edit tab not yet configured, show all fields
1538
        $edit_fields = !empty( $properties['edit_edit-fields'] ) ? $properties['edit_edit-fields'] : NULL;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1539
1540
        // Show hidden fields as text fields
1541
        $form = $this->fix_survey_fields( $form );
1542
1543
        // Hide fields depending on admin settings
1544
        $fields = $this->filter_fields( $form['fields'], $edit_fields );
1545
1546
	    // If Edit Entry fields are configured, remove adminOnly field settings. Otherwise, don't.
1547
	    $fields = $this->filter_admin_only_fields( $fields, $edit_fields, $form, $view_id );
1548
1549
        /**
1550
         * @filter `gravityview/edit_entry/form_fields` Modify the fields displayed in Edit Entry form
1551
         * @since 1.17
1552
         * @param GF_Field[] $fields Gravity Forms form fields
1553
         * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1554
         * @param array $form GF Form array (`fields` key modified to have only fields configured to show in Edit Entry)
1555
         * @param int $view_id View ID
1556
         */
1557
        $fields = apply_filters( 'gravityview/edit_entry/form_fields', $fields, $edit_fields, $form, $view_id );
1558
1559
        return $fields;
1560
    }
1561
1562
    /**
1563
     * Make sure Survey fields accept pre-populating values; otherwise existing values won't be filled-in
1564
     *
1565
     * @since 1.16.4
1566
     *
1567
     * @param array $form
1568
     *
1569
     * @return array Form, with all fields set to `allowsPrepopulate => true`
1570
     */
1571
    private function fix_survey_fields( $form ) {
1572
1573
        /** @var GF_Field $field */
1574
        foreach( $form['fields'] as &$field ) {
1575
            $field->allowsPrepopulate = true;
1576
        }
1577
1578
        return $form;
1579
    }
1580
    
1581
1582
    /**
1583
     * Filter area fields based on specified conditions
1584
     *  - This filter removes the fields that have calculation configured
1585
     *
1586
     * @uses GravityView_Edit_Entry::user_can_edit_field() Check caps
1587
     * @access private
1588
     * @param GF_Field[] $fields
1589
     * @param array $configured_fields
1590
     * @since  1.5
1591
     * @return array $fields
1592
     */
1593
    private function filter_fields( $fields, $configured_fields ) {
1594
1595
        if( empty( $fields ) || !is_array( $fields ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1596
            return $fields;
1597
        }
1598
1599
        $edit_fields = array();
1600
1601
        $field_type_blacklist = array(
1602
            'page',
1603
        );
1604
1605
	    /**
1606
	     * @filter `gravityview/edit_entry/hide-product-fields` Hide product fields from being editable.
1607
	     * @since 1.9.1
1608
         * @param boolean $hide_product_fields Whether to hide product fields in the editor.  Default: false
1609
	     */
1610
	    $hide_product_fields = apply_filters( 'gravityview/edit_entry/hide-product-fields', empty( self::$supports_product_fields ) );
1611
1612
	    if( $hide_product_fields ) {
1613
		    $field_type_blacklist[] = 'option';
1614
		    $field_type_blacklist[] = 'quantity';
1615
            $field_type_blacklist[] = 'product';
1616
            $field_type_blacklist[] = 'total';
1617
            $field_type_blacklist[] = 'shipping';
1618
            $field_type_blacklist[] = 'calculation';
1619
	    }
1620
1621
        // First, remove blacklist or calculation fields
1622
        foreach ( $fields as $key => $field ) {
1623
1624
            // Remove the fields that have calculation properties and keep them to be used later
1625
            // @since 1.16.2
1626
            if( $field->has_calculation() ) {
1627
                $this->fields_with_calculation[] = $field;
1628
                // don't remove the calculation fields on form render.
1629
            }
1630
1631
            // process total field after all fields have been saved
1632
            if ( $field->type == 'total' ) {
0 ignored issues
show
introduced by
Found "== '". Use Yoda Condition checks, you must
Loading history...
1633
                $this->total_fields[] = $field;
1634
                unset( $fields[ $key ] );
1635
            }
1636
1637
            if( in_array( $field->type, $field_type_blacklist ) ) {
1638
                unset( $fields[ $key ] );
1639
            }
1640
        }
1641
1642
        // The Edit tab has not been configured, so we return all fields by default.
