PluginProbe ʕ •ᴥ•ʔ
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments / 3.0.0-beta2
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments v3.0.0-beta2
4.7.0 4.6.6 4.6.5 4.6.4 4.6.3 4.6.2 4.6.1 4.6.0 4.5.1 4.5.0 4.4.2 4.4.1 4.4.0 4.3.3 4.3.2 4.3.1 4.3.0 4.2.3 4.2.2 4.2.1 1.0.3 1.0.4 1.0.5 1.0.6 1.1.0 1.1.1 1.1.10 1.1.11 1.1.12 1.1.13 1.1.14 1.1.15 1.1.16 1.1.17 1.1.18 1.1.19 1.1.2 1.1.3 1.1.4 1.1.5 1.1.6 1.1.7 1.1.8 1.1.9 1.10.0 1.10.1 1.10.2 1.10.3 1.10.4 1.11.0 1.11.1 1.11.2 1.2.0 1.2.1 1.2.2 1.2.3 1.2.4 1.2.5 1.3.0 1.3.1 1.3.2 1.3.3 1.3.4 1.4.0 1.4.1 1.4.2 1.5.0 1.5.1 1.5.2 1.5.3 1.5.4 1.5.5 1.5.6 1.5.7 1.5.8 1.6.0 1.6.1 1.6.2 1.6.3 1.6.4 1.7.0 1.7.1 1.7.2 1.8.0 1.8.1 1.8.2 1.8.3 1.8.4 1.8.5 1.9.0 1.9.1 1.9.2 1.9.3 1.9.4 1.9.5 2.0.0 2.0.1 2.1.0 2.1.1 2.1.2 2.1.3 2.1.4 2.10.0 2.10.1 2.11.0 2.11.1 2.11.2 2.11.3 2.11.4 2.12.0 2.13.0 2.14.0 2.14.1 2.15.0 2.15.1 2.16.0 2.16.1 2.16.2 2.16.3 2.17.0 2.17.1 2.17.2 2.18.0 2.19.0 2.19.2 2.19.3 2.19.4 2.2.0 2.2.1 2.20.0 2.20.1 2.20.2 2.20.3 2.20.4 2.20.5 2.20.6 2.21.0 2.22.0 2.22.1 2.23.0 2.24.0 2.25.0 2.25.1 2.25.2 2.26.0 2.27.0 2.27.1 2.28.0 2.29.0 2.29.1 2.29.2 2.29.3 2.29.4 2.3.0 2.3.1 2.30.0 2.31.0 2.31.1 2.31.2 2.31.3 2.4.0 2.4.1 2.4.2 2.4.3 2.4.4 2.40.0 2.40.1 2.5.0 2.5.1 2.5.2 2.6.0 2.6.1 2.6.2 2.7.0 2.7.1 2.7.2 2.7.3 2.7.4 2.7.5 2.8.0 2.8.1 2.8.2 2.8.3 2.8.4 2.9.0 3.0.0 3.0.0-RC1 3.0.0-RC2 3.0.0-beta1 3.0.0-beta2 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 3.1.0 3.1.1 3.1.2 3.1.3 3.1.4 3.1.5 3.1.6 3.10.0 3.10.1 3.11.0 3.12.0 3.13.0 3.13.1 3.13.2 3.13.3 3.13.4 3.14.0 3.15.0 3.15.1 3.15.2 3.15.3 3.15.4 3.15.5 3.16.0 3.16.1 3.16.2 3.16.3 3.16.4 3.16.5 3.16.6 3.16.7 3.16.8 3.17.0 3.17.1 3.17.2 3.17.3 3.17.4 3.17.5 3.17.6 3.18.0 3.19.0 3.19.1 3.19.2 3.2.0 3.2.1 3.2.2 3.20.0 3.20.1 3.3.0 3.3.1 3.4.0 3.4.1 3.4.2 3.4.3 3.5.0 3.5.1 3.5.2 3.5.3 3.6.0 3.6.1 3.6.2 3.7.0 3.7.1 3.7.2 3.7.3 3.8.0 3.8.1 3.8.2 3.8.3 3.8.4 3.8.5 3.9.0 4.0.0 4.0.1 4.0.2 4.0.3 trunk 4.1.0 0.2.19.1 4.1.1 1.0.0 4.2.0 1.0.1 1.0.2
surecart / app / src / Rest / CheckoutRestServiceProvider.php
surecart / app / src / Rest Last commit date
AbandonedCheckoutProtocolRestServiceProvider.php 3 years ago AbandonedCheckoutRestServiceProvider.php 2 years ago AccountRestServiceProvider.php 4 years ago ActivationRestServiceProvider.php 2 years ago AffiliationProductsRestServiceProvider.php 2 years ago AffiliationProtocolRestServiceProvider.php 2 years ago AffiliationRequestsRestServiceProvider.php 2 years ago AffiliationsRestServiceProvider.php 2 years ago BalanceTransactionRestServiceProvider.php 4 years ago BlockPatternsRestServiceProvider.php 4 years ago BrandRestServiceProvider.php 4 years ago BumpRestServiceProvider.php 2 years ago CancellationActRestServiceProvider.php 3 years ago CancellationReasonRestServiceProvider.php 3 years ago ChargesRestServiceProvider.php 4 years ago CheckEmailRestServiceProvider.php 3 years ago CheckoutRestServiceProvider.php 