PluginProbe
Yatra – Travel Booking & Tour Operator Software / 3.0.16
Yatra – Travel Booking & Tour Operator Software v3.0.16
3.0.16 3.0.15 3.0.14 3.0.14.1 3.0.14.2 3.0.12 3.0.13 3.0.11 3.0.10 3.0.9 3.0.8 3.0.7 3.0.6 3.0.5 3.0.5.1 3.0.4 3.0.3 3.0.2.9 3.0.2.7 3.0.2.8 3.0.2.6 trunk 1.0.0 2.0.0 2.0.1 All 84 releases
← All changes | app/Validators/BookingValidator.php +22 -0 3.0.8 → 3.0.16 View file →
@@ -36,8 +36,20 @@
36 36 'waitlist',
37 37 ];
38 38
39 39 /**
40 + * Accepted payment statuses — mirrors the `payment_status` ENUM on the
41 + * bookings table.
42 + */
43 + private const VALID_PAYMENT_STATUSES = [
44 + 'pending',
45 + 'partial',
46 + 'paid',
47 + 'refunded',
48 + 'failed',
49 + ];
50 +
51 + /**
40 52 * Normalize a locale-formatted numeric string to a PHP-parseable form.
41 53 *
42 54 * Russian / European locales format money as "1 200,50" (space thousands +
43 55 * comma decimal), and some browsers/inputs submit that raw string. PHP's
@@ -222,8 +234,18 @@
222 234
223 235 if (isset($data['status'])) {
224 236 if (!in_array($data['status'], self::VALID_BOOKING_STATUSES, true)) {
225 237 $errors['status'][] = __('Invalid booking status', 'yatra');
238 + }
239 + }
240 +
241 + // Reject rather than fall through to sanitize(), which coerces an
242 + // unknown value to 'pending'. On an update that silently reset a
243 + // fully-paid booking to unpaid while amount_paid kept the money that had
244 + // actually been received — and still reported success.
245 + if (isset($data['payment_status'])) {
246 + if (!in_array($data['payment_status'], self::VALID_PAYMENT_STATUSES, true)) {
247 + $errors['payment_status'][] = __('Invalid payment status', 'yatra');
226 248 }
227 249 }
228 250
229 251 if (isset($data['total_amount']) && (!is_numeric(self::normalizeNumeric($data['total_amount'])) || (float)self::normalizeNumeric($data['total_amount']) < 0)) {