PageRenderTime 45ms CodeModel.GetById 16ms RepoModel.GetById 0ms app.codeStats 0ms

/wordpress/wp-content/plugins/contact-form-7/modules/file.php

https://github.com/kronda/kronda
PHP | 353 lines | 241 code | 98 blank | 14 comment | 52 complexity | cba8efb20050a177e9aaf6f2c77f8be8 MD5 | raw file
  1. <?php
  2. /**
  3. ** A base module for [file] and [file*]
  4. **/
  5. /* Shortcode handler */
  6. add_action( 'wpcf7_init', 'wpcf7_add_shortcode_file' );
  7. function wpcf7_add_shortcode_file() {
  8. wpcf7_add_shortcode( array( 'file', 'file*' ),
  9. 'wpcf7_file_shortcode_handler', true );
  10. }
  11. function wpcf7_file_shortcode_handler( $tag ) {
  12. $tag = new WPCF7_Shortcode( $tag );
  13. if ( empty( $tag->name ) )
  14. return '';
  15. $validation_error = wpcf7_get_validation_error( $tag->name );
  16. $class = wpcf7_form_controls_class( $tag->type );
  17. if ( $validation_error )
  18. $class .= ' wpcf7-not-valid';
  19. $atts = array();
  20. $atts['size'] = $tag->get_size_option( '40' );
  21. $atts['class'] = $tag->get_class_option( $class );
  22. $atts['id'] = $tag->get_id_option();
  23. $atts['tabindex'] = $tag->get_option( 'tabindex', 'int', true );
  24. if ( $tag->is_required() )
  25. $atts['aria-required'] = 'true';
  26. $atts['aria-invalid'] = $validation_error ? 'true' : 'false';
  27. $atts['type'] = 'file';
  28. $atts['name'] = $tag->name;
  29. $atts['value'] = '1';
  30. $atts = wpcf7_format_atts( $atts );
  31. $html = sprintf(
  32. '<span class="wpcf7-form-control-wrap %1$s"><input %2$s />%3$s</span>',
  33. sanitize_html_class( $tag->name ), $atts, $validation_error );
  34. return $html;
  35. }
  36. /* Encode type filter */
  37. add_filter( 'wpcf7_form_enctype', 'wpcf7_file_form_enctype_filter' );
  38. function wpcf7_file_form_enctype_filter( $enctype ) {
  39. $multipart = (bool) wpcf7_scan_shortcode( array( 'type' => array( 'file', 'file*' ) ) );
  40. if ( $multipart ) {
  41. $enctype = 'multipart/form-data';
  42. }
  43. return $enctype;
  44. }
  45. /* Validation + upload handling filter */
  46. add_filter( 'wpcf7_validate_file', 'wpcf7_file_validation_filter', 10, 2 );
  47. add_filter( 'wpcf7_validate_file*', 'wpcf7_file_validation_filter', 10, 2 );
  48. function wpcf7_file_validation_filter( $result, $tag ) {
  49. $tag = new WPCF7_Shortcode( $tag );
  50. $name = $tag->name;
  51. $id = $tag->get_id_option();
  52. $file = isset( $_FILES[$name] ) ? $_FILES[$name] : null;
  53. if ( $file['error'] && UPLOAD_ERR_NO_FILE != $file['error'] ) {
  54. $result['valid'] = false;
  55. $result['reason'][$name] = wpcf7_get_message( 'upload_failed_php_error' );
  56. $result['idref'][$name] = $id ? $id : null;
  57. return $result;
  58. }
  59. if ( empty( $file['tmp_name'] ) && $tag->is_required() ) {
  60. $result['valid'] = false;
  61. $result['reason'][$name] = wpcf7_get_message( 'invalid_required' );
  62. $result['idref'][$name] = $id ? $id : null;
  63. return $result;
  64. }
  65. if ( ! is_uploaded_file( $file['tmp_name'] ) )
  66. return $result;
  67. $allowed_file_types = array();
  68. if ( $file_types_a = $tag->get_option( 'filetypes' ) ) {
  69. foreach ( $file_types_a as $file_types ) {
  70. $file_types = explode( '|', $file_types );
  71. foreach ( $file_types as $file_type ) {
  72. $file_type = trim( $file_type, '.' );
  73. $file_type = str_replace( array( '.', '+', '*', '?' ),
  74. array( '\.', '\+', '\*', '\?' ), $file_type );
  75. $allowed_file_types[] = $file_type;
  76. }
  77. }
  78. }
  79. $allowed_file_types = array_unique( $allowed_file_types );
  80. $file_type_pattern = implode( '|', $allowed_file_types );
  81. $allowed_size = 1048576; // default size 1 MB
  82. if ( $file_size_a = $tag->get_option( 'limit' ) ) {
  83. $limit_pattern = '/^([1-9][0-9]*)([kKmM]?[bB])?$/';
  84. foreach ( $file_size_a as $file_size ) {
  85. if ( preg_match( $limit_pattern, $file_size, $matches ) ) {
  86. $allowed_size = (int) $matches[1];
