PluginProbe
Pay with Vipps and MobilePay for WooCommerce / 6.2.5
Pay with Vipps and MobilePay for WooCommerce v6.2.5
6.2.5 6.2.4 6.2.3 6.2.2 6.2.1 6.2.0 6.1.10 6.1.9 6.1.8 6.1.7 6.1.6 6.1.5 6.1.4 6.1.3 6.1.2 6.1.1 6.1.0 6.0.5 6.0.4 6.0.3 6.0.2 6.0.1 6.0.0 5.4.3 5.4.2 All 187 releases
← All changes | payment/Vipps.class.php +418 -279 6.1.2 → 6.2.5 View file →
@@ -70,9 +70,9 @@
70 70 public static function CheckoutName($order=null) {
71 71 return "Vipps MobilePay Checkout"; // Do not translate
72 72 }
73 73 public static function ExpressCheckoutName($order=null) {
74 - return __("Vipps Express Checkout", 'woo-vipps');
74 + return __("Vipps MobilePay Express Checkout", 'woo-vipps');
75 75 }
76 76 public static function LoginName() {
77 77 return __("Login with Vipps", 'woo-vipps');
78 78 }
@@ -121,12 +121,17 @@
121 121 add_action('init',array($Vipps,'init'));
122 122 add_action( 'woocommerce_loaded', array($Vipps,'woocommerce_loaded'));
123 123 add_filter( 'woocommerce_available_payment_gateways', array($Vipps, 'payment_gateway_filter'));
124 124 add_action( 'woocommerce_blocks_loaded', [$Vipps, 'woocommerce_blocks_loaded']);
125 - // Express Checkout and Vipps Checkout supports the new pickup_location shipping method, but the admin interface for this may
125 + // Express Checkout and Checkout supports the new pickup_location shipping method, but the admin interface for this may
126 126 // not have loaded if the default checkout solution isn't the Checkout block. We'll load it anyway if the user has any local pickup locations
127 127 // stored in the database since we support this for both Vipps MobilePay checkokut and Express. IOK 2026-02-25
128 128 add_action('woocommerce_load_shipping_methods', array($Vipps, 'maybe_load_pickup_locations'), 90);
129 +
130 + // Vipps Checkout replaces the default checkout page, and currently uses its own page for this which needs to exist
131 + // Will also probably be used to maintain a real utility-page for Vipps actions later for themes where this
132 + // is important.
133 + add_filter('woocommerce_create_pages', array($Vipps, 'woocommerce_create_pages'), 50, 1);
129 134 }
130 135
131 136 // Register woocommerce store api endpoint to use in buy-now minicart block. LP 2026-02-10
132 137 public function woocommerce_blocks_loaded() {
@@ -280,8 +285,38 @@
280 285 }
281 286
282 287 // Set default button options, migrating any older setup IOK 2026-07-15
283 288 $this->init_button_options();
289 +
290 + /*
291 + From version 6.2.x we create a real physical page to handle the "special" vipps pages,
292 + where we earlier used just a fake page with no real page id, unless especially configured.
293 + We therefore need to add code to maintain this special page.
294 +
295 + woocommerce_loaded is too early for this because of maybe_create_vipps_pages which calls WC_Install::create_pages,
296 + and we hook unto this with woocommerce_create_pages. LP 2026-09-03
297 + */
298 +
299 + // Delete special page id option when its deleted or trashed, so that we dont have to load
300 + // in the post to check status in woocommerce_loaded when we ensure the special page exists. LP 2026-09-03
301 + $delete_special_page_id = function($post_id, $post = null) {
302 + if (static::get_special_page_id() === $post_id) {
303 + delete_option('woocommerce_vipps_special_page_page_id');
304 + }
305 + };
306 + add_action('delete_post', $delete_special_page_id, 10, 2);
307 + add_action('wp_trash_post', $delete_special_page_id, 10, 2);
308 +
309 + $this->ensure_special_page_exists();
310 +
311 +
312 + // We want this special page to have a certain title and maybe special scripts and so on,
313 + // this gets run in template redirect for these pages.
314 + add_action('woo_vipps_before_handling_special_page', array($this, 'pre_special_page_actions'));
315 +
316 + // Add an admin interface for this page as well IOK 2026-09-11
317 + add_action('woocommerce_settings_pages', array($this, 'woocommerce_settings_pages'));
318 +
284 319 }
285 320
286 321 public function admin_init () {
287 322 $gw = $this->gateway();
@@ -401,9 +436,77 @@
401 436 }
402 437 }
403 438 }
404 439
440 +
441 + /** Ensure we have a special page for payment flows
442 + *
443 + * woocommerce_loaded is too early for this because of maybe_create_vipps_pages which calls WC_Install::create_pages,
444 + * and we hook unto this with woocommerce_create_pages. LP 2026-09-03
445 + **/
446 + public function ensure_special_page_exists() {
447 + if (static::get_special_page_id()) return;
448 + $this->log(__('Missing id for special page, attempting to fix.', 'woo-vipps'), 'info');
405 449
450 + // If user had in previous version overriden the fake page with a real one: migrate this page to be the special page. LP 2026-09-01
451 + $old_special_page_id = $this->gateway()->get_option('vippsspecialpageid');
452 + if ($old_special_page_id && ($special_page = get_post($old_special_page_id)) && "trash" !== $special_page->post_status) {
453 + $this->log(__('Migrated old special page setting.', 'woo-vipps'), 'info');
454 + // there is no wc_set_page_id() so we update the option directly. LP 2026-09-01
455 + update_option('woocommerce_vipps_special_page_page_id', $old_special_page_id);
456 +
457 + // Ensure this page has the necessary shortcode. LP 2026-09-01
458 + if (!has_shortcode($special_page->post_content, 'vipps_special_page')) {
459 + $new_content = $special_page->post_content . "\n\n<!-- wp:shortcode -->[vipps_special_page]<!-- /wp:shortcode -->";
460 + wp_update_post([
461 + 'ID' => $old_special_page_id,
462 + 'post_content' => $new_content,
463 + ]);
464 + }
465 + } else {
466 + // Create special page if its missing. LP 2026-09-01
467 + $this->maybe_create_vipps_pages();
468 + }
469 + }
470 +
471 + // Admin interface for the special page on woo/advanced/pages
472 + public function woocommerce_settings_pages ($settings) {
473 + $i = -1;
474 + foreach($settings as $entry) {
475 + $i++;
476 + if ($entry['type'] == 'sectionend' && $entry['id'] == 'advanced_page_options') {
477 + break;
478 + }
479 + }
480 + if ($i > 0) {
481 + $vippspagesettings = array(
482 + array(
483 + 'title' => sprintf(__( '%1$s Page', 'woo-vipps' ), Vipps::CompanyName()),
484 + 'desc' => sprintf(__('This page is used for various special pages used by %1$s', 'woo-vipps'), Vipps::CompanyName()) . sprintf( __( 'Page contents: [%1$s]', 'woocommerce' ), 'vipps_special_page') ,
485 + 'id' => 'woocommerce_vipps_special_page_page_id',
486 + 'type' => 'single_select_page_with_search',
487 + 'default' => '',
488 + 'class' => 'wc-page-search',
489 + 'css' => 'min-width:300px;',
490 + 'args' => array(
491 + 'exclude' =>
492 + array(
493 + wc_get_page_id( 'myaccount' ),
494 + wc_get_page_id( 'checkout' ),
495 + wc_get_page_id( 'cart' ),
496 + ),
497 + ),
498 + 'desc_tip' => true,
499 + 'autoload' => false,
500 + ));
501 + array_splice($settings, $i, 0, $vippspagesettings);
502 + }
503 +
504 + return $settings;
505 + }
506 +
507 +
508 +
406 509 // Runs on init, adds the Vipps badge feature if activated
407 510 public function maybe_add_vipps_badge_feature () {
408 511 $badge_options = get_option('vipps_badge_options');
409 512 if (!$badge_options || !@$badge_options['badgeon']) return false;
@@ -732,8 +835,11 @@
732 835
733 836 // Get current brand and language
734 837 $current_brand = strtolower($this->get_payment_method_name());
735 838 $current_language = $this->get_customer_language();
839 + if ('se' === $current_language) $current_language = 'sv';
840 + // Looks like button and badge web components now use 'da' instead of 'dk' for danish. LP 2026-08-13
841 + if ('dk' === $current_language) $current_language = 'da';
736 842
737 843 $variants = ['white'=> __('White', 'woo-vipps'), 'grey' => __('Grey','woo-vipps'),
738 844 'filled'=> __('Filled', 'woo-vipps'), 'light'=>__('Light','woo-vipps'),
739 845 'purple'=> __('Purple', 'woo-vipps')];
@@ -796,9 +902,9 @@
796 902
797 903 <h2><?php _e('Shortcodes', 'woo-vipps'); ?> </h2>
798 904 <p><?php echo sprintf(__('If you need to add a %1$s badge on a specific page, footer, header and so on, and you cannot use the Gutenberg Block provided for this, you can either add the %1$s Badge manually (as <a href="%2$s" nofollow rel=nofollow target=_blank>documented here</a>) or you can use the shortcode.', 'woo-vipps'), Vipps::CompanyName(), "https://developer.vippsmobilepay.com/docs/knowledge-base/design-guidelines/on-site-messaging/"); ?></p>
799 905 <br><?php _e("The shortcode looks like this:", 'woo-vipps')?><br>
800 - <pre>[vipps-mobilepay-badge variant={white|filled|light|grey|purple}<br> language={en|no|fi|dk} ] </pre><br>
906 + <pre>[vipps-mobilepay-badge variant={white|filled|light|grey|purple}<br> language={en|no|fi|da|sv} ] </pre><br>
801 907 <?php _e("Please refer to the documentation for the meaning of the parameters.", 'woo-vipps'); ?></br>
802 908 <?php _e("The brand will be automatically applied.", 'woo-vipps'); ?>
803 909 </p>
804 910
@@ -876,9 +982,12 @@
876 982 public function vipps_mobilepay_badge_shortcode($atts) {
877 983 $args = shortcode_atts( array('id'=>'', 'class'=>'', 'brand' => '', 'variant' => '','language'=>''), $atts );
878 984
879 985 $variant = in_array($args['variant'], ['orange', 'light-orange', 'grey','white', 'purple', 'filled', 'light']) ? $args['variant'] : "";
880 - $language = in_array($args['language'], ['en','no', 'fi', 'dk']) ? $args['language'] : $this->get_customer_language();
