| 1 |
<?php |
| 2 |
|
| 3 |
namespace Give\DonationForms\Actions; |
| 4 |
|
| 5 |
/** |
| 6 |
* @since 4.0.0 |
| 7 |
*/ |
| 8 |
class ValidateReceiptViewPermission |
| 9 |
{ |
| 10 |
/** |
| 11 |
* The GET parameter name for the receipt ID. |
| 12 |
* |
| 13 |
* @var string |
| 14 |
*/ |
| 15 |
private const RECEIPT_ID = 'receipt_id'; |
| 16 |
|
| 17 |
/** |
| 18 |
* @since 4.0.0 |
| 19 |
*/ |
| 20 |
public function __invoke(bool $canViewReceipt, int $donationId): bool |
| 21 |
{ |
| 22 |
if (!isset($_GET[self::RECEIPT_ID])) { |
| 23 |
return $canViewReceipt; |
| 24 |
} |
| 25 |
|
| 26 |
$receiptId = give_clean($_GET[self::RECEIPT_ID]); |
| 27 |
|
| 28 |
if (empty($receiptId)) { |
| 29 |
return $canViewReceipt; |
| 30 |
} |
| 31 |
|
| 32 |
$donation = give()->donations->getByReceiptId($receiptId); |
| 33 |
|
| 34 |
if (!$donation || $donation->id !== $donationId) { |
| 35 |
return $canViewReceipt; |
| 36 |
} |
| 37 |
|
| 38 |
return true; |
| 39 |
} |
| 40 |
} |
| 41 |
|