| 1 |
<?php |
| 2 |
/** |
| 3 |
* Gateway Actions |
| 4 |
* |
| 5 |
* @package Give |
| 6 |
* @subpackage Gateways |
| 7 |
* @copyright Copyright (c) 2016, GiveWP |
| 8 |
* @license https://opensource.org/licenses/gpl-license GNU Public License |
| 9 |
* @since 1.0 |
| 10 |
*/ |
| 11 |
|
| 12 |
// Exit if accessed directly. |
| 13 |
if ( ! defined( 'ABSPATH' ) ) { |
| 14 |
exit; |
| 15 |
} |
| 16 |
|
| 17 |
use Give\Helpers\Form\Utils as FormUtils; |
| 18 |
use Give\Helpers\Frontend\Shortcode as ShortcodeUtils; |
| 19 |
|
| 20 |
/** |
| 21 |
* Processes gateway select on checkout. Only for users without ajax / javascript |
| 22 |
* |
| 23 |
* @since 1.0 |
| 24 |
* |
| 25 |
* @param $data |
| 26 |
*/ |
| 27 |
function give_process_gateway_select( $data ) { |
| 28 |
if ( isset( $_POST['gateway_submit'] ) ) { |
| 29 |
wp_redirect( esc_url_raw( add_query_arg( 'payment-mode', $_POST['payment-mode'] ) ) ); |
| 30 |
exit; |
| 31 |
} |
| 32 |
} |
| 33 |
|
| 34 |
add_action( 'give_gateway_select', 'give_process_gateway_select' ); |
| 35 |
|
| 36 |
/** |
| 37 |
* Loads a payment gateway via AJAX. |
| 38 |
* |
| 39 |
* @since 1.0 |
| 40 |
* |
| 41 |
* @return void |
| 42 |
*/ |
| 43 |
function give_load_ajax_gateway() { |
| 44 |
|
| 45 |
$post_data = give_clean( $_POST ); // WPCS: input var ok, CSRF ok. |
| 46 |
|
| 47 |
if ( |
| 48 |
! isset( $post_data['nonce'] ) |
| 49 |
|| ! give_verify_donation_form_nonce( $post_data['nonce'], $post_data['give_form_id'] ) |
| 50 |
) { |
| 51 |
Give_Notices::print_frontend_notice( __( 'We\'re unable to recognize your session. Please refresh the screen to try again; otherwise contact your website administrator for assistance.', 'give' ), true, 'error' ); |
| 52 |
exit(); |
| 53 |
|
| 54 |
} elseif ( isset( $post_data['give_payment_mode'] ) ) { |
| 55 |
|
| 56 |
$form_id_prefix = ! empty( $post_data['give_form_id_prefix'] ) ? $post_data['give_form_id_prefix'] : ''; |
| 57 |
|
| 58 |
$args = array( |
| 59 |
'id_prefix' => $form_id_prefix, |
| 60 |
); |
| 61 |
|
| 62 |
/** |
| 63 |
* Fire to render donation form. |
| 64 |
* |
| 65 |
* @since 1.7 |
| 66 |
*/ |
| 67 |
do_action( 'give_donation_form', $post_data['give_form_id'], $args ); |
| 68 |
|
| 69 |
exit(); |
| 70 |
} |
| 71 |
} |
| 72 |
|
| 73 |
add_action( 'wp_ajax_give_load_gateway', 'give_load_ajax_gateway' ); |
| 74 |
add_action( 'wp_ajax_nopriv_give_load_gateway', 'give_load_ajax_gateway' ); |
| 75 |
|
| 76 |
/** |
| 77 |
* Create wp nonce using Ajax call. |
| 78 |
* |
| 79 |
* Use give_donation_form_nonce() js fn to create nonce. |
| 80 |
* |
| 81 |
* @since 4.16.6 Bail early when the form ID is not a give_forms post or is a Visual Form Builder (v3) form. |
| 82 |
* @since 2.0 |
| 83 |
* |
| 84 |
* @return void |
| 85 |
*/ |
| 86 |
function give_donation_form_nonce() { |
| 87 |
if ( isset( $_POST['give_form_id'] ) ) { |
| 88 |
|
| 89 |
// Get donation form id. |
| 90 |
$form_id = is_numeric( $_POST['give_form_id'] ) ? absint( $_POST['give_form_id'] ) : 0; |
| 91 |
|
| 92 |
if ( ! ShortcodeUtils::isValidForm( $form_id ) ) { |
