Completed
Push — develop ( 128834...24c11c )
by Zack
21:52 queued 17:30
created

modify_fileupload_settings()   A

Complexity

Conditions 2
Paths 2

Size

Total Lines 9

Duplication

Lines 0
Ratio 0 %

Code Coverage

Tests 4
CRAP Score 2.032

Importance

Changes 0
Metric Value
cc 2
nc 2
nop 3
dl 0
loc 9
ccs 4
cts 5
cp 0.8
crap 2.032
rs 9.9666
c 0
b 0
f 0
1
<?php
0 ignored issues
show
Coding Style Compatibility introduced by
For compatibility and reusability of your code, PSR1 recommends that a file should introduce either new symbols (like classes, functions, etc.) or have side-effects (like outputting something, or including other files), but not both at the same time. The first symbol is defined on line 16 and the first side effect is on line 13.

The PSR-1: Basic Coding Standard recommends that a file should either introduce new symbols, that is classes, functions, constants or similar, or have side effects. Side effects are anything that executes logic, like for example printing output, changing ini settings or writing to a file.

The idea behind this recommendation is that merely auto-loading a class should not change the state of an application. It also promotes a cleaner style of programming and makes your code less prone to errors, because the logic is not spread out all over the place.

To learn more about the PSR-1, please see the PHP-FIG site on the PSR-1.

Loading history...
2
/**
3
 * GravityView Edit Entry - render frontend
4
 *
5
 * @package   GravityView
6
 * @license   GPL2+
7
 * @author    Katz Web Services, Inc.
8
 * @link      http://gravityview.co
9
 * @copyright Copyright 2014, Katz Web Services, Inc.
10
 */
11
12
if ( ! defined( 'WPINC' ) ) {
13
	die;
14
}
15
16
class GravityView_Edit_Entry_Render {
17
18
	/**
19
	 * @var GravityView_Edit_Entry
20
	 */
21
	protected $loader;
22
23
	/**
24
	 * @var string String used to generate unique nonce for the entry/form/view combination. Allows access to edit page.
25
	 */
26
	static $nonce_key;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $nonce_key.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
27
28
	/**
29
	 * @since 1.9
30
	 * @var string String used for check valid edit entry form submission. Allows saving edit form values.
31
	 */
32
	private static $nonce_field = 'is_gv_edit_entry';
33
34
	/**
35
	 * @since 1.9
36
	 * @var bool Whether to allow save and continue functionality
37
	 */
38
	private static $supports_save_and_continue = false;
39
40
	/**
41
	 * Gravity Forms entry array
42
	 *
43
	 * @var array
44
	 */
45
	public $entry;
46
47
	/**
48
	 * Gravity Forms entry array (it won't get changed during this class lifecycle)
49
	 * @since 1.17.2
50
	 * @var array
51
	 */
52
	private static $original_entry = array();
53
54
	/**
55
	 * Gravity Forms form array (GravityView modifies the content through this class lifecycle)
56
	 *
57
	 * @var array
58
	 */
59
	public $form;
60
61
	/**
62
	 * Gravity Forms form array (it won't get changed during this class lifecycle)
63
	 * @since 1.16.2.1
64
	 * @var array
65
	 */
66
	private static $original_form;
67
68
	/**
69
	 * Gravity Forms form array after the form validation process
70
	 * @since 1.13
71
	 * @var array
72
	 */
73
	public $form_after_validation = null;
74
75
	/**
76
	 * Hold an array of GF field objects that have calculation rules
77
	 * @var array
78
	 */
79
	public $fields_with_calculation = array();
80
81
	/**
82
	 * Gravity Forms form id
83
	 *
84
	 * @var int
85
	 */
86
	public $form_id;
87
88
	/**
89
	 * ID of the current view
90
	 *
91
	 * @var int
92
	 */
93
	public $view_id;
94
95
	/**
96
	 * ID of the current post. May also be ID of the current View.
97
     *
98
     * @since 2.0.13
99
     * 
100
     * @var int
101
	 */
102
	public $post_id;
103
104
	/**
105
	 * Updated entry is valid (GF Validation object)
106
	 *
107
	 * @var array
108
	 */
109
	public $is_valid = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
110
111 3
	function __construct( GravityView_Edit_Entry $loader ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
112 3
		$this->loader = $loader;
113 3
	}
114
115 3
	function load() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
116
117
		/** @define "GRAVITYVIEW_DIR" "../../../" */
118 3
		include_once( GRAVITYVIEW_DIR .'includes/class-admin-approve-entries.php' );
119
120
		// Don't display an embedded form when editing an entry
121 3
		add_action( 'wp_head', array( $this, 'prevent_render_form' ) );
122 3
		add_action( 'wp_footer', array( $this, 'prevent_render_form' ) );
123
124
		// Stop Gravity Forms processing what is ours!
125 3
		add_filter( 'wp', array( $this, 'prevent_maybe_process_form'), 8 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
126
127 3
		add_filter( 'gravityview_is_edit_entry', array( $this, 'is_edit_entry') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
128
129 3
		add_action( 'gravityview_edit_entry', array( $this, 'init' ) );
130
131
		// Disable conditional logic if needed (since 1.9)
132 3
		add_filter( 'gform_has_conditional_logic', array( $this, 'manage_conditional_logic' ), 10, 2 );
133
134
		// Make sure GF doesn't validate max files (since 1.9)
135 3
		add_filter( 'gform_plupload_settings', array( $this, 'modify_fileupload_settings' ), 10, 3 );
136
137
		// Add fields expected by GFFormDisplay::validate()
138 3
		add_filter( 'gform_pre_validation', array( $this, 'gform_pre_validation') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
139
140
		// Fix multiselect value for GF 2.2
141 3
		add_filter( 'gravityview/edit_entry/field_value_multiselect', array( $this, 'fix_multiselect_value_serialization' ), 10, 3 );
142 3
	}
143
144
	/**
145
	 * Don't show any forms embedded on a page when GravityView is in Edit Entry mode
146
	 *
147
	 * Adds a `__return_empty_string` filter on the Gravity Forms shortcode on the `wp_head` action
148
	 * And then removes it on the `wp_footer` action
149
	 *
150
	 * @since 1.16.1
151
	 *
152
	 * @return void
153
	 */
154 1
	public function prevent_render_form() {
155 1
		if( $this->is_edit_entry() ) {
156 1
			if( 'wp_head' === current_filter() ) {
157 1
				add_filter( 'gform_shortcode_form', '__return_empty_string' );
158
			} else {
159 1
				remove_filter( 'gform_shortcode_form', '__return_empty_string' );
160
			}
161
		}
162 1
	}
163
164
	/**
165
	 * Because we're mimicking being a front-end Gravity Forms form while using a Gravity Forms
166
	 * backend form, we need to prevent them from saving twice.
167
	 * @return void
168
	 */
169
	public function prevent_maybe_process_form() {
170
171
		if( ! empty( $_POST ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
172
	        gravityview()->log->debug( 'GravityView_Edit_Entry[prevent_maybe_process_form] $_POSTed data (sanitized): ', array( 'data' => esc_html( print_r( $_POST, true ) ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
173
		}
174
175
		if( $this->is_edit_entry_submission() ) {
176
			remove_action( 'wp',  array( 'RGForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
177
	        remove_action( 'wp',  array( 'GFForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
178
		}
179
	}
180
181
	/**
182
	 * Is the current page an Edit Entry page?
183
	 * @return boolean
184
	 */
185 8
	public function is_edit_entry() {
186
187 8
		$is_edit_entry = GravityView_frontend::is_single_entry() && ! empty( $_GET['edit'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
188
189 8
		return ( $is_edit_entry || $this->is_edit_entry_submission() );
190
	}
191
192
	/**
193
	 * Is the current page an Edit Entry page?
194
	 * @since 1.9
195
	 * @return boolean
196
	 */
197 7
	public function is_edit_entry_submission() {
198 7
		return !empty( $_POST[ self::$nonce_field ] );
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
199
	}
200
201
	/**
202
	 * When Edit entry view is requested setup the vars
203
	 */
204 3
	private function setup_vars() {
205 3
        global $post;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
206
207 3
		$gravityview_view = GravityView_View::getInstance();
208
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
209
210 3
		$entries = $gravityview_view->getEntries();
211 3
	    self::$original_entry = $entries[0];
212 3
	    $this->entry = $entries[0];
213
214 3
		self::$original_form = $gravityview_view->getForm();
215 3
		$this->form = $gravityview_view->getForm();
216 3
		$this->form_id = $gravityview_view->getFormId();
217 3
		$this->view_id = $gravityview_view->getViewId();
218 3
		$this->post_id = \GV\Utils::get( $post, 'ID', null );
219
220 3
		self::$nonce_key = GravityView_Edit_Entry::get_nonce_key( $this->view_id, $this->form_id, $this->entry['id'] );
221 3
	}
222
223
224
	/**
225
	 * Load required files and trigger edit flow
226
	 *
227
	 * Run when the is_edit_entry returns true.
228
	 *
229
	 * @param \GravityView_View_Data $gv_data GravityView Data object
230
	 * @return void
231
	 */
232 4
	public function init( $gv_data ) {
233
234 4
		require_once( GFCommon::get_base_path() . '/form_display.php' );
235 4
		require_once( GFCommon::get_base_path() . '/entry_detail.php' );
236
237 4
		$this->setup_vars();
238
239 4
		if ( ! $gv_data ) {
240
			$gv_data = GravityView_View_Data::getInstance();
241
		}
242
243
		// Multiple Views embedded, don't proceed if nonce fails
244 4
		if ( $gv_data->has_multiple_views() && ! wp_verify_nonce( $_GET['edit'], self::$nonce_key ) ) {
0 ignored issues
show
Deprecated Code introduced by
The method GravityView_View_Data::has_multiple_views() has been deprecated.

This method has been deprecated.

