| @@ -46,20 +46,40 @@ | ||
| 46 | 46 | 'date_format' => 'Y-m-d', |
| 47 | 47 | 'time_format' => 'H:i', |
| 48 | 48 | 'frontend_primary_color' => '#3b82f6', |
| 49 | 49 | 'frontend_container_max_width' => '', |
| 50 | + // Trip listing card density. 'standard' = the current comfortable card; | |
| 51 | + // 'compact_mobile' = compact card on phones/tablets only (desktop grid | |
| 52 | + // unchanged); 'compact_all' = compact card at every screen size. | |
| 53 | + 'frontend_listing_card_layout' => 'standard', | |
| 50 | 54 | |
| 51 | 55 | // Booking Settings |
| 52 | 56 | 'booking_confirmation' => true, |
| 57 | + // Legacy boolean, kept for backward compatibility. Superseded by | |
| 58 | + // 'auto_confirm_mode' below; the mode is authoritative once stored. | |
| 53 | 59 | 'auto_confirm_bookings' => false, |
| 60 | + // Auto-confirm mode: 'none' (never), 'online' (only successful online | |
| 61 | + // gateway payments), or 'all' (confirm every booking at checkout). | |
| 62 | + // Default 'online' (payment complete => confirmed). Existing sites with | |
| 63 | + // no stored mode resolve on the fly via yatra_get_auto_confirm_mode() | |
| 64 | + // (legacy true->all, false->online), preserving their prior behaviour. | |
| 65 | + 'auto_confirm_mode' => 'online', | |
| 54 | 66 | 'auto_confirm_pay_later' => true, |
| 55 | 67 | 'require_login' => false, |
| 56 | 68 | 'allow_guest_checkout' => true, |
| 57 | - 'cancellation_policy' => 'full_refund', | |
| 58 | - 'cancellation_days' => 7, | |
| 59 | - 'refund_policy' => '', | |
| 69 | + // cancellation_policy / cancellation_days / refund_policy were | |
| 70 | + // removed in 3.0.5 — they only inserted text into the booking | |
| 71 | + // confirmation email but did NOT enforce a cancellation cutoff | |
| 72 | + // because Yatra has no customer-facing self-service | |
| 73 | + // cancellation flow. Per-trip cancellation copy on the Trip | |
| 74 | + // editor is the supported way to communicate policy. If those | |
| 75 | + // legacy options still exist in wp_options on upgraded sites | |
| 76 | + // they're harmless orphans — the save endpoint no longer | |
| 77 | + // accepts them, and the email template skips the cancellation | |
| 78 | + // paragraph when the global setting is absent. | |
| 60 | 79 | 'booking_expiry_hours' => 24, |
| 61 | 80 | 'booking_reminder_days' => 3, |
| 81 | + 'availability_horizon_months' => 12, | |
| 62 | 82 | 'allow_waitlist' => true, |
| 63 | 83 | 'waitlist_auto_confirm' => false, |
| 64 | 84 | // Pro: render available departure dates as a <select> instead of a |
| 65 | 85 | // flatpickr calendar on the single-trip sidebar (desktop + mobile). |
| @@ -75,9 +95,21 @@ | ||
| 75 | 95 | 'deposit_required' => false, |
| 76 | 96 | 'deposit_percentage' => 20, |
| 77 | 97 | 'gateway_configs' => [], |
| 78 | 98 | 'gateway_order' => [], |
| 79 | - | |
| 99 | + | |
| 100 | + // Discount Stacking Mode — controls how the Advanced Discount and | |
| 101 | + // Dynamic Pricing modules combine when both can fire on the same | |
| 102 | + // booking. Default 'both' preserves the legacy stacked behavior | |
| 103 | + // (discount on top of DP-adjusted price). The Settings → Pricing | |
| 104 | + // tab only surfaces this setting when BOTH modules are enabled, | |
| 105 | + // and CalculationService only enforces a non-default mode when | |
| 106 | + // BOTH modules are loaded — so sites with only one (or neither) | |
| 107 | + // module see zero behavior change. | |
| 108 | + // | |
| 109 | + // Allowed: 'both' | 'discount_only' | 'dynamic_pricing_only' | 'best_for_customer' | |
| 110 | + 'discount_stacking_mode' => 'both', | |
| 111 | + | |
| 80 | 112 | // Scheduled/Recurring Payment Settings (Pro feature - defaults disabled) |
| 81 | 113 | 'enable_scheduled_payments' => false, |
| 82 | 114 | 'scheduled_payment_type' => 'single', // single, installments |
| 83 | 115 | 'scheduled_payment_days' => 15, // Days until first scheduled payment |
| @@ -83,8 +115,10 @@ | ||
| 83 | 115 | 'scheduled_payment_days' => 15, // Days until first scheduled payment |
| 84 | 116 | 'scheduled_payment_installments' => 1, // Number of installments (if type is installments) |
| 85 | 117 | 'scheduled_payment_interval' => 30, // Days between installments |
| 86 | 118 | 'scheduled_payment_reminder_days' => 3, // Days before to send reminder |
| 119 | + 'balance_anchor' => 'booking', // 'booking' (BC default) | 'tour' (relative to tour date) | |
| 120 | + 'balance_due_days' => 14, // When anchor=tour: balance due this many days before the tour | |
| 87 | 121 | 'allow_save_payment_methods' => false, |
| 88 | 122 | |
| 89 | 123 | // Email Settings (WordPress site defaults when Yatra options are missing) |
| 90 | 124 | 'admin_email' => $wpAdminEmail, |
| @@ -89,10 +123,16 @@ | ||
| 89 | 123 | // Email Settings (WordPress site defaults when Yatra options are missing) |
| 90 | 124 | 'admin_email' => $wpAdminEmail, |
| 91 | 125 | 'from_email' => $wpAdminEmail, |
| 92 | 126 | 'from_name' => $wpSiteName, |
| 127 | + // Blind copy of every outgoing Yatra email, for archiving/monitoring. | |
| 128 | + // Empty means no copy is sent; accepts several comma-separated addresses. | |
| 129 | + 'email_always_bcc' => '', | |
| 93 | 130 | 'email_template_booking' => true, |
| 94 | 131 | 'email_template_confirmation' => true, |