2 years ago ClicksRestServiceProvider.php 2 years ago CouponRestServiceProvider.php 4 years ago CustomerNotificationProtocolRestServiceProvider.php 4 years ago CustomerRestServiceProvider.php 3 years ago DownloadRestServiceProvider.php 4 years ago DraftCheckoutRestServiceProvider.php 3 years ago ExportsRestServiceProvider.php 2 years ago FulfillmentRestServiceProvider.php 3 years ago IncomingWebhooksRestServiceProvider.php 2 years ago IntegrationProvidersRestServiceProvider.php 4 years ago IntegrationsRestServiceProvider.php 4 years ago InvoicesRestServiceProvider.php 4 years ago LicenseRestServiceProvider.php 2 years ago LineItemsRestServiceProvider.php 2 years ago LoginRestServiceProvider.php 4 years ago ManualPaymentMethodsRestServiceProvider.php 3 years ago MediaRestServiceProvider.php 1 year ago OrderProtocolRestServiceProvider.php 4 years ago OrderRestServiceProvider.php 3 years ago PaymentIntentsRestServiceProvider.php 4 years ago PaymentMethodsRestServiceProvider.php 2 years ago PayoutGroupsRestServiceProvider.php 2 years ago PayoutsRestServiceProvider.php 2 years ago PeriodRestServiceProvider.php 3 years ago PortalProtocolRestServiceProvider.php 4 years ago PriceRestServiceProvider.php 4 years ago ProcessorRestServiceProvider.php 3 years ago ProductCollectionsRestServiceProvider.php 2 years ago ProductGroupsRestServiceProvider.php 4 years ago ProductMediaRestServiceProvider.php 1 year ago ProductsRestServiceProvider.php 1 year ago PromotionRestServiceProvider.php 4 years ago ProvisionalAccountRestServiceProvider.php 3 years ago PurchasesRestServiceProvider.php 4 years ago ReferralItemsRestServiceProvider.php 2 years ago ReferralsRestServiceProvider.php 2 years ago RefundsRestServiceProvider.php 4 years ago RegisteredWebhookRestServiceProvider.php 2 years ago RestServiceInterface.php 4 years ago RestServiceProvider.php 1 year ago ReturnItemsRestServiceProvider.php 2 years ago ReturnReasonsRestServiceProvider.php 2 years ago ReturnRequestsRestServiceProvider.php 2 years ago SettingsRestServiceProvider.php 4 years ago ShippingMethodRestServiceProvider.php 3 years ago ShippingProfileRestServiceProvider.php 3 years ago ShippingProtocolRestServiceProvider.php 3 years ago ShippingRateRestServiceProvider.php 3 years ago ShippingZoneRestServiceProvider.php 3 years ago SiteHealthRestServiceProvider.php 2 years ago StatisticRestServiceProvider.php 3 years ago SubscriptionProtocolRestServiceProvider.php 4 years ago SubscriptionRestServiceProvider.php 2 years ago TaxOverrideRestServiceProvider.php 2 years ago TaxProtocolRestServiceProvider.php 4 years ago TaxRegistrationRestServiceProvider.php 4 years ago TaxZoneRestServiceProvider.php 4 years ago UploadsRestServiceProvider.php 4 years ago UpsellFunnelRestServiceProvider.php 2 years ago UpsellRestServiceProvider.php 2 years ago VariantOptionsRestServiceProvider.php 2 years ago VariantValuesRestServiceProvider.php 2 years ago VariantsRestServiceProvider.php 2 years ago VerificationCodeRestServiceProvider.php 3 years ago WebhooksRestServiceProvider.php 4 years ago
