woocommerce /
woocommerce-gateway-stripe
This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include, or for example
via PHP's auto-loading mechanism.
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
| 1 | <?php |
||
| 2 | if ( ! defined( 'ABSPATH' ) ) { |
||
| 3 | exit; |
||
| 4 | } |
||
| 5 | |||
| 6 | /** |
||
| 7 | * WC_Gateway_Stripe class. |
||
| 8 | * |
||
| 9 | * @extends WC_Payment_Gateway |
||
| 10 | */ |
||
| 11 | class WC_Gateway_Stripe extends WC_Stripe_Payment_Gateway { |
||
| 12 | /** |
||
| 13 | * The delay between retries. |
||
| 14 | * |
||
| 15 | * @var int |
||
| 16 | */ |
||
| 17 | public $retry_interval; |
||
| 18 | |||
| 19 | /** |
||
| 20 | * Should we capture Credit cards |
||
| 21 | * |
||
| 22 | * @var bool |
||
| 23 | */ |
||
| 24 | public $capture; |
||
| 25 | |||
| 26 | /** |
||
| 27 | * Alternate credit card statement name |
||
| 28 | * |
||
| 29 | * @var bool |
||
| 30 | */ |
||
| 31 | public $statement_descriptor; |
||
| 32 | |||
| 33 | /** |
||
| 34 | * Should we store the users credit cards? |
||
| 35 | * |
||
| 36 | * @var bool |
||
| 37 | */ |
||
| 38 | public $saved_cards; |
||
| 39 | |||
| 40 | /** |
||
| 41 | * API access secret key |
||
| 42 | * |
||
| 43 | * @var string |
||
| 44 | */ |
||
| 45 | public $secret_key; |
||
| 46 | |||
| 47 | /** |
||
| 48 | * Api access publishable key |
||
| 49 | * |
||
| 50 | * @var string |
||
| 51 | */ |
||
| 52 | public $publishable_key; |
||
| 53 | |||
| 54 | /** |
||
| 55 | * Do we accept Payment Request? |
||
| 56 | * |
||
| 57 | * @var bool |
||
| 58 | */ |
||
| 59 | public $payment_request; |
||
| 60 | |||
| 61 | /** |
||
| 62 | * Is test mode active? |
||
| 63 | * |
||
| 64 | * @var bool |
||
| 65 | */ |
||
| 66 | public $testmode; |
||
| 67 | |||
| 68 | /** |
||
| 69 | * Inline CC form styling |
||
| 70 | * |
||
| 71 | * @var string |
||
| 72 | */ |
||
| 73 | public $inline_cc_form; |
||
| 74 | |||
| 75 | /** |
||
| 76 | * Pre Orders Object |
||
| 77 | * |
||
| 78 | * @var object |
||
| 79 | */ |
||
| 80 | public $pre_orders; |
||
| 81 | |||
| 82 | /** |
||
| 83 | * Constructor |
||
| 84 | */ |
||
| 85 | public function __construct() { |
||
| 86 | $this->retry_interval = 1; |
||
| 87 | $this->id = 'stripe'; |
||
| 88 | $this->method_title = __( 'Stripe', 'woocommerce-gateway-stripe' ); |
||
| 89 | /* translators: 1) link to Stripe register page 2) link to Stripe api keys page */ |
||
| 90 | $this->method_description = __( 'Stripe works by adding payment fields on the checkout and then sending the details to Stripe for verification.', 'woocommerce-gateway-stripe' ); |
||
| 91 | $this->has_fields = true; |
||
| 92 | $this->supports = array( |
||
| 93 | 'products', |
||
| 94 | 'refunds', |
||
| 95 | 'tokenization', |
||
| 96 | 'add_payment_method', |
||
| 97 | 'subscriptions', |
||
| 98 | 'subscription_cancellation', |
||
| 99 | 'subscription_suspension', |
||
| 100 | 'subscription_reactivation', |
||
| 101 | 'subscription_amount_changes', |
||
| 102 | 'subscription_date_changes', |
||
| 103 | 'subscription_payment_method_change', |
||
| 104 | 'subscription_payment_method_change_customer', |
||
| 105 | 'subscription_payment_method_change_admin', |
||
| 106 | 'multiple_subscriptions', |
||
| 107 | 'pre-orders', |
||
| 108 | ); |
||
| 109 | |||
| 110 | // Load the form fields. |
||
| 111 | $this->init_form_fields(); |
||
| 112 | |||
| 113 | // Load the settings. |
||
| 114 | $this->init_settings(); |
||
| 115 | |||
| 116 | // Get setting values. |
||
| 117 | $this->title = $this->get_option( 'title' ); |
||
| 118 | $this->description = $this->get_option( 'description' ); |
||
| 119 | $this->enabled = $this->get_option( 'enabled' ); |
||
| 120 | $this->testmode = 'yes' === $this->get_option( 'testmode' ); |
||
| 121 | $this->inline_cc_form = 'yes' === $this->get_option( 'inline_cc_form' ); |
||
| 122 | $this->capture = 'yes' === $this->get_option( 'capture', 'yes' ); |
||
| 123 | $this->statement_descriptor = WC_Stripe_Helper::clean_statement_descriptor( $this->get_option( 'statement_descriptor' ) ); |
||
| 124 | $this->saved_cards = 'yes' === $this->get_option( 'saved_cards' ); |
||
| 125 | $this->secret_key = $this->testmode ? $this->get_option( 'test_secret_key' ) : $this->get_option( 'secret_key' ); |
||
| 126 | $this->publishable_key = $this->testmode ? $this->get_option( 'test_publishable_key' ) : $this->get_option( 'publishable_key' ); |
||
| 127 | $this->payment_request = 'yes' === $this->get_option( 'payment_request', 'yes' ); |
||
| 128 | |||
| 129 | WC_Stripe_API::set_secret_key( $this->secret_key ); |
||
| 130 | |||
| 131 | // Hooks. |
||
| 132 | add_action( 'wp_enqueue_scripts', array( $this, 'payment_scripts' ) ); |
||
