| @@ -5,13 +5,17 @@ | ||
| 5 | 5 | * @package Timetics |
| 6 | 6 | */ |
| 7 | 7 | namespace Timetics\Core\Bookings; |
| 8 | 8 | |
| 9 | +defined( 'ABSPATH' ) || exit; | |
| 10 | + | |
| 9 | 11 | use Error; |
| 10 | 12 | use Timetics\Base\Api; |
| 11 | 13 | use Timetics\Core\Appointments\Api_Appointment; |
| 12 | 14 | use Timetics\Core\Appointments\Appointment; |
| 13 | 15 | use Timetics\Core\Customers\Customer; |
| 16 | +use Timetics\Core\Admin\Notification; | |
| 17 | +use Timetics\Core\Admin\Notification_Flow_Guard; | |
| 14 | 18 | use Timetics\Core\Emails\Cancel_Event_Customer_Email; |
| 15 | 19 | use Timetics\Core\Emails\Cancel_Event_Email; |
| 16 | 20 | use Timetics\Core\Emails\New_Event_Customer_Email; |
| 17 | 21 | use Timetics\Core\Emails\New_Event_Email; |
| @@ -138,9 +142,11 @@ | ||
| 138 | 142 | [ |
| 139 | 143 | 'methods' => \WP_REST_Server::READABLE, |
| 140 | 144 | 'callback' => [$this, 'search_items'], |
| 141 | 145 | 'permission_callback' => function () { |
| 142 | - return current_user_can( 'edit_posts' ); | |
| 146 | + // edit_booking is admin-only in this plugin (see get_items()) — | |
| 147 | + // staff need manage_timetics to search their own bookings at all. | |
| 148 | + return current_user_can( 'manage_timetics' ) || current_user_can( 'manage_options' ); | |
| 143 | 149 | }, |
| 144 | 150 | ], |
| 145 | 151 | ] |
| 146 | 152 | ); |
| @@ -203,9 +209,9 @@ | ||
| 203 | 209 | $bookings = Booking::all( $args ); |
| 204 | 210 | $items = []; |
| 205 | 211 | |
| 206 | 212 | foreach ( $bookings['items'] as $item ) { |
| 207 | - $items[] = $this->prepare_item( $item->ID ); | |
| 213 | + $items[] = $this->prepare_item( $item->ID, false ); | |
| 208 | 214 | } |
| 209 | 215 | |
| 210 | 216 | /** |
| 211 | 217 | * Added temporary for leagacy sass. It will remove in future. |
| @@ -433,16 +439,25 @@ | ||
| 433 | 439 | $per_page = ! empty( $request['per_page'] ) ? intval( $request['per_page'] ) : 20; |
| 434 | 440 | $paged = ! empty( $request['paged'] ) ? intval( $request['paged'] ) : 1; |
| 435 | 441 | $search = ! empty( $request['search'] ) ? sanitize_text_field( $request['search'] ) : ''; |
| 436 | 442 | |
| 443 | + $query_args = array( | |
| 444 | + 'post_type' => 'timetics-booking', | |
| 445 | + 'posts_per_page' => $per_page, | |
| 446 | + 'paged' => $paged, | |
| 447 | + 'post_status' => 'any', | |
| 448 | + ); | |
| 449 | + | |
| 450 | + if ( ! current_user_can( 'manage_options' ) ) { | |
| 451 | + $allowed_ids = Booking::get_visible_ids_for_user( get_current_user_id() ); | |
| 452 | + $query_args['post__in'] = ! empty( $allowed_ids ) ? $allowed_ids : [ 0 ]; | |
| 453 | + } | |
| 454 | + | |
| 437 | 455 | // Get search. |
| 438 | 456 | $booking = new WP_Query( |
| 439 | - array( | |
| 440 | - 'post_type' => 'timetics-booking', | |
| 441 | - 'posts_per_page' => $per_page, | |
| 442 | - 'paged' => $paged, | |
| 443 | - 'post_status' => 'any', | |
| 444 | - | |
| 457 | + array_merge( | |
| 458 | + $query_args, | |
| 459 | + array( | |
| 445 | 460 | // @codingStandardsIgnoreStart |
| 446 | 461 | 'meta_query' => array( |
| 447 | 462 | 'relation' => 'OR', |
| 448 | 463 | array( |
| @@ -496,8 +511,9 @@ | ||
| 496 | 511 | 'compare' => 'LIKE', |
| 497 | 512 | ), |
| 498 | 513 | ), |
| 499 | 514 | // @codingStandardsIgnoreEnd |
| 515 | + ) | |
| 500 | 516 | ) |
| 501 | 517 | ); |
| 502 | 518 | |
| 503 | 519 | // Prepare items for response. |
| @@ -503,9 +519,9 @@ | ||
| 503 | 519 | // Prepare items for response. |
| 504 | 520 | $items = []; |
| 505 | 521 | |
| 506 | 522 | foreach ( $booking->posts as $item ) { |
| 507 | - $items[] = $this->prepare_item( $item->ID ); | |
| 523 | + $items[] = $this->prepare_item( $item->ID, false ); | |
| 508 | 524 | } |
| 509 | 525 | |
| 510 | 526 | /** |
| 511 | 527 | * Added temporary for leagacy sass. It will remove in future. |
| @@ -600,10 +616,12 @@ | ||
| 600 | 616 | ); |
| 601 | 617 | } |
| 602 | 618 | |
| 603 | 619 | // Idempotency: refuse re-approval of a booking that already finalized. |
| 620 | + // 'failed' is deliberately not in this list — a declined card is a failed | |
| 621 | + // attempt, not a finished booking, and the customer retries on the same one. | |
| 604 | 622 | $current_status = (string) $booking->get_status(); |
| 605 | - $finalized_statuses = [ 'approved', 'completed', 'failed', 'cancelled', 'cancel' ]; | |
| 623 | + $finalized_statuses = [ 'approved', 'completed', 'cancelled', 'cancel' ]; | |
| 606 | 624 | if ( in_array( $current_status, $finalized_statuses, true ) ) { |
| 607 | 625 | return new WP_HTTP_Response( |
| 608 | 626 | [ |
| 609 | 627 | 'success' => 0, |
| @@ -701,8 +719,18 @@ | ||
| 701 | 719 | } |
| 702 | 720 | } elseif ( 'failed' === $client_status ) { |
| 703 | 721 | // Marking the user's own attempt as failed never grants access; safe to honor. |
| 704 | 722 | $verified_status = 'failed'; |
