WP Manifestindependent plugin directory
manifest / forms / gravity-flow-one-click-submit-merge-tags

Gravity Flow One-Click Submit Merge Tags

Adds {workflow_submit_url} and {workflow_submit_link} merge tags so Gravity Flow User Input steps can be completed by an assignee with a single click from an email or notification.

by Abundant Designs · github.com/robertstaddon/gravity-flow-one-click-submit-merge-tags · website

★ 0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/robertstaddon/gravity-flow-one-click-submit-merge-tags/archive/refs/heads/main.zip

Adds {workflow_submit_url} and {workflow_submit_link} merge tags to Gravity Flow so an assignee can complete a User Input step with a single click from an email or notification — no login form, no inbox UI.


What it does

Gravity Flow's built-in workflow notifications usually send the assignee a link to a page where they can review the entry and click "Submit." This plugin shortcuts that flow with a signed, single-use-style URL that, when clicked, immediately marks that user's portion of the current User Input step as complete and lets Gravity Flow advance the workflow.

Use it when:

  • You want a frictionless "Approve" / "Acknowledge" action straight from an email.
  • The current step is a Gravity Flow User Input step.
  • You're comfortable trusting the URL itself as the authorization (it's HMAC-signed against your WordPress salts).

Installation

  1. Download or clone this repository into wp-content/plugins/gravity-flow-one-click-submit-merge-tags.
  2. Activate Gravity Flow One-Click Submit Merge Tags from the WordPress Plugins screen.
  3. Make sure Gravity Forms and Gravity Flow are active.
cd wp-content/plugins
git clone https://github.com/abundantdesigns/gravity-flow-one-click-submit-merge-tags.git

Usage

Inside any Gravity Flow notification, assignee email, or step assignee email, drop in one of the new merge tags:

Merge tag Output
{workflow_submit_url} The bare submission URL (URL-encoded when used in a context that requires it).
{workflow_submit_link} A ready-to-click <a href="...">Submit Entry</a> HTML link.

Tag options

Both tags accept optional shortcode-style attributes:

Option Default Notes
page_id 0 (site home) Page the user is redirected to after clicking the link. The link itself works no matter what page renders, as long as template_redirect fires.
text Submit Entry Only applies to {workflow_submit_link} — the visible link text.

Examples

Click here to approve: {workflow_submit_url}

Or use a styled button: {workflow_submit_link:text="Approve this request"}

Land users on a "Thanks" page after submitting:
{workflow_submit_link:page_id=128 text="Approve & Continue"}

What happens when the link is clicked

  1. The plugin verifies the HMAC token in the URL against wp_salt( 'auth' ).
  2. It loads the entry and confirms it is still on the same User Input step.
  3. It confirms the URL recipient is an assignee on that step and hasn't already submitted.
  4. It marks that user's status as complete and adds a step note: Step Name: Display Name — submitted via one-click link.
  5. It hands off to Gravity Flow (gravity_flow()->process_workflow()) to evaluate the step and advance the workflow.
  6. The user is redirected to the configured page (or the site home) with ?gflow_submitted=1, which renders a green success banner in the footer.

Customization

Filter the post-submit redirect

add_filter( 'gflow_submit_redirect_url', function ( $redirect_url, $entry, $step, $page_id ) {
    return home_url( '/thank-you/' );
}, 10, 4 );

Customize the success banner

The banner is rendered in wp_footer only when ?gflow_submitted=1 is present. Hide it with CSS, dequeue it with remove_action, or replace it with your own:

remove_action( 'wp_footer', [ \AbundantDesigns\GravityFlowOneClickSubmit\Plugin::class, 'render_success_banner' ] );

Security model

  • Every URL contains an HMAC-SHA256 token bound to the entry ID, step ID, and assignee user ID, signed with wp_salt( 'auth' ).
  • Rotating your WordPress auth salts invalidates every previously generated link.
  • The link is rejected if the entry has moved past the step, or the step is no longer a User Input step.
  • Tokens are compared with hash_equals() to avoid timing attacks.

Heads up: Anyone in possession of the URL can submit on the assignee's behalf. Treat these links like password-reset links — fine for the assignee's own inbox, not for public posting.

Hooks reference

Hook Type Purpose
gform_custom_merge_tags filter Registers the two merge tags in the Gravity Forms dropdown.
gform_replace_merge_tags filter Replaces the merge tags in notification text.
template_redirect action Handles the one-click submission request.
wp_footer action Renders the success banner.
gflow_submit_redirect_url filter (provided) Override the post-submit redirect URL.

Changelog

1.0.0

  • Initial release.
  • {workflow_submit_url} and {workflow_submit_link} merge tags.
  • HMAC-signed template_redirect handler that advances the User Input step.
  • Front-end success banner via wp_footer.

Credits

Built and maintained by Abundant Designs.

License

GPL-2.0-or-later. See the headers in the main plugin file or the GPL text.