PluginProbe
Yatra – Travel Booking & Tour Operator Software / 3.0.16
Yatra – Travel Booking & Tour Operator Software v3.0.16
3.0.16 3.0.15 3.0.14 3.0.14.1 3.0.14.2 3.0.12 3.0.13 3.0.11 3.0.10 3.0.9 3.0.8 3.0.7 3.0.6 3.0.5 3.0.5.1 3.0.4 3.0.3 3.0.2.9 3.0.2.7 3.0.2.8 3.0.2.6 trunk 1.0.0 2.0.0 2.0.1 All 84 releases
← All changes | app/Core/Handlers/AccountPageHandler.php +41 -0 3.0.4 → 3.0.16 View file →
@@ -24,8 +24,20 @@
24 24 {
25 25 $page = (string) ($route_data['page'] ?? 'dashboard');
26 26 $base = (string) ($route_data['base'] ?? SettingsService::getAccountBase());
27 27
28 + // Email-change confirmation (WordPress core pattern). The emailed link
29 + // lands here as a normal front-end request, so the WordPress auth cookie
30 + // identifies the customer — unlike a REST GET, which carries no nonce and
31 + // would be treated as anonymous. Handled before anything else so the
32 + // token is consumed and we redirect away cleanly.
33 + $emailToken = isset($_GET['yatra_email_token'])
34 + ? sanitize_text_field(wp_unslash((string) $_GET['yatra_email_token']))
35 + : '';
36 + if ($emailToken !== '') {
37 + $this->confirmEmailChange($emailToken, $base); // always redirects + exits
38 + }
39 +
28 40 if (!$this->isValidAccountPage($page)) {
29 41 return false;
30 42 }
31 43
@@ -54,8 +66,37 @@
54 66
55 67 $GLOBALS['yatra_loading_react_account_page'] = true;
56 68
57 69 return $this->selectTemplate('account-page', null, 'account');
70 + }
71 +
72 + /**
73 + * Confirm a pending account email change from the emailed link, then redirect
74 + * back to the Profile tab with a success/error flag. Mirrors WordPress core's
75 + * confirmation step (logged-out visitors are bounced through login and returned
76 + * here to finish). Always redirects and exits.
77 + */
78 + private function confirmEmailChange(string $token, string $base): void
79 + {
80 + $accountUrl = home_url('/' . trailingslashit($base));
81 +
82 + if (!is_user_logged_in()) {
83 + $returnUrl = add_query_arg('yatra_email_token', rawurlencode($token), $accountUrl);
84 + wp_safe_redirect(wp_login_url($returnUrl));
85 + exit;
86 + }
87 +
88 + $result = (new \Yatra\Services\CustomerService())
89 + ->confirmEmailChange(get_current_user_id(), $token);
90 +
91 + wp_safe_redirect(add_query_arg(
92 + [
93 + 'tab' => 'profile',
94 + 'email_change' => empty($result['success']) ? 'error' : 'success',
95 + ],
96 + $accountUrl
97 + ));
98 + exit;
58 99 }
59 100
60 101 /**
61 102 * @return list<string>