1643
        if( empty( $configured_fields ) ) {
1644
            return $fields;
1645
        }
1646
1647
        // The edit tab has been configured, so we loop through to configured settings
1648
        foreach ( $configured_fields as $configured_field ) {
1649
1650
	        /** @var GF_Field $field */
1651
	        foreach ( $fields as $field ) {
1652
1653
                if( intval( $configured_field['id'] ) === intval( $field->id ) && $this->user_can_edit_field( $configured_field, false ) ) {
1654
                    $edit_fields[] = $this->merge_field_properties( $field, $configured_field );
1655
                    break;
1656
                }
1657
1658
            }
1659
1660
        }
1661
1662
        return $edit_fields;
1663
1664
    }
1665
1666
    /**
1667
     * Override GF Form field properties with the ones defined on the View
1668
     * @param  GF_Field $field GF Form field object
1669
     * @param  array $field_setting  GV field options
1670
     * @since  1.5
1671
     * @return array|GF_Field
1672
     */
1673
    private function merge_field_properties( $field, $field_setting ) {
1674
1675
        $return_field = $field;
1676
1677
        if( empty( $field_setting['show_label'] ) ) {
1678
            $return_field->label = '';
1679
        } elseif ( !empty( $field_setting['custom_label'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1680
            $return_field->label = $field_setting['custom_label'];
1681
        }
1682
1683
        if( !empty( $field_setting['custom_class'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1684
            $return_field->cssClass .= ' '. gravityview_sanitize_html_class( $field_setting['custom_class'] );
1685
        }
1686
1687
        /**
1688
         * Normalize page numbers - avoid conflicts with page validation
1689
         * @since 1.6
1690
         */
1691
        $return_field->pageNumber = 1;
1692
1693
        return $return_field;
1694
1695
    }
1696
1697
    /**
1698
     * Remove fields that shouldn't be visible based on the Gravity Forms adminOnly field property
1699
     *
1700
     * @since 1.9.1
1701
     *
1702
     * @param array|GF_Field[] $fields Gravity Forms form fields
1703
     * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1704
     * @param array $form GF Form array
1705
     * @param int $view_id View ID
1706
     *
1707
     * @return array Possibly modified form array
1708
     */
1709
    private function filter_admin_only_fields( $fields = array(), $edit_fields = null, $form = array(), $view_id = 0 ) {
1710
1711
	    /**
1712
         * @filter `gravityview/edit_entry/use_gf_admin_only_setting` When Edit tab isn't configured, should the Gravity Forms "Admin Only" field settings be used to control field display to non-admins? Default: true
1713
	     * If the Edit Entry tab is not configured, adminOnly fields will not be shown to non-administrators.
1714
	     * If the Edit Entry tab *is* configured, adminOnly fields will be shown to non-administrators, using the configured GV permissions
1715
	     * @since 1.9.1
1716
	     * @param boolean $use_gf_adminonly_setting True: Hide field if set to Admin Only in GF and the user is not an admin. False: show field based on GV permissions, ignoring GF permissions.
1717
	     * @param array $form GF Form array
1718
	     * @param int $view_id View ID
1719
	     */
1720
	    $use_gf_adminonly_setting = apply_filters( 'gravityview/edit_entry/use_gf_admin_only_setting', empty( $edit_fields ), $form, $view_id );
1721
1722
	    if( $use_gf_adminonly_setting && false === GVCommon::has_cap( 'gravityforms_edit_entries', $this->entry['id'] ) ) {
1723
            foreach( $fields as $k => $field ) {
1724
                if( $field->adminOnly ) {
1725
                    unset( $fields[ $k ] );
1726
                }
1727
            }
1728
            return $fields;
1729
        }
1730
1731
	    foreach( $fields as &$field ) {
1732
		    $field->adminOnly = false;
1733
        }
1734
1735
        return $fields;
1736
    }
1737
1738
    // --- Conditional Logic
1739
1740
    /**
1741
     * Conditional logic isn't designed to work with forms that already have content. When switching input values,
1742
     * the dependent fields will be blank.
1743
     *
1744
     * Note: This is because GF populates a JavaScript variable with the input values. This is tough to filter at the input level;
1745
     * via the `gform_field_value` filter; it requires lots of legwork. Doing it at the form level is easier.
1746
     *
1747
     * @since 1.17.4
1748
     *
1749
     * @param array $form Gravity Forms array object
1750
     *
1751
     * @return array $form, modified to fix conditional
1752
     */
1753
    function prefill_conditional_logic( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1754
1755
        if( ! GFFormDisplay::has_conditional_logic( $form ) ) {
1756
            return $form;
1757
        }
1758
1759
        // Have Conditional Logic pre-fill fields as if the data were default values
1760
        /** @var GF_Field $field */
1761
        foreach ( $form['fields'] as &$field ) {
1762
1763
            if( 'checkbox' === $field->type ) {
1764
                foreach ( $field->get_entry_inputs() as $key => $input ) {
1765
                    $input_id = $input['id'];
1766
                    $choice = $field->choices[ $key ];
1767
                    $value = rgar( $this->entry, $input_id );
1768
                    $match = RGFormsModel::choice_value_match( $field, $choice, $value );
1769
                    if( $match ) {
1770
                        $field->choices[ $key ]['isSelected'] = true;
1771
                    }
1772
                }
1773
            } else {
1774
1775
                // We need to run through each field to set the default values
1776
                foreach ( $this->entry as $field_id => $field_value ) {
1777
1778
                    if( floatval( $field_id ) === floatval( $field->id ) ) {
1779
1780
                        if( 'list' === $field->type ) {
1781
                            $list_rows = maybe_unserialize( $field_value );
1782
1783
                            $list_field_value = array();
1784
                            foreach ( $list_rows as $row ) {
1785
                                foreach ( $row as $column ) {
1786
                                    $list_field_value[] = $column;
1787
                                }
1788
                            }
1789
1790
                            $field->defaultValue = $list_field_value;
1791
                        } else {
1792
                            $field->defaultValue = $field_value;
1793
                        }
1794
                    }
1795
                }
1796
            }
1797
        }
1798
1799
        return $form;
1800
    }
1801
1802
    /**
1803
     * Remove the conditional logic rules from the form button and the form fields, if needed.
