PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / trunk
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More vtrunk
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | stripe/helpers/FrmStrpLiteLinkRedirectHelper.php +21 -6 6.25 → trunk View file →
@@ -25,8 +25,9 @@
25 25
26 26 /**
27 27 * @param string $stripe_id either a Payment Intent ID (prefixed with pi_) or a Setup Intent ID (prefixed with seti_).
28 28 * @param string $client_secret
29 + *
29 30 * @return void
30 31 */
31 32 public function __construct( $stripe_id, $client_secret ) {
32 33 $this->stripe_id = $stripe_id;
@@ -37,8 +38,9 @@
37 38 * Set the entry ID to pull referer data from.
38 39 * This is separate from the constructor as the entry ID isn't known for some error cases.
39 40 *
40 41 * @param int|string $entry_id
42 + *
41 43 * @return void
42 44 */
43 45 public function set_entry_id( $entry_id ) {
44 46 $this->entry_id = absint( $entry_id );
@@ -46,12 +48,13 @@
46 48
47 49 /**
48 50 * @param string $error_code
49 51 * @param string $charge_id
52 + *
50 53 * @return void
51 54 */
52 55 public function handle_error( $error_code, $charge_id = '' ) {
53 - if ( ! empty( $this->entry_id ) ) {
56 + if ( $this->entry_id ) {
54 57 $referer = FrmStrpLiteAuth::get_referer_url( $this->entry_id );
55 58 }
56 59
57 60 if ( empty( $referer ) ) {
@@ -75,8 +78,9 @@
75 78 * Redirect to handle the form's on success condition similar to how 3D secure is handled after being redirected.
76 79 *
77 80 * @param stdClass $entry
78 81 * @param string $charge_id
82 + *
79 83 * @return void
80 84 */
81 85 public function handle_success( $entry, $charge_id ) {
82 86 $form = FrmForm::getOne( $entry->form_id );
@@ -83,10 +87,13 @@
83 87
84 88 // Let a stripe link success message get handled the same as a 3D secure redirect.
85 89 // When it shows a message, it adds a &frmstrp= param to the URL.
86 90 $redirect = FrmStrpLiteAuth::return_url( compact( 'form', 'entry' ) );
87 - $is_message_redirect = false !== strpos( $redirect, 'frmstrp=' );
91 + $is_message_redirect = str_contains( $redirect, 'frmstrp=' );
88 92
93 + // Call this before all redirects so the referer is always deleted.
94 + $referer_url = $this->get_referer_url( $entry->id );
95 +
89 96 if ( $this->url_is_external( $redirect ) || ! $is_message_redirect ) {
90 97 wp_redirect( $redirect );
91 98 die();
92 99 }
@@ -91,14 +98,15 @@
91 98 die();
92 99 }
93 100
94 101 // $redirect may not include the whole link to the form, breaking the redirect as iDEAL/Sofort have an additional redirect.
95 - $referer_url = $this->get_referer_url( $entry->id );
96 102 if ( is_string( $referer_url ) ) {
97 103 $parts = explode( '?', $redirect, 2 );
104 +
98 105 if ( 2 === count( $parts ) ) {
99 106 $redirect = $parts[1];
100 107 }
108 +
101 109 $redirect = $referer_url . '?' . $redirect;
102 110 }
103 111
104 112 if ( $charge_id ) {
@@ -111,20 +119,24 @@
111 119 /**
112 120 * Determine if a redirect URL is going to an external site or not.
113 121 *
114 122 * @param string $url
123 + *
124 + * @return bool
115 125 */
116 126 private function url_is_external( $url ) {
117 - if ( false === strpos( $url, 'http' ) ) {
127 + if ( ! str_contains( $url, 'http' ) ) {
118 128 return false;
119 129 }
120 130
121 131 $home_url = home_url();
122 132 $parsed = parse_url( $home_url );
133 +
123 134 if ( is_array( $parsed ) ) {
124 135 $home_url = $parsed['scheme'] . '://' . $parsed['host'];
125 136 }
126 - return 0 !== strpos( $url, $home_url );
137 +
138 + return ! str_starts_with( $url, $home_url );
127 139 }
128 140
129 141 /**
130 142 * Try to get the referer URL from the entry meta.
@@ -130,8 +142,9 @@
130 142 * Try to get the referer URL from the entry meta.
131 143 * If it is found, it will also be deleted as it is only required once.
132 144 *
133 145 * @param int|string $entry_id
146 + *
134 147 * @return false|string
135 148 */
136 149 private function get_referer_url( $entry_id ) {
137 150 $row = FrmDb::get_row(
@@ -142,8 +155,9 @@
142 155 'meta_value LIKE' => '{"referer":',
143 156 ),
144 157 'id, meta_value'
145 158 );
159 +
146 160 if ( ! $row ) {
147 161 return false;
148 162 }
149 163
@@ -161,8 +175,9 @@
161 175 /**
162 176 * Delete the referer meta as we'll no longer need it.
163 177 *
164 178 * @param int $row_id
179 + *
165 180 * @return void
166 181 */
167 182 private static function delete_temporary_referer_meta( $row_id ) {
168 183 global $wpdb;
@@ -174,9 +189,9 @@
174 189 *
175 190 * @param string $url
176 191 */
177 192 private function add_intent_info_and_redirect( $url ) {
178 - if ( 0 === strpos( $this->stripe_id, 'pi_' ) ) {
193 + if ( str_starts_with( $this->stripe_id, 'pi_' ) ) {
179 194 $url = add_query_arg( 'payment_intent', $this->stripe_id, $url );
180 195 $url = add_query_arg( 'payment_intent_client_secret', $this->client_secret, $url );
181 196 } else {
182 197 $url = add_query_arg( 'setup_intent', $this->stripe_id, $url );