PluginProbe
Passster – Password Protect Pages and Content / 4.3.17
Passster – Password Protect Pages and Content v4.3.17
4.3.17 4.3.16 4.3.15 4.3.14 4.3.12 4.3.13 4.3.11 4.3.10 4.3.9 4.3.8 4.3.7 4.3.6 4.3.5 trunk 3.5.4 3.5.5.2 3.5.5.8 3.5.5.9 4.0 4.1.4 4.2.10 4.2.11 4.2.12 4.2.13 4.2.14 All 49 releases
← All changes | inc/freemius/includes/managers/class-fs-checkout-manager.php +46 -3 4.2.12 → 4.3.17 View file →
@@ -11,10 +11,39 @@
11 11 }
12 12
13 13 class FS_Checkout_Manager {
14 14
15 - # region Singleton
15 + /**
16 + * Allowlist of query parameters for checkout.
17 + */
18 + private $_allowed_custom_params = array(
19 + // currency
20 + 'currency' => true,
21 + 'default_currency' => true,
22 + // cart
23 + 'always_show_renewals_amount' => true,
24 + 'annual_discount' => true,
25 + 'billing_cycle' => true,
26 + 'billing_cycle_selector' => true,
27 + 'bundle_discount' => true,
28 + 'maximize_discounts' => true,
29 + 'multisite_discount' => true,
30 + 'show_inline_currency_selector' => true,
31 + 'show_monthly' => true,
32 + // appearance
33 + 'form_position' => true,
34 + 'is_bundle_collapsed' => true,
35 + 'layout' => true,
36 + 'refund_policy_position' => true,
37 + 'show_refund_badge' => true,
38 + 'show_reviews' => true,
39 + 'show_upsells' => true,
40 + 'title' => true,
41 + );
16 42
43 +
44 + # region Singleton
45 +
17 46 /**
18 47 * @var FS_Checkout_Manager
19 48 */
20 49 private static $_instance;
@@ -80,8 +109,17 @@
80 109 } else {
81 110 // If add-on isn't activated assume the premium version isn't installed.
82 111 $is_premium = false;
83 112 }
113 +
114 + // Override the checkout context with the add-on's purchase details so the checkout flow is initialized for the selected add-on instead of the parent product.
115 + $context_params['plugin_id'] = $plugin_id;
116 +
117 + foreach ( array( 'plan_id', 'pricing_id', 'billing_cycle', 'is_trial' ) as $param ) {
118 + if ( fs_request_has( $param ) ) {
119 + $context_params[ $param ] = fs_request_get( $param );
120 + }
121 + }
84 122 }
85 123
86 124 // Get site context secure params.
87 125 if ( $fs->is_registered() ) {
@@ -152,9 +190,14 @@
152 190 ( $fs->is_plugin() && current_user_can( 'install_plugins' ) ) ||
153 191 ( $fs->is_theme() && current_user_can( 'install_themes' ) )
154 192 );
155 193
156 - return array_merge( $context_params, $_GET, array(
194 + $filtered_params = $fs->apply_filters('checkout/parameters', $context_params);
195 +
196 + // Allowlist only allowed query params.
197 + $filtered_params = array_intersect_key($filtered_params, $this->_allowed_custom_params);
198 +
199 + return array_merge( $_GET, $context_params, $filtered_params, array(
157 200 // Current plugin version.
158 201 'plugin_version' => $fs->get_plugin_version(),
159 202 'sdk_version' => WP_FS__SDK_VERSION,
160 203 'is_premium' => $is_premium ? 'true' : 'false',
@@ -238,5 +281,5 @@
238 281
239 282 private function get_checkout_redirect_nonce_action( Freemius $fs ) {
240 283 return $fs->get_unique_affix() . '_checkout_redirect';
241 284 }
242 - }
285 + }