CheckoutRestServiceProvider.php
334 lines
1 <?php
2
3 namespace SureCart\Rest;
4
5 use SureCart\Rest\RestServiceInterface;
6 use SureCart\Controllers\Rest\CheckoutsController;
7 use SureCart\Form\FormValidationService;
8 use SureCart\Models\User;
9
10 /**
11 * Service provider for Price Rest Requests
12 */
13 class CheckoutRestServiceProvider extends RestServiceProvider implements RestServiceInterface {
14 /**
15 * Endpoint.
16 *
17 * @var string
18 */
19 protected $endpoint = 'checkouts';
20
21 /**
22 * Rest Controller
23 *
24 * @var string
25 */
26 protected $controller = CheckoutsController::class;
27
28 /**
29 * Methods allowed for the model.
30 *
31 * @var array
32 */
33 protected $methods = [ 'index', 'create', 'find', 'edit' ];
34
35 /**
36 * Register Additional REST Routes
37 *
38 * @return void
39 */
40 public function registerRoutes() {
41 register_rest_route(
42 "$this->name/v$this->version",
43 $this->endpoint . '/(?P<id>\S+)/finalize/',
44 [
45 [
46 'methods' => \WP_REST_Server::EDITABLE,
47 'callback' => $this->callback( $this->controller, 'finalize' ),
48 'permission_callback' => [ $this, 'finalize_permissions_check' ],
49 ],
50 // Register our schema callback.
51 'schema' => [ $this, 'get_item_schema' ],
52 ]
53 );
54 register_rest_route(
55 "$this->name/v$this->version",
56 $this->endpoint . '/(?P<id>\S+)/confirm/',
57 [
58 [
59 'methods' => \WP_REST_Server::EDITABLE,
60 'callback' => $this->callback( $this->controller, 'confirm' ),
61 'permission_callback' => [ $this, 'confirm_permissions_check' ],
62 ],
63 // Register our schema callback.
64 'schema' => [ $this, 'get_item_schema' ],
65 ]
66 );
67 register_rest_route(
68 "$this->name/v$this->version",
69 $this->endpoint . '/(?P<id>\S+)/manually_pay/',
70 [
71 [
72 'methods' => \WP_REST_Server::EDITABLE,
73 'callback' => $this->callback( $this->controller, 'manuallyPay' ),
74 'permission_callback' => [ $this, 'manually_pay_permissions_check' ],
75 ],
76 // Register our schema callback.
77 'schema' => [ $this, 'get_item_schema' ],
78 ]
79 );
80 register_rest_route(
81 "$this->name/v$this->version",
82 $this->endpoint . '/(?P<id>\S+)/cancel/',
83 [
84 [
85 'methods' => \WP_REST_Server::EDITABLE,
86 'callback' => $this->callback( $this->controller, 'cancel' ),
87 'permission_callback' => [ $this, 'cancel_item_permissions_check' ],
88 ],
89 // Register our schema callback.
90 'schema' => [ $this, 'get_item_schema' ],
91 ]
92 );
93 register_rest_route(
94 "$this->name/v$this->version",
95 $this->endpoint . '/(?P<id>\S+)/offer_bump/(?P<bump_id>\S+)',
96 [
97 [
98 'methods' => \WP_REST_Server::EDITABLE,
99 'callback' => $this->callback( $this->controller, 'offerBump' ),
100 'permission_callback' => [ $this, 'update_item_permissions_check' ],
101 ],
102 // Register our schema callback.