986 + $language = in_array($args['language'], ['en', 'no', 'sv', 'da', 'dk', 'fi']) ? $args['language'] : $this->get_customer_language();
987 + if ('se' === $language) $language = 'sv';
988 + // Looks like button and badge web components now use 'da' instead of 'dk' for danish. LP 2026-08-11
989 + if ('dk' === $language) $language = 'da';
881 990 $id = sanitize_title($args['id']);
882 991 $class = sanitize_text_field($args['class']);
883 992
884 993 $attributes = [];
@@ -894,13 +1003,18 @@
894 1003 return "<vipps-mobilepay-badge $badgeatts></vipps-mobilepay-badge>";
895 1004 }
896 1005
897 1006 // legacy vipps_badge shortcode, the new one is vipps_mobilepay_badge_shortcode. LP 19.11.2024
1007 + // Diff: this one doesn't support brand (JUST VIPPS). LP 2026-08-11
898 1008 public function vipps_badge_shortcode($atts) {
899 1009 $args = shortcode_atts( array('id'=>'', 'class'=>'','variant' => '','language'=>''), $atts );
900 1010
901 1011 $variant = in_array($args['variant'], ['orange', 'light-orange', 'grey','white', 'purple']) ? $args['variant'] : "";
902 - $language = in_array($args['language'], ['en','no', 'dk', 'fi']) ? $args['language'] : $this->get_customer_language();
1012 + $language = in_array($args['language'], ['en', 'no', 'sv', 'da', 'dk', 'fi']) ? $args['language'] : $this->get_customer_language();
1013 + if ('se' === $language) $language = 'sv';
1014 + // Looks like button and badge web components now use 'da' instead of 'dk' for danish. LP 2026-08-11
1015 + if ('dk' === $language) $language = 'da';
1016 +
903 1017 $id = sanitize_title($args['id']);
904 1018 $class = sanitize_text_field($args['class']);
905 1019
906 1020 $attributes = [];
@@ -929,12 +1043,30 @@
929 1043
930 1044 public function get_html_button_attrs_for_context($context = 'global') {
931 1045 $options = get_option('vipps_button_options2', []);
932 1046 if (!is_string($context)) $context = 'global';
1047 +
1048 + // Gutenberg express checkout buttons really want to be stretched, so we'll treat them somewhat differently.
1049 + $gutenberg = false;
1050 + if ($context == 'checkout_gutenberg') {
1051 + $context = 'checkout';
1052 + $gutenberg = true;
1053 + }
1054 + if ($context == 'cart_gutenberg') {
1055 + $context = 'cart';
1056 + $gutenberg = true;
1057 + }
1058 +
933 1059 $config = $options['express']['configs'][$context] ?? [];
934 - if (!$config || ($config['use-global-config'] ?? false)) {
1060 + $use_global = !$config || ($config['use-global-config'] ?? false);
1061 + if ($use_global) {
935 1062 $config = $options['express']['configs']['global'] ?? $this->get_html_button_default_attrs();
936 1063 }
1064 +
1065 + // see above.
1066 + if ($gutenberg) {
1067 + $config['stretched']='true';
1068 + }
937 1069 return $config;
938 1070 }
939 1071
940 1072 public function get_html_button_for_context($context = 'global') {
@@ -952,8 +1084,10 @@
952 1084 // Support using store language
953 1085 if ('store' === $attrs['language']) $attrs['language'] = $this->get_customer_language();
954 1086 // Don't support these login verbs. LP 2026-06-04
955 1087 if (in_array($attrs['verb'], ['login', 'register'])) $attrs['verb'] = 'buy';
1088 + // Looks like button and badge web components now use 'da' instead of 'dk' for danish. LP 2026-08-11
1089 + if ('dk' === $attrs['language']) $attrs['language'] = 'da';
956 1090
957 1091 $escaped_attrs = [];
958 1092 foreach($attrs as $k => $v) {
959 1093 $escaped_attrs[$k] = esc_attr($v);
@@ -1019,8 +1153,10 @@
1019 1153 private function button_menu_express_section() {
1020 1154 $options = get_option('vipps_button_options2', []);
1021 1155 $express = $options['express'] ?? [];
1022 1156 $configs = $express['configs'] ?? [];
1157 +
1158 +
1023 1159 $contexts = [
1024 1160 'global' => __('Global', 'woo-vipps'),
1025 1161 'product' => __('Product', 'woo-vipps'),
1026 1162 'catalog' => __('Catalog', 'woo-vipps'),
@@ -1151,9 +1287,9 @@
1151 1287
1152 1288 // Update the preview web component's attributes. LP 2026-06-24
1153 1289 function updatePreview(event) {
1154 1290 const args = getPreviewArgs();
1155 - // LP FIXME: when i use get_customer_language() here it gives me my user language, but on frontend it gives the site language, i.e not the same value. So this preview will be wrong language. so use get_locale for now. LP 2026-07-02
1291 + // FIXME: when i use get_customer_language() here it gives me my user language, but on frontend it gives the site language, i.e not the same value. So this preview will be wrong language. so use get_locale for now. LP 2026-07-02
1156 1292 // if ('store' === args.language) args.language = '<?php echo $this->get_customer_language(); ?>';
1157 1293 if ('store' === args.language) args.language = '<?php echo substr(get_locale(), 0, 2); ?>';
1158 1294 const button = jQuery('#vipps-button-express-preview');
1159 1295 button.attr(args);
@@ -1193,8 +1329,9 @@
1193 1329
1194 1330 // Swap to new context: set all input fields to the stored values if exists. LP 2026-06-25
1195 1331 const newContext = jQuery("#context").val();
1196 1332 const newConfig = contextConfigs[newContext];
1333 +
1197 1334 setInputsFromConfig(newContext, newConfig);
1198 1335 currentContext = newContext;
1199 1336 }
1200 1337
@@ -1646,9 +1783,9 @@
1646 1783 [
1647 1784 'in_footer' => true,
1648 1785 'strategy' => 'async',
1649 1786 ],
1650 - );
1787 + );
1651 1788
1652 1789 // Button web component downloaded from https://cdn.vippsmobilepay.com/js/button/button.js. LP 2026-06-24
1653 1790 wp_register_script('vipps-button-webcomponent',
1654 1791 plugins_url('js/vipps-button.js', WC_VIPPS_PAYMENT_MAIN_FILE),
@@ -1654,10 +1791,9 @@
1654 1791 plugins_url('js/vipps-button.js', WC_VIPPS_PAYMENT_MAIN_FILE),
1655 1792 array(),
1656 1793 filemtime(dirname(WC_VIPPS_PAYMENT_MAIN_FILE) . '/js/vipps-button.js'),
1657 1794 [
1658 - 'in_footer' => true,
1659 - 'strategy' => 'async',
1795 + 'in_footer' => false
1660 1796 ],
1661 1797 );
1662 1798 }
1663 1799
@@ -1692,8 +1828,11 @@
1692 1828 // New vipps-mobilepay-badge shortcode. LP 19.11.2024
1693 1829 add_shortcode('vipps-mobilepay-badge', array($this, 'vipps_mobilepay_badge_shortcode'));
1694 1830 // Legacy vipps-badge shortcode. LP 19.11.2024
1695 1831 add_shortcode('vipps-badge', array($this, 'vipps_badge_shortcode'));
1832 +
1833 + // special page handling, previously a fake page. LP 2026-08-25
1834 + add_shortcode('vipps_special_page', array($this, 'vipps_special_page_shortcode'));
1696 1835 }
1697 1836
1698 1837
1699 1838 public function log ($what,$type='info') {
@@ -1719,8 +1858,10 @@
1719 1858 }
1720 1859
1721 1860 // Show express button option on checkout form. LP 2026-03-23
1722 1861 public function checkout_before_customer_details_express () {
1862 + if (did_action('woo_vipps_checkout_before_customer_details_express')) return;
1863 + do_action('woo_vipps_checkout_before_customer_details_express');
1723 1864 $gw = $this->gateway();
1724 1865 if (!$gw->show_express_checkout()) return;
1725 1866 $this->express_checkout_section_html();
1726 1867 }
@@ -1791,16 +1932,15 @@
1791 1932 public function minicart_express_checkout_button() {
1792 1933 $gw = $this->gateway();
1793 1934
1794 1935 if ($gw->show_express_checkout()){
1795 - return $this->cart_express_checkout_button_html(true);
1936 + return $this->cart_express_checkout_button_html('minicart');
1796 1937 }
1797 1938 }
1798 1939
1799 - public function cart_express_checkout_button_html($minicart = false) {
1940 + public function cart_express_checkout_button_html($context= 'cart') {
1800 1941 $url = $this->express_checkout_url();
1801 1942 $url = wp_nonce_url($url,'express','sec');
1802 - $context = $minicart ? 'minicart' : 'cart';
1803 1943 $button= apply_filters('woo_vipps_express_checkout_button', $this->get_html_button_for_context($context));
1804 1944 $method = $this->get_payment_method_name();
1805 1945 $title = sprintf(__('Buy now with %1$s!', 'woo-vipps'), $method);
1806 1946 $html = "<a href='$url' class='vipps-express-checkout short $method' title='$title'>$button</a>";
@@ -1843,9 +1983,9 @@
1843 1983 public function express_checkout_button_shortcode() {
1844 1984 $gw = $this->gateway();
1845 1985 if (!$gw->cart_supports_express_checkout()) return;
1846 1986 ob_start();
1847 - $this->cart_express_checkout_button_html('shortcode');
1987 + $this->cart_express_checkout_button_html('cart');
1848 1988 return ob_get_clean();
1849 1989 }
1850 1990 // Show a banner normally shown for non-logged-in-users at the checkout page. It does not need to check if we are to show the button, obviously, but needs to see if the cart works
1851 1991 public function express_checkout_banner_shortcode() {
@@ -2506,77 +2646,87 @@
2506 2646 return null;
2507 2647 }
2508 2648 }
2509 2649
2650 + // Special pages, and some callbacks. IOK 2018-05-18
2651 + public function template_redirect() {
2510 2652
2511 - // If this is a special page, return true very early because we are handling this. IOK 2023-02-22
2512 - public function pre_handle_404($current, $query) {
2513 - if (!is_admin()) {
2514 - $special = $this->is_special_page();
2515 - if ($special) {
2516 - // Ensure very early on that Autooptimize does not try to optimize us (if installed) IOK 2023-03-04
2517 - add_filter( 'autoptimize_filter_noptimize', '__return_true');
2518 - return true;
2519 - }
2653 + // Handle legacy vipps-buy-now urls that auto-start express checkout for certain product - in QR codes etc IOK 2026-09-11
2654 + // We redirect these to the new location.
