PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / trunk
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More vtrunk
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | square/controllers/FrmSquareLiteAppController.php +131 -19 6.25 → trunk View file →
@@ -9,8 +9,9 @@
9 9 * Add the gateway for compatibility with the Payments submodule.
10 10 * This adds the Stripe checkbox option to the list of gateways.
11 11 *
12 12 * @param array $gateways
13 + *
13 14 * @return array
14 15 */
15 16 public static function add_gateway( $gateways ) {
16 17 $gateways['square'] = array(
@@ -34,13 +35,15 @@
34 35 * @return void
35 36 */
36 37 public static function handle_oauth() {
37 38 FrmAppHelper::permission_check( 'frm_change_settings' );
39 +
38 40 if ( ! check_admin_referer( 'frm_ajax', 'nonce' ) ) {
39 41 wp_send_json_error();
40 42 }
41 43
42 44 $redirect_url = FrmSquareLiteConnectHelper::get_oauth_redirect_url();
45 +
43 46 if ( false === $redirect_url ) {
44 47 wp_send_json_error( 'Unable to connect to Square successfully' );
45 48 }
46 49
@@ -51,8 +54,9 @@
51 54 }
52 55
53 56 public static function handle_disconnect() {
54 57 FrmAppHelper::permission_check( 'frm_change_settings' );
58 +
55 59 if ( ! check_admin_referer( 'frm_ajax', 'nonce' ) ) {
56 60 wp_send_json_error();
57 61 }
58 62
@@ -68,18 +72,20 @@
68 72 public static function verify_buyer() {
69 73 check_ajax_referer( 'frm_square_ajax', 'nonce' );
70 74
71 75 $form_id = FrmAppHelper::get_post_param( 'form_id', 0, 'absint' );
76 +
72 77 if ( ! $form_id ) {
73 78 wp_send_json_error( __( 'Invalid form ID', 'formidable' ) );
74 79 }
75 80
76 81 $actions = FrmSquareLiteActionsController::get_actions_before_submit( $form_id );
77 - if ( empty( $actions ) ) {
82 +
83 + if ( ! $actions ) {
78 84 wp_send_json_error( __( 'No Square actions found for this form', 'formidable' ) );
79 85 }
80 86
81 - $action = reset( $actions );
87 + $action = self::get_action_for_verification( $actions );
82 88 $verification_details = array(
83 89 'amount' => self::get_amount_value_for_verification( $action ),
84 90 'billingContact' => self::get_billing_contact( $action ),
85 91 'currencyCode' => strtoupper( $action->post_content['currency'] ),
@@ -94,33 +100,129 @@
94 100 );
95 101 }
96 102
97 103 /**
104 + * Get the action that the submission will actually trigger.
105 + *
106 + * Square verifies a single amount, so when a form has more than one Square action,
107 + * the conditional logic of each action is checked against the posted values. Without
108 + * this, the first action always wins and the buyer gets verified for an amount that
109 + * a different action is going to charge.
110 + *
111 + * @since 6.35
112 + *
113 + * @param array $actions Payment actions from FrmSquareLiteActionsController::get_actions_before_submit. Never empty.
114 + *
115 + * @return WP_Post
116 + */
117 + private static function get_action_for_verification( $actions ) {
118 + if ( count( $actions ) > 1 ) {
119 + $entry = self::generate_false_entry();
120 +
121 + foreach ( $actions as $action ) {
122 + if ( ! FrmFormAction::action_conditions_met( $action, $entry ) ) {
123 + // Conditions were met, so this is the action that will charge the buyer.
124 + return $action;
125 + }
126 + }
127 + }
128 +
129 + // Either there is a single action, or no action passed its conditional logic.
130 + return reset( $actions );
131 + }
132 +
133 + /**
98 134 * Get the amount value for verification.
