PluginProbe
GiveWP – Donation Plugin and Fundraising Platform / 4.18.0
GiveWP – Donation Plugin and Fundraising Platform v4.18.0
4.18.0 4.17.0 4.16.9 4.16.8.1 4.16.8 4.16.7.2 4.16.7.1 4.16.7 4.16.6.1 4.16.6 4.16.5.1 4.16.5 4.16.4 4.16.3 4.16.2 4.16.1 4.16.0 4.15.5 4.15.4 4.15.3 4.15.2 4.15.1 4.15.0 2.3.0 2.3.1 All 257 releases
← All changes | includes/admin/payments/actions.php +73 -62 2.3.1 → 4.18.0 View file →
@@ -9,10 +9,13 @@
9 9 * @since 1.0
10 10 */
11 11
12 12 // Exit if accessed directly.
13 -if ( ! defined( 'ABSPATH' ) ) {
14 - exit;
13 +use Give\Donations\Models\Donation;
14 +use Give\Donations\ValueObjects\DonationMetaKeys;
15 +
16 +if (!defined('ABSPATH')) {
17 + exit;
15 18 }
16 19
17 20 /**
18 21 *
@@ -17,12 +20,14 @@
17 20 /**
18 21 *
19 22 * Process the payment details edit
20 23 *
24 + * @since 2.27.0 Change to save comment to donations meta table
21 25 * @since 1.0
26 + *
22 27 * @access private
23 28 *
24 - * @param array $data Donation data.
29 + * @param array $data Donation data.
25 30 *
26 31 * @return void
27 32 */
28 33 function give_update_payment_details( $data ) {
@@ -61,9 +66,9 @@
61 66 $address = give_clean( $data['give-payment-address'][0] );
62 67
63 68 $curr_total = $payment->total;
64 69 $new_total = give_maybe_sanitize_amount( ( ! empty( $data['give-payment-total'] ) ? $data['give-payment-total'] : 0 ) );
65 - $date = give_get_formatted_date(sanitize_text_field( $data['give-payment-date'] ), 'Y-m-d' ) . ' ' . $hour . ':' . $minute . ':00';
70 + $date = date( 'Y-m-d', strtotime( give_clean( $data['give-payment-date'] ) ) ) . ' ' . $hour . ':' . $minute . ':00';
66 71
67 72 $curr_donor_id = sanitize_text_field( $data['give-current-donor'] );
68 73 $new_donor_id = sanitize_text_field( $data['donor-id'] );
69 74
@@ -76,14 +81,13 @@
76 81 * @param int $payment_id The ID of the payment.
77 82 */
78 83 do_action( 'give_update_edited_donation', $payment_id );
79 84
80 - $payment->date = $date;
85 + $payment->date = $date;
81 86 $payment->anonymous = isset( $data['give_anonymous_donation'] ) ? absint( $data['give_anonymous_donation'] ) : 0;
82 87
88 + $updated = $payment->save();
83 89
84 - $updated = $payment->save();
85 -
86 90 if ( 0 === $updated ) {
87 91 wp_die( __( 'Error Updating Donation.', 'give' ), __( 'Error', 'give' ), array( 'response' => 400 ) );
88 92 }
89 93
@@ -101,10 +105,13 @@
101 105 }
102 106
103 107 $donor = new Give_Donor( $email );
104 108 if ( empty( $donor->id ) ) {
105 - $donor_data = array( 'name' => $names, 'email' => $email );
106 - $user_id = email_exists( $email );
109 + $donor_data = array(
110 + 'name' => $names,
111 + 'email' => $email,
112 + );
113 + $user_id = email_exists( $email );
107 114 if ( false !== $user_id ) {
108 115 $donor_data['user_id'] = $user_id;
109 116 }
110 117
@@ -128,10 +135,10 @@
128 135
129 136 } elseif ( $curr_donor_id !== $new_donor_id ) {
130 137
131 138 $donor = new Give_Donor( $new_donor_id );
132 - $email = $donor->email;
133 - $names = $donor->name;
139 + $email = $donor->email;
140 + $names = $donor->name;
134 141
135 142 $previous_donor = new Give_Donor( $curr_donor_id );
136 143
137 144 $donor_changed = true;
@@ -137,10 +144,10 @@
137 144 $donor_changed = true;
138 145
139 146 } else {
140 147 $donor = new Give_Donor( $curr_donor_id );
141 - $email = $donor->email;
142 - $names = $donor->name;
148 + $email = $donor->email;
149 + $names = $donor->name;
143 150 }
144 151
145 152 if ( $donor_changed ) {
146 153
@@ -175,12 +182,12 @@
175 182 }
176 183 }
177 184
178 185 // Set new meta values.