1804
     *
1805
     * @todo Merge with caller method
1806
     * @since 1.9
1807
     *
1808
     * @param array $form Gravity Forms form
1809
     * @return array Modified form, if not using Conditional Logic
1810
     */
1811
    private function filter_conditional_logic( $form ) {
1812
1813
        /**
1814
         * @filter `gravityview/edit_entry/conditional_logic` Should the Edit Entry form use Gravity Forms conditional logic showing/hiding of fields?
1815
         * @since 1.9
1816
         * @param bool $use_conditional_logic True: Gravity Forms will show/hide fields just like in the original form; False: conditional logic will be disabled and fields will be shown based on configuration. Default: true
1817
         * @param array $form Gravity Forms form
1818
         */
1819
        $use_conditional_logic = apply_filters( 'gravityview/edit_entry/conditional_logic', true, $form );
1820
1821
        if( $use_conditional_logic ) {
1822
            return $form;
1823
        }
1824
1825
        foreach( $form['fields'] as &$field ) {
1826
            /* @var GF_Field $field */
1827
            $field->conditionalLogic = null;
1828
        }
1829
1830
        unset( $form['button']['conditionalLogic'] );
1831
1832
        return $form;
1833
1834
    }
1835
1836
    /**
1837
     * Disable the Gravity Forms conditional logic script and features on the Edit Entry screen
1838
     *
1839
     * @since 1.9
1840
     *
1841
     * @param $has_conditional_logic
1842
     * @param $form
1843
     * @return mixed|void
1844
     */
1845
    public function manage_conditional_logic( $has_conditional_logic, $form ) {
1846
1847
        if( ! $this->is_edit_entry() ) {
1848
            return $has_conditional_logic;
1849
        }
1850
1851
	    /** @see GravityView_Edit_Entry_Render::filter_conditional_logic for filter documentation */
1852
        return apply_filters( 'gravityview/edit_entry/conditional_logic', $has_conditional_logic, $form );
1853
    }
1854
1855
1856
    // --- User checks and nonces
1857
1858
    /**
1859
     * Check if the user can edit the entry
1860
     *
1861
     * - Is the nonce valid?
1862
     * - Does the user have the right caps for the entry
1863
     * - Is the entry in the trash?
1864
     *
1865
     * @todo Move to GVCommon
1866
     *
1867
     * @param  boolean $echo Show error messages in the form?
1868
     * @return boolean        True: can edit form. False: nope.
1869
     */
1870
    private function user_can_edit_entry( $echo = false ) {
1871
1872
        $error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1873
1874
        /**
1875
         *  1. Permalinks are turned off
1876
         *  2. There are two entries embedded using oEmbed
1877
         *  3. One of the entries has just been saved
1878
         */
1879
        if( !empty( $_POST['lid'] ) && !empty( $_GET['entry'] ) && ( $_POST['lid'] !== $_GET['entry'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1880
1881
            $error = true;
1882
1883
        }
1884
1885
        if( !empty( $_GET['entry'] ) && (string)$this->entry['id'] !== $_GET['entry'] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1886
1887
            $error = true;
1888
1889
        } elseif( ! $this->verify_nonce() ) {
1890
1891
            /**
1892
             * If the Entry is embedded, there may be two entries on the same page.
1893
             * If that's the case, and one is being edited, the other should fail gracefully and not display an error.
1894
             */
1895
            if( GravityView_oEmbed::getInstance()->get_entry_id() ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression \GravityView_oEmbed::get...tance()->get_entry_id() of type integer|null is loosely compared to true; this is ambiguous if the integer can be zero. You might want to explicitly use !== null instead.

In PHP, under loose comparison (like ==, or !=, or switch conditions), values of different types might be equal.

For integer values, zero is a special case, in particular the following results might be unexpected:

0   == false // true
0   == null  // true
123 == false // false
123 == null  // false

// It is often better to use strict comparison
0 === false // false
0 === null  // false
Loading history...
