PluginProbe ʕ •ᴥ•ʔ
WooCommerce / 11.0.1
WooCommerce v11.0.1
11.1.0-rc.2 11.1.0-rc.1 11.1.0-beta.2 11.1.0-beta.1 11.0.1 11.0.0 11.0.0-rc.3 11.0.0-rc.2 11.0.0-rc.1 11.0.0-beta.2 11.0.0-beta.1 10.9.4 10.9.3 10.9.2 10.9.1 10.9.0 10.9.0-rc.1 10.9.0-beta.2 10.9.0-beta.1 10.8.1 10.8.0 10.8.0-rc.1 10.8.0-beta.2 10.8.0-beta.1 7.8.0-beta.1 7.8.0-beta.2 7.8.0-rc.1 7.8.0-rc.2 7.8.1 7.8.2 7.8.3 7.8.4 7.9.0 7.9.0-beta.1 7.9.0-beta.2 7.9.0-rc.2 7.9.0-rc.3 7.9.1 7.9.2 8.0.0 8.0.0-beta.1 8.0.0-beta.2 8.0.0-rc.1 8.0.0-rc.2 8.0.1 8.0.2 8.0.3 8.0.4 8.0.5 8.1.0 8.1.0-beta.1 8.1.0-rc.1 8.1.0-rc.2 8.1.1 8.1.2 8.1.3 8.1.4 8.2.0 8.2.0-beta.1 8.2.0-rc.1 8.2.0-rc.2 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.3.0 8.3.0-beta.1 8.3.0-rc.1 8.3.0-rc.2 8.3.1 8.3.2 8.3.3 8.3.4 8.4.0 8.4.0-beta.1 8.4.0-rc.1 8.4.1 8.4.2 8.4.3 8.5.0 8.5.0-beta.1 8.5.0-rc.1 8.5.1 8.5.2 8.5.3 8.5.4 8.5.5 8.6.0 8.6.0-beta.1 8.6.0-rc.1 8.6.1 8.6.2 8.6.3 8.6.4 8.7.0 8.7.0-beta.1 8.7.0-beta.2 8.7.0-rc.1 8.7.1 8.7.2 8.7.3 8.8.0 8.8.0-beta.1 8.8.0-rc.1 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.8.6 8.8.7 8.9.0 8.9.0-beta.1 8.9.0-rc.1 8.9.1 8.9.2 8.9.3 8.9.4 8.9.5 9.0.0 9.0.0-beta.1 9.0.0-beta.2 9.0.0-rc.1 9.0.1 9.0.2 9.0.3 9.0.4 9.1.0 9.1.0-beta.1 9.1.0-rc.1 9.1.1 9.1.2 9.1.3 9.1.4 9.1.5 9.1.6 9.2.0 9.2.0-beta.1 9.2.0-rc.1 9.2.1 9.2.2 9.2.3 9.2.4 9.2.5 9.3.0 9.3.0-beta.1 9.3.0-rc.1 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.3.6 9.4.0 9.4.0-beta.1 9.4.0-beta.2 9.4.0-rc.1 9.4.0-rc.2 9.4.0-rc.3 9.4.0-rc.4 9.4.1 9.4.2 9.4.3 9.4.4 9.4.5 9.5.0 9.5.0-beta.1 9.5.0-beta.2 9.5.0-rc.1 9.5.1 9.5.2 9.5.3 9.5.4 9.6.0 9.6.0-beta.1 9.6.0-beta.2 9.6.0-rc.1 9.6.1 9.6.2 9.6.3 9.6.4 9.7.0 9.7.0-beta.1 9.7.0-rc.1 9.7.1 9.7.2 9.7.3 9.8.0 9.8.0-beta.1 9.8.0-rc.1 9.8.1 9.8.2 9.8.3 9.8.4 9.8.5 9.8.6 9.8.7 9.9.0 9.9.0-beta.1 9.9.0-rc.1 9.9.1 9.9.2 9.9.3 9.9.4 9.9.5 9.9.6 9.9.7 3.7.3 7.1.2 3.8.0 7.2.0 3.8.0-beta.1 7.2.0-beta.1 3.8.0-rc.1 7.2.0-beta.2 3.8.0-rc.2 7.2.0-rc.1 3.8.1 7.2.0-rc.2 3.8.2 7.2.1 3.8.3 7.2.2 3.9.0 7.2.3 3.9.0-beta.1 7.2.4 3.9.0-beta.2 7.3.0 3.9.0-rc.1 7.3.0-beta.1 3.9.0-rc.2 7.3.0-beta.2 3.9.0-rc.3 7.3.0-rc.1 3.9.0-rc.4 7.3.0-rc.2 3.9.1 7.3.1 3.9.2 7.4.0 3.9.3 7.4.0-beta.1 3.9.4 7.4.0-beta.2 3.9.5 7.4.0-rc.1 4.0.0 7.4.0-rc.2 4.0.0-beta.1 7.4.1 4.0.0-rc.1 7.4.2 4.0.0-rc.2 7.5.0 4.0.1 7.5.0-beta.1 4.0.2 7.5.0-beta.2 4.0.3 7.5.0-rc.1 4.0.4 7.5.1 4.1.0 7.5.2 4.1.0-beta.1 7.6.0 4.1.0-beta.2 7.6.0-beta.1 4.1.0-rc.1 7.6.0-beta.2 4.1.0-rc.2 7.6.0-rc.1 4.1.1 7.6.0-rc.2 4.1.2 7.6.0-rc.3 4.1.3 7.6.1 4.1.4 7.6.2 4.2.0 7.7.0 4.2.0-RC.1 7.7.0-beta.1 4.2.0-RC.2 7.7.0-beta.2 4.2.0-beta.1 7.7.0-rc.1 4.2.1 7.7.1 4.2.2 7.7.2 4.2.3 7.7.3 4.2.4 7.8.0 4.2.5 4.3.0 4.3.0-beta.1 4.3.0-rc.1 4.3.0-rc.2 4.3.0-rc.3 4.3.1 4.3.2 4.3.3 4.3.4 4.3.5 4.3.6 4.4.0 4.4.0-beta.1 4.4.0-rc.1 4.4.1 4.4.2 4.4.3 4.4.4 4.5.0 4.5.0-beta.1 4.5.0-rc.1 4.5.0-rc.3 4.5.1 4.5.2 4.5.3 4.5.4 4.5.5 4.6.0 4.6.0-beta.1 4.6.0-rc.1 4.6.1 4.6.2 4.6.3 4.6.4 4.6.5 4.7.0 4.7.0-beta.1 4.7.0-beta.2 4.7.0-rc.1 4.7.1 4.7.1-beta.1 4.7.2 4.7.3 4.7.4 4.8.0 4.8.0-beta.1 4.8.0-rc.1 4.8.0-rc.2 4.8.1 4.8.2 4.8.3 4.9.0 4.9.0-beta.1 4.9.0-rc.1 4.9.0-rc.2 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 5.0.0 5.0.0-beta.1 5.0.0-beta.2 5.0.0-rc.1 5.0.0-rc.2 5.0.0-rc.3 5.0.1 5.0.2 5.0.3 5.1.0 5.1.0-beta.1 5.1.0-rc.1 trunk 5.1.1 10.0.0 5.1.2 10.0.0-rc.1 5.1.3 10.0.0-rc.2 5.2.0 10.0.1 5.2.0-beta.1 10.0.2 5.2.0-rc.1 10.0.3 5.2.0-rc.2 10.0.4 5.2.1 10.0.5 5.2.2 10.0.6 5.2.3 10.1.0 5.2.4 10.1.0-rc.1 5.2.5 10.1.0-rc.2 5.3.0 10.1.0-rc.3 5.3.0-beta.1 10.1.0-rc.4 5.3.0-rc.1 10.1.1 5.3.0-rc.2 10.1.2 5.3.1 10.1.3 5.3.2 10.1.4 5.3.3 10.2.0 5.4.0 10.2.0-beta.1 5.4.0-beta.1 10.2.0-beta.2 5.4.0-rc.1 10.2.0-rc.1 5.4.1 10.2.1 5.4.2 10.2.2 5.4.3 10.2.3 5.4.4 10.2.4 5.4.5 10.3.0 5.5.0 10.3.0-beta.1 5.5.0-beta.1 10.3.0-beta.2 5.5.0-rc.1 10.3.0-rc.1 5.5.0-rc.2 10.3.0-rc.2 5.5.1 10.3.1 5.5.2 10.3.2 5.5.3 10.3.3 5.5.4 10.3.4 5.5.5 10.3.5 5.6.0 10.3.6 5.6.0-beta.1 10.3.7 5.6.0-rc.1 10.3.8 5.6.0-rc.2 10.4.0 5.6.1 10.4.0-beta.1 5.6.2 10.4.0-beta.2 5.6.3 10.4.0-rc.1 5.7.0 10.4.1 5.7.0-beta.1 10.4.2 5.7.0-rc.1 10.4.3 5.7.1 10.4.4 5.7.2 10.5.0 5.7.3 10.5.0-beta.1 5.8.0 10.5.0-beta.2 5.8.0-beta.1 10.5.0-rc.1 5.8.0-beta.2 10.5.0-rc.2 5.8.0-rc.1 10.5.0-rc.3 5.8.1 10.5.1 5.8.2 10.5.2 5.9.0 10.5.3 5.9.0-beta.1 10.6.0 5.9.0-rc.1 10.6.0-beta.1 5.9.0-rc.2 10.6.0-beta.2 5.9.1 10.6.0-rc.1 5.9.2 10.6.1 6.0.0 10.6.2 6.0.0-beta.1 10.7.0 6.0.0-rc.1 10.7.0-beta.1 6.0.1 10.7.0-beta.2 6.0.2 10.7.0-rc.1 6.1.0 3.0.0 6.1.0-beta.1 3.0.1 6.1.0-rc.1 3.0.2 6.1.0-rc.2 3.0.3 6.1.1 3.0.4 6.1.2 3.0.5 6.1.3 3.0.6 6.2.0 3.0.7 6.2.0-beta.1 3.0.8 6.2.0-rc.1 3.0.9 6.2.0-rc.2 3.1.0 6.2.1 3.1.1 6.2.2 3.1.2 6.2.3 3.2.0 6.3.0 3.2.1 6.3.0-beta.1 3.2.2 6.3.0-rc.1 3.2.3 6.3.0-rc.2 3.2.4 6.3.1 3.2.5 6.3.2 3.2.6 6.4.0 3.3.0 6.4.0-beta.1 3.3.1 6.4.0-rc.1 3.3.2 6.4.1 3.3.2-rc.1 6.4.2 3.3.3 6.5.0 3.3.4 6.5.0-beta.1 3.3.5 6.5.0-rc.1 3.3.6 6.5.0-rc.2 3.4.0 6.5.1 3.4.0-beta.1 6.5.2 3.4.0-rc.2 6.6.0 3.4.1 6.6.0-beta.1 3.4.2 6.6.0-rc.1 3.4.3 6.6.0-rc.2 3.4.4 6.6.1 3.4.5 6.6.2 3.4.6 6.7.0 3.4.7 6.7.0-beta.1 3.4.8 6.7.0-beta.2 3.5.0 6.7.0-rc.1 3.5.0-beta.1 6.7.1 3.5.0-rc.1 6.8.0 3.5.0-rc.2 6.8.0-beta.1 3.5.1 6.8.0-beta.2 3.5.10 6.8.0-rc.1 3.5.2 6.8.1 3.5.3 6.8.2 3.5.4 6.8.3 3.5.5 6.9.0 3.5.6 6.9.0-beta.1 3.5.7 6.9.0-beta.2 3.5.8 6.9.0-rc.1 3.5.9 6.9.1 3.6.0 6.9.2 3.6.0-beta.1 6.9.3 3.6.0-rc.1 6.9.4 3.6.0-rc.2 6.9.5 3.6.0-rc.3 7.0.0 3.6.1 7.0.0-beta.1 3.6.2 7.0.0-beta.2 3.6.3 7.0.0-beta.3 3.6.4 7.0.0-rc.1 3.6.5 7.0.0-rc.2 3.6.6 7.0.1 3.6.7 7.0.2 3.7.0 7.1.0 3.7.0-beta.1 7.1.0-beta.1 3.7.0-rc.1 7.1.0-beta.2 3.7.0-rc.2 7.1.0-rc.1 3.7.1 7.1.0-rc.2 3.7.2 7.1.1
woocommerce / includes / class-wc-form-handler.php
woocommerce / includes Last commit date