2655 + $path = parse_url($_SERVER['REQUEST_URI'], PHP_URL_PATH);
2656 + if (( ($_GET['VippsSpecialPage'] ?? '') == 'vipps-buy-product') || ($path && preg_match("!/vipps-buy-product/?$!", $path)) ) {
2657 + $url = static::get_special_page_url();
2658 + $_GET['action'] = 'buy_product';
2659 + $q = build_query($_GET);
2660 + wp_redirect($url . "?" . $q, 302);
2661 + exit();
2520 2662 }
2521 - return $current;
2663 +
2664 + if (static::is_special_page()) {
2665 + // Legacy: Stop the canonical redirect here. Unclear if still necessary. IOK 2026-09-11
2666 + remove_filter('template_redirect', 'redirect_canonical', 10);
2667 + // dont cache special page. LP 2026-08-25
2668 + $this->nocache();
2669 + // Do the custom pre-load actions for these pages IOK 2026-09-11
2670 + do_action('woo_vipps_before_handling_special_page', ($_GET['action'] ?? ""));
2671 + }
2522 2672 }
2523 2673
2524 - // Special pages, and some callbacks. IOK 2018-05-18
2525 - public function template_redirect() {
2526 - global $post;
2527 - // Handle special callbacks
2528 - $special = $this->is_special_page() ;
2674 + // Ran in template redirect for the special page. IOK 2026-09-2
2675 + public function pre_special_page_actions ($action) {
2676 + // Change title dynamically depending on action. LP 2026-09-02
2677 + add_filter('the_title', [$this, 'vipps_special_page_endpoint_title'], 10, 2);
2529 2678
2530 - if ($special) {
2531 - remove_filter('template_redirect', 'redirect_canonical', 10);
2532 - do_action('woo_vipps_before_handling_special_page', $special);
2679 + // If we are handling the 'wait for payment' action, we need to poll the order status before
2680 + // we start producing content IOK 2026-09-21
2681 + if ($action == 'wait_for_payment') {
2682 + $this->handle_payment_poll_and_redirect();
2683 + }
2533 2684
2534 - // Allow above hook to actually handle special pages. It should probably call $Vipps->fakepage or a redirect; can be used
2535 - // to intercept express checkout etc. IOK 2022-03-18
2536 - if (! apply_filters('woo_vipps_special_page_handled', false, $special)) {
2537 - $this->$special();
2538 - }
2685 + // Some validation is required for this action
2686 + if ($action == 'do_express_checkout') {
2687 + $this->vipps_express_checkout_consistency_check();
2539 2688 }
2689 + }
2540 2690
2541 - $consentremoval = $this->is_consent_removal();
2542 - if ($consentremoval) {
2543 - remove_filter('template_redirect', 'redirect_canonical', 10);
2544 - do_action('woo_vipps_before_handling_special_page', 'consentremoval');
2545 - if (! apply_filters('woo_vipps_special_page_handled', false, 'consentremoval')) {
2546 - $this->vipps_consent_removal_callback($consentremoval);
2691 +
2692 + // Dynamic special page title depending on endpoint/action, only frontend. LP 2026-09-02
2693 + public function vipps_special_page_endpoint_title($title, $postid = 0) {
2694 + global $wp_query;
2695 + // Comment from woocommerce's wc_page_endpoint_title where this logic is from: LP 2026-09-02
2696 +
2697 + // In block themes the whole template (header, footer, content) renders inside the main
2698 + // loop, so `the_title` fires for any post title rendered on the page (e.g. a product in a
2699 + // server-rendered mini-cart) - not just the page's own heading. Only replace the title of
2700 + // the queried page so an earlier title doesn't consume this one-shot filter.
2701 + if ( ! is_null( $wp_query ) && ! is_admin() && is_main_query() && in_the_loop() && is_page() && $postid == static::get_special_page_id() ) {
2702 + switch ($_GET['action'] ?? '') {
2703 + case 'wait_for_payment':
2704 + $title = __('Processing order', 'woo-vipps');
2705 + break;
2706 + case 'do_express_checkout':
2707 + case 'buy_product':
2708 + $title = __('Express Checkout', 'woo-vipps');
2709 + break;
2547 2710 }
2548 2711 }
2712 + return $title;
2549 2713 }
2714 +
2550 2715 // Template handling for special pages. IOK 2018-11-21
2716 + // This is legacy - the special page is now a real page, so it can have a special template using standard WP methods. IOK 2026-09-11
2551 2717 public function template_include($template) {
2552 - $special = $this->is_special_page() ;
2553 - if ($special) {
2718 + if (static::is_special_page()) {
2554 2719 // Get any special template override from the options IOK 2020-02-18
2555 2720 $specific = $this->gateway()->get_option('vippsspecialpagetemplate');
2556 2721 $found = locate_template($specific,false,false);
2557 2722 if ($found) $template=$found;
2558 2723
2559 - return apply_filters('woo_vipps_special_page_template', $template, $special);
2724 + return apply_filters('woo_vipps_special_page_template', $template, $_GET['action'] ?? '');
2560 2725 }
2561 2726 return $template;
2562 2727 }
2563 2728
2564 -
2565 - // Can't use wc-api for this, as that does not support DELETE . IOK 2018-05-18
2566 - private function is_consent_removal () {
2567 -
2568 - if ($_SERVER['REQUEST_METHOD'] != 'DELETE') return false;
2569 - if ( !get_option('permalink_structure')) {
2570 - if (@$_REQUEST['vipps-consent-removal']) return @$_REQUEST['callback'];
2571 - return false;
2572 - }
2573 - if (preg_match("!/vipps-consent-removal/([^/]*)!", $_SERVER['REQUEST_URI'], $matches)) {
2574 - return @$_REQUEST['callback'];
2575 - }
2576 - return false;
2577 - }
2578 -
2579 2729 // On the thank you page, we have a completed order, so we need to restore any saved cart and possibly log in
2580 2730 // the user if using Express Checkout IOK 2020-10-09
2581 2731 public function woocommerce_before_thankyou ($orderid) {
2582 2732 $order = wc_get_order($orderid);
@@ -2581,9 +2731,9 @@
2581 2731 public function woocommerce_before_thankyou ($orderid) {
2582 2732 $order = wc_get_order($orderid);
2583 2733 if ($order) {
2584 2734 // Requires that this is express checkout and that 'create users on express checkout' is chosen. IOK 2020-10-09
2585 - // -- or the same thing for Vipps Checkout. Also, the NHG code should not be running, and there is a filter, too. IOK 2023-08-04
2735 + // -- or the same thing for Checkout. Also, the NHG code should not be running, and there is a filter, too. IOK 2023-08-04
2586 2736 $this->maybe_log_in_user($order);
2587 2737 $order->delete_meta_data('_vipps_limited_session');
2588 2738 $order->save();
2589 2739
@@ -2644,9 +2794,8 @@
2644 2794
2645 2795 // Support adding pickup locations to any shipping rate using the 'woo_vipps_shipping_method_pickup_points' filter
2646 2796 // IOK 2025-11-19
2647 2797 add_filter('woo_vipps_modify_express_checkout_rate', array($this, 'express_add_pickup_location_options'), 10, 4);
2648 -
2649 2798 }
2650 2799
2651 2800 public function get_payment_method_name() {
2652 2801 return $this->gateway()->get_option('payment_method_name');
@@ -2666,14 +2815,13 @@
2666 2815 public function after_setup_theme() {
2667 2816 // To facilitate development, allow loading the plugin-supplied translations. Must be called here at the earliest.