| 723 | + } else { | |
| 724 | + // Gateways that live outside this plugin ( PayPal ) check the payment | |
| 725 | + // against their own API and answer with the status they trust. The | |
| 726 | + // default stays 'pending', so a client that sends nothing verifiable | |
| 727 | + // cannot talk its way to 'succeeded'. | |
| 728 | + $verified_status = (string) apply_filters( 'timetics_verify_payment', $verified_status, $payment_method, $data, $booking ); | |
| 729 | + | |
| 730 | + if ( ! in_array( $verified_status, ['pending', 'failed', 'succeeded'], true ) ) { | |
| 731 | + $verified_status = 'pending'; | |
| 732 | + } | |
| 705 | 733 | } |
| 706 | 734 | // Other payment methods (cash, on-site, etc.) stay pending here. They |
| 707 | 735 | // are approved through their own authenticated/admin paths. |
| 708 | 736 | $post_status = 'succeeded' === $verified_status |
| @@ -711,11 +739,14 @@ | ||
| 711 | 739 | |
| 712 | 740 | $finalizing = 'succeeded' === $verified_status && '' !== $stored_intent_id; |
| 713 | 741 | |
| 714 | 742 | if ( $finalizing ) { |
| 715 | - $claimed = add_post_meta( $booking_id, '_tt_stripe_payment_intent_id', $stored_intent_id, true ); | |
| 743 | + // Separate key from _tt_stripe_payment_intent_id: that one is written at | |
| 744 | + // bind time (before payment) so the cleanup sweep can see it, so it can't | |
| 745 | + // double as a "not yet finalized" marker here — it always already exists. | |
| 746 | + $claimed = add_post_meta( $booking_id, '_tt_stripe_payment_finalized_intent_id', $stored_intent_id, true ); | |
| 716 | 747 | if ( false === $claimed ) { |
| 717 | - $existing = (string) get_post_meta( $booking_id, '_tt_stripe_payment_intent_id', true ); | |
| 748 | + $existing = (string) get_post_meta( $booking_id, '_tt_stripe_payment_finalized_intent_id', true ); | |
| 718 | 749 | if ( $existing !== $stored_intent_id ) { |
| 719 | 750 | return new WP_HTTP_Response( |
| 720 | 751 | [ |
| 721 | 752 | 'success' => 0, |
| @@ -750,9 +781,9 @@ | ||
| 750 | 781 | |
| 751 | 782 | if ( is_wp_error( $update ) ) { |
| 752 | 783 | // Roll back the claim so a retry can finalize cleanly. |
| 753 | 784 | if ( $finalizing ) { |
| 754 | - delete_post_meta( $booking_id, '_tt_stripe_payment_intent_id', $stored_intent_id ); | |
| 785 | + delete_post_meta( $booking_id, '_tt_stripe_payment_finalized_intent_id', $stored_intent_id ); | |
| 755 | 786 | } |
| 756 | 787 | return new WP_HTTP_Response( |
| 757 | 788 | [ |
| 758 | 789 | 'success' => 0, |
| @@ -763,9 +794,20 @@ | ||
| 763 | 794 | 409 |
| 764 | 795 | ); |
| 765 | 796 | } |
| 766 | 797 | |
| 767 | - if ( $default_booking_status === $post_status ) { | |
| 798 | + // A failed payment means the booking did not happen, so release the slot | |
| 799 | + // it was holding and let it appear as free again. | |
| 800 | + if ( 'failed' === $post_status ) { | |
| 801 | + $booking->release_slot(); | |
| 802 | + } | |
| 803 | + | |
| 804 | + // Approve, notify and burn the token only when the payment actually | |
| 805 | + // cleared. This used to compare $post_status against the site default, | |
| 806 | + // which is the very same string on a site whose default booking status | |
| 807 | + // is 'pending' - so an unverified attempt still sent the "meeting | |
| 808 | + // scheduled" emails and rotated the token without a penny being paid. | |
| 809 | + if ( 'succeeded' === $verified_status ) { | |
| 768 | 810 | // Rotate the security token so the same one cannot drive a second |
| 769 | 811 | // approval after this booking has finalized. |
| 770 | 812 | $booking->rotate_security_token(); |
| 771 | 813 | |
| @@ -787,8 +829,10 @@ | ||
| 787 | 829 | $new_event_customer_email = new New_Event_Customer_Email( $booking ); |
| 788 | 830 | $new_event_customer_email->send(); |
| 789 | 831 | } |
| 790 | 832 | |
| 833 | + do_action( 'timetics_gln_hook', 'booking_created', Notification::get_hook_data( $booking ) ); | |
| 834 | + | |
| 791 | 835 | do_action( 'timetics_booking_payment', $booking ); |
| 792 | 836 | |
| 793 | 837 | } |
| 794 | 838 | |
| @@ -891,9 +935,23 @@ | ||
| 891 | 935 | } else { |
| 892 | 936 | $status = $default_status; |
| 893 | 937 | } |
| 894 | 938 | } else { |
| 895 | - $current_status = ( new Booking( $id ) )->get_status(); | |
| 939 | + $current_booking = new Booking( $id ); | |
| 940 | + | |
| 941 | + // Reschedule only moves time. | |
| 942 | + if ( (int) $current_booking->get_appointment() !== $appointment ) { | |
| 943 | + return new WP_HTTP_Response( | |
| 944 | + [ | |
| 945 | + 'status_code' => 403, | |
| 946 | + 'success' => 0, | |
| 947 | + 'message' => esc_html__( 'You can not change the appointment of a booking.', 'timetics' ), | |
| 948 | + ], | |
| 949 | + 403 | |
| 950 | + ); | |
| 951 | + } | |
| 952 | + | |
| 953 | + $current_status = $current_booking->get_status(); | |
| 896 | 954 | if ( 'cancel' === $client_status ) { |