abstracts 1 month ago admin 3 weeks ago blocks 1 month ago cli 2 months ago customizer 6 months ago data-stores 1 month ago emails 1 month ago export 1 month ago gateways 2 months ago import 1 month ago integrations 1 month ago interfaces 6 months ago legacy 1 month ago libraries 2 months ago log-handlers 1 year ago payment-tokens 6 years ago product-usage 1 year ago queue 6 months ago react-admin 1 month ago rest-api 3 weeks ago shipping 5 months ago shortcodes 1 month ago theme-support 2 years ago tracks 2 months ago traits 5 years ago walkers 5 years ago wccom-site 2 months ago widgets 1 month ago class-wc-ajax.php 1 month ago class-wc-auth.php 2 years ago class-wc-autoloader.php 10 months ago class-wc-background-emailer.php 3 months ago class-wc-background-updater.php 6 years ago class-wc-brands-brand-settings-manager.php 1 year ago class-wc-brands-coupons.php 1 year ago class-wc-brands.php 1 month ago class-wc-breadcrumb.php 6 months ago class-wc-cache-helper.php 2 months ago class-wc-cart-fees.php 2 years ago class-wc-cart-session.php 5 months ago class-wc-cart-totals.php 1 year ago class-wc-cart.php 1 month ago class-wc-checkout.php 1 month ago class-wc-cli.php 1 year ago class-wc-comments.php 6 months ago class-wc-countries.php 3 months ago class-wc-coupon.php 3 months ago class-wc-customer-download-log.php 6 years ago class-wc-customer-download.php 2 years ago class-wc-customer.php 1 month ago class-wc-data-exception.php 8 years ago class-wc-data-store.php 3 years ago class-wc-datetime.php 4 years ago class-wc-deprecated-action-hooks.php 2 years ago class-wc-deprecated-filter-hooks.php 5 months ago class-wc-discounts.php 1 year ago class-wc-download-handler.php 1 month ago class-wc-emails.php 1 month ago class-wc-embed.php 3 weeks ago class-wc-form-handler.php 1 month ago class-wc-frontend-scripts.php 4 weeks ago class-wc-geo-ip.php 10 months ago class-wc-geolite-integration.php 6 years ago class-wc-geolocation.php 1 month ago class-wc-https.php 3 years ago class-wc-install.php 1 month ago class-wc-integrations.php 6 years ago class-wc-log-levels.php 2 years ago class-wc-logger.php 6 months ago class-wc-meta-data.php 2 months ago class-wc-order-factory.php 3 months ago class-wc-order-item-coupon.php 4 years ago class-wc-order-item-fee.php 1 month ago class-wc-order-item-meta.php 4 years ago class-wc-order-item-product.php 2 months ago class-wc-order-item-shipping.php 7 months ago class-wc-order-item-tax.php 2 months ago class-wc-order-item.php 1 month ago class-wc-order-query.php 2 months ago class-wc-order-refund.php 1 year ago class-wc-order.php 1 month ago class-wc-payment-gateways.php 1 month ago class-wc-payment-tokens.php 3 years ago class-wc-post-data.php 1 month ago class-wc-post-types.php 1 month ago class-wc-privacy-background-process.php 1 year ago class-wc-privacy-erasers.php 1 year ago class-wc-privacy-exporters.php 5 years ago class-wc-privacy.php 1 year ago class-wc-product-attribute.php 6 months ago class-wc-product-download.php 1 month ago class-wc-product-external.php 1 year ago class-wc-product-factory.php 5 months ago class-wc-product-grouped.php 1 month ago class-wc-product-query.php 6 months ago class-wc-product-simple.php 1 year ago class-wc-product-variable.php 2 months ago class-wc-product-variation.php 2 months ago class-wc-query.php 1 month ago class-wc-rate-limiter.php 4 years ago class-wc-regenerate-images-request.php 3 years ago class-wc-regenerate-images.php 1 month ago class-wc-register-wp-admin-settings.php 5 years ago class-wc-rest-authentication.php 2 years ago class-wc-rest-exception.php 5 years ago class-wc-session-handler.php 3 weeks ago class-wc-shipping-rate.php 1 year ago class-wc-shipping-zone.php 5 years ago class-wc-shipping-zones.php 9 months ago class-wc-shipping.php 1 month ago class-wc-shortcodes.php 1 year ago class-wc-structured-data.php 1 month ago class-wc-tax.php 1 month ago class-wc-template-loader.php 9 months ago class-wc-tracker.php 1 month ago class-wc-validation.php 1 month ago class-wc-webhook.php 2 months ago class-woocommerce.php 3 weeks ago wc-account-functions.php 2 months ago wc-attribute-functions.php 1 month ago wc-brands-functions.php 1 year ago wc-cart-functions.php 2 months ago wc-conditional-functions.php 1 year ago wc-core-functions.php 3 months ago wc-coupon-functions.php 7 months ago wc-deprecated-functions.php 2 months ago wc-formatting-functions.php 1 month ago wc-interactivity-api-functions.php 3 months ago wc-notice-functions.php 7 months ago wc-order-functions.php 3 months ago wc-order-item-functions.php 3 years ago wc-order-step-logger-functions.php 3 weeks ago wc-page-functions.php 1 month ago wc-product-functions.php 3 weeks ago wc-rest-functions.php 9 months ago wc-stock-functions.php 1 month ago wc-template-functions.php 2 months ago wc-template-hooks.php 1 year ago wc-term-functions.php 1 month ago wc-update-functions.php 1 month ago wc-user-functions.php 1 month ago wc-webhook-functions.php 2 months ago wc-widget-functions.php 6 years ago
class-wc-form-handler.php
1308 lines
1 <?php
2 /**
3 * Handle frontend forms.
4 *
5 * @package WooCommerce\Classes\
6 */
7
8 use Automattic\WooCommerce\Enums\OrderStatus;
9 use Automattic\WooCommerce\Enums\PaymentGatewayFeature;
10 use Automattic\WooCommerce\Enums\ProductType;
11
12 defined( 'ABSPATH' ) || exit;
13
14 /**
15 * WC_Form_Handler class.
16 */
17 class WC_Form_Handler {
18
19 /**
20 * User meta key tracking the last time the set-password link was resent. Used to rate-limit resends.
21 */
22 const SET_PASSWORD_RESEND_META = '_wc_set_password_resend_at';
23
24 /**
25 * Minimum seconds between back-to-back set-password resend requests.
26 */
27 const SET_PASSWORD_RESEND_RATE_LIMIT_SECONDS = 60;
28
29 /**
30 * Hook in methods.