Loading history...
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
245
			gravityview()->log->error( 'Nonce validation failed for the Edit Entry request; returning' );
246
			return;
247
		}
248
249
		// Sorry, you're not allowed here.
250 4
		if( false === $this->user_can_edit_entry( true ) ) {
251 1
			gravityview()->log->error( 'User is not allowed to edit this entry; returning', array( 'data' => $this->entry ) );
252 1
			return;
253
		}
254
255 4
		$this->print_scripts();
256
257 4
		$this->process_save();
258
259 4
		$this->edit_entry_form();
260
261 4
	}
262
263
264
	/**
265
	 * Force Gravity Forms to output scripts as if it were in the admin
266
	 * @return void
267
	 */
268 3
	private function print_scripts() {
269 3
		$gravityview_view = GravityView_View::getInstance();
270
271 3
		wp_register_script( 'gform_gravityforms', GFCommon::get_base_url().'/js/gravityforms.js', array( 'jquery', 'gform_json', 'gform_placeholder', 'sack', 'plupload-all', 'gravityview-fe-view' ) );
272
273 3
		GFFormDisplay::enqueue_form_scripts( $gravityview_view->getForm(), false);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
274
275 3
		wp_localize_script( 'gravityview-fe-view', 'gvGlobals', array( 'cookiepath' => COOKIEPATH ) );
276
277
		// Sack is required for images
278 3
		wp_print_scripts( array( 'sack', 'gform_gravityforms', 'gravityview-fe-view' ) );
279 3
	}
280
281
282
	/**
283
	 * Process edit entry form save
284
	 */
285 4
	private function process_save() {
286
287 4
		if( empty( $_POST ) || ! isset( $_POST['lid'] ) ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
288 4
			return;
289
		}
290
291
		// Make sure the entry, view, and form IDs are all correct
292 4
		$valid = $this->verify_nonce();
293
294 4
		if( !$valid ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
295
			gravityview()->log->error( 'Nonce validation failed.' );
296
			return;
297
		}
298
299 4
		if( $this->entry['id'] !== $_POST['lid'] ) {
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
300
			gravityview()->log->error( 'Entry ID did not match posted entry ID.' );
301
			return;
302
		}
303
304 4
		gravityview()->log->debug( '$_POSTed data (sanitized): ', array( 'data' => esc_html( print_r( $_POST, true ) ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
305
306 4
		$this->process_save_process_files( $this->form_id );
307
308 4
		$this->validate();
309
310 4
		if( $this->is_valid ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using ! empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
311
312 4
			gravityview()->log->debug( 'Submission is valid.' );
313
314
			/**
315
			 * @hack This step is needed to unset the adminOnly from form fields, to add the calculation fields
316
			 */
317 4
			$form = $this->form_prepare_for_save();
318
319
			/**
320
			 * @hack to avoid the capability validation of the method save_lead for GF 1.9+
321
			 */
322 4
			unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
323
324 4
			$date_created = $this->entry['date_created'];
325
326
			/**
327
			 * @hack to force Gravity Forms to use $read_value_from_post in GFFormsModel::save_lead()
328
			 * @since 1.17.2
329
			 */
330 4
			unset( $this->entry['date_created'] );
331
332 4
			GFFormsModel::save_lead( $form, $this->entry );
333
334
	        // Delete the values for hidden inputs
335 4
	        $this->unset_hidden_field_values();
336
			
337 4
			$this->entry['date_created'] = $date_created;
338
339
			// Process calculation fields
340 4
			$this->update_calculation_fields();
341
342
			// Perform actions normally performed after updating a lead
343 4
			$this->after_update();
344
345
	        /**
346
			 * Must be AFTER after_update()!
347
			 * @see https://github.com/gravityview/GravityView/issues/764
348
			 */
349 4
			$this->maybe_update_post_fields( $form );
350
351
			/**
352
			 * @action `gravityview/edit_entry/after_update` Perform an action after the entry has been updated using Edit Entry
353
			 * @param array $form Gravity Forms form array
354
			 * @param string $entry_id Numeric ID of the entry that was updated
355
			 * @param GravityView_Edit_Entry_Render $this This object
356
			 */
357 4
			do_action( 'gravityview/edit_entry/after_update', $this->form, $this->entry['id'], $this );
358
359
		} else {
360
			gravityview()->log->error( 'Submission is NOT valid.', array( 'entry' => $this->entry ) );
361
		}
362
363 4
	} // process_save
364
365
	/**
366
	 * Delete the value of fields hidden by conditional logic when the entry is edited
367
	 *
368
	 * @uses GFFormsModel::update_lead_field_value()
369
	 *
370
	 * @since 1.17.4
371
	 *
372
	 * @return void
373
	 */
374 3
	private function unset_hidden_field_values() {
375 3
	    global $wpdb;
0 ignored issues
show
Compatibility Best Practice introduced by
Use of global functionality is not recommended; it makes your code harder to test, and less reusable.

Instead of relying on global state, we recommend one of these alternatives:

1. Pass all data via parameters

function myFunction($a, $b) {
    // Do something
}

2. Create a class that maintains your state

class MyClass {
    private $a;
    private $b;

    public function __construct($a, $b) {
        $this->a = $a;
        $this->b = $b;
    }