| 133 | add_action( 'admin_enqueue_scripts', array( $this, 'admin_scripts' ) ); |
||
| 134 | add_action( 'woocommerce_update_options_payment_gateways_' . $this->id, array( $this, 'process_admin_options' ) ); |
||
| 135 | add_action( 'woocommerce_admin_order_totals_after_total', array( $this, 'display_order_fee' ) ); |
||
| 136 | add_action( 'woocommerce_admin_order_totals_after_total', array( $this, 'display_order_payout' ), 20 ); |
||
| 137 | add_action( 'woocommerce_customer_save_address', array( $this, 'show_update_card_notice' ), 10, 2 ); |
||
| 138 | add_filter( 'woocommerce_available_payment_gateways', array( $this, 'prepare_order_pay_page' ) ); |
||
| 139 | add_action( 'woocommerce_account_view-order_endpoint', array( $this, 'check_intent_status_on_order_page' ), 1 ); |
||
| 140 | add_filter( 'woocommerce_payment_successful_result', array( $this, 'modify_successful_payment_result' ), 99999, 2 ); |
||
| 141 | add_action( 'set_logged_in_cookie', array( $this, 'set_cookie_on_current_request' ) ); |
||
| 142 | add_filter( 'woocommerce_get_checkout_payment_url', array( $this, 'get_checkout_payment_url' ), 10, 2 ); |
||
| 143 | |||
| 144 | // Note: display error is in the parent class. |
||
| 145 | add_action( 'admin_notices', array( $this, 'display_errors' ), 9999 ); |
||
| 146 | |||
| 147 | View Code Duplication | if ( WC_Stripe_Helper::is_pre_orders_exists() ) { |
|
| 148 | $this->pre_orders = new WC_Stripe_Pre_Orders_Compat(); |
||
| 149 | |||
| 150 | add_action( 'wc_pre_orders_process_pre_order_completion_payment_' . $this->id, array( $this->pre_orders, 'process_pre_order_release_payment' ) ); |
||
| 151 | } |
||
| 152 | } |
||
| 153 | |||
| 154 | /** |
||
| 155 | * Checks if gateway should be available to use. |
||
| 156 | * |
||
| 157 | * @since 4.0.2 |
||
| 158 | */ |
||
| 159 | public function is_available() { |
||
| 160 | if ( is_add_payment_method_page() && ! $this->saved_cards ) { |
||
| 161 | return false; |
||
| 162 | } |
||
| 163 | |||
| 164 | return parent::is_available(); |
||
| 165 | } |
||
| 166 | |||
| 167 | /** |
||
| 168 | * Adds a notice for customer when they update their billing address. |
||
| 169 | * |
||
| 170 | * @since 4.1.0 |
||
| 171 | * @param int $user_id The ID of the current user. |
||
| 172 | * @param string $load_address The address to load. |
||
| 173 | */ |
||
| 174 | public function show_update_card_notice( $user_id, $load_address ) { |
||
| 175 | if ( ! $this->saved_cards || ! WC_Stripe_Payment_Tokens::customer_has_saved_methods( $user_id ) || 'billing' !== $load_address ) { |
||
| 176 | return; |
||
| 177 | } |
||
| 178 | |||
| 179 | /* translators: 1) Opening anchor tag 2) closing anchor tag */ |
||
| 180 | wc_add_notice( sprintf( __( 'If your billing address has been changed for saved payment methods, be sure to remove any %1$ssaved payment methods%2$s on file and re-add them.', 'woocommerce-gateway-stripe' ), '<a href="' . esc_url( wc_get_endpoint_url( 'payment-methods' ) ) . '" class="wc-stripe-update-card-notice" style="text-decoration:underline;">', '</a>' ), 'notice' ); |
||
| 181 | } |
||
| 182 | |||
| 183 | /** |
||
| 184 | * Get_icon function. |
||
| 185 | * |
||
| 186 | * @since 1.0.0 |
||
| 187 | * @version 4.0.0 |
||
| 188 | * @return string |
||
| 189 | */ |
||
| 190 | public function get_icon() { |
||
| 191 | $icons = $this->payment_icons(); |
||
| 192 | |||
| 193 | $icons_str = ''; |
||
| 194 | |||
| 195 | $icons_str .= isset( $icons['visa'] ) ? $icons['visa'] : ''; |
||
| 196 | $icons_str .= isset( $icons['amex'] ) ? $icons['amex'] : ''; |
||
| 197 | $icons_str .= isset( $icons['mastercard'] ) ? $icons['mastercard'] : ''; |
||
| 198 | |||
| 199 | if ( 'USD' === get_woocommerce_currency() ) { |
||
| 200 | $icons_str .= isset( $icons['discover'] ) ? $icons['discover'] : ''; |
||
| 201 | $icons_str .= isset( $icons['jcb'] ) ? $icons['jcb'] : ''; |
||
| 202 | $icons_str .= isset( $icons['diners'] ) ? $icons['diners'] : ''; |
||
| 203 | } |
||
| 204 | |||
| 205 | return apply_filters( 'woocommerce_gateway_icon', $icons_str, $this->id ); |
||
| 206 | } |
||
| 207 | |||
| 208 | /** |
||
| 209 | * Initialise Gateway Settings Form Fields |
||
| 210 | */ |
||
| 211 | public function init_form_fields() { |
||
| 212 | $this->form_fields = require( dirname( __FILE__ ) . '/admin/stripe-settings.php' ); |
||
| 213 | } |
||
| 214 | |||
| 215 | /** |
||
| 216 | * Payment form on checkout page |
||
| 217 | */ |
||
| 218 | public function payment_fields() { |
||
| 219 | global $wp; |
||
| 220 | $user = wp_get_current_user(); |
||
| 221 | $display_tokenization = $this->supports( 'tokenization' ) && is_checkout() && $this->saved_cards; |
||
| 222 | $total = WC()->cart->total; |
||
| 223 | $user_email = ''; |
||
| 224 | $description = $this->get_description(); |
