| @@ -9,8 +9,9 @@ | ||
| 9 | 9 | * Add the gateway for compatibility with the Payments submodule. |
| 10 | 10 | * This adds the Stripe checkbox option to the list of gateways. |
| 11 | 11 | * |
| 12 | 12 | * @param array $gateways |
| 13 | + * | |
| 13 | 14 | * @return array |
| 14 | 15 | */ |
| 15 | 16 | public static function add_gateway( $gateways ) { |
| 16 | 17 | $gateways['square'] = array( |
| @@ -34,13 +35,15 @@ | ||
| 34 | 35 | * @return void |
| 35 | 36 | */ |
| 36 | 37 | public static function handle_oauth() { |
| 37 | 38 | FrmAppHelper::permission_check( 'frm_change_settings' ); |
| 39 | + | |
| 38 | 40 | if ( ! check_admin_referer( 'frm_ajax', 'nonce' ) ) { |
| 39 | 41 | wp_send_json_error(); |
| 40 | 42 | } |
| 41 | 43 | |
| 42 | 44 | $redirect_url = FrmSquareLiteConnectHelper::get_oauth_redirect_url(); |
| 45 | + | |
| 43 | 46 | if ( false === $redirect_url ) { |
| 44 | 47 | wp_send_json_error( 'Unable to connect to Square successfully' ); |
| 45 | 48 | } |
| 46 | 49 | |
| @@ -51,8 +54,9 @@ | ||
| 51 | 54 | } |
| 52 | 55 | |
| 53 | 56 | public static function handle_disconnect() { |
| 54 | 57 | FrmAppHelper::permission_check( 'frm_change_settings' ); |
| 58 | + | |
| 55 | 59 | if ( ! check_admin_referer( 'frm_ajax', 'nonce' ) ) { |
| 56 | 60 | wp_send_json_error(); |
| 57 | 61 | } |
| 58 | 62 | |
| @@ -68,18 +72,20 @@ | ||
| 68 | 72 | public static function verify_buyer() { |
| 69 | 73 | check_ajax_referer( 'frm_square_ajax', 'nonce' ); |
| 70 | 74 | |
| 71 | 75 | $form_id = FrmAppHelper::get_post_param( 'form_id', 0, 'absint' ); |
| 76 | + | |
| 72 | 77 | if ( ! $form_id ) { |
| 73 | 78 | wp_send_json_error( __( 'Invalid form ID', 'formidable' ) ); |
| 74 | 79 | } |
| 75 | 80 | |
| 76 | 81 | $actions = FrmSquareLiteActionsController::get_actions_before_submit( $form_id ); |
| 77 | - if ( empty( $actions ) ) { | |
| 82 | + | |
| 83 | + if ( ! $actions ) { | |
| 78 | 84 | wp_send_json_error( __( 'No Square actions found for this form', 'formidable' ) ); |
| 79 | 85 | } |
| 80 | 86 | |
| 81 | - $action = reset( $actions ); | |
| 87 | + $action = self::get_action_for_verification( $actions ); | |
| 82 | 88 | $verification_details = array( |
| 83 | 89 | 'amount' => self::get_amount_value_for_verification( $action ), |
| 84 | 90 | 'billingContact' => self::get_billing_contact( $action ), |
| 85 | 91 | 'currencyCode' => strtoupper( $action->post_content['currency'] ), |
| @@ -94,33 +100,129 @@ | ||
| 94 | 100 | ); |
| 95 | 101 | } |
| 96 | 102 | |
| 97 | 103 | /** |
| 104 | + * Get the action that the submission will actually trigger. | |
| 105 | + * | |
| 106 | + * Square verifies a single amount, so when a form has more than one Square action, | |
| 107 | + * the conditional logic of each action is checked against the posted values. Without | |
| 108 | + * this, the first action always wins and the buyer gets verified for an amount that | |
| 109 | + * a different action is going to charge. | |
| 110 | + * | |
| 111 | + * @since 6.35 | |
| 112 | + * | |
| 113 | + * @param array $actions Payment actions from FrmSquareLiteActionsController::get_actions_before_submit. Never empty. | |
| 114 | + * | |