| 897 | 955 | $status = 'cancel'; |
| 898 | 956 | } else { |
| 899 | 957 | $status = $current_status; |
| @@ -917,20 +975,28 @@ | ||
| 917 | 975 | // Use the validated email from the security check |
| 918 | 976 | $email = $email_validation; |
| 919 | 977 | } |
| 920 | 978 | |
| 921 | - $validate = $this->validate( | |
| 922 | - $data, [ | |
| 923 | - 'first_name', | |
| 924 | - 'email', | |
| 925 | - 'payment_method', | |
| 926 | - 'appointment', | |
| 927 | - 'start_date', | |
| 928 | - 'start_time', | |
| 929 | - 'end_time', | |
| 930 | - ] | |
| 931 | - ); | |
| 979 | + $required_fields = [ | |
| 980 | + 'first_name', | |
| 981 | + 'email', | |
| 982 | + 'appointment', | |
| 983 | + 'start_date', | |
| 984 | + 'start_time', | |
| 985 | + 'end_time', | |
| 986 | + ]; | |
| 932 | 987 | |
| 988 | + // Payment method is only chosen once, at booking creation. Later | |
| 989 | + // updates (status change, reschedule, staff swap, ...) shouldn't have | |
| 990 | + // to resubmit it — requiring it here made admin actions like | |
| 991 | + // cancelling from the calendar popover fail whenever the form didn't | |
| 992 | + // carry the original payment method in its state. | |
| 993 | + if ( 'created' === $action ) { | |
| 994 | + $required_fields[] = 'payment_method'; | |
| 995 | + } | |
| 996 | + | |
| 997 | + $validate = $this->validate( $data, $required_fields ); | |
| 998 | + | |
| 933 | 999 | if ( is_wp_error( $validate ) ) { |
| 934 | 1000 | $data = [ |
| 935 | 1001 | 'status_code' => 403, |
| 936 | 1002 | 'success' => 0, |
| @@ -986,30 +1052,40 @@ | ||
| 986 | 1052 | 'phone' => $phone, |
| 987 | 1053 | ] |
| 988 | 1054 | ); |
| 989 | 1055 | |
| 990 | - // Update booking schedule. | |
| 1056 | + // Update booking schedule. Release the slot the booking currently holds; | |
| 1057 | + // the new one is taken further below. | |
| 991 | 1058 | if ( $id ) { |
| 1059 | + // Entries are stored in the meeting's timezone, so the booking's own | |
| 1060 | + // date/time has to be converted before the lookup. Without this the | |
| 1061 | + // entry is missed whenever the two timezones differ and it stays | |
| 1062 | + // behind blocking a slot nobody holds. | |
| 1063 | + $old_meeting = new Appointment( $booking->get_appointment() ); | |
| 1064 | + $old_datetime = timetics_convert_timezone( | |
| 1065 | + $booking->get_start_date() . ' ' . $booking->get_start_time(), | |
| 1066 | + $booking->get_timezone(), | |
| 1067 | + $old_meeting->get_timezone() | |
| 1068 | + ); | |
| 992 | 1069 | |
| 993 | 1070 | $entries = $booking_entry->find( |
| 994 | 1071 | [ |
| 995 | 1072 | 'staff_id' => $booking->get_staff_id(), |
| 996 | 1073 | 'meeting_id' => $booking->get_appointment(), |
| 997 | - 'date' => $booking->get_start_date(), | |
| 998 | - 'start' => $booking->get_start_time(), | |
| 1074 | + 'date' => $old_datetime->format( 'Y-m-d' ), | |
| 1075 | + 'start' => $old_datetime->format( 'h:i a' ), | |
| 999 | 1076 | ] |
| 1000 | - | |
| 1001 | 1077 | ); |
| 1002 | 1078 | |
| 1003 | 1079 | if ( $entries ) { |
| 1004 | 1080 | $entry = $booking_entry->first(); |
| 1005 | 1081 | |
| 1006 | - if ( 'one-to-one' == strtolower( $meeting->get_type() ) ) { | |
| 1082 | + if ( 'one-to-one' == strtolower( $old_meeting->get_type() ) ) { | |
| 1007 | 1083 | $entry->delete(); |
| 1008 | 1084 | } else { |
| 1009 | 1085 | $booked = intval( $entry->get_booked() ) - 1; |
| 1010 | 1086 | $booked_data = apply_filters( 'timetics_booking_update_schedule', $entry, ['booked' => $booked], $data, $booking ); |
| 1011 | - $entry->update( $booked_data ); | |
| 1087 | + $entry->update( $this->normalize_schedule_update( $booked_data, $booked ) ); | |
| 1012 | 1088 | } |
| 1013 | 1089 | } |
| 1014 | 1090 | } |
| 1015 | 1091 | |
| @@ -1038,9 +1114,9 @@ | ||
| 1038 | 1114 | 'date' => $date, |
| 1039 | 1115 | 'end_date' => $end_date, |
| 1040 | 1116 | 'start_time' => $start_time, |
| 1041 | 1117 | 'end_time' => $end_time, |
| 1042 | - 'order_total' => $this->calculate_order_total( $data ), | |
| 1118 | + 'order_total' => ( $id && ! $is_privileged ) ? $booking->get_total() : $this->calculate_order_total( $data ), | |
| 1043 | 1119 | 'post_status' => $status, |
| 1044 | 1120 | 'location' => $location, |
| 1045 | 1121 | 'location_type' => $location_type, |
| 1046 | 1122 | 'timezone' => $timezone, |
| @@ -1046,12 +1122,23 @@ | ||
| 1046 | 1122 | 'timezone' => $timezone, |
| 1047 | 1123 | 'cancel_reason' => $cancel_reason, |
| 1048 | 1124 | ]; |
| 1049 | 1125 | |
| 1126 | + if ( 'created' === $action && '' !== $payment_method ) { | |
| 1127 | + $booking_props['payment_method'] = $payment_method; | |
| 1128 | + } | |
| 1129 | + | |
| 1130 | + $old_meeting_timestamp = 0; | |
| 1131 | + | |
| 1050 | 1132 | if ( $id ) { |
| 1051 | 1133 | $old_start_date = $booking->get_start_date(); |