||
| 225 | $description = ! empty( $description ) ? $description : ''; |
||
| 226 | $firstname = ''; |
||
| 227 | $lastname = ''; |
||
| 228 | |||
| 229 | // If paying from order, we need to get total from order not cart. |
||
| 230 | if ( isset( $_GET['pay_for_order'] ) && ! empty( $_GET['key'] ) ) { // wpcs: csrf ok. |
||
| 231 | $order = wc_get_order( wc_clean( $wp->query_vars['order-pay'] ) ); // wpcs: csrf ok, sanitization ok. |
||
| 232 | $total = $order->get_total(); |
||
| 233 | $user_email = $order->get_billing_email(); |
||
| 234 | } else { |
||
| 235 | if ( $user->ID ) { |
||
| 236 | $user_email = get_user_meta( $user->ID, 'billing_email', true ); |
||
| 237 | $user_email = $user_email ? $user_email : $user->user_email; |
||
| 238 | } |
||
| 239 | } |
||
| 240 | |||
| 241 | if ( is_add_payment_method_page() ) { |
||
| 242 | $firstname = $user->user_firstname; |
||
| 243 | $lastname = $user->user_lastname; |
||
| 244 | } |
||
| 245 | |||
| 246 | ob_start(); |
||
| 247 | |||
| 248 | echo '<div |
||
| 249 | id="stripe-payment-data" |
||
| 250 | data-email="' . esc_attr( $user_email ) . '" |
||
| 251 | data-full-name="' . esc_attr( $firstname . ' ' . $lastname ) . '" |
||
| 252 | data-currency="' . esc_attr( strtolower( get_woocommerce_currency() ) ) . '" |
||
| 253 | >'; |
||
| 254 | |||
| 255 | if ( $this->testmode ) { |
||
| 256 | /* translators: link to Stripe testing page */ |
||
| 257 | $description .= ' ' . sprintf( __( 'TEST MODE ENABLED. In test mode, you can use the card number 4242424242424242 with any CVC and a valid expiration date or check the <a href="%s" target="_blank">Testing Stripe documentation</a> for more card numbers.', 'woocommerce-gateway-stripe' ), 'https://stripe.com/docs/testing' ); |
||
| 258 | } |
||
| 259 | |||
| 260 | $description = trim( $description ); |
||
| 261 | |||
| 262 | echo apply_filters( 'wc_stripe_description', wpautop( wp_kses_post( $description ) ), $this->id ); // wpcs: xss ok. |
||
| 263 | |||
| 264 | if ( $display_tokenization ) { |
||
| 265 | $this->tokenization_script(); |
||
| 266 | $this->saved_payment_methods(); |
||
| 267 | } |
||
| 268 | |||
| 269 | $this->elements_form(); |
||
| 270 | |||
| 271 | View Code Duplication | if ( apply_filters( 'wc_stripe_display_save_payment_method_checkbox', $display_tokenization ) && ! is_add_payment_method_page() && ! isset( $_GET['change_payment_method'] ) ) { // wpcs: csrf ok. |
|
| 272 | |||
| 273 | $this->save_payment_method_checkbox(); |
||
| 274 | } |
||
| 275 | |||
| 276 | do_action( 'wc_stripe_cards_payment_fields', $this->id ); |
||
| 277 | |||
| 278 | echo '</div>'; |
||
| 279 | |||
| 280 | ob_end_flush(); |
||
| 281 | } |
||
| 282 | |||
| 283 | /** |
||
| 284 | * Renders the Stripe elements form. |
||
| 285 | * |
||
| 286 | * @since 4.0.0 |
||
| 287 | * @version 4.0.0 |
||
| 288 | */ |
||
| 289 | public function elements_form() { |
||
| 290 | ?> |
||
| 291 | <fieldset id="wc-<?php echo esc_attr( $this->id ); ?>-cc-form" class="wc-credit-card-form wc-payment-form" style="background:transparent;"> |
||
| 292 | <?php do_action( 'woocommerce_credit_card_form_start', $this->id ); ?> |
||
| 293 | |||
| 294 | <?php if ( $this->inline_cc_form ) { ?> |
||
| 295 | <label for="card-element"> |
||
| 296 | <?php esc_html_e( 'Credit or debit card', 'woocommerce-gateway-stripe' ); ?> |
||
| 297 | </label> |
||
| 298 | |||
| 299 | <div id="stripe-card-element" class="wc-stripe-elements-field"> |
||
| 300 | <!-- a Stripe Element will be inserted here. --> |
||
| 301 | </div> |
||
| 302 | <?php } else { ?> |
||
| 303 | <div class="form-row form-row-wide"> |
||
| 304 | <label for="stripe-card-element"><?php esc_html_e( 'Card Number', 'woocommerce-gateway-stripe' ); ?> <span class="required">*</span></label> |
||
| 305 | <div class="stripe-card-group"> |
||
| 306 | <div id="stripe-card-element" class="wc-stripe-elements-field"> |
||
| 307 | <!-- a Stripe Element will be inserted here. --> |
||
| 308 | </div> |
||
| 309 | |||
| 310 | <i class="stripe-credit-card-brand stripe-card-brand" alt="Credit Card"></i> |
||
| 311 | </div> |
||
| 312 | </div> |
||
| 313 | |||
| 314 | <div class="form-row form-row-first"> |
||
| 315 | <label for="stripe-exp-element"><?php esc_html_e( 'Expiry Date', 'woocommerce-gateway-stripe' ); ?> <span class="required">*</span></label> |
||
| 316 | |||
| 317 | <div id="stripe-exp-element" class="wc-stripe-elements-field"> |
||
| 318 | <!-- a Stripe Element will be inserted here. --> |
||
| 319 | </div> |
||
| 320 | </div> |
||
| 321 | |||
| 322 | <div class="form-row form-row-last"> |
||
| 323 | <label for="stripe-cvc-element"><?php esc_html_e( 'Card Code (CVC)', 'woocommerce-gateway-stripe' ); ?> <span class="required">*</span></label> |
||