| 132 | + // Separate part-payment email. Off by default so existing sites keep | |
| 133 | + // sending the single payment template for every payment. | |
| 134 | + 'email_template_partial_payment' => false, | |
| 95 | 135 | 'email_template_cancellation' => true, |
| 96 | 136 | 'email_template_reminder' => true, |
| 97 | 137 | 'email_template_admin_new_booking' => true, |
| 98 | 138 | 'email_template_admin_payment' => true, |
| @@ -98,8 +138,11 @@ | ||
| 98 | 138 | 'email_template_admin_payment' => true, |
| 99 | 139 | 'email_template_admin_cancellation' => true, |
| 100 | 140 | 'email_template_trip_consent' => true, |
| 101 | 141 | 'email_template_customer_verification' => true, |
| 142 | + 'email_template_guest_verification' => true, | |
| 143 | + 'email_template_account_email_change' => true, | |
| 144 | + 'email_template_account_email_changed' => true, | |
| 102 | 145 | 'email_template_booking_completed' => true, |
| 103 | 146 | 'email_template_booking_expired_customer' => true, |
| 104 | 147 | 'email_template_admin_booking_expired' => true, |
| 105 | 148 | 'email_template_scheduled_payment_reminder' => true, |
| @@ -108,9 +151,18 @@ | ||
| 108 | 151 | 'email_template_admin_scheduled_payment_failed' => true, |
| 109 | 152 | 'email_template_enquiry_received' => true, |
| 110 | 153 | 'email_template_enquiry_admin' => true, |
| 111 | 154 | 'email_template_enquiry_response' => true, |
| 112 | - 'email_template_review_request' => true, | |
| 155 | + // Off by default, unlike the other templates. A review request is the | |
| 156 | + // one transactional email that is not a response to something the | |
| 157 | + // customer just did, and several jurisdictions treat it as advertising | |
| 158 | + // rather than service mail — in Germany the BGH (VI ZR 225/17) holds it | |
| 159 | + // needs prior consent, and the existing-customer exemption in | |
| 160 | + // §7 Abs. 3 UWG does not cover it. Shipping it on would have every new | |
| 161 | + // site mailing customers for consent it has not collected, so the | |
| 162 | + // operator turns it on once they have decided how they collect it. | |
| 163 | + // Sites that already have it on are untouched. | |
| 164 | + 'email_template_review_request' => false, | |
| 113 | 165 | 'email_template_abandoned_booking_recovery_first' => true, |
| 114 | 166 | 'email_template_abandoned_booking_recovery_second' => true, |
| 115 | 167 | 'email_template_abandoned_booking_recovery_final' => true, |
| 116 | 168 | 'smtp_enabled' => false, |
| @@ -123,8 +175,13 @@ | ||
| 123 | 175 | // Customer Settings |
| 124 | 176 | 'customer_registration' => true, |
| 125 | 177 | 'customer_fields' => [], |
| 126 | 178 | 'require_email_verification' => false, |
| 179 | + // Per-booking verification for guest checkouts. Distinct from the | |
| 180 | + // account-creation `require_email_verification` flag because a guest | |
| 181 | + // never registers — the verification is gated on the booking itself | |
| 182 | + // (BookingSessionController checks this when admitting a guest). | |
| 183 | + 'require_guest_email_verification' => false, | |
| 127 | 184 | 'customer_account_page' => '', |
| 128 | 185 | 'allow_customer_reviews' => true, |
| 129 | 186 | 'customer_dashboard_enabled' => true, |
| 130 | 187 | |
| @@ -134,9 +191,13 @@ | ||
| 134 | 191 | 'auto_approve_reviews' => false, |
| 135 | 192 | 'review_moderation' => true, |
| 136 | 193 | 'min_rating' => 1, |
| 137 | 194 | 'allow_anonymous_reviews' => false, |
| 138 | - 'review_reminder_days' => 7, | |
| 195 | + 'review_reminder_days' => 3, | |
| 196 | + // Never ask about a trip that ended longer ago than this. The | |
| 197 | + // reminder is anchored to the tour's end date, so a backlog of | |
| 198 | + // bookings completed late is skipped rather than mailed in bulk. | |
| 199 | + 'review_reminder_max_age_days' => 14, | |
| 139 | 200 | |
| 140 | 201 | // Tax Settings |
| 141 | 202 | 'enable_tax' => false, |
| 142 | 203 | 'tax_name' => __('Tax', 'yatra'), |
| @@ -167,9 +228,22 @@ | ||
| 167 | 228 | 'facebook_pixel' => '', |
| 168 | 229 | 'recaptcha_enabled' => false, |
| 169 | 230 | 'recaptcha_site_key' => '', |
| 170 | 231 | 'recaptcha_secret_key' => '', |
| 171 | - | |
| 232 | + // reCAPTCHA v3: score threshold (0.0-1.0) + per-form protection toggles. | |
| 233 | + // All off by default so enabling reCAPTCHA alone changes nothing until | |
| 234 | + // the operator picks which forms to protect. | |
| 235 | + 'recaptcha_score_threshold' => 0.5, | |
| 236 | + 'recaptcha_protect_enquiry' => false, | |
| 237 | + 'recaptcha_protect_booking' => false, | |
| 238 | + 'recaptcha_protect_registration' => false, | |
| 239 | + | |
| 240 | + // Uninstall. Off by default and deliberately never defaulted to true: | |
| 241 | + // turning this on means deleting the operator's bookings, customers and | |
| 242 | + // payment history when the plugin is removed, so it has to be a decision | |
| 243 | + // somebody makes on purpose. | |
| 244 | + 'delete_data_on_uninstall' => false, | |
| 245 | + | |
| 172 | 246 | // Permalink Settings |
| 173 | 247 | 'trip_base' => 'trip', |
| 174 | 248 | 'destination_base' => 'destination', |
| 175 | 249 | 'activity_base' => 'activity', |
| @@ -176,9 +250,29 @@ | ||
| 176 | 250 | 'trip_category_base' => 'trip-category', |
| 177 | 251 | 'booking_base' => 'book', |
| 178 | 252 | // Wishlist (Pro) — stored in free options; active only when Pro + setting on |