31 */
32 public static function init() {
33 add_action( 'template_redirect', array( __CLASS__, 'redirect_reset_password_link' ) );
34 add_action( 'template_redirect', array( __CLASS__, 'resend_set_password' ) );
35 add_action( 'template_redirect', array( __CLASS__, 'save_address' ) );
36 add_action( 'template_redirect', array( __CLASS__, 'save_account_details' ) );
37 add_action( 'wp_loaded', array( __CLASS__, 'checkout_action' ), 20 );
38 add_action( 'wp_loaded', array( __CLASS__, 'process_login' ), 20 );
39 add_action( 'wp_loaded', array( __CLASS__, 'process_registration' ), 20 );
40 add_action( 'wp_loaded', array( __CLASS__, 'process_lost_password' ), 20 );
41 add_action( 'wp_loaded', array( __CLASS__, 'process_reset_password' ), 20 );
42 add_action( 'wp_loaded', array( __CLASS__, 'cancel_order' ), 20 );
43 add_action( 'wp_loaded', array( __CLASS__, 'update_cart_action' ), 20 );
44 add_action( 'wp_loaded', array( __CLASS__, 'add_to_cart_action' ), 20 );
45
46 // May need $wp global to access query vars.
47 add_action( 'wp', array( __CLASS__, 'pay_action' ), 20 );
48 add_action( 'wp', array( __CLASS__, 'add_payment_method_action' ), 20 );
49 add_action( 'wp', array( __CLASS__, 'delete_payment_method_action' ), 20 );
50 add_action( 'wp', array( __CLASS__, 'set_default_payment_method_action' ), 20 );
51 }
52
53 /**
54 * Remove key and user ID (or user login, as a fallback) from query string, set cookie, and redirect to account page to show the form.
55 */
56 public static function redirect_reset_password_link() {
57 if ( is_account_page() && isset( $_GET['key'] ) && ( isset( $_GET['id'] ) || isset( $_GET['login'] ) ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
58
59 // If available, get $user_id from query string parameter for fallback purposes.
60 if ( isset( $_GET['login'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
61 $user = get_user_by( 'login', sanitize_user( wp_unslash( $_GET['login'] ) ) ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
62 $user_id = $user ? $user->ID : 0;
63 } else {
64 $user_id = absint( $_GET['id'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
65 }
66
67 // If the reset token is not for the current user, ignore the reset request (don't redirect).
68 $logged_in_user_id = get_current_user_id();
69 if ( $logged_in_user_id && $logged_in_user_id !== $user_id ) {
70 wc_add_notice( __( 'This password reset key is for a different user account. Please log out and try again.', 'woocommerce' ), 'error' );
71 return;
72 }
73
74 $action = isset( $_GET['action'] ) ? sanitize_text_field( wp_unslash( $_GET['action'] ) ) : '';
75 $value = sprintf( '%d:%s', $user_id, wp_unslash( $_GET['key'] ) ); // phpcs:ignore
76 WC_Shortcode_My_Account::set_reset_password_cookie( $value );
77 wp_safe_redirect(
78 add_query_arg(
79 array(
80 'show-reset-form' => 'true',
81 'action' => $action,
82 ),
83 wc_lostpassword_url()
84 )
85 );
86 exit;
87 }
88 }
89
90 /**
91 * Resend the change-password link to a logged-in customer who still has a temporary password.
92 *
93 * Triggered by the temporary-password notice on the My Account pages. Generates a fresh
94 * password-reset key for the current user and dispatches the reset-password email, mirroring
95 * the lost-password flow but for the already-authenticated user.
96 *
97 * @since 11.0.0
98 */
99 public static function resend_set_password(): void {
100 // phpcs:ignore WordPress.Security.NonceVerification.Recommended
101 if ( ! isset( $_GET['wc-resend-set-password'] ) || ! is_user_logged_in() ) {
102 return;
103 }
104
105 // phpcs:ignore WordPress.Security.NonceVerification.Recommended
106 $nonce_value = isset( $_GET['_wpnonce'] ) ? sanitize_text_field( wp_unslash( $_GET['_wpnonce'] ) ) : '';
107
108 if ( ! wp_verify_nonce( $nonce_value, 'wc-resend-set-password' ) ) {
109 return;
110 }
111
112 $user = wp_get_current_user();
113 $redirect = wc_get_page_permalink( 'myaccount' );
114
115 // Rate-limit resends so the button can't be used to spam the customer's inbox.
116 $last_sent_at = (int) get_user_meta( $user->ID, self::SET_PASSWORD_RESEND_META, true );
117 if ( $last_sent_at > 0 && ( time() - $last_sent_at ) < self::SET_PASSWORD_RESEND_RATE_LIMIT_SECONDS ) {
118 wc_add_notice( __( 'Please wait a moment before requesting another link to change your password.', 'woocommerce' ), 'notice' );
119 wp_safe_redirect( $redirect );
120 exit;
121 }
122
123 $key = get_password_reset_key( $user );
124
125 if ( is_wp_error( $key ) ) {
126 wc_add_notice( __( 'Sorry, we were unable to resend the link. Please try again.', 'woocommerce' ), 'error' );
127 } else {
128 // Persist the rate-limit timestamp before dispatching so two near-simultaneous requests can't both pass.
129 // This timestamp also suppresses the temporary-password notice during the cooldown — see
130 // WC_Shortcode_My_Account::my_account_add_notices() — so the confirmation below isn't contradicted.
131 update_user_meta( $user->ID, self::SET_PASSWORD_RESEND_META, (string) time() );
132 // Load email classes so the reset-password notification has a listener.
133 WC()->mailer();
134 // phpcs:ignore WooCommerce.Commenting.CommentHooks -- Re-fires woocommerce_reset_password_notification, documented in WC_Shortcode_My_Account::retrieve_password().
135 do_action( 'woocommerce_reset_password_notification', $user->user_login, $key );
136 wc_add_notice( __( 'We have emailed you a new link to change your password.', 'woocommerce' ) );
137 }
138
139 wp_safe_redirect( $redirect );
140 exit;
141 }
142
143 /**
144 * Save and and update a billing or shipping address if the
145 * form was submitted through the user account page.
146 */
147 public static function save_address() {
148 global $wp;
149
150 $nonce_value = wc_get_var( $_REQUEST['woocommerce-edit-address-nonce'], wc_get_var( $_REQUEST['_wpnonce'], '' ) ); // @codingStandardsIgnoreLine.
151
152 if ( ! wp_verify_nonce( $nonce_value, 'woocommerce-edit_address' ) ) {
153 return;
154 }
155
156 if ( empty( $_POST['action'] ) || 'edit_address' !== $_POST['action'] ) {
157 return;
158 }
159
160 wc_nocache_headers();
161
162 $user_id = get_current_user_id();
163
164 if ( $user_id <= 0 ) {
165 return;
166 }
167
168 $customer = new WC_Customer( $user_id );
169
170 if ( ! $customer ) {
171 return;
172 }
173
174 $address_type = isset( $wp->query_vars['edit-address'] ) ? wc_edit_address_i18n( sanitize_title( $wp->query_vars['edit-address'] ), true ) : 'billing';
175
176 if ( ! isset( $_POST[ $address_type . '_country' ] ) ) {
177 return;
178 }
179
180 $address = WC()->countries->get_address_fields( wc_clean( wp_unslash( $_POST[ $address_type . '_country' ] ) ), $address_type . '_' );
181
182 foreach ( $address as $key => $field ) {
183 if ( ! isset( $field['type'] ) ) {
184 $field['type'] = 'text';
185 }
186
187 // Get Value.
188 if ( 'checkbox' === $field['type'] ) {
189 $value = (int) isset( $_POST[ $key ] );
190 } else {
191 $value = isset( $_POST[ $key ] ) ? wc_clean( wp_unslash( $_POST[ $key ] ) ) : '';
192 }
193
194 // Hook to allow modification of value.
195 $value = apply_filters( 'woocommerce_process_myaccount_field_' . $key, $value );
196
197 // Validation: Required fields.
198 if ( ! empty( $field['required'] ) && empty( $value ) ) {
199 /* translators: %s: Field name. */
200 wc_add_notice( sprintf( __( '%s is a required field.', 'woocommerce' ), $field['label'] ), 'error', array( 'id' => $key ) );
201 }
202
203 if ( ! empty( $value ) ) {
204 // Validation and formatting rules.
205 if ( ! empty( $field['validate'] ) && is_array( $field['validate'] ) ) {
206 foreach ( $field['validate'] as $rule ) {
207 switch ( $rule ) {
208 case 'postcode':
209 $country = wc_clean( wp_unslash( $_POST[ $address_type . '_country' ] ) );
210 $value = wc_format_postcode( $value, $country );
211
212 if ( '' !== $value && ! WC_Validation::is_postcode( $value, $country ) ) {
213 switch ( $country ) {
214 case 'IE':
215 $postcode_validation_notice = __( 'Please enter a valid Eircode.', 'woocommerce' );
216 break;
217 default:
218 $postcode_validation_notice = __( 'Please enter a valid postcode / ZIP.', 'woocommerce' );
219 }
220 wc_add_notice( $postcode_validation_notice, 'error' );
221 }
222 break;
223 case 'phone':
224 $country = wc_clean( wp_unslash( $_POST[ $address_type . '_country' ] ) );
225 $country = is_string( $country ) ? $country : '';
226 if ( '' !== $value && ! WC_Validation::is_phone( $value, $country ) ) {
227 /* translators: %s: Phone number. */
228 wc_add_notice( sprintf( __( '%s is not a valid phone number.', 'woocommerce' ), '<strong>' . $field['label'] . '</strong>' ), 'error' );
229 }
230 break;
231 case 'email':
232 $value = strtolower( $value );
233
234 if ( ! is_email( $value ) ) {
235 /* translators: %s: Email address. */
236 wc_add_notice( sprintf( __( '%s is not a valid email address.', 'woocommerce' ), '<strong>' . $field['label'] . '</strong>' ), 'error' );
237 }
238 break;
239 }
240 }
241 }
242 }
243
244 try {
245 // Set prop in customer object.