    public function myFunction() {
        // Do something
    }
}
Loading history...
376
377
		/**
378
		 * @filter `gravityview/edit_entry/unset_hidden_field_values` Whether to delete values of fields hidden by conditional logic
379
		 * @since 1.22.2
380
		 * @param bool $unset_hidden_field_values Default: true
381
		 * @param GravityView_Edit_Entry_Render $this This object
382
		 */
383 3
		$unset_hidden_field_values = apply_filters( 'gravityview/edit_entry/unset_hidden_field_values', true, $this );
384
385 3
		if( ! $unset_hidden_field_values ) {
386
			return;
387
		}
388
389 3
		if ( version_compare( GravityView_GFFormsModel::get_database_version(), '2.3-dev-1', '>=' ) && method_exists( 'GFFormsModel', 'get_entry_meta_table_name' ) ) {
390 3
			$entry_meta_table = GFFormsModel::get_entry_meta_table_name();
391 3
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT meta_key, meta_value FROM $entry_meta_table WHERE entry_id=%d", $this->entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
392
		} else {
393
			$lead_detail_table = GFFormsModel::get_lead_details_table_name();
394
			$current_fields = $wpdb->get_results( $wpdb->prepare( "SELECT id, field_number FROM $lead_detail_table WHERE lead_id=%d", $this->entry['id'] ) );
0 ignored issues
show
introduced by
Usage of a direct database call is discouraged.
Loading history...
introduced by
Usage of a direct database call without caching is prohibited. Use wp_cache_get / wp_cache_set.
Loading history...
395
		}
396
397 3
	    foreach ( $this->entry as $input_id => $field_value ) {
398
399 3
		    $field = RGFormsModel::get_field( $this->form, $input_id );
400
401
		    // Reset fields that are hidden
402
		    // Don't pass $entry as fourth parameter; force using $_POST values to calculate conditional logic
403 3
		    if ( GFFormsModel::is_field_hidden( $this->form, $field, array(), NULL ) ) {
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
404
405
		        // List fields are stored as empty arrays when empty
406
			    $empty_value = $this->is_field_json_encoded( $field ) ? '[]' : '';
407
408
			    $lead_detail_id = GFFormsModel::get_lead_detail_id( $current_fields, $input_id );
409
410
			    GFFormsModel::update_lead_field_value( $this->form, $this->entry, $field, $lead_detail_id, $input_id, $empty_value );
411
412
			    // Prevent the $_POST values of hidden fields from being used as default values when rendering the form
413
				// after submission
414
			    $post_input_id = 'input_' . str_replace( '.', '_', $input_id );
415 3
			    $_POST[ $post_input_id ] = '';
416
		    }
417
	    }
418 3
	}
419
420
	/**
421
	 * Have GF handle file uploads
422
	 *
423
	 * Copy of code from GFFormDisplay::process_form()
424
	 *
425
	 * @param int $form_id
426
	 */
427 3
	private function process_save_process_files( $form_id ) {
428
429
		//Loading files that have been uploaded to temp folder
430 3
		$files = GFCommon::json_decode( stripslashes( RGForms::post( 'gform_uploaded_files' ) ) );
431 3
		if ( ! is_array( $files ) ) {
432 2
			$files = array();
433
		}
434
435
		/**
436
		 * Make sure the fileuploads are not overwritten if no such request was done.
437
		 * @since 1.20.1
438
		 */
439 3
		add_filter( "gform_save_field_value_$form_id", array( $this, 'save_field_value' ), 99, 5 );
440
441 3
		RGFormsModel::$uploaded_files[ $form_id ] = $files;
442 3
	}
443
444
	/**
445
	 * Make sure the fileuploads are not overwritten if no such request was done.
446
	 *
447
	 * TO ONLY BE USED INTERNALLY; DO NOT DEVELOP ON; MAY BE REMOVED AT ANY TIME.
448
	 *
449
	 * @since 1.20.1
450
	 *
451
	 * @param string $value Field value
452
	 * @param array $entry GF entry array
453
	 * @param GF_Field_FileUpload $field
454
	 * @param array $form GF form array
455
	 * @param string $input_id ID of the input being saved
456
	 *
457
	 * @return string
458
	 */
459 3
	public function save_field_value( $value = '', $entry = array(), $field = null, $form = array(), $input_id = '' ) {
460
461 3
		if ( ! $field || $field->type != 'fileupload' ) {
0 ignored issues
show
introduced by
Found "!= '". Use Yoda Condition checks, you must
Loading history...
462 3
			return $value;
463
		}
464
465 1
		$input_name = 'input_' . str_replace( '.', '_', $input_id );
466
467 1
		if ( $field->multipleFiles ) {
468
			if ( empty( $value ) ) {
469
				return json_decode( $entry[ $input_id ], true );
470
			}
471
			return $value;
472
		}
473
474
		/** No file is being uploaded. */
475 1
		if ( empty( $_FILES[ $input_name ]['name'] ) ) {
476
			/** So return the original upload */
477 1
			return $entry[ $input_id ];
478
		}
479
480 1
		return $value;
481
	}
482
483
	/**
484
	 * Remove max_files validation (done on gravityforms.js) to avoid conflicts with GravityView
485
	 * Late validation done on self::custom_validation
486
	 *
487
	 * @param $plupload_init array Plupload settings
488
	 * @param $form_id
489
	 * @param $instance
490
	 * @return mixed
491
	 */
492 1
	public function modify_fileupload_settings( $plupload_init, $form_id, $instance ) {
0 ignored issues
show
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $instance is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
493 1
		if( ! $this->is_edit_entry() ) {
494
			return $plupload_init;
495
		}
496
497 1
		$plupload_init['gf_vars']['max_files'] = 0;
498
499 1
		return $plupload_init;
500
	}
501
502
503
	/**
504
	 * Set visibility to visible and convert field input key to string
505
	 * @return array $form
506
	 */
507 3
	private function form_prepare_for_save() {
508
509 3
		$form = $this->form;
510
511
	    /** @var GF_Field $field */
512 3
		foreach( $form['fields'] as $k => &$field ) {
513
514
			/**
515
			 * Remove the fields with calculation formulas before save to avoid conflicts with GF logic
516
			 * @since 1.16.3
517
			 * @var GF_Field $field
518
			 */
519 3
			if( $field->has_calculation() ) {
520
				unset( $form['fields'][ $k ] );
521
			}
522
523 3
			$field->adminOnly = false;
524
525 3
			if( isset( $field->inputs ) && is_array( $field->inputs ) ) {
526
				foreach( $field->inputs as $key => $input ) {
527 3
				    $field->inputs[ $key ][ 'id' ] = (string)$input['id'];
0 ignored issues
show
introduced by
Array keys should NOT be surrounded by spaces if they only contain a string or an integer.
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
528
				}
529
			}
530
		}
531
532 3
		return $form;
533
	}
534
535 3
	private function update_calculation_fields() {
536
537 3
		$form = self::$original_form;
538 3
		$update = false;
539
540
		// get the most up to date entry values
541 3
		$entry = GFAPI::get_entry( $this->entry['id'] );
542
543 3
		if( !empty( $this->fields_with_calculation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
544
			$update = true;
545
			foreach ( $this->fields_with_calculation as $calc_field ) {
546
				$inputs = $calc_field->get_entry_inputs();
547
				if ( is_array( $inputs ) ) {
548
				    foreach ( $inputs as $input ) {
549
				        $input_name = 'input_' . str_replace( '.', '_', $input['id'] );
550
				        $entry[ strval( $input['id'] ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
551
				    }
552
				} else {
553
				    $input_name = 'input_' . str_replace( '.', '_', $calc_field->id);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
554
				    $entry[ strval( $calc_field->id ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
555
				}
556
			}
557
558
		}
559
560 3
		if( $update ) {
561
562
			$return_entry = GFAPI::update_entry( $entry );
563
564
			if( is_wp_error( $return_entry ) ) {
565
				gravityview()->log->error( 'Updating the entry calculation fields failed', array( 'data' => $return_entry ) );
566
			} else {
567
				gravityview()->log->debug( 'Updating the entry calculation fields succeeded' );
568
			}
569
		}
570 3
	}
571
572
	/**
573
	 * Handle updating the Post Image field
574
	 *
575
	 * Sets a new Featured Image if configured in Gravity Forms; otherwise uploads/updates media
576
	 *
577
	 * @since 1.17
578
	 *
579
	 * @uses GFFormsModel::media_handle_upload
580
	 * @uses set_post_thumbnail
581
	 * 
582
	 * @param array $form GF Form array
583
	 * @param GF_Field $field GF Field
584
	 * @param string $field_id Numeric ID of the field
585
	 * @param string $value
586
	 * @param array $entry GF Entry currently being edited
587
	 * @param int $post_id ID of the Post being edited
588
	 *
589
	 * @return mixed|string
590
	 */
591 1
	private function update_post_image( $form, $field, $field_id, $value, $entry, $post_id ) {
592
593 1
		$input_name = 'input_' . $field_id;
594
595 1
		if ( !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
596
597
			// We have a new image
598
599
			$value = RGFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'] );
600
601
			$ary = ! empty( $value ) ? explode( '|:|', $value ) : array();
602
	        $ary = stripslashes_deep( $ary );
603
			$img_url = \GV\Utils::get( $ary, 0 );
604
605
			$img_title       = count( $ary ) > 1 ? $ary[1] : '';
606
			$img_caption     = count( $ary ) > 2 ? $ary[2] : '';
607
			$img_description = count( $ary ) > 3 ? $ary[3] : '';
608
609
			$image_meta = array(
610
				'post_excerpt' => $img_caption,
611
				'post_content' => $img_description,
612
			);
613
614
			//adding title only if it is not empty. It will default to the file name if it is not in the array
615
			if ( ! empty( $img_title ) ) {
616
				$image_meta['post_title'] = $img_title;
617
			}
618
619
			/**
620
			 * todo: As soon as \GFFormsModel::media_handle_upload becomes a public method, move this call to \GFFormsModel::media_handle_upload and remove the hack from this class.
621
			 * Note: the method became public in GF 1.9.17.7, but we don't require that version yet.
622
			 */
623
			require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
624
			$media_id = GravityView_GFFormsModel::media_handle_upload( $img_url, $post_id, $image_meta );
625
626
			// is this field set as featured image?
627
			if ( $media_id && $field->postFeaturedImage ) {
628
				set_post_thumbnail( $post_id, $media_id );
629
			}
630
631 1
		} elseif ( ! empty( $_POST[ $input_name ] ) && is_array( $value ) ) {
632
633 1
			$img_url         = stripslashes_deep( $_POST[ $input_name ] );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
634 1
			$img_title       = stripslashes_deep( \GV\Utils::_POST( $input_name . '_1' ) );
635 1
			$img_caption     = stripslashes_deep( \GV\Utils::_POST( $input_name . '_4' ) );
636 1
			$img_description = stripslashes_deep( \GV\Utils::_POST( $input_name . '_7' ) );
637
638 1
			$value = ! empty( $img_url ) ? $img_url . "|:|" . $img_title . "|:|" . $img_caption . "|:|" . $img_description : '';
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal |:| does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
639
640 1
			if ( $field->postFeaturedImage ) {
641
642
				$image_meta = array(
643 1
					'ID' => get_post_thumbnail_id( $post_id ),
644 1
					'post_title' => $img_title,
645 1
					'post_excerpt' => $img_caption,
646 1
					'post_content' => $img_description,
647
				);
648
649
				// update image title, caption or description
650 1
				wp_update_post( $image_meta );
651
			}
652
		} else {
653
654
