PluginProbe
GiveWP – Donation Plugin and Fundraising Platform / 4.18.0
GiveWP – Donation Plugin and Fundraising Platform v4.18.0
4.18.0 4.17.0 4.16.9 4.16.8.1 4.16.8 4.16.7.2 4.16.7.1 4.16.7 4.16.6.1 4.16.6 4.16.5.1 4.16.5 4.16.4 4.16.3 4.16.2 4.16.1 4.16.0 4.15.5 4.15.4 4.15.3 4.15.2 4.15.1 4.15.0 2.3.0 2.3.1 All 257 releases
← All changes | src/DonationForms/DataTransferObjects/DonateFormRouteData.php +31 -3 4.15.5 → 4.18.0 View file →
@@ -43,8 +43,9 @@
43 43
44 44 /**
45 45 * Convert data from request into DTO
46 46 *
47 + * @since 4.17.0 Validate the client-provided origin URL before it is used in redirects.
47 48 * @since 3.0.0
48 49 */
49 50 public static function fromRequest(array $requestData): self
50 51 {
@@ -50,9 +51,9 @@
50 51 {
51 52 $self = new self();
52 53 $self->formId = (int)$requestData['formId'];
53 54 $self->gatewayId = $requestData['gatewayId'];
54 - $self->originUrl = $requestData['originUrl'];
55 + $self->originUrl = self::validateOriginUrl($requestData['originUrl'] ?? '');
55 56 $self->isEmbed = filter_var($requestData['isEmbed'], FILTER_VALIDATE_BOOLEAN);
56 57 $self->embedId = $self->isEmbed ? $requestData['embedId'] : null;
57 58 $self->requestData = $requestData;
58 59
@@ -90,13 +91,15 @@
90 91
91 92 $validatedValues = $validator->validated();
92 93
93 94 /**
95 + * @since 4.16.0 added $isFinalSubmission (true here: the final donation submission)
94 96 * @since 3.22.0
95 97 *
96 - * @param array $data validated values in key value pairs
98 + * @param array $data validated values in key value pairs
99 + * @param bool $isFinalSubmission whether this is the final donation submission
97 100 */
98 - do_action('givewp_donation_form_fields_validated', $validatedValues);
101 + do_action('givewp_donation_form_fields_validated', $validatedValues, true);
99 102
100 103 foreach ($validatedValues as $fieldId => $value) {
101 104 $validData->{$fieldId} = $value;
102 105 }
@@ -115,8 +118,33 @@
115 118 */
116 119 public function getRequestData(): array
117 120 {
118 121 return $this->requestData;
122 + }
123 +
124 + /**
125 + * The origin URL is client-provided and later used as a redirect target,
126 + * so anything that is not a valid http(s) URL falls back to the site URL.
127 + * Intentionally not wp_http_validate_url(), which rejects localhost hosts
128 + * that are valid embed origins during development.
129 + *
130 + * @since 4.17.0
131 + *
132 + * @param mixed $originUrl
133 + */
134 + private static function validateOriginUrl($originUrl): string
135 + {
136 + if (!is_string($originUrl) || $originUrl === '') {
137 + return '';
138 + }
139 +
140 + $scheme = wp_parse_url($originUrl, PHP_URL_SCHEME);
141 +
142 + if (in_array($scheme, ['http', 'https'], true) && filter_var($originUrl, FILTER_VALIDATE_URL)) {
143 + return $originUrl;
144 + }
145 +
146 + return home_url();
119 147 }
120 148
121 149 /**
122 150 * This loops over an array of errors in the specific FieldAPI format,