103 'schema' => [ $this, 'get_item_schema' ],
104 ]
105 );
106 register_rest_route(
107 "$this->name/v$this->version",
108 $this->endpoint . '/(?P<id>\S+)/offer_upsell/(?P<upsell_id>\S+)',
109 [
110 [
111 'methods' => \WP_REST_Server::EDITABLE,
112 'callback' => $this->callback( $this->controller, 'offerUpsell' ),
113 'permission_callback' => [ $this, 'update_item_permissions_check' ],
114 ],
115 // Register our schema callback.
116 'schema' => [ $this, 'get_item_schema' ],
117 ]
118 );
119 register_rest_route(
120 "$this->name/v$this->version",
121 $this->endpoint . '/(?P<id>\S+)/decline_upsell/(?P<upsell_id>\S+)',
122 [
123 [
124 'methods' => \WP_REST_Server::EDITABLE,
125 'callback' => $this->callback( $this->controller, 'declineUpsell' ),
126 'permission_callback' => [ $this, 'update_item_permissions_check' ],
127 ],
128 // Register our schema callback.
129 'schema' => [ $this, 'get_item_schema' ],
130 ]
131 );
132 }
133
134 /**
135 * Get our sample schema for a post.
136 *
137 * @return array The sample schema for a post
138 */
139 public function get_item_schema() {
140 if ( $this->schema ) {
141 // Since WordPress 5.3, the schema can be cached in the $schema property.
142 return $this->schema;
143 }
144
145 $this->schema = [
146 // This tells the spec of JSON Schema we are using which is draft 4.
147 '$schema' => 'http://json-schema.org/draft-04/schema#',
148 // The title property marks the identity of the resource.
149 'title' => $this->endpoint,
150 'type' => 'object',
151 // In JSON Schema you can specify object properties in the properties attribute.
152 'properties' => [
153 'id' => [
154 'description' => esc_html__( 'Unique identifier for the object.', 'surecart' ),
155 'type' => 'string',
156 'context' => [ 'view', 'edit', 'embed' ],
157 'readonly' => true,
158 ],
159 'currency' => [
160 'description' => esc_html__( 'The currency for the session.', 'surecart' ),
161 'type' => 'string',
162 ],
163 'metadata' => [
164 'description' => esc_html__( 'Metadata for the order.', 'surecart' ),
165 'type' => 'object',
166 // 'context' => [ 'edit' ],
167 ],
168 'customer_id' => [
169 'description' => esc_html__( 'The customer id for the order.', 'surecart' ),
170 'type' => 'string',
171 'context' => [ 'edit' ],
172 ],
173 'customer' => [
174 'description' => esc_html__( 'The customer for the session.', 'surecart' ),
175 'type' => 'object',
176 'context' => [ 'edit' ],
177 ],
178 'line_items' => [
179 'description' => esc_html__( 'The line items for the session.', 'surecart' ),
180 'type' => 'object',
181 ],
182 'discount' => [
183 'description' => esc_html__( 'The discount for the session.', 'surecart' ),
184 'type' => 'object',
185 ],
186 ],
187 ];
188
189 return $this->schema;
190 }
191
192 /**
193 * Finalizing an order requires some server side form validation.
194 *
195 * @param \WP_REST_Request $request Full details about the request.
196 * @return true|\WP_Error True if the request has access to create items, WP_Error object otherwise.
197 */
198 public function finalize_permissions_check( \WP_REST_Request $request ) {
199 // form id or a product id is required.
200 if ( empty( $request['form_id'] ) && empty( $request['product_id'] ) ) {
201 return new \WP_Error( 'form_id_required', esc_html__( 'Form ID is required.', 'surecart' ), [ 'status' => 400 ] );
202 }
203
204 // get form.
205 if ( ! empty( $request['form_id'] ) ) {
206 $form = get_post( $request['form_id'] );
207 if ( ! $form || 'sc_form' !== $form->post_type ) {
208 return new \WP_Error( 'form_id_invalid', esc_html__( 'Form ID is invalid.', 'surecart' ), [ 'status' => 400 ] );
209 }
210 // validate form input based on saved form content.