			// if we get here, image was removed or not set.
655
			$value = '';
656
657
			if ( $field->postFeaturedImage ) {
658
				delete_post_thumbnail( $post_id );
659
			}
660
		}
661
662 1
		return $value;
663
	}
664
665
	/**
666
	 * Loop through the fields being edited and if they include Post fields, update the Entry's post object
667
	 *
668
	 * @param array $form Gravity Forms form
669
	 *
670
	 * @return void
671
	 */
672 3
	private function maybe_update_post_fields( $form ) {
673
674 3
		if( empty( $this->entry['post_id'] ) ) {
675 2
	        gravityview()->log->debug( 'This entry has no post fields. Continuing...' );
676 2
			return;
677
		}
678
679 1
		$post_id = $this->entry['post_id'];
680
681
		// Security check
682 1
		if( false === GVCommon::has_cap( 'edit_post', $post_id ) ) {
683
			gravityview()->log->error( 'The current user does not have the ability to edit Post #{post_id}', array( 'post_id' => $post_id ) );
684
			return;
685
		}
686
687 1
		$update_entry = false;
688
689 1
		$updated_post = $original_post = get_post( $post_id );
690
691 1
		foreach ( $this->entry as $field_id => $value ) {
692
693 1
			$field = RGFormsModel::get_field( $form, $field_id );
694
695 1
			if( ! $field ) {
696 1
				continue;
697
			}
698
699 1
			if( GFCommon::is_post_field( $field ) && 'post_category' !== $field->type ) {
700
701
				// Get the value of the field, including $_POSTed value
702 1
				$value = RGFormsModel::get_field_value( $field );
703
704
				// Use temporary entry variable, to make values available to fill_post_template() and update_post_image()
705 1
				$entry_tmp = $this->entry;
706 1
				$entry_tmp["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
707
708 1
				switch( $field->type ) {
709
710 1
				    case 'post_title':
711
				        $post_title = $value;
712
				        if ( \GV\Utils::get( $form, 'postTitleTemplateEnabled' ) ) {
713
				            $post_title = $this->fill_post_template( $form['postTitleTemplate'], $form, $entry_tmp );
714
				        }
715
				        $updated_post->post_title = $post_title;
716
				        $updated_post->post_name  = $post_title;
717
				        unset( $post_title );
718
				        break;
719
720 1
				    case 'post_content':
721
				        $post_content = $value;
722
				        if ( \GV\Utils::get( $form, 'postContentTemplateEnabled' ) ) {
723
				            $post_content = $this->fill_post_template( $form['postContentTemplate'], $form, $entry_tmp, true );
724
				        }
725
				        $updated_post->post_content = $post_content;
726
				        unset( $post_content );
727
				        break;
728 1
				    case 'post_excerpt':
729
				        $updated_post->post_excerpt = $value;
730
				        break;
731 1
				    case 'post_tags':
732
				        wp_set_post_tags( $post_id, $value, false );
733
				        break;
734 1
				    case 'post_category':
735
				        break;
736 1
				    case 'post_custom_field':
737
						if ( is_array( $value ) && ( floatval( $field_id ) !== floatval( $field->id ) ) ) {
738
							$value = $value[ $field_id ];
739
						}
740
741
				        if( ! empty( $field->customFieldTemplateEnabled ) ) {
742
				            $value = $this->fill_post_template( $field->customFieldTemplate, $form, $entry_tmp, true );
743
				        }
744
745
	                    if ( $this->is_field_json_encoded( $field ) && ! is_string( $value ) ) {
746
		                    $value = function_exists('wp_json_encode') ? wp_json_encode( $value ) : json_encode( $value );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
747
	                    }
748
749
				        update_post_meta( $post_id, $field->postCustomFieldName, $value );
750
				        break;
751
752 1
				    case 'post_image':
753 1
				        $value = $this->update_post_image( $form, $field, $field_id, $value, $this->entry, $post_id );
754 1
				        break;
755
756
				}
757
758
				// update entry after
759 1
				$this->entry["{$field_id}"] = $value;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
760
761 1
				$update_entry = true;
762
763 1
				unset( $entry_tmp );
764
			}
765
766
		}
767
768 1
		if( $update_entry ) {
769
770 1
			$return_entry = GFAPI::update_entry( $this->entry );
771
772 1
			if( is_wp_error( $return_entry ) ) {
773
				gravityview()->log->error( 'Updating the entry post fields failed', array( 'data' => array( '$this->entry' => $this->entry, '$return_entry' => $return_entry ) ) );
774
			} else {
775 1
				gravityview()->log->debug( 'Updating the entry post fields for post #{post_id} succeeded', array( 'post_id' => $post_id ) );
776
			}
777
778
		}
779
780 1
		$return_post = wp_update_post( $updated_post, true );
781
782 1
		if( is_wp_error( $return_post ) ) {
783
			$return_post->add_data( $updated_post, '$updated_post' );
784
			gravityview()->log->error( 'Updating the post content failed', array( 'data' => compact( 'updated_post', 'return_post' ) ) );
785
		} else {
786 1
			gravityview()->log->debug( 'Updating the post content for post #{post_id} succeeded', array( 'post_id' => $post_id, 'data' => $updated_post ) );
787
		}
788 1
	}
789
790
	/**
791
	 * Is the field stored in a JSON-encoded manner?
792
	 *
793
	 * @param GF_Field $field
794
	 *
795
	 * @return bool True: stored in DB json_encode()'d; False: not encoded
796
	 */
797
	private function is_field_json_encoded( $field ) {
798
799
	    $json_encoded = false;
800
801
		$input_type = RGFormsModel::get_input_type( $field );
802
803
	    // Only certain custom field types are supported
804
	    switch( $input_type ) {
805
		    case 'fileupload':
806
		    case 'list':
807
		    case 'multiselect':
808
			    $json_encoded = true;
809
			    break;
810
	    }
811
812
	    return $json_encoded;
813
	}
814
815
	/**
816
	 * Convert a field content template into prepared output
817
	 *
818
	 * @uses GravityView_GFFormsModel::get_post_field_images()
819
	 *
820
	 * @since 1.17
821
	 *
822
	 * @param string $template The content template for the field
823
	 * @param array $form Gravity Forms form
824
	 * @param bool $do_shortcode Whether to process shortcode inside content. In GF, only run on Custom Field and Post Content fields
825
	 *
826
	 * @return string
827
	 */
828
	private function fill_post_template( $template, $form, $entry, $do_shortcode = false ) {
829
830
		require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
831
832
		$post_images = GravityView_GFFormsModel::get_post_field_images( $form, $entry );
833
834
		//replacing post image variables
835
		$output = GFCommon::replace_variables_post_image( $template, $post_images, $entry );
836
837
		//replacing all other variables
838
		$output = GFCommon::replace_variables( $output, $form, $entry, false, false, false );
839
840
		// replace conditional shortcodes
841
		if( $do_shortcode ) {
842
			$output = do_shortcode( $output );
843
		}
844
845
		return $output;
846
	}
847
848
849
	/**
850
	 * Perform actions normally performed after updating a lead
851
	 *
852
	 * @since 1.8
853
	 *
854
	 * @see GFEntryDetail::lead_detail_page()
855
	 *
856
	 * @return void
857
	 */
858 3
	private function after_update() {
859
860 3
		do_action( 'gform_after_update_entry', $this->form, $this->entry['id'], self::$original_entry );
861 3
		do_action( "gform_after_update_entry_{$this->form['id']}", $this->form, $this->entry['id'], self::$original_entry );
862
863
		// Re-define the entry now that we've updated it.
864 3
		$entry = RGFormsModel::get_lead( $this->entry['id'] );
865
866 3
		$entry = GFFormsModel::set_entry_meta( $entry, $this->form );
867
868 3
		if ( version_compare( GFFormsModel::get_database_version(), '2.3-dev-1', '<' ) ) {
869
			// We need to clear the cache because Gravity Forms caches the field values, which
870
			// we have just updated.
871
			foreach ($this->form['fields'] as $key => $field) {
0 ignored issues
show
introduced by
No space after opening parenthesis is prohibited
Loading history...
introduced by
No space before closing parenthesis is prohibited
Loading history...
872
				GFFormsModel::refresh_lead_field_value( $entry['id'], $field->id );
873
			}
874
		}
875
876 3
		$this->entry = $entry;
877 3
	}
878
879
880
	/**
881
	 * Display the Edit Entry form
882
	 *
883
	 * @return void
884
	 */
885 3
	public function edit_entry_form() {
886
887
		?>
888
889
		<div class="gv-edit-entry-wrapper"><?php
890
891 3
			$javascript = gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/inline-javascript.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
892
893
			/**
894
			 * Fixes weird wpautop() issue
895
			 * @see https://github.com/katzwebservices/GravityView/issues/451
896
			 */
897 3
			echo gravityview_strip_whitespace( $javascript );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'gravityview_strip_whitespace'
Loading history...
898
899
			?><h2 class="gv-edit-entry-title">
900
				<span><?php
901
902
				    /**
903
				     * @filter `gravityview_edit_entry_title` Modify the edit entry title
904
				     * @param string $edit_entry_title Modify the "Edit Entry" title
905
				     * @param GravityView_Edit_Entry_Render $this This object
906
				     */
907 3
				    $edit_entry_title = apply_filters('gravityview_edit_entry_title', __('Edit Entry', 'gravityview'), $this );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
908
909 3
				    echo esc_attr( $edit_entry_title );
910
			?></span>
911
			</h2>
912
913
			<?php $this->maybe_print_message(); ?>
914
915
			<?php // The ID of the form needs to be `gform_{form_id}` for the pluploader ?>
916
917
			<form method="post" id="gform_<?php echo $this->form_id; ?>" enctype="multipart/form-data">
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$this'
Loading history...
918
919
				<?php
920
921 3
				wp_nonce_field( self::$nonce_key, self::$nonce_key );
922
923 3
				wp_nonce_field( self::$nonce_field, self::$nonce_field, false );
924
925
				// Print the actual form HTML
926 3
				$this->render_edit_form();
927
928
				?>
929 3
			</form>
930
931
			<script>
932
				gform.addFilter('gform_reset_pre_conditional_logic_field_action', function ( reset, formId, targetId, defaultValues, isInit ) {
933
				    return false;
934
				});
935
			</script>
936
937
		</div>
938
939
	<?php
940 3
	}
941
942
	/**
943
	 * Display success or error message if the form has been submitted
944
	 *
945
	 * @uses GVCommon::generate_notice
946
	 *
947
	 * @since 1.16.2.2
948
	 *
949
	 * @return void
950
	 */
951 3
	private function maybe_print_message() {
952
953 3
		if ( \GV\Utils::_POST( 'action' ) === 'update' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
954
955
			$back_link = esc_url( remove_query_arg( array( 'page', 'view', 'edit' ) ) );
956
957
			if( ! $this->is_valid ){
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
958
959
				// Keeping this compatible with Gravity Forms.
960
				$validation_message = "<div class='validation_error'>" . __('There was a problem with your submission.', 'gravityview') . " " . __('Errors have been highlighted below.', 'gravityview') . "</div>";
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw '__'
Loading history...
Coding Style Comprehensibility introduced by
The string literal </div> does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
