| @@ -5,13 +5,17 @@ | ||
| 5 | 5 | * @package Timetics |
| 6 | 6 | */ |
| 7 | 7 | namespace Timetics\Core\Bookings; |
| 8 | 8 | |
| 9 | +defined( 'ABSPATH' ) || exit; | |
| 10 | + | |
| 9 | 11 | use Error; |
| 10 | 12 | use Timetics\Base\Api; |
| 11 | 13 | use Timetics\Core\Appointments\Api_Appointment; |
| 12 | 14 | use Timetics\Core\Appointments\Appointment; |
| 13 | 15 | use Timetics\Core\Customers\Customer; |
| 16 | +use Timetics\Core\Admin\Notification; | |
| 17 | +use Timetics\Core\Admin\Notification_Flow_Guard; | |
| 14 | 18 | use Timetics\Core\Emails\Cancel_Event_Customer_Email; |
| 15 | 19 | use Timetics\Core\Emails\Cancel_Event_Email; |
| 16 | 20 | use Timetics\Core\Emails\New_Event_Customer_Email; |
| 17 | 21 | use Timetics\Core\Emails\New_Event_Email; |
| @@ -16,8 +20,9 @@ | ||
| 16 | 20 | use Timetics\Core\Emails\New_Event_Customer_Email; |
| 17 | 21 | use Timetics\Core\Emails\New_Event_Email; |
| 18 | 22 | use Timetics\Core\Emails\Update_Event_Customer_Email; |
| 19 | 23 | use Timetics\Core\Emails\Update_Event_Email; |
| 24 | +use Timetics\Core\Integrations\Stripe\StripePayment; | |
| 20 | 25 | use Timetics\Core\Staffs\Staff; |
| 21 | 26 | use Timetics\Utils\Singleton; |
| 22 | 27 | use TimeticsPro\Core\SeatPlan\SeatPlan; |
| 23 | 28 | use WP_Error; |
| @@ -122,14 +127,26 @@ | ||
| 122 | 127 | ] |
| 123 | 128 | ); |
| 124 | 129 | |
| 125 | 130 | register_rest_route( |
| 131 | + $this->namespace, '/' . $this->rest_base . '/(?P<booking_id>[\d]+)/payment-intent', [ | |
| 132 | + [ | |
| 133 | + 'methods' => \WP_REST_Server::CREATABLE, | |
| 134 | + 'callback' => [$this, 'bind_payment_intent'], | |
| 135 | + 'permission_callback' => [$this, 'make_payment_permission_callback'], | |
| 136 | + ], | |
| 137 | + ] | |
| 138 | + ); | |
| 139 | + | |
| 140 | + register_rest_route( | |
| 126 | 141 | $this->namespace, $this->rest_base . '/search', [ |
| 127 | 142 | [ |
| 128 | 143 | 'methods' => \WP_REST_Server::READABLE, |
| 129 | 144 | 'callback' => [$this, 'search_items'], |
| 130 | 145 | 'permission_callback' => function () { |
| 131 | - return current_user_can( 'edit_posts' ); | |
| 146 | + // edit_booking is admin-only in this plugin (see get_items()) — | |
| 147 | + // staff need manage_timetics to search their own bookings at all. | |
| 148 | + return current_user_can( 'manage_timetics' ) || current_user_can( 'manage_options' ); | |
| 132 | 149 | }, |
| 133 | 150 | ], |
| 134 | 151 | ] |
| 135 | 152 | ); |
| @@ -192,9 +209,9 @@ | ||
| 192 | 209 | $bookings = Booking::all( $args ); |
| 193 | 210 | $items = []; |
| 194 | 211 | |
| 195 | 212 | foreach ( $bookings['items'] as $item ) { |
| 196 | - $items[] = $this->prepare_item( $item->ID ); | |
| 213 | + $items[] = $this->prepare_item( $item->ID, false ); | |
| 197 | 214 | } |
| 198 | 215 | |
| 199 | 216 | /** |
| 200 | 217 | * Added temporary for leagacy sass. It will remove in future. |
| @@ -422,16 +439,25 @@ | ||
| 422 | 439 | $per_page = ! empty( $request['per_page'] ) ? intval( $request['per_page'] ) : 20; |
| 423 | 440 | $paged = ! empty( $request['paged'] ) ? intval( $request['paged'] ) : 1; |
| 424 | 441 | $search = ! empty( $request['search'] ) ? sanitize_text_field( $request['search'] ) : ''; |
| 425 | 442 | |
| 443 | + $query_args = array( | |
| 444 | + 'post_type' => 'timetics-booking', | |
| 445 | + 'posts_per_page' => $per_page, | |
| 446 | + 'paged' => $paged, | |
| 447 | + 'post_status' => 'any', | |
| 448 | + ); | |
| 449 | + | |
| 450 | + if ( ! current_user_can( 'manage_options' ) ) { | |
| 451 | + $allowed_ids = Booking::get_visible_ids_for_user( get_current_user_id() ); | |
| 452 | + $query_args['post__in'] = ! empty( $allowed_ids ) ? $allowed_ids : [ 0 ]; | |
| 453 | + } | |
| 454 | + | |
| 426 | 455 | // Get search. |
| 427 | 456 | $booking = new WP_Query( |
| 428 | - array( | |
| 429 | - 'post_type' => 'timetics-booking', | |
| 430 | - 'posts_per_page' => $per_page, | |
| 431 | - 'paged' => $paged, | |
| 432 | - 'post_status' => 'any', | |
| 433 | - | |
| 457 | + array_merge( | |
| 458 | + $query_args, | |
| 459 | + array( | |
| 434 | 460 | // @codingStandardsIgnoreStart |
| 435 | 461 | 'meta_query' => array( |
| 436 | 462 | 'relation' => 'OR', |
| 437 | 463 | array( |
| @@ -485,8 +511,9 @@ | ||
| 485 | 511 | 'compare' => 'LIKE', |
| 486 | 512 | ), |
| 487 | 513 | ), |
| 488 | 514 | // @codingStandardsIgnoreEnd |
| 515 | + ) | |
| 489 | 516 | ) |
| 490 | 517 | ); |
| 491 | 518 | |
| 492 | 519 | // Prepare items for response. |
| @@ -492,9 +519,9 @@ | ||
| 492 | 519 | // Prepare items for response. |
| 493 | 520 | $items = []; |
| 494 | 521 | |
| 495 | 522 | foreach ( $booking->posts as $item ) { |
| 496 | - $items[] = $this->prepare_item( $item->ID ); | |
| 523 | + $items[] = $this->prepare_item( $item->ID, false ); | |
| 497 | 524 | } |
| 498 | 525 | |
| 499 | 526 | /** |
| 500 | 527 | * Added temporary for leagacy sass. It will remove in future. |
| @@ -571,27 +598,183 @@ | ||
| 571 | 598 | public function make_payment( $request ) { |
| 572 | 599 | $booking_id = intval( $request['booking_id'] ); |
| 573 | 600 | $booking = new Booking( $booking_id ); |
| 574 | 601 | $data = json_decode( $request->get_body(), true ); |
| 575 | - $status = ! empty( $data['status'] ) ? sanitize_text_field( $data['status'] ) : ''; | |
| 602 | + $data = is_array( $data ) ? $data : []; | |
| 603 | + $client_status = ! empty( $data['status'] ) ? sanitize_text_field( $data['status'] ) : ''; | |
| 604 | + $payment_method = ! empty( $data['payment_method'] ) ? sanitize_text_field( $data['payment_method'] ) : ''; | |
| 576 | 605 | $default_booking_status = timetics_get_option( 'default_booking_status', 'approved' ); |
| 577 | - $post_status = 'succeeded' === $status ? $default_booking_status : ( 'failed' === $status ? 'failed' : 'pending' ); | |
| 578 | - $payment_method = ! empty( $data['payment_method'] ) ? sanitize_text_field( $data['payment_method'] ) : ''; | |
| 579 | - $payment_details = ! empty( $data['payment_details'] ) ? $data['payment_details'] : ''; | |
| 580 | 606 | $type = $booking->get_type(); |
| 581 | 607 | |
| 582 | 608 | if ( ! $booking->is_booking() ) { |
| 583 | - return [ | |
| 584 | - 'status_code' => 404, | |
| 585 | - 'message' => esc_html__( 'Invalid booking id.', 'timetics' ), | |
| 586 | - 'data' => [], | |
| 587 | - ]; | |
| 609 | + return new WP_HTTP_Response( | |
| 610 | + [ | |
| 611 | + 'success' => 0, | |
| 612 | + 'status_code' => 404, | |
| 613 | + 'message' => esc_html__( 'Invalid booking id.', 'timetics' ), | |
| 614 | + ], | |
| 615 | + 404 | |
| 616 | + ); | |
| 588 | 617 | } |
| 589 | 618 | |
| 619 | + // Idempotency: refuse re-approval of a booking that already finalized. | |
| 620 | + // 'failed' is deliberately not in this list — a declined card is a failed | |
| 621 | + // attempt, not a finished booking, and the customer retries on the same one. | |
| 622 | + $current_status = (string) $booking->get_status(); | |
| 623 | + $finalized_statuses = [ 'approved', 'completed', 'cancelled', 'cancel' ]; | |
| 624 | + if ( in_array( $current_status, $finalized_statuses, true ) ) { | |
| 625 | + return new WP_HTTP_Response( | |
| 626 | + [ | |
| 627 | + 'success' => 0, | |
| 628 | + 'status_code' => 409, | |
| 629 | + 'message' => esc_html__( 'Booking has already been finalized.', 'timetics' ), | |
| 630 | + ], | |
| 631 | + 409 | |
| 632 | + ); | |
| 633 | + } | |
| 634 | + | |
| 635 | + $verified_status = 'pending'; | |
| 636 | + $payment_details = ''; | |
| 637 | + $stored_intent_id = ''; | |
| 638 | + | |