2668 2817 $ok = Vipps::load_plugin_textdomain('woo-vipps', false, basename( dirname( dirname( __FILE__ ) ) ) . "/languages");
2669 2818
2670 - // Vipps Checkout replaces the default checkout page, and currently uses its own page for this which needs to exist
2819 + // Checkout replaces the default checkout page, and currently uses its own page for this which needs to exist
2671 2820 // Will also probably be used to maintain a real utility-page for Vipps actions later for themes where this
2672 2821 // is important.
2673 2822 add_filter('woocommerce_create_pages', array($this, 'woocommerce_create_pages'), 50, 1);
2674 2823
2675 -
2676 2824 // Callbacks use the Woo API IOK 2018-05-18
2677 2825 add_action( 'woocommerce_api_wc_gateway_vipps', array($this,'vipps_callback'));
2678 2826 add_action( 'woocommerce_api_vipps_shipping_details', array($this,'vipps_shipping_details_callback'));
2679 2827
@@ -2684,9 +2832,9 @@
2684 2832 add_action( 'woocommerce_cart_actions', array($this, 'cart_express_checkout_button'));
2685 2833 add_action( 'woocommerce_widget_shopping_cart_buttons', array($this, 'minicart_express_checkout_button'), 30);
2686 2834
2687 2835 // Previously we added an express html banner to the action 'woocommerce_before_checkout_form.',
2688 - // replaced by the new express buttons in manner more like Gutenberg. LP 2026-03-23
2836 + // replaced by the new express buttons in manner more like Gutenberg. for grepping: "express legacy checkout". LP 2026-03-23
2689 2837 add_action('woocommerce_checkout_before_customer_details', array($this, 'checkout_before_customer_details_express'), 5);
2690 2838
2691 2839 add_action('woocommerce_after_add_to_cart_button', array($this, 'single_product_buy_now_button'));
2692 2840 add_action('woocommerce_after_shop_loop_item', array($this, 'loop_single_product_buy_now_button'), 20);
@@ -2691,12 +2839,10 @@
2691 2839 add_action('woocommerce_after_add_to_cart_button', array($this, 'single_product_buy_now_button'));
2692 2840 add_action('woocommerce_after_shop_loop_item', array($this, 'loop_single_product_buy_now_button'), 20);
2693 2841
2694 2842
2695 - // Special pages and callbacks handled by template_redirect
2696 - // We must also notify WP and other plugins that we are handling this 404-like situation. IOK 2023-02-22
2843 + // Special pages and callbacks handled by template_redirect. IOK 2023-02-22
2697 2844 add_action('template_redirect', array($this,'template_redirect'),1);
2698 - add_action('pre_handle_404', array($this, 'pre_handle_404'), 1, 2);
2699 2845
2700 2846 // Allow overriding their templates
2701 2847 add_filter('template_include', array($this,'template_include'), 10, 1);
2702 2848
@@ -2982,14 +3128,14 @@
2982 3128
2983 3129 $raw_post = @file_get_contents( 'php://input' );
2984 3130 $result = @json_decode($raw_post,true);
2985 3131
2986 - // This handler handles both Vipps Checkout and Vipps ECom IOK 2021-09-02
3132 + // This handler handles both Checkout and Vipps ECom IOK 2021-09-02
2987 3133 // .. and the epayment webhooks 2023-12-19
2988 3134 $ischeckout = false;
2989 3135 $iswebhook = false;
2990 3136 $callback = isset($_REQUEST['callback']) ? $_REQUEST['callback'] : "";
2991 - // For Vipps Checkout v3 and onwards, we control the callback so the type is just this field
3137 + // For Checkout v3 and onwards, we control the callback so the type is just this field
2992 3138 if ($callback == 'checkout') {
2993 3139 $ischeckout = true;
2994 3140 }
2995 3141 // For the webhooks, we will add 'webhook' to the result, but we also know that 'pspReference' will be present. IOK 2023-12-19
@@ -3403,10 +3549,10 @@
3403 3549 $this->log(sprintf(__("Wrong %1\$s Orderid on shipping details callback", 'woo-vipps'), $this->get_payment_method_name()), 'warning');
3404 3550 exit();
3405 3551 }
3406 3552
3407 - // If we are doing this for Vipps Checkout after version 3, communicate to any shipping methods with
3408 - // special support for Vipps Checkout that this is in fact happening. IOK 2023-01-19
3553 + // If we are doing this for Checkout after version 3, communicate to any shipping methods with
3554 + // special support for Checkout that this is in fact happening. IOK 2023-01-19
3409 3555 // This needs to be done before "calculate totals".
3410 3556 // Moved from "vipps_shipping_details_callback_handler" because we need it before restoring sessions. IOK 2025-05-06
3411 3557 $ischeckout = $order->get_meta('_vipps_checkout');
3412 3558
@@ -3582,9 +3728,9 @@
3582 3728 ), 'debug');
3583 3729
3584 3730 }
3585 3731
3586 - // Add shipping tax rates to the *order* so we can calculate this correctly when using Vipps Checkouts
3732 + // Add shipping tax rates to the *order* so we can calculate this correctly when using Checkouts
3587 3733 // 'dynamic pricing' 2023-01-26
3588 3734 // Which may be deprecated, but anyway, for future use IOK 2025-08-14
3589 3735 $taxrate = 0;
3590 3736 if (is_array($shipping_tax_rates) && !empty($shipping_tax_rates)) {
@@ -3710,9 +3856,9 @@
3710 3856 $vippsmethod['shippingMethod'] = $rate->get_label();
3711 3857 $vippsmethod['shippingMethodId'] = $key;
3712 3858 $vippsmethods[]=$vippsmethod;
3713 3859
3714 - // Metadata and settings stored for later use for Vipps Checkout
3860 + // Metadata and settings stored for later use for Checkout
3715 3861 // and express checkout - basically, for each *key* have the corresponding object. IOK 2025-08-15
3716 3862 // In the end, this data will be serialized and stored in the Order, and used in the gateways method set_order_shipping_details to
3717 3863 // finalize the order. IOK 2025-08-15
3718 3864 $ratemap[$key]=$rate;
@@ -3730,9 +3876,9 @@
3730 3876 // This then is the old Express Checkout format, which we have exposed in filters. IOK 2025-08-14
3731 3877 $return = array('addressId'=>intval($addressid), 'orderId'=>$vippsorderid, 'shippingDetails'=>$vippsmethods);
3732 3878 $return = apply_filters('woo_vipps_vipps_formatted_shipping_methods', $return); // Mostly for debugging
3733 3879
3734 - // IOK 2021-11-16 Vipps Checkout uses a slightly different syntax and format.
3880 + // IOK 2021-11-16 Checkout uses a slightly different syntax and format.
3735 3881 // IOK 2025-08-15 and new Express yet another slightly different format.