| 1052 | 1134 | $old_start_time = $booking->get_start_time(); |
| 1053 | 1135 | $old_end_time = $booking->get_end_time(); |
| 1136 | + | |
| 1137 | + // Captured before the props are overwritten so pending delayed | |
| 1138 | + // flows can be matched against the meeting time they were frozen | |
| 1139 | + // with. | |
| 1140 | + $old_meeting_timestamp = Notification::get_booking_timestamp( $booking ); | |
| 1054 | 1141 | } |
| 1055 | 1142 | |
| 1056 | 1143 | if( 'created' == $action ){ |
| 1057 | 1144 | $booking_props['security_token'] = $booking->generate_security_token(); |
| @@ -1066,27 +1153,13 @@ | ||
| 1066 | 1153 | |
| 1067 | 1154 | // Fire when booking is completed. |
| 1068 | 1155 | do_action( 'timetics_after_booking_create', $booking->get_id(), $customer->get_id(), $meeting->get_id(), $data ); |
| 1069 | 1156 | |
| 1070 | - // Send booking creation emails for new bookings not processed through | |
| 1071 | - // a separate payment flow. Online gateways (stripe/paypal/woocommerce) | |
| 1072 | - // send this email themselves once payment is finalized, so excluding | |
| 1073 | - // them here avoids a duplicate email for the same booking. | |
| 1074 | - if ( 'created' === $action && 'failed' !== $status && ! in_array( $payment_method_l, ['stripe', 'paypal', 'woocommerce'], true ) ) { | |
| 1075 | - $is_email_to_customer = timetics_get_option( 'booking_created_customer'); | |
| 1076 | - $is_email_to_host = timetics_get_option( 'booking_created_host'); | |
| 1157 | + // Note: booking creation emails for new bookings are sent further below, | |
| 1158 | + // AFTER the calendar event is created, so the Google Meet join link is | |
| 1159 | + // available in the email. See the "created" branch after the schedule | |
| 1160 | + // entry is created. | |
| 1077 | 1161 | |
| 1078 | - if ( $is_email_to_host ) { | |
| 1079 | - $new_event_email = new New_Event_Email( $booking ); | |
| 1080 | - $new_event_email->send(); | |
| 1081 | - } | |
| 1082 | - | |
| 1083 | - if ( $is_email_to_customer ) { | |
| 1084 | - $new_event_customer_email = new New_Event_Customer_Email( $booking ); | |
| 1085 | - $new_event_customer_email->send(); | |
| 1086 | - } | |
| 1087 | - } | |
| 1088 | - | |
| 1089 | 1162 | // Create or update calendar event. |
| 1090 | 1163 | if ( $id ) { |
| 1091 | 1164 | if ( 'cancel' === $status ) { |
| 1092 | 1165 | $booking->delete_event(); |
| @@ -1102,12 +1175,27 @@ | ||
| 1102 | 1175 | $customer_cancel_event_email = new Cancel_Event_Customer_Email( $booking ); |
| 1103 | 1176 | $customer_cancel_event_email->send(); |
| 1104 | 1177 | } |
| 1105 | 1178 | |
| 1179 | + do_action( 'timetics_gln_hook', 'booking_canceled', Notification::get_hook_data( $booking ) ); | |
| 1180 | + | |
| 1106 | 1181 | /** |
| 1107 | 1182 | * Added temporary for leagacy sass. It will remove in future. |
| 1108 | 1183 | */ |
| 1109 | 1184 | do_action( 'timetics/admin/booking/after_delete_item', $booking ); |
| 1185 | + | |
| 1186 | + /** | |
| 1187 | + * Fired when an existing booking is cancelled. | |
| 1188 | + * | |
| 1189 | + * Cancel had no dedicated hook before, so integrations could | |
| 1190 | + * only react to create/reschedule/delete. | |
| 1191 | + * | |
| 1192 | + * @param int $booking_id Booking ID. | |
| 1193 | + * @param int $customer_id Customer ID. | |
| 1194 | + * @param int $meeting_id Meeting (appointment) ID. | |
| 1195 | + * @param array $data Request data. | |
| 1196 | + */ | |
| 1197 | + do_action( 'timetics_after_booking_cancel', $booking->get_id(), $customer->get_id(), $meeting->get_id(), $data ); | |
| 1110 | 1198 | } else { |
| 1111 | 1199 | // Check if the booking date/time was actually changed |
| 1112 | 1200 | $date_time_changed = ( |
| 1113 | 1201 | $old_start_date !== $start_date || |
| @@ -1117,8 +1205,15 @@ | ||
| 1117 | 1205 | |
| 1118 | 1206 | $booking->update_event(); |
| 1119 | 1207 | |
| 1120 | 1208 | if ( $date_time_changed ) { |
| 1209 | + $reschedule_hook_data = Notification::get_hook_data( $booking ); | |
| 1210 | + | |
| 1211 | + // Move any pending delayed flow onto the new meeting time so | |
| 1212 | + // the reminder keeps its offset instead of firing at the old | |
| 1213 | + // moment with the old details. | |
| 1214 | + Notification_Flow_Guard::reschedule_pending_flows( $booking->get_id(), $reschedule_hook_data ); | |
| 1215 | + | |
| 1121 | 1216 | $is_email_to_reschedule_customer = timetics_get_option( 'booking_rescheduled_customer'); |
| 1122 | 1217 | $is_email_to_reschedule_host = timetics_get_option( 'booking_rescheduled_host'); |
| 1123 | 1218 | |
| 1124 | 1219 | if ( $is_email_to_reschedule_host ) { |
| @@ -1129,8 +1224,31 @@ | ||
| 1129 | 1224 | if ( $is_email_to_reschedule_customer ) { |
| 1130 | 1225 | $update_event_customer_email = new Update_Event_Customer_Email( $booking ); |
| 1131 | 1226 | $update_event_customer_email->send(); |
| 1132 | 1227 | } |
| 1228 | + | |
