| @@ -6,8 +6,10 @@ | ||
| 6 | 6 | */ |
| 7 | 7 | |
| 8 | 8 | namespace Timetics\Core\Integrations\Woocommerce; |
| 9 | 9 | |
| 10 | +defined( 'ABSPATH' ) || exit; | |
| 11 | + | |
| 10 | 12 | use Timetics\Base\Api; |
| 11 | 13 | use Timetics\Core\Appointments\Appointment; |
| 12 | 14 | use Timetics\Utils\Singleton; |
| 13 | 15 | |
| @@ -65,17 +67,54 @@ | ||
| 65 | 67 | public function set_up_woocommerce( $requst ) { |
| 66 | 68 | $data = json_decode( $requst->get_body(), true ); |
| 67 | 69 | |
| 68 | 70 | $booking_id = ! empty( $data['booking_id'] ) ? intval( $data['booking_id'] ) : 0; |
| 69 | - $meeting_id = ! empty( $data['meeting_id'] ) ? intval( $data['meeting_id'] ) : 0; | |
| 70 | - $price = ! empty( $data['price'] ) ? intval( $data['price'] ) : 0; | |
| 71 | + $token = ! empty( $data['security_token'] ) ? sanitize_text_field( $data['security_token'] ) : ''; | |
| 71 | 72 | |
| 73 | + $booking = new \Timetics\Core\Bookings\Booking( $booking_id ); | |
| 74 | + // everything from the booking record itself once ownership is proven. | |
| 75 | + if ( ! $booking_id || '' === $token || ! $booking->is_booking() ) { | |
| 76 | + return new \WP_HTTP_Response( | |
| 77 | + [ | |
| 78 | + 'success' => 0, | |
| 79 | + 'status_code' => 404, | |
| 80 | + 'message' => __( 'Invalid booking.', 'timetics' ), | |
| 81 | + ], | |
| 82 | + 404 | |
| 83 | + ); | |
| 84 | + } | |
| 85 | + | |
| 86 | + $stored = (string) $booking->get_security_token(); | |
| 87 | + | |
| 88 | + if ( '' === $stored || ! hash_equals( $stored, $token ) ) { | |
| 89 | + return new \WP_HTTP_Response( | |
| 90 | + [ | |
| 91 | + 'success' => 0, | |
| 92 | + 'status_code' => 403, | |
| 93 | + 'message' => __( 'Invalid booking token.', 'timetics' ), | |
| 94 | + ], | |
| 95 | + 403 | |
| 96 | + ); | |
| 97 | + } | |
| 98 | + | |
| 99 | + $meeting_id = (int) $booking->get_appointment(); | |
| 100 | + $price = (int) $booking->get_total(); | |
| 101 | + | |
| 102 | + // Hooks::add_product_to_cart() already ran on timetics_after_booking_create and | |
| 103 | + // stored the meeting details ( date, time, duration, timezone, location ) in this | |
| 104 | + // session. Keep them - overwriting the whole array would drop them before checkout. | |
| 105 | + $session_data = WC()->session->get( 'timetics_data' ); | |
| 106 | + | |
| 107 | + if ( ! is_array( $session_data ) || empty( $session_data['booking_id'] ) || (int) $session_data['booking_id'] !== $booking_id ) { | |
| 108 | + $session_data = []; | |
| 109 | + } | |
| 110 | + | |
| 72 | 111 | // Set session for timetics data for woocommerce. |
| 73 | - WC()->session->set( 'timetics_data', [ | |
| 112 | + WC()->session->set( 'timetics_data', array_merge( $session_data, [ | |
| 74 | 113 | 'booking_id' => $booking_id, |
| 75 | 114 | 'meeting_id' => $meeting_id, |
| 76 | 115 | 'price' => $price, |
| 77 | - ] ); | |
| 116 | + ] ) ); | |
| 78 | 117 | |
| 79 | 118 | // Remove all items from cart. |
| 80 | 119 | WC()->cart->empty_cart(); |
| 81 | 120 | |