| 179 | 253 | 'enable_wishlist' => false, |
| 180 | - | |
| 254 | + // Sold-out date visibility on the storefront. Default true keeps the | |
| 255 | + // existing behaviour (sold-out dates stay visible, badged "sold out" and | |
| 256 | + // able to drive the waitlist); owners can switch it off to hide them the | |
| 257 | + // same way blocked dates are hidden. | |
| 258 | + 'show_sold_out' => true, | |
| 259 | + | |
| 260 | + // Search & Listing storefront UX. Defaults preserve current behaviour: | |
| 261 | + // every search field shown (true) and mobile filters expanded (false), | |
| 262 | + // so existing installs are unchanged until the owner opts in. Booleans | |
| 263 | + // are auto-sanitized from the default type. | |
| 264 | + 'search_show_keyword' => true, | |
| 265 | + 'search_show_destination' => true, | |
| 266 | + 'search_show_activities' => true, | |
| 267 | + 'search_show_duration' => true, | |
| 268 | + 'search_show_budget' => true, | |
| 269 | + // Date field is opt-in (default false) so updating the plugin never | |
| 270 | + // changes an existing site's search bar. Operators enable it to let | |
| 271 | + // customers find trips with a departure on a specific date. | |
| 272 | + 'search_show_date' => false, | |
| 273 | + 'collapse_filters_on_mobile' => false, | |
| 274 | + | |
| 181 | 275 | // Booking Page Settings |
| 182 | 276 | 'use_booking_page' => false, |
| 183 | 277 | 'booking_page_id' => 0, |
| 184 | 278 | |
| @@ -190,9 +284,17 @@ | ||
| 190 | 284 | 'seo_trip_meta_title' => '', |
| 191 | 285 | 'seo_trip_meta_description' => '', |
| 192 | 286 | 'seo_trip_meta_keywords' => '', |
| 193 | 287 | 'seo_trip_meta_image' => 0, |
| 194 | - | |
| 288 | + 'enable_sitemap' => true, | |
| 289 | + // Which Yatra content types appear in /yatra-sitemap.xml. Defaults to | |
| 290 | + // every type, so a site that never touches this keeps today's sitemap. | |
| 291 | + 'sitemap_types' => ['archive', 'trip', 'destination', 'activity', 'category'], | |
| 292 | + // Opt-in, and deliberately separate from the list above: dropping a type | |
| 293 | + // from the sitemap is housekeeping, while noindex de-indexes pages that | |
| 294 | + // may currently rank. That should never happen as a side effect. | |
| 295 | + 'sitemap_noindex_excluded' => false, | |
| 296 | + | |
| 195 | 297 | // Advanced Settings |
| 196 | 298 | 'debug_mode' => false, |
| 197 | 299 | 'enable_logging' => false, |
| 198 | 300 | 'cache_enabled' => true, |
| @@ -239,8 +341,26 @@ | ||
| 239 | 341 | 'permission_callback' => [$this, 'check_permission'], |
| 240 | 342 | ], |
| 241 | 343 | ]); |
| 242 | 344 | |
| 345 | + // Booking form config, optionally resolved for one trip (Pro form | |
| 346 | + // conditions). Readable by anyone who can view bookings, so the | |
| 347 | + // booking detail screen can label the fields a trip actually asked. | |
| 348 | + register_rest_route($namespace, '/' . $base . '/booking-form', [ | |
| 349 | + [ | |
| 350 | + 'methods' => \WP_REST_Server::READABLE, | |
| 351 | + 'callback' => [$this, 'get_booking_form_config'], | |
| 352 | + 'permission_callback' => [$this, 'check_booking_form_permission'], | |
| 353 | + 'args' => [ | |
| 354 | + 'trip_id' => [ | |
| 355 | + 'type' => 'integer', | |
| 356 | + 'required' => false, | |
| 357 | + 'sanitize_callback' => 'absint', | |
| 358 | + ], | |
| 359 | + ], | |
| 360 | + ], | |
| 361 | + ]); | |
| 362 | + | |
| 243 | 363 | // Get WordPress pages for booking page selection |
| 244 | 364 | register_rest_route($namespace, '/' . $base . '/pages', [ |
| 245 | 365 | [ |
| 246 | 366 | 'methods' => \WP_REST_Server::READABLE, |
| @@ -308,20 +428,60 @@ | ||
| 308 | 428 | return $this->error_response($e->getMessage(), 500); |
| 309 | 429 | } |
| 310 | 430 | } |
| 311 | 431 | |
| 432 | + /** | |
| 433 | + * Plugin settings — high-sensitivity cap. By default only the | |
| 434 | + * Owner role holds `yatra_manage_settings` (Manager doesn't, by | |
| 435 | + * design — settings include payment gateway routing, email | |
| 436 | + * delivery configuration, currency formatting and similar | |
| 437 | + * global behaviour). WP admins pass via the Team module's | |
| 438 | + * admin-fallback filter. | |
| 439 | + */ | |
| 312 | 440 | public function check_permission(?WP_REST_Request $request = null): bool |
| 313 | 441 | { |
| 314 | 442 | if (!is_user_logged_in()) { |
| 315 | 443 | return false; |
| 316 | 444 | } |
| 445 | + return current_user_can('yatra_manage_settings'); | |
| 446 | + } | |
| 317 | 447 | |
| 318 | - // Match other Yatra admin surfaces (e.g. Email Automation, Pro modules) | |
| 319 | - return current_user_can('manage_options') | |
| 320 | - || current_user_can('manage_yatra'); | |
| 448 | + /** | |
| 449 | + * The booking form config is needed to label booking data, so it is | |
| 450 | + * readable by booking staff, not only settings managers. | |
| 451 | + */ | |
| 452 | + public function check_booking_form_permission(?WP_REST_Request $request = null): bool | |
| 453 | + { | |
| 454 | + if (!is_user_logged_in()) { | |
| 455 | + return false; | |
| 456 | + } | |
| 457 | + return current_user_can('yatra_manage_settings') | |
| 458 | + || current_user_can('yatra_view_bookings') | |
| 459 | + || current_user_can('yatra_edit_bookings'); | |
| 321 | 460 | } |
| 322 | 461 | |
| 323 | 462 | /** |
