| @@ -151,8 +151,10 @@ | ||
| 151 | 151 | case 'create_subscription_failed': |
| 152 | 152 | return __( 'Something went wrong when trying to create a subscription.', 'formidable' ); |
| 153 | 153 | case 'payment_failed': |
| 154 | 154 | return __( 'Payment was not successfully processed.', 'formidable' ); |
| 155 | + case 'amount_mismatch': | |
| 156 | + return __( 'The payment amount does not match the expected amount.', 'formidable' ); | |
| 155 | 157 | } |
| 156 | 158 | return ''; |
| 157 | 159 | } |
| 158 | 160 | |
| @@ -172,14 +174,16 @@ | ||
| 172 | 174 | $atts['conf_method'] = ! empty( $atts['form']->options[ $opt ] ) ? $atts['form']->options[ $opt ] : 'message'; |
| 173 | 175 | |
| 174 | 176 | $actions = FrmFormsController::get_met_on_submit_actions( $atts, 'create' ); |
| 175 | 177 | |
| 176 | - if ( $actions ) { | |
| 177 | - $action = reset( $actions ); | |
| 178 | + if ( ! $actions ) { | |
| 179 | + return; | |
| 180 | + } | |
| 178 | 181 | |
| 179 | - if ( ! empty( $action->post_content['success_action'] ) && 'message' === $action->post_content['success_action'] ) { | |
| 180 | - $atts['conf_method'] = $action->post_content['success_action']; | |
| 181 | - } | |
| 182 | + $action = reset( $actions ); | |
| 183 | + | |
| 184 | + if ( ! empty( $action->post_content['success_action'] ) && 'message' === $action->post_content['success_action'] ) { | |
| 185 | + $atts['conf_method'] = $action->post_content['success_action']; | |
| 182 | 186 | } |
| 183 | 187 | } |
| 184 | 188 | |
| 185 | 189 | /** |
| @@ -223,9 +227,9 @@ | ||
| 223 | 227 | |
| 224 | 228 | $intents = self::get_payment_intents( 'frmintent' . $form->id ); |
| 225 | 229 | |
| 226 | 230 | if ( $intents ) { |
| 227 | - self::update_intent_pricing( $form->id, $intents ); | |
| 231 | + self::update_intent_pricing( $form->id, $intents, $_POST ); // phpcs:ignore WordPress.Security.NonceVerification.Missing | |
| 228 | 232 | } else { |
| 229 | 233 | $intents = self::maybe_create_intents( $form->id ); |
| 230 | 234 | } |
| 231 | 235 | |
| @@ -306,20 +310,19 @@ | ||
| 306 | 310 | if ( ! $intents ) { |
| 307 | 311 | wp_die(); |
| 308 | 312 | } |
| 309 | 313 | |
| 310 | - if ( ! is_array( $intents ) ) { | |
| 311 | - $intents = array( $intents ); | |
| 312 | - } else { | |
| 314 | + if ( is_array( $intents ) ) { | |
| 313 | 315 | foreach ( $intents as $k => $intent ) { |
| 314 | 316 | if ( is_array( $intent ) && isset( $intent[ $k ] ) ) { |
| 315 | 317 | $intents[ $k ] = $intent[ $k ]; |
| 316 | 318 | } |
| 317 | 319 | } |
| 320 | + } else { | |
| 321 | + $intents = array( $intents ); | |
| 318 | 322 | } |
| 319 | 323 | |
| 320 | - $_POST = $form; | |
| 321 | - self::update_intent_pricing( $form_id, $intents ); | |
| 324 | + self::update_intent_pricing( $form_id, $intents, $form ); | |
| 322 | 325 | |
| 323 | 326 | wp_die(); |
| 324 | 327 | } |
| 325 | 328 | |
| @@ -327,22 +330,22 @@ | ||
| 327 | 330 | * Update pricing on page turn and non-ajax validation. |
| 328 | 331 | * |
| 329 | 332 | * @since 6.5, introduced in v2.0 of the Stripe add on. |
| 330 | 333 | * |
| 331 | - * @param int $form_id | |
| 332 | - * @param array $intents | |
| 334 | + * @param int|string $form_id | |
| 335 | + * @param array $intents | |
| 336 | + * @param array $form_data | |
| 333 | 337 | * |
| 334 | 338 | * @return void |
| 335 | 339 | */ |
| 336 | - private static function update_intent_pricing( $form_id, &$intents ) { | |
| 337 | - // phpcs:ignore WordPress.Security.NonceVerification.Missing, Universal.Operators.StrictComparisons | |
| 338 | - if ( ! isset( $_POST['form_id'] ) || absint( $_POST['form_id'] ) != $form_id ) { | |
| 340 | + private static function update_intent_pricing( $form_id, &$intents, $form_data ) { | |
| 341 | + if ( ! isset( $form_data['form_id'] ) || absint( $form_data['form_id'] ) !== (int) $form_id ) { | |
| 339 | 342 | return; |
| 340 | 343 | } |
| 341 | 344 | |
| 342 | 345 | $actions = FrmStrpLiteActionsController::get_actions_before_submit( $form_id ); |
| 343 | 346 | |