246 if ( is_callable( array( $customer, "set_$key" ) ) ) {
247 $customer->{"set_$key"}( $value );
248 } else {
249 $customer->update_meta_data( $key, $value );
250 }
251 } catch ( WC_Data_Exception $e ) {
252 // Set notices. Ignore invalid billing email, since is already validated.
253 if ( 'customer_invalid_billing_email' !== $e->getErrorCode() ) {
254 wc_add_notice( $e->getMessage(), 'error' );
255 }
256 }
257 }
258
259 /**
260 * Hook: woocommerce_after_save_address_validation.
261 *
262 * Allow developers to add custom validation logic and throw an error to prevent save.
263 *
264 * @since 3.6.0
265 * @param int $user_id User ID being saved.
266 * @param string $address_type Type of address; 'billing' or 'shipping'.
267 * @param array $address The address fields.
268 * @param WC_Customer $customer The customer object being saved.
269 */
270 do_action( 'woocommerce_after_save_address_validation', $user_id, $address_type, $address, $customer );
271
272 if ( 0 < wc_notice_count( 'error' ) ) {
273 return;
274 }
275
276 $customer->save();
277
278 /**
279 * Hook: woocommerce_customer_save_address.
280 *
281 * Fires after a customer address has been saved.
282 *
283 * @since 3.6.0
284 * @param int $user_id User ID being saved.
285 * @param string $address_type Type of address; 'billing' or 'shipping'.
286 * @param array $address The address fields. Since 9.8.0.
287 * @param WC_Customer $customer The customer object being saved. Since 9.8.0.
288 */
289 do_action( 'woocommerce_customer_save_address', $user_id, $address_type, $address, $customer );
290
291 if ( 0 < wc_notice_count( 'error' ) ) {
292 return;
293 }
294
295 wc_add_notice( __( 'Address changed successfully.', 'woocommerce' ) );
296 wp_safe_redirect( wc_get_endpoint_url( 'edit-address', '', wc_get_page_permalink( 'myaccount' ) ) );
297 exit;
298 }
299
300 /**
301 * Save the password/account details and redirect back to the my account page.
302 */
303 public static function save_account_details() {
304 $nonce_value = wc_get_var( $_REQUEST['save-account-details-nonce'], wc_get_var( $_REQUEST['_wpnonce'], '' ) ); // @codingStandardsIgnoreLine.
305
306 if ( ! wp_verify_nonce( $nonce_value, 'save_account_details' ) ) {
307 return;
308 }
309
310 if ( empty( $_POST['action'] ) || 'save_account_details' !== $_POST['action'] ) {
311 return;
312 }
313
314 wc_nocache_headers();
315
316 $user_id = get_current_user_id();
317
318 if ( $user_id <= 0 ) {
319 return;
320 }
321
322 $account_first_name = ! empty( $_POST['account_first_name'] ) ? wc_clean( wp_unslash( $_POST['account_first_name'] ) ) : '';
323 $account_last_name = ! empty( $_POST['account_last_name'] ) ? wc_clean( wp_unslash( $_POST['account_last_name'] ) ) : '';
324 $account_display_name = ! empty( $_POST['account_display_name'] ) ? wc_clean( wp_unslash( $_POST['account_display_name'] ) ) : '';
325 $account_email = ! empty( $_POST['account_email'] ) ? wc_clean( wp_unslash( $_POST['account_email'] ) ) : '';
326 $pass_cur = ! empty( $_POST['password_current'] ) ? $_POST['password_current'] : ''; // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized, WordPress.Security.ValidatedSanitizedInput.MissingUnslash
327 $pass1 = ! empty( $_POST['password_1'] ) ? $_POST['password_1'] : ''; // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized, WordPress.Security.ValidatedSanitizedInput.MissingUnslash
328 $pass2 = ! empty( $_POST['password_2'] ) ? $_POST['password_2'] : ''; // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized, WordPress.Security.ValidatedSanitizedInput.MissingUnslash
329 $save_pass = true;
330
331 // Current user data.
332 $current_user = get_user_by( 'id', $user_id );
333 $current_first_name = $current_user->first_name;
334 $current_last_name = $current_user->last_name;
335 $current_email = $current_user->user_email;
336
337 // New user data.
338 $user = new stdClass();
339 $user->ID = $user_id;
340 $user->first_name = $account_first_name;
341 $user->last_name = $account_last_name;
342 $user->display_name = $account_display_name;
343
344 // Prevent display name to be changed to email.
345 if ( is_email( $account_display_name ) ) {
346 wc_add_notice( __( 'Display name cannot be changed to email address due to privacy concern.', 'woocommerce' ), 'error' );
347 }
348
349 // Handle required fields.
350 $required_fields = apply_filters(
351 'woocommerce_save_account_details_required_fields',
352 array(
353 'account_first_name' => __( 'First name', 'woocommerce' ),
354 'account_last_name' => __( 'Last name', 'woocommerce' ),
355 'account_display_name' => __( 'Display name', 'woocommerce' ),
356 'account_email' => __( 'Email address', 'woocommerce' ),
357 )
358 );
359
360 foreach ( $required_fields as $field_key => $field_name ) {
361 if ( empty( $_POST[ $field_key ] ) ) {
362 /* translators: %s: Field name. */
363 wc_add_notice( sprintf( __( '%s is a required field.', 'woocommerce' ), '<strong>' . esc_html( $field_name ) . '</strong>' ), 'error', array( 'id' => $field_key ) );
364 }
365 }
366
367 if ( $account_email ) {
368 $account_email = sanitize_email( $account_email );
369 if ( ! is_email( $account_email ) ) {
370 wc_add_notice( __( 'Please provide a valid email address.', 'woocommerce' ), 'error' );
371 } elseif ( email_exists( $account_email ) && $account_email !== $current_user->user_email ) {
372 wc_add_notice( __( 'This email address is already registered.', 'woocommerce' ), 'error' );
373 }
374 $user->user_email = $account_email;
375 }
376
377 if ( ! empty( $pass_cur ) && empty( $pass1 ) && empty( $pass2 ) ) {
378 wc_add_notice( __( 'Please fill out all password fields.', 'woocommerce' ), 'error' );
379 $save_pass = false;
380 } elseif ( ! empty( $pass1 ) && empty( $pass_cur ) ) {
381 wc_add_notice( __( 'Please enter your current password.', 'woocommerce' ), 'error' );
382 $save_pass = false;
383 } elseif ( ! empty( $pass1 ) && empty( $pass2 ) ) {
384 wc_add_notice( __( 'Please re-enter your password.', 'woocommerce' ), 'error' );
385 $save_pass = false;
386 } elseif ( ( ! empty( $pass1 ) || ! empty( $pass2 ) ) && $pass1 !== $pass2 ) {
387 wc_add_notice( __( 'New passwords do not match.', 'woocommerce' ), 'error' );
388 $save_pass = false;
389 } elseif ( ! empty( $pass1 ) && ! wp_check_password( $pass_cur, $current_user->user_pass, $current_user->ID ) ) {
390 wc_add_notice( __( 'Your current password is incorrect.', 'woocommerce' ), 'error' );
391 $save_pass = false;
392 }
393
394 if ( $pass1 && $save_pass ) {
395 $user->user_pass = $pass1;
396 }
397
398 // Allow plugins to return their own errors.
399 $errors = new WP_Error();
400 do_action_ref_array( 'woocommerce_save_account_details_errors', array( &$errors, &$user ) );
401
402 if ( $errors->get_error_messages() ) {
403 foreach ( $errors->get_error_messages() as $error ) {
404 wc_add_notice( $error, 'error' );
405 }
406 }
407
408 if ( wc_notice_count( 'error' ) === 0 ) {
409 wp_update_user( $user );
410
411 // Update customer object to keep data in sync.
412 try {
413 $customer = new WC_Customer( $user->ID );
414
415 // Keep billing data in sync if data changed.
416 if ( isset( $user->user_email ) && is_email( $user->user_email ) && $current_email !== $user->user_email ) {
417 $customer->set_billing_email( $user->user_email );
418 }
419
420 if ( $current_first_name !== $user->first_name ) {
421 $customer->set_billing_first_name( $user->first_name );
422 }
423
424 if ( $current_last_name !== $user->last_name ) {
425 $customer->set_billing_last_name( $user->last_name );
426 }
427
428 $customer->save();
429 } catch ( WC_Data_Exception $e ) {
430 // These error messages are already translated.
431 wc_add_notice( $e->getMessage(), 'error' );
432 } catch ( \Exception $e ) {
433 wc_add_notice(
434 sprintf(
435 /* translators: %s: Error message. */
436 __( 'An error occurred while saving account details: %s', 'woocommerce' ),
437 esc_html( $e->getMessage() )
438 ),
439 'error'
440 );
441 }
442
443 /**
444 * Hook: woocommerce_save_account_details.
445 *
446 * @since 3.6.0
447 * @param int $user_id User ID being saved.
448 */
449 do_action( 'woocommerce_save_account_details', $user->ID );
450
451 // Notices are checked here so that if something created a notice during the save hooks above, the redirect will not happen.
452 if ( 0 === wc_notice_count( 'error' ) ) {
453 wc_add_notice( __( 'Account details changed successfully.', 'woocommerce' ) );
454 wp_safe_redirect( wc_get_endpoint_url( 'edit-account', '', wc_get_page_permalink( 'myaccount' ) ) );
455 exit;
456 }
457 }
458 }
459
460 /**
461 * Process the checkout form.
462 */
463 public static function checkout_action() {
464 if ( isset( $_POST['woocommerce_checkout_place_order'] ) || isset( $_POST['woocommerce_checkout_update_totals'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing
465 wc_nocache_headers();
466
467 if ( WC()->cart->is_empty() ) {
468 wp_safe_redirect( wc_get_cart_url() );
469 exit;
470 }
471
472 wc_maybe_define_constant( 'WOOCOMMERCE_CHECKOUT', true );
473
474 WC()->checkout()->process_checkout();
475 }
476 }
477
478 /**
479 * Process the pay form.