| 463 | + * GET /settings/booking-form[?trip_id=N] | |
| 464 | + * | |
| 465 | + * Without trip_id: the full config exactly as the Settings screen sees it. | |
| 466 | + * With trip_id: the config as that trip's checkout renders it — Pro form | |
| 467 | + * conditions resolved (no Pro / no conditions → identical to the global). | |
| 468 | + */ | |
| 469 | + public function get_booking_form_config(WP_REST_Request $request) | |
| 470 | + { | |
| 471 | + try { | |
| 472 | + $trip_id = (int) $request->get_param('trip_id'); | |
| 473 | + | |
| 474 | + return $this->success_response([ | |
| 475 | + 'booking_form_config' => \Yatra\Services\SettingsService::getBookingFormConfig($trip_id > 0 ? $trip_id : null), | |
| 476 | + 'trip_id' => $trip_id > 0 ? $trip_id : null, | |
| 477 | + ]); | |
| 478 | + } catch (\Exception $e) { | |
| 479 | + return $this->error_response($e->getMessage(), 500); | |
| 480 | + } | |
| 481 | + } | |
| 482 | + | |
| 483 | + /** | |
| 324 | 484 | * Get all settings |
| 325 | 485 | */ |
| 326 | 486 | public function get_settings(WP_REST_Request $request) |
| 327 | 487 | { |
| @@ -327,18 +487,36 @@ | ||
| 327 | 487 | { |
| 328 | 488 | try { |
| 329 | 489 | $settings = []; |
| 330 | 490 | |
| 331 | - // Get all settings from WordPress options table with yatra_ prefix | |
| 491 | + // Get all settings from WordPress options table with yatra_ prefix. | |
| 492 | + // A sentinel default is essential here: get_option() returns boolean | |
| 493 | + // false for a stored-false option just as it does for a missing one, | |
| 494 | + // so checking `=== false` would reset every saved-off boolean back to | |
| 495 | + // its default. That is exactly the "Show sold-out dates" bug — the | |
| 496 | + // storefront honoured the saved value (isEnabled coerces '' -> false) | |
| 497 | + // while the admin checkbox re-appeared enabled because this endpoint | |
| 498 | + // handed React the default (true) instead of the saved false. | |
| 499 | + $unset_sentinel = "\0__yatra_option_unset__\0"; | |
| 332 | 500 | foreach ($this->default_settings as $key => $default_value) { |
| 333 | 501 | $option_name = 'yatra_' . $key; |
| 334 | - $value = get_option($option_name, false); | |
| 335 | - | |
| 336 | - // Only use default if option doesn't exist (wasn't set by InstallerService) | |
| 337 | - if ($value === false) { | |
| 502 | + $value = get_option($option_name, $unset_sentinel); | |
| 503 | + | |
| 504 | + // Only use default when the option truly does not exist. | |
| 505 | + if ($value === $unset_sentinel) { | |
| 338 | 506 | $value = $default_value; |
| 339 | 507 | } |
| 340 | 508 | |
| 509 | + // Auto-Confirm mode has no stored default — it is resolved on | |
| 510 | + // the fly. Return the effective mode so the admin shows the | |
| 511 | + // site's real behaviour: a stored choice if the operator made | |
| 512 | + // one, otherwise derived from the legacy boolean | |
| 513 | + // (true -> 'all', false -> 'online'). Prevents an existing | |
| 514 | + // "confirm all" site from displaying (and re-saving) as 'online'. | |
| 515 | + if ($key === 'auto_confirm_mode' && function_exists('yatra_get_auto_confirm_mode')) { | |
| 516 | + $value = yatra_get_auto_confirm_mode(); | |
| 517 | + } | |
| 518 | + | |
| 341 | 519 | // Stored empty string should behave like "unset" for delivery identity (matches installer / backfill). |
| 342 | 520 | if (($key === 'admin_email' || $key === 'from_email') && is_string($value) && trim($value) === '') { |
| 343 | 521 | $wp = (string) get_option('admin_email', ''); |
| 344 | 522 | $value = $wp !== '' ? $wp : $value; |
| @@ -356,9 +534,18 @@ | ||
| 356 | 534 | // Ensure arrays are returned as arrays (not objects) |
| 357 | 535 | if (is_array($default_value) && !is_array($value)) { |
| 358 | 536 | $value = []; |
| 359 | 537 | } |
| 360 | - | |
| 538 | + | |
| 539 | + // Boolean settings must round-trip to the admin as real booleans. | |
| 540 | + // update_option() stores false as '' and the object cache can | |
| 541 | + // return boolean false, so without this a disabled toggle would | |
| 542 | + // reach React as '' / false and the checkbox (checked unless the | |
| 543 | + // value is strictly !== false) would render enabled again. | |
| 544 | + if (is_bool($default_value)) { | |
| 545 | + $value = filter_var($value, FILTER_VALIDATE_BOOLEAN); | |
| 546 | + } | |
| 547 | + | |
| 361 | 548 | $settings[$key] = $value; |
| 362 | 549 | } |
| 363 | 550 | |
| 364 | 551 | // Special handling for booking_form_config - always use getBookingFormConfig which handles locked fields |
| @@ -383,8 +570,10 @@ | ||
| 383 | 570 | 'scheduled_payment_days', |
| 384 | 571 | 'scheduled_payment_installments', |
| 385 | 572 | 'scheduled_payment_interval', |
| 386 | 573 | 'scheduled_payment_reminder_days', |
| 574 | + 'balance_anchor', | |
| 575 | + 'balance_due_days', | |
| 387 | 576 | ] as $sk |
| 388 | 577 | ) { |
| 389 | 578 | if (array_key_exists($sk, $this->default_settings)) { |
| 390 | 579 | $settings[$sk] = \Yatra\Services\SettingsService::get( |
| @@ -443,8 +632,10 @@ | ||
| 443 | 632 | 'scheduled_payment_days', |
| 444 | 633 | 'scheduled_payment_installments', |
| 445 | 634 | 'scheduled_payment_interval', |
| 446 | 635 | 'scheduled_payment_reminder_days', |
| 636 | + 'balance_anchor', | |
| 637 | + 'balance_due_days', | |
| 447 | 638 | ]; |
| 448 | 639 | |