  87. if ( ! empty( $matches[2] ) ) {
  88. $kbmb = strtolower( $matches[2] );
  89. if ( 'kb' == $kbmb )
  90. $allowed_size *= 1024;
  91. elseif ( 'mb' == $kbmb )
  92. $allowed_size *= 1024 * 1024;
  93. }
  94. break;
  95. }
  96. }
  97. }
  98. /* File type validation */
  99. // Default file-type restriction
  100. if ( '' == $file_type_pattern )
  101. $file_type_pattern = 'jpg|jpeg|png|gif|pdf|doc|docx|ppt|pptx|odt|avi|ogg|m4a|mov|mp3|mp4|mpg|wav|wmv';
  102. $file_type_pattern = trim( $file_type_pattern, '|' );
  103. $file_type_pattern = '(' . $file_type_pattern . ')';
  104. $file_type_pattern = '/\.' . $file_type_pattern . '$/i';
  105. if ( ! preg_match( $file_type_pattern, $file['name'] ) ) {
  106. $result['valid'] = false;
  107. $result['reason'][$name] = wpcf7_get_message( 'upload_file_type_invalid' );
  108. $result['idref'][$name] = $id ? $id : null;
  109. return $result;
  110. }
  111. /* File size validation */
  112. if ( $file['size'] > $allowed_size ) {
  113. $result['valid'] = false;
  114. $result['reason'][$name] = wpcf7_get_message( 'upload_file_too_large' );
  115. $result['idref'][$name] = $id ? $id : null;
  116. return $result;
  117. }
  118. $uploads_dir = wpcf7_upload_tmp_dir();
  119. wpcf7_init_uploads(); // Confirm upload dir
  120. $filename = $file['name'];
  121. $filename = wpcf7_antiscript_file_name( $filename );
  122. $filename = wp_unique_filename( $uploads_dir, $filename );
  123. $new_file = trailingslashit( $uploads_dir ) . $filename;
  124. if ( false === @move_uploaded_file( $file['tmp_name'], $new_file ) ) {
  125. $result['valid'] = false;
  126. $result['reason'][$name] = wpcf7_get_message( 'upload_failed' );
  127. $result['idref'][$name] = $id ? $id : null;
  128. return $result;
  129. }
  130. // Make sure the uploaded file is only readable for the owner process
  131. @chmod( $new_file, 0400 );
  132. if ( $submission = WPCF7_Submission::get_instance() ) {
  133. $submission->add_uploaded_file( $name, $new_file );
  134. }
  135. return $result;
  136. }
  137. /* Messages */
  138. add_filter( 'wpcf7_messages', 'wpcf7_file_messages' );
  139. function wpcf7_file_messages( $messages ) {
  140. return array_merge( $messages, array(
  141. 'upload_failed' => array(
  142. 'description' => __( "Uploading a file fails for any reason", 'contact-form-7' ),
  143. 'default' => __( 'Failed to upload file.', 'contact-form-7' )
  144. ),
  145. 'upload_file_type_invalid' => array(
  146. 'description' => __( "Uploaded file is not allowed file type", 'contact-form-7' ),
  147. 'default' => __( 'This file type is not allowed.', 'contact-form-7' )
  148. ),
  149. 'upload_file_too_large' => array(
  150. 'description' => __( "Uploaded file is too large", 'contact-form-7' ),
  151. 'default' => __( 'This file is too large.', 'contact-form-7' )
  152. ),
  153. 'upload_failed_php_error' => array(
  154. 'description' => __( "Uploading a file fails for PHP error", 'contact-form-7' ),
  155. 'default' => __( 'Failed to upload file. Error occurred.', 'contact-form-7' )
  156. )
  157. ) );
  158. }
  159. /* Tag generator */
  160. add_action( 'admin_init', 'wpcf7_add_tag_generator_file', 50 );
  161. function wpcf7_add_tag_generator_file() {
  162. if ( ! function_exists( 'wpcf7_add_tag_generator' ) )
  163. return;
  164. wpcf7_add_tag_generator( 'file', __( 'File upload', 'contact-form-7' ),
  165. 'wpcf7-tg-pane-file', 'wpcf7_tg_pane_file' );
  166. }
  167. function wpcf7_tg_pane_file( $contact_form ) {
  168. ?>
  169. <div id="wpcf7-tg-pane-file" class="hidden">
  170. <form action="">
  171. <table>
  172. <tr><td><input type="checkbox" name="required" />&nbsp;<?php echo esc_html( __( 'Required field?', 'contact-form-7' ) ); ?></td></tr>
  173. <tr><td><?php echo esc_html( __( 'Name', 'contact-form-7' ) ); ?><br /><input type="text" name="name" class="tg-name oneline" /></td><td></td></tr>
  174. </table>
  175. <table>
  176. <tr>
