PluginProbe
GiveWP – Donation Plugin and Fundraising Platform / 4.18.0
GiveWP – Donation Plugin and Fundraising Platform v4.18.0
4.18.0 4.17.0 4.16.9 4.16.8.1 4.16.8 4.16.7.2 4.16.7.1 4.16.7 4.16.6.1 4.16.6 4.16.5.1 4.16.5 4.16.4 4.16.3 4.16.2 4.16.1 4.16.0 4.15.5 4.15.4 4.15.3 4.15.2 4.15.1 4.15.0 2.3.0 2.3.1 All 257 releases
← All changes | includes/admin/payments/actions.php +74 -64 2.3.0 → 4.18.0 View file →
@@ -3,16 +3,19 @@
3 3 * Admin Payment Actions
4 4 *
5 5 * @package Give
6 6 * @subpackage Admin/Payments
7 - * @copyright Copyright (c) 2016, WordImpress
7 + * @copyright Copyright (c) 2016, GiveWP
8 8 * @license https://opensource.org/licenses/gpl-license GNU Public License
9 9 * @since 1.0
10 10 */
11 11
12 12 // Exit if accessed directly.
13 -if ( ! defined( 'ABSPATH' ) ) {
14 - exit;
13 +use Give\Donations\Models\Donation;
14 +use Give\Donations\ValueObjects\DonationMetaKeys;
15 +
16 +if (!defined('ABSPATH')) {
17 + exit;
15 18 }
16 19
17 20 /**
18 21 *
@@ -17,12 +20,14 @@
17 20 /**
18 21 *
19 22 * Process the payment details edit
20 23 *
24 + * @since 2.27.0 Change to save comment to donations meta table
21 25 * @since 1.0
26 + *
22 27 * @access private
23 28 *
24 - * @param array $data Donation data.
29 + * @param array $data Donation data.
25 30 *
26 31 * @return void
27 32 */
28 33 function give_update_payment_details( $data ) {
@@ -39,9 +44,8 @@
39 44 /* @var Give_Payment $payment */
40 45 $payment = new Give_Payment( $payment_id );
41 46
42 47 $status = $data['give-payment-status'];
43 - $date = DateTime::createFromFormat( get_option( 'date_format' ), sanitize_text_field( $data['give-payment-date'] ) );
44 48 $hour = sanitize_text_field( $data['give-payment-time-hour'] );
45 49
46 50 // Restrict to our high and low.
47 51 if ( $hour > 23 ) {
@@ -62,9 +66,9 @@
62 66 $address = give_clean( $data['give-payment-address'][0] );
63 67
64 68 $curr_total = $payment->total;
65 69 $new_total = give_maybe_sanitize_amount( ( ! empty( $data['give-payment-total'] ) ? $data['give-payment-total'] : 0 ) );
66 - $date = $date->format('Y-m-d' ) . ' ' . $hour . ':' . $minute . ':00';
70 + $date = date( 'Y-m-d', strtotime( give_clean( $data['give-payment-date'] ) ) ) . ' ' . $hour . ':' . $minute . ':00';
67 71
68 72 $curr_donor_id = sanitize_text_field( $data['give-current-donor'] );
69 73 $new_donor_id = sanitize_text_field( $data['donor-id'] );
70 74
@@ -77,14 +81,13 @@
77 81 * @param int $payment_id The ID of the payment.
78 82 */
79 83 do_action( 'give_update_edited_donation', $payment_id );
80 84
81 - $payment->date = $date;
85 + $payment->date = $date;
82 86 $payment->anonymous = isset( $data['give_anonymous_donation'] ) ? absint( $data['give_anonymous_donation'] ) : 0;
83 87
88 + $updated = $payment->save();
84 89
85 - $updated = $payment->save();
86 -
87 90 if ( 0 === $updated ) {
88 91 wp_die( __( 'Error Updating Donation.', 'give' ), __( 'Error', 'give' ), array( 'response' => 400 ) );
89 92 }
90 93
@@ -102,10 +105,13 @@
102 105 }
103 106
104 107 $donor = new Give_Donor( $email );
105 108 if ( empty( $donor->id ) ) {
106 - $donor_data = array( 'name' => $names, 'email' => $email );
107 - $user_id = email_exists( $email );
109 + $donor_data = array(
110 + 'name' => $names,
111 + 'email' => $email,
112 + );
113 + $user_id = email_exists( $email );
108 114 if ( false !== $user_id ) {
109 115 $donor_data['user_id'] = $user_id;
110 116 }
111 117
@@ -129,10 +135,10 @@
129 135
130 136 } elseif ( $curr_donor_id !== $new_donor_id ) {
131 137
132 138 $donor = new Give_Donor( $new_donor_id );
133 - $email = $donor->email;
134 - $names = $donor->name;
139 + $email = $donor->email;
140 + $names = $donor->name;
135 141
136 142 $previous_donor = new Give_Donor( $curr_donor_id );
137 143
138 144 $donor_changed = true;
@@ -138,10 +144,10 @@
138 144 $donor_changed = true;
139 145
140 146 } else {
141 147 $donor = new Give_Donor( $curr_donor_id );
142 - $email = $donor->email;
143 - $names = $donor->name;
148 + $email = $donor->email;
149 + $names = $donor->name;
144 150 }
145 151
146 152 if ( $donor_changed ) {
147 153
@@ -176,12 +182,12 @@
176 182 }
177 183 }
178 184
179 185 // Set new meta values.