| 449 | 640 | // Collect flexible payment settings to delegate to Pro |
| 450 | 641 | $flexible_payment_settings = []; |
| @@ -562,12 +753,78 @@ | ||
| 562 | 753 | if (!empty($updated)) { |
| 563 | 754 | \Yatra\Services\SettingsService::reload(); |
| 564 | 755 | } |
| 565 | 756 | |
| 566 | - return $this->success_response([ | |
| 757 | + // Cross-validation: booking-auth settings interact via OR | |
| 758 | + // logic in booking-content.php, so some combinations are | |
| 759 | + // semantically inconsistent or redundant. We don't block | |
| 760 | + // the save (the resulting state still has well-defined | |
| 761 | + // behavior), but we surface a clear notice so the operator | |
| 762 | + // understands what they just configured. | |
| 763 | + // | |
| 764 | + // require_login=true + allow_guest_checkout=true → | |
| 765 | + // require_login wins; allow_guest_checkout is a no-op. | |
| 766 | + // require_login=true + allow_guest_checkout=false → | |
| 767 | + // Strictest setting (login required, no guest path). | |
| 768 | + // Internally consistent. | |
| 769 | + // require_login=false + allow_guest_checkout=false → | |
| 770 | + // Guests blocked, logged-in users can book. Consistent. | |
| 771 | + // require_login=false + allow_guest_checkout=true → | |
| 772 | + // Default. Permissive. | |
| 773 | + $notices = []; | |
| 774 | + $effective_require_login = \array_key_exists('require_login', $data) | |
| 775 | + ? (bool) $data['require_login'] | |
| 776 | + : (bool) \Yatra\Services\SettingsService::get('require_login', false); | |
| 777 | + $effective_allow_guest = \array_key_exists('allow_guest_checkout', $data) | |
| 778 | + ? (bool) $data['allow_guest_checkout'] | |
| 779 | + : (bool) \Yatra\Services\SettingsService::get('allow_guest_checkout', true); | |
| 780 | + | |
| 781 | + if ($effective_require_login && $effective_allow_guest) { | |
| 782 | + $notices[] = [ | |
| 783 | + 'level' => 'warning', | |
| 784 | + 'code' => 'booking_auth_redundant', | |
| 785 | + 'message' => __( | |
| 786 | + 'Heads up: "Require login" is on, so "Allow guest checkout" has no effect — every customer will need to log in to book. To accept guests, turn "Require login" off.', | |
| 787 | + 'yatra' | |
| 788 | + ), | |
| 789 | + ]; | |
| 790 | + } | |
| 791 | + | |
| 792 | + // Scheduled Payments + guest checkout — incompatible at | |
| 793 | + // the gateway level. Scheduled charges require a saved | |
| 794 | + // payment-method tied to a customer record on the | |
| 795 | + // gateway side (Stripe Customer, etc.), which in turn | |
| 796 | + // requires a logged-in WP user. When both settings are | |
| 797 | + // on, the system gracefully skips installment creation | |
| 798 | + // for guest bookings — but operators expect them to | |
| 799 | + // work and only discover the gap when reconciling | |
| 800 | + // unpaid bookings weeks later. Surface this proactively. | |
| 801 | + $effective_scheduled_payments = \array_key_exists('enable_scheduled_payments', $data) | |
| 802 | + ? (bool) $data['enable_scheduled_payments'] | |
| 803 | + : (bool) \Yatra\Services\SettingsService::get('enable_scheduled_payments', false); | |
| 804 | + if ( | |
| 805 | + $effective_scheduled_payments | |
| 806 | + && $effective_allow_guest | |
| 807 | + && !$effective_require_login | |
| 808 | + ) { | |
| 809 | + $notices[] = [ | |
| 810 | + 'level' => 'info', | |
| 811 | + 'code' => 'scheduled_payments_guest_caveat', | |
| 812 | + 'message' => __( | |
| 813 | + 'Scheduled Payments is on with guest checkout allowed. Scheduled installments only run for bookings made by logged-in customers (they need a saved payment method tied to their account). Guest bookings will be charged in full at checkout instead. Turn on "Require login" if every booking must support installments.', | |
| 814 | + 'yatra' | |
| 815 | + ), | |
| 816 | + ]; | |
| 817 | + } | |
| 818 | + | |
| 819 | + $response = [ | |
| 567 | 820 | 'message' => 'Settings updated successfully', |
| 568 | 821 | 'updated' => $updated, |
| 569 | - ]); | |
| 822 | + ]; | |
| 823 | + if ($notices !== []) { | |
| 824 | + $response['notices'] = $notices; | |
| 825 | + } | |
| 826 | + return $this->success_response($response); | |
| 570 | 827 | } catch (\Exception $e) { |
| 571 | 828 | return $this->error_response($e->getMessage(), 500); |
| 572 | 829 | } |
| 573 | 830 | } |
| @@ -589,8 +846,19 @@ | ||
| 589 | 846 | if ($filtered_value !== null) { |
| 590 | 847 | return $filtered_value; |
| 591 | 848 | } |
| 592 | 849 | |
| 850 | + // The booking-form config has its own structured sanitiser (field type | |
| 851 | + // and width whitelists, locked core fields, text-block content, per-trip | |
| 852 | + // conditions). It must run BEFORE the generic | |
| 853 | + // is_array($default) branch below: that branch only text-sanitises | |
| 854 | + // values and was catching this key first — because its default is [] — | |
| 855 | + // so the structured sanitiser further down was never reached and any | |
| 856 | + // shape at all was stored. | |
| 857 | + if ($key === 'booking_form_config') { | |
| 858 | + return is_array($value) ? $this->sanitize_booking_form_config($value) : []; | |
| 859 | + } | |
| 860 | + | |
| 593 | 861 | // Handle null values - use default |
| 594 | 862 | if ($value === null) { |
| 595 | 863 | return $default; |
| 596 | 864 | } |
| @@ -636,12 +904,15 @@ | ||