| 1229 | + // Hand the previous meeting timestamp to the SDK as well — | |
| 1230 | + // its delay node uses `previous_<key>` to drop a checkpoint | |
| 1231 | + // it scheduled itself on an earlier run. | |
| 1232 | + if ( $old_meeting_timestamp ) { | |
| 1233 | + $reschedule_hook_data['previous_meeting_date_timestamp'] = $old_meeting_timestamp; | |
| 1234 | + } | |
| 1235 | + | |
| 1236 | + do_action( 'timetics_gln_hook', 'booking_rescheduled', $reschedule_hook_data ); | |
| 1237 | + | |
| 1238 | + /** | |
| 1239 | + * Fired when a booking's date or time actually changed. | |
| 1240 | + * | |
| 1241 | + * `timetics_after_booking_schedule` runs on every save, so | |
| 1242 | + * it cannot tell a reschedule from an edit of the phone | |
| 1243 | + * number. This one only fires on a real time change. | |
| 1244 | + * | |
| 1245 | + * @param int $booking_id Booking ID. | |
| 1246 | + * @param int $customer_id Customer ID. | |
| 1247 | + * @param int $meeting_id Meeting (appointment) ID. | |
| 1248 | + * @param array $data Request data. | |
| 1249 | + */ | |
| 1250 | + do_action( 'timetics_after_booking_reschedule', $booking->get_id(), $customer->get_id(), $meeting->get_id(), $data ); | |
| 1133 | 1251 | } |
| 1134 | 1252 | } |
| 1135 | 1253 | } |
| 1136 | 1254 | |
| @@ -1137,49 +1255,85 @@ | ||
| 1137 | 1255 | // Convert booking time to staff/meeting time. |
| 1138 | 1256 | $date_time = timetics_convert_timezone( $start_date . ' ' . $start_time, $timezone, $meeting->get_timezone() ); |
| 1139 | 1257 | $end_time = timetics_convert_timezone( $start_date . ' ' . $end_time, $timezone, $meeting->get_timezone() ); |
| 1140 | 1258 | |
| 1141 | - // Create booking schedule. | |
| 1142 | - $entries = $booking_entry->find( | |
| 1143 | - [ | |
| 1144 | - 'staff_id' => $staff->get_id(), | |
| 1145 | - 'meeting_id' => $meeting->get_id(), | |
| 1146 | - 'date' => $date_time->format( 'Y-m-d' ), | |
| 1147 | - 'start' => $date_time->format( 'h:i a' ), | |
| 1148 | - ] | |
| 1149 | - ); | |
| 1259 | + // Create booking schedule. Skipped on cancel — the slot for this | |
| 1260 | + // booking was already released above, and re-running this block would | |
| 1261 | + // either recreate the just-deleted entry (one-to-one) or double the | |
| 1262 | + // decrement (group), re-blocking or over-freeing the slot. | |
| 1263 | + if ( 'cancel' !== $status ) { | |
| 1264 | + $entries = $booking_entry->find( | |
| 1265 | + [ | |
| 1266 | + 'staff_id' => $staff->get_id(), | |
| 1267 | + 'meeting_id' => $meeting->get_id(), | |
| 1268 | + 'date' => $date_time->format( 'Y-m-d' ), | |
| 1269 | + 'start' => $date_time->format( 'h:i a' ), | |
| 1270 | + ] | |
| 1271 | + ); | |
| 1150 | 1272 | |
| 1151 | - if ( $entries ) { | |
| 1152 | - $entry = $booking_entry->first(); | |
| 1273 | + if ( $entries ) { | |
| 1274 | + $entry = $booking_entry->first(); | |
| 1153 | 1275 | |
| 1154 | - if ( 'cancel' === $status ) { | |
| 1155 | - $booked = intval( $entry->get_booked() ) - 1; | |
| 1276 | + $booked = intval( $entry->get_booked() ) + 1; | |
| 1277 | + $booked_data = apply_filters( 'timetics_booking_update_schedule', $entry, ['booked' => $booked], $data, $booking ); | |
| 1278 | + | |
| 1279 | + $entry->update( $this->normalize_schedule_update( $booked_data, $booked ) ); | |
| 1156 | 1280 | } else { |
| 1157 | - $booked = intval( $entry->get_booked() ) + 1; | |
| 1281 | + $book_entry_data = [ | |
| 1282 | + 'meeting_id' => $meeting->get_id(), | |
| 1283 | + 'staff_id' => $staff->get_id(), | |
| 1284 | + 'customer_id' => $customer->get_id(), | |
| 1285 | + 'booking_id' => $booking->get_id(), | |
| 1286 | + 'booked' => 1, | |
| 1287 | + 'date' => $date_time->format( 'Y-m-d' ), | |
| 1288 | + 'start' => $date_time->format( 'h:i a' ), | |
| 1289 | + 'end' => $end_time->format( 'h:i a' ), | |
| 1290 | + ]; | |
| 1291 | + | |
| 1292 | + $book_entry_data = apply_filters( 'timetics_booking_schedule', $book_entry_data, $data ); | |
| 1293 | + $booking_entry->create( $book_entry_data ); | |
| 1158 | 1294 | } |
| 1295 | + } | |
| 1159 | 1296 | |
| 1160 | - $booked_data = apply_filters( 'timetics_booking_update_schedule', $entry, ['booked' => $booked], $data, $booking ); | |
| 1297 | + // For newly created bookings, create the calendar event now that the | |
| 1298 | + // booking schedule entry exists. This generates the Google Meet link | |
| 1299 | + // (stored in booking meta) so it can be shown on the success page and | |
| 1300 | + // included in the notification emails sent below. | |
| 1301 | + // | |
| 1302 | + // Skipped while an online gateway payment is still outstanding — the | |
| 1303 | + // real event gets created once payment confirms, in make_payment() and | |
| 1304 | + // Hooks::update_booking_payment_status(). Based on payment_method and | |
| 1305 | + // amount alone, NOT $status: a privileged (logged-in admin/staff) user | |