| 639 | + if ( 'stripe' === $payment_method ) { | |
| 640 | + $client_details = ! empty( $data['payment_details'] ) ? $data['payment_details'] : []; | |
| 641 | + $intent_id = is_array( $client_details ) && ! empty( $client_details['id'] ) | |
| 642 | + ? sanitize_text_field( (string) $client_details['id'] ) | |
| 643 | + : ''; | |
| 644 | + | |
| 645 | + if ( '' === $intent_id || strpos( $intent_id, 'pi_' ) !== 0 ) { | |
| 646 | + if ( 'failed' === $client_status ) { | |
| 647 | + $verified_status = 'failed'; | |
| 648 | + } else { | |
| 649 | + return new WP_HTTP_Response( | |
| 650 | + [ | |
| 651 | + 'success' => 0, | |
| 652 | + 'status_code' => 400, | |
| 653 | + 'message' => esc_html__( 'Missing payment intent.', 'timetics' ), | |
| 654 | + ], | |
| 655 | + 400 | |
| 656 | + ); | |
| 657 | + } | |
| 658 | + } else { | |
| 659 | + $intent = ( new StripePayment() )->retrieve_payment_intent( $intent_id ); | |
| 660 | + | |
| 661 | + if ( is_wp_error( $intent ) || ! is_array( $intent ) || empty( $intent['id'] ) ) { | |
| 662 | + return new WP_HTTP_Response( | |
| 663 | + [ | |
| 664 | + 'success' => 0, | |
| 665 | + 'status_code' => 502, | |
| 666 | + 'message' => esc_html__( 'Cannot verify payment with Stripe.', 'timetics' ), | |
| 667 | + ], | |
| 668 | + 502 | |
| 669 | + ); | |
| 670 | + } | |
| 671 | + | |
| 672 | + $expected_amount = (int) round( (float) $booking->get_total() * 100 ); | |
| 673 | + $expected_currency = strtolower( (string) apply_filters( 'timetics_currency', timetics_get_option( 'currency', 'USD' ) ) ); | |
| 674 | + $intent_status = isset( $intent['status'] ) ? (string) $intent['status'] : ''; | |
| 675 | + $intent_amount = isset( $intent['amount'] ) ? (int) $intent['amount'] : 0; | |
| 676 | + $intent_currency = isset( $intent['currency'] ) ? strtolower( (string) $intent['currency'] ) : ''; | |
| 677 | + $meta_booking_id = isset( $intent['metadata']['booking_id'] ) ? (int) $intent['metadata']['booking_id'] : 0; | |
| 678 | + $meta_token = isset( $intent['metadata']['security_token'] ) ? (string) $intent['metadata']['security_token'] : ''; | |
| 679 | + $stored_token = (string) $booking->get_security_token(); | |
| 680 | + | |
| 681 | + $mismatch = ( | |
| 682 | + 'succeeded' !== $intent_status || | |
| 683 | + $expected_amount !== $intent_amount || | |
| 684 | + $expected_currency !== $intent_currency || | |
| 685 | + $booking_id !== $meta_booking_id || | |
| 686 | + '' === $stored_token || | |
| 687 | + '' === $meta_token || | |
| 688 | + ! hash_equals( $stored_token, $meta_token ) | |
| 689 | + ); | |
| 690 | + | |
| 691 | + if ( $mismatch ) { | |
| 692 | + return new WP_HTTP_Response( | |
| 693 | + [ | |
| 694 | + 'success' => 0, | |
| 695 | + 'status_code' => 402, | |
| 696 | + 'message' => esc_html__( 'Payment verification failed.', 'timetics' ), | |
| 697 | + ], | |
| 698 | + 402 | |
| 699 | + ); | |
| 700 | + } | |
| 701 | + | |
| 702 | + // Replay protection: this booking can be bound to exactly one | |
| 703 | + // PaymentIntent. A second call with a different intent fails. | |
| 704 | + $bound = $booking->get_stripe_payment_intent_id(); | |
| 705 | + if ( '' !== $bound && $bound !== $intent['id'] ) { | |
| 706 | + return new WP_HTTP_Response( | |
| 707 | + [ | |
| 708 | + 'success' => 0, | |
| 709 | + 'status_code' => 409, | |
| 710 | + 'message' => esc_html__( 'Payment intent does not match this booking.', 'timetics' ), | |
| 711 | + ], | |
| 712 | + 409 | |
| 713 | + ); | |
| 714 | + } | |
| 715 | + | |
| 716 | + $stored_intent_id = $intent['id']; | |
| 717 | + $verified_status = 'succeeded'; | |
| 718 | + $payment_details = $intent; | |
| 719 | + } | |
| 720 | + } elseif ( 'failed' === $client_status ) { | |
| 721 | + // Marking the user's own attempt as failed never grants access; safe to honor. | |
| 722 | + $verified_status = 'failed'; | |
| 723 | + } else { | |
| 724 | + // Gateways that live outside this plugin ( PayPal ) check the payment | |
| 725 | + // against their own API and answer with the status they trust. The | |
| 726 | + // default stays 'pending', so a client that sends nothing verifiable | |
| 727 | + // cannot talk its way to 'succeeded'. | |
| 728 | + $verified_status = (string) apply_filters( 'timetics_verify_payment', $verified_status, $payment_method, $data, $booking ); | |
| 729 | + | |
| 730 | + if ( ! in_array( $verified_status, ['pending', 'failed', 'succeeded'], true ) ) { | |
| 731 | + $verified_status = 'pending'; | |
| 732 | + } | |
| 733 | + } | |
| 734 | + // Other payment methods (cash, on-site, etc.) stay pending here. They | |
| 735 | + // are approved through their own authenticated/admin paths. | |
| 736 | + $post_status = 'succeeded' === $verified_status | |
| 737 | + ? $default_booking_status | |
| 738 | + : ( 'failed' === $verified_status ? 'failed' : 'pending' ); | |
| 739 | + | |
| 740 | + $finalizing = 'succeeded' === $verified_status && '' !== $stored_intent_id; | |
| 741 | + | |
| 742 | + if ( $finalizing ) { | |
| 743 | + // Separate key from _tt_stripe_payment_intent_id: that one is written at | |
| 744 | + // bind time (before payment) so the cleanup sweep can see it, so it can't | |
| 745 | + // double as a "not yet finalized" marker here — it always already exists. | |
| 746 | + $claimed = add_post_meta( $booking_id, '_tt_stripe_payment_finalized_intent_id', $stored_intent_id, true ); | |
| 747 | + if ( false === $claimed ) { | |
| 748 | + $existing = (string) get_post_meta( $booking_id, '_tt_stripe_payment_finalized_intent_id', true ); | |
| 749 | + if ( $existing !== $stored_intent_id ) { | |
| 750 | + return new WP_HTTP_Response( | |
| 751 | + [ | |
| 752 | + 'success' => 0, | |
| 753 | + 'status_code' => 409, | |
| 754 | + 'message' => esc_html__( 'Payment intent does not match this booking.', 'timetics' ), | |
| 755 | + ], | |
| 756 | + 409 | |
| 757 | + ); | |
| 758 | + } | |
| 759 | + | |
| 760 | + if ( 'pending' !== (string) $booking->get_status() ) { | |
| 761 | + return new WP_HTTP_Response( | |
| 762 | + [ | |
| 763 | + 'success' => 1, | |
| 764 | + 'status_code' => 200, | |
| 765 | + 'message' => esc_html__( 'Payment already finalized.', 'timetics' ), | |
| 766 | + ], | |
| 767 | + 200 | |
| 768 | + ); | |
| 769 | + } | |
| 770 | + } | |
| 771 | + } | |
| 772 | + | |
| 590 | 773 | $update = $booking->update( |
| 591 | 774 | [ |
| 592 | 775 | 'post_status' => $post_status, |
| 593 | - 'payment_status' => $status, | |
| 776 | + 'payment_status' => $verified_status, | |
| 594 | 777 | 'payment_details' => $payment_details, |
| 595 | 778 | 'payment_method' => $payment_method, |
| 596 | 779 | ] |
| 597 | 780 | ); |
| @@ -596,19 +779,39 @@ | ||
| 596 | 779 | ] |
| 597 | 780 | ); |
| 598 | 781 | |
| 599 | 782 | if ( is_wp_error( $update ) ) { |
| 600 | - $data = [ | |
| 601 | - 'success' => 0, | |
| 602 | - 'status_code' => 409, | |
| 603 | - /* translators: Action */ | |
| 604 | - 'message' => $update->get_error_message(), | |
| 605 | - ]; | |
| 783 | + // Roll back the claim so a retry can finalize cleanly. | |
| 784 | + if ( $finalizing ) { | |
| 785 | + delete_post_meta( $booking_id, '_tt_stripe_payment_finalized_intent_id', $stored_intent_id ); | |
| 786 | + } | |
| 787 | + return new WP_HTTP_Response( | |
| 788 | + [ | |
| 789 | + 'success' => 0, | |
| 790 | + 'status_code' => 409, | |
| 791 | + /* translators: Action */ | |
| 792 | + 'message' => $update->get_error_message(), | |
| 793 | + ], | |
| 794 | + 409 | |
| 795 | + ); | |
| 796 | + } | |
| 606 | 797 | |
| 607 | - return new WP_HTTP_Response( $data, 409 ); | |