961
				$message = apply_filters("gform_validation_message_{$this->form['id']}", apply_filters("gform_validation_message", $validation_message, $this->form), $this->form);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal gform_validation_message does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
962
963
				echo GVCommon::generate_notice( $message , 'gv-error' );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
964
965
			} else {
966
				$entry_updated_message = sprintf( esc_attr__('Entry Updated. %sReturn to Entry%s', 'gravityview'), '<a href="'. $back_link .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
967
968
				/**
969
				 * @filter `gravityview/edit_entry/success` Modify the edit entry success message (including the anchor link)
970
				 * @since 1.5.4
971
				 * @param string $entry_updated_message Existing message
972
				 * @param int $view_id View ID
973
				 * @param array $entry Gravity Forms entry array
974
				 * @param string $back_link URL to return to the original entry. @since 1.6
975
				 */
976
				$message = apply_filters( 'gravityview/edit_entry/success', $entry_updated_message , $this->view_id, $this->entry, $back_link );
977
978
				echo GVCommon::generate_notice( $message );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
979
			}
980
981
		}
982 3
	}
983
984
	/**
985
	 * Display the Edit Entry form in the original Gravity Forms format
986
	 *
987
	 * @since 1.9
988
	 *
989
	 * @return void
990
	 */
991 3
	private function render_edit_form() {
992
993
		/**
994
		 * @action `gravityview/edit-entry/render/before` Before rendering the Edit Entry form
995
		 * @since 1.17
996
		 * @param GravityView_Edit_Entry_Render $this
997
		 */
998 3
		do_action( 'gravityview/edit-entry/render/before', $this );
999
1000 3
		add_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields'), 5000, 3 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
1001 3
		add_filter( 'gform_submit_button', array( $this, 'render_form_buttons') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
1002 3
		add_filter( 'gform_disable_view_counter', '__return_true' );
1003
1004 3
		add_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5, 5 );
1005 3
		add_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10, 5 );
1006
1007
		// We need to remove the fake $_GET['page'] arg to avoid rendering form as if in admin.
1008 3
		unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
1009
1010
		// TODO: Verify multiple-page forms
1011
1012 3
		ob_start(); // Prevent PHP warnings possibly caused by prefilling list fields for conditional logic
1013
1014 3
		$html = GFFormDisplay::get_form( $this->form['id'], false, false, true, $this->entry );
1015
1016 3
		ob_get_clean();
1017
1018 3
	    remove_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields' ), 5000 );
1019 3
		remove_filter( 'gform_submit_button', array( $this, 'render_form_buttons' ) );
1020 3
		remove_filter( 'gform_disable_view_counter', '__return_true' );
1021 3
		remove_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5 );
1022 3
		remove_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10 );
1023
1024 3
		echo $html;
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$html'
Loading history...
1025
1026
		/**
1027
		 * @action `gravityview/edit-entry/render/after` After rendering the Edit Entry form
1028
		 * @since 1.17
1029
		 * @param GravityView_Edit_Entry_Render $this
1030
		 */
1031 3
		do_action( 'gravityview/edit-entry/render/after', $this );
1032 3
	}
1033
1034
	/**
1035
	 * Display the Update/Cancel/Delete buttons for the Edit Entry form
1036
	 * @since 1.8
1037
	 * @return string
1038
	 */
1039 3
	public function render_form_buttons() {
1040 3
		return gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/form-buttons.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
1041
	}
1042
1043
1044
	/**
1045
	 * Modify the form fields that are shown when using GFFormDisplay::get_form()
1046
	 *
1047
	 * By default, all fields will be shown. We only want the Edit Tab configured fields to be shown.
1048
	 *
1049
	 * @param array $form
1050
	 * @param boolean $ajax Whether in AJAX mode
1051
	 * @param array|string $field_values Passed parameters to the form
1052
	 *
1053
	 * @since 1.9
1054
	 *
1055
	 * @return array Modified form array
1056
	 */
1057 3
	public function filter_modify_form_fields( $form, $ajax = false, $field_values = '' ) {
0 ignored issues
show
Unused Code introduced by
The parameter $ajax is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $field_values is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1058
1059
		// In case we have validated the form, use it to inject the validation results into the form render
1060 3
		if( isset( $this->form_after_validation ) ) {
1061 3
			$form = $this->form_after_validation;
1062
		} else {
1063 3
			$form['fields'] = $this->get_configured_edit_fields( $form, $this->view_id );
1064
		}
1065
1066 3
		$form = $this->filter_conditional_logic( $form );
1067
1068 3
		$form = $this->prefill_conditional_logic( $form );
1069
1070
		// for now we don't support Save and Continue feature.
1071 3
		if( ! self::$supports_save_and_continue ) {
1072 3
	        unset( $form['save'] );
1073
		}
1074
1075 3
		return $form;
1076
	}
1077
1078
	/**
1079
	 * When displaying a field, check if it's a Post Field, and if so, make sure the post exists and current user has edit rights.
1080
	 *
1081
	 * @since 1.16.2.2
1082
	 *
1083
	 * @param string $field_content Always empty. Returning not-empty overrides the input.
1084
	 * @param GF_Field $field
1085
	 * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1086
	 * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1087
	 * @param int $form_id Form ID
1088
	 *
1089
	 * @return string If error, the error message. If no error, blank string (modify_edit_field_input() runs next)
1090
	 */
1091 3
	public function verify_user_can_edit_post( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1092
1093 3
		if( GFCommon::is_post_field( $field ) ) {
1094
1095 1
			$message = null;
1096
1097
			// First, make sure they have the capability to edit the post.
1098 1
			if( false === current_user_can( 'edit_post', $this->entry['post_id'] ) ) {
1099
1100
				/**
1101
				 * @filter `gravityview/edit_entry/unsupported_post_field_text` Modify the message when someone isn't able to edit a post
1102
				 * @param string $message The existing "You don't have permission..." text
1103
				 */
1104
				$message = apply_filters('gravityview/edit_entry/unsupported_post_field_text', __('You don&rsquo;t have permission to edit this post.', 'gravityview') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1105
1106 1
			} elseif( null === get_post( $this->entry['post_id'] ) ) {
1107
				/**
1108
				 * @filter `gravityview/edit_entry/no_post_text` Modify the message when someone is editing an entry attached to a post that no longer exists
1109
				 * @param string $message The existing "This field is not editable; the post no longer exists." text
1110
				 */
1111
				$message = apply_filters('gravityview/edit_entry/no_post_text', __('This field is not editable; the post no longer exists.', 'gravityview' ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1112
			}
1113
1114 1
			if( $message ) {
1115
				$field_content = sprintf('<div class="ginput_container ginput_container_' . $field->type . '">%s</div>', wpautop( $message ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1116
			}
1117
		}
1118
1119 3
		return $field_content;
1120
	}
1121
1122
	/**
1123
	 *
1124
	 * Fill-in the saved values into the form inputs
1125
	 *
1126
	 * @param string $field_content Always empty. Returning not-empty overrides the input.
1127
	 * @param GF_Field $field
1128
	 * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
1129
	 * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
1130
	 * @param int $form_id Form ID
1131
	 *
1132
	 * @return mixed
1133
	 */
1134 3
	public function modify_edit_field_input( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
1135
1136 3
		$gv_field = GravityView_Fields::get_associated_field( $field );
1137
1138
		// If the form has been submitted, then we don't need to pre-fill the values,
1139
		// Except for fileupload type and when a field input is overridden- run always!!
1140
		if(
1141 3
			( $this->is_edit_entry_submission() && !in_array( $field->type, array( 'fileupload', 'post_image' ) ) )
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1142 3
			&& false === ( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) )
1143
			&& ! GFCommon::is_product_field( $field->type )
1144 3
			|| ! empty( $field_content )
1145 3
			|| in_array( $field->type, array( 'honeypot' ) )
1146
		) {
1147
	        return $field_content;
1148
		}
1149
1150
		// SET SOME FIELD DEFAULTS TO PREVENT ISSUES
1151 3
		$field->adminOnly = false; /** @see GFFormDisplay::get_counter_init_script() need to prevent adminOnly */
1152
1153 3
		$field_value = $this->get_field_value( $field );
1154
1155
	    // Prevent any PHP warnings, like undefined index
1156 3
	    ob_start();
1157
1158 3
	    $return = null;
1159
1160
		/** @var GravityView_Field $gv_field */
1161 3
		if( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) ) {
1162 2
			$return = $gv_field->get_field_input( $this->form, $field_value, $this->entry, $field );
1163
		} else {
1164 3
	        $return = $field->get_field_input( $this->form, $field_value, $this->entry );
1165
	    }
1166
1167
	    // If there was output, it's an error
1168 3
	    $warnings = ob_get_clean();
1169
1170 3
	    if( !empty( $warnings ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1171
		    gravityview()->log->error( '{warning}', array( 'warning' => $warnings, 'data' => $field_value ) );
1172
	    }
1173
1174 3
		return $return;
1175
	}
1176
1177
	/**
1178
	 * Modify the value for the current field input
1179
	 *
1180
	 * @param GF_Field $field
1181
	 *
1182
	 * @return array|mixed|string
1183
	 */
1184 3
	private function get_field_value( $field ) {
1185
1186
		/**
1187
		 * @filter `gravityview/edit_entry/pre_populate/override` Allow the pre-populated value to override saved value in Edit Entry form. By default, pre-populate mechanism only kicks on empty fields.
1188
		 * @param boolean True: override saved values; False: don't override (default)
1189
		 * @param $field GF_Field object Gravity Forms field object
1190
		 * @since 1.13
1191
		 */
1192 3
		$override_saved_value = apply_filters( 'gravityview/edit_entry/pre_populate/override', false, $field );
1193
1194
		// We're dealing with multiple inputs (e.g. checkbox) but not time or date (as it doesn't store data in input IDs)
1195 3
		if( isset( $field->inputs ) && is_array( $field->inputs ) && !in_array( $field->type, array( 'time', 'date' ) ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1196
1197
			$field_value = array();
1198
1199
			// only accept pre-populated values if the field doesn't have any choice selected.
1200
			$allow_pre_populated = $field->allowsPrepopulate;
1201
1202
			foreach ( (array)$field->inputs as $input ) {
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1203
1204
				$input_id = strval( $input['id'] );
1205
				