| 324 | <div id="stripe-cvc-element" class="wc-stripe-elements-field"> |
||
| 325 | <!-- a Stripe Element will be inserted here. --> |
||
| 326 | </div> |
||
| 327 | </div> |
||
| 328 | <div class="clear"></div> |
||
| 329 | <?php } ?> |
||
| 330 | |||
| 331 | <!-- Used to display form errors --> |
||
| 332 | <div class="stripe-source-errors" role="alert"></div> |
||
| 333 | <br /> |
||
| 334 | <?php do_action( 'woocommerce_credit_card_form_end', $this->id ); ?> |
||
| 335 | <div class="clear"></div> |
||
| 336 | </fieldset> |
||
| 337 | <?php |
||
| 338 | } |
||
| 339 | |||
| 340 | /** |
||
| 341 | * Load admin scripts. |
||
| 342 | * |
||
| 343 | * @since 3.1.0 |
||
| 344 | * @version 3.1.0 |
||
| 345 | */ |
||
| 346 | public function admin_scripts() { |
||
| 347 | if ( 'woocommerce_page_wc-settings' !== get_current_screen()->id ) { |
||
| 348 | return; |
||
| 349 | } |
||
| 350 | |||
| 351 | $suffix = defined( 'SCRIPT_DEBUG' ) && SCRIPT_DEBUG ? '' : '.min'; |
||
| 352 | |||
| 353 | wp_enqueue_script( 'woocommerce_stripe_admin', plugins_url( 'assets/js/stripe-admin' . $suffix . '.js', WC_STRIPE_MAIN_FILE ), array(), WC_STRIPE_VERSION, true ); |
||
| 354 | } |
||
| 355 | |||
| 356 | /** |
||
| 357 | * Payment_scripts function. |
||
| 358 | * |
||
| 359 | * Outputs scripts used for stripe payment |
||
| 360 | * |
||
| 361 | * @since 3.1.0 |
||
| 362 | * @version 4.0.0 |
||
| 363 | */ |
||
| 364 | public function payment_scripts() { |
||
| 365 | global $wp; |
||
| 366 | if ( |
||
| 367 | ! is_product() |
||
| 368 | && ! is_cart() |
||
| 369 | && ! is_checkout() |
||
| 370 | && ! isset( $_GET['pay_for_order'] ) // wpcs: csrf ok. |
||
| 371 | && ! is_add_payment_method_page() |
||
| 372 | && ! isset( $_GET['change_payment_method'] ) // wpcs: csrf ok. |
||
| 373 | && ! ( ! empty( get_query_var( 'view-subscription' ) ) && is_callable( 'WCS_Early_Renewal_Manager::is_early_renewal_via_modal_enabled' ) && WCS_Early_Renewal_Manager::is_early_renewal_via_modal_enabled() ) |
||
| 374 | || ( is_order_received_page() ) |
||
| 375 | ) { |
||
| 376 | return; |
||
| 377 | } |
||
| 378 | |||
| 379 | // If Stripe is not enabled bail. |
||
| 380 | if ( 'no' === $this->enabled ) { |
||
| 381 | return; |
||
| 382 | } |
||
| 383 | |||
| 384 | // If keys are not set bail. |
||
| 385 | if ( ! $this->are_keys_set() ) { |
||
| 386 | WC_Stripe_Logger::log( 'Keys are not set correctly.' ); |
||
| 387 | return; |
||
| 388 | } |
||
| 389 | |||
| 390 | // If no SSL bail. |
||
| 391 | if ( ! $this->testmode && ! is_ssl() ) { |
||
| 392 | WC_Stripe_Logger::log( 'Stripe live mode requires SSL.' ); |
||
| 393 | return; |
||
| 394 | } |
||
| 395 | |||
| 396 | $current_theme = wp_get_theme(); |
||
| 397 | |||
| 398 | $suffix = defined( 'SCRIPT_DEBUG' ) && SCRIPT_DEBUG ? '' : '.min'; |
||
| 399 | |||
| 400 | wp_register_style( 'stripe_styles', plugins_url( 'assets/css/stripe-styles.css', WC_STRIPE_MAIN_FILE ), array(), WC_STRIPE_VERSION ); |
||
| 401 | wp_enqueue_style( 'stripe_styles' ); |
||
| 402 | |||
| 403 | wp_register_script( 'stripe', 'https://js.stripe.com/v3/', '', '3.0', true ); |
||
| 404 | wp_register_script( 'woocommerce_stripe', plugins_url( 'assets/js/stripe' . $suffix . '.js', WC_STRIPE_MAIN_FILE ), array( 'jquery-payment', 'stripe' ), WC_STRIPE_VERSION, true ); |
||
| 405 | |||
| 406 | $stripe_params = array( |
||
| 407 | 'key' => $this->publishable_key, |
||
| 408 | 'i18n_terms' => __( 'Please accept the terms and conditions first', 'woocommerce-gateway-stripe' ), |
||
| 409 | 'i18n_required_fields' => __( 'Please fill in required checkout fields first', 'woocommerce-gateway-stripe' ), |
||
| 410 | ); |
||
| 411 | |||
| 412 | // If we're on the pay page we need to pass stripe.js the address of the order. |
||
| 413 | if ( isset( $_GET['pay_for_order'] ) && 'true' === $_GET['pay_for_order'] ) { // wpcs: csrf ok. |
||
| 414 | $order_id = wc_clean( $wp->query_vars['order-pay'] ); // wpcs: csrf ok, sanitization ok, xss ok. |
||
| 415 | $order = wc_get_order( $order_id ); |
||
| 416 | |||
| 417 | if ( is_a( $order, 'WC_Order' ) ) { |
||
| 418 | $stripe_params['billing_first_name'] = $order->get_billing_first_name(); |
||
| 419 | $stripe_params['billing_last_name'] = $order->get_billing_last_name(); |
||
| 420 | $stripe_params['billing_address_1'] = $order->get_billing_address_1(); |
||
| 421 | $stripe_params['billing_address_2'] = $order->get_billing_address_2(); |
||
| 422 | $stripe_params['billing_state'] = $order->get_billing_state(); |
||
| 423 | $stripe_params['billing_city'] = $order->get_billing_city(); |
||
| 424 | $stripe_params['billing_postcode'] = $order->get_billing_postcode(); |
||
| 425 | $stripe_params['billing_country'] = $order->get_billing_country(); |
||
| 426 | } |