| 798 | + // A failed payment means the booking did not happen, so release the slot | |
| 799 | + // it was holding and let it appear as free again. | |
| 800 | + if ( 'failed' === $post_status ) { | |
| 801 | + $booking->release_slot(); | |
| 608 | 802 | } |
| 609 | 803 | |
| 610 | - if ( $default_booking_status === $post_status ) { | |
| 804 | + // Approve, notify and burn the token only when the payment actually | |
| 805 | + // cleared. This used to compare $post_status against the site default, | |
| 806 | + // which is the very same string on a site whose default booking status | |
| 807 | + // is 'pending' - so an unverified attempt still sent the "meeting | |
| 808 | + // scheduled" emails and rotated the token without a penny being paid. | |
| 809 | + if ( 'succeeded' === $verified_status ) { | |
| 810 | + // Rotate the security token so the same one cannot drive a second | |
| 811 | + // approval after this booking has finalized. | |
| 812 | + $booking->rotate_security_token(); | |
| 813 | + | |
| 611 | 814 | $booking->create_event(); |
| 612 | 815 | |
| 613 | 816 | if( 'timetics-event' == $type ){ |
| 614 | 817 | return; |
| @@ -626,8 +829,10 @@ | ||
| 626 | 829 | $new_event_customer_email = new New_Event_Customer_Email( $booking ); |
| 627 | 830 | $new_event_customer_email->send(); |
| 628 | 831 | } |
| 629 | 832 | |
| 833 | + do_action( 'timetics_gln_hook', 'booking_created', Notification::get_hook_data( $booking ) ); | |
| 834 | + | |
| 630 | 835 | do_action( 'timetics_booking_payment', $booking ); |
| 631 | 836 | |
| 632 | 837 | } |
| 633 | 838 | |
| @@ -677,8 +882,20 @@ | ||
| 677 | 882 | $first_name = ! empty( $data['first_name'] ) ? sanitize_text_field( $data['first_name'] ) : ''; |
| 678 | 883 | $last_name = ! empty( $data['last_name'] ) ? sanitize_text_field( $data['last_name'] ) : ''; |
| 679 | 884 | $email = ! empty( $data['email'] ) ? sanitize_text_field( $data['email'] ) : ''; |
| 680 | 885 | $phone = ! empty( $data['phone'] ) ? sanitize_text_field( $data['phone'] ) : ''; |
| 886 | + | |
| 887 | + // Fallback: when built-in phone field absent (e.g., non attendee-call location), | |
| 888 | + // pick phone from custom form field so customer record still gets it. | |
| 889 | + if ( empty( $phone ) && ! empty( $data['custom_form_data'] ) ) { | |
| 890 | + $custom_form = is_array( $data['custom_form_data'] ) ? $data['custom_form_data'] : (array) json_decode( wp_json_encode( $data['custom_form_data'] ), true ); | |
| 891 | + foreach ( [ 'phone', 'Phone', 'phone_number', 'mobile', 'contact_number' ] as $key ) { | |
| 892 | + if ( ! empty( $custom_form[ $key ] ) ) { | |
| 893 | + $phone = sanitize_text_field( $custom_form[ $key ] ); | |
| 894 | + break; | |
| 895 | + } | |
| 896 | + } | |
| 897 | + } | |
| 681 | 898 | $city = ! empty( $data['city'] ) ? sanitize_text_field( $data['city'] ) : ''; |
| 682 | 899 | $state = ! empty( $data['state'] ) ? sanitize_text_field( $data['state'] ) : ''; |
| 683 | 900 | $post_code = ! empty( $data['post_code'] ) ? sanitize_text_field( $data['post_code'] ) : ''; |
| 684 | 901 | $country = ! empty( $data['country'] ) ? sanitize_text_field( $data['country'] ) : ''; |
| @@ -691,10 +908,9 @@ | ||
| 691 | 908 | $date = ! empty( $data['date'] ) ? sanitize_text_field( $data['date'] ) : ''; |
| 692 | 909 | $end_date = ! empty( $data['end_date'] ) ? sanitize_text_field( $data['end_date'] ) : $start_date; |
| 693 | 910 | $start_time = ! empty( $data['start_time'] ) ? sanitize_text_field( $data['start_time'] ) : ''; |
| 694 | 911 | $end_time = ! empty( $data['end_time'] ) ? sanitize_text_field( $data['end_time'] ) : ''; |
| 695 | - $order_total = ! empty( $data['order_total'] ) ? intval( $data['order_total'] ) : 0; | |
| 696 | - $status = ! empty( $data['status'] ) ? sanitize_text_field( $data['status'] ) : timetics_get_option( 'default_booking_status', 'approved' ); | |
| 912 | + $client_status = ! empty( $data['status'] ) ? sanitize_text_field( $data['status'] ) : ''; | |
| 697 | 913 | $location = ! empty( $data['location'] ) ? sanitize_text_field( $data['location'] ) : ''; |
| 698 | 914 | $location_type = ! empty( $data['location_type'] ) ? sanitize_text_field( $data['location_type'] ) : ''; |
| 699 | 915 | $description = ! empty( $data['description'] ) ? sanitize_text_field( $data['description'] ) : ''; |
| 700 | 916 | $timezone = ! empty( $data['timezone'] ) ? sanitize_text_field( $data['timezone'] ) : ''; |
| @@ -703,16 +919,44 @@ | ||
| 703 | 919 | $cancel_reason = ! empty( $data['cancel_reason'] ) ? $data['cancel_reason'] : []; |
| 704 | 920 | $booking_time = ! empty( $data['booking_createAt'] ) ? $data['booking_createAt'] : ''; |
| 705 | 921 | $action = $id ? 'updated' : 'created'; |
| 706 | 922 | |
| 707 | - // For WooCommerce payments, create booking in failed status until payment is confirmed | |
| 708 | - if ( 'woocommerce' === $payment_method && 'created' === $action && $order_total != 0 ) { | |
| 709 | - $status = 'failed'; | |
| 710 | - } | |
| 923 | + $is_privileged = current_user_can( 'manage_timetics' ) || current_user_can( 'edit_booking' ); | |
| 924 | + $server_total = (int) $this->calculate_order_total( $data ); | |
| 925 | + $default_status = timetics_get_option( 'default_booking_status', 'approved' ); | |
| 926 | + $payment_method_l = strtolower( $payment_method ); | |
| 711 | 927 | |
| 712 | - // For Stripe payments, create booking in pending status until payment is confirmed | |
| 713 | - if ( 'stripe' === strtolower( $payment_method ) && 'created' === $action && $order_total != 0 ) { | |
| 714 | - $status = 'pending'; | |
| 928 | + if ( $is_privileged ) { | |
| 929 | + $status = '' !== $client_status ? $client_status : $default_status; | |
| 930 | + } elseif ( 'created' === $action ) { | |
| 931 | + if ( $server_total > 0 && 'stripe' === $payment_method_l ) { | |
| 932 | + $status = 'pending'; | |
| 933 | + } elseif ( $server_total > 0 && 'woocommerce' === $payment_method_l ) { | |
| 934 | + $status = 'failed'; | |
| 935 | + } else { | |
| 936 | + $status = $default_status; | |
| 937 | + } | |
| 938 | + } else { | |
| 939 | + $current_booking = new Booking( $id ); | |
| 940 | + | |
| 941 | + // Reschedule only moves time. | |
| 942 | + if ( (int) $current_booking->get_appointment() !== $appointment ) { | |
| 943 | + return new WP_HTTP_Response( | |
| 944 | + [ | |
| 945 | + 'status_code' => 403, | |
| 946 | + 'success' => 0, | |
| 947 | + 'message' => esc_html__( 'You can not change the appointment of a booking.', 'timetics' ), | |
| 948 | + ], | |
| 949 | + 403 | |
| 950 | + ); | |
| 951 | + } | |
| 952 | + | |
| 953 | + $current_status = $current_booking->get_status(); | |
| 954 | + if ( 'cancel' === $client_status ) { | |
| 955 | + $status = 'cancel'; | |
| 956 | + } else { | |
| 957 | + $status = $current_status; | |
| 958 | + } | |
| 715 | 959 | } |
| 716 | 960 | $appointment_token = ! empty( $data['appointment_token'] ) ? sanitize_text_field( $data['appointment_token'] ) : ''; |
| 717 | 961 | |
| 718 | 962 | if ( $id ) { |
| @@ -731,20 +975,28 @@ | ||
| 731 | 975 | // Use the validated email from the security check |
| 732 | 976 | $email = $email_validation; |
| 733 | 977 | } |
| 734 | 978 | |
| 735 | - $validate = $this->validate( | |
| 736 | - $data, [ | |
| 737 | - 'first_name', | |
| 738 | - 'email', | |
| 739 | - 'payment_method', | |
| 740 | - 'appointment', | |
| 741 | - 'start_date', | |
| 742 | - 'start_time', | |
| 743 | - 'end_time', | |
| 744 | - ] | |
| 745 | - ); | |
| 979 | + $required_fields = [ | |