| 636 | 904 | return null; |
| 637 | 905 | } |
| 638 | 906 | $int_value = (int) $value; |
| 639 | 907 | // Validate ranges for specific fields |
| 640 | - if ($key === 'cancellation_days' && $int_value < 0) { | |
| 908 | + if ($key === 'booking_expiry_hours' && $int_value < 0) { | |
| 641 | 909 | return null; |
| 642 | 910 | } |
| 643 | - if ($key === 'booking_expiry_hours' && $int_value < 0) { | |
| 911 | + // Storefront booking horizon: 1–36 months. Out of range is rejected | |
| 912 | + // (not clamped) so a bad write can never blank the calendar — the | |
| 913 | + // previously stored value, or the 12-month default, stays in force. | |
| 914 | + if ($key === 'availability_horizon_months' && ($int_value < 1 || $int_value > 36)) { | |
| 644 | 915 | return null; |
| 645 | 916 | } |
| 646 | 917 | if ($key === 'partial_payment_percentage' && ($int_value < 0 || $int_value > 100)) { |
| 647 | 918 | return null; |
| @@ -690,8 +961,17 @@ | ||
| 690 | 961 | $v = is_string($value) ? strtolower(trim($value)) : ''; |
| 691 | 962 | |
| 692 | 963 | return in_array($v, $allowed, true) ? $v : (is_string($default) ? $default : 'left'); |
| 693 | 964 | } |
| 965 | + if ($key === 'discount_stacking_mode') { | |
| 966 | + // Strict enum — any other value silently falls back to the | |
| 967 | + // backward-compatible default so a malformed POST cannot | |
| 968 | + // change pricing behavior unexpectedly. | |
| 969 | + $allowed = ['both', 'discount_only', 'dynamic_pricing_only', 'best_for_customer']; | |
| 970 | + $v = is_string($value) ? strtolower(trim($value)) : ''; | |
| 971 | + | |
| 972 | + return in_array($v, $allowed, true) ? $v : 'both'; | |
| 973 | + } | |
| 694 | 974 | // Special handling for specific fields |
| 695 | 975 | if ($key === 'company_email' || $key === 'admin_email' || $key === 'from_email' || $key === 'smtp_username') { |
| 696 | 976 | return sanitize_email($value); |
| 697 | 977 | } |
| @@ -697,11 +977,8 @@ | ||
| 697 | 977 | } |
| 698 | 978 | if ($key === 'company_website' || $key === 'company_logo' || $key === 'google_analytics' || $key === 'facebook_pixel') { |
| 699 | 979 | return esc_url_raw($value); |
| 700 | 980 | } |
| 701 | - if ($key === 'refund_policy' || $key === 'cancellation_policy') { | |
| 702 | - return sanitize_textarea_field($value); | |
| 703 | - } | |
| 704 | 981 | if ($key === 'seo_trip_meta_title') { |
| 705 | 982 | // Allow more characters for meta title, but strip HTML |
| 706 | 983 | return wp_strip_all_tags($value); |
| 707 | 984 | } |
| @@ -720,8 +997,18 @@ | ||
| 720 | 997 | return \Yatra\Utils\FrontendThemeCss::sanitizeContainerMaxWidthSetting( |
| 721 | 998 | is_string($value) ? $value : '' |
| 722 | 999 | ); |
| 723 | 1000 | } |
| 1001 | + if ($key === 'frontend_listing_card_layout') { | |
| 1002 | + $allowed = ['standard', 'compact_mobile', 'compact_all']; | |
| 1003 | + $v = is_string($value) ? strtolower(trim($value)) : ''; | |
| 1004 | + return in_array($v, $allowed, true) ? $v : 'standard'; | |
| 1005 | + } | |
| 1006 | + if ($key === 'auto_confirm_mode') { | |
| 1007 | + $allowed = ['none', 'online', 'all']; | |
| 1008 | + $v = is_string($value) ? strtolower(trim($value)) : ''; | |
| 1009 | + return in_array($v, $allowed, true) ? $v : 'online'; | |
| 1010 | + } | |
| 724 | 1011 | if (is_string($key) && strpos($key, 'email_tpl_') === 0 && substr($key, -5) === '_body') { |
| 725 | 1012 | return wp_kses_post((string) $value); |
| 726 | 1013 | } |
| 727 | 1014 | if (is_string($key) && strpos($key, 'email_tpl_') === 0 && substr($key, -8) === '_subject') { |
| @@ -737,15 +1024,8 @@ | ||
| 737 | 1024 | return $this->sanitize_gateway_configs($value); |
| 738 | 1025 | } |
| 739 | 1026 | return []; |
| 740 | 1027 | } |
| 741 | - if ($key === 'booking_form_config') { | |
| 742 | - // Handle nested array structure for booking form config | |
| 743 | - if (is_array($value)) { | |
| 744 | - return $this->sanitize_booking_form_config($value); | |
| 745 | - } | |
| 746 | - return []; | |
| 747 | - } | |
| 748 | 1028 | if ($key === 'tax_rates') { |
| 749 | 1029 | // Handle nested array structure for tax rates |
| 750 | 1030 | if (is_array($value)) { |
| 751 | 1031 | return $this->sanitize_tax_rates($value); |
| @@ -971,70 +1251,194 @@ | ||
| 971 | 1251 | private function sanitize_booking_form_config(array $config): array |
| 972 | 1252 | { |
| 973 | 1253 | $sanitized = []; |
| 974 | 1254 | $allowed_form_types = ['contact_form', 'emergency_contact_form', 'traveler_form']; |
| 975 | - $allowed_field_types = ['text', 'email', 'tel', 'date', 'select', 'country', 'textarea', 'checkbox', 'number']; | |
| 976 | - $allowed_widths = ['full', 'half', 'third']; | |
| 977 | - | |
| 1255 | + | |
| 978 | 1256 | foreach ($config as $form_type => $form_config) { |
| 979 | 1257 | if (!in_array($form_type, $allowed_form_types, true)) { |
| 980 | 1258 | continue; |
| 981 | 1259 | } |
| 982 | - | |
| 1260 | + | |
| 983 | 1261 | $sanitized[$form_type] = [ |
| 984 | 1262 | 'title' => isset($form_config['title']) ? sanitize_text_field($form_config['title']) : '', |
| 985 | 1263 | 'description' => isset($form_config['description']) ? sanitize_text_field($form_config['description']) : '', |
| 986 | 1264 | 'enabled' => isset($form_config['enabled']) ? (bool) $form_config['enabled'] : true, |
| 987 | - 'fields' => [], | |
