PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / trunk
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More vtrunk
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | square/controllers/FrmSquareLiteAppController.php +118 -19 6.26 → trunk View file →
@@ -79,13 +79,13 @@
79 79 }
80 80
81 81 $actions = FrmSquareLiteActionsController::get_actions_before_submit( $form_id );
82 82
83 - if ( empty( $actions ) ) {
83 + if ( ! $actions ) {
84 84 wp_send_json_error( __( 'No Square actions found for this form', 'formidable' ) );
85 85 }
86 86
87 - $action = reset( $actions );
87 + $action = self::get_action_for_verification( $actions );
88 88 $verification_details = array(
89 89 'amount' => self::get_amount_value_for_verification( $action ),
90 90 'billingContact' => self::get_billing_contact( $action ),
91 91 'currencyCode' => strtoupper( $action->post_content['currency'] ),
@@ -100,10 +100,45 @@
100 100 );
101 101 }
102 102
103 103 /**
104 + * Get the action that the submission will actually trigger.
105 + *
106 + * Square verifies a single amount, so when a form has more than one Square action,
107 + * the conditional logic of each action is checked against the posted values. Without
108 + * this, the first action always wins and the buyer gets verified for an amount that
109 + * a different action is going to charge.
110 + *
111 + * @since 6.35
112 + *
113 + * @param array $actions Payment actions from FrmSquareLiteActionsController::get_actions_before_submit. Never empty.
114 + *
115 + * @return WP_Post
116 + */
117 + private static function get_action_for_verification( $actions ) {
118 + if ( count( $actions ) > 1 ) {
119 + $entry = self::generate_false_entry();
120 +
121 + foreach ( $actions as $action ) {
122 + if ( ! FrmFormAction::action_conditions_met( $action, $entry ) ) {
123 + // Conditions were met, so this is the action that will charge the buyer.
124 + return $action;
125 + }
126 + }
127 + }
128 +
129 + // Either there is a single action, or no action passed its conditional logic.
130 + return reset( $actions );
131 + }
132 +
133 + /**
104 134 * Get the amount value for verification.
105 135 *
136 + * Square's verifyBuyer expects the amount as a decimal string in the currency's
137 + * major units ("20.00" for twenty pounds), not the smallest denomination that the
138 + * Payments API uses. FrmSquareLiteActionsController::prepare_amount returns the
139 + * smallest denomination, so the parent is called here instead.
140 + *
106 141 * @param WP_Post $action
107 142 *
108 143 * @return string
109 144 */
@@ -109,10 +144,11 @@
109 144 */
110 145 private static function get_amount_value_for_verification( $action ) {
111 146 $amount = $action->post_content['amount'];
112 147
113 - if ( strpos( $amount, '[' ) === false ) {
114 - return $amount;
148 + if ( ! str_contains( $amount, '[' ) ) {
149 + $currency = $action->post_content['currency'];
150 + return FrmTransLiteActionsController::prepare_amount( $amount, compact( 'currency' ) );
115 151 }
116 152
117 153 $form = FrmForm::getOne( $action->menu_order );
118 154
@@ -120,15 +156,71 @@
120 156 return $amount;
121 157 }
122 158
123 159 // Update amount based on field shortcodes.
124 - $entry = self::generate_false_entry();
125 - $amount = FrmSquareLiteActionsController::prepare_amount( $amount, compact( 'form', 'entry', 'action' ) );
160 + $entry = self::generate_false_entry();
126 161
127 - return $amount;
162 + return FrmTransLiteActionsController::prepare_amount( $amount, compact( 'form', 'entry', 'action' ) );
128 163 }
129 164
130 165 /**
166 + * Show a warning in the payment action settings when the selected address field
167 + * uses an address type without a country, as Square requires a country code.
168 + *
169 + * @since 6.34
170 + *
171 + * @param object $action
172 + *
173 + * @return void
174 + */
175 + public static function maybe_show_address_type_warning( $action ) {
176 + if ( is_callable( 'FrmProSquareLiteController::maybe_show_address_type_warning' ) ) {
177 + // Pro renders this warning with the same hook.
178 + return;
179 + }
180 +
181 + if ( empty( $action->post_content['gateway'] ) ) {
182 + return;
183 + }
184 +
185 + $gateways = (array) $action->post_content['gateway'];
186 +
187 + if ( ! in_array( 'square', $gateways, true ) ) {
188 + return;
189 + }
190 +
191 + if ( empty( $action->post_content['billing_address'] ) ) {
192 + return;
193 + }
194 +
195 + $address_field = FrmField::getOne( $action->post_content['billing_address'] );
196 +
197 + if ( ! $address_field || self::address_field_is_compatible_with_square( $address_field ) ) {
198 + return;
199 + }
200 + ?>
201 + <div class="frm_warning_style">
202 + <?php
203 + esc_html_e( 'The address field selected is not compatible with Square, because it does not include the country code. Select another address type to prevent checkout errors.', 'formidable' ); // phpcs:ignore SlevomatCodingStandard.Files.LineLength.LineTooLong
204 + ?>
205 + </div>
206 + <?php
207 + }
208 +
209 + /**
210 + * Square requires a country code, which the generic address type does not collect.
