PluginProbe
Pay with Vipps and MobilePay for WooCommerce / 6.3.1
Pay with Vipps and MobilePay for WooCommerce v6.3.1
6.3.1 6.2.6 6.3.0 6.2.5 6.2.4 6.2.3 6.2.2 6.2.1 6.2.0 6.1.10 6.1.9 6.1.8 6.1.7 6.1.6 6.1.5 6.1.4 6.1.3 6.1.2 6.1.1 6.1.0 6.0.5 6.0.4 6.0.3 6.0.2 6.0.1 All 190 releases
← All changes | payment/WC_Gateway_Vipps.class.php +15 -28 6.2.0 → 6.3.1 View file →
@@ -227,9 +227,9 @@
227 227 return $enabled;
228 228 }
229 229 $is_vipps_express = (bool) $order->get_meta( '_vipps_express_checkout' );
230 230 $has_billing_email = (bool) $order->get_billing_email();
231 - if ( $is_vipps_express && ! $has_billing_email ) {
231 + if ( $is_vipps_express) {
232 232 return false;
233 233 }
234 234 return $enabled;
235 235 }, 10, 3);
@@ -1623,17 +1623,8 @@
1623 1623 'description' => sprintf(__('If set, this image will be uploaded to %1$s and used to profile your store in the %1$s app for links to the order confirmation etc', 'woo-vipps'), Vipps::CompanyName()),
1624 1624 'default' => 0,
1625 1625 ),
1626 1626
1627 -
1628 - 'use_flock' => array (
1629 - 'title' => __('Use flock() to lock orders for Express Checkout', 'woo-vipps'),
1630 - 'label' => __('Use flock() to lock orders for Express Checkout', 'woo-vipps'),
1631 - 'type' => 'checkbox',
1632 - 'description' => __('Use the flock() system call to ensure orders are only finalized once. You can use this for normal setups, but probably not on Windows with IIS, and possibly not on distributed filesystems like NFS. If you don\t know what it is, probably do not use it. If you get duplicated shipping lines on some express orders, you may try using this', 'woo-vipps'),
1633 - 'default' => 'no',
1634 - ),
1635 -
1636 1627 'delete_settings_on_deactivation' => array (
1637 1628 'title' => __('Delete plugin settings on deactivation', 'woo-vipps'),
1638 1629 'label' => __('Delete plugin settings on deactivation', 'woo-vipps'),
1639 1630 'type' => 'checkbox',
@@ -2356,15 +2347,15 @@
2356 2347 // Default should never happen, but just to ensure we are in our enumeration
2357 2348 return "initiated";
2358 2349 }
2359 2350
2360 - // This does not normally call Vipps, so if you need to refresh status, please use callback_check_order_status first. IOK 2019-01-23
2351 + // This does not normally call Vipps, so if you need to refresh status, please use poll_and_check_order_status first. IOK 2019-01-23
2361 2352 public function check_payment_status($order) {
2362 2353 if (!$order) return 'cancelled';
2363 2354 $status = $this->interpret_vipps_order_status($order->get_meta('_vipps_status'));
2364 2355 // This can happen if the vipps status is set from the back end for instance. IOK 2020-08-14
2365 2356 if ($order->get_status() == 'pending' && $status != 'initiated') {
2366 - $this->callback_check_order_status($order);
2357 + $this->poll_and_check_order_status($order);
2367 2358 $order = wc_get_order($order->get_id()); // refresh to get the new status IOK 2021-01-20
2368 2359 $status = $this->interpret_vipps_order_status($order->get_meta('_vipps_status'));
2369 2360 }
2370 2361 return $status;
@@ -2369,9 +2360,9 @@
2369 2360 }
2370 2361 return $status;
2371 2362 }
2372 2363
2373 - // Called by callback_check_order_status and handle_callback to handle the situation where
2364 + // Called by poll_and_check_order_status and handle_callback to handle the situation where
2374 2365 // the payment method has been set to something else *after* Vipps has gotten the order.