||
| 427 | } |
||
| 428 | |||
| 429 | $sepa_elements_options = apply_filters( |
||
| 430 | 'wc_stripe_sepa_elements_options', |
||
| 431 | array( |
||
| 432 | 'supportedCountries' => array( 'SEPA' ), |
||
| 433 | 'placeholderCountry' => WC()->countries->get_base_country(), |
||
| 434 | 'style' => array( 'base' => array( 'fontSize' => '15px' ) ), |
||
| 435 | ) |
||
| 436 | ); |
||
| 437 | |||
| 438 | $stripe_params['no_prepaid_card_msg'] = __( 'Sorry, we\'re not accepting prepaid cards at this time. Your credit card has not been charged. Please try with alternative payment method.', 'woocommerce-gateway-stripe' ); |
||
| 439 | $stripe_params['no_sepa_owner_msg'] = __( 'Please enter your IBAN account name.', 'woocommerce-gateway-stripe' ); |
||
| 440 | $stripe_params['no_sepa_iban_msg'] = __( 'Please enter your IBAN account number.', 'woocommerce-gateway-stripe' ); |
||
| 441 | $stripe_params['payment_intent_error'] = __( 'We couldn\'t initiate the payment. Please try again.', 'woocommerce-gateway-stripe' ); |
||
| 442 | $stripe_params['sepa_mandate_notification'] = apply_filters( 'wc_stripe_sepa_mandate_notification', 'email' ); |
||
| 443 | $stripe_params['allow_prepaid_card'] = apply_filters( 'wc_stripe_allow_prepaid_card', true ) ? 'yes' : 'no'; |
||
| 444 | $stripe_params['inline_cc_form'] = $this->inline_cc_form ? 'yes' : 'no'; |
||
| 445 | $stripe_params['is_checkout'] = ( is_checkout() && empty( $_GET['pay_for_order'] ) ) ? 'yes' : 'no'; // wpcs: csrf ok. |
||
| 446 | $stripe_params['return_url'] = $this->get_stripe_return_url(); |
||
| 447 | $stripe_params['ajaxurl'] = WC_AJAX::get_endpoint( '%%endpoint%%' ); |
||
| 448 | $stripe_params['stripe_nonce'] = wp_create_nonce( '_wc_stripe_nonce' ); |
||
| 449 | $stripe_params['statement_descriptor'] = $this->statement_descriptor; |
||
| 450 | $stripe_params['elements_options'] = apply_filters( 'wc_stripe_elements_options', array() ); |
||
| 451 | $stripe_params['sepa_elements_options'] = $sepa_elements_options; |
||
| 452 | $stripe_params['invalid_owner_name'] = __( 'Billing First Name and Last Name are required.', 'woocommerce-gateway-stripe' ); |
||
| 453 | $stripe_params['is_change_payment_page'] = isset( $_GET['change_payment_method'] ) ? 'yes' : 'no'; // wpcs: csrf ok. |
||
| 454 | $stripe_params['is_add_payment_page'] = is_wc_endpoint_url( 'add-payment-method' ) ? 'yes' : 'no'; |
||
| 455 | $stripe_params['is_pay_for_order_page'] = is_wc_endpoint_url( 'order-pay' ) ? 'yes' : 'no'; |
||
| 456 | $stripe_params['elements_styling'] = apply_filters( 'wc_stripe_elements_styling', false ); |
||
| 457 | $stripe_params['elements_classes'] = apply_filters( 'wc_stripe_elements_classes', false ); |
||
| 458 | $stripe_params['add_card_nonce'] = wp_create_nonce( 'wc_stripe_create_si' ); |
||
| 459 | |||
| 460 | // Merge localized messages to be use in JS. |
||
| 461 | $stripe_params = array_merge( $stripe_params, WC_Stripe_Helper::get_localized_messages() ); |
||
| 462 | |||
| 463 | wp_localize_script( 'woocommerce_stripe', 'wc_stripe_params', apply_filters( 'wc_stripe_params', $stripe_params ) ); |
||
| 464 | |||
| 465 | $this->tokenization_script(); |
||
| 466 | wp_enqueue_script( 'woocommerce_stripe' ); |
||
| 467 | } |
||
| 468 | |||
| 469 | /** |
||
| 470 | * Checks if a source object represents a prepaid credit card and |
||
| 471 | * throws an exception if it is one, but that is not allowed. |
||
| 472 | * |
||
| 473 | * @since 4.2.0 |
||
| 474 | * @param object $prepared_source The object with source details. |
||
| 475 | * @throws WC_Stripe_Exception An exception if the card is prepaid, but prepaid cards are not allowed. |
||
| 476 | */ |
||
| 477 | public function maybe_disallow_prepaid_card( $prepared_source ) { |
||
| 478 | // Check if we don't allow prepaid credit cards. |
||
| 479 | if ( apply_filters( 'wc_stripe_allow_prepaid_card', true ) || ! $this->is_prepaid_card( $prepared_source->source_object ) ) { |
||
| 480 | return; |
||
| 481 | } |
||
| 482 | |||
| 483 | $localized_message = __( 'Sorry, we\'re not accepting prepaid cards at this time. Your credit card has not been charged. Please try with alternative payment method.', 'woocommerce-gateway-stripe' ); |
||
| 484 | throw new WC_Stripe_Exception( print_r( $prepared_source->source_object, true ), $localized_message ); |
||
| 485 | } |
||
| 486 | |||
| 487 | /** |
||
| 488 | * Checks whether a source exists. |
||
| 489 | * |
||
| 490 | * @since 4.2.0 |
||
| 491 | * @param object $prepared_source The source that should be verified. |
||
| 492 | * @throws WC_Stripe_Exception An exception if the source ID is missing. |
||
| 493 | */ |
||
| 494 | public function check_source( $prepared_source ) { |
||
| 495 | View Code Duplication | if ( empty( $prepared_source->source ) ) { |
