← All changes
|
src/PaymentGateways/Gateways/PayPalStandard/Webhooks/WebhookValidator.php
+1
-6
4.16.8.1
→
4.18.0.1
View file →
| @@ -14,8 +14,9 @@ | ||
| 14 | 14 | { |
| 15 | 15 | /** |
| 16 | 16 | * @since 2.19.0 |
| 17 | 17 | * @since 2.19.3 Update log message. |
| 18 | + * @since 4.18.0.1 Always validate the IPN with PayPal and verify its SSL certificate. | |
| 18 | 19 | * |
| 19 | 20 | * @param array $eventData PayPal ipn body data. |
| 20 | 21 | * |
| 21 | 22 | * @return bool |
| @@ -23,13 +24,8 @@ | ||
| 23 | 24 | public function verifyEventSignature(array $eventData) |
| 24 | 25 | { |
| 25 | 26 | $eventData = array_merge( [ 'cmd' => '_notify-validate' ], $eventData ); |
| 26 | 27 | |
| 27 | - // Validate IPN request w/ PayPal if user hasn't disabled this security measure. | |
| 28 | - if (! give_is_setting_enabled(give_get_option('paypal_verification', 'enabled'))) { | |
| 29 | - return true; | |
| 30 | - } | |
| 31 | - | |
| 32 | 28 | $requestArgs = [ |
| 33 | 29 | 'method' => 'POST', |
| 34 | 30 | 'timeout' => 45, |
| 35 | 31 | 'redirection' => 5, |
| @@ -40,9 +36,8 @@ | ||
| 40 | 36 | 'connection' => 'close', |
| 41 | 37 | 'content-type' => 'application/x-www-form-urlencoded', |
| 42 | 38 | 'post' => '/cgi-bin/webscr HTTP/1.1', |
| 43 | 39 | ], |
| 44 | - 'sslverify' => false, | |
| 45 | 40 | 'body' => $eventData, |
| 46 | 41 | ]; |
| 47 | 42 | |
| 48 | 43 | $apiResponse = wp_remote_post(give_get_paypal_redirect(), $requestArgs); |