| 980 | + 'first_name', | |
| 981 | + 'email', | |
| 982 | + 'appointment', | |
| 983 | + 'start_date', | |
| 984 | + 'start_time', | |
| 985 | + 'end_time', | |
| 986 | + ]; | |
| 746 | 987 | |
| 988 | + // Payment method is only chosen once, at booking creation. Later | |
| 989 | + // updates (status change, reschedule, staff swap, ...) shouldn't have | |
| 990 | + // to resubmit it — requiring it here made admin actions like | |
| 991 | + // cancelling from the calendar popover fail whenever the form didn't | |
| 992 | + // carry the original payment method in its state. | |
| 993 | + if ( 'created' === $action ) { | |
| 994 | + $required_fields[] = 'payment_method'; | |
| 995 | + } | |
| 996 | + | |
| 997 | + $validate = $this->validate( $data, $required_fields ); | |
| 998 | + | |
| 747 | 999 | if ( is_wp_error( $validate ) ) { |
| 748 | 1000 | $data = [ |
| 749 | 1001 | 'status_code' => 403, |
| 750 | 1002 | 'success' => 0, |
| @@ -800,30 +1052,40 @@ | ||
| 800 | 1052 | 'phone' => $phone, |
| 801 | 1053 | ] |
| 802 | 1054 | ); |
| 803 | 1055 | |
| 804 | - // Update booking schedule. | |
| 1056 | + // Update booking schedule. Release the slot the booking currently holds; | |
| 1057 | + // the new one is taken further below. | |
| 805 | 1058 | if ( $id ) { |
| 1059 | + // Entries are stored in the meeting's timezone, so the booking's own | |
| 1060 | + // date/time has to be converted before the lookup. Without this the | |
| 1061 | + // entry is missed whenever the two timezones differ and it stays | |
| 1062 | + // behind blocking a slot nobody holds. | |
| 1063 | + $old_meeting = new Appointment( $booking->get_appointment() ); | |
| 1064 | + $old_datetime = timetics_convert_timezone( | |
| 1065 | + $booking->get_start_date() . ' ' . $booking->get_start_time(), | |
| 1066 | + $booking->get_timezone(), | |
| 1067 | + $old_meeting->get_timezone() | |
| 1068 | + ); | |
| 806 | 1069 | |
| 807 | 1070 | $entries = $booking_entry->find( |
| 808 | 1071 | [ |
| 809 | 1072 | 'staff_id' => $booking->get_staff_id(), |
| 810 | 1073 | 'meeting_id' => $booking->get_appointment(), |
| 811 | - 'date' => $booking->get_start_date(), | |
| 812 | - 'start' => $booking->get_start_time(), | |
| 1074 | + 'date' => $old_datetime->format( 'Y-m-d' ), | |
| 1075 | + 'start' => $old_datetime->format( 'h:i a' ), | |
| 813 | 1076 | ] |
| 814 | - | |
| 815 | 1077 | ); |
| 816 | 1078 | |
| 817 | 1079 | if ( $entries ) { |
| 818 | 1080 | $entry = $booking_entry->first(); |
| 819 | 1081 | |
| 820 | - if ( 'one-to-one' == strtolower( $meeting->get_type() ) ) { | |
| 1082 | + if ( 'one-to-one' == strtolower( $old_meeting->get_type() ) ) { | |
| 821 | 1083 | $entry->delete(); |
| 822 | 1084 | } else { |
| 823 | 1085 | $booked = intval( $entry->get_booked() ) - 1; |
| 824 | 1086 | $booked_data = apply_filters( 'timetics_booking_update_schedule', $entry, ['booked' => $booked], $data, $booking ); |
| 825 | - $entry->update( $booked_data ); | |
| 1087 | + $entry->update( $this->normalize_schedule_update( $booked_data, $booked ) ); | |
| 826 | 1088 | } |
| 827 | 1089 | } |
| 828 | 1090 | } |
| 829 | 1091 | |
| @@ -852,9 +1114,9 @@ | ||
| 852 | 1114 | 'date' => $date, |
| 853 | 1115 | 'end_date' => $end_date, |
| 854 | 1116 | 'start_time' => $start_time, |
| 855 | 1117 | 'end_time' => $end_time, |
| 856 | - 'order_total' => $this->calculate_order_total( $data ), | |
| 1118 | + 'order_total' => ( $id && ! $is_privileged ) ? $booking->get_total() : $this->calculate_order_total( $data ), | |
| 857 | 1119 | 'post_status' => $status, |
| 858 | 1120 | 'location' => $location, |
| 859 | 1121 | 'location_type' => $location_type, |
| 860 | 1122 | 'timezone' => $timezone, |
| @@ -860,12 +1122,23 @@ | ||
| 860 | 1122 | 'timezone' => $timezone, |
| 861 | 1123 | 'cancel_reason' => $cancel_reason, |
| 862 | 1124 | ]; |
| 863 | 1125 | |
| 1126 | + if ( 'created' === $action && '' !== $payment_method ) { | |
| 1127 | + $booking_props['payment_method'] = $payment_method; | |
| 1128 | + } | |
| 1129 | + | |
| 1130 | + $old_meeting_timestamp = 0; | |
| 1131 | + | |
| 864 | 1132 | if ( $id ) { |
| 865 | 1133 | $old_start_date = $booking->get_start_date(); |
| 866 | 1134 | $old_start_time = $booking->get_start_time(); |
| 867 | 1135 | $old_end_time = $booking->get_end_time(); |
| 1136 | + | |
| 1137 | + // Captured before the props are overwritten so pending delayed | |
| 1138 | + // flows can be matched against the meeting time they were frozen | |
| 1139 | + // with. | |
| 1140 | + $old_meeting_timestamp = Notification::get_booking_timestamp( $booking ); | |
| 868 | 1141 | } |
| 869 | 1142 | |
| 870 | 1143 | if( 'created' == $action ){ |
| 871 | 1144 | $booking_props['security_token'] = $booking->generate_security_token(); |
| @@ -880,8 +1153,13 @@ | ||
| 880 | 1153 | |
| 881 | 1154 | // Fire when booking is completed. |
| 882 | 1155 | do_action( 'timetics_after_booking_create', $booking->get_id(), $customer->get_id(), $meeting->get_id(), $data ); |
| 883 | 1156 | |
| 1157 | + // Note: booking creation emails for new bookings are sent further below, | |
| 1158 | + // AFTER the calendar event is created, so the Google Meet join link is | |
| 1159 | + // available in the email. See the "created" branch after the schedule | |
| 1160 | + // entry is created. | |
| 1161 | + | |
| 884 | 1162 | // Create or update calendar event. |
| 885 | 1163 | if ( $id ) { |
| 886 | 1164 | if ( 'cancel' === $status ) { |
| 887 | 1165 | $booking->delete_event(); |
| @@ -897,12 +1175,27 @@ | ||
| 897 | 1175 | $customer_cancel_event_email = new Cancel_Event_Customer_Email( $booking ); |
| 898 | 1176 | $customer_cancel_event_email->send(); |
| 899 | 1177 | } |
| 900 | 1178 | |
| 1179 | + do_action( 'timetics_gln_hook', 'booking_canceled', Notification::get_hook_data( $booking ) ); | |
| 1180 | + | |
| 901 | 1181 | /** |
| 902 | 1182 | * Added temporary for leagacy sass. It will remove in future. |
| 903 | 1183 | */ |
| 904 | 1184 | do_action( 'timetics/admin/booking/after_delete_item', $booking ); |
| 1185 | + | |
| 1186 | + /** | |
| 1187 | + * Fired when an existing booking is cancelled. | |
| 1188 | + * | |
| 1189 | + * Cancel had no dedicated hook before, so integrations could | |
| 1190 | + * only react to create/reschedule/delete. | |
| 1191 | + * | |
| 1192 | + * @param int $booking_id Booking ID. | |
| 1193 | + * @param int $customer_id Customer ID. | |
| 1194 | + * @param int $meeting_id Meeting (appointment) ID. | |
| 1195 | + * @param array $data Request data. | |
| 1196 | + */ | |
| 1197 | + do_action( 'timetics_after_booking_cancel', $booking->get_id(), $customer->get_id(), $meeting->get_id(), $data ); | |
| 905 | 1198 | } else { |
| 906 | 1199 | // Check if the booking date/time was actually changed |
| 907 | 1200 | $date_time_changed = ( |
| 908 | 1201 | $old_start_date !== $start_date || |
| @@ -912,8 +1205,15 @@ | ||
| 912 | 1205 | |
| 913 | 1206 | $booking->update_event(); |
| 914 | 1207 | |
| 915 | 1208 | if ( $date_time_changed ) { |
| 1209 | + $reschedule_hook_data = Notification::get_hook_data( $booking ); | |
| 1210 | + | |
| 1211 | + // Move any pending delayed flow onto the new meeting time so | |
| 1212 | + // the reminder keeps its offset instead of firing at the old | |
| 1213 | + // moment with the old details. | |
| 1214 | + Notification_Flow_Guard::reschedule_pending_flows( $booking->get_id(), $reschedule_hook_data ); | |
| 1215 | + | |
| 916 | 1216 | $is_email_to_reschedule_customer = timetics_get_option( 'booking_rescheduled_customer'); |
