Completed
Push — master ( 1ca2d3...2adc18 )
by Zack
44:30 queued 29:54
created

update_calculation_fields()   D

Complexity

Conditions 9
Paths 12

Size

Total Lines 45
Code Lines 26

Duplication

Lines 0
Ratio 0 %
Metric Value
dl 0
loc 45
rs 4.909
cc 9
eloc 26
nc 12
nop 0
1
<?php
0 ignored issues
show
Coding Style Compatibility introduced by
For compatibility and reusability of your code, PSR1 recommends that a file should introduce either new symbols (like classes, functions, etc.) or have side-effects (like outputting something, or including other files), but not both at the same time. The first symbol is defined on line 17 and the first side effect is on line 13.

The PSR-1: Basic Coding Standard recommends that a file should either introduce new symbols, that is classes, functions, constants or similar, or have side effects. Side effects are anything that executes logic, like for example printing output, changing ini settings or writing to a file.

The idea behind this recommendation is that merely auto-loading a class should not change the state of an application. It also promotes a cleaner style of programming and makes your code less prone to errors, because the logic is not spread out all over the place.

To learn more about the PSR-1, please see the PHP-FIG site on the PSR-1.

Loading history...
2
/**
3
 * GravityView Edit Entry - render frontend
4
 *
5
 * @package   GravityView
6
 * @license   GPL2+
7
 * @author    Katz Web Services, Inc.
8
 * @link      http://gravityview.co
9
 * @copyright Copyright 2014, Katz Web Services, Inc.
10
 */
11
12
if ( ! defined( 'WPINC' ) ) {
13
    die;
14
}
15
16
17
class GravityView_Edit_Entry_Render {
18
19
    /**
20
     * @var GravityView_Edit_Entry
21
     */
22
    protected $loader;
23
24
	/**
25
	 * @var string String used to generate unique nonce for the entry/form/view combination. Allows access to edit page.
26
	 */
27
    static $nonce_key;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $nonce_key.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
28
29
	/**
30
	 * @since 1.9
31
	 * @var string String used for check valid edit entry form submission. Allows saving edit form values.
32
	 */
33
	private static $nonce_field = 'is_gv_edit_entry';
34
35
	/**
36
	 * @since 1.9
37
	 * @var bool Whether to allow save and continue functionality
38
	 */
39
	private static $supports_save_and_continue = false;
40
41
	/**
42
	 * @since 1.9
43
	 * @var bool Whether to allow editing product fields
44
	 */
45
	private static $supports_product_fields = false;
46
47
    /**
48
     * Gravity Forms entry array
49
     *
50
     * @var array
51
     */
52
    var $entry;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $entry.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
53
54
    /**
55
     * Gravity Forms form array (GravityView modifies the content through this class lifecycle)
56
     *
57
     * @var array
58
     */
59
    var $form;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $form.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
60
61
    /**
62
     * Gravity Forms form array (it won't get changed during this class lifecycle)
63
     * @since 1.16.2.1
64
     * @var array
65
     */
66
    var $original_form;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $original_form.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
67
68
    /**
69
     * Gravity Forms form array after the form validation process
70
     * @since 1.13
71
     * @var array
72
     */
73
    var $form_after_validation = null;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $form_after_validation.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
74
75
    /**
76
     * Hold an array of GF field objects that have calculation rules
77
     * @var array
78
     */
79
    var $fields_with_calculation = array();
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $fields_with_calculation.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
80
81
    /**
82
     * Hold an array of GF field objects with type 'total'
83
     * @var array
84
     */
85
    var $total_fields = array();
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $total_fields.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
86
87
    /**
88
     * Gravity Forms form id
89
     *
90
     * @var int
91
     */
92
    var $form_id;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $form_id.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
93
94
    /**
95
     * ID of the current view
96
     *
97
     * @var int
98
     */
99
    var $view_id;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $view_id.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
100
101
    /**
102
     * Updated entry is valid (GF Validation object)
103
     *
104
     * @var array
105
     */
106
    var $is_valid = NULL;
0 ignored issues
show
Coding Style introduced by
The visibility should be declared for property $is_valid.

The PSR-2 coding standard requires that all properties in a class have their visibility explicitly declared. If you declare a property using

class A {
    var $property;
}

the property is implicitly global.

To learn more about the PSR-2, please see the PHP-FIG site on the PSR-2.

Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
107
108
    function __construct( GravityView_Edit_Entry $loader ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
109
        $this->loader = $loader;
110
    }
111
112
    function load() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
113
114
        /** @define "GRAVITYVIEW_DIR" "../../../" */
115
        include_once( GRAVITYVIEW_DIR .'includes/class-admin-approve-entries.php' );
116
117
        // Don't display an embedded form when editing an entry
118
        add_action( 'wp_head', array( $this, 'prevent_render_form' ) );
119
        add_action( 'wp_footer', array( $this, 'prevent_render_form' ) );
120
121
        // Stop Gravity Forms processing what is ours!
122
        add_filter( 'wp', array( $this, 'prevent_maybe_process_form'), 8 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
123
124
        add_filter( 'gravityview_is_edit_entry', array( $this, 'is_edit_entry') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
125
126
        add_action( 'gravityview_edit_entry', array( $this, 'init' ) );
127
128
        // Disable conditional logic if needed (since 1.9)
129
        add_filter( 'gform_has_conditional_logic', array( $this, 'manage_conditional_logic' ), 10, 2 );
130
131
        // Make sure GF doesn't validate max files (since 1.9)
132
        add_filter( 'gform_plupload_settings', array( $this, 'modify_fileupload_settings' ), 10, 3 );
133
134
        // Add fields expected by GFFormDisplay::validate()
135
        add_filter( 'gform_pre_validation', array( $this, 'gform_pre_validation') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
136
137
    }
138
139
    /**
140
     * Don't show any forms embedded on a page when GravityView is in Edit Entry mode
141
     *
142
     * Adds a `__return_empty_string` filter on the Gravity Forms shortcode on the `wp_head` action
143
     * And then removes it on the `wp_footer` action
144
     *
145
     * @since 1.16.1
146
     *
147
     * @return void
148
     */
149
    function prevent_render_form() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
150
        if( $this->is_edit_entry() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
151
            if( 'wp_head' === current_filter() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
152
                add_filter( 'gform_shortcode_form', '__return_empty_string' );
153
            } else {
154
                remove_filter( 'gform_shortcode_form', '__return_empty_string' );
155
            }
156
        }
157
    }
158
159
    /**
160
     * Because we're mimicking being a front-end Gravity Forms form while using a Gravity Forms
161
     * backend form, we need to prevent them from saving twice.
162
     * @return void
163
     */
164
    function prevent_maybe_process_form() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
165
166
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[prevent_maybe_process_form] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
167
168
        if( $this->is_edit_entry_submission() && $this->verify_nonce() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
169
            remove_action( 'wp',  array( 'RGForms', 'maybe_process_form'), 9 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
170
        }
171
    }
172
173
    /**
174
     * Is the current page an Edit Entry page?
175
     * @return boolean
176
     */
177
    public function is_edit_entry() {
178
179
        $gf_page = ( 'entry' === RGForms::get( 'view' ) );
180
181
        return ( $gf_page && isset( $_GET['edit'] ) || RGForms::post( 'action' ) === 'update' );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
182
    }
183
184
	/**
185
	 * Is the current page an Edit Entry page?
186
	 * @since 1.9
187
	 * @return boolean
188
	 */
189
	public function is_edit_entry_submission() {
190
		return !empty( $_POST[ self::$nonce_field ] );
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
191
	}
192
193
    /**
194
     * When Edit entry view is requested setup the vars
195
     */
196
    function setup_vars() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
197
        $gravityview_view = GravityView_View::getInstance();
198
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
199
200
        $entries = $gravityview_view->getEntries();
201
        $this->entry = $entries[0];
202
203
        $this->original_form = $this->form = $gravityview_view->getForm();
204
        $this->form_id = $gravityview_view->getFormId();
205
        $this->view_id = $gravityview_view->getViewId();
206
207
        self::$nonce_key = GravityView_Edit_Entry::get_nonce_key( $this->view_id, $this->form_id, $this->entry['id'] );
208
    }
209
210
211
    /**
212
     * Load required files and trigger edit flow
213
     *
214
     * Run when the is_edit_entry returns true.
215
     *
216
     * @param GravityView_View_Data $gv_data GravityView Data object
217
     * @return void
218
     */
219
    function init( $gv_data ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
220
221
        require_once( GFCommon::get_base_path() . '/form_display.php' );
222
        require_once( GFCommon::get_base_path() . '/entry_detail.php' );
223
224
        $this->setup_vars();
225
226
        // Multiple Views embedded, don't proceed if nonce fails
227
        if( $gv_data->has_multiple_views() && ! wp_verify_nonce( $_GET['edit'], self::$nonce_key ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
228
            return;
229
        }
230
231
        // Sorry, you're not allowed here.
232
        if( false === $this->user_can_edit_entry( true ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
233
            return;
234
        }
235
236
        $this->print_scripts();
237
238
        $this->process_save();
239
240
        $this->edit_entry_form();
241
242
    }
243
244
245
    /**
246
     * Force Gravity Forms to output scripts as if it were in the admin
247
     * @return void
248
     */
249
    function print_scripts() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
250
        $gravityview_view = GravityView_View::getInstance();
251
252
        wp_register_script( 'gform_gravityforms', GFCommon::get_base_url().'/js/gravityforms.js', array( 'jquery', 'gform_json', 'gform_placeholder', 'sack', 'plupload-all', 'gravityview-fe-view' ) );
253
254
        GFFormDisplay::enqueue_form_scripts($gravityview_view->getForm(), false);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
255
256
        // Sack is required for images
257
        wp_print_scripts( array( 'sack', 'gform_gravityforms' ) );
258
    }
259
260
261
    /**
262
     * Process edit entry form save
263
     */
264
    function process_save() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
265
266
        if( empty( $_POST ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
267
            return;
268
        }
269
270
        // Make sure the entry, view, and form IDs are all correct
271
        $valid = $this->verify_nonce();
272
273
        if( !$valid ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
274
            do_action('gravityview_log_error', __METHOD__ . ' Nonce validation failed.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
275
            return;
276
        }
277
278
        if( $this->entry['id'] !== $_POST['lid'] ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
279
            do_action('gravityview_log_error', __METHOD__ . ' Entry ID did not match posted entry ID.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
280
            return;
281
        }
282
283
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[process_save] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
284
285
        $this->process_save_process_files( $this->form_id );
286
287
        $this->validate();
288
289
        if( $this->is_valid ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using ! empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
introduced by
Space after opening control structure is required
Loading history...
290
291
            do_action('gravityview_log_debug', 'GravityView_Edit_Entry[process_save] Submission is valid.' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
292
293
            /**
294
             * @hack This step is needed to unset the adminOnly from form fields, to add the calculation fields
295
             */
296
            $form = $this->form_prepare_for_save();
297
298
            /**
299
             * @hack to avoid the capability validation of the method save_lead for GF 1.9+
300
             */
301
            unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
302
303
            GFFormsModel::save_lead( $form, $this->entry );
304
305
            // If there's a post associated with the entry, process post fields
306
            if( !empty( $this->entry['post_id'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
307
                $this->maybe_update_post_fields( $form );
308
            }
309
310
            // Process calculation fields
311
            $this->update_calculation_fields();
312
313
            // Perform actions normally performed after updating a lead
314
            $this->after_update();
315
316
            /**
317
             * @action `gravityview/edit_entry/after_update` Perform an action after the entry has been updated using Edit Entry
318
             * @param array $form Gravity Forms form array
319
             * @param string $entry_id Numeric ID of the entry that was updated
320
             */
321
            do_action( 'gravityview/edit_entry/after_update', $this->form, $this->entry['id'] );
322
        }
323
324
    } // process_save
325
326
327
    /**
328
     * Have GF handle file uploads
329
     *
330
     * Copy of code from GFFormDisplay::process_form()
331
     *
332
     * @param int $form_id
333
     */
334
    function process_save_process_files( $form_id ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
335
336
        //Loading files that have been uploaded to temp folder
337
        $files = GFCommon::json_decode( stripslashes( RGForms::post( 'gform_uploaded_files' ) ) );
338
        if ( ! is_array( $files ) ) {
339
            $files = array();
340
        }
341
342
        RGFormsModel::$uploaded_files[ $form_id ] = $files;
343
    }
344
345
    /**
346
     * Remove max_files validation (done on gravityforms.js) to avoid conflicts with GravityView
347
     * Late validation done on self::custom_validation
348
     *
349
     * @param $plupload_init array Plupload settings
350
     * @param $form_id
351
     * @param $instance
352
     * @return mixed
353
     */
354
    public function modify_fileupload_settings( $plupload_init, $form_id, $instance ) {
0 ignored issues
show
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $instance is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
355
        if( ! $this->is_edit_entry() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
356
            return $plupload_init;
357
        }
358
359
        $plupload_init['gf_vars']['max_files'] = 0;
360
361
        return $plupload_init;
362
    }
363
364
365
    /**
366
     * Unset adminOnly and convert field input key to string
367
     * @return array $form
368
     */
369
    private function form_prepare_for_save() {
370
371
        $form = $this->form;
372
373
        foreach( $form['fields'] as &$field ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
374
375
            $field->adminOnly = false;
376
377
            if( isset( $field->inputs ) && is_array( $field->inputs ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
378
                foreach( $field->inputs as $key => $input ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
379
                    $field->inputs[ $key ][ 'id' ] = (string)$input['id'];
0 ignored issues
show
introduced by
Array keys should NOT be surrounded by spaces if they only contain a string or an integer.
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
380
                }
381
            }
382
        }
383
384
        return $form;
385
    }
386
387
    private function update_calculation_fields() {
388
389
        $form = $this->original_form;
390
        $update = false;
391
392
        // get the most up to date entry values
393
        $entry = GFAPI::get_entry( $this->entry['id'] );
394
395
        if( !empty( $this->fields_with_calculation ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
396
            $update = true;
397
            foreach ( $this->fields_with_calculation as $calc_field ) {
398
                $inputs = $calc_field->get_entry_inputs();
399
                if ( is_array( $inputs ) ) {
400
                    foreach ( $inputs as $input ) {
401
                        $input_name = 'input_' . str_replace( '.', '_', $input['id'] );
402
                        $entry[ strval( $input['id'] ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
403
                    }
404
                } else {
405
                    $input_name = 'input_' . str_replace( '.', '_', $calc_field->id);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
406
                    $entry[ strval( $calc_field->id ) ] = RGFormsModel::prepare_value( $form, $calc_field, '', $input_name, $entry['id'], $entry );
407
                }
408
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
409
410
        }
411
412
        //saving total field as the last field of the form.
413
        if ( ! empty( $this->total_fields ) ) {
414
            $update = true;
415
            foreach ( $this->total_fields as $total_field ) {
416
                $input_name = 'input_' . str_replace( '.', '_', $total_field->id);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
417
                $entry[ strval( $total_field->id ) ] = RGFormsModel::prepare_value( $form, $total_field, '', $input_name, $entry['id'], $entry );
418
            }
419
        }
420
421
        if( $update ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
422
423
            $return_entry = GFAPI::update_entry( $entry );
424
425
            if( is_wp_error( $return_entry ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
426
                do_action( 'gravityview_log_error', 'Updating the entry calculation and total fields failed', $return_entry );
427
            } else {
428
                do_action( 'gravityview_log_debug', 'Updating the entry calculation and total fields succeeded' );
429
            }
430
        }
431
    }
432
433
434
    /**
435
     * Loop through the fields being edited and if they include Post fields, update the Entry's post object
436
     *
437
     * @param array $form Gravity Forms form
438
     *
439
     * @return void
440
     */
441
    function maybe_update_post_fields( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
442
443
        $post_id = $this->entry['post_id'];
444
445
        // Security check
446
        if( false === GVCommon::has_cap( 'edit_post', $post_id ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
447
            do_action( 'gravityview_log_error', 'The current user does not have the ability to edit Post #'.$post_id );