99 135 *
136 + * Square's verifyBuyer expects the amount as a decimal string in the currency's
137 + * major units ("20.00" for twenty pounds), not the smallest denomination that the
138 + * Payments API uses. FrmSquareLiteActionsController::prepare_amount returns the
139 + * smallest denomination, so the parent is called here instead.
140 + *
100 141 * @param WP_Post $action
142 + *
101 143 * @return string
102 144 */
103 145 private static function get_amount_value_for_verification( $action ) {
104 146 $amount = $action->post_content['amount'];
105 - if ( strpos( $amount, '[' ) === false ) {
106 - return $amount;
147 +
148 + if ( ! str_contains( $amount, '[' ) ) {
149 + $currency = $action->post_content['currency'];
150 + return FrmTransLiteActionsController::prepare_amount( $amount, compact( 'currency' ) );
107 151 }
108 152
109 153 $form = FrmForm::getOne( $action->menu_order );
154 +
110 155 if ( ! $form ) {
111 156 return $amount;
112 157 }
113 158
114 159 // Update amount based on field shortcodes.
115 - $entry = self::generate_false_entry();
116 - $amount = FrmSquareLiteActionsController::prepare_amount( $amount, compact( 'form', 'entry', 'action' ) );
160 + $entry = self::generate_false_entry();
117 161
118 - return $amount;
162 + return FrmTransLiteActionsController::prepare_amount( $amount, compact( 'form', 'entry', 'action' ) );
119 163 }
120 164
121 165 /**
166 + * Show a warning in the payment action settings when the selected address field
167 + * uses an address type without a country, as Square requires a country code.
168 + *
169 + * @since 6.34
170 + *
171 + * @param object $action
172 + *
173 + * @return void
174 + */
175 + public static function maybe_show_address_type_warning( $action ) {
176 + if ( is_callable( 'FrmProSquareLiteController::maybe_show_address_type_warning' ) ) {
177 + // Pro renders this warning with the same hook.
178 + return;
179 + }
180 +
181 + if ( empty( $action->post_content['gateway'] ) ) {
182 + return;
183 + }
184 +
185 + $gateways = (array) $action->post_content['gateway'];
186 +
187 + if ( ! in_array( 'square', $gateways, true ) ) {
188 + return;
189 + }
190 +
191 + if ( empty( $action->post_content['billing_address'] ) ) {
192 + return;
193 + }
194 +
195 + $address_field = FrmField::getOne( $action->post_content['billing_address'] );
196 +
197 + if ( ! $address_field || self::address_field_is_compatible_with_square( $address_field ) ) {
198 + return;
199 + }
200 + ?>
201 + <div class="frm_warning_style">
202 + <?php
203 + esc_html_e( 'The address field selected is not compatible with Square, because it does not include the country code. Select another address type to prevent checkout errors.', 'formidable' ); // phpcs:ignore SlevomatCodingStandard.Files.LineLength.LineTooLong
204 + ?>
205 + </div>
206 + <?php
207 + }
208 +
209 + /**
210 + * Square requires a country code, which the generic address type does not collect.