| 917 | 1217 | $is_email_to_reschedule_host = timetics_get_option( 'booking_rescheduled_host'); |
| 918 | 1218 | |
| 919 | 1219 | if ( $is_email_to_reschedule_host ) { |
| @@ -924,8 +1224,31 @@ | ||
| 924 | 1224 | if ( $is_email_to_reschedule_customer ) { |
| 925 | 1225 | $update_event_customer_email = new Update_Event_Customer_Email( $booking ); |
| 926 | 1226 | $update_event_customer_email->send(); |
| 927 | 1227 | } |
| 1228 | + | |
| 1229 | + // Hand the previous meeting timestamp to the SDK as well — | |
| 1230 | + // its delay node uses `previous_<key>` to drop a checkpoint | |
| 1231 | + // it scheduled itself on an earlier run. | |
| 1232 | + if ( $old_meeting_timestamp ) { | |
| 1233 | + $reschedule_hook_data['previous_meeting_date_timestamp'] = $old_meeting_timestamp; | |
| 1234 | + } | |
| 1235 | + | |
| 1236 | + do_action( 'timetics_gln_hook', 'booking_rescheduled', $reschedule_hook_data ); | |
| 1237 | + | |
| 1238 | + /** | |
| 1239 | + * Fired when a booking's date or time actually changed. | |
| 1240 | + * | |
| 1241 | + * `timetics_after_booking_schedule` runs on every save, so | |
| 1242 | + * it cannot tell a reschedule from an edit of the phone | |
| 1243 | + * number. This one only fires on a real time change. | |
| 1244 | + * | |
| 1245 | + * @param int $booking_id Booking ID. | |
| 1246 | + * @param int $customer_id Customer ID. | |
| 1247 | + * @param int $meeting_id Meeting (appointment) ID. | |
| 1248 | + * @param array $data Request data. | |
| 1249 | + */ | |
| 1250 | + do_action( 'timetics_after_booking_reschedule', $booking->get_id(), $customer->get_id(), $meeting->get_id(), $data ); | |
| 928 | 1251 | } |
| 929 | 1252 | } |
| 930 | 1253 | } |
| 931 | 1254 | |
| @@ -932,49 +1255,85 @@ | ||
| 932 | 1255 | // Convert booking time to staff/meeting time. |
| 933 | 1256 | $date_time = timetics_convert_timezone( $start_date . ' ' . $start_time, $timezone, $meeting->get_timezone() ); |
| 934 | 1257 | $end_time = timetics_convert_timezone( $start_date . ' ' . $end_time, $timezone, $meeting->get_timezone() ); |
| 935 | 1258 | |
| 936 | - // Create booking schedule. | |
| 937 | - $entries = $booking_entry->find( | |
| 938 | - [ | |
| 939 | - 'staff_id' => $staff->get_id(), | |
| 940 | - 'meeting_id' => $meeting->get_id(), | |
| 941 | - 'date' => $date_time->format( 'Y-m-d' ), | |
| 942 | - 'start' => $date_time->format( 'h:i a' ), | |
| 943 | - ] | |
| 944 | - ); | |
| 1259 | + // Create booking schedule. Skipped on cancel — the slot for this | |
| 1260 | + // booking was already released above, and re-running this block would | |
| 1261 | + // either recreate the just-deleted entry (one-to-one) or double the | |
| 1262 | + // decrement (group), re-blocking or over-freeing the slot. | |
| 1263 | + if ( 'cancel' !== $status ) { | |
| 1264 | + $entries = $booking_entry->find( | |
| 1265 | + [ | |
| 1266 | + 'staff_id' => $staff->get_id(), | |
| 1267 | + 'meeting_id' => $meeting->get_id(), | |
| 1268 | + 'date' => $date_time->format( 'Y-m-d' ), | |
| 1269 | + 'start' => $date_time->format( 'h:i a' ), | |
| 1270 | + ] | |
| 1271 | + ); | |
| 945 | 1272 | |
| 946 | - if ( $entries ) { | |
| 947 | - $entry = $booking_entry->first(); | |
| 1273 | + if ( $entries ) { | |
| 1274 | + $entry = $booking_entry->first(); | |
| 948 | 1275 | |
| 949 | - if ( 'cancel' === $status ) { | |
| 950 | - $booked = intval( $entry->get_booked() ) - 1; | |
| 1276 | + $booked = intval( $entry->get_booked() ) + 1; | |
| 1277 | + $booked_data = apply_filters( 'timetics_booking_update_schedule', $entry, ['booked' => $booked], $data, $booking ); | |
| 1278 | + | |
| 1279 | + $entry->update( $this->normalize_schedule_update( $booked_data, $booked ) ); | |
| 951 | 1280 | } else { |
| 952 | - $booked = intval( $entry->get_booked() ) + 1; | |
| 1281 | + $book_entry_data = [ | |
| 1282 | + 'meeting_id' => $meeting->get_id(), | |
| 1283 | + 'staff_id' => $staff->get_id(), | |
| 1284 | + 'customer_id' => $customer->get_id(), | |
| 1285 | + 'booking_id' => $booking->get_id(), | |
| 1286 | + 'booked' => 1, | |
| 1287 | + 'date' => $date_time->format( 'Y-m-d' ), | |
| 1288 | + 'start' => $date_time->format( 'h:i a' ), | |
| 1289 | + 'end' => $end_time->format( 'h:i a' ), | |
| 1290 | + ]; | |
| 1291 | + | |
| 1292 | + $book_entry_data = apply_filters( 'timetics_booking_schedule', $book_entry_data, $data ); | |
| 1293 | + $booking_entry->create( $book_entry_data ); | |
| 953 | 1294 | } |
| 1295 | + } | |
| 954 | 1296 | |
| 955 | - $booked_data = apply_filters( 'timetics_booking_update_schedule', $entry, ['booked' => $booked], $data, $booking ); | |
| 1297 | + // For newly created bookings, create the calendar event now that the | |
| 1298 | + // booking schedule entry exists. This generates the Google Meet link | |
| 1299 | + // (stored in booking meta) so it can be shown on the success page and | |
| 1300 | + // included in the notification emails sent below. | |
| 1301 | + // | |
| 1302 | + // Skipped while an online gateway payment is still outstanding — the | |
| 1303 | + // real event gets created once payment confirms, in make_payment() and | |
| 1304 | + // Hooks::update_booking_payment_status(). Based on payment_method and | |
| 1305 | + // amount alone, NOT $status: a privileged (logged-in admin/staff) user | |
| 1306 | + // gets $default_status regardless of gateway, which can be 'approved' | |
| 1307 | + // even though no payment happened yet — checking $status here would | |
| 1308 | + // miss that and create the event before the customer actually pays. | |
| 1309 | + $is_awaiting_online_payment = 'created' === $action && $server_total > 0 | |
| 1310 | + && in_array( $payment_method_l, [ 'stripe', 'woocommerce', 'paypal' ], true ); | |
| 956 | 1311 | |
| 957 | - if ( 'cancel' === $status && 'one-to-one' == strtolower( $meeting->get_type() ) ) { | |
| 958 | - $entry->delete(); | |
| 959 | - } else { | |
| 960 | - $entry->update( $booked_data ); | |
| 1312 | + if ( 'created' === $action && 'cancel' !== $status && ! $is_awaiting_online_payment ) { | |
| 1313 | + $booking->create_event(); | |
| 1314 | + } | |
| 1315 | + | |
| 1316 | + // Send booking creation emails for new bookings not processed through | |
| 1317 | + // a separate payment flow. Online gateways (stripe/paypal/woocommerce) | |
| 1318 | + // send this email themselves once payment is finalized, so excluding | |
| 1319 | + // them here avoids a duplicate email for the same booking. Sent here | |
| 1320 | + // (after create_event) so the Google Meet link is present in the email. | |
| 1321 | + if ( 'created' === $action && 'failed' !== $status && ! in_array( $payment_method_l, ['stripe', 'paypal', 'woocommerce'], true ) ) { | |
| 1322 | + $is_email_to_customer = timetics_get_option( 'booking_created_customer'); | |
| 1323 | + $is_email_to_host = timetics_get_option( 'booking_created_host'); | |
| 1324 | + | |
| 1325 | + if ( $is_email_to_host ) { | |
| 1326 | + $new_event_email = new New_Event_Email( $booking ); | |
| 1327 | + $new_event_email->send(); | |
| 961 | 1328 | } |
| 962 | 1329 | |
| 963 | - } else { | |
| 964 | - $book_entry_data = [ | |
| 965 | - 'meeting_id' => $meeting->get_id(), | |
| 966 | - 'staff_id' => $staff->get_id(), | |
| 967 | - 'customer_id' => $customer->get_id(), | |
| 968 | - 'booking_id' => $booking->get_id(), | |
| 969 | - 'booked' => 1, | |
| 970 | - 'date' => $date_time->format( 'Y-m-d' ), | |
| 971 | - 'start' => $date_time->format( 'h:i a' ), | |
| 972 | - 'end' => $end_time->format( 'h:i a' ), | |
| 973 | - ]; | |
| 1330 | + if ( $is_email_to_customer ) { | |