448
            return;
449
        }
450
451
        $update_entry = false;
452
453
        $updated_post = $original_post = get_post( $post_id );
454
455
        // get the most up to date entry values
456
        $entry = GFAPI::get_entry( $this->entry['id'] );
457
458
        foreach ( $entry as $field_id => $value ) {
459
460
            //todo: only run through the edit entry configured fields
461
462
            $field = RGFormsModel::get_field( $form, $field_id );
463
464
            if( class_exists('GF_Fields') ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
465
                $field = GF_Fields::create( $field );
466
            }
467
468
            if( GFCommon::is_post_field( $field ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
469
470
                // Get the value of the field, including $_POSTed value
471
                $value = RGFormsModel::get_field_value( $field );
472
473
                switch( $field->type ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
474
475
                    case 'post_title':
476
                    case 'post_content':
477
                    case 'post_excerpt':
478
                        $updated_post->{$field->type} = $value;
479
                        break;
480
                    case 'post_tags':
481
                        wp_set_post_tags( $post_id, $value, false );
482
                        break;
483
                    case 'post_category':
484
485
                        $categories = is_array( $value ) ? array_values( $value ) : (array)$value;
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
486
                        $categories = array_filter( $categories );
487
488
                        wp_set_post_categories( $post_id, $categories, false );
489
490
                        // if post_category is type checkbox, then value is an array of inputs
491
                        if( isset( $value[ strval( $field_id ) ] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
492
                            foreach( $value as $input_id => $val ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
493
                                $input_name = 'input_' . str_replace( '.', '_', $input_id );
494
                                $entry[ strval( $input_id ) ] = RGFormsModel::prepare_value( $form, $field, $val, $input_name, $entry['id'], $entry );
495
                            }
496
                        } else {
497
                            $input_name = 'input_' . str_replace( '.', '_', $field_id );
498
                            $entry[ strval( $field_id ) ] = RGFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'], $entry );
499
                        }
500
501
                        break;
502
                    case 'post_custom_field':
503
504
                        $input_type = RGFormsModel::get_input_type( $field );
505
                        $custom_field_name = $field->postCustomFieldName;
506
507
                        // Only certain custom field types are supported
508
                        switch( $input_type ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
509
                            case 'fileupload':
510
                            /** @noinspection PhpMissingBreakStatementInspection */
0 ignored issues
show
Coding Style introduced by
Line indented incorrectly; expected at least 8 tabs, found 7
Loading history...
511
                            case 'list':
512
                                if( ! is_string( $value ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
513
                                    $value = function_exists('wp_json_encode') ? wp_json_encode( $value ) : json_encode( $value );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
514
                                }
515
                            // break; left intentionally out
1 ignored issue
show
Coding Style introduced by
Line indented incorrectly; expected at least 8 tabs, found 7
Loading history...
516
                            default:
517
                                update_post_meta( $post_id, $custom_field_name, $value );
518
                        }
519
520
                        break;
521
522
                    case 'post_image':
523
524
                        $input_name = 'input_' . $field_id;
525
526
                        if ( !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
527
528
                            // We have a new image
529
530
                            $value = RGFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'] );
531
532
                            // is this field set as featured image, if not, leave
533
                            if ( ! $field->postFeaturedImage ) {
534
                                break;
535
                            }
536
537
                            $ary = ! empty( $value ) ? explode( '|:|', $value ) : array();
538
                            $img_url = rgar( $ary, 0 );
539
540
                            $img_title       = count( $ary ) > 1 ? $ary[1] : '';
541
                            $img_caption     = count( $ary ) > 2 ? $ary[2] : '';
542
                            $img_description = count( $ary ) > 3 ? $ary[3] : '';
543
544
                            $image_meta = array(
545
                                'post_excerpt' => $img_caption,
546
                                'post_content' => $img_description,
547
                            );
548
549
                            //adding title only if it is not empty. It will default to the file name if it is not in the array
550
                            if ( ! empty( $img_title ) ) {
551
                                $image_meta['post_title'] = $img_title;
552
                            }
553
554
                            //todo: As soon as \GFFormsModel::media_handle_upload becomes a public method, move this call to \GFFormsModel::media_handle_upload and remove the hack from this class.
555
                            require_once GRAVITYVIEW_DIR . 'includes/class-gravityview-gfformsmodel.php';
556
                            $media_id = GravityView_GFFormsModel::media_handle_upload( $img_url, $post_id, $image_meta );
557
558
                            if ( $media_id ) {
559
                                set_post_thumbnail( $post_id, $media_id );
560
                            }
561
562
                            break;
563
564
                        } elseif ( !empty( $_POST[ $input_name ] ) && is_array( $value ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
565
566
                            // Same image although the image title, caption or description might have changed
567
568
                            $ary = ! empty( $entry[ $field_id ] ) ? explode( '|:|', $entry[ $field_id ] ) : array();
569
                            $img_url = rgar( $ary, 0 );
570
571
                            // is this really the same image or something went wrong ?
572
                            if( $img_url === $_POST[ $input_name ] ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
573
574
                                $img_title       = isset( $value[ $field_id .'.1' ] ) ? $value[ $field_id .'.1' ] : '';
575
                                $img_caption     = isset( $value[ $field_id .'.4' ] ) ? $value[ $field_id .'.4' ] : '';
576
                                $img_description = isset( $value[ $field_id .'.7' ] ) ? $value[ $field_id .'.7' ] : '';
577
578
                                $value = ! empty( $img_url ) ? $img_url . "|:|" . $img_title . "|:|" . $img_caption . "|:|" . $img_description : '';
0 ignored issues
show
Coding Style Comprehensibility introduced by
The string literal |:| does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
579
580
                                if ( $field->postFeaturedImage ) {
581
582
                                    $image_meta = array(
583
                                        'ID' => get_post_thumbnail_id( $post_id ),
584
                                        'post_title' => $img_title,
585
                                        'post_excerpt' => $img_caption,
586
                                        'post_content' => $img_description,
587
                                    );
588
589
                                    // update image title, caption or description
590
                                    wp_update_post( $image_meta );
591
                                }
592
593
                                break;
594
                            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
595
596
                        }
597
598
                        // if we get here, image was removed or not set.
599
600
                        $value = '';
601
                        if ( $field->postFeaturedImage ) {
602
                            delete_post_thumbnail( $post_id );
603
                        }
604
605
                        break;
606
607
                }
608
609
                //ignore fields that have not changed
610
                if ( $value === rgget( (string) $field_id, $entry ) ) {
611
                    continue;
612
                }
613
614
                // update entry
615
                if( 'post_category' !== $field->type ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
616
                    $entry[ strval( $field_id ) ] = $value;
617
                }
618
619
                $update_entry = true;
620
621
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
622
623
        }
624
625
        if( $update_entry ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
626
627
            $return_entry = GFAPI::update_entry( $entry );
628
629
            if( is_wp_error( $return_entry ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
630
                do_action( 'gravityview_log_error', 'Updating the entry post fields failed', $return_entry );
631
            } else {
632
                do_action( 'gravityview_log_debug', 'Updating the entry post fields for post #'.$post_id.' succeeded' );
633
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
634
635
        }
636
637
        $return_post = wp_update_post( $updated_post, true );
638
639
        if( is_wp_error( $return_post ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
640
            $return_post->add_data( $updated_post, '$updated_post' );
641
            do_action( 'gravityview_log_error', 'Updating the post content failed', $return_post );
642
        } else {
643
            do_action( 'gravityview_log_debug', 'Updating the post content for post #'.$post_id.' succeeded', $updated_post );
644
        }
645
646
    }
647
648
649
    /**
650
     * Perform actions normally performed after updating a lead
651
     *
652
     * @since 1.8
653
     *
654
     * @see GFEntryDetail::lead_detail_page()
655
     *
656
     * @return void
657
     */
658
    function after_update() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
659
660
        do_action( 'gform_after_update_entry', $this->form, $this->entry['id'] );
661
        do_action( "gform_after_update_entry_{$this->form['id']}", $this->form, $this->entry['id'] );
662
663
        // Re-define the entry now that we've updated it.
664
        $entry = RGFormsModel::get_lead( $this->entry['id'] );
665
666
        $entry = GFFormsModel::set_entry_meta( $entry, $this->form );
667
668
        // We need to clear the cache because Gravity Forms caches the field values, which
669
        // we have just updated.
670
        foreach ($this->form['fields'] as $key => $field) {
0 ignored issues
show
introduced by
No space after opening parenthesis is prohibited
Loading history...
introduced by
No space before closing parenthesis is prohibited
Loading history...
671
            GFFormsModel::refresh_lead_field_value( $entry['id'], $field->id );
672
        }
673
674
        $this->entry = $entry;
675
    }
676
677
678
    /**
679
     * Display the Edit Entry form
680
     *
681
     * @return [type] [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
682
     */
683
    public function edit_entry_form() {
684
685
        ?>
686
687
        <div class="gv-edit-entry-wrapper"><?php
688
689
            $javascript = gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/inline-javascript.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
690
691
            /**
692
             * Fixes weird wpautop() issue
693
             * @see https://github.com/katzwebservices/GravityView/issues/451
694
             */
695
            echo gravityview_strip_whitespace( $javascript );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'gravityview_strip_whitespace'
Loading history...
696
697
            ?><h2 class="gv-edit-entry-title">
698
                <span><?php
699
700
                    /**
701
                     * @filter `gravityview_edit_entry_title` Modify the edit entry title
702
                     * @param string $edit_entry_title Modify the "Edit Entry" title
703
                     * @param GravityView_Edit_Entry_Render $this This object
704
                     */
705
                    $edit_entry_title = apply_filters('gravityview_edit_entry_title', __('Edit Entry', 'gravityview'), $this );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
706
707
                    echo esc_attr( $edit_entry_title );
708
            ?></span>
709
            </h2>
710
711
            <?php $this->maybe_print_message(); ?>
712
713
            <?php // The ID of the form needs to be `gform_{form_id}` for the pluploader ?>
714
715
            <form method="post" id="gform_<?php echo $this->form_id; ?>" enctype="multipart/form-data">
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$this'
Loading history...
716
717
                <?php
718
719
                wp_nonce_field( self::$nonce_key, self::$nonce_key );
720
721
                wp_nonce_field( self::$nonce_field, self::$nonce_field, false );
722
723
                // Print the actual form HTML
724
                $this->render_edit_form();
725
726
                ?>
727
            </form>
728
729
        </div>
730
731
    <?php
732
    }
733
734
    /**
735
     * Display success or error message if the form has been submitted
736
     *
737
     * @uses GVCommon::generate_notice
738
     *
739
     * @since TODO
740
     *
741
     * @return void
742
     */
743
    private function maybe_print_message() {
744
745
        if( rgpost('action') === 'update' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
introduced by
Space after opening control structure is required
Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
746
747
            $back_link = esc_url( remove_query_arg( array( 'page', 'view', 'edit' ) ) );
748
749
            if( ! $this->is_valid ){
0 ignored issues
show
Bug Best Practice introduced by
The expression $this->is_valid of type array is implicitly converted to a boolean; are you sure this is intended? If so, consider using empty($expr) instead to make it clear that you intend to check for an array without elements.