| 115 | + * @return WP_Post | |
| 116 | + */ | |
| 117 | + private static function get_action_for_verification( $actions ) { | |
| 118 | + if ( count( $actions ) > 1 ) { | |
| 119 | + $entry = self::generate_false_entry(); | |
| 120 | + | |
| 121 | + foreach ( $actions as $action ) { | |
| 122 | + if ( ! FrmFormAction::action_conditions_met( $action, $entry ) ) { | |
| 123 | + // Conditions were met, so this is the action that will charge the buyer. | |
| 124 | + return $action; | |
| 125 | + } | |
| 126 | + } | |
| 127 | + } | |
| 128 | + | |
| 129 | + // Either there is a single action, or no action passed its conditional logic. | |
| 130 | + return reset( $actions ); | |
| 131 | + } | |
| 132 | + | |
| 133 | + /** | |
| 98 | 134 | * Get the amount value for verification. |
| 99 | 135 | * |
| 136 | + * Square's verifyBuyer expects the amount as a decimal string in the currency's | |
| 137 | + * major units ("20.00" for twenty pounds), not the smallest denomination that the | |
| 138 | + * Payments API uses. FrmSquareLiteActionsController::prepare_amount returns the | |
| 139 | + * smallest denomination, so the parent is called here instead. | |
| 140 | + * | |
| 100 | 141 | * @param WP_Post $action |
| 142 | + * | |
| 101 | 143 | * @return string |
| 102 | 144 | */ |
| 103 | 145 | private static function get_amount_value_for_verification( $action ) { |
| 104 | 146 | $amount = $action->post_content['amount']; |
| 105 | - if ( strpos( $amount, '[' ) === false ) { | |
| 106 | - return $amount; | |
| 147 | + | |
| 148 | + if ( ! str_contains( $amount, '[' ) ) { | |
| 149 | + $currency = $action->post_content['currency']; | |
| 150 | + return FrmTransLiteActionsController::prepare_amount( $amount, compact( 'currency' ) ); | |
| 107 | 151 | } |
| 108 | 152 | |
| 109 | 153 | $form = FrmForm::getOne( $action->menu_order ); |
| 154 | + | |
| 110 | 155 | if ( ! $form ) { |
| 111 | 156 | return $amount; |
| 112 | 157 | } |
| 113 | 158 | |
| 114 | 159 | // Update amount based on field shortcodes. |
| 115 | - $entry = self::generate_false_entry(); | |
| 116 | - $amount = FrmSquareLiteActionsController::prepare_amount( $amount, compact( 'form', 'entry', 'action' ) ); | |
| 160 | + $entry = self::generate_false_entry(); | |
| 117 | 161 | |
| 118 | - return $amount; | |
| 162 | + return FrmTransLiteActionsController::prepare_amount( $amount, compact( 'form', 'entry', 'action' ) ); | |
| 119 | 163 | } |
| 120 | 164 | |
| 121 | 165 | /** |
| 166 | + * Show a warning in the payment action settings when the selected address field | |
| 167 | + * uses an address type without a country, as Square requires a country code. | |
| 168 | + * | |
| 169 | + * @since 6.34 | |
| 170 | + * | |
| 171 | + * @param object $action | |
| 172 | + * | |
| 173 | + * @return void | |
| 174 | + */ | |
| 175 | + public static function maybe_show_address_type_warning( $action ) { | |
| 176 | + if ( is_callable( 'FrmProSquareLiteController::maybe_show_address_type_warning' ) ) { | |
| 177 | + // Pro renders this warning with the same hook. | |
| 178 | + return; | |
| 179 | + } | |
| 180 | + | |
| 181 | + if ( empty( $action->post_content['gateway'] ) ) { | |
