Gravity Flow One-Click Submit Merge Tags
Adds {workflow_submit_url} and {workflow_submit_link} merge tags so Gravity Flow User Input steps can be completed by an assignee with a single click from an email or notification.
by Abundant Designs · github.com/robertstaddon/gravity-flow-one-click-submit-merge-tags · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/robertstaddon/gravity-flow-one-click-submit-merge-tags/archive/refs/heads/main.zipAdds
{workflow_submit_url}and{workflow_submit_link}merge tags to Gravity Flow so an assignee can complete a User Input step with a single click from an email or notification — no login form, no inbox UI.
- Version: 1.0.0
- Requires WordPress: 5.0+
- Requires PHP: 7.4+
- Requires: Gravity Forms and Gravity Flow
- Author: Abundant Designs
- License: GPL-2.0-or-later
What it does
Gravity Flow's built-in workflow notifications usually send the assignee a link to a page where they can review the entry and click "Submit." This plugin shortcuts that flow with a signed, single-use-style URL that, when clicked, immediately marks that user's portion of the current User Input step as complete and lets Gravity Flow advance the workflow.
Use it when:
- You want a frictionless "Approve" / "Acknowledge" action straight from an email.
- The current step is a Gravity Flow User Input step.
- You're comfortable trusting the URL itself as the authorization (it's HMAC-signed against your WordPress salts).
Installation
- Download or clone this repository into
wp-content/plugins/gravity-flow-one-click-submit-merge-tags. - Activate Gravity Flow One-Click Submit Merge Tags from the WordPress Plugins screen.
- Make sure Gravity Forms and Gravity Flow are active.
cd wp-content/plugins
git clone https://github.com/abundantdesigns/gravity-flow-one-click-submit-merge-tags.git
Usage
Inside any Gravity Flow notification, assignee email, or step assignee email, drop in one of the new merge tags:
| Merge tag | Output |
|---|---|
{workflow_submit_url} |
The bare submission URL (URL-encoded when used in a context that requires it). |
{workflow_submit_link} |
A ready-to-click <a href="...">Submit Entry</a> HTML link. |
Tag options
Both tags accept optional shortcode-style attributes:
| Option | Default | Notes |
|---|---|---|
page_id |
0 (site home) |
Page the user is redirected to after clicking the link. The link itself works no matter what page renders, as long as template_redirect fires. |
text |
Submit Entry |
Only applies to {workflow_submit_link} — the visible link text. |
Examples
Click here to approve: {workflow_submit_url}
Or use a styled button: {workflow_submit_link:text="Approve this request"}
Land users on a "Thanks" page after submitting:
{workflow_submit_link:page_id=128 text="Approve & Continue"}
What happens when the link is clicked
- The plugin verifies the HMAC token in the URL against
wp_salt( 'auth' ). - It loads the entry and confirms it is still on the same User Input step.
- It confirms the URL recipient is an assignee on that step and hasn't already submitted.
- It marks that user's status as
completeand adds a step note:Step Name: Display Name — submitted via one-click link. - It hands off to Gravity Flow (
gravity_flow()->process_workflow()) to evaluate the step and advance the workflow. - The user is redirected to the configured page (or the site home) with
?gflow_submitted=1, which renders a green success banner in the footer.
Customization
Filter the post-submit redirect
add_filter( 'gflow_submit_redirect_url', function ( $redirect_url, $entry, $step, $page_id ) {
return home_url( '/thank-you/' );
}, 10, 4 );
Customize the success banner
The banner is rendered in wp_footer only when ?gflow_submitted=1 is present. Hide it with CSS, dequeue it with remove_action, or replace it with your own:
remove_action( 'wp_footer', [ \AbundantDesigns\GravityFlowOneClickSubmit\Plugin::class, 'render_success_banner' ] );
Security model
- Every URL contains an HMAC-SHA256 token bound to the entry ID, step ID, and assignee user ID, signed with
wp_salt( 'auth' ). - Rotating your WordPress auth salts invalidates every previously generated link.
- The link is rejected if the entry has moved past the step, or the step is no longer a User Input step.
- Tokens are compared with
hash_equals()to avoid timing attacks.
Heads up: Anyone in possession of the URL can submit on the assignee's behalf. Treat these links like password-reset links — fine for the assignee's own inbox, not for public posting.
Hooks reference
| Hook | Type | Purpose |
|---|---|---|
gform_custom_merge_tags |
filter | Registers the two merge tags in the Gravity Forms dropdown. |
gform_replace_merge_tags |
filter | Replaces the merge tags in notification text. |
template_redirect |
action | Handles the one-click submission request. |
wp_footer |
action | Renders the success banner. |
gflow_submit_redirect_url |
filter (provided) | Override the post-submit redirect URL. |
Changelog
1.0.0
- Initial release.
{workflow_submit_url}and{workflow_submit_link}merge tags.- HMAC-signed
template_redirecthandler that advances the User Input step. - Front-end success banner via
wp_footer.
Credits
Built and maintained by Abundant Designs.
License
GPL-2.0-or-later. See the headers in the main plugin file or the GPL text.