211 $validator = new FormValidationService( $form->post_content, $request->get_body_params() );
212 $validated = $validator->validate();
213 if ( is_wp_error( $validated ) ) {
214 return $validated;
215 }
216 }
217
218 return true;
219 }
220
221 /**
222 * Confirming an order was paid for.
223 *
224 * @param \WP_REST_Request $request Full details about the request.
225 * @return true|\WP_Error True if the request has access to create items, WP_Error object otherwise.
226 */
227 public function confirm_permissions_check( \WP_REST_Request $request ) {
228 return $this->get_item_permissions_check( $request );
229 }
230
231 /**
232 * Filters a response based on the context defined in the schema.
233 *
234 * @since 4.7.0
235 *
236 * @param array|\WP_REST_Response $data Response data to filter.
237 * @param string $context Context defined in the schema.
238 * @return array Filtered response.
239 */
240 public function filter_response_by_context( $data, $context ) {
241 $schema = $this->get_item_schema();
242
243 // if the user can edit customers, show the edit context.
244 if ( current_user_can( 'edit_sc_customers' ) ) {
245 return rest_filter_response_by_context( $data, $schema, 'edit' );
246 }
247
248 $data = is_a( $data, 'WP_REST_Response' ) ? $data->get_data() : $data;
249
250 // if the user is logged in, and we have customer data.
251 // if it matches the current customer, then we can show the edit context.
252 if ( is_user_logged_in() && ! empty( $data['customer'] ) ) {
253 $customer_id = ! empty( $data['customer']['id'] ) ? $data['customer']['id'] : $data['customer'];
254 if ( User::current()->customerId() === $customer_id ) {
255 return rest_filter_response_by_context( $data, $schema, 'edit' );
256 }
257 }
258
259 return rest_filter_response_by_context( $data, $schema, 'view' );
260 }
261
262
263 /**
264 * Anyone can get a specific order if they have the unique order id.
265 *
266 * @param \WP_REST_Request $request Full details about the request.
267 * @return true|\WP_Error True if the request has access to create items, WP_Error object otherwise.
268 */
269 public function get_item_permissions_check( $request ) {
270 return true;
271 }
272
273 /**
274 * Listing
275 *
276 * @param \WP_REST_Request $request Full details about the request.
277 * @return true|\WP_Error True if the request has access to create items, WP_Error object otherwise.
278 */
279 public function get_items_permissions_check( $request ) {
280 return current_user_can( 'read_sc_checkouts', $request->get_params() );
281 }
282
283 /**
284 * Anyone can create.
285 *
286 * @param \WP_REST_Request $request Full details about the request.
287 * @return true|\WP_Error True if the request has access to create items, WP_Error object otherwise.
288 */
289 public function create_item_permissions_check( $request ) {
290 return true;
291 }
292
293 /**
294 * Update permissions.
295 *
296 * @param \WP_REST_Request $request Full details about the request.
297 * @return true|\WP_Error True if the request has access to create items, WP_Error object otherwise.
298 */
299 public function update_item_permissions_check( $request ) {
300 return true;
301 }
302
303 /**
304 * Nobody can delete.
305 *
306 * @param \WP_REST_Request $request Full details about the request.
307 * @return false
308 */
309 public function delete_item_permissions_check( $request ) {
310 return false;
311 }
312
313 /**
314 * Can the user manually mark the checkout as paid?
315 *
316 * @param \WP_REST_Request $request Full details about the request.
317 *
318 * @return boolean
319 */
320 public function manually_pay_permissions_check( $request ) {
321 return current_user_can( 'edit_sc_checkouts' );
322 }
323
324 /**
325 * Cancelling orders.
326 *
327 * @param \WP_REST_Request $request Full details about the request.
328 * @return true|\WP_Error True if the request has access to create items, WP_Error object otherwise.
329 */
330 public function cancel_item_permissions_check( $request ) {
331 return current_user_can( 'edit_sc_orders' );
332 }
333 }
334