180 - $payment->user_id = $donor->user_id;
181 - $payment->email = $donor->email;
182 - $payment->address = $address;
183 - $payment->total = $new_total;
186 + $payment->user_id = $donor->user_id;
187 + $payment->email = $donor->email;
188 + $payment->address = $address;
189 + $payment->total = $new_total;
184 190
185 191 // Check for payment notes.
186 192 if ( ! empty( $data['give-payment-note'] ) ) {
187 193
@@ -253,12 +259,14 @@
253 259 // Re setup payment to update new meta value in object.
254 260 $payment->update_payment_setup( $payment->ID );
255 261
256 262 // Update form id in payment logs.
257 - Give()->async_process->data( array(
258 - 'data' => array( $new_form_id, $payment_id ),
259 - 'hook' => 'give_update_log_form_id',
260 - ) )->dispatch();
263 + Give()->async_process->data(
264 + array(
265 + 'data' => array( $new_form_id, $payment_id ),
266 + 'hook' => 'give_update_log_form_id',
267 + )
268 + )->dispatch();
261 269 }
262 270
263 271 // Update price id if current form is variable form.
264 272 /* @var Give_Donate_Form $form */
@@ -269,14 +277,14 @@
269 277 // Get payment meta data.
270 278 $payment_meta = $payment->get_meta();
271 279
272 280 $price_info = array();
273 - $price_id = '';
281 + $price_id = '';
274 282
275 283 // Get price info
276 - if( 0 <= $data['give-variable-price'] ) {
284 + if ( 0 <= $data['give-variable-price'] ) {
277 285 foreach ( $form->prices as $variable_price ) {
278 - if( $new_total === give_maybe_sanitize_amount( $variable_price['_give_amount'] ) ) {
286 + if ( $new_total === give_maybe_sanitize_amount( $variable_price['_give_amount'] ) ) {
279 287 $price_info = $variable_price;
280 288 break;
281 289 }
282 290 }
@@ -282,17 +290,16 @@
282 290 }
283 291 }
284 292
285 293 // Set price id.
286 - if( ! empty( $price_info ) ) {
294 + if ( ! empty( $price_info ) ) {
287 295 $price_id = $data['give-variable-price'];
288 296
289 - if( $data['give-variable-price'] !== $price_info['_give_id']['level_id'] ) {
297 + if ( $data['give-variable-price'] !== $price_info['_give_id']['level_id'] ) {
290 298 // Set price id to amount match.
291 299 $price_id = $price_info['_give_id']['level_id'];
292 300 }
293 -
294 - } elseif( $form->is_custom_price_mode() ){
301 + } elseif ( $form->is_custom_price_mode() ) {
295 302 $price_id = 'custom';
296 303 }
297 304
298 305 // Update payment meta data.
@@ -305,9 +312,22 @@
305 312 // Re setup payment to update new meta value in object.
306 313 $payment->update_payment_setup( $payment->ID );
307 314 }
308 315
309 - $comment_id = isset( $data['give_comment_id'] ) ? absint( $data['give_comment_id'] ) : 0;
316 + // Update payment campaign.
317 + $donation = Donation::find($payment->ID);
318 +
319 + if ($donation) {
320 + $new_campaign_id = absint($data['give-payment-campaign-select']);
321 + $current_campaign_id = absint($donation->campaignId);
322 +
323 + if ($new_campaign_id && $new_campaign_id !== $current_campaign_id) {
324 + $donation->campaignId = $new_campaign_id;
325 + $donation->save();
326 + }
327 + }
328 +
329 + $comment_id = isset( $data['give_comment_id'] ) ? absint( $data['give_comment_id'] ) : 0;
310 330 $has_anonymous_setting_field = give_is_anonymous_donation_field_enabled( $payment->form_id );
311 331
312 332 if ( $has_anonymous_setting_field ) {
313 333 give_update_meta( $payment->ID, '_give_anonymous_donation', $payment->anonymous );
@@ -315,31 +335,15 @@
315 335
316 336 // Update comment.
317 337 if ( give_is_donor_comment_field_enabled( $payment->form_id ) ) {
318 338 // We are access comment directly from $_POST because comment formatting remove because of give_clean in give_post_actions.