  177. <td><code>id</code> (<?php echo esc_html( __( 'optional', 'contact-form-7' ) ); ?>)<br />
  178. <input type="text" name="id" class="idvalue oneline option" /></td>
  179. <td><code>class</code> (<?php echo esc_html( __( 'optional', 'contact-form-7' ) ); ?>)<br />
  180. <input type="text" name="class" class="classvalue oneline option" /></td>
  181. </tr>
  182. <tr>
  183. <td><?php echo esc_html( __( "File size limit", 'contact-form-7' ) ); ?> (<?php echo esc_html( __( 'bytes', 'contact-form-7' ) ); ?>) (<?php echo esc_html( __( 'optional', 'contact-form-7' ) ); ?>)<br />
  184. <input type="text" name="limit" class="filesize oneline option" /></td>
  185. <td><?php echo esc_html( __( "Acceptable file types", 'contact-form-7' ) ); ?> (<?php echo esc_html( __( 'optional', 'contact-form-7' ) ); ?>)<br />
  186. <input type="text" name="filetypes" class="filetype oneline option" /></td>
  187. </tr>
  188. </table>
  189. <div class="tg-tag"><?php echo esc_html( __( "Copy this code and paste it into the form left.", 'contact-form-7' ) ); ?><br /><input type="text" name="file" class="tag wp-ui-text-highlight code" readonly="readonly" onfocus="this.select()" /></div>
  190. <div class="tg-mail-tag"><?php echo esc_html( __( "And, put this code into the File Attachments field below.", 'contact-form-7' ) ); ?><br /><input type="text" class="mail-tag wp-ui-text-highlight code" readonly="readonly" onfocus="this.select()" /></div>
  191. </form>
  192. </div>
  193. <?php
  194. }
  195. /* Warning message */
  196. add_action( 'wpcf7_admin_notices', 'wpcf7_file_display_warning_message' );
  197. function wpcf7_file_display_warning_message() {
  198. if ( ! $contact_form = wpcf7_get_current_contact_form() ) {
  199. return;
  200. }
  201. $has_tags = (bool) $contact_form->form_scan_shortcode(
  202. array( 'type' => array( 'file', 'file*' ) ) );
  203. if ( ! $has_tags )
  204. return;
  205. $uploads_dir = wpcf7_upload_tmp_dir();
  206. wpcf7_init_uploads();
  207. if ( ! is_dir( $uploads_dir ) || ! wp_is_writable( $uploads_dir ) ) {
  208. $message = sprintf( __( 'This contact form contains file uploading fields, but the temporary folder for the files (%s) does not exist or is not writable. You can create the folder or change its permission manually.', 'contact-form-7' ), $uploads_dir );
  209. echo '<div class="error"><p><strong>' . esc_html( $message ) . '</strong></p></div>';
  210. }
  211. }
  212. /* File uploading functions */
  213. function wpcf7_init_uploads() {
  214. $dir = wpcf7_upload_tmp_dir();
  215. wp_mkdir_p( trailingslashit( $dir ) );
  216. @chmod( $dir, 0733 );
  217. $htaccess_file = trailingslashit( $dir ) . '.htaccess';
  218. if ( file_exists( $htaccess_file ) )
  219. return;
  220. if ( $handle = @fopen( $htaccess_file, 'w' ) ) {
  221. fwrite( $handle, "Deny from all\n" );
  222. fclose( $handle );
  223. }
  224. }
  225. function wpcf7_upload_tmp_dir() {
  226. if ( defined( 'WPCF7_UPLOADS_TMP_DIR' ) )
  227. return WPCF7_UPLOADS_TMP_DIR;
  228. else
  229. return wpcf7_upload_dir( 'dir' ) . '/wpcf7_uploads';
  230. }
  231. add_action( 'template_redirect', 'wpcf7_cleanup_upload_files', 20 );
  232. function wpcf7_cleanup_upload_files() {
  233. if ( is_admin() || 'GET' != $_SERVER['REQUEST_METHOD']
  234. || is_robots() || is_feed() || is_trackback() ) {
  235. return;
  236. }
  237. $dir = trailingslashit( wpcf7_upload_tmp_dir() );
  238. if ( ! is_dir( $dir ) || ! is_readable( $dir ) || ! wp_is_writable( $dir ) ) {
  239. return;
  240. }
  241. if ( $handle = @opendir( $dir ) ) {
  242. while ( false !== ( $file = readdir( $handle ) ) ) {
  243. if ( $file == "." || $file == ".." || $file == ".htaccess" ) {
  244. continue;
  245. }
  246. $mtime = @filemtime( $dir . $file );
  247. if ( $mtime && time() < $mtime + 60 ) { // less than 60 secs old
  248. continue;
  249. }
  250. @unlink( $dir . $file );
  251. }
  252. closedir( $handle );
  253. }
  254. }
  255. ?>