1206
				if ( isset( $this->entry[ $input_id ] ) && ! gv_empty( $this->entry[ $input_id ], false, false ) ) {
1207
				    $field_value[ $input_id ] =  'post_category' === $field->type ? GFCommon::format_post_category( $this->entry[ $input_id ], true ) : $this->entry[ $input_id ];
0 ignored issues
show
introduced by
Expected 1 space after "="; 2 found
Loading history...
1208
				    $allow_pre_populated = false;
1209
				}
1210
1211
			}
1212
1213
			$pre_value = $field->get_value_submission( array(), false );
1214
1215
			$field_value = ! $allow_pre_populated && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $field_value : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1216
1217
		} else {
1218
1219 3
			$id = intval( $field->id );
1220
1221
			// get pre-populated value if exists
1222 3
			$pre_value = $field->allowsPrepopulate ? GFFormsModel::get_parameter_value( $field->inputName, array(), $field ) : '';
1223
1224
			// saved field entry value (if empty, fallback to the pre-populated value, if exists)
1225
			// or pre-populated value if not empty and set to override saved value
1226 3
			$field_value = isset( $this->entry[ $id ] ) && ! gv_empty( $this->entry[ $id ], false, false ) && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $this->entry[ $id ] : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1227
1228
			// in case field is post_category but inputType is select, multi-select or radio, convert value into array of category IDs.
1229 3
			if ( 'post_category' === $field->type && !gv_empty( $field_value, false, false ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1230
				$categories = array();
1231
				foreach ( explode( ',', $field_value ) as $cat_string ) {
1232
				    $categories[] = GFCommon::format_post_category( $cat_string, true );
1233
				}
1234
				$field_value = 'multiselect' === $field->get_input_type() ? $categories : implode( '', $categories );
1235
			}
1236
1237
		}
1238
1239
		// if value is empty get the default value if defined
1240 3
		$field_value = $field->get_value_default_if_empty( $field_value );
1241
1242
	    /**
1243
	     * @filter `gravityview/edit_entry/field_value` Change the value of an Edit Entry field, if needed
1244
	     * @since 1.11
1245
	     * @since 1.20 Added third param
1246
	     * @param mixed $field_value field value used to populate the input
1247
	     * @param object $field Gravity Forms field object ( Class GF_Field )
1248
	     * @param GravityView_Edit_Entry_Render $this Current object
1249
	     */
1250 3
	    $field_value = apply_filters( 'gravityview/edit_entry/field_value', $field_value, $field, $this );
1251
1252
	    /**
1253
	     * @filter `gravityview/edit_entry/field_value_{field_type}` Change the value of an Edit Entry field for a specific field type
1254
	     * @since 1.17
1255
	     * @since 1.20 Added third param
1256
	     * @param mixed $field_value field value used to populate the input
1257
	     * @param GF_Field $field Gravity Forms field object
1258
	     * @param GravityView_Edit_Entry_Render $this Current object
1259
	     */
1260 3
	    $field_value = apply_filters( 'gravityview/edit_entry/field_value_' . $field->type , $field_value, $field, $this );
1261
1262 3
		return $field_value;
1263
	}
1264
1265
1266
	// ---- Entry validation
1267
1268
	/**
1269
	 * Add field keys that Gravity Forms expects.
1270
	 *
1271
	 * @see GFFormDisplay::validate()
1272
	 * @param  array $form GF Form
1273
	 * @return array       Modified GF Form
1274
	 */
1275 3
	public function gform_pre_validation( $form ) {
1276
1277 3
		if( ! $this->verify_nonce() ) {
1278
			return $form;
1279
		}
1280
1281
		// Fix PHP warning regarding undefined index.
1282 3
		foreach ( $form['fields'] as &$field) {
0 ignored issues
show
introduced by
No space before closing parenthesis is prohibited
Loading history...
1283
1284
			// This is because we're doing admin form pretending to be front-end, so Gravity Forms
1285
			// expects certain field array items to be set.
1286 3
			foreach ( array( 'noDuplicates', 'adminOnly', 'inputType', 'isRequired', 'enablePrice', 'inputs', 'allowedExtensions' ) as $key ) {
1287 3
	            $field->{$key} = isset( $field->{$key} ) ? $field->{$key} : NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1288
			}
1289
1290 3
			switch( RGFormsModel::get_input_type( $field ) ) {
1291
1292
				/**
1293
				 * this whole fileupload hack is because in the admin, Gravity Forms simply doesn't update any fileupload field if it's empty, but it DOES in the frontend.
1294
				 *
1295
				 * What we have to do is set the value so that it doesn't get overwritten as empty on save and appears immediately in the Edit Entry screen again.
1296
				 *
1297
				 * @hack
1298
				 */
1299 3
				case 'fileupload':
1300
1301
				    // Set the previous value
1302 1
				    $entry = $this->get_entry();
1303
1304 1
				    $input_name = 'input_'.$field->id;
1305 1
				    $form_id = $form['id'];
1306
1307 1
				    $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1308
1309
				    // Use the previous entry value as the default.
1310 1
				    if( isset( $entry[ $field->id ] ) ) {
1311 1
				        $value = $entry[ $field->id ];
1312
				    }
1313
1314
				    // If this is a single upload file
1315 1
				    if( !empty( $_FILES[ $input_name ] ) && !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1316 1
				        $file_path = GFFormsModel::get_file_upload_path( $form['id'], $_FILES[ $input_name ]['name'] );
1317 1
				        $value = $file_path['url'];
1318
1319
				    } else {
1320
1321
				        // Fix PHP warning on line 1498 of form_display.php for post_image fields
1322
				        // Fix PHP Notice:  Undefined index:  size in form_display.php on line 1511
1323 1
				        $_FILES[ $input_name ] = array('name' => '', 'size' => '' );
0 ignored issues
show
introduced by
No space after opening parenthesis of array is bad style
Loading history...
1324
1325
				    }
1326
1327 1
				    if ( \GV\Utils::get( $field, "multipleFiles" ) ) {
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal multipleFiles does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1328
1329
				        // If there are fresh uploads, process and merge them.
1330
				        // Otherwise, use the passed values, which should be json-encoded array of URLs
1331 1
				        if( isset( GFFormsModel::$uploaded_files[$form_id][$input_name] ) ) {
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1332
				            $value = empty( $value ) ? '[]' : $value;
1333
				            $value = stripslashes_deep( $value );
1334 1
				            $value = GFFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'], array());
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1335
				        }
1336
1337
				    } else {
1338
1339
				        // A file already exists when editing an entry
1340
				        // We set this to solve issue when file upload fields are required.
1341 1
				        GFFormsModel::$uploaded_files[ $form_id ][ $input_name ] = $value;
1342
1343
				    }
1344
1345 1
				    $this->entry[ $input_name ] = $value;
1346 1
				    $_POST[ $input_name ] = $value;
1347
1348 1
				    break;
1349
1350 3
				case 'number':
1351
				    // Fix "undefined index" issue at line 1286 in form_display.php
1352 1
				    if( !isset( $_POST['input_'.$field->id ] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1353
				        $_POST['input_'.$field->id ] = NULL;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1354
				    }
1355 3
				    break;
1356
			}
1357
1358
		}
1359
1360 3
		return $form;
1361
	}
1362
1363
1364
	/**
1365
	 * Process validation for a edit entry submission
1366
	 *
1367
	 * Sets the `is_valid` object var
1368
	 *
1369
	 * @return void
1370
	 */
1371 4
	private function validate() {
1372
1373
		/**
1374
		 * If using GF User Registration Add-on, remove the validation step, otherwise generates error when updating the entry
1375
		 * GF User Registration Add-on version > 3.x has a different class name
1376
		 * @since 1.16.2
1377
		 */
1378 4
		if ( class_exists( 'GF_User_Registration' ) ) {
1379 4
			remove_filter( 'gform_validation', array( GF_User_Registration::get_instance(), 'validate' ) );
1380
		} else  if ( class_exists( 'GFUser' ) ) {
1381
			remove_filter( 'gform_validation', array( 'GFUser', 'user_registration_validation' ) );
1382
		}
1383
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1384
1385
		/**
1386
		 * For some crazy reason, Gravity Forms doesn't validate Edit Entry form submissions.
1387
		 * You can enter whatever you want!
1388
		 * We try validating, and customize the results using `self::custom_validation()`
1389
		 */
1390 4
		add_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10, 4);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1391
1392
		// Needed by the validate funtion
1393 4
		$failed_validation_page = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1394 4
		$field_values = RGForms::post( 'gform_field_values' );
1395
1396
		// Prevent entry limit from running when editing an entry, also
1397
		// prevent form scheduling from preventing editing
1398 4
		unset( $this->form['limitEntries'], $this->form['scheduleForm'] );
1399
1400
		// Hide fields depending on Edit Entry settings
1401 4
		$this->form['fields'] = $this->get_configured_edit_fields( $this->form, $this->view_id );
1402
1403 4
		$this->is_valid = GFFormDisplay::validate( $this->form, $field_values, 1, $failed_validation_page );
1404
1405 4
		remove_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10 );
1406 4
	}
1407
1408
1409
	/**
1410
	 * Make validation work for Edit Entry
1411
	 *
1412
	 * Because we're calling the GFFormDisplay::validate() in an unusual way (as a front-end
1413
	 * form pretending to be a back-end form), validate() doesn't know we _can't_ edit post
1414
	 * fields. This goes through all the fields and if they're an invalid post field, we
1415
	 * set them as valid. If there are still issues, we'll return false.
1416
	 *
1417
	 * @param  [type] $validation_results [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1418
	 * @return [type]                     [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1419
	 */
1420 4
	public function custom_validation( $validation_results ) {
1421
1422 4
		gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Validation results: ', array( 'data' => $validation_results ) );
1423
1424 4
		gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] $_POSTed data (sanitized): ', array( 'data' => esc_html( print_r( $_POST, true ) ) ) );
0 ignored issues
show
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
1425
1426 4
		$gv_valid = true;
1427
1428 4
		foreach ( $validation_results['form']['fields'] as $key => &$field ) {
1429
1430 4
			$value = RGFormsModel::get_field_value( $field );
1431 4
			$field_type = RGFormsModel::get_input_type( $field );
1432
1433
			// Validate always
1434 4
			switch ( $field_type ) {
1435
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1436
1437 4
				case 'fileupload' :
1438 4
				case 'post_image':
1439
1440
				    // in case nothing is uploaded but there are already files saved
1441 2
				    if( !empty( $field->failed_validation ) && !empty( $field->isRequired ) && !empty( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1442
				        $field->failed_validation = false;
1443
				        unset( $field->validation_message );
1444
				    }
1445
1446
				    // validate if multi file upload reached max number of files [maxFiles] => 2
1447 2
				    if( \GV\Utils::get( $field, 'maxFiles') && \GV\Utils::get( $field, 'multipleFiles') ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1448
1449
				        $input_name = 'input_' . $field->id;
1450
				        //uploaded
1451
				        $file_names = isset( GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] ) ? GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] : array();
1452
1453
				        //existent
1454
				        $entry = $this->get_entry();
1455
				        $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1456
				        if( isset( $entry[ $field->id ] ) ) {
1457
				            $value = json_decode( $entry[ $field->id ], true );
1458
				        }
1459
1460
				        // count uploaded files and existent entry files
1461
				        $count_files = count( $file_names ) + count( $value );
1462
1463
				        if( $count_files > $field->maxFiles ) {
1464
				            $field->validation_message = __( 'Maximum number of files reached', 'gravityview' );
1465
				            $field->failed_validation = 1;
1466
				            $gv_valid = false;
1467
1468
				            // in case of error make sure the newest upload files are removed from the upload input
1469
				            GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ] = null;
1470
				        }
1471
1472
				    }
1473
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1474
1475 2
				    break;
1476
1477
			}
1478
1479
			// This field has failed validation.
1480 4
			if( !empty( $field->failed_validation ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1481
1482 1
				gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Field is invalid.', array( 'data' => array( 'field' => $field, 'value' => $value ) ) );
1483
1484 1
				switch ( $field_type ) {
1485
1486
				    // Captchas don't need to be re-entered.
1487 1
				    case 'captcha':
1488
1489
				        // Post Image fields aren't editable, so we un-fail them.
1490 1
				    case 'post_image':
1491
				        $field->failed_validation = false;
1492
				        unset( $field->validation_message );
1493
				        break;
1494
1495
				}
1496
1497
				// You can't continue inside a switch, so we do it after.
1498 1
				if( empty( $field->failed_validation ) ) {
1499
				    continue;
1500
				}
1501
1502
				// checks if the No Duplicates option is not validating entry against itself, since
1503
				// we're editing a stored entry, it would also assume it's a duplicate.
1504 1
				if( !empty( $field->noDuplicates ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1505
1506
				    $entry = $this->get_entry();
1507
1508
				    // If the value of the entry is the same as the stored value
1509
				    // Then we can assume it's not a duplicate, it's the same.
1510
				    if( !empty( $entry ) && $value == $entry[ $field->id ] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1511
				        //if value submitted was not changed, then don't validate
1512
				        $field->failed_validation = false;