| 1265 | + 'fields' => $this->sanitize_booking_form_fields($form_config['fields'] ?? null, $form_type), | |
| 988 | 1266 | ]; |
| 989 | - | |
| 990 | - if (!empty($form_config['fields']) && is_array($form_config['fields'])) { | |
| 991 | - foreach ($form_config['fields'] as $field) { | |
| 992 | - if (!is_array($field) || empty($field['id'])) { | |
| 993 | - continue; | |
| 1267 | + | |
| 1268 | + // Per-trip form conditions (Pro Dynamic Form Field): each condition | |
| 1269 | + // is a complete alternative version of this section — its own | |
| 1270 | + // title, description and field list — used on the trips it names. | |
| 1271 | + // Only persisted when there is at least one, so configs saved | |
| 1272 | + // without the feature stay byte-identical. | |
| 1273 | + $conditions = $this->sanitize_booking_form_conditions($form_config['conditions'] ?? null, $form_type); | |
| 1274 | + if ($conditions !== []) { | |
| 1275 | + $sanitized[$form_type]['conditions'] = $conditions; | |
| 1276 | + } | |
| 1277 | + } | |
| 1278 | + | |
| 1279 | + return apply_filters('yatra_save_booking_form_config', $sanitized, $config); | |
| 1280 | + } | |
| 1281 | + | |
| 1282 | + /** | |
| 1283 | + * Sanitise one section's field list (global fields or a condition's fields). | |
| 1284 | + * | |
| 1285 | + * @param mixed $fields | |
| 1286 | + * @return array<int, array<string, mixed>> | |
| 1287 | + */ | |
| 1288 | + private function sanitize_booking_form_fields($fields, string $form_type): array | |
| 1289 | + { | |
| 1290 | + $allowed_field_types = ['text', 'email', 'tel', 'date', 'select', 'country', 'textarea', 'checkbox', 'number', 'text_block']; | |
| 1291 | + $allowed_widths = ['full', 'half', 'third']; | |
| 1292 | + $sanitized = []; | |
| 1293 | + | |
| 1294 | + if (empty($fields) || !is_array($fields)) { | |
| 1295 | + return $sanitized; | |
| 1296 | + } | |
| 1297 | + | |
| 1298 | + foreach ($fields as $field) { | |
| 1299 | + if (!is_array($field) || empty($field['id'])) { | |
| 1300 | + continue; | |
| 1301 | + } | |
| 1302 | + | |
| 1303 | + $sanitized_field = [ | |
| 1304 | + 'id' => sanitize_key($field['id']), | |
| 1305 | + 'type' => in_array($field['type'] ?? 'text', $allowed_field_types, true) ? $field['type'] : 'text', | |
| 1306 | + 'label' => isset($field['label']) ? sanitize_text_field($field['label']) : '', | |
| 1307 | + 'placeholder' => isset($field['placeholder']) ? sanitize_text_field($field['placeholder']) : '', | |
| 1308 | + 'required' => isset($field['required']) ? (bool) $field['required'] : false, | |
| 1309 | + 'enabled' => isset($field['enabled']) ? (bool) $field['enabled'] : true, | |
| 1310 | + 'order' => isset($field['order']) ? (int) $field['order'] : 0, | |
| 1311 | + 'width' => in_array($field['width'] ?? 'full', $allowed_widths, true) ? ($field['width'] ?? 'full') : 'full', | |
| 1312 | + ]; | |
| 1313 | + | |
| 1314 | + // Only persist `locked` when set: every reader treats a missing key | |
| 1315 | + // as unlocked, and configs saved before this sanitiser ran never | |
| 1316 | + // carried a `locked => false`, so they stay byte-identical. | |
| 1317 | + if (!empty($field['locked'])) { | |
| 1318 | + $sanitized_field['locked'] = true; | |
| 1319 | + } | |
| 1320 | + | |
| 1321 | + // Handle optional section | |
| 1322 | + if (!empty($field['section'])) { | |
| 1323 | + $sanitized_field['section'] = sanitize_key($field['section']); | |
| 1324 | + } | |
| 1325 | + | |
| 1326 | + // Per-traveler targeting — Traveler section only. Whitelist | |
| 1327 | + // the allowed values; only persist the non-default "lead" so | |
| 1328 | + // other sections and existing configs stay byte-identical. | |
| 1329 | + if ( | |
| 1330 | + $form_type === 'traveler_form' | |
| 1331 | + && ($field['applies_to'] ?? 'all') === 'lead' | |
| 1332 | + ) { | |
| 1333 | + $sanitized_field['applies_to'] = 'lead'; | |
| 1334 | + } | |
| 1335 | + | |
| 1336 | + // Handle options for select fields | |
| 1337 | + if ($sanitized_field['type'] === 'select' && !empty($field['options']) && is_array($field['options'])) { | |
| 1338 | + $sanitized_field['options'] = []; | |
| 1339 | + foreach ($field['options'] as $option) { | |
| 1340 | + if (is_array($option) && isset($option['value'])) { | |
| 1341 | + $sanitized_field['options'][] = [ | |
| 1342 | + 'value' => sanitize_key($option['value']), | |
| 1343 | + 'label' => isset($option['label']) ? sanitize_text_field($option['label']) : $option['value'], | |
| 1344 | + ]; | |
| 994 | 1345 | } |
| 995 | - | |
| 996 | - $sanitized_field = [ | |
| 997 | - 'id' => sanitize_key($field['id']), | |
| 998 | - 'type' => in_array($field['type'] ?? 'text', $allowed_field_types, true) ? $field['type'] : 'text', | |
| 999 | - 'label' => isset($field['label']) ? sanitize_text_field($field['label']) : '', | |
| 1000 | - 'placeholder' => isset($field['placeholder']) ? sanitize_text_field($field['placeholder']) : '', | |
| 1001 | - 'required' => isset($field['required']) ? (bool) $field['required'] : false, | |
| 1002 | - 'enabled' => isset($field['enabled']) ? (bool) $field['enabled'] : true, | |
| 1003 | - 'order' => isset($field['order']) ? (int) $field['order'] : 0, | |
| 1004 | - 'width' => in_array($field['width'] ?? 'full', $allowed_widths, true) ? $field['width'] : 'full', | |
| 1005 | - 'locked' => isset($field['locked']) ? (bool) $field['locked'] : false, | |
| 1006 | - ]; | |
| 1007 | - | |
