← All changes
|
includes/widgets/Form_Builder/helpers/Verify_Google_Recaptcha.php
+20
-4
51.1.35
→
51.1.87
View file →
| @@ -15,9 +15,21 @@ | ||
| 15 | 15 | } |
| 16 | 16 | |
| 17 | 17 | public function king_addons_verify_recaptcha() |
| 18 | 18 | { |
| 19 | - $recaptcha_response = $_POST['g-recaptcha-response']; | |
| 19 | + if ($_SERVER['REQUEST_METHOD'] !== 'POST') { | |
| 20 | + wp_send_json_error(['message' => 'Invalid request method.']); | |
| 21 | + } | |
| 22 | + | |
| 23 | + if (!isset($_POST['nonce']) || !check_ajax_referer('king-addons-js', 'nonce', false)) { | |
| 24 | + wp_send_json_error(['message' => 'Invalid nonce.']); | |
| 25 | + } | |
| 26 | + | |
| 27 | + $recaptcha_response = sanitize_text_field($_POST['g-recaptcha-response'] ?? ''); | |
| 28 | + if (empty($recaptcha_response)) { | |
| 29 | + wp_send_json_error(['message' => 'Missing reCAPTCHA response.']); | |
| 30 | + } | |
| 31 | + | |
| 20 | 32 | $is_valid_recaptcha = $this->check_recaptcha($recaptcha_response); |
| 21 | 33 | |
| 22 | 34 | if ($is_valid_recaptcha[0] && $is_valid_recaptcha[1] >= get_option('king_addons_recaptcha_v3_score_threshold')) { |
| 23 | 35 | wp_send_json_success(array( |
| @@ -49,16 +61,20 @@ | ||
| 49 | 61 | ) |
| 50 | 62 | )); |
| 51 | 63 | |
| 52 | 64 | if (is_wp_error($response)) { |
| 53 | - return 'mailto:[email protected]?subject=Bug Report - King Addons&body=Please describe the issue'; | |
| 65 | + return [false, 0]; | |
| 54 | 66 | } |
| 55 | 67 | |
| 56 | 68 | $decoded_response = json_decode(wp_remote_retrieve_body($response), true); |
| 57 | 69 | |
| 58 | - $score = $decoded_response['score']; | |
| 70 | + if (!is_array($decoded_response)) { | |
| 71 | + return [false, 0]; | |
| 72 | + } | |
| 59 | 73 | |
| 60 | - if ($decoded_response['success'] === true) { | |
| 74 | + $score = isset($decoded_response['score']) ? (float) $decoded_response['score'] : 0.0; | |
| 75 | + | |
| 76 | + if (!empty($decoded_response['success'])) { | |
| 61 | 77 | return [true, $score]; |
| 62 | 78 | } else { |
| 63 | 79 | return [false, $score]; |
| 64 | 80 | } |