This check marks implicit conversions of arrays to boolean values in a comparison. While in PHP an empty array is considered to be equal (but not identical) to false, this is not always apparent.

Consider making the comparison explicit by using empty(..) or ! empty(...) instead.

Loading history...
introduced by
Space after opening control structure is required
Loading history...
750
751
                // Keeping this compatible with Gravity Forms.
752
                $validation_message = "<div class='validation_error'>" . __('There was a problem with your submission.', 'gravityview') . " " . __('Errors have been highlighted below.', 'gravityview') . "</div>";
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw '__'
Loading history...
Coding Style Comprehensibility introduced by
The string literal </div> does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
753
                $message = apply_filters("gform_validation_message_{$this->form['id']}", apply_filters("gform_validation_message", $validation_message, $this->form), $this->form);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal gform_validation_message does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
754
755
                echo GVCommon::generate_notice( $message , 'gv-error' );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
756
757
            } else {
758
                $entry_updated_message = sprintf( esc_attr__('Entry Updated. %sReturn to Entry%s', 'gravityview'), '<a href="'. $back_link .'">', '</a>' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
759
760
                /**
761
                 * @filter `gravityview/edit_entry/success` Modify the edit entry success message (including the anchor link)
762
                 * @since 1.5.4
763
                 * @param string $entry_updated_message Existing message
764
                 * @param int $view_id View ID
765
                 * @param array $entry Gravity Forms entry array
766
                 * @param string $back_link URL to return to the original entry. @since 1.6
767
                 */
768
                $message = apply_filters( 'gravityview/edit_entry/success', $entry_updated_message , $this->view_id, $this->entry, $back_link );
769
770
                echo GVCommon::generate_notice( $message );
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
771
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
772
773
        }
774
    }
775
776
    /**
777
     * Display the Edit Entry form in the original Gravity Forms format
778
     *
779
     * @since 1.9
780
     *
781
     * @param $form
782
     * @param $lead
783
     * @param $view_id
784
     *
785
     * @return void
786
     */
787
    private function render_edit_form() {
788
789
        add_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields'), 5000, 3 );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
790
        add_filter( 'gform_submit_button', array( $this, 'render_form_buttons') );
0 ignored issues
show
introduced by
No space before closing parenthesis of array is bad style
Loading history...
791
        add_filter( 'gform_disable_view_counter', '__return_true' );
792
793
        add_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5, 5 );
794
        add_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10, 5 );
795
796
        // We need to remove the fake $_GET['page'] arg to avoid rendering form as if in admin.
797
        unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
798
799
        // TODO: Make sure validation isn't handled by GF
800
        // TODO: Include CSS for file upload fields
801
        // TODO: Verify multiple-page forms
802
        // TODO: Product fields are not editable
803
        // TODO: Check Updated and Error messages
804
805
        $html = GFFormDisplay::get_form( $this->form['id'], false, false, true, $this->entry );
806
807
	    remove_filter( 'gform_pre_render', array( $this, 'filter_modify_form_fields' ), 5000 );
808
        remove_filter( 'gform_submit_button', array( $this, 'render_form_buttons' ) );
809
        remove_filter( 'gform_disable_view_counter', '__return_true' );
810
        remove_filter( 'gform_field_input', array( $this, 'verify_user_can_edit_post' ), 5 );
811
        remove_filter( 'gform_field_input', array( $this, 'modify_edit_field_input' ), 10 );
812
813
        echo $html;
0 ignored issues
show
introduced by
Expected next thing to be a escaping function, not '$html'
Loading history...
814
    }
815
816
    /**
817
     * Display the Update/Cancel/Delete buttons for the Edit Entry form
818
     * @since 1.8
819
     * @return string
820
     */
821
    public function render_form_buttons() {
822
        return gravityview_ob_include( GravityView_Edit_Entry::$file .'/partials/form-buttons.php', $this );
0 ignored issues
show
Bug introduced by
The property file cannot be accessed from this context as it is declared private in class GravityView_Edit_Entry.

This check looks for access to properties that are not accessible from the current context.

If you need to make a property accessible to another context you can either raise its visibility level or provide an accessible getter in the defining class.

Loading history...
823
    }
824
825
826
    /**
827
     * Modify the form fields that are shown when using GFFormDisplay::get_form()
828
     *
829
     * By default, all fields will be shown. We only want the Edit Tab configured fields to be shown.
830
     *
831
     * @param array $form
832
     * @param boolean $ajax Whether in AJAX mode
833
     * @param array|string $field_values Passed parameters to the form
834
     *
835
     * @since 1.9
836
     *
837
     * @return array Modified form array
838
     */
839
    public function filter_modify_form_fields( $form, $ajax = false, $field_values = '' ) {
0 ignored issues
show
Unused Code introduced by
The parameter $ajax is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $field_values is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
840
841
        // In case we have validated the form, use it to inject the validation results into the form render
842
        if( isset( $this->form_after_validation ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
843
            $form = $this->form_after_validation;
844
        } else {
845
            $form['fields'] = $this->get_configured_edit_fields( $form, $this->view_id );
846
        }
847
848
        $form = $this->filter_conditional_logic( $form );
849
850
        // for now we don't support Save and Continue feature.
851
        if( ! self::$supports_save_and_continue ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
852
	        unset( $form['save'] );
853
        }
854
855
        return $form;
856
    }
857
858
    /**
859
     * When displaying a field, check if it's a Post Field, and if so, make sure the post exists and current user has edit rights.
860
     *
861
     * @since TODO
862
     *
863
     * @param string $field_content Always empty. Returning not-empty overrides the input.
864
     * @param GF_Field $field
865
     * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
866
     * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
867
     * @param int $form_id Form ID
868
     *
869
     * @return string If error, the error message. If no error, blank string (modify_edit_field_input() runs next)
870
     */
871
    function verify_user_can_edit_post( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $value is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
872
873
        if( GFCommon::is_post_field( $field ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
874
875
            $message = null;
876
877
            // First, make sure they have the capability to edit the post.
878
            if( false === current_user_can( 'edit_post', $this->entry['post_id'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
879
880
                /**
881
                 * @filter `gravityview/edit_entry/unsupported_post_field_text` Modify the message when someone isn't able to edit a post
882
                 * @param string $message The existing "You don't have permission..." text
883
                 */
884
                $message = apply_filters('gravityview/edit_entry/unsupported_post_field_text', __('You don&rsquo;t have permission to edit this post.', 'gravityview') );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
885
886
            } elseif( null === get_post( $this->entry['post_id'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
887
                /**
888
                 * @filter `gravityview/edit_entry/no_post_text` Modify the message when someone is editing an entry attached to a post that no longer exists
889
                 * @param string $message The existing "This field is not editable; the post no longer exists." text
890
                 */
891
                $message = apply_filters('gravityview/edit_entry/no_post_text', __('This field is not editable; the post no longer exists.', 'gravityview' ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
892
            }
893
894
            if( $message ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
895
                $field_content = sprintf('<div class="ginput_container ginput_container_' . $field->type . '">%s</div>', wpautop( $message ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
896
            }
897
        }
898
899
        return $field_content;
900
    }
901
902
    /**
903
     *
904
     * Fill-in the saved values into the form inputs
905
     *
906
     * @param string $field_content Always empty. Returning not-empty overrides the input.
907
     * @param GF_Field $field
908
     * @param string|array $value If array, it's a field with multiple inputs. If string, single input.
909
     * @param int $lead_id Lead ID. Always 0 for the `gform_field_input` filter.
910
     * @param int $form_id Form ID
911
     *
912
     * @return mixed
913
     */
914
    function modify_edit_field_input( $field_content = '', $field, $value, $lead_id = 0, $form_id ) {
0 ignored issues
show
Unused Code introduced by
The parameter $lead_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Unused Code introduced by
The parameter $form_id is not used and could be removed.