1896
                $error = true;
1897
            } else {
1898
                $error = __( 'The link to edit this entry is not valid; it may have expired.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1899
            }
1900
1901
        }
1902
1903
        if( ! GravityView_Edit_Entry::check_user_cap_edit_entry( $this->entry ) ) {
1904
            $error = __( 'You do not have permission to edit this entry.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1905
        }
1906
1907
        if( $this->entry['status'] === 'trash' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
1908
            $error = __('You cannot edit the entry; it is in the trash.', 'gravityview' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1909
        }
1910
1911
        // No errors; everything's fine here!
1912
        if( empty( $error ) ) {
1913
            return true;
1914
        }
1915
1916
        if( $echo && $error !== true ) {
0 ignored issues
show
introduced by
Found "!== true". Use Yoda Condition checks, you must
Loading history...
1917
1918
	        $error = esc_html( $error );
1919
1920
	        /**
1921
	         * @since 1.9
1922
	         */
1923
	        if ( ! empty( $this->entry ) ) {
1924
		        $error .= ' ' . gravityview_get_link( '#', _x('Go back.', 'Link shown when invalid Edit Entry link is clicked', 'gravityview' ), array( 'onclick' => "window.history.go(-1); return false;" ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal window.history.go(-1); return false; does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1925
	        }
1926
1927
            echo GVCommon::generate_notice( wpautop( $error ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1928
        }
1929
1930
        do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_entry]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1931
1932
        return false;
1933
    }
1934
1935
1936
    /**
1937
     * Check whether a field is editable by the current user, and optionally display an error message
1938
     * @uses  GravityView_Edit_Entry->check_user_cap_edit_field() Check user capabilities
1939
     * @param  array  $field Field or field settings array
1940
     * @param  boolean $echo  Whether to show error message telling user they aren't allowed
1941
     * @return boolean         True: user can edit the current field; False: nope, they can't.
1942
     */
1943
    private function user_can_edit_field( $field, $echo = false ) {
1944
1945
        $error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1946
1947
        if( ! $this->check_user_cap_edit_field( $field ) ) {
1948
            $error = __( 'You do not have permission to edit this field.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1949
        }
1950
1951
        // No errors; everything's fine here!
1952
        if( empty( $error ) ) {
1953
            return true;
1954
        }
1955
1956
        if( $echo ) {
1957
            echo GVCommon::generate_notice( wpautop( esc_html( $error ) ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1958
        }
1959
1960
        do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_field]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1961
1962
        return false;
1963
1964
    }
1965
1966
1967
    /**
1968
     * checks if user has permissions to edit a specific field
1969
     *
1970
     * Needs to be used combined with GravityView_Edit_Entry::user_can_edit_field for maximum security!!
1971
     *
1972
     * @param  [type] $field [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1973
     * @return bool
1974
     */
1975
    private function check_user_cap_edit_field( $field ) {
1976
1977
        // If they can edit any entries (as defined in Gravity Forms), we're good.
1978
        if( GVCommon::has_cap( array( 'gravityforms_edit_entries', 'gravityview_edit_others_entries' ) ) ) {
1979
            return true;
1980
        }
1981
1982
        $field_cap = isset( $field['allow_edit_cap'] ) ? $field['allow_edit_cap'] : false;
1983
1984
        // If the field has custom editing capaibilities set, check those
1985
        if( $field_cap ) {
1986
            return GVCommon::has_cap( $field['allow_edit_cap'] );
1987
        }
1988
1989
        return false;
1990
    }
1991
1992
1993
    /**
1994
     * Is the current nonce valid for editing the entry?
1995
     * @return boolean
1996
     */
1997
    public function verify_nonce() {
1998
1999
        // Verify form submitted for editing single
2000
        if( $this->is_edit_entry_submission() ) {
2001
            $valid = wp_verify_nonce( $_POST[ self::$nonce_field ], self::$nonce_field );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
2002
        }
2003
2004
        // Verify
2005
        else if( ! $this->is_edit_entry() ) {
2006
            $valid = false;
2007
        }
2008
2009
        else {
2010
            $valid = wp_verify_nonce( $_GET['edit'], self::$nonce_key );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
2011
        }
2012
2013
        /**
2014
         * @filter `gravityview/edit_entry/verify_nonce` Override Edit Entry nonce validation. Return true to declare nonce valid.
2015
         * @since 1.13
2016
         * @param int|boolean $valid False if invalid; 1 or 2 when nonce was generated
2017
         * @param string $nonce_field Key used when validating submissions. Default: is_gv_edit_entry
2018
         */
2019
        $valid = apply_filters( 'gravityview/edit_entry/verify_nonce', $valid, self::$nonce_field );
2020
2021
        return $valid;
2022
    }
2023
2024
2025
2026
} //end class