3736 3882 // IOK 2025-08-15 pass the ratemap as a reference, so transforms can update them
3737 3883 if ($ischeckout) {
3738 3884 $return = VippsCheckout::instance()->format_shipping_methods($return, $ratemap, $methodmap, $order);
@@ -4022,9 +4168,9 @@
4022 4168 WC()->cart->calculate_totals();
4023 4169 WC()->cart->set_session();
4024 4170 return true;
4025 4171 } catch (Exception $e) {
4026 - $this->log(sprintf(__("Error regenerating cart from order %1\$d: %2\$s", 'woo-vipps'), $order_id, $e->get_message()), 'error');
4172 + $this->log(sprintf(__("Error regenerating cart from order %1\$d: %2\$s", 'woo-vipps'), $order_id, $e->getMessage()), 'error');
4027 4173 return false;
4028 4174 }
4029 4175 }
4030 4176
@@ -4108,17 +4254,8 @@
4108 4254 header("X-Accel-Expires: 0");
4109 4255 }
4110 4256
4111 4257
4112 -
4113 - // Handle DELETE on a vipps consent removal callback
4114 - public function vipps_consent_removal_callback ($callback) {
4115 - Vipps::nocache();
4116 - // Currently, no such requests will be posted, and as this code isn't sufficiently tested,we'll just have
4117 - // to escape here when the API is changed. IOK 2020-10-14
4118 - $this->log("Consent removal is non-functional pending API changes as of 2020-10-14"); print "1"; exit();
4119 - }
4120 -
4121 4258 public function woocommerce_payment_gateways($methods) {
4122 4259 require_once(dirname(__FILE__) . "/WC_Gateway_Vipps.class.php");
4123 4260 require_once(dirname(__FILE__) . "/WC_Gateway_VippsCard.class.php");
4124 4261 // Protect the singleton: Use the object instead of the class name IOK 2025-02-04
@@ -4143,9 +4280,11 @@
4143 4280 if ( empty($_REQUEST['add-to-cart']) || ! is_numeric($_REQUEST['add-to-cart']) || empty($_REQUEST['vipps_compat_mode']) || !$_REQUEST['vipps_compat_mode']) {
4144 4281 return $url;
4145 4282 }
4146 4283 $url = $this->express_checkout_url();
4147 - $url = wp_nonce_url($url,'express','sec');
4284 + // At this point, there is always a query argument here. IOK 2026-09-21
4285 + $nonce = wp_create_nonce('express');
4286 + $url = $url . "&sec=$nonce";
4148 4287
4149 4288 return $url;
4150 4289 }
4151 4290
@@ -4212,9 +4351,9 @@
4212 4351 // Poll status and correct woo status. LP 2026-05-19
4213 4352 $order_data = $gw->get_payment_details($order);
4214 4353
4215 4354 // If we already know the order failed, we don't need to process the order further below. LP 2026-05-19
4216 - if ('CANCEL' === $order_data['STATE']) {
4355 + if ('CANCEL' === ($order_data['state'] ?? "")) {
4217 4356 /* translators: company name */
4218 4357 $order->update_status('cancelled', sprintf(__('Payment cancelled at %1$s.', 'woo-vipps'), Vipps::CompanyName()));
4219 4358 return;
4220 4359 }
@@ -4241,20 +4380,40 @@
4241 4380 }
4242 4381 }
4243 4382
4244 4383 public function activate () {
4245 - static::maybe_add_cron_event();
4246 - $gw = $this->gateway();
4384 + static::maybe_add_cron_event();
4385 + $gw = $this->gateway();
4247 4386
4248 - // If store is using the default "Woo" orderprefix, generate a new one, this time using the stores' sitename if possible. IOK 2020-05-19
4249 - if ($gw->get_option('orderprefix') == 'Woo') {
4250 - $gw->update_option('orderprefix', $this->generate_order_prefix());
4251 - }
4252 - // IOK 2023-12-20 for the epayment api, we need to re-initialize webhooks at this point.
4253 - $gw->initialize_webhooks();
4254 - $this->payment_method_name = $gw->get_option('payment_method_name');
4255 - }
4387 + // If store is using the default "Woo" orderprefix, generate a new one, this time using the stores' sitename if possible. IOK 2020-05-19
4388 + if ($gw->get_option('orderprefix') == 'Woo') {
4389 + $gw->update_option('orderprefix', $this->generate_order_prefix());
4390 + }
4391 + // IOK 2023-12-20 for the epayment api, we need to re-initialize webhooks at this point.
4392 + $gw->initialize_webhooks();
4393 + $this->payment_method_name = $gw->get_option('payment_method_name');
4256 4394
4395 +
4396 + // Check if the special page is noted and actually does exist
4397 + $special = static::get_special_page_id();
4398 + if ($special) {
4399 + $special_page = get_post($special);
4400 + if ($special_page && 'trash' !== $special_page->post_status) {
4401 + // Ensure this page has the necessary shortcode. LP 2026-09-01
4402 + if (!has_shortcode($special_page->post_content, 'vipps_special_page')) {
4403 + $new_content = $special_page->post_content . "\n\n<!-- wp:shortcode -->[vipps_special_page]<!-- /wp:shortcode -->";
4404 + wp_update_post([
4405 + 'ID' => $special,
4406 + 'post_content' => $new_content,
4407 + ]);
4408 + }
4409 + } else {
4410 + delete_option('woocommerce_vipps_special_page_page_id');
4411 + }
4412 + }
4413 +
4414 + }
4415 +
4257 4416 // We have added some hooks to wp-cron; remove these. IOK 2020-04-01
4258 4417 public static function deactivate() {
4259 4418 $timestamp = wp_next_scheduled('vipps_cron_cleanup_hook');
4260 4419 wp_unschedule_event($timestamp, 'vipps_cron_cleanup_hook');
@@ -4307,9 +4466,10 @@
4307 4466 // If setting is true, use Vipps as default payment. Called by the woocommrece_cart_updated hook. IOK 2018-06-06
4308 4467 private function maybe_set_vipps_as_default() {
4309 4468 if (WC()->session->get('chosen_payment_method')) return; // User has already chosen payment method, so we're done.
4310 4469 $gw = $this->gateway();
4311 - if ($gw->get_option('vippsdefault')=='yes') {
4470 + // Do *not* default to vipps if Kustom Checkout is installed IOK 2026-09-11
4471 + if ($gw->get_option('vippsdefault')=='yes' && !class_exists('KCO')) {
4312 4472 WC()->session->set('chosen_payment_method', $gw->id);
4313 4473 }
4314 4474 }
4315 4475
@@ -4414,13 +4574,13 @@
4414 4574 if (is_user_logged_in()) return;
4415 4575 if (!$order || ! self::is_vipps_order($order)) return;
4416 4576
4417 4577 // We *do* want to log in express checkout customers, but not those that
4418 - // use the Vipps Checkout solution - those can change their emails in the
4578 + // use the Checkout solution - those can change their emails in the
4419 4579 // checkout screen. IOK 2021-09-03
4420 4580 $do_login = $order->get_meta('_vipps_express_checkout');
4421 4581
4422 - // We will not log in Vipps Checkout users unless the option for that is true
4582 + // We will not log in Checkout users unless the option for that is true
4423 4583 if ($order->get_meta('_vipps_checkout') && 'yes' != $this->gateway()->get_option('checkoutcreateuser')) {
4424 4584 $do_login = false;
4425 4585 }
4426 4586
@@ -4455,9 +4615,9 @@
4455 4615
4456 4616 // Both Checkout and Express Checkout have the below value set to true
4457 4617 if (!$order->get_meta('_vipps_express_checkout')) return;
4458 4618
4459 - // Creating/logging in users are handled separately for Vipps Checkout and Express Checkout, so check the correct setting
4619 + // Creating/logging in users are handled separately for Checkout and Express Checkout, so check the correct setting
4460 4620 // IOK 2023-07-27
4461 4621 $ischeckout = $order->get_meta('_vipps_checkout');
4462 4622 if ($ischeckout) {
4463 4623 if ($this->gateway()->get_option('checkoutcreateuser') != 'yes') return null;
@@ -4557,9 +4717,10 @@
4557 4717 }
4558 4718 if (!$o) return;
4559 4719 if (!$o->get_meta('_vipps_single_product_express')) return;
4560 4720 if ($failed && !apply_filters('woo_vipps_restore_cart_on_express_checkout_failure', true, $o)) return;
4561 - if ($failed) WC()->cart->empty_cart();
4721 + // Restoring cart! But clear it first so we dont add this single product to the restored cart. LP 2026-09-22
4722 + WC()->cart->empty_cart();
4562 4723 $this->restore_cart($o);
4563 4724 }
4564 4725
4565 4726
@@ -4842,9 +5003,9 @@
4842 5003 $ok = wc()->shipping->register_shipping_method( new Automattic\WooCommerce\Blocks\Shipping\PickupLocation() );
4843 5004 }
4844 5005 }
4845 5006
4846 - // Vipps Checkout and Express Checkout allows loading specific kinds of shipping methods with non-standard APIs, such as PickupLocations. IOK 2025-05-08
5007 + // Checkout and Express Checkout allows loading specific kinds of shipping methods with non-standard APIs, such as PickupLocations. IOK 2025-05-08
4847 5008 // Must be called *early*. IOK 2025-05-08. Called in callback methods, and if using static shipping, in the 'start session' callback.
4848 5009 public function load_extra_shipping_methods($order, $addressdata, $ischeckout=false) {
4849 5010 // If we need to add more shipping methods *before* the shipping callback starts, it must be done before we load the session. IOK 2025-05-06
4850 5011 add_action('woocommerce_load_shipping_methods', function () use ($order, $addressdata) {
@@ -4915,46 +5076,37 @@
4915 5076 wp_send_json(array('status'=>'error', 'msg'=> __('Unknown payment status','woo-vipps') . ' ' . $payment));
4916 5077 return false;
4917 5078 }
4918 5079
4919 - // The various return URLs for special pages of the Vipps stuff depend on settings and pretty-URLs so we supply them from here
4920 - // These are for the "fallback URL" mostly. IOK 2018-05-18
4921 - private function make_vipps_url($what) {
4922 - if ( !get_option('permalink_structure')) {
4923 - return add_query_arg('VippsSpecialPage', $what, home_url("/", 'https'));
4924 - }
4925 - return trailingslashit(home_url($what, 'https'));
5080 + // The various return URLs for special pages of the Vipps stuff. Previously used a fake page and had to check permalink_structure. LP 2026-08-26
5081 + private function make_special_page_url($action) {
5082 + return add_query_arg('action', $action, $this->get_special_page_url());
4926 5083 }
5084 +
4927 5085 public function payment_return_url() {
4928 - return apply_filters('woo_vipps_payment_return_url', $this->make_vipps_url('vipps-betaling'));
5086 + return apply_filters('woo_vipps_payment_return_url', $this->make_special_page_url('wait_for_payment'));
4929 5087 }
4930 5088 public function express_checkout_url() {
4931 - return $this->make_vipps_url('vipps-express-checkout');
5089 + return $this->make_special_page_url('do_express_checkout');
4932 5090 }
4933 5091 public function buy_product_url() {
4934 - return $this->make_vipps_url('vipps-buy-product');
5092 + return $this->make_special_page_url('buy_product');
4935 5093 }
4936 5094
4937 - // Return the method in the Vipps
4938 - public function is_special_page() {
4939 - $specials = array('vipps-betaling' => 'vipps_wait_for_payment', 'vipps-express-checkout'=>'vipps_express_checkout', 'vipps-buy-product'=>'vipps_buy_product');
4940 - $method = null;
4941 - if ( get_option('permalink_structure')) {
4942 - foreach($specials as $special=>$specialmethod) {
4943 - // IOK 2018-06-07 Change to add any prefix from home-url for better matching IOK 2018-06-07
4944 - $path = parse_url($_SERVER['REQUEST_URI'], PHP_URL_PATH);
4945 - if ($path && preg_match("!/$special/?$!", $path, $matches)) {
4946 - $method = $specialmethod; break;
4947 - }
4948 - }
4949 - } else {
4950 - if (isset($_GET['VippsSpecialPage'])) {
4951 - $method = @$specials[$_GET['VippsSpecialPage']];
4952 - }
4953 - }
4954 - return $method;
5095 + public static function is_special_page() {
5096 + $id = static::get_special_page_id();
5097 + return $id && is_page($id);
4955 5098 }
4956 5099
5100 + public static function get_special_page_id() {
5101 + $id = wc_get_page_id('vipps_special_page'); // -1 if not found
5102 + return $id > 0 ? $id : null;
5103 + }
5104 +
5105 + public static function get_special_page_url() {
5106 + return get_permalink(static::get_special_page_id());
5107 + }
5108 +
4957 5109 // Just create a spinner and a overlay.