This check looks from parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
915
916
        $gv_field = GravityView_Fields::get_associated_field( $field );
917
918
        // If the form has been submitted, then we don't need to pre-fill the values,
919
        // Except for fileupload type and when a field input is overridden- run always!!
920
        if(
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
921
            ( $this->is_edit_entry_submission() && !in_array( $field->type, array( 'fileupload', 'post_image' ) ) )
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
922
            && false === ( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) )
923
            || ! empty( $field_content )
924
            || GFCommon::is_product_field( $field->type ) // Prevent product fields from appearing editable
925
        ) {
926
	        return $field_content;
927
        }
928
929
        // Turn on Admin-style display for file upload fields only
930
        if( 'fileupload' === $field->type ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
931
            $_GET['page'] = 'gf_entries';
932
        }
933
934
        // SET SOME FIELD DEFAULTS TO PREVENT ISSUES
935
        $field->adminOnly = false; /** @see GFFormDisplay::get_counter_init_script() need to prevent adminOnly */
936
937
        // add categories as choices for Post Category field
938
        if ( 'post_category' === $field->type ) {
939
            $field = GFCommon::add_categories_as_choices( $field, $value );
940
        }
941
942
        $field_value = $this->get_field_value( $field );
943
944
        /**
945
         * @filter `gravityview/edit_entry/field_value` Change the value of an Edit Entry field, if needed
946
         * @since 1.11
947
         * @param mixed $field_value field value used to populate the input
948
         * @param object $field Gravity Forms field object ( Class GF_Field )
949
         */
950
        $field_value = apply_filters( 'gravityview/edit_entry/field_value', $field_value, $field );
951
952
	    // Prevent any PHP warnings, like undefined index
953
	    ob_start();
954
955
        if( $gv_field && is_callable( array( $gv_field, 'get_field_input' ) ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
956
            $return = $gv_field->get_field_input( $this->form, $field_value, $this->entry, $field );
957
        } else {
958
	        $return = $field->get_field_input( $this->form, $field_value, $this->entry );
959
        }
960
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
961
962
	    // If there was output, it's an error
963
	    $warnings = ob_get_clean();
964
965
	    if( !empty( $warnings ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
966
		    do_action( 'gravityview_log_error', __METHOD__ . $warnings, $field_value );
967
	    }
968
969
        /**
970
         * Unset hack $_GET['page'] = 'gf_entries'
971
         * We need the fileupload html field to render with the proper id
972
         *  ( <li id="field_80_16" ... > )
973
         */
974
        unset( $_GET['page'] );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
975
976
        return $return;
977
    }
978
979
    /**
980
     * Modify the value for the current field input
981
     *
982
     * @param GF_Field $field
983
     *
984
     * @return array|mixed|string|void
985
     */
986
    private function get_field_value( $field ) {
987
988
        /**
989
         * @filter `gravityview/edit_entry/pre_populate/override` Allow the pre-populated value to override saved value in Edit Entry form. By default, pre-populate mechanism only kicks on empty fields.
990
         * @param boolean True: override saved values; False: don't override (default)
991
         * @param $field GF_Field object Gravity Forms field object
992
         * @since 1.13
993
         */
994
        $override_saved_value = apply_filters( 'gravityview/edit_entry/pre_populate/override', false, $field );
995
996
        // We're dealing with multiple inputs (e.g. checkbox) but not time or date (as it doesn't store data in input IDs)
997
        if( isset( $field->inputs ) && is_array( $field->inputs ) && !in_array( $field->type, array( 'time', 'date' ) ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
998
999
            $field_value = array();
1000
1001
            // only accept pre-populated values if the field doesn't have any choice selected.
1002
            $allow_pre_populated = $field->allowsPrepopulate;
1003
1004
            foreach ( (array)$field->inputs as $input ) {
0 ignored issues
show
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1005
1006
                $input_id = strval( $input['id'] );
1007
                
1008
                if ( isset( $this->entry[ $input_id ] ) && ! gv_empty( $this->entry[ $input_id ], false, false ) ) {
1009
                    $field_value[ $input_id ] =  'post_category' === $field->type ? GFCommon::format_post_category( $this->entry[ $input_id ], true ) : $this->entry[ $input_id ];
0 ignored issues
show
introduced by
Expected 1 space after "="; 2 found
Loading history...
1010
                    $allow_pre_populated = false;
1011
                }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1012
1013
            }
1014
1015
            $pre_value = $field->get_value_submission( array(), false );
1016
1017
            $field_value = ! $allow_pre_populated && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $field_value : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1018
1019
        } else {
1020
1021
            $id = intval( $field->id );
1022
1023
            // get pre-populated value if exists
1024
            $pre_value = $field->allowsPrepopulate ? GFFormsModel::get_parameter_value( $field->inputName, array(), $field ) : '';
1025
1026
            // saved field entry value (if empty, fallback to the pre-populated value, if exists)
1027
            // or pre-populated value if not empty and set to override saved value
1028
            $field_value = !gv_empty( $this->entry[ $id ], false, false ) && ! ( $override_saved_value && !gv_empty( $pre_value, false, false ) ) ? $this->entry[ $id ] : $pre_value;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1029
1030
            // in case field is post_category but inputType is select, multi-select or radio, convert value into array of category IDs.
1031
            if ( 'post_category' === $field->type && !gv_empty( $field_value, false, false ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1032
                $categories = array();
1033
                foreach ( explode( ',', $field_value ) as $cat_string ) {
1034
                    $categories[] = GFCommon::format_post_category( $cat_string, true );
1035
                }
1036
                $field_value = 'multiselect' === $field->get_input_type() ? $categories : implode( '', $categories );
1037
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1038
1039
        }
1040
1041
        // if value is empty get the default value if defined
1042
        $field_value = $field->get_value_default_if_empty( $field_value );
1043
1044
        return $field_value;
1045
    }
1046
1047
1048
    // ---- Entry validation
1049
1050
    /**
1051
     * Add field keys that Gravity Forms expects.
1052
     *
1053
     * @see GFFormDisplay::validate()
1054
     * @param  array $form GF Form
1055
     * @return array       Modified GF Form
1056
     */
1057
    function gform_pre_validation( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1058
1059
        if( ! $this->verify_nonce() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1060
            return $form;
1061
        }
1062
1063
        // Fix PHP warning regarding undefined index.
1064
        foreach ( $form['fields'] as &$field) {
0 ignored issues
show
introduced by
No space before closing parenthesis is prohibited
Loading history...
1065
1066
            // This is because we're doing admin form pretending to be front-end, so Gravity Forms
1067
            // expects certain field array items to be set.
1068
            foreach ( array( 'noDuplicates', 'adminOnly', 'inputType', 'isRequired', 'enablePrice', 'inputs', 'allowedExtensions' ) as $key ) {
1069
	            $field->{$key} = isset( $field->{$key} ) ? $field->{$key} : NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1070
            }
1071
1072
            // unset emailConfirmEnabled for email type fields
1073
           /* if( 'email' === $field['type'] && !empty( $field['emailConfirmEnabled'] ) ) {
1 ignored issue
show
Unused Code Comprehensibility introduced by
61% of this comment could be valid code. Did you maybe forget this after debugging?

Sometimes obsolete code just ends up commented out instead of removed. In this case it is better to remove the code once you have checked you do not need it.

The code might also have been commented out for debugging purposes. In this case it is vital that someone uncomments it again or your project may behave in very unexpected ways in production.

This check looks for comments that seem to be mostly valid code and reports them.