| 93 |
wp_send_json_error( [ 'error' => 'give_invalid_donation_form' ], 400 ); |
| 94 |
} |
| 95 |
|
| 96 |
// Visual Form Builder (v3) forms use route signatures instead of the legacy nonce endpoint. |
| 97 |
if ( FormUtils::isV3Form( $form_id ) ) { |
| 98 |
wp_send_json_error( [ 'error' => 'give_unsupported_form_version' ], 400 ); |
| 99 |
} |
| 100 |
|
| 101 |
// Send nonce json data. |
| 102 |
wp_send_json_success( wp_create_nonce( "give_donation_form_nonce_{$form_id}" ) ); |
| 103 |
} |
| 104 |
} |
| 105 |
|
| 106 |
add_action( 'wp_ajax_give_donation_form_nonce', 'give_donation_form_nonce' ); |
| 107 |
add_action( 'wp_ajax_nopriv_give_donation_form_nonce', 'give_donation_form_nonce' ); |
| 108 |
|
| 109 |
|
| 110 |
/** |
| 111 |
* Create all nonce of donation form using Ajax call. |
| 112 |
* Note: only for internal use |
| 113 |
* |
| 114 |
* @since 4.16.6 Bail early when the form ID is not a give_forms post. |
| 115 |
* @since 4.9.0 rename function - PHP 8 compatibility |
| 116 |
* @since 2.2.0 |
| 117 |
* |
| 118 |
* @return void |
| 119 |
*/ |
| 120 |
function give_donation_form_reset_all_nonce() { |
| 121 |
if ( isset( $_POST['give_form_id'] ) ) { |
| 122 |
|
| 123 |
// Get donation form id. |
| 124 |
$form_id = is_numeric( $_POST['give_form_id'] ) ? absint( $_POST['give_form_id'] ) : 0; |
| 125 |
|
| 126 |
if ( ! ShortcodeUtils::isValidForm( $form_id ) ) { |
| 127 |
wp_send_json_error( [ 'error' => 'give_invalid_donation_form' ], 400 ); |
| 128 |
} |
| 129 |
|
| 130 |
$data = array( |
| 131 |
'give_form_hash' => wp_create_nonce( "give_donation_form_nonce_{$form_id}" ), |
| 132 |
'give_form_user_register_hash' => wp_create_nonce( "give_form_create_user_nonce_{$form_id}" ), |
| 133 |
); |
| 134 |
|
| 135 |
/** |
| 136 |
* Filter the ajax request data |
| 137 |
* |
| 138 |
* @since 2.2.0 |
| 139 |
*/ |
| 140 |
$data = apply_filters( 'give_donation_form_reset_all_nonce_data', $data ); |
| 141 |
|
| 142 |
// Send nonce json data. |
| 143 |
wp_send_json_success( $data ); |
| 144 |
} |
| 145 |
|
| 146 |
wp_send_json_error(); |
| 147 |
} |
| 148 |
|
| 149 |
add_action( 'wp_ajax_give_donation_form_reset_all_nonce', 'give_donation_form_reset_all_nonce'); |
| 150 |
add_action( 'wp_ajax_nopriv_give_donation_form_reset_all_nonce', 'give_donation_form_reset_all_nonce'); |
| 151 |
|
| 152 |
/** |
| 153 |
* Sets an error within the donation form if no gateways are enabled. |
| 154 |
* |
| 155 |
* @todo: we can deprecate this function in future because gateways will not empty if get via Give API. |
| 156 |
* |
| 157 |
* @since 1.0 |
| 158 |
* |
| 159 |
* @return void |
| 160 |
*/ |
| 161 |
function give_no_gateway_error() { |
| 162 |
$gateways = give_get_enabled_payment_gateways(); |
| 163 |
|
| 164 |
if ( empty( $gateways ) ) { |
| 165 |
give_set_error( 'no_gateways', esc_html__( 'You must enable a payment gateway to use Give.', 'give' ) ); |
| 166 |
} else { |
| 167 |
give_unset_error( 'no_gateways' ); |
| 168 |
} |
| 169 |
} |
| 170 |
|
| 171 |
add_action( 'init', 'give_no_gateway_error' ); |
| 172 |
|