| @@ -24,8 +24,20 @@ | ||
| 24 | 24 | { |
| 25 | 25 | $page = (string) ($route_data['page'] ?? 'dashboard'); |
| 26 | 26 | $base = (string) ($route_data['base'] ?? SettingsService::getAccountBase()); |
| 27 | 27 | |
| 28 | + // Email-change confirmation (WordPress core pattern). The emailed link | |
| 29 | + // lands here as a normal front-end request, so the WordPress auth cookie | |
| 30 | + // identifies the customer — unlike a REST GET, which carries no nonce and | |
| 31 | + // would be treated as anonymous. Handled before anything else so the | |
| 32 | + // token is consumed and we redirect away cleanly. | |
| 33 | + $emailToken = isset($_GET['yatra_email_token']) | |
| 34 | + ? sanitize_text_field(wp_unslash((string) $_GET['yatra_email_token'])) | |
| 35 | + : ''; | |
| 36 | + if ($emailToken !== '') { | |
| 37 | + $this->confirmEmailChange($emailToken, $base); // always redirects + exits | |
| 38 | + } | |
| 39 | + | |
| 28 | 40 | if (!$this->isValidAccountPage($page)) { |
| 29 | 41 | return false; |
| 30 | 42 | } |
| 31 | 43 | |
| @@ -41,27 +53,50 @@ | ||
| 41 | 53 | wp_safe_redirect(add_query_arg('tab', $tab)); |
| 42 | 54 | exit; |
| 43 | 55 | } |
| 44 | 56 | |
| 45 | - $this->prevent404(); | |
| 57 | + $this->setupPageEnvironment('singular', [ | |
| 58 | + 'title' => __('My Account', 'yatra'), | |
| 59 | + 'post_type' => 'page', | |
| 60 | + 'post_name' => $base, | |
| 61 | + ]); | |
| 46 | 62 | |
| 47 | 63 | $this->setQueryVars([ |
| 48 | 64 | 'yatra_account_page' => $page, |
| 49 | 65 | ]); |
| 50 | 66 | |
| 51 | - $template_path = YATRA_PLUGIN_PATH . 'templates/account-page.php'; | |
| 67 | + $GLOBALS['yatra_loading_react_account_page'] = true; | |
| 52 | 68 | |
| 53 | - if (!file_exists($template_path)) { | |
| 54 | - $this->logError("Account page template not found: {$template_path}"); | |
| 55 | - return false; | |
| 69 | + return $this->selectTemplate('account-page', null, 'account'); | |
| 70 | + } | |
| 71 | + | |
| 72 | + /** | |
| 73 | + * Confirm a pending account email change from the emailed link, then redirect | |
| 74 | + * back to the Profile tab with a success/error flag. Mirrors WordPress core's | |
| 75 | + * confirmation step (logged-out visitors are bounced through login and returned | |
| 76 | + * here to finish). Always redirects and exits. | |
| 77 | + */ | |
| 78 | + private function confirmEmailChange(string $token, string $base): void | |
| 79 | + { | |
| 80 | + $accountUrl = home_url('/' . trailingslashit($base)); | |
| 81 | + | |
| 82 | + if (!is_user_logged_in()) { | |
| 83 | + $returnUrl = add_query_arg('yatra_email_token', rawurlencode($token), $accountUrl); | |
| 84 | + wp_safe_redirect(wp_login_url($returnUrl)); | |
| 85 | + exit; | |
| 56 | 86 | } |
| 57 | 87 | |
| 58 | - $GLOBALS['yatra_loading_react_account_page'] = true; | |
| 88 | + $result = (new \Yatra\Services\CustomerService()) | |
| 89 | + ->confirmEmailChange(get_current_user_id(), $token); | |
| 59 | 90 | |
| 60 | - include $template_path; | |
| 61 | - $this->exit(); | |
| 62 | - | |
| 63 | - return true; | |
| 91 | + wp_safe_redirect(add_query_arg( | |
| 92 | + [ | |
| 93 | + 'tab' => 'profile', | |
| 94 | + 'email_change' => empty($result['success']) ? 'error' : 'success', | |
| 95 | + ], | |
| 96 | + $accountUrl | |
| 97 | + )); | |
| 98 | + exit; | |
| 64 | 99 | } |
| 65 | 100 | |
| 66 | 101 | /** |
| 67 | 102 | * @return list<string> |