480 *
481 * @throws Exception On payment error.
482 */
483 public static function pay_action() {
484 global $wp;
485
486 if ( isset( $_POST['woocommerce_pay'], $_GET['key'] ) ) {
487 wc_nocache_headers();
488
489 $nonce_value = wc_get_var( $_REQUEST['woocommerce-pay-nonce'], wc_get_var( $_REQUEST['_wpnonce'], '' ) ); // @codingStandardsIgnoreLine.
490
491 if ( ! wp_verify_nonce( $nonce_value, 'woocommerce-pay' ) ) {
492 return;
493 }
494
495 ob_start();
496
497 // Pay for existing order.
498 $order_key = wp_unslash( $_GET['key'] ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
499 $order_id = absint( $wp->query_vars['order-pay'] );
500 $order = wc_get_order( $order_id );
501
502 if ( $order_id === $order->get_id() && hash_equals( $order->get_order_key(), $order_key ) && $order->needs_payment() ) {
503
504 do_action( 'woocommerce_before_pay_action', $order );
505
506 WC()->customer->set_props(
507 array(
508 'billing_country' => $order->get_billing_country() ? $order->get_billing_country() : null,
509 'billing_state' => $order->get_billing_state() ? $order->get_billing_state() : null,
510 'billing_postcode' => $order->get_billing_postcode() ? $order->get_billing_postcode() : null,
511 'billing_city' => $order->get_billing_city() ? $order->get_billing_city() : null,
512 )
513 );
514 WC()->customer->save();
515
516 if ( ! empty( $_POST['terms-field'] ) && empty( $_POST['terms'] ) ) {
517 wc_add_notice( __( 'Please read and accept the terms and conditions to proceed with your order.', 'woocommerce' ), 'error' );
518 return;
519 }
520
521 // Update payment method.
522 if ( $order->needs_payment() ) {
523 try {
524 $payment_method_id = isset( $_POST['payment_method'] ) ? wc_clean( wp_unslash( $_POST['payment_method'] ) ) : false;
525
526 if ( ! $payment_method_id ) {
527 throw new Exception( __( 'Invalid payment method.', 'woocommerce' ) );
528 }
529
530 $available_gateways = WC()->payment_gateways->get_available_payment_gateways();
531 $payment_method = isset( $available_gateways[ $payment_method_id ] ) ? $available_gateways[ $payment_method_id ] : false;
532
533 if ( ! $payment_method ) {
534 throw new Exception( __( 'Invalid payment method.', 'woocommerce' ) );
535 }
536
537 $order->set_payment_method( $payment_method );
538 $order->save();
539
540 $payment_method->validate_fields();
541
542 if ( 0 === wc_notice_count( 'error' ) ) {
543
544 $result = $payment_method->process_payment( $order_id );
545
546 // Redirect to success/confirmation/payment page.
547 if ( isset( $result['result'] ) && 'success' === $result['result'] ) {
548 $result['order_id'] = $order_id;
549
550 $result = apply_filters( 'woocommerce_payment_successful_result', $result, $order_id );
551
552 wp_redirect( $result['redirect'] ); //phpcs:ignore WordPress.Security.SafeRedirect.wp_redirect_wp_redirect
553 exit;
554 }
555 }
556 } catch ( Exception $e ) {
557 wc_add_notice( $e->getMessage(), 'error' );
558 }
559 } else {
560 // No payment was required for order.
561 $order->payment_complete();
562 wp_safe_redirect( $order->get_checkout_order_received_url() );
563 exit;
564 }
565
566 do_action( 'woocommerce_after_pay_action', $order );
567
568 }
569 }
570 }
571
572 /**
573 * Process the add payment method form.
574 */
575 public static function add_payment_method_action() {
576 if ( isset( $_POST['woocommerce_add_payment_method'], $_POST['payment_method'] ) ) {
577 wc_nocache_headers();
578
579 $nonce_value = wc_get_var( $_REQUEST['woocommerce-add-payment-method-nonce'], wc_get_var( $_REQUEST['_wpnonce'], '' ) ); // @codingStandardsIgnoreLine.
580
581 if ( ! wp_verify_nonce( $nonce_value, 'woocommerce-add-payment-method' ) ) {
582 return;
583 }
584
585 if ( ! apply_filters( 'woocommerce_add_payment_method_form_is_valid', true ) ) {
586 return;
587 }
588
589 // Test rate limit.
590 $current_user_id = get_current_user_id();
591 $rate_limit_id = 'add_payment_method_' . $current_user_id;
592 $delay = (int) apply_filters( 'woocommerce_payment_gateway_add_payment_method_delay', 20 );
593
594 if ( WC_Rate_Limiter::retried_too_soon( $rate_limit_id ) ) {
595 wc_add_notice(
596 sprintf(
597 /* translators: %d number of seconds */
598 _n(
599 'You cannot add a new payment method so soon after the previous one. Please wait for %d second.',
600 'You cannot add a new payment method so soon after the previous one. Please wait for %d seconds.',
601 $delay,
602 'woocommerce'
603 ),
604 $delay
605 ),
606 'error'
607 );
608 return;
609 }
610
611 WC_Rate_Limiter::set_rate_limit( $rate_limit_id, $delay );
612
613 ob_start();
614
615 $payment_method_id = wc_clean( wp_unslash( $_POST['payment_method'] ) );
616 $available_gateways = WC()->payment_gateways->get_available_payment_gateways();
617
618 if ( isset( $available_gateways[ $payment_method_id ] ) ) {
619 $gateway = $available_gateways[ $payment_method_id ];
620
621 if ( ! $gateway->supports( PaymentGatewayFeature::ADD_PAYMENT_METHOD ) && ! $gateway->supports( PaymentGatewayFeature::TOKENIZATION ) ) {
622 wc_add_notice( __( 'Invalid payment gateway.', 'woocommerce' ), 'error' );
623 return;
624 }
625
626 $gateway->validate_fields();
627
628 if ( wc_notice_count( 'error' ) > 0 ) {
629 return;
630 }
631
632 $result = $gateway->add_payment_method();
633
634 if ( 'success' === $result['result'] ) {
635 wc_add_notice( __( 'Payment method successfully added.', 'woocommerce' ) );
636 }
637
638 if ( 'failure' === $result['result'] ) {
639 wc_add_notice( __( 'Unable to add payment method to your account.', 'woocommerce' ), 'error' );
640 }
641
642 if ( ! empty( $result['redirect'] ) ) {
643 wp_redirect( $result['redirect'] ); //phpcs:ignore WordPress.Security.SafeRedirect.wp_redirect_wp_redirect
644 exit();
645 }
646 }
647 }
648 }
649
650 /**
651 * Process the delete payment method form.
652 */
653 public static function delete_payment_method_action() {
654 global $wp;
655
656 if ( isset( $wp->query_vars['delete-payment-method'] ) ) {
657 wc_nocache_headers();
658
659 $token_id = absint( $wp->query_vars['delete-payment-method'] );
660 $token = WC_Payment_Tokens::get( $token_id );
661
662 if ( is_null( $token ) || get_current_user_id() !== $token->get_user_id() || ! isset( $_REQUEST['_wpnonce'] ) || false === wp_verify_nonce( wp_unslash( $_REQUEST['_wpnonce'] ), 'delete-payment-method-' . $token_id ) ) { // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
663 wc_add_notice( __( 'Invalid payment method.', 'woocommerce' ), 'error' );
664 } else {
665 WC_Payment_Tokens::delete( $token_id );
666 wc_add_notice( __( 'Payment method deleted.', 'woocommerce' ) );
667 }
668
669 wp_safe_redirect( wc_get_account_endpoint_url( 'payment-methods' ) );
670 exit();
671 }
672 }
673
674 /**
675 * Process the delete payment method form.
676 */
677 public static function set_default_payment_method_action() {
678 global $wp;
679
680 if ( isset( $wp->query_vars['set-default-payment-method'] ) ) {
681 wc_nocache_headers();
682
683 $token_id = absint( $wp->query_vars['set-default-payment-method'] );
684 $token = WC_Payment_Tokens::get( $token_id );
685
686 if ( is_null( $token ) || get_current_user_id() !== $token->get_user_id() || ! isset( $_REQUEST['_wpnonce'] ) || false === wp_verify_nonce( wp_unslash( $_REQUEST['_wpnonce'] ), 'set-default-payment-method-' . $token_id ) ) { // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
687 wc_add_notice( __( 'Invalid payment method.', 'woocommerce' ), 'error' );
688 } else {
689 WC_Payment_Tokens::set_users_default( $token->get_user_id(), intval( $token_id ) );
690 wc_add_notice( __( 'This payment method was successfully set as your default.', 'woocommerce' ) );
691 }
692
693 wp_safe_redirect( wc_get_account_endpoint_url( 'payment-methods' ) );
694 exit();
695 }
696 }
697
698 /**
699 * Remove from cart/update.
700 */
701 public static function update_cart_action() {
702 if ( ! ( isset( $_REQUEST['apply_coupon'] ) || isset( $_REQUEST['remove_coupon'] ) || isset( $_REQUEST['remove_item'] ) || isset( $_REQUEST['undo_item'] ) || isset( $_REQUEST['update_cart'] ) || isset( $_REQUEST['proceed'] ) ) ) {
703 return;
704 }
705
706 wc_maybe_define_constant( 'WOOCOMMERCE_CART', true );
707
708 wc_nocache_headers();
709
710 $nonce_value = wc_get_var( $_REQUEST['woocommerce-cart-nonce'], wc_get_var( $_REQUEST['_wpnonce'], '' ) ); // @codingStandardsIgnoreLine.