| 1331 | + $new_event_customer_email = new New_Event_Customer_Email( $booking ); | |
| 1332 | + $new_event_customer_email->send(); | |
| 1333 | + } | |
| 974 | 1334 | |
| 975 | - $book_entry_data = apply_filters( 'timetics_booking_schedule', $book_entry_data, $data ); | |
| 976 | - $booking_entry->create( $book_entry_data ); | |
| 1335 | + do_action( 'timetics_gln_hook', 'booking_created', Notification::get_hook_data( $booking ) ); | |
| 977 | 1336 | } |
| 978 | 1337 | |
| 979 | 1338 | // Fire after booking schedule create. |
| 980 | 1339 | do_action( 'timetics_after_booking_schedule', $booking->get_id(), $customer->get_id(), $meeting->get_id(), $data ); |
| @@ -996,9 +1355,9 @@ | ||
| 996 | 1355 | * @param integer $booking_id |
| 997 | 1356 | * |
| 998 | 1357 | * @return array |
| 999 | 1358 | */ |
| 1000 | - public function prepare_item( $booking_id ) { | |
| 1359 | + public function prepare_item( $booking_id, $expose_token = true ) { | |
| 1001 | 1360 | $booking = new Booking( $booking_id ); |
| 1002 | 1361 | $appointment = new Appointment( $booking->get_appointment() ); |
| 1003 | 1362 | $staff = new Staff( $booking->get_staff_id() ); |
| 1004 | 1363 | $customer = new Customer( $booking->get_customer_id() ); |
| @@ -1013,24 +1372,33 @@ | ||
| 1013 | 1372 | $join_link = 'google-meet' === $booking->get_location_type() && ! empty( $event['hangoutLink'] ) ? $event['hangoutLink'] : ''; |
| 1014 | 1373 | |
| 1015 | 1374 | $booking_title = $appointment->is_appointment() ? $appointment->get_name() : $booking->get_appointment_name(); |
| 1016 | 1375 | |
| 1376 | + $payment_details_raw = $booking->get_payment_details(); | |
| 1377 | + $payment_details = is_array( $payment_details_raw ) ? $payment_details_raw : []; | |
| 1378 | + | |
| 1017 | 1379 | $response = [ |
| 1018 | - 'id' => $booking->get_id(), | |
| 1019 | - 'random_id' => $booking->get_random_id(), | |
| 1020 | - 'status' => $booking->get_status(), | |
| 1021 | - 'order_total' => $booking->get_total(), | |
| 1022 | - 'start_date' => $start_date_time->format( 'Y-m-d' ), | |
| 1023 | - 'end_date' => $end_date_time->format( 'Y-m-d' ), | |
| 1024 | - 'date' => $date, | |
| 1025 | - 'start_time' => $start_date_time->format( 'h:i a' ), | |
| 1026 | - 'end_time' => $end_date_time->format( 'h:i a' ), | |
| 1027 | - 'booking_time' => $booking->get_booking_time(), | |
| 1028 | - 'location' => $booking->get_location(), | |
| 1029 | - 'location_type' => $booking->get_location_type(), | |
| 1030 | - 'description' => $booking->get_description(), | |
| 1031 | - 'cancel_reason' => $booking->get_cancel_reason(), | |
| 1032 | - 'security_token'=> $booking->get_security_token(), | |
| 1380 | + 'id' => $booking->get_id(), | |
| 1381 | + 'random_id' => $booking->get_random_id(), | |
| 1382 | + 'status' => $booking->get_status(), | |
| 1383 | + 'order_total' => $booking->get_total(), | |
| 1384 | + 'start_date' => $start_date_time->format( 'Y-m-d' ), | |
| 1385 | + 'end_date' => $end_date_time->format( 'Y-m-d' ), | |
| 1386 | + 'date' => $date, | |
| 1387 | + 'start_time' => $start_date_time->format( 'h:i a' ), | |
| 1388 | + 'end_time' => $end_date_time->format( 'h:i a' ), | |
| 1389 | + 'booking_time' => $booking->get_booking_time(), | |
| 1390 | + 'location' => $booking->get_location(), | |
| 1391 | + 'location_type' => $booking->get_location_type(), | |
| 1392 | + 'description' => $booking->get_description(), | |
| 1393 | + 'cancel_reason' => $booking->get_cancel_reason(), | |
| 1394 | + // Listing endpoints (get_items / get_booking_list) pass $expose_token = false — | |
| 1395 | + // a viewer browsing many bookings at once has no legitimate need for every | |
| 1396 | + // one's bearer token; single-booking reads (create/get/update) keep it. | |
| 1397 | + 'security_token' => $expose_token ? $booking->get_security_token() : '', | |
| 1398 | + 'payment_method' => $booking->get_payment_method(), | |
| 1399 | + 'payment_status' => $booking->get_payment_status(), | |
| 1400 | + 'payment_details' => $payment_details, | |
| 1033 | 1401 | 'customer' => [ |
| 1034 | 1402 | 'id' => $customer->get_id(), |
| 1035 | 1403 | 'full_name' => $customer->get_display_name(), |
| 1036 | 1404 | 'first_name' => $customer->get_first_name(), |
| @@ -1095,39 +1463,27 @@ | ||
| 1095 | 1463 | |
| 1096 | 1464 | return new WP_HTTP_Response( $data, 403 ); |
| 1097 | 1465 | } |
| 1098 | 1466 | |
| 1099 | - $booking_entry = new Booking_Entry(); | |
| 1100 | 1467 | |
| 1101 | - $date_time = timetics_convert_timezone( $booking->get_start_date() . ' ' . $booking->get_start_time(), $booking->get_timezone(), $meeting->get_timezone() ); | |
| 1468 | + $booking->release_slot(); | |
| 1102 | 1469 | |
| 1103 | - $entries = $booking_entry->find( | |
| 1104 | - [ | |
| 1105 | - 'staff_id' => $booking->get_staff_id(), | |
| 1106 | - 'meeting_id' => $booking->get_appointment(), | |
| 1107 | - 'date' => $date_time->format( 'Y-m-d' ), | |
| 1108 | - 'start' => $date_time->format( 'h:i a' ), | |
| 1109 | - ] | |
| 1110 | - ); | |
| 1470 | + $recurrences = $booking->get_recurrence(); | |
| 1111 | 1471 | |
| 1112 | - if ( $entries ) { | |
| 1113 | - $entry = $booking_entry->first(); | |
| 1472 | + /** | |
| 1473 | + * Fired before a booking is deleted, while its data can still be read. | |
| 1474 | + * | |
| 1475 | + * `timetics_after_booking_delete` runs after the post has already gone | |
| 1476 | + * and only receives the recurrence data, so an integration that needs | |
| 1477 | + * the booking, customer or meeting has to listen here instead. | |
| 1478 | + * | |
| 1479 | + * @param int $booking_id Booking ID. | |
| 1480 | + * @param int $customer_id Customer ID. | |
| 1481 | + * @param int $meeting_id Meeting (appointment) ID. | |
| 1482 | + * @param array $data Request data. | |
| 1483 | + */ | |
| 1484 | + do_action( 'timetics_before_booking_delete', $booking->get_id(), $booking->get_customer_id(), $meeting->get_id(), [] ); | |
| 1114 | 1485 | |
| 1115 | - if ( 'one-to-one' == strtolower( $meeting->get_type() ) ) { | |
| 1116 | - $entry->delete(); | |
| 1117 | - } else { | |
| 1118 | - $booked = intval( $entry->get_booked() ) - 1; | |
| 1119 | - $booked_seat = ! empty( $booking->get_seat() ) ? $booking->get_seat() : []; | |
| 1120 | - $existing_seat = ! empty( $entry->get_seats() ) ? $entry->get_seats() : []; | |
| 1121 | - | |
| 1122 | - $entry->update( [ | |
| 1123 | - 'booked' => $booked, | |
| 1124 | - 'seats' => array_values( array_diff( $existing_seat, $booked_seat ) ), | |
| 1125 | - ] ); | |
| 1126 | - } | |
| 1127 | - } | |
| 1128 | - | |
| 1129 | - $recurrences = $booking->get_recurrence(); | |
| 1130 | 1486 | $booking->delete_event(); |
| 1131 | 1487 | $booking->delete(); |
| 1132 | 1488 | |
| 1133 | 1489 | $is_email_to_customer = timetics_get_option( 'booking_canceled_customer'); |
| @@ -1143,10 +1499,12 @@ | ||
| 1143 | 1499 | $customer_cancel_event_email = new Cancel_Event_Customer_Email( $booking ); |
| 1144 | 1500 | $customer_cancel_event_email->send(); |
| 1145 | 1501 | } |
| 1146 | 1502 | |
| 1503 | + do_action( 'timetics_gln_hook', 'booking_canceled', Notification::get_hook_data( $booking ) ); | |
| 1147 | 1504 | |
| 1148 | 1505 | |
| 1506 | + | |
| 1149 | 1507 | do_action( 'timetics_after_booking_delete', $recurrences ); |
| 1150 | 1508 | |
| 1151 | 1509 | return true; |
| 1152 | 1510 | } |
| @@ -1158,36 +1516,57 @@ | ||
| 1158 | 1516 | $booking_entry = new Booking_Entry(); |
| 1159 | 1517 | $meeting_id = $meeting->get_id(); |
| 1160 | 1518 | $staff_id = $booking_data['staff_id']; |