4958 5110 public function spinner () {
4959 5111 $flavour = sanitize_title($this->get_payment_method_name());
4960 5112 ob_start();
@@ -5001,16 +5153,8 @@
5001 5153 }
5002 5154 return null;
5003 5155 }
5004 5156
5005 - // DEPRECATED: Legacy function as of new web component express buttons. see get_buy_now_button and get_html_button. LP 2026-06-26
5006 - public function get_buy_now_button_manual($product_id, $variation_id=null, $sku=null, $disabled=false, $classes='',
5007 - $_logo_variant=null, $_logo_lang=null, // deprecated params
5008 - $context='global', $button_args_override = [],
5009 - ) {
5010 - return $this->get_buy_now_button($product_id, $variation_id, $sku, $disabled, $classes, $context, $button_args_override);
5011 - }
5012 -
5013 5157 // Code that will generate various versions of the 'buy now with Vipps' button IOK 2018-09-27
5014 5158 // $context is slug describing where its to be used, like 'catalog', 'cart', 'product' etc. and will
5015 5159 // be used unless $button_args_override is nonempty. See init_button_options() and get_html_button() LP 2026-06-26
5016 5160 public function get_buy_now_button($product_id,$variation_id=null,$sku=null,$disabled=false, $classes='', $context='global', $button_args_override = []) {
@@ -5029,9 +5173,8 @@
5029 5173 if ($sku) $data['product_sku'] = $sku;
5030 5174 if ($product_id) $data['product_id'] = $product_id;
5031 5175 if ($variation_id) $data['variation_id'] = $variation_id;
5032 5176
5033 -
5034 5177 $buttoncode = "<a href='javascript:void(0)' $disabled ";
5035 5178 foreach($data as $key=>$value) {
5036 5179 $value = esc_attr($value);
5037 5180 $buttoncode .= " data-$key='$value' ";
@@ -5055,8 +5198,11 @@
5055 5198 if ($classes) $classes = " $classes";
5056 5199 if ($short) $classes = "short $classes";
5057 5200
5058 5201 $buttoncode .= " class='single-product button vipps-buy-now $payment_method $disabled$classes' title='$title'>$button</a>";
5202 +
5203 +
5204 +
5059 5205 return apply_filters('woo_vipps_buy_now_button', $buttoncode, $product_id, $variation_id, $sku, $disabled);
5060 5206 }
5061 5207
5062 5208 // Display a 'buy now with express checkout' button on the product page IOK 2018-09-27
@@ -5140,43 +5286,90 @@
5140 5286 }
5141 5287
5142 5288
5143 5289
5144 - // Vipps Checkout replaces the default checkout page, and currently uses its own page for this which needs to exist
5290 + // Checkout replaces the default checkout page, and currently uses its own page for this which needs to exist
5145 5291 // IOK 2026-04-30 remove this when checkout is end-of-life'd
5292 + // We now also use this for the vipps special page, previously a fakepage. LP 2026-08-18
5146 5293 public function woocommerce_create_pages ($data) {
5294 + // Vipps Checkout page
5147 5295 $vipps_checkout_activated = get_option('woo_vipps_checkout_activated', false);
5148 - if (!$vipps_checkout_activated) return $data;
5296 + if ($vipps_checkout_activated) {
5297 + $data['vipps_checkout'] = array(
5298 + 'name' => _x( 'vipps_checkout', 'Page slug', 'woo-vipps' ),
5299 + 'title' => _x( 'Vipps MobilePay Checkout', 'Page title', 'woo-vipps' ),
5300 + 'content' => '<!-- wp:shortcode -->[' . 'vipps_checkout' . ']<!-- /wp:shortcode -->',
5301 + );
5302 + }
5149 5303
5150 - $data['vipps_checkout'] = array(
5151 - 'name' => _x( 'vipps_checkout', 'Page slug', 'woo-vipps' ),
5152 - 'title' => _x( 'Vipps MobilePay Checkout', 'Page title', 'woo-vipps' ),
5153 - 'content' => '<!-- wp:shortcode -->[' . 'vipps_checkout' . ']<!-- /wp:shortcode -->',
5154 - );
5155 -
5304 + // Vipps special page for certain payment flow actions. Previously a fake page. LP 2026-08-18
5305 + $data['vipps_special_page'] = [
5306 + 'name' => 'vipps-payment', // slug
5307 + /* translators: company name */
5308 + 'title' => sprintf(__('%s special page', 'woo-vipps'), static::CompanyName()), // we hide the title frontend in template_redirect. LP 2026-08-27
5309 + 'content' => '<!-- wp:shortcode -->[vipps_special_page]<!-- /wp:shortcode -->',
5310 + ];
5156 5311 return $data;
5157 5312 }
5158 5313
5159 - // Creates any necessary Vipps pages. Will be called e.g. when activating Vipps Checkout or turning it on.
5314 + // Creates any necessary Vipps pages. E.g vipps checkout page or vipps special page. LP 2026-09-01
5315 + // If a page slug already exists, then it won't overwrite or duplicate it!. LP 2026-09-02
5160 5316 public function maybe_create_vipps_pages () {
5317 + $make_pages = false;
5318 +
5319 + // Vipps Checkout page. LP 2026-08-18
5161 5320 $checkoutid = wc_get_page_id('vipps_checkout');
5162 - $makeit = !$checkoutid || ! get_post_status($checkoutid);
5163 - if ($makeit) {
5321 + if (!$checkoutid || ! get_post_status($checkoutid)) {
5164 5322 delete_option('woocommerce_vipps_checkout_page_id');
5323 + $make_pages = true;
5165 5324 }
5166 5325
5167 - if ($makeit) {
5168 - WC_Install::create_pages();
5326 + // vipps special page, previously a fake page. LP 2026-08-18
5327 + $builtin_special_page_id = static::get_special_page_id();
5328 + if (!$builtin_special_page_id || !get_post_status($builtin_special_page_id)) {
5329 + delete_option('woocommerce_vipps_special_page_page_id');
5330 + $make_pages = true;
5169 5331 }
5332 +
5333 + if ($make_pages) {
5334 + WC_Install::create_pages();
5335 + }
5170 5336 }
5171 5337
5338 + public function vipps_special_page_shortcode($atts, $content) {
5339 + // No point in expanding this unless we are actually doing the special actions. LP 2026-08-25
5340 + if (is_admin()) return;
5341 + if (wp_doing_ajax()) return;
5342 + if (defined('REST_REQUEST') && REST_REQUEST) return;
5343 + if (did_filter('woo_vipps_special_page_html')) return; // User has somehow added two shortcodes. IOK 2026-09-18
5172 5344
5345 + $action = $_GET['action'] ?? '';
5346 + $html = "";
5347 + switch ($action) {
5348 + case 'wait_for_payment':
5349 + $html = $this->vipps_wait_for_payment();
5350 + break;
5351 + case 'do_express_checkout':
5352 + $html = $this->vipps_express_checkout();
5353 + break;
5354 + case 'buy_product':
5355 + $html = $this->vipps_buy_product();
5356 + break;
5357 + default:
5358 + $html = '';
5359 + }
5360 + // This is mostly to avoid this shortcode evaluating twice IOK 2026-09-18
5361 + $html = apply_filters('woo_vipps_special_page_html', $html, $action);
5362 +
5363 + // Remember, this is a shortcode, so the html must be returned, not echoed IOK 2026-09-11
5364 + return $html;
5365 + }
5366 +
5367 +
5173 5368 // This URL will when accessed add a product to the cart and go directly to the express checkout page.