711
712 if ( ! empty( $_POST['apply_coupon'] ) && ! empty( $_POST['coupon_code'] ) ) {
713 WC()->cart->add_discount( wc_format_coupon_code( wp_unslash( $_POST['coupon_code'] ) ) ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
714
715 } elseif ( isset( $_GET['remove_coupon'] ) ) {
716 WC()->cart->remove_coupon( wc_format_coupon_code( urldecode( wp_unslash( $_GET['remove_coupon'] ) ) ) ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
717
718 } elseif ( ! empty( $_GET['remove_item'] ) && wp_verify_nonce( $nonce_value, 'woocommerce-cart' ) ) {
719 $cart_item_key = sanitize_text_field( wp_unslash( $_GET['remove_item'] ) );
720 $cart_item = WC()->cart->get_cart_item( $cart_item_key );
721
722 if ( $cart_item ) {
723 $removed = WC()->cart->remove_cart_item( $cart_item_key );
724
725 if ( $removed ) {
726 /**
727 * Fires when a cart item is removed from a user request.
728 *
729 * @param string $cart_item_key Cart item key.
730 * @param \WC_Cart $cart Cart object.
731 *
732 * @since 10.6.0
733 */
734 do_action( 'internal_woocommerce_cart_item_removed_from_user_request', $cart_item_key, WC()->cart );
735 }
736
737 $product = wc_get_product( $cart_item['product_id'] );
738
739 /* translators: %s: Item name. */
740 $item_removed_title = apply_filters( 'woocommerce_cart_item_removed_title', $product ? sprintf( _x( '&ldquo;%s&rdquo;', 'Item name in quotes', 'woocommerce' ), $product->get_name() ) : __( 'Item', 'woocommerce' ), $cart_item );
741
742 // Don't show undo link if removed item is out of stock.
743 if ( $product && $product->is_in_stock() && $product->has_enough_stock( $cart_item['quantity'] ) ) {
744 /* Translators: %s Product title. */
745 $removed_notice = sprintf( __( '%s removed.', 'woocommerce' ), $item_removed_title );
746 $removed_notice .= ' <a href="' . esc_url( wc_get_cart_undo_url( $cart_item_key ) ) . '" class="restore-item">' . __( 'Undo?', 'woocommerce' ) . '</a>';
747 } else {
748 /* Translators: %s Product title. */
749 $removed_notice = sprintf( __( '%s removed.', 'woocommerce' ), $item_removed_title );
750 }
751
752 wc_add_notice( $removed_notice, apply_filters( 'woocommerce_cart_item_removed_notice_type', 'success' ) );
753 }
754
755 if ( wp_get_referer() ) {
756 wp_safe_redirect( remove_query_arg( array( 'remove_item', 'add-to-cart', 'added-to-cart', 'order_again', '_wpnonce' ), add_query_arg( 'removed_item', '1', wp_get_referer() ) ) );
757 exit;
758 }
759 } elseif ( ! empty( $_GET['undo_item'] ) && isset( $_GET['_wpnonce'] ) && wp_verify_nonce( $nonce_value, 'woocommerce-cart' ) ) {
760
761 // Undo Cart Item.
762 $cart_item_key = sanitize_text_field( wp_unslash( $_GET['undo_item'] ) );
763
764 WC()->cart->restore_cart_item( $cart_item_key );
765
766 if ( wp_get_referer() ) {
767 wp_safe_redirect( remove_query_arg( array( 'undo_item', '_wpnonce' ), wp_get_referer() ) );
768 exit;
769 }
770 }
771
772 // Update Cart - checks apply_coupon too because they are in the same form.
773 if ( ( ! empty( $_POST['apply_coupon'] ) || ! empty( $_POST['update_cart'] ) || ! empty( $_POST['proceed'] ) ) && wp_verify_nonce( $nonce_value, 'woocommerce-cart' ) ) {
774
775 $cart_updated = false;
776 $cart_totals = isset( $_POST['cart'] ) ? wp_unslash( $_POST['cart'] ) : ''; // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
777
778 if ( ! WC()->cart->is_empty() && is_array( $cart_totals ) ) {
779 foreach ( WC()->cart->get_cart() as $cart_item_key => $values ) {
780
781 $_product = $values['data'];
782
783 // Skip product if no updated quantity was posted.
784 if ( ! isset( $cart_totals[ $cart_item_key ] ) || ! isset( $cart_totals[ $cart_item_key ]['qty'] ) ) {
785 continue;
786 }
787
788 // Sanitize.
789 $quantity = apply_filters( 'woocommerce_stock_amount_cart_item', wc_stock_amount( preg_replace( '/[^0-9\.]/', '', $cart_totals[ $cart_item_key ]['qty'] ) ), $cart_item_key );
790
791 if ( '' === $quantity || $quantity === $values['quantity'] ) {
792 continue;
793 }
794
795 // Update cart validation.
796 $passed_validation = apply_filters( 'woocommerce_update_cart_validation', true, $cart_item_key, $values, $quantity );
797
798 // is_sold_individually.
799 if ( $_product->is_sold_individually() && $quantity > 1 ) {
800 /* Translators: %s Product title. */
801 wc_add_notice( sprintf( __( 'You can only have 1 %s in your cart.', 'woocommerce' ), $_product->get_name() ), 'error' );
802 $passed_validation = false;
803 }
804
805 if ( $passed_validation ) {
806 $old_quantity = $values['quantity'];
807 WC()->cart->set_quantity( $cart_item_key, $quantity, false );
808 $cart_updated = true;
809
810 /**
811 * Fires when a cart item quantity is updated from a user request.
812 *
813 * @param string $cart_item_key Cart item key.
814 * @param int|float $quantity New quantity.
815 * @param int|float $old_quantity Old quantity.
816 * @param \WC_Cart $cart Cart object.
817 *
818 * @since 10.6.0
819 */
820 do_action( 'internal_woocommerce_cart_item_updated_from_user_request', $cart_item_key, $quantity, $old_quantity, WC()->cart );
821 }
822 }
823 }
824
825 // Trigger action - let 3rd parties update the cart if they need to and update the $cart_updated variable.
826 $cart_updated = apply_filters( 'woocommerce_update_cart_action_cart_updated', $cart_updated );
827
828 if ( $cart_updated ) {
829 WC()->cart->calculate_totals();
830 }
831
832 if ( ! empty( $_POST['proceed'] ) ) {
833 wp_safe_redirect( wc_get_checkout_url() );
834 exit;
835 } elseif ( $cart_updated ) {
836 wc_add_notice( __( 'Cart updated.', 'woocommerce' ), apply_filters( 'woocommerce_cart_updated_notice_type', 'success' ) );
837
838 if ( wp_get_referer() ) {
839 wp_safe_redirect( remove_query_arg( array( 'remove_coupon', 'add-to-cart' ), wp_get_referer() ) );
840 exit;
841 }
842 }
843 }
844 }
845
846 /**
847 * Place a previous order again.
848 *
849 * @deprecated 3.5.0 Logic moved to cart session handling.
850 */
851 public static function order_again() {
852 wc_deprecated_function( 'WC_Form_Handler::order_again', '3.5', 'This method should not be called manually.' );
853 }
854
855 /**
856 * Cancel a pending order.
857 */
858 public static function cancel_order() {
859 if (
860 isset( $_GET['cancel_order'] ) &&
861 isset( $_GET['order'] ) &&
862 isset( $_GET['order_id'] ) &&
863 ( isset( $_GET['_wpnonce'] ) && wp_verify_nonce( wp_unslash( $_GET['_wpnonce'] ), 'woocommerce-cancel_order' ) ) // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
864 ) {
865 wc_nocache_headers();
866
867 $order_key = wp_unslash( $_GET['order'] ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
868 $order_id = absint( $_GET['order_id'] );
869 $order = wc_get_order( $order_id );
870 /**
871 * Filter valid order statuses for cancel.
872 *
873 * @since 3.5.0
874 *
875 * @param array $valid_statuses Array of valid order statuses for cancel.
876 * @param WC_Order $order Order object.
877 */
878 $valid_statuses = apply_filters( 'woocommerce_valid_order_statuses_for_cancel', array( OrderStatus::PENDING, OrderStatus::FAILED ), $order );
879 $user_can_cancel = current_user_can( 'cancel_order', $order_id );
880 $order_can_cancel = $order->has_status( $valid_statuses );
881 $redirect = isset( $_GET['redirect'] ) ? wp_unslash( $_GET['redirect'] ) : ''; // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
882
883 if ( $user_can_cancel && $order_can_cancel && $order->get_id() === $order_id && hash_equals( $order->get_order_key(), $order_key ) ) {
884
885 // Cancel the order + restore stock.
886 WC()->session->set( 'order_awaiting_payment', false );
887 $order->update_status( OrderStatus::CANCELLED, __( 'Order cancelled by customer.', 'woocommerce' ) );
888
889 wc_add_notice( apply_filters( 'woocommerce_order_cancelled_notice', __( 'Your order was cancelled.', 'woocommerce' ) ), apply_filters( 'woocommerce_order_cancelled_notice_type', 'notice' ) );
890
891 do_action( 'woocommerce_cancelled_order', $order->get_id() );
892
893 } elseif ( $user_can_cancel && ! $order_can_cancel ) {
894 wc_add_notice( __( 'Your order can no longer be cancelled. Please contact us if you need assistance.', 'woocommerce' ), 'error' );
895 } else {
896 wc_add_notice( __( 'Invalid order.', 'woocommerce' ), 'error' );
897 }
898
899 if ( $redirect ) {
900 wp_safe_redirect( $redirect );
901 exit;
902 }
903 }
904 }
905
906 /**
907 * Add to cart action.