| 182 | + return; | |
| 183 | + } | |
| 184 | + | |
| 185 | + $gateways = (array) $action->post_content['gateway']; | |
| 186 | + | |
| 187 | + if ( ! in_array( 'square', $gateways, true ) ) { | |
| 188 | + return; | |
| 189 | + } | |
| 190 | + | |
| 191 | + if ( empty( $action->post_content['billing_address'] ) ) { | |
| 192 | + return; | |
| 193 | + } | |
| 194 | + | |
| 195 | + $address_field = FrmField::getOne( $action->post_content['billing_address'] ); | |
| 196 | + | |
| 197 | + if ( ! $address_field || self::address_field_is_compatible_with_square( $address_field ) ) { | |
| 198 | + return; | |
| 199 | + } | |
| 200 | + ?> | |
| 201 | + <div class="frm_warning_style"> | |
| 202 | + <?php | |
| 203 | + esc_html_e( 'The address field selected is not compatible with Square, because it does not include the country code. Select another address type to prevent checkout errors.', 'formidable' ); // phpcs:ignore SlevomatCodingStandard.Files.LineLength.LineTooLong | |
| 204 | + ?> | |
| 205 | + </div> | |
| 206 | + <?php | |
| 207 | + } | |
| 208 | + | |
| 209 | + /** | |
| 210 | + * Square requires a country code, which the generic address type does not collect. | |
| 211 | + * | |
| 212 | + * @since 6.34 | |
| 213 | + * | |
| 214 | + * @param stdClass $field | |
| 215 | + * | |
| 216 | + * @return bool | |
| 217 | + */ | |
| 218 | + private static function address_field_is_compatible_with_square( $field ) { | |
| 219 | + return ! isset( $field->field_options['address_type'] ) || 'generic' !== $field->field_options['address_type']; | |
| 220 | + } | |
| 221 | + | |
| 222 | + /** | |
| 122 | 223 | * @param WP_Post $action |
| 224 | + * | |
| 123 | 225 | * @return array |
| 124 | 226 | */ |
| 125 | 227 | public static function get_billing_contact( $action ) { |
| 126 | 228 | $email_setting = $action->post_content['email']; |
| @@ -125,10 +227,12 @@ | ||
| 125 | 227 | public static function get_billing_contact( $action ) { |
| 126 | 228 | $email_setting = $action->post_content['email']; |
| 127 | 229 | $first_name_setting = $action->post_content['billing_first_name']; |
| 128 | 230 | $last_name_setting = $action->post_content['billing_last_name']; |
| 129 | - $address_setting = $action->post_content['billing_address']; | |
| 130 | 231 | |
| 232 | + // @phpstan-ignore-next-line | |
| 233 | + $address_setting = $action->post_content['billing_address'] ?? ''; | |
| 234 | + | |
| 131 | 235 | $entry = self::generate_false_entry(); |
| 132 | 236 | $first_name = $first_name_setting && isset( $entry->metas[ $first_name_setting ] ) ? $entry->metas[ $first_name_setting ] : ''; |
| 133 | 237 | $last_name = $last_name_setting && isset( $entry->metas[ $last_name_setting ] ) ? $entry->metas[ $last_name_setting ] : ''; |
| 134 | 238 | $address = $address_setting && isset( $entry->metas[ $address_setting ] ) ? $entry->metas[ $address_setting ] : ''; |
| @@ -165,16 +269,18 @@ | ||
| 165 | 269 | * |
| 166 | 270 | * @param array $details |
| 167 | 271 | * @param array $address |
| 168 | 272 | * @param int $address_field_id |
| 273 | + * | |
| 169 | 274 | * @return void |
| 170 | 275 | */ |