Loading history...
Coding Style introduced by
Line indented incorrectly; expected at least 3 tabs, found 2
Loading history...
1074
                $field['emailConfirmEnabled'] = '';
1075
            }*/
1076
1077
            switch( RGFormsModel::get_input_type( $field ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1078
1079
                /**
1080
                 * this whole fileupload hack is because in the admin, Gravity Forms simply doesn't update any fileupload field if it's empty, but it DOES in the frontend.
1081
                 *
1082
                 * What we have to do is set the value so that it doesn't get overwritten as empty on save and appears immediately in the Edit Entry screen again.
1083
                 *
1084
                 * @hack
1085
                 */
1086
                case 'fileupload':
1087
1088
                    // Set the previous value
1089
                    $entry = $this->get_entry();
1090
1091
                    $input_name = 'input_'.$field->id;
1092
                    $form_id = $form['id'];
1093
1094
                    $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1095
1096
                    // Use the previous entry value as the default.
1097
                    if( isset( $entry[ $field->id ] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1098
                        $value = $entry[ $field->id ];
1099
                    }
1100
1101
                    // If this is a single upload file
1102
                    if( !empty( $_FILES[ $input_name ] ) && !empty( $_FILES[ $input_name ]['name'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1103
                        $file_path = GFFormsModel::get_file_upload_path( $form['id'], $_FILES[ $input_name ]['name'] );
1104
                        $value = $file_path['url'];
1105
1106
                    } else {
1107
1108
                        // Fix PHP warning on line 1498 of form_display.php for post_image fields
1109
                        // Fix PHP Notice:  Undefined index:  size in form_display.php on line 1511
1110
                        $_FILES[ $input_name ] = array('name' => '', 'size' => '' );
0 ignored issues
show
introduced by
No space after opening parenthesis of array is bad style
Loading history...
1111
1112
                    }
1113
1114
                    if( rgar($field, "multipleFiles") ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal multipleFiles does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1115
1116
                        // If there are fresh uploads, process and merge them.
1117
                        // Otherwise, use the passed values, which should be json-encoded array of URLs
1118
                        if( isset( GFFormsModel::$uploaded_files[$form_id][$input_name] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1119
                            $value = empty( $value ) ? '[]' : $value;
1120
                            $value = stripslashes_deep( $value );
1121
                            $value = GFFormsModel::prepare_value( $form, $field, $value, $input_name, $entry['id'], array());
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1122
                        }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1123
1124
                    } else {
1125
1126
                        // A file already exists when editing an entry
1127
                        // We set this to solve issue when file upload fields are required.
1128
                        GFFormsModel::$uploaded_files[ $form_id ][ $input_name ] = $value;
1129
1130
                    }
1131
1132
                    $this->entry[ $input_name ] = $value;
1133
                    $_POST[ $input_name ] = $value;
1134
1135
                    break;
1136
1137
                case 'number':
1138
                    // Fix "undefined index" issue at line 1286 in form_display.php
1139
                    if( !isset( $_POST['input_'.$field->id ] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
1140
                        $_POST['input_'.$field->id ] = NULL;
0 ignored issues
show
introduced by
Array keys should be surrounded by spaces unless they contain a string or an integer.
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1141
                    }
1142
                    break;
1143
                case 'captcha':
1144
                    // Fix issue with recaptcha_check_answer() on line 1458 in form_display.php
1145
                    $_POST['recaptcha_challenge_field'] = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1146
                    $_POST['recaptcha_response_field'] = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1147
                    break;
1148
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1149
1150
        }
1151
1152
        return $form;
1153
    }
1154
1155
1156
    /**
1157
     * Process validation for a edit entry submission
1158
     *
1159
     * Sets the `is_valid` object var
1160
     *
1161
     * @return void
1162
     */
1163
    function validate() {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1164
1165
        /**
1166
         * If using GF User Registration Add-on, remove the validation step, otherwise generates error when updating the entry
1167
         * GF User Registration Add-on version > 3.x has a different class name
1168
         * @since 1.16.2
1169
         */
1170
        if ( class_exists( 'GF_User_Registration' ) ) {
1171
            remove_filter( 'gform_validation', array( GF_User_Registration::get_instance(), 'validate' ) );
1172
        } else  if ( class_exists( 'GFUser' ) ) {
1173
            remove_filter( 'gform_validation', array( 'GFUser', 'user_registration_validation' ) );
1174
        }
1175
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1176
1177
        /**
1178
         * For some crazy reason, Gravity Forms doesn't validate Edit Entry form submissions.
1179
         * You can enter whatever you want!
1180
         * We try validating, and customize the results using `self::custom_validation()`
1181
         */
1182
        add_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10, 4);
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1183
1184
        // Needed by the validate funtion
1185
        $failed_validation_page = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1186
        $field_values = RGForms::post( 'gform_field_values' );
1187
1188
        // Prevent entry limit from running when editing an entry, also
1189
        // prevent form scheduling from preventing editing
1190
        unset( $this->form['limitEntries'], $this->form['scheduleForm'] );
1191
1192
        // Hide fields depending on Edit Entry settings
1193
        $this->form['fields'] = $this->get_configured_edit_fields( $this->form, $this->view_id );
1194
1195
        $this->is_valid = GFFormDisplay::validate( $this->form, $field_values, 1, $failed_validation_page );
1196
1197
        remove_filter( 'gform_validation_'. $this->form_id, array( $this, 'custom_validation' ), 10 );
1198
    }
1199
1200
1201
    /**
1202
     * Make validation work for Edit Entry
1203
     *
1204
     * Because we're calling the GFFormDisplay::validate() in an unusual way (as a front-end
1205
     * form pretending to be a back-end form), validate() doesn't know we _can't_ edit post
1206
     * fields. This goes through all the fields and if they're an invalid post field, we
1207
     * set them as valid. If there are still issues, we'll return false.
1208
     *
1209
     * @param  [type] $validation_results [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1210
     * @return [type]                     [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1211
     */
1212
    function custom_validation( $validation_results ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1213
1214
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results: ', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1215
1216
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] $_POSTed data (sanitized): ', esc_html( print_r( $_POST, true ) ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
introduced by
The use of function print_r() is discouraged
Loading history...
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
1217
1218
        $gv_valid = true;
1219
1220
        foreach ( $validation_results['form']['fields'] as $key => &$field ) {
1221
1222
            $value = RGFormsModel::get_field_value( $field );
1223
            $field_type = RGFormsModel::get_input_type( $field );
1224
1225
            // Validate always
1226
            switch ( $field_type ) {
1227
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1228
1229
                case 'fileupload' :
1230
                case 'post_image':
1231
1232
                    // in case nothing is uploaded but there are already files saved
1233
                    if( !empty( $field->failed_validation ) && !empty( $field->isRequired ) && !empty( $value ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1234
                        $field->failed_validation = false;
1235
                        unset( $field->validation_message );
1236
                    }
1237
1238
                    // validate if multi file upload reached max number of files [maxFiles] => 2
1239
                    if( rgobj( $field, 'maxFiles') && rgobj( $field, 'multipleFiles') ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1240
1241
                        $input_name = 'input_' . $field->id;
1242
                        //uploaded
1243
                        $file_names = isset( GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] ) ? GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ][ $input_name ] : array();
1244
1245
                        //existent
1246
                        $entry = $this->get_entry();
1247
                        $value = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1248
                        if( isset( $entry[ $field->id ] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1249
                            $value = json_decode( $entry[ $field->id ], true );
1250
                        }
1251
1252
                        // count uploaded files and existent entry files
1253
                        $count_files = count( $file_names ) + count( $value );
1254
1255
                        if( $count_files > $field->maxFiles ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1256
                            $field->validation_message = __( 'Maximum number of files reached', 'gravityview' );
1257
                            $field->failed_validation = 1;
1258
                            $gv_valid = false;
1259
1260
                            // in case of error make sure the newest upload files are removed from the upload input
1261
                            GFFormsModel::$uploaded_files[ $validation_results['form']['id'] ] = null;
1262
                        }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1263
1264
                    }
1265
0 ignored issues
show
Coding Style introduced by
Functions must not contain multiple empty lines in a row; found 2 empty lines
Loading history...
1266
1267
                    break;
1268
1269
            }
1270
1271
            // This field has failed validation.
1272
            if( !empty( $field->failed_validation ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1273
1274
                do_action( 'gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field is invalid.', array( 'field' => $field, 'value' => $value ) );
1275
1276
                switch ( $field_type ) {
1277
1278
                    // Captchas don't need to be re-entered.
1279
                    case 'captcha':
1280
1281
                        // Post Image fields aren't editable, so we un-fail them.
1282
                    case 'post_image':
1283
                        $field->failed_validation = false;
1284
                        unset( $field->validation_message );
1285
                        break;
1286
1287
                }
1288
1289
                // You can't continue inside a switch, so we do it after.
1290
                if( empty( $field->failed_validation ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1291
                    continue;
1292
                }
1293
1294
                // checks if the No Duplicates option is not validating entry against itself, since
1295
                // we're editing a stored entry, it would also assume it's a duplicate.
1296
                if( !empty( $field->noDuplicates ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1297
1298
                    $entry = $this->get_entry();
1299
1300
                    // If the value of the entry is the same as the stored value
1301
                    // Then we can assume it's not a duplicate, it's the same.
1302
                    if( !empty( $entry ) && $value == $entry[ $field->id ] ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1303
                        //if value submitted was not changed, then don't validate
1304
                        $field->failed_validation = false;
1305
1306
                        unset( $field->validation_message );
1307
1308
                        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Field not a duplicate; it is the same entry.', $entry );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1309
1310
                        continue;
1311
                    }
1312
                }
1313
1314
                // if here then probably we are facing the validation 'At least one field must be filled out'
1315
                if( GFFormDisplay::is_empty( $field, $this->form_id  ) && empty( $field->isRequired ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 2 found
Loading history...
1316
                    unset( $field->validation_message );
1317
	                $field->validation_message = false;
1318
                    continue;
1319
                }
1320
1321
                $gv_valid = false;
1322
1323
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1324
1325
        }
1326
1327
        $validation_results['is_valid'] = $gv_valid;
1328
1329
        do_action('gravityview_log_debug', 'GravityView_Edit_Entry[custom_validation] Validation results.', $validation_results );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1330
1331
        // We'll need this result when rendering the form ( on GFFormDisplay::get_form )
1332
        $this->form_after_validation = $validation_results['form'];
1333
1334
        return $validation_results;
1335
    }
1336
1337
1338
    /**
1339
     * TODO: This seems to be hacky... we should remove it. Entry is set when updating the form using setup_vars()!
1340
     * Get the current entry and set it if it's not yet set.
1341
     * @return array Gravity Forms entry array
1342
     */
1343
    private function get_entry() {
1344
1345
        if( empty( $this->entry ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1346
            // Get the database value of the entry that's being edited
1347
            $this->entry = gravityview_get_entry( GravityView_frontend::is_single_entry() );
1348
        }
1349
1350
        return $this->entry;
1351
    }
1352
1353
1354
1355
    // --- Filters
1356
1357
    /**
1358
     * Get the Edit Entry fields as configured in the View
1359
     *
1360
     * @since 1.8
1361
     *
1362
     * @param int $view_id
1363
     *
1364
     * @return array Array of fields that are configured in the Edit tab in the Admin
1365
     */
1366
    private function get_configured_edit_fields( $form, $view_id ) {
1367
1368
        // Get all fields for form
1369
        $properties = GravityView_View_Data::getInstance()->get_fields( $view_id );
1370
1371
        // If edit tab not yet configured, show all fields
1372
        $edit_fields = !empty( $properties['edit_edit-fields'] ) ? $properties['edit_edit-fields'] : NULL;
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1373
1374
	    // Show hidden fields as text fields
1375
	    $form = $this->fix_hidden_fields( $form );
1376
1377
        // Hide fields depending on admin settings
1378
        $fields = $this->filter_fields( $form['fields'], $edit_fields );
1379
1380
	    // If Edit Entry fields are configured, remove adminOnly field settings. Otherwise, don't.
1381
	    $fields = $this->filter_admin_only_fields( $fields, $edit_fields, $form, $view_id );
1382
1383
        return $fields;
1384
    }
1385
1386
	/**
1387
	 * @since 1.9.2
1388
	 *
1389
	 * @param $fields
1390
	 *
1391
	 * @return mixed
1392
	 */
1393
	private function fix_hidden_fields( $form ) {
1394
1395
		/** @var GF_Field $field */
1396
		foreach( $form['fields'] as $key => $field ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1397
			if( 'hidden' === $field->type ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1398
				$text_field = new GF_Field_Text( $field );
1399
				$text_field->type = 'text';
1400
				$form['fields'][ $key ] = $text_field;
1401
			}
1402
		}
1403
1404
		return $form;
1405
	}
1406
1407
1408
    /**
1409
     * Filter area fields based on specified conditions
1410
     *  - This filter removes the fields that have calculation configured
1411
     *
1412
     * @uses GravityView_Edit_Entry::user_can_edit_field() Check caps
1413
     * @access private
1414
     * @param GF_Field[] $fields
1415
     * @param array $configured_fields
1416
     * @since  1.5
1417
     * @return array $fields
1418
     */
1419
    private function filter_fields( $fields, $configured_fields ) {
1420
1421
        if( empty( $fields ) || !is_array( $fields ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1422
            return $fields;
1423
        }
1424
1425
        $edit_fields = array();
1426
1427
        $field_type_blacklist = array(
1428
            'page',
1429
        );
1430
1431
	    /**
1432
	     * @filter `gravityview/edit_entry/hide-product-fields` Hide product fields from being editable.
1433
	     * @since 1.9.1
1434
         * @param boolean $hide_product_fields Whether to hide product fields in the editor.  Default: false
1435
	     */
1436
	    $hide_product_fields = apply_filters( 'gravityview/edit_entry/hide-product-fields', empty( self::$supports_product_fields ) );
1437
1438
	    if( $hide_product_fields ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1439
		    $field_type_blacklist[] = 'option';
1440
		    $field_type_blacklist[] = 'quantity';
1441
            $field_type_blacklist[] = 'product';
1442
            $field_type_blacklist[] = 'total';
1443
            $field_type_blacklist[] = 'shipping';
1444
            $field_type_blacklist[] = 'calculation';
1445
	    }
1446
1447
        // First, remove blacklist or calculation fields
1448
        foreach ( $fields as $key => $field ) {
1449
1450
            // Remove the fields that have calculation properties and keep them to be used later
1451
            // @since 1.16.2
1452
            if( $field->has_calculation() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1453
                $this->fields_with_calculation[] = $field;
1454
                unset( $fields[ $key ] );
1455
            }
1456
1457
            // process total field after all fields have been saved
1458
            if ( $field->type == 'total' ) {
0 ignored issues
show
introduced by
Found "== '". Use Yoda Condition checks, you must
Loading history...
1459
                $this->total_fields[] = $field;
1460
                unset( $fields[ $key ] );
1461
            }
1462
1463
            if( in_array( $field->type, $field_type_blacklist ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1464
                unset( $fields[ $key ] );
1465
            }
1466
        }
1467
1468
        // The Edit tab has not been configured, so we return all fields by default.
1469
        if( empty( $configured_fields ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1470
            return $fields;
1471
        }
1472
1473
        // The edit tab has been configured, so we loop through to configured settings
1474
        foreach ( $configured_fields as $configured_field ) {
1475
1476
	        /** @var GF_Field $field */
1477
	        foreach ( $fields as $field ) {
1478
1479
                if( intval( $configured_field['id'] ) === intval( $field->id ) && $this->user_can_edit_field( $configured_field, false ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1480
                    $edit_fields[] = $this->merge_field_properties( $field, $configured_field );
1481
                    break;
1482
                }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1483
1484
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1485
1486
        }
1487
1488
        return $edit_fields;
1489
1490
    }
1491
1492
    /**
1493
     * Override GF Form field properties with the ones defined on the View
1494
     * @param  GF_Field $field GF Form field object
1495
     * @param  array $setting  GV field options
0 ignored issues
show
Documentation introduced by
There is no parameter named $setting. Did you maybe mean $field_setting?