5174 5369 // The argument passed must be a shareable link created for a given product - so this in effect acts as a landing page for
5175 5370 // the buying thru Vipps Express Checkout of a single product linked to in for instance banners. IOK 2018-09-24
5176 5371 public function vipps_buy_product() {
5177 - status_header(200,'OK');
5178 - Vipps::nocache();
5179 5372
5180 5373 add_filter('body_class', function ($classes) {
5181 5374 $classes[] = 'vipps-express-checkout';
5182 5375 $classes[] = 'woocommerce-checkout'; // Required by Pixel Your Site IOK 2022-11-24
@@ -5212,9 +5405,9 @@
5212 5405
5213 5406 if (!$productinfo) {
5214 5407 $title = __("Product is no longer available",'woo-vipps');
5215 5408 $content = __("The link you have followed is for a product that is no longer available at this location. Please return to the store and try again",'woo-vipps');
5216 - return $this->fakepage($title,$content);
5409 + return $this->special_page_html($title,$content);
5217 5410 }
5218 5411
5219 5412 // Pass the productinfo to the express checkout form
5220 5413 $args = array();
@@ -5231,20 +5424,16 @@
5231 5424 }
5232 5425 $args[sanitize_title(wp_unslash($key))] = sanitize_text_field(wp_unslash($value));
5233 5426 }
5234 5427
5235 - $this->print_express_checkout_page(true,'do_single_product_express_checkout',$args);
5428 + return $this->express_checkout_page_html(true,'do_single_product_express_checkout',$args);
5236 5429 }
5237 5430
5238 - // This is a landing page for the express checkout of then normal cart - it is done like this because this could take time on slower hosts.
5239 - public function vipps_express_checkout() {
5240 - status_header(200,'OK');
5241 - Vipps::nocache();
5431 + public function vipps_express_checkout_consistency_check() {
5242 5432 // We need a nonce to get here, but we should only get here when we have a cart, so this will not be cached.
5243 5433 // IOK 2018-05-28
5244 5434 $ok = isset($_REQUEST['sec']) && wp_verify_nonce($_REQUEST['sec'],'express');
5245 5435
5246 -
5247 5436 $backurl = wp_validate_redirect(@$_SERVER['HTTP_REFERER']);
5248 5437 if (!$backurl) $backurl = home_url();
5249 5438
5250 5439 if (!$ok) {
@@ -5258,8 +5447,19 @@
5258 5447 wp_redirect($backurl);
5259 5448 exit();
5260 5449 }
5261 5450
5451 + add_filter('woo_vipps_express_checkout_consistent', '__return_true');
5452 + }
5453 +
5454 + // This is a landing page for the express checkout of then normal cart - it is done like this because this could take time on slower hosts.
5455 + public function vipps_express_checkout() {
5456 + // Some checks are made in template_redirect, we check here if they are ok IOK 2026-09-21
5457 + if (!apply_filters('woo_vipps_express_checkout_consistent', false)) {
5458 + $content = __('Link expired, please try again', 'woo-vipps');
5459 + return $content;
5460 + }
5461 +
5262 5462 add_filter('body_class', function ($classes) {
5263 5463 $classes[] = 'vipps-express-checkout';
5264 5464 $classes[] = 'woocommerce-checkout'; // Required by Pixel Your Site IOK 2022-11-24
5265 5465 return apply_filters('woo_vipps_express_checkout_body_class', $classes);
@@ -5266,9 +5466,9 @@
5266 5466 });
5267 5467
5268 5468 do_action('woo_vipps_express_checkout_page');
5269 5469
5270 - $this->print_express_checkout_page(true, 'do_express_checkout');
5470 + return $this->express_checkout_page_html(true, 'do_express_checkout');
5271 5471 }
5272 5472
5273 5473 // This method tries to ensure that a customer does not 'lose' the return page and
5274 5474 // starts ordering the same products twice. IOK 2020-01-22
@@ -5363,9 +5563,10 @@
5363 5563 return $orderspec;
5364 5564 }
5365 5565
5366 5566 // Used as a landing page for launching express checkout - borh for the cart and for single products. IOK 2018-09-28
5367 - protected function print_express_checkout_page($execute,$action,$productinfo=null) {
5567 + // Returns the html. LP 2026-08-27
5568 + protected function express_checkout_page_html($execute,$action,$productinfo=null) {
5368 5569 $gw = $this->gateway();
5369 5570
5370 5571 $expressCheckoutMessages = array();
5371 5572 $expressCheckoutMessages['termsAndConditionsError'] = __( 'Please read and accept the terms and conditions to proceed with your order.', 'woocommerce' );
@@ -5448,10 +5649,9 @@
5448 5649
5449 5650 if ($execute) {
5450 5651 $content .= "<p id=waiting>" . __("Please wait while we are preparing your order", 'woo-vipps') . "</p>";
5451 5652 $content .= "<div id='vipps-status-message'></div>";
5452 - $this->fakepage(__('Order in progress','woo-vipps'), $content);
5453 - return;
5653 + return $this->special_page_html('', $content);
5454 5654 } else {
5455 5655 $content .= $askForConfirmationHTML;
5456 5656 $content .= $extraHTML;
5457 5657 $content .= $termsHTML;
@@ -5458,21 +5658,16 @@
5458 5658 $content .= apply_filters('woo_vipps_express_checkout_validation_elements', '');
5459 5659 $title = sprintf(__('Buy now with %1$s!', 'woo-vipps'), $this->get_payment_method_name());
5460 5660 $content .= "<div class='vipps_buy_now_wrapper noloop'><a href='#' id='do-express-checkout' class='vipps-express-checkout' title='$title'>$buttonhtml</a></div>";
5461 5661 $content .= "<div id='vipps-status-message'></div>";
5462 - $this->fakepage(sprintf(__('%1$s Express Checkout','woo-vipps'), $this->get_payment_method_name()), $content);
5463 - return;
5662 + return $this->special_page_html('', $content);
5464 5663 }
5465 5664 }
5466 5665
5467 5666
5468 -
5469 - public function vipps_wait_for_payment() {
5470 - status_header(200,'OK');
5471 - Vipps::nocache();
5472 -
5667 + // Called in template_redirect before we get to the wait-for-payment page IOK 2026-09-21
5668 + private function handle_payment_poll_and_redirect () {
5473 5669 $orderid = WC()->session->get('_vipps_pending_order');
5474 -
5475 5670 $order = null;
5476 5671 $gw = $this->gateway();
5477 5672
5478 5673 // Failsafe for when the session disappears IOK 2018-11-19
@@ -5484,9 +5679,9 @@
5484 5679 // If so, we will read the order id from the GET arguments and check if the auth token is correct,
5485 5680 // simulating the session with that.
5486 5681 // IOK 2019-11-19, changed to using GET 2023-01-23
5487 5682 if ($no_session && $limited_session) {
5488 - $orderid = intval(@$_GET['id']);
5683 + $orderid = intval($_GET['id'] ?? false);
5489 5684 }
5490 5685 if ($orderid) {
5491 5686 clean_post_cache($orderid);
5492 5687 $order = wc_get_order($orderid);
@@ -5505,11 +5700,8 @@
5505 5700 $session->set('_vipps_pending_order', $orderid);
5506 5701 }
5507 5702 }
5508 5703
5509 -
5510 - do_action('woo_vipps_wait_for_payment_page',$order);
5511 -
5512 5704 $deleted_order=0;
5513 5705 if ($orderid && !$order) {
5514 5706 // If this happens, we actually did have an order, but it has been deleted, which must mean that it was cancelled.
5515 5707 // Concievably a hook on the 'cancel'-transition or in the callback handlers could clean that up before we get here. IOK 2019-09-26
@@ -5534,9 +5726,9 @@
5534 5726 clean_post_cache($orderid);
5535 5727 $order = wc_get_order($orderid); // Reload order object
5536 5728 }
5537 5729 } else {
5538 - // No need to do anyting here. IOK 2020-01-26
5730 + // No need to do anyting here. IOK 2020-01-26
5539 5731 }
5540 5732
5541 5733 $payment = 'notchecked';
5542 5734 if ($do_poll) {
@@ -5552,9 +5744,8 @@
5552 5744 exit();
5553 5745 }
5554 5746
5555 5747 // We are done, but in failure. Don't poll.
5556 - $content = "";
5557 5748 $failure_redirect = apply_filters('woo_vipps_order_failed_redirect', '', $orderid);
5558 5749
5559 5750 // Status is failed; still send to return url (as of now /order-recieved), the text there will depend on the status.