| 1161 | 1519 | |
| 1162 | - $time = is_string( $start_time ) ? strtotime( $start_time ) : $start_time; | |
| 1163 | - $time = gmdate( 'H:i', $time ); | |
| 1164 | 1520 | $booking_entries = new Booking_Entry(); |
| 1165 | 1521 | $meeting = new Appointment( $meeting_id ); |
| 1522 | + $slot_datetime = timetics_convert_timezone( $start_date . ' ' . $start_time, $booking_timezone, $meeting->get_timezone() ); | |
| 1166 | 1523 | |
| 1167 | 1524 | $entries = $booking_entries->find( [ |
| 1168 | 1525 | 'meeting_id' => $meeting_id, |
| 1169 | 1526 | 'staff_id' => $staff_id, |
| 1170 | - 'date' => $start_date, | |
| 1527 | + 'date' => $slot_datetime->format( 'Y-m-d' ), | |
| 1528 | + 'start' => $slot_datetime->format( 'h:i a' ), | |
| 1171 | 1529 | ] ); |
| 1172 | 1530 | |
| 1173 | - $booked = false; | |
| 1531 | + $booked = $entries ? $booking_entries->first() : false; | |
| 1174 | 1532 | |
| 1175 | - foreach ( $entries as $entry ) { | |
| 1176 | - $booking = new Booking( $entry->get_booking_id() ); | |
| 1177 | - $booking_time = timetics_convert_timezone( $booking->get_start_date() . ' ' . $entry->get_start(), $booking->get_timezone(), $booking_timezone )->format( 'H:i' ); | |
| 1178 | - | |
| 1179 | - if ( $booking_time == $time ) { | |
| 1180 | - $booked = $entry; | |
| 1181 | - break; | |
| 1182 | - } | |
| 1533 | + if ( $booked && intval( $booked->get_booked() ) >= $meeting->get_effective_capacity() ) { | |
| 1534 | + return false; | |
| 1183 | 1535 | } |
| 1184 | 1536 | |
| 1185 | - if ( $booked && $booked->get_booked() >= $meeting->get_capacity() ) { | |
| 1186 | - return false; | |
| 1187 | - } | |
| 1537 | + /** | |
| 1538 | + * Let integrations veto a slot at booking time. | |
| 1539 | + * | |
| 1540 | + * Slot listing is filtered separately, so without this a client posting | |
| 1541 | + * straight to the REST endpoint could still book a slot that the UI | |
| 1542 | + * hides — which is how a Google Calendar conflict turned into a real | |
| 1543 | + * double booking. Integrations must fail open: return true when they | |
| 1544 | + * cannot determine availability. | |
| 1545 | + * | |
| 1546 | + * @param bool $available | |
| 1547 | + * @param Appointment $meeting | |
| 1548 | + * @param array $booking_data | |
| 1549 | + */ | |
| 1550 | + return (bool) apply_filters( 'timetics_is_slot_available', true, $meeting, $booking_data ); | |
| 1551 | + } | |
| 1188 | 1552 | |
| 1189 | - return true; | |
| 1553 | + /** | |
| 1554 | + * Resolve what `timetics_booking_update_schedule` returned into an update payload. | |
| 1555 | + * | |
| 1556 | + * The filter passes the entry as its filtered value and the payload only as | |
| 1557 | + * an extra argument, so with nothing hooked it hands back the entry object. | |
| 1558 | + * Booking_Entry::update() then matches none of its keys and silently writes | |
| 1559 | + * nothing, leaving group counters frozen. Keep the published signature and | |
| 1560 | + * fall back to the payload whenever the result is not usable. | |
| 1561 | + * | |
| 1562 | + * @param mixed $filtered Whatever the filter returned. | |
| 1563 | + * @param integer $booked Counter this call meant to store. | |
| 1564 | + * | |
| 1565 | + * @return array | |
| 1566 | + */ | |
| 1567 | + private function normalize_schedule_update( $filtered, $booked ) { | |
| 1568 | + return is_array( $filtered ) ? $filtered : [ 'booked' => $booked ]; | |
| 1190 | 1569 | } |
| 1191 | 1570 | |
| 1192 | 1571 | /** |
| 1193 | 1572 | * Validates a booking. |
| @@ -1295,12 +1674,12 @@ | ||
| 1295 | 1674 | if (!$booking->is_booking()) { |
| 1296 | 1675 | return false; |
| 1297 | 1676 | } |
| 1298 | 1677 | |
| 1299 | - // Guests: must provide a valid token | |
| 1678 | + // Guests: must provide a valid token (constant-time compare). | |
| 1300 | 1679 | if ( ! empty( $appointment_token ) ) { |
| 1301 | - $stored_token = $booking->get_security_token(); | |
| 1302 | - if ($appointment_token === $stored_token && !empty($stored_token)) { | |
| 1680 | + $stored_token = (string) $booking->get_security_token(); | |
| 1681 | + if ( '' !== $stored_token && hash_equals( $stored_token, (string) $appointment_token ) ) { | |
| 1303 | 1682 | return true; |
| 1304 | 1683 | } |
| 1305 | 1684 | } |
| 1306 | 1685 | |
| @@ -1307,13 +1686,19 @@ | ||
| 1307 | 1686 | if (empty($booking_id) || ! wp_verify_nonce($nonce, 'wp_rest')) { |
| 1308 | 1687 | return false; |
| 1309 | 1688 | } |
| 1310 | 1689 | |
| 1311 | - // Allow booking owner or admins/managers. | |
| 1312 | - if ( (int) $booking->get_customer_id() === get_current_user_id() || current_user_can( 'manage_timetics' )) { | |
| 1690 | + // manage_timetics is not admin-only — every staff account holds it — so it | |
| 1691 | + // cannot stand in for an ownership check. Real admins, the booking's own | |
| 1692 | + // customer, or staff this specific booking is actually visible to. | |
| 1693 | + if ( | |
| 1694 | + ( get_current_user_id() > 0 && (int) $booking->get_customer_id() === get_current_user_id() ) | |
| 1695 | + || timetics_can_view_all_data() | |
| 1696 | + || in_array( $booking_id, timetics_get_visible_booking_ids(), true ) | |
| 1697 | + ) { | |
| 1313 | 1698 | return true; |
| 1314 | 1699 | } |
| 1315 | - | |
| 1700 | + | |
| 1316 | 1701 | return false; |
| 1317 | 1702 | } |
| 1318 | 1703 | |
| 1319 | 1704 | /** |
| @@ -1331,19 +1716,28 @@ | ||
| 1331 | 1716 | if (!$booking->is_booking()) { |
| 1332 | 1717 | return false; |
| 1333 | 1718 | } |
| 1334 | 1719 | |
| 1335 | - // Guests: must provide a valid token | |
| 1720 | + // Guests: must provide a valid token (constant-time compare). | |
| 1336 | 1721 | if ( ! empty( $appointment_token ) ) { |
| 1337 | - $stored_token = $booking->get_security_token(); | |
| 1338 | - if ($appointment_token === $stored_token && !empty($stored_token)) { | |
| 1722 | + $stored_token = (string) $booking->get_security_token(); | |
| 1723 | + if ( '' !== $stored_token && hash_equals( $stored_token, (string) $appointment_token ) ) { | |
| 1339 | 1724 | return true; |
| 1340 | 1725 | } |
| 1341 | - } | |
| 1726 | + } | |
| 1342 | 1727 | |
| 1343 | - if (wp_verify_nonce($nonce, 'wp_rest') && current_user_can( 'manage_timetics' ) ) { | |
| 1728 | + if ( ! wp_verify_nonce( $nonce, 'wp_rest' ) ) { | |
| 1729 | + return false; | |
| 1730 | + } | |
| 1731 | + | |
| 1732 | + if ( | |
| 1733 | + ( get_current_user_id() > 0 && (int) $booking->get_customer_id() === get_current_user_id() ) | |
| 1734 | + || timetics_can_view_all_data() | |
| 1735 | + || in_array( $booking_id, timetics_get_visible_booking_ids(), true ) | |
| 1736 | + ) { | |
| 1344 | 1737 | return true; |
| 1345 | 1738 | } |
| 1739 | + | |
| 1346 | 1740 | return false; |
| 1347 | 1741 | } |
| 1348 | 1742 | |
| 1349 | 1743 | /** |
| @@ -1357,10 +1751,10 @@ | ||
| 1357 | 1751 | * |
| 1358 | 1752 | * @return string|WP_Error Returns the validated email on success, WP_Error on failure. |
| 1359 | 1753 | */ |
| 1360 | 1754 | private function validate_email_change_permission( $booking_id, $new_email ) { |
| 1361 | - // Admin users have full permission to change email addresses | |
| 1362 | - if ( current_user_can( 'manage_timetics' ) ) { | |
| 1755 | + // manage_timetics is not admin-only — every staff account holds it. | |
| 1756 | + if ( timetics_can_view_all_data() ) { | |
| 1363 | 1757 | return $new_email; |
| 1364 | 1758 | } |
| 1365 | 1759 | |
| 1366 | 1760 | $existing_booking = new Booking( $booking_id ); |
| @@ -1386,34 +1780,179 @@ | ||
| 1386 | 1780 | |
| 1387 | 1781 | return $original_email; |
