PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / trunk
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More vtrunk
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
formidable / stripe / helpers / FrmStrpLiteUrlParamHelper.php

FrmStrpLiteUrlParamHelper.php in Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More trunk, at stripe/helpers/FrmStrpLiteUrlParamHelper.php

119 lines 3.2 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 if ( ! defined( 'ABSPATH' ) ) {
3 die( 'You are not allowed to call this page directly.' );
4 }
5
6 /**
7 * Check, verify, and store URL param details.
8 * This is used for 3D Secure and Stripe Link.
9 *
10 * @since 6.5.1
11 */
12 class FrmStrpLiteUrlParamHelper {
13
14 /**
15 * Each set of details includes an entry object, a payment object, and an intent object.
16 *
17 * @var array
18 */
19 private static $details_by_form_id = array();
20
21 /**
22 * Get some associated payment objects based on the URL param data.
23 * This includes the intent, the entry, and the payments table model instance.
24 *
25 * @param int|string $form_id
26 *
27 * @return array|false
28 */
29 public static function get_details_for_form( $form_id ) {
30 if ( ! isset( self::$details_by_form_id[ $form_id ] ) ) {
31 self::set_details_for_form( (int) $form_id );
32 }
33 return self::$details_by_form_id[ $form_id ] ?? false;
34 }
35
36 /**
37 * Check the URL params for Stripe intent details.
38 * These params are used in 3D secure as well as Stripe Link.
39 *
40 * The params include:
41 * - The ID of the payment intent or setup intent.
42 * - The ID of the entry.
43 * - The client secret which is used to verify the intent.
44 * - The charge ID (if applicable)
45 *
46 * @since 6.5.1
47 *
48 * @param int|string $form_id
49 *
50 * @return void
51 */
52 private static function set_details_for_form( $form_id ) {
53 $intent_id = FrmAppHelper::simple_get( 'payment_intent' );
54 $is_setup_intent = false;
55
56 if ( ! $intent_id ) {
57 $intent_id = FrmAppHelper::simple_get( 'setup_intent' );
58 $is_setup_intent = true;
59
60 if ( ! $intent_id ) {
61 return;
62 }
63 }
64
65 $intent_function_name = $is_setup_intent ? 'get_setup_intent' : 'get_intent';
66 $intent = FrmStrpLiteAppHelper::call_stripe_helper_class( $intent_function_name, $intent_id );
67
68 if ( ! $intent || ! self::verify_client_secret( $intent, $is_setup_intent ) ) {
69 return;
70 }
71
72 $charge_id = FrmAppHelper::simple_get( 'charge' );
73 $has_charge = (bool) $charge_id;
74 $frm_payment = new FrmTransLitePayment();
75
76 if ( $has_charge ) {
77 // Stripe link payments use charge id.
78 $payment = $frm_payment->get_one_by( $charge_id, 'receipt_id' );
79 }
80
81 if ( ! isset( $payment ) || ! is_object( $payment ) ) {
82 // 3D secure payments use intent id.
83 $payment = $frm_payment->get_one_by( $intent_id, 'receipt_id' );
84 }
85
86 if ( ! is_object( $payment ) ) {
87 return;
88 }
89
90 $entry = FrmEntry::getOne( $payment->item_id, true );
91
92 if ( ! is_object( $entry ) || (int) $entry->form_id !== $form_id ) {
93 return;
94 }
95
96 self::$details_by_form_id[ $form_id ] = array(
97 'entry' => $entry,
98 'intent' => $intent,
99 'payment' => $payment,
100 );
101 }
102
103 /**
104 * Check the client secret in the URL, verify it matches the Stripe object and isn't being manipulated.
105 *
106 * @since 6.5.1
107 *
108 * @param object $intent
109 * @param bool $is_setup_intent
110 *
111 * @return bool True if the client secret is set and valid.
112 */
113 private static function verify_client_secret( $intent, $is_setup_intent ) {
114 $client_secret_param = $is_setup_intent ? 'setup_intent_client_secret' : 'payment_intent_client_secret';
115 $client_secret = FrmAppHelper::simple_get( $client_secret_param );
116 return $client_secret && $client_secret === $intent->client_secret;
117 }
118 }
119