5560 5751 // For failed it shows a "Retry payment" button that takes the customer to /pay-for-order where it will be retried. LP 2026-03-17
@@ -5562,8 +5753,9 @@
5562 5753 $failure_redirect = $failure_redirect ?: $gw->get_return_url($order);
5563 5754 wp_redirect($failure_redirect);
5564 5755 exit();
5565 5756 }
5757 +
5566 5758 if ($status == 'cancelled' || $payment == 'cancelled') {
5567 5759 $this->maybe_restore_cart($orderid,'failed');
5568 5760 if ($failure_redirect){
5569 5761 wp_redirect($failure_redirect);
@@ -5568,27 +5760,45 @@
5568 5760 if ($failure_redirect){
5569 5761 wp_redirect($failure_redirect);
5570 5762 exit();
5571 5763 }
5764 + } else {
5765 + // If not, enqueue the status checker IOK 2026-09-21
5766 + wp_enqueue_script('check-vipps',plugins_url('js/check-order-status.js',__FILE__),array('jquery','vipps-gw'),filemtime(dirname(__FILE__) . "/js/check-order-status.js"), 'true');
5767 + }
5768 +
5769 + // Communicate this to the shortcode IOK 2026-09-21
5770 + add_filter('woo_vipps_wait_for_payment_status', function () use($orderid, $status, $payment) {
5771 + return ['orderid'=>$orderid, 'status'=>$status, 'payment'=>$payment];
5772 + });
5773 +
5774 + }
5775 +
5776 + public function vipps_wait_for_payment() {
5777 +
5778 + // This will have been computed in template_redirect, but the status will be either still pending or failed. IOK 2026-09-21
5779 + $data = apply_filters('woo_vipps_wait_for_payment_status', []);
5780 +
5781 + $orderid = $data['orderid'] ?? 0;
5782 + $status = $data['status'] ?? "";
5783 + $payment = $data['payment'] ?? "";
5784 +
5785 + $order = wc_get_order($orderid);
5786 + if (!$order) wp_die(__('Unknown order', 'woo-vipps'));
5787 +
5788 + do_action('woo_vipps_wait_for_payment_page',$order);
5789 + $gw = $this->gateway();
5790 +
5791 + $content = "";
5792 + if ($status == 'cancelled' || $payment == 'cancelled') {
5572 5793 $content .= "<div id=failure><p>". __('Order cancelled','woo-vipps') . '</p>';
5573 5794 $content .= "<p><a href='" . home_url() . "' class='btn button'>" . __('Continue shopping','woo-vipps') . '</a></p>';
5574 5795 $content .= "</div>";
5575 - $this->fakepage(__('Order cancelled','woo-vipps'), $content);
5576 -
5577 - return;
5796 + return $this->special_page_html('', $content);
5578 5797 }
5579 5798
5580 5799 // Still pending and order is supposed to exist, so wait for Vipps. This happens all the time, so logging is removed. IOK 2018-09-27
5581 -
5582 5800 // Otherwise, go to a page waiting/polling for the callback. IOK 2018-05-16
5583 - wp_enqueue_script('check-vipps',plugins_url('js/check-order-status.js',__FILE__),array('jquery','vipps-gw'),filemtime(dirname(__FILE__) . "/js/check-order-status.js"), 'true');
5584 -
5585 - // Check that order exists and belongs to our session. Can use WC()->session->get() I guess - set the orderid or a hash value in the session
5586 - // and check that the order matches (and is 'pending') (and exists)
5587 - $vippsstamp = $order->get_meta('_vipps_init_timestamp');
5588 - $vippsstatus = $order->get_meta('_vipps_status');
5589 - $message = __($order->get_meta('_vipps_confirm_message'),'woo-vipps');
5590 -
5591 5801 $signal = $this->callbackSignal($order);
5592 5802 $content = "";
5593 5803 $content .= "<div id='waiting'><p>" . sprintf(__('Waiting for confirmation of purchase from %1$s','woo-vipps'), $this->get_payment_method_name());
5594 5804
@@ -5596,15 +5806,16 @@
5596 5806 $signalurl = $this->callbackSignalURL($signal);
5597 5807
5598 5808 $content .= "</p></div>";
5599 5809
5600 - // We impersonate the woocommerce-checkout form here mainly to work with the Pixel Your Site plugin IOK 2022-11-24
5601 - $classlist = apply_filters("woo_vipps_express_checkout_form_classes", "woocommerce-checkout");
5602 - $content .= "<form id='vippsdata' class='" . esc_attr($classlist) . "'>";
5810 + $failure_redirect = apply_filters('woo_vipps_order_failed_redirect', '', $orderid);
5811 +
5812 + // Carry the order status to the checking script IOK 2026-09-21
5813 + $content .= "<form id='vippsdata'>";
5603 5814 $content .= "<input type='hidden' id='fkey' name='fkey' value='".htmlspecialchars($signalurl)."'>";
5604 5815 $content .= "<input type='hidden' name='key' value='".htmlspecialchars($order->get_order_key())."'>";
5605 5816 $content .= "<input type='hidden' name='action' value='check_order_status'>";
5606 - $content .= wp_nonce_field('vippsstatus','sec',1,false);
5817 + $content .= wp_nonce_field('vippsstatus','sec',1,false);
5607 5818 $content .= "</form>";
5608 5819
5609 5820
5610 5821 $content .= "<div id='error' style='display:none'><p>".__('Error during order confirmation','woo-vipps'). '</p>';
@@ -5621,93 +5832,21 @@
5621 5832 $content .= "<a id='continueToOrderFailed' style='display:none' href='" . $failure_redirect . "'></a>";
5622 5833 $content .= "<a id='continueToOrderFailedFallback' style='display:none' href='" . $gw->get_return_url($order) . "'></a>";
5623 5834 $content .= "</div>";
5624 5835
5836 + return $this->special_page_html('', $content);
5837 + }
5625 5838
5626 - $this->fakepage(__('Waiting for your order confirmation','woo-vipps'), $content);
5839 + // Returns formatted html for the vipps special page. LP 2026-08-27
5840 + public function special_page_html($header, $content) {
5841 + $header_html = $header ? "<h2 class='vipps-special-page-title page-title'>$header</h2>" : '';
5842 + $html = <<<EOF
5843 + $header_html
5844 + <div class="vipps-special-page-content">$content</div>
5845 + EOF;
5846 + return apply_filters('woo_vipps_special_page_html', $html, $header, $content);
5627 5847 }
5628 5848
5629 -
5630 -
5631 - public function fakepage($title,$content) {
5632 - global $wp, $wp_query;
5633 - // We don't want this here.
5634 - remove_filter ('the_content', 'wpautop');
5635 -
5636 - $specialid = $this->gateway()->get_option('vippsspecialpageid');
5637 - $wp_post = null;
5638 - if ($specialid) {
5639 - $wp_post = get_post($specialid);
5640 - if ($wp_post) {
5641 - $wp_post->post_title = $title;
5642 - $wp_post->post_content = $content;
5643 - // Normalize a bit
5644 - $wp_post->filter = 'raw'; // important
5645 - $wp_post->post_status = 'publish';
5646 - $wp_post->comment_status= 'closed';
5647 - $wp_post->ping_status= 'closed';
5648 - } else {
5649 - $this->log(sprintf(__("Could not use special page with id %s - it seems not to exist.", 'woo-vipps'), $specialid), 'error');
5650 - }
5651 - }
5652 - if (!$wp_post || is_wp_error($wp_post)) {
5653 - $post = new stdClass();
5654 - $post->ID = -99;
5655 - $post->post_author = 1;
5656 - $post->post_date = current_time( 'mysql' );
5657 - $post->post_date_gmt = current_time( 'mysql', 1 );
5658 - $post->post_title = $title;
5659 - $post->post_content = $content;
5660 - $post->post_status = 'publish';
5661 - $post->comment_status = 'closed';
5662 - $post->ping_status = 'closed';
5663 - $post->post_name = 'vippsconfirm-fake-page-name';
5664 - $post->post_type = 'page';
5665 - $post->filter = 'raw'; // important
5666 - $wp_post = new WP_Post($post);
5667 - wp_cache_add( -99, $wp_post, 'posts' );
5668 - }
5669 -
5670 - // Update the main query
5671 - $wp_query->post = $wp_post;
5672 - $wp_query->posts = array( $wp_post );
5673 - $wp_query->queried_object = $wp_post;
5674 - $wp_query->queried_object_id = $wp_post->ID;
5675 - $wp_query->found_posts = 1;
5676 - $wp_query->post_count = 1;
5677 - $wp_query->max_num_pages = 1;
5678 - $wp_query->is_page = true;
5679 - $wp_query->is_singular = true;
5680 - $wp_query->is_single = false;
5681 - $wp_query->is_attachment = false;
5682 - $wp_query->is_archive = false;
5683 - $wp_query->is_category = false;
5684 - $wp_query->is_tag = false;
5685 - $wp_query->is_tax = false;
5686 - $wp_query->is_author = false;
5687 - $wp_query->is_date = false;
5688 - $wp_query->is_year = false;
5689 - $wp_query->is_month = false;
5690 - $wp_query->is_day = false;
5691 - $wp_query->is_time = false;
5692 - $wp_query->is_search = false;
5693 - $wp_query->is_feed = false;
5694 - $wp_query->is_comment_feed = false;
5695 - $wp_query->is_trackback = false;
5696 - $wp_query->is_home = false;
5697 - $wp_query->is_embed = false;
5698 - $wp_query->is_404 = false;
5699 - $wp_query->is_paged = false;
5700 - $wp_query->is_admin = false;
5701 - $wp_query->is_preview = false;
5702 - $wp_query->is_robots = false;
5703 - $wp_query->is_posts_page = false;
5704 - $wp_query->is_post_type_archive = false;
5705 - // Update globals
5706 - $GLOBALS['wp_query'] = $wp_query;
5707 - $wp->register_globals();
5708 - return $wp_post;
5709 - }
5710 5849
5711 5850 // Support the interactivity API with data about our cart IOK 2026-02-23
5712 5851 public function woo_vipps_store_api_cart_data() {
5713 5852 // Reverting the condition with the directive data-wp-bind--hidden does not work, so we need the flipped bool here (hide instead of show). LP 2026-02-10