| 1388 | 1782 | } |
| 1389 | 1783 | |
| 1784 | + /** | |
| 1785 | + * Bind a Stripe PaymentIntent to a booking by writing the booking_id and security_token into the PaymentIntent's metadata. | |
| 1786 | + * | |
| 1787 | + * @param \WP_REST_Request $request | |
| 1788 | + * @return \WP_HTTP_Response | |
| 1789 | + */ | |
| 1790 | + public function bind_payment_intent( $request ) { | |
| 1791 | + $booking_id = (int) $request['booking_id']; | |
| 1792 | + $booking = new Booking( $booking_id ); | |
| 1793 | + | |
| 1794 | + if ( ! $booking->is_booking() ) { | |
| 1795 | + return new WP_HTTP_Response( | |
| 1796 | + [ | |
| 1797 | + 'success' => 0, | |
| 1798 | + 'status_code' => 404, | |
| 1799 | + 'message' => esc_html__( 'Invalid booking id.', 'timetics' ), | |
| 1800 | + ], | |
| 1801 | + 404 | |
| 1802 | + ); | |
| 1803 | + } | |
| 1804 | + | |
| 1805 | + $body = json_decode( $request->get_body(), true ); | |
| 1806 | + $body = is_array( $body ) ? $body : []; | |
| 1807 | + $intent_id = ! empty( $body['payment_intent_id'] ) ? sanitize_text_field( (string) $body['payment_intent_id'] ) : ''; | |
| 1808 | + | |
| 1809 | + if ( '' === $intent_id || strpos( $intent_id, 'pi_' ) !== 0 ) { | |
| 1810 | + return new WP_HTTP_Response( | |
| 1811 | + [ | |
| 1812 | + 'success' => 0, | |
| 1813 | + 'status_code' => 400, | |
| 1814 | + 'message' => esc_html__( 'Invalid payment intent id.', 'timetics' ), | |
| 1815 | + ], | |
| 1816 | + 400 | |
| 1817 | + ); | |
| 1818 | + } | |
| 1819 | + | |
| 1820 | + $stripe = new StripePayment(); | |
| 1821 | + | |
| 1822 | + $bound = $booking->get_stripe_payment_intent_id(); | |
| 1823 | + if ( '' !== $bound && $bound !== $intent_id ) { | |
| 1824 | + return new WP_HTTP_Response( | |
| 1825 | + [ | |
| 1826 | + 'success' => 0, | |
| 1827 | + 'status_code' => 409, | |
| 1828 | + 'message' => esc_html__( 'Booking already bound to another payment intent.', 'timetics' ), | |
| 1829 | + ], | |
| 1830 | + 409 | |
| 1831 | + ); | |
| 1832 | + } | |
| 1833 | + | |
| 1834 | + $intent = $stripe->retrieve_payment_intent( $intent_id ); | |
| 1835 | + | |
| 1836 | + if ( is_wp_error( $intent ) || ! is_array( $intent ) || empty( $intent['id'] ) ) { | |
| 1837 | + return new WP_HTTP_Response( | |
| 1838 | + [ | |
| 1839 | + 'success' => 0, | |
| 1840 | + 'status_code' => 502, | |
| 1841 | + 'message' => esc_html__( 'Cannot verify payment intent with Stripe.', 'timetics' ), | |
| 1842 | + ], | |
| 1843 | + 502 | |
| 1844 | + ); | |
| 1845 | + } | |
| 1846 | + | |
| 1847 | + $expected_amount = (int) round( (float) $booking->get_total() * 100 ); | |
| 1848 | + $expected_currency = strtolower( (string) apply_filters( 'timetics_currency', timetics_get_option( 'currency', 'USD' ) ) ); | |
| 1849 | + $intent_amount = isset( $intent['amount'] ) ? (int) $intent['amount'] : 0; | |
| 1850 | + $intent_currency = isset( $intent['currency'] ) ? strtolower( (string) $intent['currency'] ) : ''; | |
| 1851 | + $intent_meta_book = isset( $intent['metadata']['booking_id'] ) ? (int) $intent['metadata']['booking_id'] : 0; | |
| 1852 | + | |
| 1853 | + if ( $expected_amount <= 0 || $intent_amount !== $expected_amount || $intent_currency !== $expected_currency ) { | |
| 1854 | + return new WP_HTTP_Response( | |
| 1855 | + [ | |
| 1856 | + 'success' => 0, | |
| 1857 | + 'status_code' => 409, | |
| 1858 | + 'message' => esc_html__( 'Payment intent does not match this booking.', 'timetics' ), | |
| 1859 | + ], | |
| 1860 | + 409 | |
| 1861 | + ); | |
| 1862 | + } | |
| 1863 | + | |
| 1864 | + if ( 0 !== $intent_meta_book && $booking_id !== $intent_meta_book ) { | |
| 1865 | + return new WP_HTTP_Response( | |
| 1866 | + [ | |
| 1867 | + 'success' => 0, | |
| 1868 | + 'status_code' => 409, | |
| 1869 | + 'message' => esc_html__( 'Payment intent is bound to another booking.', 'timetics' ), | |
| 1870 | + ], | |
| 1871 | + 409 | |
| 1872 | + ); | |
| 1873 | + } | |
| 1874 | + | |
| 1875 | + // A previous decline released this booking's slot. Bind runs before the card | |
| 1876 | + // is charged, so it is the last safe point to take the slot back — refusing | |
| 1877 | + // here costs the customer nothing, refusing after payment would take their | |
| 1878 | + // money for a time somebody else now holds. | |
| 1879 | + if ( ! $booking->reserve_slot() ) { | |
| 1880 | + return new WP_HTTP_Response( | |
| 1881 | + [ | |
| 1882 | + 'success' => 0, | |
| 1883 | + 'status_code' => 409, | |
| 1884 | + 'message' => esc_html__( 'This time slot is no longer available. Please pick another time.', 'timetics' ), | |
| 1885 | + ], | |
| 1886 | + 409 | |
| 1887 | + ); | |
| 1888 | + } | |
| 1889 | + | |
| 1890 | + $result = $stripe->update_payment_intent( | |
| 1891 | + $intent_id, | |
| 1892 | + [ | |
| 1893 | + 'booking_id' => $booking_id, | |
| 1894 | + 'security_token' => (string) $booking->get_security_token(), | |
| 1895 | + ] | |
| 1896 | + ); | |
| 1897 | + | |
| 1898 | + if ( is_wp_error( $result ) ) { | |
| 1899 | + return new WP_HTTP_Response( | |
| 1900 | + [ | |
| 1901 | + 'success' => 0, | |
| 1902 | + 'status_code' => 502, | |
| 1903 | + 'message' => $result->get_error_message(), | |
| 1904 | + ], | |
| 1905 | + 502 | |
| 1906 | + ); | |
| 1907 | + } | |
| 1908 | + | |
| 1909 | + // Record the intent id now (not just at make_payment finalize) so the | |
| 1910 | + // unpaid-booking cleanup sweep can check Stripe before cancelling. | |
| 1911 | + $booking->set_stripe_payment_intent_id( $intent_id ); | |
| 1912 | + | |
| 1913 | + return new WP_HTTP_Response( | |
| 1914 | + [ | |
| 1915 | + 'success' => 1, | |
| 1916 | + 'status_code' => 200, | |
| 1917 | + 'message' => esc_html__( 'Payment intent bound.', 'timetics' ), | |
| 1918 | + ], | |
| 1919 | + 200 | |
| 1920 | + ); | |
| 1921 | + } | |
| 1922 | + | |
| 1390 | 1923 | public function make_payment_permission_callback( $request ) { |
| 1391 | 1924 | |
| 1392 | 1925 | $booking_id = (int) $request->get_param('booking_id'); |
| 1393 | 1926 | $appointment_token = sanitize_text_field( $request->get_param('appointment_token') ); |
| 1394 | - | |
| 1927 | + | |
| 1395 | 1928 | if ( empty( $booking_id ) || empty( $appointment_token ) ) { |
| 1396 | 1929 | return false; |
| 1397 | 1930 | } |
| 1398 | - | |
| 1931 | + | |
| 1399 | 1932 | $booking = new Booking( $booking_id ); |
| 1400 | - | |
| 1933 | + | |
| 1401 | 1934 | if ( ! $booking->is_booking() ) { |
| 1402 | 1935 | return false; |
| 1403 | 1936 | } |
| 1404 | - | |
| 1937 | + | |
| 1405 | 1938 | $stored_token = $booking->get_security_token(); |
| 1406 | - | |
| 1939 | + | |
| 1407 | 1940 | if ( empty( $stored_token ) ) { |
| 1408 | 1941 | return false; |
| 1409 | 1942 | } |
| 1410 | - | |
| 1943 | + | |
| 1411 | 1944 | // constant-time comparison |
| 1412 | - if ( hash_equals( $stored_token, $appointment_token ) ) { | |
| 1413 | - return true; | |
| 1945 | + if ( ! hash_equals( $stored_token, $appointment_token ) ) { | |
| 1946 | + return false; | |
| 1414 | 1947 | } |
| 1415 | - | |
| 1416 | - return false; | |
| 1948 | + // A declined card leaves the booking 'failed' and the customer retries on that | |
| 1949 | + // same booking, so 'failed' has to pass too. Anything further along | |
| 1950 | + // ( approved / completed / cancelled ) is finished and must never be payable. | |
| 1951 | + if ( ! in_array( (string) $booking->get_status(), [ 'pending', 'failed' ], true ) ) { | |
| 1952 | + return false; | |
| 1953 | + } | |
| 1954 | + | |
| 1955 | + return true; | |
| 1417 | 1956 | } |
| 1418 | 1957 | |
| 1419 | 1958 | } |