| 1306 | + // gets $default_status regardless of gateway, which can be 'approved' | |
| 1307 | + // even though no payment happened yet — checking $status here would | |
| 1308 | + // miss that and create the event before the customer actually pays. | |
| 1309 | + $is_awaiting_online_payment = 'created' === $action && $server_total > 0 | |
| 1310 | + && in_array( $payment_method_l, [ 'stripe', 'woocommerce', 'paypal' ], true ); | |
| 1161 | 1311 | |
| 1162 | - if ( 'cancel' === $status && 'one-to-one' == strtolower( $meeting->get_type() ) ) { | |
| 1163 | - $entry->delete(); | |
| 1164 | - } else { | |
| 1165 | - $entry->update( $booked_data ); | |
| 1312 | + if ( 'created' === $action && 'cancel' !== $status && ! $is_awaiting_online_payment ) { | |
| 1313 | + $booking->create_event(); | |
| 1314 | + } | |
| 1315 | + | |
| 1316 | + // Send booking creation emails for new bookings not processed through | |
| 1317 | + // a separate payment flow. Online gateways (stripe/paypal/woocommerce) | |
| 1318 | + // send this email themselves once payment is finalized, so excluding | |
| 1319 | + // them here avoids a duplicate email for the same booking. Sent here | |
| 1320 | + // (after create_event) so the Google Meet link is present in the email. | |
| 1321 | + if ( 'created' === $action && 'failed' !== $status && ! in_array( $payment_method_l, ['stripe', 'paypal', 'woocommerce'], true ) ) { | |
| 1322 | + $is_email_to_customer = timetics_get_option( 'booking_created_customer'); | |
| 1323 | + $is_email_to_host = timetics_get_option( 'booking_created_host'); | |
| 1324 | + | |
| 1325 | + if ( $is_email_to_host ) { | |
| 1326 | + $new_event_email = new New_Event_Email( $booking ); | |
| 1327 | + $new_event_email->send(); | |
| 1166 | 1328 | } |
| 1167 | 1329 | |
| 1168 | - } else { | |
| 1169 | - $book_entry_data = [ | |
| 1170 | - 'meeting_id' => $meeting->get_id(), | |
| 1171 | - 'staff_id' => $staff->get_id(), | |
| 1172 | - 'customer_id' => $customer->get_id(), | |
| 1173 | - 'booking_id' => $booking->get_id(), | |
| 1174 | - 'booked' => 1, | |
| 1175 | - 'date' => $date_time->format( 'Y-m-d' ), | |
| 1176 | - 'start' => $date_time->format( 'h:i a' ), | |
| 1177 | - 'end' => $end_time->format( 'h:i a' ), | |
| 1178 | - ]; | |
| 1330 | + if ( $is_email_to_customer ) { | |
| 1331 | + $new_event_customer_email = new New_Event_Customer_Email( $booking ); | |
| 1332 | + $new_event_customer_email->send(); | |
| 1333 | + } | |
| 1179 | 1334 | |
| 1180 | - $book_entry_data = apply_filters( 'timetics_booking_schedule', $book_entry_data, $data ); | |
| 1181 | - $booking_entry->create( $book_entry_data ); | |
| 1335 | + do_action( 'timetics_gln_hook', 'booking_created', Notification::get_hook_data( $booking ) ); | |
| 1182 | 1336 | } |
| 1183 | 1337 | |
| 1184 | 1338 | // Fire after booking schedule create. |
| 1185 | 1339 | do_action( 'timetics_after_booking_schedule', $booking->get_id(), $customer->get_id(), $meeting->get_id(), $data ); |
| @@ -1201,9 +1355,9 @@ | ||
| 1201 | 1355 | * @param integer $booking_id |
| 1202 | 1356 | * |
| 1203 | 1357 | * @return array |
| 1204 | 1358 | */ |
| 1205 | - public function prepare_item( $booking_id ) { | |
| 1359 | + public function prepare_item( $booking_id, $expose_token = true ) { | |
| 1206 | 1360 | $booking = new Booking( $booking_id ); |
| 1207 | 1361 | $appointment = new Appointment( $booking->get_appointment() ); |
| 1208 | 1362 | $staff = new Staff( $booking->get_staff_id() ); |
| 1209 | 1363 | $customer = new Customer( $booking->get_customer_id() ); |
| @@ -1236,9 +1390,12 @@ | ||
| 1236 | 1390 | 'location' => $booking->get_location(), |
| 1237 | 1391 | 'location_type' => $booking->get_location_type(), |
| 1238 | 1392 | 'description' => $booking->get_description(), |
| 1239 | 1393 | 'cancel_reason' => $booking->get_cancel_reason(), |
| 1240 | - 'security_token' => $booking->get_security_token(), | |
| 1394 | + // Listing endpoints (get_items / get_booking_list) pass $expose_token = false — | |
| 1395 | + // a viewer browsing many bookings at once has no legitimate need for every | |
| 1396 | + // one's bearer token; single-booking reads (create/get/update) keep it. | |
| 1397 | + 'security_token' => $expose_token ? $booking->get_security_token() : '', | |
| 1241 | 1398 | 'payment_method' => $booking->get_payment_method(), |
| 1242 | 1399 | 'payment_status' => $booking->get_payment_status(), |
| 1243 | 1400 | 'payment_details' => $payment_details, |
| 1244 | 1401 | 'customer' => [ |
| @@ -1306,39 +1463,27 @@ | ||
| 1306 | 1463 | |
| 1307 | 1464 | return new WP_HTTP_Response( $data, 403 ); |
| 1308 | 1465 | } |
| 1309 | 1466 | |
| 1310 | - $booking_entry = new Booking_Entry(); | |
| 1311 | 1467 | |
| 1312 | - $date_time = timetics_convert_timezone( $booking->get_start_date() . ' ' . $booking->get_start_time(), $booking->get_timezone(), $meeting->get_timezone() ); | |
