← All changes
|
inc/freemius/includes/managers/class-fs-checkout-manager.php
+46
-3
4.2.12
→
4.3.17
View file →
| @@ -11,10 +11,39 @@ | ||
| 11 | 11 | } |
| 12 | 12 | |
| 13 | 13 | class FS_Checkout_Manager { |
| 14 | 14 | |
| 15 | - # region Singleton | |
| 15 | + /** | |
| 16 | + * Allowlist of query parameters for checkout. | |
| 17 | + */ | |
| 18 | + private $_allowed_custom_params = array( | |
| 19 | + // currency | |
| 20 | + 'currency' => true, | |
| 21 | + 'default_currency' => true, | |
| 22 | + // cart | |
| 23 | + 'always_show_renewals_amount' => true, | |
| 24 | + 'annual_discount' => true, | |
| 25 | + 'billing_cycle' => true, | |
| 26 | + 'billing_cycle_selector' => true, | |
| 27 | + 'bundle_discount' => true, | |
| 28 | + 'maximize_discounts' => true, | |
| 29 | + 'multisite_discount' => true, | |
| 30 | + 'show_inline_currency_selector' => true, | |
| 31 | + 'show_monthly' => true, | |
| 32 | + // appearance | |
| 33 | + 'form_position' => true, | |
| 34 | + 'is_bundle_collapsed' => true, | |
| 35 | + 'layout' => true, | |
| 36 | + 'refund_policy_position' => true, | |
| 37 | + 'show_refund_badge' => true, | |
| 38 | + 'show_reviews' => true, | |
| 39 | + 'show_upsells' => true, | |
| 40 | + 'title' => true, | |
| 41 | + ); | |
| 16 | 42 | |
| 43 | + | |
| 44 | + # region Singleton | |
| 45 | + | |
| 17 | 46 | /** |
| 18 | 47 | * @var FS_Checkout_Manager |
| 19 | 48 | */ |
| 20 | 49 | private static $_instance; |
| @@ -80,8 +109,17 @@ | ||
| 80 | 109 | } else { |
| 81 | 110 | // If add-on isn't activated assume the premium version isn't installed. |
| 82 | 111 | $is_premium = false; |
| 83 | 112 | } |
| 113 | + | |
| 114 | + // Override the checkout context with the add-on's purchase details so the checkout flow is initialized for the selected add-on instead of the parent product. | |
| 115 | + $context_params['plugin_id'] = $plugin_id; | |
| 116 | + | |
| 117 | + foreach ( array( 'plan_id', 'pricing_id', 'billing_cycle', 'is_trial' ) as $param ) { | |
| 118 | + if ( fs_request_has( $param ) ) { | |
| 119 | + $context_params[ $param ] = fs_request_get( $param ); | |
| 120 | + } | |
| 121 | + } | |
| 84 | 122 | } |
| 85 | 123 | |
| 86 | 124 | // Get site context secure params. |
| 87 | 125 | if ( $fs->is_registered() ) { |
| @@ -152,9 +190,14 @@ | ||
| 152 | 190 | ( $fs->is_plugin() && current_user_can( 'install_plugins' ) ) || |
| 153 | 191 | ( $fs->is_theme() && current_user_can( 'install_themes' ) ) |
| 154 | 192 | ); |
| 155 | 193 | |
| 156 | - return array_merge( $context_params, $_GET, array( | |
| 194 | + $filtered_params = $fs->apply_filters('checkout/parameters', $context_params); | |
| 195 | + | |
| 196 | + // Allowlist only allowed query params. | |
| 197 | + $filtered_params = array_intersect_key($filtered_params, $this->_allowed_custom_params); | |
| 198 | + | |
| 199 | + return array_merge( $_GET, $context_params, $filtered_params, array( | |
| 157 | 200 | // Current plugin version. |
| 158 | 201 | 'plugin_version' => $fs->get_plugin_version(), |
| 159 | 202 | 'sdk_version' => WP_FS__SDK_VERSION, |
| 160 | 203 | 'is_premium' => $is_premium ? 'true' : 'false', |
| @@ -238,5 +281,5 @@ | ||
| 238 | 281 | |
| 239 | 282 | private function get_checkout_redirect_nonce_action( Freemius $fs ) { |
| 240 | 283 | return $fs->get_unique_affix() . '_checkout_redirect'; |
| 241 | 284 | } |
| 242 | - } | |
| 285 | + } | |