| @@ -80,8 +80,16 @@ | ||
| 80 | 80 | 'variation' => $variation, |
| 81 | 81 | 'product' => !$isCustom ? $variation->product : [] |
| 82 | 82 | ]); |
| 83 | 83 | |
| 84 | + // After the filter, not before: this path takes its quantity straight from a | |
| 85 | + // public URL param, and the filter above can replace it with anything. | |
| 86 | + $error = CartHelper::validateQuantity($quantity); | |
| 87 | + if ($error) { | |
| 88 | + return $error; | |
| 89 | + } | |
| 90 | + $quantity = (int)$quantity; | |
| 91 | + | |
| 84 | 92 | if ($variation->payment_type === 'subscription') { |
| 85 | 93 | $quantity = 1; |
| 86 | 94 | } |
| 87 | 95 | |
| @@ -215,11 +223,13 @@ | ||
| 215 | 223 | { |
| 216 | 224 | $itemId = Arr::get($data, 'id'); |
| 217 | 225 | $quantity = Arr::get($data, 'quantity', 1); |
| 218 | 226 | |
| 219 | - if ($quantity <= 0) { | |
| 227 | + // This path writes cart_data directly instead of going through Cart::addItem(). | |
| 228 | + $error = CartHelper::validateQuantity($quantity); | |
| 229 | + if ($error) { | |
| 220 | 230 | return static::makeErrorResponse([ |
| 221 | - ['code' => 403, 'message' => __('Quantity can not be negative.', 'fluent-cart')] | |
| 231 | + ['code' => 403, 'message' => $error->get_error_message()] | |
| 222 | 232 | ]); |
| 223 | 233 | } |
| 224 | 234 | |
| 225 | 235 | $cart = CartResource::get([ |
| @@ -581,8 +591,15 @@ | ||
| 581 | 591 | if ($updatedQuantity < 0) { |
| 582 | 592 | $updatedQuantity = 0; |
| 583 | 593 | } |
| 584 | 594 | |
| 595 | + if ($updatedQuantity > 0 && ($error = CartHelper::validateQuantity($updatedQuantity))) { | |
| 596 | + return [ | |
| 597 | + 'code' => 'failed', | |
| 598 | + 'message' => $error->get_error_message() | |
| 599 | + ]; | |
| 600 | + } | |
| 601 | + | |
| 585 | 602 | if (!$isFilteredItem) { |
| 586 | 603 | |
| 587 | 604 | if (!CartHelper::shouldAddItemToCart($productVariation, $updatedQuantity)) { |
| 588 | 605 | return [ |
| @@ -611,8 +628,16 @@ | ||
| 611 | 628 | |
| 612 | 629 | if ($quantity < 1) { |
| 613 | 630 | $quantity = 1; |
| 614 | 631 | } |
| 632 | + | |
| 633 | + if ($error = CartHelper::validateQuantity($quantity)) { | |
| 634 | + return [ | |
| 635 | + 'code' => 'failed', | |
| 636 | + 'message' => $error->get_error_message() | |
| 637 | + ]; | |
| 638 | + } | |
| 639 | + | |
| 615 | 640 | if (!$isFilteredItem) { |
| 616 | 641 | if (!CartHelper::shouldAddItemToCart($productVariation, $quantity)) { |
| 617 | 642 | return [ |
| 618 | 643 | 'code' => 'failed', |