This check looks for PHPDoc comments describing methods or function parameters that do not exist on the corresponding method or function. It has, however, found a similar but not annotated parameter which might be a good fit.

Consider the following example. The parameter $ireland is not defined by the method finale(...).

/**
 * @param array $germany
 * @param array $ireland
 */
function finale($germany, $island) {
    return "2:1";
}

The most likely cause is that the parameter was changed, but the annotation was not.

Loading history...
1496
     * @since  1.5
1497
     * @return array
1498
     */
1499
    private function merge_field_properties( $field, $field_setting ) {
1500
1501
        $return_field = $field;
1502
1503
        if( empty( $field_setting['show_label'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1504
            $return_field->label = '';
1505
        } elseif ( !empty( $field_setting['custom_label'] ) ) {
0 ignored issues
show
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1506
            $return_field->label = $field_setting['custom_label'];
1507
        }
1508
1509
        if( !empty( $field_setting['custom_class'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1510
            $return_field->cssClass .= ' '. gravityview_sanitize_html_class( $field_setting['custom_class'] );
1511
        }
1512
1513
        /**
1514
         * Normalize page numbers - avoid conflicts with page validation
1515
         * @since 1.6
1516
         */
1517
        $return_field->pageNumber = 1;
1518
1519
        return $return_field;
1520
1521
    }
1522
1523
    /**
1524
     * Remove fields that shouldn't be visible based on the Gravity Forms adminOnly field property
1525
     *
1526
     * @since 1.9.1
1527
     *
1528
     * @param array|GF_Field[] $fields Gravity Forms form fields
1529
     * @param array|null $edit_fields Fields for the Edit Entry tab configured in the View Configuration
1530
     * @param array $form GF Form array
1531
     * @param int $view_id View ID
1532
     *
1533
     * @return array Possibly modified form array
1534
     */
1535
    function filter_admin_only_fields( $fields = array(), $edit_fields = null, $form = array(), $view_id = 0 ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1536
1537
	    /**
1538
         * @filter `gravityview/edit_entry/use_gf_admin_only_setting` When Edit tab isn't configured, should the Gravity Forms "Admin Only" field settings be used to control field display to non-admins? Default: true
1539
	     * If the Edit Entry tab is not configured, adminOnly fields will not be shown to non-administrators.
1540
	     * If the Edit Entry tab *is* configured, adminOnly fields will be shown to non-administrators, using the configured GV permissions
1541
	     * @since 1.9.1
1542
	     * @param boolean $use_gf_adminonly_setting True: Hide field if set to Admin Only in GF and the user is not an admin. False: show field based on GV permissions, ignoring GF permissions.
1543
	     * @param array $form GF Form array
1544
	     * @param int $view_id View ID
1545
	     */
1546
	    $use_gf_adminonly_setting = apply_filters( 'gravityview/edit_entry/use_gf_admin_only_setting', empty( $edit_fields ), $form, $view_id );
1547
1548
	    if( $use_gf_adminonly_setting && false === GVCommon::has_cap( 'gravityforms_edit_entries', $this->entry['id'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1549
            foreach( $fields as $k => $field ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1550
                if( $field->adminOnly ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1551
                    unset( $fields[ $k ] );
1552
                }
1553
            }
1554
            return $fields;
1555
        }
1556
1557
	    foreach( $fields as &$field ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1558
		    $field->adminOnly = false;
1559
        }
1560
1561
        return $fields;
1562
    }
1563
1564
    // --- Conditional Logic
1565
1566
    /**
1567
     * Remove the conditional logic rules from the form button and the form fields, if needed.
1568
     *
1569
     * @since 1.9
1570
     *
1571
     * @param array $form Gravity Forms form
1572
     * @return array Modified form, if not using Conditional Logic
1573
     */
1574
    function filter_conditional_logic( $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1575
1576
        /**
1577
         * @filter `gravityview/edit_entry/conditional_logic` Should the Edit Entry form use Gravity Forms conditional logic showing/hiding of fields?
1578
         * @since 1.9
1579
         * @param bool $use_conditional_logic True: Gravity Forms will show/hide fields just like in the original form; False: conditional logic will be disabled and fields will be shown based on configuration. Default: true
1580
         * @param array $form Gravity Forms form
1581
         */
1582
        $use_conditional_logic = apply_filters( 'gravityview/edit_entry/conditional_logic', true, $form );
1583
1584
        if( $use_conditional_logic ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1585
            return $form;
1586
        }
1587
1588
        foreach( $form['fields'] as &$field ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1589
            /* @var GF_Field $field */
1590
            $field->conditionalLogic = null;
1591
        }
1592
1593
        unset( $form['button']['conditionalLogic'] );
1594
1595
        return $form;
1596
1597
    }
1598
1599
    /**
1600
     * Disable the Gravity Forms conditional logic script and features on the Edit Entry screen
1601
     *
1602
     * @since 1.9
1603
     *
1604
     * @param $has_conditional_logic
1605
     * @param $form
1606
     * @return mixed|void
1607
     */
1608
    function manage_conditional_logic( $has_conditional_logic, $form ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1609
1610
        if( ! $this->is_edit_entry() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1611
            return $has_conditional_logic;
1612
        }
1613
1614
        return apply_filters( 'gravityview/edit_entry/conditional_logic', $has_conditional_logic, $form );
1615
    }
1616
1617
1618
    // --- User checks and nonces
1619
1620
    /**
1621
     * Check if the user can edit the entry
1622
     *
1623
     * - Is the nonce valid?
1624
     * - Does the user have the right caps for the entry
1625
     * - Is the entry in the trash?
1626
     *
1627
     * @todo Move to GVCommon
1628
     *
1629
     * @param  boolean $echo Show error messages in the form?
1630
     * @return boolean        True: can edit form. False: nope.
1631
     */
1632
    function user_can_edit_entry( $echo = false ) {
0 ignored issues
show
Best Practice introduced by
It is generally recommended to explicitly declare the visibility for methods.