211 + *
212 + * @since 6.34
213 + *
214 + * @param stdClass $field
215 + *
216 + * @return bool
217 + */
218 + private static function address_field_is_compatible_with_square( $field ) {
219 + return ! isset( $field->field_options['address_type'] ) || 'generic' !== $field->field_options['address_type'];
220 + }
221 +
222 + /**
122 223 * @param WP_Post $action
224 + *
123 225 * @return array
124 226 */
125 227 public static function get_billing_contact( $action ) {
126 228 $email_setting = $action->post_content['email'];
@@ -125,10 +227,12 @@
125 227 public static function get_billing_contact( $action ) {
126 228 $email_setting = $action->post_content['email'];
127 229 $first_name_setting = $action->post_content['billing_first_name'];
128 230 $last_name_setting = $action->post_content['billing_last_name'];
129 - $address_setting = $action->post_content['billing_address'];
130 231
232 + // @phpstan-ignore-next-line
233 + $address_setting = $action->post_content['billing_address'] ?? '';
234 +
131 235 $entry = self::generate_false_entry();
132 236 $first_name = $first_name_setting && isset( $entry->metas[ $first_name_setting ] ) ? $entry->metas[ $first_name_setting ] : '';
133 237 $last_name = $last_name_setting && isset( $entry->metas[ $last_name_setting ] ) ? $entry->metas[ $last_name_setting ] : '';
134 238 $address = $address_setting && isset( $entry->metas[ $address_setting ] ) ? $entry->metas[ $address_setting ] : '';
@@ -165,16 +269,18 @@
165 269 *
166 270 * @param array $details
167 271 * @param array $address
168 272 * @param int $address_field_id
273 + *
169 274 * @return void
170 275 */
171 276 private static function maybe_add_address_data( &$details, $address, $address_field_id ) {
172 - if ( ! is_array( $address ) || ! isset( $address['line1'] ) || ! isset( $address['line2'] ) || ! is_callable( 'FrmProAddressesController::get_country_code' ) ) {
277 + if ( ! is_array( $address ) || ! isset( $address['line1'] ) || ! isset( $address['line2'] ) ) {
173 278 return;
174 279 }
175 280
176 281 $address_field = FrmField::getOne( $address_field_id );
282 +
177 283 if ( ! $address_field ) {
178 284 return;
179 285 }
180 286
@@ -180,9 +286,9 @@
180 286
181 287 if ( 'us' === $address_field->field_options['address_type'] ) {
182 288 $country_code = 'US';
183 289 } else {
184 - $country_code = FrmProAddressesController::get_country_code( $address['country'] );
290 + $country_code = FrmAddressesController::get_country_code( $address['country'] );
185 291 }
186 292
187 293 if ( ! $address['line1'] && ! $address['line2'] && ! $address['city'] && ! $address['state'] && ! $address['zip'] && ! $country_code ) {
188 294 return;
@@ -198,8 +304,9 @@
198 304 /**
199 305 * Create an entry object with posted values.
200 306 *
201 307 * @since 6.22
308 + *
202 309 * @return stdClass
203 310 */
204 311 private static function generate_false_entry() {
205 312 $entry = new stdClass();
@@ -205,9 +312,11 @@
205 312 $entry = new stdClass();
206 313 $entry->post_id = 0;
207 314 $entry->id = 0;
208 315 $entry->item_key = '';
209 - $entry->metas = array();
316 + // Shortcode replacement reads ip off of the entry, so it cannot be left unset.
317 + $entry->ip = '';
318 + $entry->metas = array();
210 319
211 320 // phpcs:ignore WordPress.Security.NonceVerification.Missing
212 321 foreach ( $_POST as $k => $v ) {
213 322 $k = sanitize_text_field( stripslashes( $k ) );
@@ -212,18 +321,21 @@
212 321 foreach ( $_POST as $k => $v ) {
213 322 $k = sanitize_text_field( stripslashes( $k ) );
214 323 $v = wp_unslash( $v );
215 324
216 - if ( $k === 'item_meta' ) {
217 - if ( is_array( $v ) ) {
218 - foreach ( $v as $f => $value ) {
219 - FrmAppHelper::sanitize_value( 'wp_kses_post', $value );
220 - $entry->metas[ absint( $f ) ] = $value;
221 - }
222 - }
223 - } else {
325 + if ( $k !== 'item_meta' ) {
224 326 FrmAppHelper::sanitize_value( 'wp_kses_post', $v );
225 327 $entry->{$k} = $v;
328 + continue;
329 + }
330 +
331 + if ( ! is_array( $v ) ) {
332 + continue;
333 + }
334 +
335 + foreach ( $v as $f => $value ) {
336 + FrmAppHelper::sanitize_value( 'wp_kses_post', $value );
337 + $entry->metas[ absint( $f ) ] = $value;
226 338 }
227 339 }
228 340
229 341 return $entry;