| 1008 | - // Handle optional section | |
| 1009 | - if (!empty($field['section'])) { | |
| 1010 | - $sanitized_field['section'] = sanitize_key($field['section']); | |
| 1346 | + } | |
| 1347 | + } | |
| 1348 | + | |
| 1349 | + // A text block is display-only content placed between fields: | |
| 1350 | + // keep its (safe-HTML) content, and it can never be required. | |
| 1351 | + if ($sanitized_field['type'] === 'text_block') { | |
| 1352 | + $sanitized_field['content'] = isset($field['content']) ? wp_kses_post($field['content']) : ''; | |
| 1353 | + $sanitized_field['required'] = false; | |
| 1354 | + } | |
| 1355 | + | |
| 1356 | + // Phone fields: the country-code selector is ON by default. | |
| 1357 | + // Only persist the non-default `false`, so existing configs | |
| 1358 | + // (which never carried this key) stay byte-identical and read | |
| 1359 | + // back as ON. | |
| 1360 | + if ( | |
| 1361 | + $sanitized_field['type'] === 'tel' | |
| 1362 | + && array_key_exists('show_country_code', $field) | |
| 1363 | + && !$field['show_country_code'] | |
| 1364 | + ) { | |
| 1365 | + $sanitized_field['show_country_code'] = false; | |
| 1366 | + } | |
| 1367 | + | |
| 1368 | + $sanitized[] = $sanitized_field; | |
| 1369 | + } | |
| 1370 | + | |
| 1371 | + // Sort fields by order | |
| 1372 | + usort($sanitized, function ($a, $b) { | |
| 1373 | + return ($a['order'] ?? 0) - ($b['order'] ?? 0); | |
| 1374 | + }); | |
| 1375 | + | |
| 1376 | + return $sanitized; | |
| 1377 | + } | |
| 1378 | + | |
| 1379 | + /** | |
| 1380 | + * Sanitise a section's per-trip conditions. A condition without any | |
| 1381 | + * target (trip, category or trip type) can never match and is dropped. | |
| 1382 | + * | |
| 1383 | + * @param mixed $conditions | |
| 1384 | + * @return array<int, array<string, mixed>> | |
| 1385 | + */ | |
| 1386 | + private function sanitize_booking_form_conditions($conditions, string $form_type): array | |
| 1387 | + { | |
| 1388 | + if (empty($conditions) || !is_array($conditions)) { | |
| 1389 | + return []; | |
| 1390 | + } | |
| 1391 | + | |
| 1392 | + $allowed_trip_types = ['single_day', 'multi_day', 'flexible']; | |
| 1393 | + $sanitized = []; | |
| 1394 | + $n = 0; | |
| 1395 | + | |
| 1396 | + foreach ($conditions as $condition) { | |
| 1397 | + if (!is_array($condition)) { | |
| 1398 | + continue; | |
| 1399 | + } | |
| 1400 | + $n++; | |
| 1401 | + | |
| 1402 | + $raw_targets = is_array($condition['targets'] ?? null) ? $condition['targets'] : []; | |
| 1403 | + $targets = []; | |
| 1404 | + foreach (['trips', 'categories'] as $selector) { | |
| 1405 | + $ids = array_values(array_unique(array_filter( | |
| 1406 | + array_map('intval', is_array($raw_targets[$selector] ?? null) ? $raw_targets[$selector] : []), | |
| 1407 | + static function ($id) { | |
| 1408 | + return $id > 0; | |
| 1011 | 1409 | } |
| 1012 | - | |
| 1013 | - // Handle options for select fields | |
| 1014 | - if ($sanitized_field['type'] === 'select' && !empty($field['options']) && is_array($field['options'])) { | |
| 1015 | - $sanitized_field['options'] = []; | |
| 1016 | - foreach ($field['options'] as $option) { | |
| 1017 | - if (is_array($option) && isset($option['value'])) { | |
| 1018 | - $sanitized_field['options'][] = [ | |
| 1019 | - 'value' => sanitize_key($option['value']), | |
| 1020 | - 'label' => isset($option['label']) ? sanitize_text_field($option['label']) : $option['value'], | |
| 1021 | - ]; | |
| 1022 | - } | |
| 1023 | - } | |
| 1024 | - } | |
| 1025 | - | |
| 1026 | - $sanitized[$form_type]['fields'][] = $sanitized_field; | |
| 1410 | + ))); | |
| 1411 | + if ($ids !== []) { | |
| 1412 | + $targets[$selector] = $ids; | |
| 1027 | 1413 | } |
| 1028 | - | |
| 1029 | - // Sort fields by order | |
| 1030 | - usort($sanitized[$form_type]['fields'], function($a, $b) { | |
| 1031 | - return ($a['order'] ?? 0) - ($b['order'] ?? 0); | |
| 1032 | - }); | |
| 1033 | 1414 | } |
| 1415 | + $types = array_values(array_unique(array_filter( | |
| 1416 | + array_map(static function ($t) { | |
| 1417 | + return sanitize_key((string) $t); | |
| 1418 | + }, is_array($raw_targets['trip_types'] ?? null) ? $raw_targets['trip_types'] : []), | |
| 1419 | + static function ($t) use ($allowed_trip_types) { | |
| 1420 | + return in_array($t, $allowed_trip_types, true); | |
| 1421 | + } | |
| 1422 | + ))); | |
| 1423 | + if ($types !== []) { | |
| 1424 | + $targets['trip_types'] = $types; | |
| 1425 | + } | |
| 1426 | + if ($targets === []) { | |
| 1427 | + continue; | |
| 1428 | + } | |
| 1429 | + | |
| 1430 | + $id = sanitize_key((string) ($condition['id'] ?? '')); | |
| 1431 | + $sanitized[] = [ | |
| 1432 | + 'id' => $id !== '' ? $id : 'condition_' . $n, | |
| 1433 | + 'targets' => $targets, | |
| 1434 | + 'title' => isset($condition['title']) ? sanitize_text_field($condition['title']) : '', | |
| 1435 | + 'description' => isset($condition['description']) ? sanitize_text_field($condition['description']) : '', | |
| 1436 | + 'fields' => $this->sanitize_booking_form_fields($condition['fields'] ?? null, $form_type), | |
| 1437 | + ]; | |
| 1034 | 1438 | } |
| 1035 | - | |
| 1036 | - return apply_filters('yatra_save_booking_form_config', $sanitized, $config); | |
| 1439 | + | |
| 1440 | + return $sanitized; | |
| 1037 | 1441 | } |
| 1038 | 1442 | |
| 1039 | 1443 | /** |
| 1040 | 1444 | * Flush rewrite rules |