| 1 |
<?php |
| 2 |
/** |
| 3 |
* Public AJAX endpoint for resolving Appointment selector stages. |
| 4 |
* |
| 5 |
* @package Booking Calendar |
| 6 |
*/ |
| 7 |
|
| 8 |
if ( ! defined( 'ABSPATH' ) ) { |
| 9 |
exit; |
| 10 |
} |
| 11 |
|
| 12 |
/** |
| 13 |
* Resolve a Service/Provider selection and return the next complete stage. |
| 14 |
* |
| 15 |
* The endpoint never mutates data. It verifies the public nonce, validates the |
| 16 |
* signed shortcode configuration, rebuilds the active assignment catalogue, |
| 17 |
* and renders one complete native resource-bound form when selection is final. |
| 18 |
* |
| 19 |
* @return void Terminates with a JSON response. |
| 20 |
*/ |
| 21 |
function wpbc_booking_appointment_ajax_resolve() { |
| 22 |
if ( false === check_ajax_referer( 'wpbc_booking_appointment_ajax', 'nonce', false ) ) { |
| 23 |
wp_send_json_error( array( 'message' => __( 'Security check failed. Reload the page and try again.', 'booking' ) ), 403 ); |
| 24 |
} |
| 25 |
|
| 26 |
$config_token = isset( $_POST['config_token'] ) && ! is_array( $_POST['config_token'] ) ? sanitize_text_field( wp_unslash( $_POST['config_token'] ) ) : ''; // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized |
| 27 |
$config = wpbc_booking_appointment_decode_config( $config_token ); |
| 28 |
if ( is_wp_error( $config ) ) { |
| 29 |
wp_send_json_error( array( 'message' => $config->get_error_message(), 'code' => $config->get_error_code() ), 400 ); |
| 30 |
} |
| 31 |
|
| 32 |
$is_preview_request = ! empty( $config['return_url'] ) && false !== strpos( (string) $config['return_url'], 'wpbc_bfb_preview=' ); |
| 33 |
if ( $is_preview_request ) { |
| 34 |
$preview_activated = class_exists( 'WPBC_BFB_Preview_Service' ) |
| 35 |
&& WPBC_BFB_Preview_Service::get_instance()->activate_appointment_preview_from_url( $config['return_url'] ); |
| 36 |
if ( ! $preview_activated ) { |
| 37 |
wp_send_json_error( |
| 38 |
array( |
| 39 |
'message' => __( 'This booking form preview expired. Refresh the preview and try again.', 'booking' ), |
| 40 |
'code' => 'appointment_preview_expired', |
| 41 |
), |
| 42 |
403 |
| 43 |
); |
| 44 |
} |
| 45 |
} |
| 46 |
|
| 47 |
$service_id = isset( $_POST['service_id'] ) && ! is_array( $_POST['service_id'] ) ? absint( wp_unslash( $_POST['service_id'] ) ) : 0; |
| 48 |
$provider_id = isset( $_POST['provider_id'] ) && ! is_array( $_POST['provider_id'] ) ? absint( wp_unslash( $_POST['provider_id'] ) ) : 0; |
| 49 |
$result = wpbc_booking_appointment_resolve_stage( $config, $service_id, $provider_id ); |
| 50 |
if ( is_wp_error( $result ) ) { |
| 51 |
wp_send_json_error( wpbc_booking_appointment_get_error_response_data( $result ), 400 ); |
| 52 |
} |
| 53 |
|
| 54 |
wp_send_json_success( $result ); |
| 55 |
} |
| 56 |
add_action( 'wp_ajax_nopriv_WPBC_AJX_BOOKING_APPOINTMENT_RESOLVE', 'wpbc_booking_appointment_ajax_resolve' ); |
| 57 |
add_action( 'wp_ajax_WPBC_AJX_BOOKING_APPOINTMENT_RESOLVE', 'wpbc_booking_appointment_ajax_resolve' ); |
| 58 |
|