| 1468 | + $booking->release_slot(); | |
| 1313 | 1469 | |
| 1314 | - $entries = $booking_entry->find( | |
| 1315 | - [ | |
| 1316 | - 'staff_id' => $booking->get_staff_id(), | |
| 1317 | - 'meeting_id' => $booking->get_appointment(), | |
| 1318 | - 'date' => $date_time->format( 'Y-m-d' ), | |
| 1319 | - 'start' => $date_time->format( 'h:i a' ), | |
| 1320 | - ] | |
| 1321 | - ); | |
| 1470 | + $recurrences = $booking->get_recurrence(); | |
| 1322 | 1471 | |
| 1323 | - if ( $entries ) { | |
| 1324 | - $entry = $booking_entry->first(); | |
| 1472 | + /** | |
| 1473 | + * Fired before a booking is deleted, while its data can still be read. | |
| 1474 | + * | |
| 1475 | + * `timetics_after_booking_delete` runs after the post has already gone | |
| 1476 | + * and only receives the recurrence data, so an integration that needs | |
| 1477 | + * the booking, customer or meeting has to listen here instead. | |
| 1478 | + * | |
| 1479 | + * @param int $booking_id Booking ID. | |
| 1480 | + * @param int $customer_id Customer ID. | |
| 1481 | + * @param int $meeting_id Meeting (appointment) ID. | |
| 1482 | + * @param array $data Request data. | |
| 1483 | + */ | |
| 1484 | + do_action( 'timetics_before_booking_delete', $booking->get_id(), $booking->get_customer_id(), $meeting->get_id(), [] ); | |
| 1325 | 1485 | |
| 1326 | - if ( 'one-to-one' == strtolower( $meeting->get_type() ) ) { | |
| 1327 | - $entry->delete(); | |
| 1328 | - } else { | |
| 1329 | - $booked = intval( $entry->get_booked() ) - 1; | |
| 1330 | - $booked_seat = ! empty( $booking->get_seat() ) ? $booking->get_seat() : []; | |
| 1331 | - $existing_seat = ! empty( $entry->get_seats() ) ? $entry->get_seats() : []; | |
| 1332 | - | |
| 1333 | - $entry->update( [ | |
| 1334 | - 'booked' => $booked, | |
| 1335 | - 'seats' => array_values( array_diff( $existing_seat, $booked_seat ) ), | |
| 1336 | - ] ); | |
| 1337 | - } | |
| 1338 | - } | |
| 1339 | - | |
| 1340 | - $recurrences = $booking->get_recurrence(); | |
| 1341 | 1486 | $booking->delete_event(); |
| 1342 | 1487 | $booking->delete(); |
| 1343 | 1488 | |
| 1344 | 1489 | $is_email_to_customer = timetics_get_option( 'booking_canceled_customer'); |
| @@ -1354,10 +1499,12 @@ | ||
| 1354 | 1499 | $customer_cancel_event_email = new Cancel_Event_Customer_Email( $booking ); |
| 1355 | 1500 | $customer_cancel_event_email->send(); |
| 1356 | 1501 | } |
| 1357 | 1502 | |
| 1503 | + do_action( 'timetics_gln_hook', 'booking_canceled', Notification::get_hook_data( $booking ) ); | |
| 1358 | 1504 | |
| 1359 | 1505 | |
| 1506 | + | |
| 1360 | 1507 | do_action( 'timetics_after_booking_delete', $recurrences ); |
| 1361 | 1508 | |
| 1362 | 1509 | return true; |
| 1363 | 1510 | } |
| @@ -1386,12 +1533,43 @@ | ||
| 1386 | 1533 | if ( $booked && intval( $booked->get_booked() ) >= $meeting->get_effective_capacity() ) { |
| 1387 | 1534 | return false; |
| 1388 | 1535 | } |
| 1389 | 1536 | |
| 1390 | - return true; | |
| 1537 | + /** | |
| 1538 | + * Let integrations veto a slot at booking time. | |
| 1539 | + * | |
| 1540 | + * Slot listing is filtered separately, so without this a client posting | |
| 1541 | + * straight to the REST endpoint could still book a slot that the UI | |
| 1542 | + * hides — which is how a Google Calendar conflict turned into a real | |
| 1543 | + * double booking. Integrations must fail open: return true when they | |
| 1544 | + * cannot determine availability. | |
| 1545 | + * | |
| 1546 | + * @param bool $available | |
| 1547 | + * @param Appointment $meeting | |
| 1548 | + * @param array $booking_data | |
| 1549 | + */ | |
| 1550 | + return (bool) apply_filters( 'timetics_is_slot_available', true, $meeting, $booking_data ); | |
| 1391 | 1551 | } |
| 1392 | 1552 | |
| 1393 | 1553 | /** |
| 1554 | + * Resolve what `timetics_booking_update_schedule` returned into an update payload. | |
| 1555 | + * | |
| 1556 | + * The filter passes the entry as its filtered value and the payload only as | |
| 1557 | + * an extra argument, so with nothing hooked it hands back the entry object. | |
| 1558 | + * Booking_Entry::update() then matches none of its keys and silently writes | |
| 1559 | + * nothing, leaving group counters frozen. Keep the published signature and | |
| 1560 | + * fall back to the payload whenever the result is not usable. | |
| 1561 | + * | |
| 1562 | + * @param mixed $filtered Whatever the filter returned. | |
| 1563 | + * @param integer $booked Counter this call meant to store. | |
| 1564 | + * | |
| 1565 | + * @return array | |
| 1566 | + */ | |
| 1567 | + private function normalize_schedule_update( $filtered, $booked ) { | |
| 1568 | + return is_array( $filtered ) ? $filtered : [ 'booked' => $booked ]; | |
| 1569 | + } | |
| 1570 | + | |
| 1571 | + /** | |
| 1394 | 1572 | * Validates a booking. |
| 1395 | 1573 | * |