1513
1514
				        unset( $field->validation_message );
1515
1516
				        gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Field not a duplicate; it is the same entry.', array( 'data' => $entry ) );
1517
1518
				        continue;
1519
				    }
1520
				}
1521
1522
				// if here then probably we are facing the validation 'At least one field must be filled out'
1523 1
				if( GFFormDisplay::is_empty( $field, $this->form_id  ) && empty( $field->isRequired ) ) {
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 2 found
Loading history...
1524
				    unset( $field->validation_message );
1525
	                $field->validation_message = false;
1526
				    continue;
1527
				}
1528
1529 4
				$gv_valid = false;
1530
1531
			}
1532
1533
		}
1534
1535 4
		$validation_results['is_valid'] = $gv_valid;
1536
1537 4
		gravityview()->log->debug( 'GravityView_Edit_Entry[custom_validation] Validation results.', array( 'data' => $validation_results ) );
1538
1539
		// We'll need this result when rendering the form ( on GFFormDisplay::get_form )
1540 4
		$this->form_after_validation = $validation_results['form'];
1541
1542 4
		return $validation_results;
1543
	}
1544
1545
1546
	/**
1547
	 * TODO: This seems to be hacky... we should remove it. Entry is set when updating the form using setup_vars()!
1548
	 * Get the current entry and set it if it's not yet set.
1549
	 * @return array Gravity Forms entry array
1550
	 */
1551 1
	public function get_entry() {
1552
1553 1
		if( empty( $this->entry ) ) {
1554
			// Get the database value of the entry that's being edited
1555 1
			$this->entry = gravityview_get_entry( GravityView_frontend::is_single_entry() );
1556
		}
1557
1558 1
		return $this->entry;
1559
	}
1560
1561
1562
1563
	// --- Filters
1564
1565
	/**
1566
	 * Get the Edit Entry fields as configured in the View
1567
	 *
1568
	 * @since 1.8
1569
	 *
1570
	 * @param int $view_id
1571
	 *
1572
	 * @return array Array of fields that are configured in the Edit tab in the Admin
1573
	 */
1574 4
	private function get_configured_edit_fields( $form, $view_id ) {
1575
1576
		// Get all fields for form
1577 4
		if ( \GV\View::exists( $view_id ) ) {
1578 4
			$view = \GV\View::by_id( $view_id );
1579 4
			$properties = $view->fields ? $view->fields->as_configuration() : array();
1580
		} else {
1581
			$properties = null;
1582
		}
1583
1584
		// If edit tab not yet configured, show all fields
1585 4
		$edit_fields = !empty( $properties['edit_edit-fields'] ) ? $properties['edit_edit-fields'] : NULL;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1586
1587
		// Hide fields depending on admin settings
1588 4
		$fields = $this->filter_fields( $form['fields'], $edit_fields );
1589
1590
	    // If Edit Entry fields are configured, remove adminOnly field settings. Otherwise, don't.
1591 4
	    $fields = $this->filter_admin_only_fields( $fields, $edit_fields, $form, $view_id );
1592
1593
		/**
1594
		 * @filter `gravityview/edit_entry/form_fields` Modify the fields displayed in Edit Entry form
1595
		 * @since 1.17
1596
		 * @param GF_Field[] $fields Gravity Forms form fields
1597
		 * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1598
		 * @param array $form GF Form array (`fields` key modified to have only fields configured to show in Edit Entry)
1599
		 * @param int $view_id View ID
1600
		 */
1601 4
		$fields = apply_filters( 'gravityview/edit_entry/form_fields', $fields, $edit_fields, $form, $view_id );
1602
1603 4
		return $fields;
1604
	}
1605
1606
1607
	/**
1608
	 * Filter area fields based on specified conditions
1609
	 *  - This filter removes the fields that have calculation configured
1610
	 *
1611
	 * @uses GravityView_Edit_Entry::user_can_edit_field() Check caps
1612
	 * @access private
1613
	 * @param GF_Field[] $fields
1614
	 * @param array $configured_fields
1615
	 * @since  1.5
1616
	 * @return array $fields
1617
	 */
1618 3
	private function filter_fields( $fields, $configured_fields ) {
1619
1620 3
		if( empty( $fields ) || !is_array( $fields ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1621
			return $fields;
1622
		}
1623
1624 3
		$edit_fields = array();
1625
1626 3
		$field_type_blacklist = $this->loader->get_field_blacklist( $this->entry );
1627
1628
		// First, remove blacklist or calculation fields
1629 3
		foreach ( $fields as $key => $field ) {
1630
1631
			// Remove the fields that have calculation properties and keep them to be used later
1632
			// @since 1.16.2
1633 3
			if( $field->has_calculation() ) {
1634
				$this->fields_with_calculation[] = $field;
1635
				// don't remove the calculation fields on form render.
1636
			}
1637
1638 3
			if( in_array( $field->type, $field_type_blacklist ) ) {
1639 3
				unset( $fields[ $key ] );
1640
			}
1641
		}
1642
1643
		// The Edit tab has not been configured, so we return all fields by default.
1644 3
		if( empty( $configured_fields ) ) {
1645 3
			return $fields;
1646
		}
1647
1648
		// The edit tab has been configured, so we loop through to configured settings
1649
		foreach ( $configured_fields as $configured_field ) {
1650
1651
	        /** @var GF_Field $field */
1652
	        foreach ( $fields as $field ) {
1653
				if( intval( $configured_field['id'] ) === intval( $field->id ) && $this->user_can_edit_field( $configured_field, false ) ) {
1654
				    $edit_fields[] = $this->merge_field_properties( $field, $configured_field );
1655
				    break;
1656
				}
1657
1658
			}
1659
1660
		}
1661
1662
		return $edit_fields;
1663
1664
	}
1665
1666
	/**
1667
	 * Override GF Form field properties with the ones defined on the View
1668
	 * @param  GF_Field $field GF Form field object
1669
	 * @param  array $field_setting  GV field options
1670
	 * @since  1.5
1671
	 * @return array|GF_Field
1672
	 */
1673
	private function merge_field_properties( $field, $field_setting ) {
1674
1675
		$return_field = $field;
1676
1677
		if( empty( $field_setting['show_label'] ) ) {
1678
			$return_field->label = '';
1679
		} elseif ( !empty( $field_setting['custom_label'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1680
			$return_field->label = $field_setting['custom_label'];
1681
		}
1682
1683
		if( !empty( $field_setting['custom_class'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1684
			$return_field->cssClass .= ' '. gravityview_sanitize_html_class( $field_setting['custom_class'] );
1685
		}
1686
1687
		/**
1688
		 * Normalize page numbers - avoid conflicts with page validation
1689
		 * @since 1.6
1690
		 */
1691
		$return_field->pageNumber = 1;
1692
1693
		return $return_field;
1694
1695
	}
1696
1697
	/**
1698
	 * Remove fields that shouldn't be visible based on the Gravity Forms adminOnly field property
1699
	 *
1700
	 * @since 1.9.1
1701
	 *
1702
	 * @param array|GF_Field[] $fields Gravity Forms form fields
1703
	 * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1704
	 * @param array $form GF Form array
1705
	 * @param int $view_id View ID
1706
	 *
1707
	 * @return array Possibly modified form array
1708
	 */
1709 3
	private function filter_admin_only_fields( $fields = array(), $edit_fields = null, $form = array(), $view_id = 0 ) {
1710
1711
	    /**
1712
		 * @filter `gravityview/edit_entry/use_gf_admin_only_setting` When Edit tab isn't configured, should the Gravity Forms "Admin Only" field settings be used to control field display to non-admins? Default: true
1713
	     * If the Edit Entry tab is not configured, adminOnly fields will not be shown to non-administrators.
1714
	     * If the Edit Entry tab *is* configured, adminOnly fields will be shown to non-administrators, using the configured GV permissions
1715
	     * @since 1.9.1
1716
	     * @param boolean $use_gf_adminonly_setting True: Hide field if set to Admin Only in GF and the user is not an admin. False: show field based on GV permissions, ignoring GF permissions.
1717
	     * @param array $form GF Form array
1718
	     * @param int $view_id View ID
1719
	     */
1720 3
	    $use_gf_adminonly_setting = apply_filters( 'gravityview/edit_entry/use_gf_admin_only_setting', empty( $edit_fields ), $form, $view_id );
1721
1722 3
	    if( $use_gf_adminonly_setting && false === GVCommon::has_cap( 'gravityforms_edit_entries', $this->entry['id'] ) ) {
1723
			foreach( $fields as $k => $field ) {
1724
				if( $field->adminOnly ) {
1725
				    unset( $fields[ $k ] );
1726
				}
1727
			}
1728
			return $fields;
1729
		}
1730
1731 3
	    foreach( $fields as &$field ) {
1732 3
		    $field->adminOnly = false;
1733
		}
1734
1735 3
		return $fields;
1736
	}
1737
1738
	// --- Conditional Logic
1739
1740
	/**
1741
	 * Conditional logic isn't designed to work with forms that already have content. When switching input values,
1742
	 * the dependent fields will be blank.
1743
	 *
1744
	 * Note: This is because GF populates a JavaScript variable with the input values. This is tough to filter at the input level;
1745
	 * via the `gform_field_value` filter; it requires lots of legwork. Doing it at the form level is easier.
1746
	 *
1747
	 * @since 1.17.4
1748
	 *
1749
	 * @param array $form Gravity Forms array object
1750
	 *
1751
	 * @return array $form, modified to fix conditional
1752
	 */
1753 3
	function prefill_conditional_logic( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1754
1755 3
		if( ! GFFormDisplay::has_conditional_logic( $form ) ) {
1756 3
			return $form;
1757
		}
1758
1759
		// Have Conditional Logic pre-fill fields as if the data were default values
1760
		/** @var GF_Field $field */
1761
		foreach ( $form['fields'] as &$field ) {
1762
1763
			if( 'checkbox' === $field->type ) {
1764
				foreach ( $field->get_entry_inputs() as $key => $input ) {
1765
				    $input_id = $input['id'];
1766
				    $choice = $field->choices[ $key ];
1767
				    $value = \GV\Utils::get( $this->entry, $input_id );
1768
				    $match = RGFormsModel::choice_value_match( $field, $choice, $value );
1769
				    if( $match ) {
1770
				        $field->choices[ $key ]['isSelected'] = true;
1771
				    }
1772
				}
1773
			} else {
1774
1775
				// We need to run through each field to set the default values
1776
				foreach ( $this->entry as $field_id => $field_value ) {
1777
1778
				    if( floatval( $field_id ) === floatval( $field->id ) ) {
1779
1780
				        if( 'list' === $field->type ) {
1781
				            $list_rows = maybe_unserialize( $field_value );
1782
1783
				            $list_field_value = array();
1784
				            foreach ( (array) $list_rows as $row ) {
1785
				                foreach ( (array) $row as $column ) {
1786
				                    $list_field_value[] = $column;
1787
				                }
1788
				            }
1789
1790
				            $field->defaultValue = serialize( $list_field_value );
1791
				        } else {
1792
				            $field->defaultValue = $field_value;
1793
				        }
1794
				    }
1795
				}
1796
			}
1797
		}
1798
1799
		return $form;
1800
	}
1801
1802
	/**
1803
	 * Remove the conditional logic rules from the form button and the form fields, if needed.
1804
	 *
1805
	 * @todo Merge with caller method
1806
	 * @since 1.9
1807
	 *
1808
	 * @param array $form Gravity Forms form
1809
	 * @return array Modified form, if not using Conditional Logic
1810
	 */
1811 3
	private function filter_conditional_logic( $form ) {
1812
1813
		/**
1814
		 * @filter `gravityview/edit_entry/conditional_logic` Should the Edit Entry form use Gravity Forms conditional logic showing/hiding of fields?
1815
		 * @since 1.9
1816
		 * @param bool $use_conditional_logic True: Gravity Forms will show/hide fields just like in the original form; False: conditional logic will be disabled and fields will be shown based on configuration. Default: true
1817
		 * @param array $form Gravity Forms form
1818
		 */
1819 3
		$use_conditional_logic = apply_filters( 'gravityview/edit_entry/conditional_logic', true, $form );
1820
1821 3
		if( $use_conditional_logic ) {
1822 3
			return $form;
1823
		}
1824
1825
		foreach( $form['fields'] as &$field ) {
1826
			/* @var GF_Field $field */
1827
			$field->conditionalLogic = null;
1828
		}
1829
1830
		unset( $form['button']['conditionalLogic'] );
1831
1832
		return $form;
1833
1834
	}
1835
1836
	/**
1837
	 * Disable the Gravity Forms conditional logic script and features on the Edit Entry screen
1838
	 *
1839
	 * @since 1.9
1840
	 *
1841
	 * @param $has_conditional_logic
1842
	 * @param $form
1843
	 * @return mixed
1844
	 */
1845 3
	public function manage_conditional_logic( $has_conditional_logic, $form ) {
1846
1847 3
		if( ! $this->is_edit_entry() ) {
1848
			return $has_conditional_logic;
1849
		}
1850
1851
	    /** @see GravityView_Edit_Entry_Render::filter_conditional_logic for filter documentation */
1852 3
		return apply_filters( 'gravityview/edit_entry/conditional_logic', $has_conditional_logic, $form );
1853
	}
1854
1855
1856
	// --- User checks and nonces
1857
1858
	/**
1859
	 * Check if the user can edit the entry
1860
	 *
1861
	 * - Is the nonce valid?
1862
	 * - Does the user have the right caps for the entry
1863
	 * - Is the entry in the trash?
1864
	 *
1865
	 * @todo Move to GVCommon
1866
	 *
1867
	 * @param  boolean $echo Show error messages in the form?
1868
	 * @return boolean        True: can edit form. False: nope.
1869
	 */
1870 4
	private function user_can_edit_entry( $echo = false ) {
1871
1872 4
		$error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1873
1874
		/**
1875
		 *  1. Permalinks are turned off
1876
		 *  2. There are two entries embedded using oEmbed
1877
		 *  3. One of the entries has just been saved
1878
		 */
1879 4
		if( !empty( $_POST['lid'] ) && !empty( $_GET['entry'] ) && ( $_POST['lid'] !== $_GET['entry'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1880
1881
			$error = true;
1882
1883
		}
1884
1885 4
		if( !empty( $_GET['entry'] ) && (string)$this->entry['id'] !== $_GET['entry'] ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1886
1887
			$error = true;
1888
1889 4
		} elseif( ! $this->verify_nonce() ) {
1890
1891
			/**
1892
			 * If the Entry is embedded, there may be two entries on the same page.
1893
			 * If that's the case, and one is being edited, the other should fail gracefully and not display an error.
1894
			 */
1895
			if( GravityView_oEmbed::getInstance()->get_entry_id() ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression \GravityView_oEmbed::get...tance()->get_entry_id() of type integer|null is loosely compared to true; this is ambiguous if the integer can be zero. You might want to explicitly use !== null instead.