| 171 | 276 | private static function maybe_add_address_data( &$details, $address, $address_field_id ) { |
| 172 | - if ( ! is_array( $address ) || ! isset( $address['line1'] ) || ! isset( $address['line2'] ) || ! is_callable( 'FrmProAddressesController::get_country_code' ) ) { | |
| 277 | + if ( ! is_array( $address ) || ! isset( $address['line1'] ) || ! isset( $address['line2'] ) ) { | |
| 173 | 278 | return; |
| 174 | 279 | } |
| 175 | 280 | |
| 176 | 281 | $address_field = FrmField::getOne( $address_field_id ); |
| 282 | + | |
| 177 | 283 | if ( ! $address_field ) { |
| 178 | 284 | return; |
| 179 | 285 | } |
| 180 | 286 | |
| @@ -180,9 +286,9 @@ | ||
| 180 | 286 | |
| 181 | 287 | if ( 'us' === $address_field->field_options['address_type'] ) { |
| 182 | 288 | $country_code = 'US'; |
| 183 | 289 | } else { |
| 184 | - $country_code = FrmProAddressesController::get_country_code( $address['country'] ); | |
| 290 | + $country_code = FrmAddressesController::get_country_code( $address['country'] ); | |
| 185 | 291 | } |
| 186 | 292 | |
| 187 | 293 | if ( ! $address['line1'] && ! $address['line2'] && ! $address['city'] && ! $address['state'] && ! $address['zip'] && ! $country_code ) { |
| 188 | 294 | return; |
| @@ -198,8 +304,9 @@ | ||
| 198 | 304 | /** |
| 199 | 305 | * Create an entry object with posted values. |
| 200 | 306 | * |
| 201 | 307 | * @since 6.22 |
| 308 | + * | |
| 202 | 309 | * @return stdClass |
| 203 | 310 | */ |
| 204 | 311 | private static function generate_false_entry() { |
| 205 | 312 | $entry = new stdClass(); |
| @@ -205,9 +312,11 @@ | ||
| 205 | 312 | $entry = new stdClass(); |
| 206 | 313 | $entry->post_id = 0; |
| 207 | 314 | $entry->id = 0; |
| 208 | 315 | $entry->item_key = ''; |
| 209 | - $entry->metas = array(); | |
| 316 | + // Shortcode replacement reads ip off of the entry, so it cannot be left unset. | |
| 317 | + $entry->ip = ''; | |
| 318 | + $entry->metas = array(); | |
| 210 | 319 | |
| 211 | 320 | // phpcs:ignore WordPress.Security.NonceVerification.Missing |
| 212 | 321 | foreach ( $_POST as $k => $v ) { |
| 213 | 322 | $k = sanitize_text_field( stripslashes( $k ) ); |
| @@ -212,18 +321,21 @@ | ||
| 212 | 321 | foreach ( $_POST as $k => $v ) { |
| 213 | 322 | $k = sanitize_text_field( stripslashes( $k ) ); |
| 214 | 323 | $v = wp_unslash( $v ); |
| 215 | 324 | |
| 216 | - if ( $k === 'item_meta' ) { | |
| 217 | - if ( is_array( $v ) ) { | |
| 218 | - foreach ( $v as $f => $value ) { | |
| 219 | - FrmAppHelper::sanitize_value( 'wp_kses_post', $value ); | |
| 220 | - $entry->metas[ absint( $f ) ] = $value; | |
| 221 | - } | |
| 222 | - } | |
| 223 | - } else { | |
| 325 | + if ( $k !== 'item_meta' ) { | |
| 224 | 326 | FrmAppHelper::sanitize_value( 'wp_kses_post', $v ); |
| 225 | 327 | $entry->{$k} = $v; |
| 328 | + continue; | |
| 329 | + } | |
| 330 | + | |
| 331 | + if ( ! is_array( $v ) ) { | |
| 332 | + continue; | |
| 333 | + } | |
| 334 | + | |
| 335 | + foreach ( $v as $f => $value ) { | |
| 336 | + FrmAppHelper::sanitize_value( 'wp_kses_post', $value ); | |
| 337 | + $entry->metas[ absint( $f ) ] = $value; | |
| 226 | 338 | } |
| 227 | 339 | } |
| 228 | 340 | |
| 229 | 341 | return $entry; |