api.php
2 months ago
auth.php
6 months ago
cart.php
6 months ago
coupon-apply.php
6 months ago
coupon-get.php
6 months ago
giftcard-apply.php
1 year ago
order.php
8 months ago
prepay-cod.php
2 months ago
save-abandonment-data.php
1 year ago
shipping-info.php
1 year ago
auth.php
61 lines
| 1 | <?php |
| 2 | |
| 3 | /** |
| 4 | * custom auth to secure 1cc APIs |
| 5 | */ |
| 6 | |
| 7 | require_once __DIR__ . '/../../razorpay-sdk/Razorpay.php'; |
| 8 | use Razorpay\Api\Errors; |
| 9 | |
| 10 | function checkAuthCredentials() |
| 11 | { |
| 12 | return true; |
| 13 | } |
| 14 | |
| 15 | /** |
| 16 | * Validate HMAC signature using Razorpay Webhook Secret. |
| 17 | * Expects header 'X-Razorpay-Signature' computed over raw request body with HMAC-SHA256. |
| 18 | * |
| 19 | * @param WP_REST_Request $request |
| 20 | * @return bool|WP_Error |
| 21 | */ |
| 22 | function checkHmacSignature($request) |
| 23 | { |
| 24 | $signature = ''; |
| 25 | if (isset($_SERVER['HTTP_X_RAZORPAY_SIGNATURE'])) |
| 26 | { |
| 27 | $signature = sanitize_text_field($_SERVER['HTTP_X_RAZORPAY_SIGNATURE']); |
| 28 | } |
| 29 | |
| 30 | if (empty($signature)) |
| 31 | { |
| 32 | return new WP_Error('rest_forbidden', __('Signature missing'), array('status' => 403)); |
| 33 | } |
| 34 | |
| 35 | $payload = file_get_contents('php://input'); |
| 36 | |
| 37 | // Retrieve 1CC signing HMAC secret saved at plugin load time |
| 38 | $secret = get_option('rzp1cc_hmac_secret'); |
| 39 | |
| 40 | if (empty($secret)) |
| 41 | { |
| 42 | return new WP_Error('rest_forbidden', __('Secret not configured'), array('status' => 403)); |
| 43 | } |
| 44 | |
| 45 | // Verify using Razorpay SDK (same as webhook) |
| 46 | try |
| 47 | { |
| 48 | $rzp = new WC_Razorpay(false); |
| 49 | $api = $rzp->getRazorpayApiInstance(); |
| 50 | $api->utility->verifySignature($payload, $signature, $secret); |
| 51 | } |
| 52 | catch (Errors\SignatureVerificationError $e) |
| 53 | { |
| 54 | return new WP_Error('rest_forbidden', __('Invalid signature'), array('status' => 403)); |
| 55 | } |
| 56 | |
| 57 | return true; |
| 58 | } |
| 59 | |
| 60 | ?> |
| 61 |