2375 2366 // This happens very rarely for people who use Vipps as an external payment method in Klarna, so
2376 2367 // we only do it for orders that match this. IOK 2023-02-03
2377 2368 public function reset_erroneous_payment_method($order) {
@@ -2398,9 +2389,9 @@
2398 2389 }
2399 2390
2400 2391 // Check status of order at Vipps, in case the callback has been delayed or failed.
2401 2392 // Should only be called if in status 'pending'; it will modify the order when status changes.
2402 - public function callback_check_order_status($order, $allow_retry = true) {
2393 + public function poll_and_check_order_status($order, $allow_retry = true) {
2403 2394 global $Vipps;
2404 2395 $orderid = $order->get_id();
2405 2396
2406 2397 clean_post_cache($order->get_id());
@@ -2433,15 +2424,8 @@
2433 2424 }
2434 2425 // Something changed, so we are now going to sideeffect the order. IOK 2025-10-15
2435 2426 $this->log(sprintf(__("%1\$s poll: Handling order: ", 'woo-vipps'), Vipps::CompanyName()) . " " . $orderid, 'debug');
2436 2427
2437 - // If we are in the process of getting a callback from vipps, don't update anything. Currently, Woo/WP has no locking mechanism,
2438 - // and it isn't feasible to implement one portably. So this reduces somewhat the likelihood of races when this method is called
2439 - // and callbacks happen at the same time.
2440 - if (!$Vipps->lockOrder($order)) {
2441 - return $oldstatus;
2442 - }
2443 -
2444 2428 // Failsafe for rare bug when using Klarna Checkout with Vipps as an external payment method
2445 2429 // IOK 2024-01-09 ensure this is called only when order is complete/authorized
2446 2430 if ($ready) {
2447 2431 $this->reset_erroneous_payment_method($order);
@@ -2473,9 +2457,8 @@
2473 2457
2474 2458 } catch (Exception $e) {
2475 2459 $this->log(sprintf(__("Error getting payment details from %1\$s for order_id:",'woo-vipps'), $this->get_payment_method_name()) . $orderid . "\n" . $e->getMessage(), 'error');
2476 2460 clean_post_cache($order->get_id());
2477 - $Vipps->unlockOrder($order);
2478 2461 return $oldstatus;
2479 2462 }
2480 2463 $order->save();
2481 2464
@@ -2508,9 +2491,8 @@
2508 2491 $this->log(sprintf(__("No address information for order %2\$d, but there still might be an active %1\$s session for it, so do not cancel it.", 'woo-vipps'), Vipps::CheckoutName(), $order->get_id()));
2509 2492 }
2510 2493 }
2511 2494 clean_post_cache($order->get_id());
2512 - $Vipps->unlockOrder($order);
2513 2495 return $oldstatus;
2514 2496 }
2515 2497 }
2516 2498
@@ -2546,9 +2528,8 @@
2546 2528
2547 2529 $order->save();
2548 2530 clean_post_cache($order->get_id());
2549 2531 $newstatus = $order->get_status();
2550 - $Vipps->unlockOrder($order);
2551 2532 return $newstatus;
2552 2533 }
2553 2534
2554 2535 // IOK 2020-01-20 Previously was just a debugging tool, then was used to update postmeta values. Now is used as the main source of info
@@ -3190,9 +3171,14 @@
3190 3171 $is_base64 = $shipping_table ? ( $shipping_table['_is_base64'] ?? false) : false;
3191 3172
3192 3173 if (is_array($shipping_table) && isset($shipping_table[$key])) {
3193 3174 $decoded = $is_base64 ? @base64_decode($shipping_table[$key]) : $shipping_table[$key];
3194 - $shipping_rate = $decoded ? @unserialize($decoded) : null;
3175 +
3176 + // Ensure no shop manager has injected an evil object (that they would have had to add as a plugin) here. IOK 2026-09-18
