| @@ -147,8 +147,12 @@ | ||
| 147 | 147 | 'gateway' => $request->get_param('gateway') ?: '', |
| 148 | 148 | 'search' => $request->get_param('search') ?: '', |
| 149 | 149 | 'date_from' => $request->get_param('date_from') ?: '', |
| 150 | 150 | 'date_to' => $request->get_param('date_to') ?: '', |
| 151 | + // Column sorting from the table headers. Both are validated against a | |
| 152 | + // whitelist in the repository — never interpolated raw into SQL. | |
| 153 | + 'orderby' => $request->get_param('orderby') ?: '', | |
| 154 | + 'order' => $request->get_param('order') ?: '', | |
| 151 | 155 | ]; |
| 152 | 156 | |
| 153 | 157 | $result = $this->paymentService->getPayments($filters); |
| 154 | 158 | |
| @@ -184,8 +188,16 @@ | ||
| 184 | 188 | $data = $request->get_json_params(); |
| 185 | 189 | |
| 186 | 190 | try { |
| 187 | 191 | $payment = $this->paymentService->createPayment($data); |
| 192 | + | |
| 193 | + // The service reports validation failures (unknown booking, invalid | |
| 194 | + // status) as ['success' => false]; answering 201 made the admin form | |
| 195 | + // redirect as if the payment had been saved. | |
| 196 | + if (is_array($payment) && isset($payment['success']) && !$payment['success']) { | |
| 197 | + return new WP_REST_Response($payment, 400); | |
| 198 | + } | |
| 199 | + | |
| 188 | 200 | return new WP_REST_Response($payment, 201); |
| 189 | 201 | } catch (\Exception $e) { |
| 190 | 202 | return new WP_Error('payment_creation_failed', $e->getMessage(), ['status' => 400]); |
| 191 | 203 | } |
| @@ -203,8 +215,12 @@ | ||
| 203 | 215 | $payment = $this->paymentService->updatePayment($id, $data); |
| 204 | 216 | |
| 205 | 217 | if (!$payment) { |
| 206 | 218 | return new WP_Error('payment_not_found', 'Payment not found', ['status' => 404]); |
| 219 | + } | |
| 220 | + | |
| 221 | + if (is_array($payment) && isset($payment['success']) && !$payment['success']) { | |
| 222 | + return new WP_REST_Response($payment, 400); | |
| 207 | 223 | } |
| 208 | 224 | |
| 209 | 225 | return new WP_REST_Response($payment, 200); |
| 210 | 226 | } catch (\Exception $e) { |