|
| 496 | $localized_message = __( 'Payment processing failed. Please retry.', 'woocommerce-gateway-stripe' ); |
||
| 497 | throw new WC_Stripe_Exception( print_r( $prepared_source, true ), $localized_message ); |
||
| 498 | } |
||
| 499 | } |
||
| 500 | |||
| 501 | /** |
||
| 502 | * Customer param wrong? The user may have been deleted on stripe's end. Remove customer_id. Can be retried without. |
||
| 503 | * |
||
| 504 | * @since 4.2.0 |
||
| 505 | * @param object $error The error that was returned from Stripe's API. |
||
| 506 | * @param WC_Order $order The order those payment is being processed. |
||
| 507 | * @return bool A flag that indicates that the customer does not exist and should be removed. |
||
| 508 | */ |
||
| 509 | public function maybe_remove_non_existent_customer( $error, $order ) { |
||
| 510 | if ( ! $this->is_no_such_customer_error( $error ) ) { |
||
| 511 | return false; |
||
| 512 | } |
||
| 513 | |||
| 514 | delete_user_option( $order->get_customer_id(), '_stripe_customer_id' ); |
||
| 515 | $order->delete_meta_data( '_stripe_customer_id' ); |
||
| 516 | $order->save(); |
||
| 517 | |||
| 518 | return true; |
||
| 519 | } |
||
| 520 | |||
| 521 | /** |
||
| 522 | * Completes an order without a positive value. |
||
| 523 | * |
||
| 524 | * @since 4.2.0 |
||
| 525 | * @param WC_Order $order The order to complete. |
||
| 526 | * @param WC_Order $prepared_source Payment source and customer data. |
||
| 527 | * @param boolean $force_save_source Whether the payment source must be saved, like when dealing with a Subscription setup. |
||
| 528 | * @return array Redirection data for `process_payment`. |
||
| 529 | */ |
||
| 530 | public function complete_free_order( $order, $prepared_source, $force_save_source ) { |
||
| 531 | if ( $force_save_source ) { |
||
| 532 | $intent_secret = $this->setup_intent( $order, $prepared_source ); |
||
| 533 | |||
| 534 | if ( ! empty( $intent_secret ) ) { |
||
| 535 | // `get_return_url()` must be called immediately before returning a value. |
||
| 536 | return array( |
||
| 537 | 'result' => 'success', |
||
| 538 | 'redirect' => $this->get_return_url( $order ), |
||
| 539 | 'setup_intent_secret' => $intent_secret, |
||
| 540 | ); |
||
| 541 | } |
||
| 542 | } |
||
| 543 | |||
| 544 | // Remove cart. |
||
| 545 | WC()->cart->empty_cart(); |
||
| 546 | |||
| 547 | $order->payment_complete(); |
||
| 548 | |||
| 549 | // Return thank you page redirect. |
||
| 550 | return array( |
||
| 551 | 'result' => 'success', |
||
| 552 | 'redirect' => $this->get_return_url( $order ), |
||
| 553 | ); |
||
| 554 | } |
||
| 555 | |||
| 556 | /** |
||
| 557 | * Process the payment |
||
| 558 | * |
||
| 559 | * @since 1.0.0 |
||
| 560 | * @since 4.1.0 Add 4th parameter to track previous error. |
||
| 561 | * @param int $order_id Reference. |
||
| 562 | * @param bool $retry Should we retry on fail. |
||
| 563 | * @param bool $force_save_source Force save the payment source. |
||
| 564 | * @param mix $previous_error Any error message from previous request. |
||
| 565 | * @param bool $use_order_source Whether to use the source, which should already be attached to the order. |
||
| 566 | * |
||
| 567 | * @throws Exception If payment will not be accepted. |
||
| 568 | * @return array|void |
||
| 569 | */ |
||
| 570 | public function process_payment( $order_id, $retry = true, $force_save_source = false, $previous_error = false, $use_order_source = false ) { |
||
| 571 | try { |
||
| 572 | $order = wc_get_order( $order_id ); |
||
| 573 | |||
| 574 | // ToDo: `process_pre_order` saves the source to the order for a later payment. |
||
| 575 | // This might not work well with PaymentIntents. |
||
| 576 | if ( $this->maybe_process_pre_orders( $order_id ) ) { |
||
| 577 | return $this->pre_orders->process_pre_order( $order_id ); |
||
| 578 | } |
||
| 579 | |||
| 580 | // Check whether there is an existing intent. |
||
| 581 | $intent = $this->get_intent_from_order( $order ); |
||
| 582 | if ( isset( $intent->object ) && 'setup_intent' === $intent->object ) { |
||
| 583 | $intent = false; // This function can only deal with *payment* intents |
||
| 584 | } |
||
| 585 | |||
| 586 | $stripe_customer_id = null; |
||
| 587 | if ( $intent && ! empty( $intent->customer ) ) { |
||
| 588 | $stripe_customer_id = $intent->customer; |
||
| 589 | } |
||
| 590 | |||
| 591 | // For some payments the source should already be present in the order. |
||
| 592 | if ( $use_order_source ) { |
||
| 593 | $prepared_source = $this->prepare_order_source( $order ); |
||
| 594 | } else { |
||
| 595 | $prepared_source = $this->prepare_source( get_current_user_id(), $force_save_source, $stripe_customer_id ); |
||
| 596 | } |
||
