Design System is here - Read the release post

Learn GeneratePress

Developers

Forms: processing and validation (Pro)

Hooks for what happens when a Form block is submitted: checking where the request came from, verifying and validating the data, and acting once it succeeds. For emails, webhooks and email marketing services, see Forms: email, webhooks and integrations. For stored submissions, see Forms: rendering and stored submissions.

Jump to

The submission flow

A submission passes through these hooks in order: the origin check, generateblocks_form_verify_submission (all raw fields), field sanitizing (generateblocks_form_type_sanitizers), generateblocks_form_validate_submission (sanitized fields), the form’s actions, and finally generateblocks_form_after_process.

generateblocks_form_allow_missing_origin

GB Pro

The generateblocks_form_allow_missing_origin filter chooses whether to accept a submission that has neither an Origin nor a Referer header. Submissions with either header must come from the same site.

Parameters: $allow (bool). Default: false. Submissions without either header are rejected.

add_filter( 'generateblocks_form_allow_missing_origin', '__return_true' );

Related: generateblocks_form_verify_submission Guide: Forms

generateblocks_form_verify_submission

GB Pro — since GenerateBlocks 2.6.

The generateblocks_form_verify_submission filter verifies a submission before it is processed. It receives every submitted field, including fields added by other plugins such as Cloudflare Turnstile or hCaptcha. Those extra fields are removed during sanitizing, so this is the place to check them. Return a WP_Error to reject the submission. The visitor sees a generic message.

Parameters: $pre_result (null or WP_Error), $form_id (int), $raw_fields (array, all submitted fields), $context (array with post_id and page_url). Default: null, which accepts the submission.

add_filter( 'generateblocks_form_verify_submission', function( $pre_result, $form_id, $raw_fields, $context ) {
    if ( empty( $raw_fields['my-captcha-token'] ) ) {
        return new WP_Error( 'missing_token', 'Captcha token missing.' );
    }

    return $pre_result;
}, 10, 4 );

Related: generateblocks_form_validate_submission, generateblocks_form_turnstile_fail_open Guide: Forms

generateblocks_form_type_sanitizers

GB Pro — since GenerateBlocks 2.6.

The generateblocks_form_type_sanitizers filter changes the sanitizer used for each field type. Use it to add a sanitizer for a custom field type.

Parameters: $type_sanitizers (array of field type => callable). Default: text, hidden, select, checkbox, radio and checkbox-group use sanitize_text_field. textarea uses sanitize_textarea_field, email uses sanitize_email, url uses esc_url_raw, and tel and number use GenerateBlocks’ own sanitizers. A field type with no sanitizer falls back to sanitize_text_field. Every value is first stripped of null bytes and cut to 10,000 characters.

add_filter( 'generateblocks_form_type_sanitizers', function( $type_sanitizers ) {
    $type_sanitizers['postcode'] = function( $value ) {
        return strtoupper( sanitize_text_field( $value ) );
    };

    return $type_sanitizers;
} );

Related: generateblocks_form_validate_submission Guide: Forms

generateblocks_form_validate_submission

GB Pro — since GenerateBlocks 2.6.

The generateblocks_form_validate_submission filter validates the sanitized data before any action runs. Return a WP_Error to stop the submission. To show the visitor your own message, add public_message to the error data.

Parameters: $sanitized (array, the sanitized fields; each field’s value is in its value key), $form_id (int), $form_settings (array, the form settings), $context (array with post_id and page_url). Default: $sanitized unchanged.

add_filter( 'generateblocks_form_validate_submission', function( $sanitized, $form_id, $form_settings, $context ) {
    $email = $sanitized['email']['value'] ?? '';

    if ( $email && str_ends_with( $email, '@example.com' ) ) {
        return new WP_Error(
            'blocked_domain',
            'Blocked email domain.',
            [ 'public_message' => __( 'Please use a different email address.', 'my-plugin' ) ]
        );
    }

    return $sanitized;
}, 10, 4 );

Related: generateblocks_form_verify_submission, generateblocks_form_type_sanitizers Guide: Forms

generateblocks_form_after_process

GB Pro — since GenerateBlocks 2.6.

The generateblocks_form_after_process action fires after a submission has been processed successfully, after all of the form’s actions have run.

Parameters: $form_id (int, the form post ID), $context (array with post_id and page_url). Default: none. It is an action.

add_action( 'generateblocks_form_after_process', function( $form_id, $context ) {
    error_log( 'Form ' . $form_id . ' submitted on ' . ( $context['page_url'] ?? '' ) );
}, 10, 2 );

Related: generateblocks_form_webhook_payload Guide: Forms

Back to top

Spam protection and permissions

generateblocks_form_turnstile_fail_open

GB Pro — since GenerateBlocks 2.6.

The generateblocks_form_turnstile_fail_open filter chooses what happens when Cloudflare Turnstile can’t be reached. By default the form fails closed, so submissions are rejected and the form keeps its CAPTCHA protection. Return true to accept submissions during a Cloudflare outage.

Parameters: $fail_open (bool), $form_id (int). Default: false.

add_filter( 'generateblocks_form_turnstile_fail_open', '__return_true' );

Related: generateblocks_form_verify_submission Guide: Forms

generateblocks_form_capability

GB Pro — since GenerateBlocks 2.6.

The generateblocks_form_capability filter sets the capability needed to use or manage forms. A user who can manage forms can always use them.

Parameters: $capability (string), $context (string: use to add a form to content, or manage to create and edit forms). Default: edit_others_posts for use, manage_options for manage.

add_filter( 'generateblocks_form_capability', function( $capability, $context ) {
    if ( 'use' === $context ) {
        return 'edit_posts';
    }

    return $capability;
}, 10, 2 );

Related: generateblocks_conditions_capability Guide: Forms

Back to top