211 + *
212 + * @since 6.34
213 + *
214 + * @param stdClass $field
215 + *
216 + * @return bool
217 + */
218 + private static function address_field_is_compatible_with_square( $field ) {
219 + return ! isset( $field->field_options['address_type'] ) || 'generic' !== $field->field_options['address_type'];
220 + }
221 +
222 + /**
131 223 * @param WP_Post $action
132 224 *
133 225 * @return array
134 226 */
@@ -135,10 +227,12 @@
135 227 public static function get_billing_contact( $action ) {
136 228 $email_setting = $action->post_content['email'];
137 229 $first_name_setting = $action->post_content['billing_first_name'];
138 230 $last_name_setting = $action->post_content['billing_last_name'];
139 - $address_setting = $action->post_content['billing_address'];
140 231
232 + // @phpstan-ignore-next-line
233 + $address_setting = $action->post_content['billing_address'] ?? '';
234 +
141 235 $entry = self::generate_false_entry();
142 236 $first_name = $first_name_setting && isset( $entry->metas[ $first_name_setting ] ) ? $entry->metas[ $first_name_setting ] : '';
143 237 $last_name = $last_name_setting && isset( $entry->metas[ $last_name_setting ] ) ? $entry->metas[ $last_name_setting ] : '';
144 238 $address = $address_setting && isset( $entry->metas[ $address_setting ] ) ? $entry->metas[ $address_setting ] : '';
@@ -179,9 +273,9 @@
179 273 *
180 274 * @return void
181 275 */
182 276 private static function maybe_add_address_data( &$details, $address, $address_field_id ) {
183 - if ( ! is_array( $address ) || ! isset( $address['line1'] ) || ! isset( $address['line2'] ) || ! is_callable( 'FrmProAddressesController::get_country_code' ) ) {
277 + if ( ! is_array( $address ) || ! isset( $address['line1'] ) || ! isset( $address['line2'] ) ) {
184 278 return;
185 279 }
186 280
187 281 $address_field = FrmField::getOne( $address_field_id );
@@ -192,9 +286,9 @@
192 286
193 287 if ( 'us' === $address_field->field_options['address_type'] ) {
194 288 $country_code = 'US';
195 289 } else {
196 - $country_code = FrmProAddressesController::get_country_code( $address['country'] );
290 + $country_code = FrmAddressesController::get_country_code( $address['country'] );
197 291 }
198 292
199 293 if ( ! $address['line1'] && ! $address['line2'] && ! $address['city'] && ! $address['state'] && ! $address['zip'] && ! $country_code ) {
200 294 return;
@@ -218,9 +312,11 @@
218 312 $entry = new stdClass();
219 313 $entry->post_id = 0;
220 314 $entry->id = 0;
221 315 $entry->item_key = '';
222 - $entry->metas = array();
316 + // Shortcode replacement reads ip off of the entry, so it cannot be left unset.
317 + $entry->ip = '';
318 + $entry->metas = array();
223 319
224 320 // phpcs:ignore WordPress.Security.NonceVerification.Missing
225 321 foreach ( $_POST as $k => $v ) {
226 322 $k = sanitize_text_field( stripslashes( $k ) );
@@ -225,18 +321,21 @@
225 321 foreach ( $_POST as $k => $v ) {
226 322 $k = sanitize_text_field( stripslashes( $k ) );
227 323 $v = wp_unslash( $v );
228 324
229 - if ( $k === 'item_meta' ) {
230 - if ( is_array( $v ) ) {
231 - foreach ( $v as $f => $value ) {
232 - FrmAppHelper::sanitize_value( 'wp_kses_post', $value );
233 - $entry->metas[ absint( $f ) ] = $value;
234 - }
235 - }
236 - } else {
325 + if ( $k !== 'item_meta' ) {
237 326 FrmAppHelper::sanitize_value( 'wp_kses_post', $v );
238 327 $entry->{$k} = $v;
328 + continue;
329 + }
330 +
331 + if ( ! is_array( $v ) ) {
332 + continue;
333 + }
334 +
335 + foreach ( $v as $f => $value ) {
336 + FrmAppHelper::sanitize_value( 'wp_kses_post', $value );
337 + $entry->metas[ absint( $f ) ] = $value;
239 338 }
240 339 }
241 340
242 341 return $entry;