3177 + $allowed_classes = apply_filters('woo_vipps_express_checkout_allowed_shipping_classes', [WC_Shipping_Rate::class, \stdClass::class]);
3178 + $shipping_rate = $decoded ? @unserialize($decoded, ['allowed_classes' => $allowed_classes]) : null;
3179 + $shipping_rate = is_a($shipping_rate,'WC_Shipping_Rate') ? $shipping_rate : null;
3180 +
3195 3181 if (!$shipping_rate) {
3196 3182 $this->log(sprintf(__("%1\$s: Could not deserialize the chosen shipping method %2\$s for order %3\$d", 'woo-vipps'), Vipps::ExpressCheckoutName(), $method, $order->get_id()), 'error');
3197 3183 $this->log(sprintf(__("Serialized data was %1\$s", 'woo-vipps'), $decoded), 'error');
3198 3184 } else {
@@ -3376,9 +3362,9 @@
3376 3362 $shipping_rate = apply_filters('woo_vipps_express_checkout_shipping_rate',$shipping_rate,$costExTax,$tax,$method,$product);
3377 3363 return $shipping_rate;
3378 3364 }
3379 3365
3380 - // Used by both callback_check_order_status and handle_callback - sets the neccessary order metadata after a successful (or not vipps transaction). IOK 2025-08-13
3366 + // Used by both poll_and_check_order_status and handle_callback - sets the neccessary order metadata after a successful (or not vipps transaction). IOK 2025-08-13
3381 3367 public function order_set_transaction_metadata($order, $transaction) {
3382 3368 // Set Vipps metadata as early as possible
3383 3369 $vippsstamp = strtotime($transaction['timeStamp']);
3384 3370 $vippsamount = $transaction['amount'] ?? '';
@@ -3758,9 +3744,9 @@
3758 3744 }
3759 3745 do_action('woo_vipps_payment_complete_at_shutdown', $order, $this);
3760 3746 } catch (Exception $e) {
3761 3747 // This is/should be non-critical so just log it.
3762 - $this->log(sprintf(__("Could not do all payment-complete actions on %1\$s order %2\$d: %3\$s ", 'woo-vipps'), Vipps::CompanyName(), $orderid, $e->etMessage()), "error");
3748 + $this->log(sprintf(__("Could not do all payment-complete actions on %1\$s order %2\$d: %3\$s ", 'woo-vipps'), Vipps::CompanyName(), $orderid, $e->getMessage()), "error");
3763 3749 }
3764 3750 }
3765 3751
3766 3752 // This is run on payment complete. Per default will it only add a link to the order confirmation page, but
@@ -3867,9 +3853,9 @@
3867 3853
3868 3854 $contents = WC()->cart->get_cart_contents();
3869 3855 $contents = apply_filters('woo_vipps_create_express_checkout_cart_contents',$contents);
3870 3856 try {
3871 - $cart_hash = md5(json_encode(wc_clean($contents)) . WC()->cart->total);
3857 + $cart_hash = WC()->cart->get_cart_hash();
3872 3858 $order = new WC_Order();
3873 3859 $order->set_status('pending');
3874 3860 $order->set_payment_method($this);
3875 3861 if ($ischeckout) {
@@ -3880,8 +3866,9 @@
3880 3866 }
3881 3867 // We use 'checkout' as the created_via key as per requests, but allow merchants to use their own. IOK 2022-09-15
3882 3868 $created_via = apply_filters('woo_vipps_express_checkout_created_via', 'checkout', $order, $ischeckout);
3883 3869 $order->set_created_via($created_via);
3870 + $order->set_cart_hash($cart_hash);
3884 3871
3885 3872 $dummy = sprintf(__('Vipps Express Checkout', 'woo-vipps')); // this is so gettext will find this string.
3886 3873 $dummy = sprintf(__('Vipps Checkout', 'woo-vipps')); // this is so gettext will find this string.
3887 3874