| @@ -132,9 +132,10 @@ | ||
| 132 | 132 | ] |
| 133 | 133 | ); |
| 134 | 134 | } |
| 135 | 135 | |
| 136 | - $license_key = Stripe_Helper::get_license_key(); | |
| 136 | + // Public checkout request - never block the visitor on a SureCart license call. | |
| 137 | + $license_key = Stripe_Helper::get_license_key( false ); | |
| 137 | 138 | |
| 138 | 139 | // Create payment intent with confirm: true for immediate processing. |
| 139 | 140 | $payment_intent_data = [ |
| 140 | 141 | 'secret_key' => $secret_key, |
| @@ -358,9 +359,10 @@ | ||
| 358 | 359 | if ( ! $customer_id ) { |
| 359 | 360 | throw new \Exception( __( 'Failed to create customer for subscription.', 'sureforms' ) ); |
| 360 | 361 | } |
| 361 | 362 | |
| 362 | - $license_key = Stripe_Helper::get_license_key(); | |
| 363 | + // Public checkout request - never block the visitor on a SureCart license call. | |
| 364 | + $license_key = Stripe_Helper::get_license_key( false ); | |
| 363 | 365 | // Prepare subscription data for middleware. |
| 364 | 366 | $subscription_data = apply_filters( |
| 365 | 367 | 'srfm_create_subscription_data', |
| 366 | 368 | [ |
| @@ -484,8 +486,17 @@ | ||
| 484 | 486 | |
| 485 | 487 | // Block IDs that produced a verified payment on this submission. |
| 486 | 488 | $verified_block_ids = []; |
| 487 | 489 | |
| 490 | + // Field keys of every payment field seen in this submission, and the | |
| 491 | + // subset whose payment we actually verified below. A payment field's | |
| 492 | + // value is only a trustworthy payment-record id once verified here; any | |
| 493 | + // field left unverified is cleared before it reaches the submission data, | |
| 494 | + // so the {form-payment} smart tag can never resolve a client-supplied id | |
| 495 | + // to an arbitrary payment row. | |
| 496 | + $payment_field_names = []; | |
| 497 | + $verified_field_names = []; | |
| 498 | + | |
| 488 | 499 | // Loop through form data to find payment fields. |
| 489 | 500 | foreach ( $form_data as $field_name => $field_value ) { |
| 490 | 501 | // Check if field name contains "-lbl-" pattern. |
| 491 | 502 | if ( strpos( $field_name, '-lbl-' ) === false ) { |
| @@ -504,8 +515,10 @@ | ||
| 504 | 515 | if ( ! ( strpos( $name_parts[0], 'srfm-payment-' ) === 0 ) ) { |
| 505 | 516 | continue; |
| 506 | 517 | } |
| 507 | 518 | |
| 519 | + $payment_field_names[] = $field_name; | |
| 520 | + | |
| 508 | 521 | // Value will be in the form of the json string. |
| 509 | 522 | $payment_value = json_decode( $field_value, true ); |
| 510 | 523 | |
| 511 | 524 | if ( empty( $payment_value ) || ! is_array( $payment_value ) ) { |
| @@ -551,8 +564,18 @@ | ||
| 551 | 564 | // Modify the form data with the payment ID. |
| 552 | 565 | $form_data[ $field_name ] = $payment_response['payment_id']; |
| 553 | 566 | |
| 554 | 567 | $verified_block_ids[ Helper::get_string_value( $block_id ) ] = true; |
| 568 | + | |
| 569 | + $verified_field_names[ $field_name ] = true; | |
| 570 | + } | |
| 571 | + } | |
| 572 | + | |
| 573 | + // Deny-by-default: drop any payment field we did not verify this request, | |
| 574 | + // so its raw client value cannot later be read back as a payment-record id. | |
| 575 | + foreach ( $payment_field_names as $payment_field_name ) { | |
| 576 | + if ( ! isset( $verified_field_names[ $payment_field_name ] ) ) { | |
| 577 | + $form_data[ $payment_field_name ] = ''; | |
| 555 | 578 | } |
| 556 | 579 | } |
| 557 | 580 | |
| 558 | 581 | if ( ! empty( $payment_response ) && isset( $payment_response['error'] ) ) { |