908 *
909 * Checks for a valid request, does validation (via hooks) and then redirects if valid.
910 *
911 * @param bool $url (default: false) URL to redirect to.
912 */
913 public static function add_to_cart_action( $url = false ) {
914 if ( ! isset( $_REQUEST['add-to-cart'] ) || ! is_numeric( wp_unslash( $_REQUEST['add-to-cart'] ) ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
915 return;
916 }
917
918 wc_nocache_headers();
919
920 $product_id = apply_filters( 'woocommerce_add_to_cart_product_id', absint( wp_unslash( $_REQUEST['add-to-cart'] ) ) ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
921 $was_added_to_cart = false;
922 $adding_to_cart = wc_get_product( $product_id );
923
924 if ( ! $adding_to_cart ) {
925 return;
926 }
927
928 $add_to_cart_handler = apply_filters( 'woocommerce_add_to_cart_handler', $adding_to_cart->get_type(), $adding_to_cart );
929
930 if ( ProductType::VARIABLE === $add_to_cart_handler || ProductType::VARIATION === $add_to_cart_handler ) {
931 $was_added_to_cart = self::add_to_cart_handler_variable( $product_id );
932 $product_id = ! empty( $_REQUEST['variation_id'] ) ? absint( wp_unslash( $_REQUEST['variation_id'] ) ) : $product_id; // phpcs:ignore WordPress.Security.NonceVerification.Recommended
933 } elseif ( ProductType::GROUPED === $add_to_cart_handler ) {
934 $was_added_to_cart = self::add_to_cart_handler_grouped( $product_id );
935 } elseif ( has_action( 'woocommerce_add_to_cart_handler_' . $add_to_cart_handler ) ) {
936 do_action( 'woocommerce_add_to_cart_handler_' . $add_to_cart_handler, $url ); // Custom handler.
937 } else {
938 $was_added_to_cart = self::add_to_cart_handler_simple( $product_id );
939 }
940
941 // If we added the product to the cart we can now optionally do a redirect.
942 if ( $was_added_to_cart && 0 === wc_notice_count( 'error' ) ) {
943 $quantity = empty( $_REQUEST['quantity'] ) ? 1 : wc_stock_amount( wp_unslash( $_REQUEST['quantity'] ) ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
944
945 /**
946 * Fires when an item is added to the cart from a user request.
947 *
948 * @param int $product_id Product ID.
949 * @param int|float $quantity Quantity added to the cart.
950 *
951 * @since 10.6.0
952 */
953 do_action( 'internal_woocommerce_cart_item_added_from_user_request', $product_id, $quantity );
954
955 $url = apply_filters( 'woocommerce_add_to_cart_redirect', $url, $adding_to_cart );
956
957 if ( $url ) {
958 wp_safe_redirect( $url );
959 exit;
960 } elseif ( 'yes' === get_option( 'woocommerce_cart_redirect_after_add' ) ) {
961 wp_safe_redirect( wc_get_cart_url() );
962 exit;
963 }
964 }
965 }
966
967 /**
968 * Handle adding simple products to the cart.
969 *
970 * @since 2.4.6 Split from add_to_cart_action.
971 * @param int $product_id Product ID to add to the cart.
972 * @return bool success or not
973 */
974 private static function add_to_cart_handler_simple( $product_id ) {
975 if ( ! WC()->cart ) {
976 wc_doing_it_wrong( __FUNCTION__, 'Cart is not initialized.', '10.5.0' );
977 return false;
978 }
979
980 $quantity = empty( $_REQUEST['quantity'] ) ? 1 : wc_stock_amount( wp_unslash( $_REQUEST['quantity'] ) ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
981 $passed_validation = apply_filters( 'woocommerce_add_to_cart_validation', true, $product_id, $quantity );
982
983 if ( $passed_validation && false !== WC()->cart->add_to_cart( $product_id, $quantity ) ) {
984 wc_add_to_cart_message( array( $product_id => $quantity ), true );
985 return true;
986 }
987 return false;
988 }
989
990 /**
991 * Handle adding grouped products to the cart.
992 *
993 * @since 2.4.6 Split from add_to_cart_action.
994 * @param int $product_id Product ID to add to the cart.
995 * @return bool success or not
996 */
997 private static function add_to_cart_handler_grouped( $product_id ) {
998 $was_added_to_cart = false;
999 $added_to_cart = array();
1000 $items = isset( $_REQUEST['quantity'] ) && is_array( $_REQUEST['quantity'] ) ? wp_unslash( $_REQUEST['quantity'] ) : array(); // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1001
1002 if ( ! empty( $items ) ) {
1003 $quantity_set = false;
1004
1005 foreach ( $items as $item => $quantity ) {
1006 $quantity = wc_stock_amount( $quantity );
1007 if ( $quantity <= 0 ) {
1008 continue;
1009 }
1010 $quantity_set = true;
1011
1012 // Add to cart validation.
1013 $passed_validation = apply_filters( 'woocommerce_add_to_cart_validation', true, $item, $quantity );
1014
1015 // Suppress total recalculation until finished.
1016 remove_action( 'woocommerce_add_to_cart', array( WC()->cart, 'calculate_totals' ), 20, 0 );
1017
1018 if ( $passed_validation && false !== WC()->cart->add_to_cart( $item, $quantity ) ) {
1019 $was_added_to_cart = true;
1020 $added_to_cart[ $item ] = $quantity;
1021 }
1022
1023 add_action( 'woocommerce_add_to_cart', array( WC()->cart, 'calculate_totals' ), 20, 0 );
1024 }
1025
1026 if ( ! $was_added_to_cart && ! $quantity_set ) {
1027 wc_add_notice( __( 'Please choose the quantity of items you wish to add to your cart&hellip;', 'woocommerce' ), 'error' );
1028 } elseif ( $was_added_to_cart ) {
1029 wc_add_to_cart_message( $added_to_cart );
1030 WC()->cart->calculate_totals();
1031 return true;
1032 }
1033 } elseif ( $product_id ) {
1034 /* Link on product archives */
1035 wc_add_notice( __( 'Please choose a product to add to your cart&hellip;', 'woocommerce' ), 'error' );
1036 }
1037 return false;
1038 }
1039
1040 /**
1041 * Handle adding variable products to the cart.
1042 *
1043 * @since 2.4.6 Split from add_to_cart_action.
1044 * @throws Exception If add to cart fails.
1045 * @param int $product_id Product ID to add to the cart.
1046 * @return bool success or not
1047 */
1048 private static function add_to_cart_handler_variable( $product_id ) {
1049 $variation_id = empty( $_REQUEST['variation_id'] ) ? '' : absint( wp_unslash( $_REQUEST['variation_id'] ) ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
1050 $quantity = empty( $_REQUEST['quantity'] ) ? 1 : wc_stock_amount( wp_unslash( $_REQUEST['quantity'] ) ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
1051 $variations = array();
1052
1053 $product = wc_get_product( $product_id );
1054
1055 foreach ( $_REQUEST as $key => $value ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
1056 if ( 'attribute_' !== substr( $key, 0, 10 ) ) {
1057 continue;
1058 }
1059
1060 $variations[ sanitize_title( wp_unslash( $key ) ) ] = wp_unslash( $value );
1061 }
1062
1063 $passed_validation = apply_filters( 'woocommerce_add_to_cart_validation', true, $product_id, $quantity, $variation_id, $variations );
1064
1065 if ( ! $passed_validation ) {
1066 return false;
1067 }
1068
1069 // Prevent parent variable product from being added to cart.
1070 if ( empty( $variation_id ) && $product && $product->is_type( ProductType::VARIABLE ) ) {
1071 $current_url = isset( $_SERVER['REQUEST_URI'] ) ? wp_parse_url( sanitize_text_field( wp_unslash( $_SERVER['REQUEST_URI'] ) ), PHP_URL_PATH ) : '';
1072 $product_url = wp_parse_url( get_permalink( $product_id ), PHP_URL_PATH );
1073 $is_in_product_page = $current_url && $product_url && untrailingslashit( $current_url ) === untrailingslashit( $product_url );
1074
1075 if ( $is_in_product_page ) {
1076 /* translators: 1: product name */
1077 $error_message = sprintf( __( 'Please choose product options for %1$s.', 'woocommerce' ), esc_html( $product->get_name() ) );
1078 } else {
1079 /* translators: 1: product link, 2: product name */
1080 $error_message = sprintf( __( 'Please choose product options by visiting <a href="%1$s" title="%2$s">%2$s</a>.', 'woocommerce' ), esc_url( get_permalink( $product_id ) ), esc_html( $product->get_name() ) );
1081 }
1082
1083 wc_add_notice( $error_message, 'error' );
1084
1085 return false;
1086 }
1087
1088 if ( false !== WC()->cart->add_to_cart( $product_id, $quantity, $variation_id, $variations ) ) {
1089 wc_add_to_cart_message( array( $product_id => $quantity ), true );
1090 return true;
1091 }
1092
1093 return false;
1094 }
1095
1096 /**
1097 * Process the login form.
1098 *
1099 * @throws Exception On login error.
1100 */
1101 public static function process_login() {
1102
1103 static $valid_nonce = null;
1104
1105 if ( null === $valid_nonce ) {
1106 // The global form-login.php template used `_wpnonce` in template versions < 3.3.0.
1107 $nonce_value = wc_get_var( $_REQUEST['woocommerce-login-nonce'], wc_get_var( $_REQUEST['_wpnonce'], '' ) ); // @codingStandardsIgnoreLine.
