| @@ -3192,9 +3192,10 @@ | ||
| 3192 | 3192 | if (is_array($shipping_table) && isset($shipping_table[$key])) { |
| 3193 | 3193 | $decoded = $is_base64 ? @base64_decode($shipping_table[$key]) : $shipping_table[$key]; |
| 3194 | 3194 | |
| 3195 | 3195 | // Ensure no shop manager has injected an evil object (that they would have had to add as a plugin) here. IOK 2026-09-18 |
| 3196 | - $shipping_rate = $decoded ? @unserialize($decoded, ['allowed_classes' => [WC_Shipping_Rate::class]]) : null; | |
| 3196 | + $allowed_classes = apply_filters('woo_vipps_express_checkout_allowed_shipping_classes', [WC_Shipping_Rate::class, \stdClass::class]); | |
| 3197 | + $shipping_rate = $decoded ? @unserialize($decoded, ['allowed_classes' => $allowed_classes]) : null; | |
| 3197 | 3198 | $shipping_rate = is_a($shipping_rate,'WC_Shipping_Rate') ? $shipping_rate : null; |
| 3198 | 3199 | |
| 3199 | 3200 | if (!$shipping_rate) { |
| 3200 | 3201 | $this->log(sprintf(__("%1\$s: Could not deserialize the chosen shipping method %2\$s for order %3\$d", 'woo-vipps'), Vipps::ExpressCheckoutName(), $method, $order->get_id()), 'error'); |
| @@ -3762,9 +3763,9 @@ | ||
| 3762 | 3763 | } |
| 3763 | 3764 | do_action('woo_vipps_payment_complete_at_shutdown', $order, $this); |
| 3764 | 3765 | } catch (Exception $e) { |
| 3765 | 3766 | // This is/should be non-critical so just log it. |
| 3766 | - $this->log(sprintf(__("Could not do all payment-complete actions on %1\$s order %2\$d: %3\$s ", 'woo-vipps'), Vipps::CompanyName(), $orderid, $e->etMessage()), "error"); | |
| 3767 | + $this->log(sprintf(__("Could not do all payment-complete actions on %1\$s order %2\$d: %3\$s ", 'woo-vipps'), Vipps::CompanyName(), $orderid, $e->getMessage()), "error"); | |
| 3767 | 3768 | } |
| 3768 | 3769 | } |
| 3769 | 3770 | |
| 3770 | 3771 | // This is run on payment complete. Per default will it only add a link to the order confirmation page, but |