PluginProbe
Pay with Vipps and MobilePay for WooCommerce / 6.3.1
Pay with Vipps and MobilePay for WooCommerce v6.3.1
6.3.1 6.2.6 6.3.0 6.2.5 6.2.4 6.2.3 6.2.2 6.2.1 6.2.0 6.1.10 6.1.9 6.1.8 6.1.7 6.1.6 6.1.5 6.1.4 6.1.3 6.1.2 6.1.1 6.1.0 6.0.5 6.0.4 6.0.3 6.0.2 6.0.1 All 190 releases
← All changes | payment/VippsCheckout.class.php +17 -8 6.0.2 → 6.3.1 View file →
@@ -183,16 +183,19 @@
183 183
184 184 # Called in admin-post and will finalize a Vipps Checkout order + send the customer to the payment page.
185 185 public function choose_other_gw () {
186 186 $orderid = intval($_GET['o']);
187 +
188 +
187 189 $gw = trim(sanitize_title($_GET['gw']));
188 190 if ($gw == 'any') $gw = "";
189 191 $nonce = $_GET['cb'];
190 - $ok = wp_verify_nonce($nonce, 'vipps_gw');
192 + $ok = wp_verify_nonce($nonce, 'vipps_gw_' . $orderid);
191 193 if (!$ok) {
192 194 $this->abandonVippsCheckoutOrder(false);
193 195 $this->log(sprintf(__("Orderid %1\$s: Wrong nonce when trying to switch payment methods.", 'woo-vipps'), $orderid), 'error');
194 196 wp_redirect(home_url());
197 + exit();
195 198 }
196 199 $order = wc_get_order($orderid);
197 200 if (!$order || $order->get_status() != 'pending') {
198 201 $this->abandonVippsCheckoutOrder(false);
@@ -197,8 +200,9 @@
197 200 if (!$order || $order->get_status() != 'pending') {
198 201 $this->abandonVippsCheckoutOrder(false);
199 202 $this->log(sprintf(__("Orderid %1\$s is not pending when choosing another payment method from Vipps Checkout", 'woo-vipps'), $orderid), 'error');
200 203 wp_redirect(home_url());
204 + exit();
201 205 }
202 206
203 207 try {
204 208 // Load session from cookies - it will not get loaded on admin-post.
@@ -207,8 +211,19 @@
207 211 if (WC()->session) {
208 212 if (! WC()->session->has_session()) {
209 213 WC()->session->set_customer_session_cookie( true );
210 214 }
215 +
216 + // Check to see if we actually are paying for an order in session IOK 2026-09-24
217 + $current_pending = WC()->session->get('vipps_checkout_current_pending');
218 +
219 + if ($orderid != $current_pending) {
220 + $this->abandonVippsCheckoutOrder(false);
221 + $this->log(sprintf(__("Orderid %1\$s: Wrong current pending order when trying to switch payment methods.", 'woo-vipps'), $orderid), 'error');
222 + wp_redirect(home_url());
223 + exit();
224 + }
225 +
211 226 // There is actually a bug here for KCO which will redirect to the normal checkout page with an error message.
212 227 // Try to stop that.. IOK 2024-05-15
213 228 if ($gw != 'kco') {
214 229 WC()->session->set('chosen_payment_method', $gw);
@@ -1294,14 +1309,8 @@
1294 1309 WC()->session->set('vipps_address_hash', false);
1295 1310 }
1296 1311
1297 1312 if (is_a($order, 'WC_Order') && $order->get_status() == 'pending') {
1298 - // We want to kill orders that have failed, or that the user has abandoned. To do this,
1299 - // we must ensure that no race or other mechanism kills the order while or after being paid.
1300 - // if order is in the process of being finalized, don't kill it
1301 - if (Vipps::instance()->isLocked($order)) {
1302 - return false;
1303 - }
1304 1313 // Get it again to ensure we have all the info, and check status again
1305 1314 clean_post_cache($order->get_id());
1306 1315 $order = wc_get_order($order->get_id());
1307 1316 if ($order->get_status() != 'pending') return false;
@@ -1588,9 +1597,9 @@
1588 1597 } else {
1589 1598 // specialcase some known methods so they get brands, and put the label into the description
1590 1599 if ($shipping_method && is_a($shipping_method, 'WC_Shipping_Method') && get_class($shipping_method) == 'WC_Shipping_Method_Bring_Pro') {
1591 1600 $m2['brand'] = "POSTEN";
1592 - $m2['description'] = $rate->get_label();
1601 + $m2['description'] = html_entity_decode($rate->get_label());
1593 1602 }
1594 1603 $m2['brand'] = apply_filters('woo_vipps_shipping_method_brand', $m2['brand'],$shipping_method, $rate);
1595 1604 }
1596 1605