179 - $payment->user_id = $donor->user_id;
180 - $payment->email = $donor->email;
181 - $payment->address = $address;
182 - $payment->total = $new_total;
186 + $payment->user_id = $donor->user_id;
187 + $payment->email = $donor->email;
188 + $payment->address = $address;
189 + $payment->total = $new_total;
183 190
184 191 // Check for payment notes.
185 192 if ( ! empty( $data['give-payment-note'] ) ) {
186 193
@@ -252,12 +259,14 @@
252 259 // Re setup payment to update new meta value in object.
253 260 $payment->update_payment_setup( $payment->ID );
254 261
255 262 // Update form id in payment logs.
256 - Give()->async_process->data( array(
257 - 'data' => array( $new_form_id, $payment_id ),
258 - 'hook' => 'give_update_log_form_id',
259 - ) )->dispatch();
263 + Give()->async_process->data(
264 + array(
265 + 'data' => array( $new_form_id, $payment_id ),
266 + 'hook' => 'give_update_log_form_id',
267 + )
268 + )->dispatch();
260 269 }
261 270
262 271 // Update price id if current form is variable form.
263 272 /* @var Give_Donate_Form $form */
@@ -268,14 +277,14 @@
268 277 // Get payment meta data.
269 278 $payment_meta = $payment->get_meta();
270 279
271 280 $price_info = array();
272 - $price_id = '';
281 + $price_id = '';
273 282
274 283 // Get price info
275 - if( 0 <= $data['give-variable-price'] ) {
284 + if ( 0 <= $data['give-variable-price'] ) {
276 285 foreach ( $form->prices as $variable_price ) {
277 - if( $new_total === give_maybe_sanitize_amount( $variable_price['_give_amount'] ) ) {
286 + if ( $new_total === give_maybe_sanitize_amount( $variable_price['_give_amount'] ) ) {
278 287 $price_info = $variable_price;
279 288 break;
280 289 }
281 290 }
@@ -281,17 +290,16 @@
281 290 }
282 291 }
283 292
284 293 // Set price id.
285 - if( ! empty( $price_info ) ) {
294 + if ( ! empty( $price_info ) ) {
286 295 $price_id = $data['give-variable-price'];
287 296
288 - if( $data['give-variable-price'] !== $price_info['_give_id']['level_id'] ) {
297 + if ( $data['give-variable-price'] !== $price_info['_give_id']['level_id'] ) {
289 298 // Set price id to amount match.
290 299 $price_id = $price_info['_give_id']['level_id'];
291 300 }
292 -
293 - } elseif( $form->is_custom_price_mode() ){
301 + } elseif ( $form->is_custom_price_mode() ) {
294 302 $price_id = 'custom';
295 303 }
296 304
297 305 // Update payment meta data.
@@ -304,9 +312,22 @@
304 312 // Re setup payment to update new meta value in object.
305 313 $payment->update_payment_setup( $payment->ID );
306 314 }
307 315
308 - $comment_id = isset( $data['give_comment_id'] ) ? absint( $data['give_comment_id'] ) : 0;
316 + // Update payment campaign.
317 + $donation = Donation::find($payment->ID);
318 +
319 + if ($donation) {
320 + $new_campaign_id = absint($data['give-payment-campaign-select']);
321 + $current_campaign_id = absint($donation->campaignId);
322 +
323 + if ($new_campaign_id && $new_campaign_id !== $current_campaign_id) {
324 + $donation->campaignId = $new_campaign_id;
325 + $donation->save();
326 + }
327 + }
328 +
329 + $comment_id = isset( $data['give_comment_id'] ) ? absint( $data['give_comment_id'] ) : 0;
309 330 $has_anonymous_setting_field = give_is_anonymous_donation_field_enabled( $payment->form_id );
310 331
311 332 if ( $has_anonymous_setting_field ) {
312 333 give_update_meta( $payment->ID, '_give_anonymous_donation', $payment->anonymous );
@@ -314,31 +335,15 @@
314 335
315 336 // Update comment.
316 337 if ( give_is_donor_comment_field_enabled( $payment->form_id ) ) {
317 338 // We are access comment directly from $_POST because comment formatting remove because of give_clean in give_post_actions.