Adding explicit visibility (private, protected, or public) is generally recommend to communicate to other developers how, and from where this method is intended to be used.

Loading history...
1633
1634
        $error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1635
1636
        /**
1637
         *  1. Permalinks are turned off
1638
         *  2. There are two entries embedded using oEmbed
1639
         *  3. One of the entries has just been saved
1640
         */
1641
        if( !empty( $_POST['lid'] ) && !empty( $_GET['entry'] ) && ( $_POST['lid'] !== $_GET['entry'] ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
1642
1643
            $error = true;
1644
1645
        }
1646
1647
        if( !empty( $_GET['entry'] ) && (string)$this->entry['id'] !== $_GET['entry'] ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
introduced by
Expected 1 space after "!"; 0 found
Loading history...
introduced by
No space after closing casting parenthesis is prohibited
Loading history...
1648
1649
            $error = true;
1650
1651
        } elseif( ! $this->verify_nonce() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1652
1653
            /**
1654
             * If the Entry is embedded, there may be two entries on the same page.
1655
             * If that's the case, and one is being edited, the other should fail gracefully and not display an error.
1656
             */
1657
            if( GravityView_oEmbed::getInstance()->get_entry_id() ) {
0 ignored issues
show
Bug Best Practice introduced by
The expression \GravityView_oEmbed::get...tance()->get_entry_id() of type integer|null is loosely compared to true; this is ambiguous if the integer can be zero. You might want to explicitly use !== null instead.

In PHP, under loose comparison (like ==, or !=, or switch conditions), values of different types might be equal.

For integer values, zero is a special case, in particular the following results might be unexpected:

0   == false // true
0   == null  // true
123 == false // false
123 == null  // false

// It is often better to use strict comparison
0 === false // false
0 === null  // false
Loading history...
introduced by
Space after opening control structure is required
Loading history...
1658
                $error = true;
1659
            } else {
1660
                $error = __( 'The link to edit this entry is not valid; it may have expired.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1661
            }
1 ignored issue
show
introduced by
Blank line found after control structure
Loading history...
1662
1663
        }
1664
1665
        if( ! GravityView_Edit_Entry::check_user_cap_edit_entry( $this->entry ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1666
            $error = __( 'You do not have permission to edit this entry.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1667
        }
1668
1669
        if( $this->entry['status'] === 'trash' ) {
0 ignored issues
show
introduced by
Found "=== '". Use Yoda Condition checks, you must
Loading history...
introduced by
Space after opening control structure is required
Loading history...
1670
            $error = __('You cannot edit the entry; it is in the trash.', 'gravityview' );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1671
        }
1672
1673
        // No errors; everything's fine here!
1674
        if( empty( $error ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1675
            return true;
1676
        }
1677
1678
        if( $echo && $error !== true ) {
0 ignored issues
show
introduced by
Found "!== true". Use Yoda Condition checks, you must
Loading history...
introduced by
Space after opening control structure is required
Loading history...
1679
1680
	        $error = esc_html( $error );
1681
1682
	        /**
1683
	         * @since 1.9
1684
	         */
1685
	        if ( ! empty( $this->entry ) ) {
1686
		        $error .= ' ' . gravityview_get_link( '#', _x('Go back.', 'Link shown when invalid Edit Entry link is clicked', 'gravityview' ), array( 'onclick' => "window.history.go(-1); return false;" ) );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
Coding Style Comprehensibility introduced by
The string literal window.history.go(-1); return false; does not require double quotes, as per coding-style, please use single quotes.

PHP provides two ways to mark string literals. Either with single quotes 'literal' or with double quotes "literal". The difference between these is that string literals in double quotes may contain variables with are evaluated at run-time as well as escape sequences.

String literals in single quotes on the other hand are evaluated very literally and the only two characters that needs escaping in the literal are the single quote itself (\') and the backslash (\\). Every other character is displayed as is.

Double quoted string literals may contain other variables or more complex escape sequences.

<?php

$singleQuoted = 'Value';
$doubleQuoted = "\tSingle is $singleQuoted";

print $doubleQuoted;

will print an indented: Single is Value

If your string literal does not contain variables or escape sequences, it should be defined using single quotes to make that fact clear.

For more information on PHP string literals and available escape sequences see the PHP core documentation.

Loading history...
1687
	        }
1688
1689
            echo GVCommon::generate_notice( wpautop( $error ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1690
        }
1691
1692
        do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_entry]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1693
1694
        return false;
1695
    }
1696
1697
1698
    /**
1699
     * Check whether a field is editable by the current user, and optionally display an error message
1700
     * @uses  GravityView_Edit_Entry->check_user_cap_edit_field() Check user capabilities
1701
     * @param  array  $field Field or field settings array
1702
     * @param  boolean $echo  Whether to show error message telling user they aren't allowed
1703
     * @return boolean         True: user can edit the current field; False: nope, they can't.
1704
     */
1705
    private function user_can_edit_field( $field, $echo = false ) {
1706
1707
        $error = NULL;
0 ignored issues
show
Coding Style introduced by
TRUE, FALSE and NULL must be lowercase; expected null, but found NULL.
Loading history...
1708
1709
        if( ! $this->check_user_cap_edit_field( $field ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1710
            $error = __( 'You do not have permission to edit this field.', 'gravityview');
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1711
        }
1712
1713
        // No errors; everything's fine here!
1714
        if( empty( $error ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1715
            return true;
1716
        }
1717
1718
        if( $echo ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1719
            echo GVCommon::generate_notice( wpautop( esc_html( $error ) ), 'gv-error error');
0 ignored issues
show
introduced by
Expected a sanitizing function (see Codex for 'Data Validation'), but instead saw 'GVCommon'
Loading history...
Coding Style introduced by
Expected 1 spaces before closing bracket; 0 found
Loading history...
1720
        }
1721
1722
        do_action('gravityview_log_error', 'GravityView_Edit_Entry[user_can_edit_field]' . $error );
0 ignored issues
show
Coding Style introduced by
Expected 1 spaces after opening bracket; 0 found
Loading history...
1723
1724
        return false;
1725
1726
    }
1727
1728
1729
    /**
1730
     * checks if user has permissions to edit a specific field
1731
     *
1732
     * Needs to be used combined with GravityView_Edit_Entry::user_can_edit_field for maximum security!!
1733
     *
1734
     * @param  [type] $field [description]
0 ignored issues
show
Documentation introduced by
The doc-type [type] could not be parsed: Unknown type name "" at position 0. [(view supported doc-types)

This check marks PHPDoc comments that could not be parsed by our parser. To see which comment annotations we can parse, please refer to our documentation on supported doc-types.

Loading history...
1735
     * @return bool
1736
     */
1737
    private function check_user_cap_edit_field( $field ) {
1738
1739
        // If they can edit any entries (as defined in Gravity Forms), we're good.
1740
        if( GVCommon::has_cap( array( 'gravityforms_edit_entries', 'gravityview_edit_others_entries' ) ) ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1741
            return true;
1742
        }
1743
1744
        $field_cap = isset( $field['allow_edit_cap'] ) ? $field['allow_edit_cap'] : false;
1745
1746
        // If the field has custom editing capaibilities set, check those
1747
        if( $field_cap ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1748
            return GVCommon::has_cap( $field['allow_edit_cap'] );
1749
        }
1750
1751
        return false;
1752
    }
1753
1754
1755
    /**
1756
     * Is the current nonce valid for editing the entry?
1757
     * @return boolean
1758
     */
1759
    public function verify_nonce() {
1760
1761
        // Verify form submitted for editing single
1762
        if( $this->is_edit_entry_submission() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1763
            $valid = wp_verify_nonce( $_POST[ self::$nonce_field ], self::$nonce_field );
0 ignored issues
show
introduced by
Detected access of super global var $_POST, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_POST
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_POST
Loading history...
1764
        }
1765
1766
        // Verify
1767
        else if( ! $this->is_edit_entry() ) {
0 ignored issues
show
introduced by
Space after opening control structure is required
Loading history...
1768
            $valid = false;
1769
        }
1770
1771
        else {
1772
            $valid = wp_verify_nonce( $_GET['edit'], self::$nonce_key );
0 ignored issues
show
introduced by
Detected access of super global var $_GET, probably need manual inspection.
Loading history...
introduced by
Detected usage of a non-validated input variable: $_GET
Loading history...
introduced by
Detected usage of a non-sanitized input variable: $_GET
Loading history...
1773
        }
1774
1775
        /**
1776
         * @filter `gravityview/edit_entry/verify_nonce` Override Edit Entry nonce validation. Return true to declare nonce valid.
1777
         * @since 1.13
1778
         * @param int|boolean $valid False if invalid; 1 or 2 when nonce was generated
1779
         * @param string $nonce_field Key used when validating submissions. Default: is_gv_edit_entry
1780
         */
1781
        $valid = apply_filters( 'gravityview/edit_entry/verify_nonce', $valid, self::$nonce_field );
1782
1783
        return $valid;
1784
    }
1785
1786
1787
1788
} //end class