| 597 | |||
| 598 | $this->maybe_disallow_prepaid_card( $prepared_source ); |
||
| 599 | $this->check_source( $prepared_source ); |
||
| 600 | $this->save_source_to_order( $order, $prepared_source ); |
||
| 601 | |||
| 602 | if ( 0 >= $order->get_total() ) { |
||
| 603 | return $this->complete_free_order( $order, $prepared_source, $force_save_source ); |
||
| 604 | } |
||
| 605 | |||
| 606 | // This will throw exception if not valid. |
||
| 607 | $this->validate_minimum_order_amount( $order ); |
||
| 608 | |||
| 609 | WC_Stripe_Logger::log( "Info: Begin processing payment for order $order_id for the amount of {$order->get_total()}" ); |
||
| 610 | |||
| 611 | if ( $intent ) { |
||
| 612 | $intent = $this->update_existing_intent( $intent, $order, $prepared_source ); |
||
| 613 | } else { |
||
| 614 | $intent = $this->create_intent( $order, $prepared_source ); |
||
| 615 | } |
||
| 616 | |||
| 617 | // Confirm the intent after locking the order to make sure webhooks will not interfere. |
||
| 618 | if ( empty( $intent->error ) ) { |
||
| 619 | $this->lock_order_payment( $order, $intent ); |
||
| 620 | $intent = $this->confirm_intent( $intent, $order, $prepared_source ); |
||
| 621 | } |
||
| 622 | |||
| 623 | if ( ! empty( $intent->error ) ) { |
||
| 624 | $this->maybe_remove_non_existent_customer( $intent->error, $order ); |
||
| 625 | |||
| 626 | // We want to retry. |
||
| 627 | if ( $this->is_retryable_error( $intent->error ) ) { |
||
| 628 | return $this->retry_after_error( $intent, $order, $retry, $force_save_source, $previous_error, $use_order_source ); |
||
| 629 | } |
||
| 630 | |||
| 631 | $this->unlock_order_payment( $order ); |
||
| 632 | $this->throw_localized_message( $intent, $order ); |
||
| 633 | } |
||
| 634 | |||
| 635 | if ( ! empty( $intent ) ) { |
||
| 636 | // Use the last charge within the intent to proceed. |
||
| 637 | $response = end( $intent->charges->data ); |
||
| 638 | |||
| 639 | // If the intent requires a 3DS flow, redirect to it. |
||
| 640 | if ( 'requires_action' === $intent->status ) { |
||
| 641 | $this->unlock_order_payment( $order ); |
||
| 642 | |||
| 643 | if ( is_wc_endpoint_url( 'order-pay' ) ) { |
||
| 644 | $redirect_url = add_query_arg( 'wc-stripe-confirmation', 1, $order->get_checkout_payment_url( false ) ); |
||
| 645 | |||
| 646 | return array( |
||
| 647 | 'result' => 'success', |
||
| 648 | 'redirect' => $redirect_url, |
||
| 649 | ); |
||
| 650 | } else { |
||
| 651 | /** |
||
| 652 | * This URL contains only a hash, which will be sent to `checkout.js` where it will be set like this: |
||
| 653 | * `window.location = result.redirect` |
||
| 654 | * Once this redirect is sent to JS, the `onHashChange` function will execute `handleCardPayment`. |
||
| 655 | */ |
||
| 656 | |||
| 657 | return array( |
||
| 658 | 'result' => 'success', |
||
| 659 | 'redirect' => $this->get_return_url( $order ), |
||
| 660 | 'payment_intent_secret' => $intent->client_secret, |
||
| 661 | ); |
||
| 662 | } |
||
| 663 | } |
||
| 664 | } |
||
| 665 | |||
| 666 | // Process valid response. |
||
| 667 | $this->process_response( $response, $order ); |
||
|
0 ignored issues
–
show
|
|||
| 668 | |||
| 669 | // Remove cart. |
||
| 670 | if ( isset( WC()->cart ) ) { |
||
| 671 | WC()->cart->empty_cart(); |
||
| 672 | } |
||
| 673 | |||
| 674 | // Unlock the order. |
||
| 675 | $this->unlock_order_payment( $order ); |
||
| 676 | |||
| 677 | // Return thank you page redirect. |
||
| 678 | return array( |
||
| 679 | 'result' => 'success', |
||
| 680 | 'redirect' => $this->get_return_url( $order ), |
||
| 681 | ); |
||
| 682 | |||
| 683 | } catch ( WC_Stripe_Exception $e ) { |
||
| 684 | wc_add_notice( $e->getLocalizedMessage(), 'error' ); |
||
| 685 | WC_Stripe_Logger::log( 'Error: ' . $e->getMessage() ); |
||
| 686 | |||
| 687 | do_action( 'wc_gateway_stripe_process_payment_error', $e, $order ); |
||
| 688 | |||
| 689 | /* translators: error message */ |
||
| 690 | $order->update_status( 'failed' ); |
||
| 691 | |||
| 692 | return array( |
||
| 693 | 'result' => 'fail', |
||
| 694 | 'redirect' => '', |
||
| 695 | ); |
||
| 696 | } |
||
| 697 | } |
||
| 698 | |||
| 699 | /** |
||
| 700 | * Displays the Stripe fee |
||
| 701 | * |
||
| 702 | * @since 4.1.0 |
||
| 703 | * |
||
| 704 | * @param int $order_id The ID of the order. |
||
| 705 | */ |
||
| 706 | View Code Duplication | public function display_order_fee( $order_id ) { |
|
| 707 | if ( apply_filters( 'wc_stripe_hide_display_order_fee', false, $order_id ) ) { |
||
| 708 | return; |
||
| 709 | } |
||
| 710 | |||
| 711 | $order = wc_get_order( $order_id ); |
||
| 712 | |||
| 713 | $fee = WC_Stripe_Helper::get_stripe_fee( $order ); |
||
| 714 | $currency = WC_Stripe_Helper::get_stripe_currency( $order ); |