319 - $data['give_comment'] = trim( $_POST['give_comment'] );
339 + $data['give_comment'] = trim($_POST['give_comment']);
340 + $payment->update_meta(DonationMetaKeys::COMMENT, sanitize_textarea_field($data['give_comment']));
341 + }
320 342
321 - if ( empty( $data['give_comment'] ) ) {
322 - // Delete comment if empty
323 - Give_Comment::delete( $comment_id, $payment_id, 'payment' );
324 - $comment_id = 0;
325 -
326 - } else {
327 - $comment_args = array(
328 - 'comment_author_email' => $payment->email
329 - );
330 -
331 - if ( $comment_id ) {
332 - $comment_args['comment_ID'] = $comment_id;
333 - }
334 -
335 - $comment_id = give_insert_donor_donation_comment(
336 - $payment->ID,
337 - $payment->donor_id,
338 - $data['give_comment'],
339 - $comment_args
340 - );
341 - }
343 + // Check if payment status is not completed then update the goal progress for donation form.
344 + if ( 'publish' !== $status ) {
345 + give_update_goal_progress( $form->ID );
342 346 }
343 347
344 348 /**
345 349 * Fires after updating edited donation.
@@ -370,10 +374,10 @@
370 374 if ( wp_verify_nonce( $data['_wpnonce'], 'give_donation_nonce' ) ) {
371 375
372 376 $payment_id = absint( $data['purchase_id'] );
373 377
374 - if ( ! current_user_can( 'edit_give_payments', $payment_id ) ) {
375 - wp_die( __( 'You do not have permission to edit payments.', 'give' ), __( 'Error', 'give' ), array( 'response' => 403 ) );
378 + if ( ! current_user_can( 'delete_give_payments', $payment_id ) ) {
379 + wp_die( __( 'You do not have permission to delete payments.', 'give' ), __( 'Error', 'give' ), array( 'response' => 403 ) );
376 380 }
377 381
378 382 give_delete_donation( $payment_id );
379 383 wp_redirect( admin_url( 'edit.php?post_type=give_forms&page=give-payment-history&give-messages[]=donation-deleted' ) );
@@ -384,18 +388,22 @@
384 388 add_action( 'give_delete_payment', 'give_trigger_donation_delete' );
385 389
386 390 /**
387 391 * AJAX Store Donation Note
392 + *
393 + * @since 2.25.3 Add nonce check.
388 394 */
389 395 function give_ajax_store_payment_note() {
390 - $payment_id = absint( $_POST['payment_id'] );
391 - $note = wp_kses( $_POST['note'], array() );
392 - $note_type = give_clean( $_POST['type'] );
396 + check_ajax_referer('give_insert_payment_note');
393 397
394 - if ( ! current_user_can( 'edit_give_payments', $payment_id ) ) {
395 - wp_die( __( 'You do not have permission to edit payments.', 'give' ), __( 'Error', 'give' ), array( 'response' => 403 ) );
396 - }
398 + $payment_id = absint($_POST['payment_id']);
399 + $note = wp_kses($_POST['note'], []);
400 + $note_type = give_clean($_POST['type']);
397 401
402 + if ( ! current_user_can('edit_give_payments', $payment_id)) {
403 + wp_die(__('You do not have permission to edit payments.', 'give'), __('Error', 'give'), ['response' => 403]);
404 + }
405 +
398 406 if ( empty( $payment_id ) || empty( $note ) ) {
399 407 die( '-1' );
400 408 }
401 409
@@ -412,13 +420,13 @@
412 420 )
413 421 );
414 422 }
415 423
416 - if( $note_id && $note_type ) {
424 + if ( $note_id && $note_type ) {
417 425
418 - if( ! give_has_upgrade_completed('v230_move_donor_note' ) ) {
426 + if ( ! give_has_upgrade_completed( 'v230_move_donor_note' ) ) {
419 427 add_comment_meta( $note_id, 'note_type', $note_type, true );
420 - } else{
428 + } else {
421 429 Give()->comment->db_meta->update_meta( $note_id, 'note_type', $note_type );
422 430 }
423 431
424 432 /**
@@ -464,13 +472,15 @@
464 472
465 473 /**
466 474 * Delete a payment note deletion with ajax
467 475 *
476 + * @since 2.25.3 Add nonce check.
468 477 * @since 1.0
469 478 *
470 479 * @return void
471 480 */
472 481 function give_ajax_delete_payment_note() {
482 + check_ajax_referer('give_delete_payment_note');
473 483
474 484 if ( ! current_user_can( 'edit_give_payments', $_POST['payment_id'] ) ) {
475 485 wp_die( __( 'You do not have permission to edit payments.', 'give' ), __( 'Error', 'give' ), array( 'response' => 403 ) );
476 486 }