PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 2.12.8
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v2.12.8
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
← All changes | inc/payments/front-end.php +25 -2 2.12.3 → 2.12.8 View file →
@@ -132,9 +132,10 @@
132 132 ]
133 133 );
134 134 }
135 135
136 - $license_key = Stripe_Helper::get_license_key();
136 + // Public checkout request - never block the visitor on a SureCart license call.
137 + $license_key = Stripe_Helper::get_license_key( false );
137 138
138 139 // Create payment intent with confirm: true for immediate processing.
139 140 $payment_intent_data = [
140 141 'secret_key' => $secret_key,
@@ -358,9 +359,10 @@
358 359 if ( ! $customer_id ) {
359 360 throw new \Exception( __( 'Failed to create customer for subscription.', 'sureforms' ) );
360 361 }
361 362
362 - $license_key = Stripe_Helper::get_license_key();
363 + // Public checkout request - never block the visitor on a SureCart license call.
364 + $license_key = Stripe_Helper::get_license_key( false );
363 365 // Prepare subscription data for middleware.
364 366 $subscription_data = apply_filters(
365 367 'srfm_create_subscription_data',
366 368 [
@@ -484,8 +486,17 @@
484 486
485 487 // Block IDs that produced a verified payment on this submission.
486 488 $verified_block_ids = [];
487 489
490 + // Field keys of every payment field seen in this submission, and the
491 + // subset whose payment we actually verified below. A payment field's
492 + // value is only a trustworthy payment-record id once verified here; any
493 + // field left unverified is cleared before it reaches the submission data,
494 + // so the {form-payment} smart tag can never resolve a client-supplied id
495 + // to an arbitrary payment row.
496 + $payment_field_names = [];
497 + $verified_field_names = [];
498 +
488 499 // Loop through form data to find payment fields.
489 500 foreach ( $form_data as $field_name => $field_value ) {
490 501 // Check if field name contains "-lbl-" pattern.
491 502 if ( strpos( $field_name, '-lbl-' ) === false ) {
@@ -504,8 +515,10 @@
504 515 if ( ! ( strpos( $name_parts[0], 'srfm-payment-' ) === 0 ) ) {
505 516 continue;
506 517 }
507 518
519 + $payment_field_names[] = $field_name;
520 +
508 521 // Value will be in the form of the json string.
509 522 $payment_value = json_decode( $field_value, true );
510 523
511 524 if ( empty( $payment_value ) || ! is_array( $payment_value ) ) {
@@ -551,8 +564,18 @@
551 564 // Modify the form data with the payment ID.
552 565 $form_data[ $field_name ] = $payment_response['payment_id'];
553 566
554 567 $verified_block_ids[ Helper::get_string_value( $block_id ) ] = true;
568 +
569 + $verified_field_names[ $field_name ] = true;
570 + }
571 + }
572 +
573 + // Deny-by-default: drop any payment field we did not verify this request,
574 + // so its raw client value cannot later be read back as a payment-record id.
575 + foreach ( $payment_field_names as $payment_field_name ) {
576 + if ( ! isset( $verified_field_names[ $payment_field_name ] ) ) {
577 + $form_data[ $payment_field_name ] = '';
555 578 }
556 579 }
557 580
558 581 if ( ! empty( $payment_response ) && isset( $payment_response['error'] ) ) {