1108
1109 $valid_nonce = wp_verify_nonce( $nonce_value, 'woocommerce-login' );
1110 }
1111
1112 if ( isset( $_POST['login'], $_POST['username'], $_POST['password'] ) && is_string( $_POST['username'] ) && is_string( $_POST['password'] ) && $valid_nonce ) {
1113
1114 try {
1115 $creds = array(
1116 'user_login' => trim( wp_unslash( $_POST['username'] ) ), // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1117 'user_password' => $_POST['password'], // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized, WordPress.Security.ValidatedSanitizedInput.MissingUnslash
1118 'remember' => isset( $_POST['rememberme'] ), // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1119 );
1120
1121 $validation_error = new WP_Error();
1122 $validation_error = apply_filters( 'woocommerce_process_login_errors', $validation_error, $creds['user_login'], $creds['user_password'] );
1123
1124 if ( $validation_error->get_error_code() ) {
1125 throw new Exception( '<strong>' . __( 'Error:', 'woocommerce' ) . '</strong> ' . $validation_error->get_error_message() );
1126 }
1127
1128 if ( empty( $creds['user_login'] ) ) {
1129 throw new Exception( '<strong>' . __( 'Error:', 'woocommerce' ) . '</strong> ' . __( 'Username is required.', 'woocommerce' ) );
1130 }
1131
1132 // On multisite, ensure user exists on current site, if not add them before allowing login.
1133 if ( is_multisite() ) {
1134 $user_data = get_user_by( is_email( $creds['user_login'] ) ? 'email' : 'login', $creds['user_login'] );
1135
1136 if ( $user_data && ! is_user_member_of_blog( $user_data->ID, get_current_blog_id() ) ) {
1137 add_user_to_blog( get_current_blog_id(), $user_data->ID, 'customer' );
1138 }
1139 }
1140
1141 // Perform the login.
1142 $user = wp_signon( apply_filters( 'woocommerce_login_credentials', $creds ), is_ssl() );
1143
1144 if ( is_wp_error( $user ) ) {
1145 throw new Exception( $user->get_error_message() );
1146 } else {
1147
1148 if ( ! empty( $_POST['redirect'] ) ) {
1149 $redirect = wp_unslash( $_POST['redirect'] ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1150 } elseif ( wc_get_raw_referer() ) {
1151 $redirect = wc_get_raw_referer();
1152 } else {
1153 $redirect = wc_get_page_permalink( 'myaccount' );
1154 }
1155
1156 $redirect = remove_query_arg( array( 'wc_error', 'password-reset' ), $redirect );
1157
1158 wp_redirect( wp_validate_redirect( apply_filters( 'woocommerce_login_redirect', $redirect, $user ), wc_get_page_permalink( 'myaccount' ) ) ); // phpcs:ignore
1159 exit;
1160 }
1161 } catch ( Exception $e ) {
1162 wc_add_notice( apply_filters( 'login_errors', $e->getMessage() ), 'error' );
1163 do_action( 'woocommerce_login_failed' );
1164 }
1165 }
1166 }
1167
1168 /**
1169 * Handle lost password form.
1170 */
1171 public static function process_lost_password() {
1172 if ( isset( $_POST['wc_reset_password'], $_POST['user_login'] ) ) {
1173 $nonce_value = wc_get_var( $_REQUEST['woocommerce-lost-password-nonce'], wc_get_var( $_REQUEST['_wpnonce'], '' ) ); // @codingStandardsIgnoreLine.
1174
1175 if ( ! wp_verify_nonce( $nonce_value, 'lost_password' ) ) {
1176 return;
1177 }
1178
1179 $success = WC_Shortcode_My_Account::retrieve_password();
1180
1181 // If successful, redirect to my account with query arg set.
1182 if ( $success ) {
1183 wp_safe_redirect( add_query_arg( 'reset-link-sent', 'true', wc_get_account_endpoint_url( 'lost-password' ) ) );
1184 exit;
1185 }
1186 }
1187 }
1188
1189 /**
1190 * Handle reset password form.
1191 */
1192 public static function process_reset_password() {
1193 $nonce_value = wc_get_var( $_REQUEST['woocommerce-reset-password-nonce'], wc_get_var( $_REQUEST['_wpnonce'], '' ) ); // @codingStandardsIgnoreLine.
1194
1195 if ( ! wp_verify_nonce( $nonce_value, 'reset_password' ) ) {
1196 return;
1197 }
1198
1199 $posted_fields = array( 'wc_reset_password', 'password_1', 'password_2', 'reset_key', 'reset_login' );
1200
1201 foreach ( $posted_fields as $field ) {
1202 if ( ! isset( $_POST[ $field ] ) ) {
1203 return;
1204 }
1205
1206 if ( in_array( $field, array( 'password_1', 'password_2' ), true ) ) {
1207 // Don't unslash password fields
1208 // @see https://github.com/woocommerce/woocommerce/issues/23922.
1209 $posted_fields[ $field ] = $_POST[ $field ]; // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized, WordPress.Security.ValidatedSanitizedInput.MissingUnslash
1210 } else {
1211 $posted_fields[ $field ] = wp_unslash( $_POST[ $field ] ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1212 }
1213 }
1214
1215 $user = WC_Shortcode_My_Account::check_password_reset_key( $posted_fields['reset_key'], $posted_fields['reset_login'] );
1216
1217 if ( $user instanceof WP_User ) {
1218 if ( empty( $posted_fields['password_1'] ) ) {
1219 wc_add_notice( __( 'Please enter your password.', 'woocommerce' ), 'error' );
1220 }
1221
1222 if ( $posted_fields['password_1'] !== $posted_fields['password_2'] ) {
1223 wc_add_notice( __( 'Passwords do not match.', 'woocommerce' ), 'error' );
1224 }
1225
1226 $errors = new WP_Error();
1227
1228 do_action( 'validate_password_reset', $errors, $user );
1229
1230 wc_add_wp_error_notices( $errors );
1231
1232 if ( 0 === wc_notice_count( 'error' ) ) {
1233 WC_Shortcode_My_Account::reset_password( $user, $posted_fields['password_1'] );
1234
1235 do_action( 'woocommerce_customer_reset_password', $user );
1236
1237 wp_safe_redirect( add_query_arg( 'password-reset', 'true', wc_get_page_permalink( 'myaccount' ) ) );
1238 exit;
1239 }
1240 }
1241 }
1242
1243 /**
1244 * Process the registration form.
1245 *
1246 * @throws Exception On registration error.
1247 */
1248 public static function process_registration() {
1249 $nonce_value = isset( $_POST['_wpnonce'] ) ? wp_unslash( $_POST['_wpnonce'] ) : ''; // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1250 $nonce_value = isset( $_POST['woocommerce-register-nonce'] ) ? wp_unslash( $_POST['woocommerce-register-nonce'] ) : $nonce_value; // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1251
1252 if ( isset( $_POST['register'], $_POST['email'] ) && wp_verify_nonce( $nonce_value, 'woocommerce-register' ) ) {
1253 $username = 'no' === get_option( 'woocommerce_registration_generate_username' ) && isset( $_POST['username'] ) ? wp_unslash( $_POST['username'] ) : ''; // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1254 $password = 'no' === get_option( 'woocommerce_registration_generate_password' ) && isset( $_POST['password'] ) ? $_POST['password'] : ''; // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized, WordPress.Security.ValidatedSanitizedInput.MissingUnslash
1255 $email = wp_unslash( $_POST['email'] ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1256
1257 try {
1258 $validation_error = new WP_Error();
1259 $validation_error = apply_filters( 'woocommerce_process_registration_errors', $validation_error, $username, $password, $email );
1260 $validation_errors = $validation_error->get_error_messages();
1261
1262 if ( 1 === count( $validation_errors ) ) {
1263 throw new Exception( $validation_error->get_error_message() );
1264 } elseif ( $validation_errors ) {
1265 foreach ( $validation_errors as $message ) {
1266 wc_add_notice( '<strong>' . __( 'Error:', 'woocommerce' ) . '</strong> ' . $message, 'error' );
1267 }
1268 throw new Exception();
1269 }
1270
1271 $new_customer = wc_create_new_customer( sanitize_email( $email ), wc_clean( $username ), $password );
1272
1273 if ( is_wp_error( $new_customer ) ) {
1274 throw new Exception( $new_customer->get_error_message() );
1275 }
1276
1277 if ( 'yes' === get_option( 'woocommerce_registration_generate_password' ) ) {
1278 wc_add_notice( __( 'Your account was created successfully and a password has been sent to your email address.', 'woocommerce' ) );
1279 } else {
1280 wc_add_notice( __( 'Your account was created successfully. Your login details have been sent to your email address.', 'woocommerce' ) );
1281 }
1282
1283 // Only redirect after a forced login - otherwise output a success notice.
1284 if ( apply_filters( 'woocommerce_registration_auth_new_customer', true, $new_customer ) ) {
1285 wc_set_customer_auth_cookie( $new_customer );
1286
1287 if ( ! empty( $_POST['redirect'] ) ) {
1288 $redirect = wp_sanitize_redirect( wp_unslash( $_POST['redirect'] ) ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
1289 } elseif ( wc_get_raw_referer() ) {
1290 $redirect = wc_get_raw_referer();
1291 } else {
1292 $redirect = wc_get_page_permalink( 'myaccount' );
1293 }
1294
1295 wp_redirect( wp_validate_redirect( apply_filters( 'woocommerce_registration_redirect', $redirect ), wc_get_page_permalink( 'myaccount' ) ) ); //phpcs:ignore WordPress.Security.SafeRedirect.wp_redirect_wp_redirect
1296 exit;
1297 }
1298 } catch ( Exception $e ) {
1299 if ( $e->getMessage() ) {
1300 wc_add_notice( '<strong>' . __( 'Error:', 'woocommerce' ) . '</strong> ' . $e->getMessage(), 'error' );
1301 }
1302 }
1303 }
1304 }
1305 }
1306
1307 WC_Form_Handler::init();
1308