In PHP, under loose comparison (like ==, or !=, or switch conditions), values of different types might be equal.

For integer values, zero is a special case, in particular the following results might be unexpected:

0   == false // true
0   == null  // true
123 == false // false
123 == null  // false

// It is often better to use strict comparison
0 === false // false
0 === null  // false
Loading history...
Deprecated Code introduced by
The method GravityView_oEmbed::getInstance() has been deprecated with message: Use \GV\oEmbed instead.

This method has been deprecated. The supplier of the class has supplied an explanatory message.

The explanatory message should give you some clue as to whether and when the method will be removed from the class and what other method or class to use instead.

Loading history...
Deprecated Code introduced by
The method GravityView_oEmbed::get_entry_id() has been deprecated with message: Use \GV\oEmbed instead.

This method has been deprecated. The supplier of the class has supplied an explanatory message.

The explanatory message should give you some clue as to whether and when the method will be removed from the class and what other method or class to use instead.

Loading history...
1896
				$error = true;
1897
			} else {
1898
				$error = __( 'The link to edit this entry is not valid; it may have expired.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1899
			}
1900
1901
		}
1902
1903 4
		if( ! GravityView_Edit_Entry::check_user_cap_edit_entry( $this->entry ) ) {
1904 1
			$error = __( 'You do not have permission to edit this entry.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1905
		}
1906
1907 4
		if( $this->entry['status'] === 'trash' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
1908
			$error = __('You cannot edit the entry; it is in the trash.', 'gravityview' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1909
		}
1910
1911
		// No errors; everything's fine here!
1912 4
		if( empty( $error ) ) {
1913 4
			return true;
1914
		}
1915
1916 1
		if( $echo && $error !== true ) {
0 ignored issues
show
introduced by
Found "!== true". Use Yoda Condition checks, you must
Loading history...
1917
1918 1
	        $error = esc_html( $error );
1919
1920
	        /**
1921
	         * @since 1.9
1922
	         */
1923 1
	        if ( ! empty( $this->entry ) ) {
1924 1
		        $error .= ' ' . gravityview_get_link( '#', _x('Go back.', 'Link shown when invalid Edit Entry link is clicked', 'gravityview' ), array( 'onclick' => "window.history.go(-1); return false;" ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal window.history.go(-1); return false; does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1925
	        }
1926
1927 1
			echo GVCommon::generate_notice( wpautop( $error ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1928
		}
1929
1930 1
		gravityview()->log->error( '{error}', array( 'error' => $error ) );
1931
1932 1
		return false;
1933
	}
1934
1935
1936
	/**
1937
	 * Check whether a field is editable by the current user, and optionally display an error message
1938
	 * @uses  GravityView_Edit_Entry->check_user_cap_edit_field() Check user capabilities
1939
	 * @param  array  $field Field or field settings array
1940
	 * @param  boolean $echo  Whether to show error message telling user they aren't allowed
1941
	 * @return boolean         True: user can edit the current field; False: nope, they can't.
1942
	 */
1943
	private function user_can_edit_field( $field, $echo = false ) {
1944
1945
		$error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1946
1947
		if( ! $this->check_user_cap_edit_field( $field ) ) {
1948
			$error = __( 'You do not have permission to edit this field.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1949
		}
1950
1951
		// No errors; everything's fine here!
1952
		if( empty( $error ) ) {
1953
			return true;
1954
		}
1955
1956
		if( $echo ) {
1957
			echo GVCommon::generate_notice( wpautop( esc_html( $error ) ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1958
		}
1959
1960
		gravityview()->log->error( '{error}', array( 'error' => $error ) );
1961
1962
		return false;
1963
1964
	}
1965
1966
1967
	/**
1968
	 * checks if user has permissions to edit a specific field
1969
	 *
1970
	 * Needs to be used combined with GravityView_Edit_Entry::user_can_edit_field for maximum security!!
1971
	 *
1972
	 * @param  [type] $field [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1973
	 * @return bool
1974
	 */
1975
	private function check_user_cap_edit_field( $field ) {
1976
1977
		// If they can edit any entries (as defined in Gravity Forms), we're good.
1978
		if( GVCommon::has_cap( array( 'gravityforms_edit_entries', 'gravityview_edit_others_entries' ) ) ) {
1979
			return true;
1980
		}
1981
1982
		$field_cap = isset( $field['allow_edit_cap'] ) ? $field['allow_edit_cap'] : false;
1983
1984
		if( $field_cap ) {
1985
			return GVCommon::has_cap( $field['allow_edit_cap'] );
1986
		}
1987
1988
		return false;
1989
	}
1990
1991
1992
	/**
1993
	 * Is the current nonce valid for editing the entry?
1994
	 * @return boolean
1995
	 */
1996 3
	public function verify_nonce() {
1997
1998
		// Verify form submitted for editing single
1999 3
		if( $this->is_edit_entry_submission() ) {
2000
			$valid = wp_verify_nonce( $_POST[ self::$nonce_field ], self::$nonce_field );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
2001
		}
2002
2003
		// Verify
2004 3
		else if( ! $this->is_edit_entry() ) {
2005
			$valid = false;
2006
		}
2007
2008
		else {
2009 3
			$valid = wp_verify_nonce( $_GET['edit'], self::$nonce_key );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
2010
		}
2011
2012
		/**
2013
		 * @filter `gravityview/edit_entry/verify_nonce` Override Edit Entry nonce validation. Return true to declare nonce valid.
2014
		 * @since 1.13
2015
		 * @param int|boolean $valid False if invalid; 1 or 2 when nonce was generated
2016
		 * @param string $nonce_field Key used when validating submissions. Default: is_gv_edit_entry
2017
		 */
2018 3
		$valid = apply_filters( 'gravityview/edit_entry/verify_nonce', $valid, self::$nonce_field );
2019
2020 3
		return $valid;
2021
	}
2022
2023
2024
	/**
2025
	 * Multiselect in GF 2.2 became a json_encoded value. Fix it.
2026
	 *
2027
	 * As a hack for now we'll implode it back.
2028
	 */
2029
	public function fix_multiselect_value_serialization( $field_value, $field, $_this ) {
0 ignored issues
show
Unused Code introduced by
The parameter $_this is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
2030
		if ( empty ( $field->storageType ) || $field->storageType != 'json' ) {
0 ignored issues
show
introduced by
Found "!= '". Use Yoda Condition checks, you must
Loading history...
Coding Style introduced by
Space before opening parenthesis of function call prohibited
Loading history...
2031
			return $field_value;
2032
		}
2033
2034
		$maybe_json = @json_decode( $field_value, true );
0 ignored issues
show
Coding Style introduced by
Silencing errors is discouraged
Loading history...
2035
2036
		if ( $maybe_json ) {
2037
			return implode( ',', $maybe_json );
2038
		}
2039
2040
		return $field_value;
2041
	}
2042
2043
2044
2045
} //end class
2046