| 1396 | 1574 | * @param int $appointment_id The ID of the appointment. |
| 1397 | 1575 | * @param array $data The data for the booking. |
| @@ -1508,10 +1686,16 @@ | ||
| 1508 | 1686 | if (empty($booking_id) || ! wp_verify_nonce($nonce, 'wp_rest')) { |
| 1509 | 1687 | return false; |
| 1510 | 1688 | } |
| 1511 | 1689 | |
| 1512 | - // Allow booking owner or admins/managers. | |
| 1513 | - if ( (int) $booking->get_customer_id() === get_current_user_id() || current_user_can( 'manage_timetics' )) { | |
| 1690 | + // manage_timetics is not admin-only — every staff account holds it — so it | |
| 1691 | + // cannot stand in for an ownership check. Real admins, the booking's own | |
| 1692 | + // customer, or staff this specific booking is actually visible to. | |
| 1693 | + if ( | |
| 1694 | + ( get_current_user_id() > 0 && (int) $booking->get_customer_id() === get_current_user_id() ) | |
| 1695 | + || timetics_can_view_all_data() | |
| 1696 | + || in_array( $booking_id, timetics_get_visible_booking_ids(), true ) | |
| 1697 | + ) { | |
| 1514 | 1698 | return true; |
| 1515 | 1699 | } |
| 1516 | 1700 | |
| 1517 | 1701 | return false; |
| @@ -1540,11 +1724,20 @@ | ||
| 1540 | 1724 | return true; |
| 1541 | 1725 | } |
| 1542 | 1726 | } |
| 1543 | 1727 | |
| 1544 | - if (wp_verify_nonce($nonce, 'wp_rest') && current_user_can( 'manage_timetics' ) ) { | |
| 1728 | + if ( ! wp_verify_nonce( $nonce, 'wp_rest' ) ) { | |
| 1729 | + return false; | |
| 1730 | + } | |
| 1731 | + | |
| 1732 | + if ( | |
| 1733 | + ( get_current_user_id() > 0 && (int) $booking->get_customer_id() === get_current_user_id() ) | |
| 1734 | + || timetics_can_view_all_data() | |
| 1735 | + || in_array( $booking_id, timetics_get_visible_booking_ids(), true ) | |
| 1736 | + ) { | |
| 1545 | 1737 | return true; |
| 1546 | 1738 | } |
| 1739 | + | |
| 1547 | 1740 | return false; |
| 1548 | 1741 | } |
| 1549 | 1742 | |
| 1550 | 1743 | /** |
| @@ -1558,10 +1751,10 @@ | ||
| 1558 | 1751 | * |
| 1559 | 1752 | * @return string|WP_Error Returns the validated email on success, WP_Error on failure. |
| 1560 | 1753 | */ |
| 1561 | 1754 | private function validate_email_change_permission( $booking_id, $new_email ) { |
| 1562 | - // Admin users have full permission to change email addresses | |
| 1563 | - if ( current_user_can( 'manage_timetics' ) ) { | |
| 1755 | + // manage_timetics is not admin-only — every staff account holds it. | |
| 1756 | + if ( timetics_can_view_all_data() ) { | |
| 1564 | 1757 | return $new_email; |
| 1565 | 1758 | } |
| 1566 | 1759 | |
| 1567 | 1760 | $existing_booking = new Booking( $booking_id ); |
| @@ -1678,8 +1871,23 @@ | ||
| 1678 | 1871 | 409 |
| 1679 | 1872 | ); |
| 1680 | 1873 | } |
| 1681 | 1874 | |
| 1875 | + // A previous decline released this booking's slot. Bind runs before the card | |
| 1876 | + // is charged, so it is the last safe point to take the slot back — refusing | |
| 1877 | + // here costs the customer nothing, refusing after payment would take their | |
| 1878 | + // money for a time somebody else now holds. | |
| 1879 | + if ( ! $booking->reserve_slot() ) { | |
| 1880 | + return new WP_HTTP_Response( | |
| 1881 | + [ | |
| 1882 | + 'success' => 0, | |
| 1883 | + 'status_code' => 409, | |
| 1884 | + 'message' => esc_html__( 'This time slot is no longer available. Please pick another time.', 'timetics' ), | |
| 1885 | + ], | |
| 1886 | + 409 | |
| 1887 | + ); | |
| 1888 | + } | |
| 1889 | + | |
| 1682 | 1890 | $result = $stripe->update_payment_intent( |
| 1683 | 1891 | $intent_id, |
| 1684 | 1892 | [ |
| 1685 | 1893 | 'booking_id' => $booking_id, |
| @@ -1697,8 +1905,12 @@ | ||
| 1697 | 1905 | 502 |
| 1698 | 1906 | ); |
| 1699 | 1907 | } |
| 1700 | 1908 | |
| 1909 | + // Record the intent id now (not just at make_payment finalize) so the | |
| 1910 | + // unpaid-booking cleanup sweep can check Stripe before cancelling. | |
| 1911 | + $booking->set_stripe_payment_intent_id( $intent_id ); | |
| 1912 | + | |
| 1701 | 1913 | return new WP_HTTP_Response( |
| 1702 | 1914 | [ |
| 1703 | 1915 | 'success' => 1, |
| 1704 | 1916 | 'status_code' => 200, |
| @@ -1732,9 +1944,12 @@ | ||
| 1732 | 1944 | // constant-time comparison |
| 1733 | 1945 | if ( ! hash_equals( $stored_token, $appointment_token ) ) { |
| 1734 | 1946 | return false; |
| 1735 | 1947 | } |
| 1736 | - if ( 'pending' !== (string) $booking->get_status() ) { | |
| 1948 | + // A declined card leaves the booking 'failed' and the customer retries on that | |
| 1949 | + // same booking, so 'failed' has to pass too. Anything further along | |
| 1950 | + // ( approved / completed / cancelled ) is finished and must never be payable. | |
| 1951 | + if ( ! in_array( (string) $booking->get_status(), [ 'pending', 'failed' ], true ) ) { | |
| 1737 | 1952 | return false; |
| 1738 | 1953 | } |
| 1739 | 1954 | |
| 1740 | 1955 | return true; |