| 344 | - if ( ! $actions || empty( $intents ) ) { | |
| 347 | + if ( ! $actions || ! $intents ) { | |
| 345 | 348 | return; |
| 346 | 349 | } |
| 347 | 350 | |
| 348 | 351 | $form = FrmForm::getOne( $form_id ); |
| @@ -388,9 +391,9 @@ | ||
| 388 | 391 | continue; |
| 389 | 392 | } |
| 390 | 393 | |
| 391 | 394 | // Update amount based on field shortcodes. |
| 392 | - $entry = self::generate_false_entry(); | |
| 395 | + $entry = self::generate_false_entry( $form_data ); | |
| 393 | 396 | $amount = FrmStrpLiteActionsController::prepare_amount( $amount, compact( 'form', 'entry', 'action' ) ); |
| 394 | 397 | |
| 395 | 398 | // phpcs:ignore Universal.Operators.StrictComparisons |
| 396 | 399 | if ( $saved->amount == $amount || $amount == '000' ) { |
| @@ -406,11 +409,13 @@ | ||
| 406 | 409 | * Create an entry object with posted values. |
| 407 | 410 | * |
| 408 | 411 | * @since 6.5, introduced in v2.0 of the Stripe add on. |
| 409 | 412 | * |
| 413 | + * @param array $form_data | |
| 414 | + * | |
| 410 | 415 | * @return stdClass |
| 411 | 416 | */ |
| 412 | - private static function generate_false_entry() { | |
| 417 | + private static function generate_false_entry( $form_data ) { | |
| 413 | 418 | $entry = new stdClass(); |
| 414 | 419 | $entry->post_id = 0; |
| 415 | 420 | $entry->id = 0; |
| 416 | 421 | $entry->item_key = ''; |
| @@ -415,22 +420,22 @@ | ||
| 415 | 420 | $entry->id = 0; |
| 416 | 421 | $entry->item_key = ''; |
| 417 | 422 | $entry->metas = array(); |
| 418 | 423 | |
| 419 | - // phpcs:ignore WordPress.Security.NonceVerification.Missing | |
| 420 | - foreach ( $_POST as $k => $v ) { | |
| 424 | + foreach ( $form_data as $k => $v ) { | |
| 421 | 425 | $k = sanitize_text_field( stripslashes( $k ) ); |
| 422 | 426 | $v = wp_unslash( $v ); |
| 423 | 427 | |
| 424 | - if ( $k === 'item_meta' ) { | |
| 425 | - foreach ( $v as $f => $value ) { | |
| 426 | - FrmAppHelper::sanitize_value( 'wp_kses_post', $value ); | |
| 427 | - $entry->metas[ absint( $f ) ] = $value; | |
| 428 | - } | |
| 429 | - } else { | |
| 428 | + if ( $k !== 'item_meta' ) { | |
| 430 | 429 | FrmAppHelper::sanitize_value( 'wp_kses_post', $v ); |
| 431 | 430 | $entry->{$k} = $v; |
| 431 | + continue; | |
| 432 | 432 | } |
| 433 | + | |
| 434 | + foreach ( $v as $f => $value ) { | |
| 435 | + FrmAppHelper::sanitize_value( 'wp_kses_post', $value ); | |
| 436 | + $entry->metas[ absint( $f ) ] = $value; | |
| 437 | + } | |
| 433 | 438 | } |
| 434 | 439 | |
| 435 | 440 | return $entry; |
| 436 | 441 | } |
| @@ -449,16 +454,17 @@ | ||
| 449 | 454 | |
| 450 | 455 | foreach ( $form as $input ) { |
| 451 | 456 | $key = $input['name']; |
| 452 | 457 | |
| 453 | - if ( isset( $formatted[ $key ] ) ) { | |
| 454 | - if ( is_array( $formatted[ $key ] ) ) { | |
| 455 | - $formatted[ $key ][] = $input['value']; | |
| 456 | - } else { | |
| 457 | - $formatted[ $key ] = array( $formatted[ $key ], $input['value'] ); | |
| 458 | - } | |
| 458 | + if ( ! isset( $formatted[ $key ] ) ) { | |
| 459 | + $formatted[ $key ] = $input['value']; | |
| 460 | + continue; | |
| 461 | + } | |
| 462 | + | |
| 463 | + if ( is_array( $formatted[ $key ] ) ) { | |
| 464 | + $formatted[ $key ][] = $input['value']; | |
| 459 | 465 | } else { |
| 460 | - $formatted[ $key ] = $input['value']; | |
| 466 | + $formatted[ $key ] = array( $formatted[ $key ], $input['value'] ); | |
| 461 | 467 | } |
| 462 | 468 | } |
| 463 | 469 | |
| 464 | 470 | parse_str( http_build_query( $formatted ), $form ); |
| @@ -760,9 +766,9 @@ | ||
| 760 | 766 | if ( empty( $success_url ) ) { |
| 761 | 767 | $success_url = $atts['form']->options['success_url']; |
| 762 | 768 | } |
| 763 | 769 | |
| 764 | - $success_url = trim( $atts['form']->options['success_url'] ); | |
| 770 | + $success_url = trim( $success_url ); | |
| 765 | 771 | $success_url = apply_filters( 'frm_content', $success_url, $atts['form'], $atts['entry'] ); |
| 766 | 772 | $success_url = do_shortcode( $success_url ); |
| 767 | 773 | $atts['id'] = $atts['entry']->id; |
| 768 | 774 | |