PluginProbe
Yatra – Travel Booking & Tour Operator Software / 3.0.16
Yatra – Travel Booking & Tour Operator Software v3.0.16
3.0.16 3.0.15 3.0.14 3.0.14.1 3.0.14.2 3.0.12 3.0.13 3.0.11 3.0.10 3.0.9 3.0.8 3.0.7 3.0.6 3.0.5 3.0.5.1 3.0.4 3.0.3 3.0.2.9 3.0.2.7 3.0.2.8 3.0.2.6 trunk 1.0.0 2.0.0 2.0.1 All 84 releases
← All changes | app/Controllers/PaymentController.php +16 -0 3.0.11 → 3.0.16 View file →
@@ -147,8 +147,12 @@
147 147 'gateway' => $request->get_param('gateway') ?: '',
148 148 'search' => $request->get_param('search') ?: '',
149 149 'date_from' => $request->get_param('date_from') ?: '',
150 150 'date_to' => $request->get_param('date_to') ?: '',
151 + // Column sorting from the table headers. Both are validated against a
152 + // whitelist in the repository — never interpolated raw into SQL.
153 + 'orderby' => $request->get_param('orderby') ?: '',
154 + 'order' => $request->get_param('order') ?: '',
151 155 ];
152 156
153 157 $result = $this->paymentService->getPayments($filters);
154 158
@@ -184,8 +188,16 @@
184 188 $data = $request->get_json_params();
185 189
186 190 try {
187 191 $payment = $this->paymentService->createPayment($data);
192 +
193 + // The service reports validation failures (unknown booking, invalid
194 + // status) as ['success' => false]; answering 201 made the admin form
195 + // redirect as if the payment had been saved.
196 + if (is_array($payment) && isset($payment['success']) && !$payment['success']) {
197 + return new WP_REST_Response($payment, 400);
198 + }
199 +
188 200 return new WP_REST_Response($payment, 201);
189 201 } catch (\Exception $e) {
190 202 return new WP_Error('payment_creation_failed', $e->getMessage(), ['status' => 400]);
191 203 }
@@ -203,8 +215,12 @@
203 215 $payment = $this->paymentService->updatePayment($id, $data);
204 216
205 217 if (!$payment) {
206 218 return new WP_Error('payment_not_found', 'Payment not found', ['status' => 404]);
219 + }
220 +
221 + if (is_array($payment) && isset($payment['success']) && !$payment['success']) {
222 + return new WP_REST_Response($payment, 400);
207 223 }
208 224
209 225 return new WP_REST_Response($payment, 200);
210 226 } catch (\Exception $e) {