| @@ -151,8 +151,10 @@ | ||
| 151 | 151 | case 'create_subscription_failed': |
| 152 | 152 | return __( 'Something went wrong when trying to create a subscription.', 'formidable' ); |
| 153 | 153 | case 'payment_failed': |
| 154 | 154 | return __( 'Payment was not successfully processed.', 'formidable' ); |
| 155 | + case 'amount_mismatch': | |
| 156 | + return __( 'The payment amount does not match the expected amount.', 'formidable' ); | |
| 155 | 157 | } |
| 156 | 158 | return ''; |
| 157 | 159 | } |
| 158 | 160 | |
| @@ -225,9 +227,9 @@ | ||
| 225 | 227 | |
| 226 | 228 | $intents = self::get_payment_intents( 'frmintent' . $form->id ); |
| 227 | 229 | |
| 228 | 230 | if ( $intents ) { |
| 229 | - self::update_intent_pricing( $form->id, $intents ); | |
| 231 | + self::update_intent_pricing( $form->id, $intents, $_POST ); // phpcs:ignore WordPress.Security.NonceVerification.Missing | |
| 230 | 232 | } else { |
| 231 | 233 | $intents = self::maybe_create_intents( $form->id ); |
| 232 | 234 | } |
| 233 | 235 | |
| @@ -308,20 +310,19 @@ | ||
| 308 | 310 | if ( ! $intents ) { |
| 309 | 311 | wp_die(); |
| 310 | 312 | } |
| 311 | 313 | |
| 312 | - if ( ! is_array( $intents ) ) { | |
| 313 | - $intents = array( $intents ); | |
| 314 | - } else { | |
| 314 | + if ( is_array( $intents ) ) { | |
| 315 | 315 | foreach ( $intents as $k => $intent ) { |
| 316 | 316 | if ( is_array( $intent ) && isset( $intent[ $k ] ) ) { |
| 317 | 317 | $intents[ $k ] = $intent[ $k ]; |
| 318 | 318 | } |
| 319 | 319 | } |
| 320 | + } else { | |
| 321 | + $intents = array( $intents ); | |
| 320 | 322 | } |
| 321 | 323 | |
| 322 | - $_POST = $form; | |
| 323 | - self::update_intent_pricing( $form_id, $intents ); | |
| 324 | + self::update_intent_pricing( $form_id, $intents, $form ); | |
| 324 | 325 | |
| 325 | 326 | wp_die(); |
| 326 | 327 | } |
| 327 | 328 | |
| @@ -329,16 +330,16 @@ | ||
| 329 | 330 | * Update pricing on page turn and non-ajax validation. |
| 330 | 331 | * |
| 331 | 332 | * @since 6.5, introduced in v2.0 of the Stripe add on. |
| 332 | 333 | * |
| 333 | - * @param int $form_id | |
| 334 | - * @param array $intents | |
| 334 | + * @param int|string $form_id | |
| 335 | + * @param array $intents | |
| 336 | + * @param array $form_data | |
| 335 | 337 | * |
| 336 | 338 | * @return void |
| 337 | 339 | */ |
| 338 | - private static function update_intent_pricing( $form_id, &$intents ) { | |
| 339 | - // phpcs:ignore WordPress.Security.NonceVerification.Missing, Universal.Operators.StrictComparisons | |
| 340 | - if ( ! isset( $_POST['form_id'] ) || absint( $_POST['form_id'] ) != $form_id ) { | |
| 340 | + private static function update_intent_pricing( $form_id, &$intents, $form_data ) { | |
| 341 | + if ( ! isset( $form_data['form_id'] ) || absint( $form_data['form_id'] ) !== (int) $form_id ) { | |
| 341 | 342 | return; |
| 342 | 343 | } |
| 343 | 344 | |
| 344 | 345 | $actions = FrmStrpLiteActionsController::get_actions_before_submit( $form_id ); |
| @@ -390,9 +391,9 @@ | ||
| 390 | 391 | continue; |
| 391 | 392 | } |
| 392 | 393 | |
| 393 | 394 | // Update amount based on field shortcodes. |
| 394 | - $entry = self::generate_false_entry(); | |
| 395 | + $entry = self::generate_false_entry( $form_data ); | |
| 395 | 396 | $amount = FrmStrpLiteActionsController::prepare_amount( $amount, compact( 'form', 'entry', 'action' ) ); |
| 396 | 397 | |
| 397 | 398 | // phpcs:ignore Universal.Operators.StrictComparisons |
| 398 | 399 | if ( $saved->amount == $amount || $amount == '000' ) { |
| @@ -408,11 +409,13 @@ | ||
| 408 | 409 | * Create an entry object with posted values. |
| 409 | 410 | * |
| 410 | 411 | * @since 6.5, introduced in v2.0 of the Stripe add on. |
| 411 | 412 | * |
| 413 | + * @param array $form_data | |
| 414 | + * | |
| 412 | 415 | * @return stdClass |
| 413 | 416 | */ |
| 414 | - private static function generate_false_entry() { | |
| 417 | + private static function generate_false_entry( $form_data ) { | |
| 415 | 418 | $entry = new stdClass(); |
| 416 | 419 | $entry->post_id = 0; |
| 417 | 420 | $entry->id = 0; |
| 418 | 421 | $entry->item_key = ''; |
| @@ -417,10 +420,9 @@ | ||
| 417 | 420 | $entry->id = 0; |
| 418 | 421 | $entry->item_key = ''; |
| 419 | 422 | $entry->metas = array(); |
| 420 | 423 | |
| 421 | - // phpcs:ignore WordPress.Security.NonceVerification.Missing | |
| 422 | - foreach ( $_POST as $k => $v ) { | |
| 424 | + foreach ( $form_data as $k => $v ) { | |
| 423 | 425 | $k = sanitize_text_field( stripslashes( $k ) ); |
| 424 | 426 | $v = wp_unslash( $v ); |
| 425 | 427 | |
| 426 | 428 | if ( $k !== 'item_meta' ) { |
| @@ -764,9 +766,9 @@ | ||
| 764 | 766 | if ( empty( $success_url ) ) { |
| 765 | 767 | $success_url = $atts['form']->options['success_url']; |
| 766 | 768 | } |
| 767 | 769 | |
| 768 | - $success_url = trim( $atts['form']->options['success_url'] ); | |
| 770 | + $success_url = trim( $success_url ); | |
| 769 | 771 | $success_url = apply_filters( 'frm_content', $success_url, $atts['form'], $atts['entry'] ); |
| 770 | 772 | $success_url = do_shortcode( $success_url ); |
| 771 | 773 | $atts['id'] = $atts['entry']->id; |
| 772 | 774 | |