318 - $data['give_comment'] = trim( $_POST['give_comment'] );
339 + $data['give_comment'] = trim($_POST['give_comment']);
340 + $payment->update_meta(DonationMetaKeys::COMMENT, sanitize_textarea_field($data['give_comment']));
341 + }
319 342
320 - if ( empty( $data['give_comment'] ) ) {
321 - // Delete comment if empty
322 - Give_Comment::delete( $comment_id, $payment_id, 'payment' );
323 - $comment_id = 0;
324 -
325 - } else {
326 - $comment_args = array(
327 - 'comment_author_email' => $payment->email
328 - );
329 -
330 - if ( $comment_id ) {
331 - $comment_args['comment_ID'] = $comment_id;
332 - }
333 -
334 - $comment_id = give_insert_donor_donation_comment(
335 - $payment->ID,
336 - $payment->donor_id,
337 - $data['give_comment'],
338 - $comment_args
339 - );
340 - }
343 + // Check if payment status is not completed then update the goal progress for donation form.
344 + if ( 'publish' !== $status ) {
345 + give_update_goal_progress( $form->ID );
341 346 }
342 347
343 348 /**
344 349 * Fires after updating edited donation.
@@ -369,10 +374,10 @@
369 374 if ( wp_verify_nonce( $data['_wpnonce'], 'give_donation_nonce' ) ) {
370 375
371 376 $payment_id = absint( $data['purchase_id'] );
372 377
373 - if ( ! current_user_can( 'edit_give_payments', $payment_id ) ) {
374 - wp_die( __( 'You do not have permission to edit payments.', 'give' ), __( 'Error', 'give' ), array( 'response' => 403 ) );
378 + if ( ! current_user_can( 'delete_give_payments', $payment_id ) ) {
379 + wp_die( __( 'You do not have permission to delete payments.', 'give' ), __( 'Error', 'give' ), array( 'response' => 403 ) );
375 380 }
376 381
377 382 give_delete_donation( $payment_id );
378 383 wp_redirect( admin_url( 'edit.php?post_type=give_forms&page=give-payment-history&give-messages[]=donation-deleted' ) );
@@ -383,18 +388,22 @@
383 388 add_action( 'give_delete_payment', 'give_trigger_donation_delete' );
384 389
385 390 /**
386 391 * AJAX Store Donation Note
392 + *
393 + * @since 2.25.3 Add nonce check.
387 394 */
388 395 function give_ajax_store_payment_note() {
389 - $payment_id = absint( $_POST['payment_id'] );
390 - $note = wp_kses( $_POST['note'], array() );
391 - $note_type = give_clean( $_POST['type'] );
396 + check_ajax_referer('give_insert_payment_note');
392 397
393 - if ( ! current_user_can( 'edit_give_payments', $payment_id ) ) {
394 - wp_die( __( 'You do not have permission to edit payments.', 'give' ), __( 'Error', 'give' ), array( 'response' => 403 ) );
395 - }
398 + $payment_id = absint($_POST['payment_id']);
399 + $note = wp_kses($_POST['note'], []);
400 + $note_type = give_clean($_POST['type']);
396 401
402 + if ( ! current_user_can('edit_give_payments', $payment_id)) {
403 + wp_die(__('You do not have permission to edit payments.', 'give'), __('Error', 'give'), ['response' => 403]);
404 + }
405 +
397 406 if ( empty( $payment_id ) || empty( $note ) ) {
398 407 die( '-1' );
399 408 }
400 409
@@ -411,13 +420,13 @@
411 420 )
412 421 );
413 422 }
414 423
415 - if( $note_id && $note_type ) {
424 + if ( $note_id && $note_type ) {
416 425
417 - if( ! give_has_upgrade_completed('v230_move_donor_note' ) ) {
426 + if ( ! give_has_upgrade_completed( 'v230_move_donor_note' ) ) {
418 427 add_comment_meta( $note_id, 'note_type', $note_type, true );
419 - } else{
428 + } else {
420 429 Give()->comment->db_meta->update_meta( $note_id, 'note_type', $note_type );
421 430 }
422 431
423 432 /**
@@ -463,13 +472,15 @@
463 472
464 473 /**
465 474 * Delete a payment note deletion with ajax
466 475 *
476 + * @since 2.25.3 Add nonce check.
467 477 * @since 1.0
468 478 *
469 479 * @return void
470 480 */
471 481 function give_ajax_delete_payment_note() {
482 + check_ajax_referer('give_delete_payment_note');
472 483
473 484 if ( ! current_user_can( 'edit_give_payments', $_POST['payment_id'] ) ) {
474 485 wp_die( __( 'You do not have permission to edit payments.', 'give' ), __( 'Error', 'give' ), array( 'response' => 403 ) );
475 486 }