||
| 715 | |||
| 716 | if ( ! $fee || ! $currency ) { |
||
| 717 | return; |
||
| 718 | } |
||
| 719 | |||
| 720 | ?> |
||
| 721 | |||
| 722 | <tr> |
||
| 723 | <td class="label stripe-fee"> |
||
| 724 | <?php echo wc_help_tip( __( 'This represents the fee Stripe collects for the transaction.', 'woocommerce-gateway-stripe' ) ); // wpcs: xss ok. ?> |
||
| 725 | <?php esc_html_e( 'Stripe Fee:', 'woocommerce-gateway-stripe' ); ?> |
||
| 726 | </td> |
||
| 727 | <td width="1%"></td> |
||
| 728 | <td class="total"> |
||
| 729 | - <?php echo wc_price( $fee, array( 'currency' => $currency ) ); // wpcs: xss ok. ?> |
||
| 730 | </td> |
||
| 731 | </tr> |
||
| 732 | |||
| 733 | <?php |
||
| 734 | } |
||
| 735 | |||
| 736 | /** |
||
| 737 | * Displays the net total of the transaction without the charges of Stripe. |
||
| 738 | * |
||
| 739 | * @since 4.1.0 |
||
| 740 | * |
||
| 741 | * @param int $order_id The ID of the order. |
||
| 742 | */ |
||
| 743 | View Code Duplication | public function display_order_payout( $order_id ) { |
|
| 744 | if ( apply_filters( 'wc_stripe_hide_display_order_payout', false, $order_id ) ) { |
||
| 745 | return; |
||
| 746 | } |
||
| 747 | |||
| 748 | $order = wc_get_order( $order_id ); |
||
| 749 | |||
| 750 | $net = WC_Stripe_Helper::get_stripe_net( $order ); |
||
| 751 | $currency = WC_Stripe_Helper::get_stripe_currency( $order ); |
||
| 752 | |||
| 753 | if ( ! $net || ! $currency ) { |
||
| 754 | return; |
||
| 755 | } |
||
| 756 | |||
| 757 | ?> |
||
| 758 | |||
| 759 | <tr> |
||
| 760 | <td class="label stripe-payout"> |
||
| 761 | <?php echo wc_help_tip( __( 'This represents the net total that will be credited to your Stripe bank account. This may be in the currency that is set in your Stripe account.', 'woocommerce-gateway-stripe' ) ); // wpcs: xss ok. ?> |
||
| 762 | <?php esc_html_e( 'Stripe Payout:', 'woocommerce-gateway-stripe' ); ?> |
||
| 763 | </td> |
||
| 764 | <td width="1%"></td> |
||
| 765 | <td class="total"> |
||
| 766 | <?php echo wc_price( $net, array( 'currency' => $currency ) ); // wpcs: xss ok. ?> |
||
| 767 | </td> |
||
| 768 | </tr> |
||
| 769 | |||
| 770 | <?php |
||
| 771 | } |
||
| 772 | |||
| 773 | /** |
||
| 774 | * Generates a localized message for an error from a response. |
||
| 775 | * |
||
| 776 | * @since 4.3.2 |
||
| 777 | * |
||
| 778 | * @param stdClass $response The response from the Stripe API. |
||
| 779 | * |
||
| 780 | * @return string The localized error message. |
||
| 781 | */ |
||
| 782 | public function get_localized_error_message_from_response( $response ) { |
||
| 783 | $localized_messages = WC_Stripe_Helper::get_localized_messages(); |
||
| 784 | |||
| 785 | if ( 'card_error' === $response->error->type ) { |
||
| 786 | $localized_message = isset( $localized_messages[ $response->error->code ] ) ? $localized_messages[ $response->error->code ] : $response->error->message; |
||
| 787 | } else { |
||
| 788 | $localized_message = isset( $localized_messages[ $response->error->type ] ) ? $localized_messages[ $response->error->type ] : $response->error->message; |
||
| 789 | } |
||
| 790 | |||
| 791 | return $localized_message; |
||
| 792 | } |
||
| 793 | |||
| 794 | /** |
||
| 795 | * Gets a localized message for an error from a response, adds it as a note to the order, and throws it. |
||
| 796 | * |
||
| 797 | * @since 4.2.0 |
||
| 798 | * @param stdClass $response The response from the Stripe API. |
||
| 799 | * @param WC_Order $order The order to add a note to. |
||
| 800 | * @throws WC_Stripe_Exception An exception with the right message. |
||
| 801 | */ |
||
| 802 | public function throw_localized_message( $response, $order ) { |
||
| 803 | $localized_message = $this->get_localized_error_message_from_response( $response ); |
||
| 804 | |||
| 805 | $order->add_order_note( $localized_message ); |
||
| 806 | |||
| 807 | throw new WC_Stripe_Exception( print_r( $response, true ), $localized_message ); |
||
| 808 | } |
||
| 809 | |||
| 810 | /** |
||
| 811 | * Retries the payment process once an error occured. |
||
| 812 | * |
||
| 813 | * @since 4.2.0 |
||
| 814 | * @param object $response The response from the Stripe API. |
||
| 815 | * @param WC_Order $order An order that is being paid for. |
||
| 816 | * @param bool $retry A flag that indicates whether another retry should be attempted. |
||
| 817 | * @param bool $force_save_source Force save the payment source. |
||
| 818 | * @param mixed $previous_error Any error message from previous request. |
||
| 819 | * @param bool $use_order_source Whether to use the source, which should already be attached to the order. |
||
| 820 | * @throws WC_Stripe_Exception If the payment is not accepted. |
||
| 821 | * @return array|void |
||
| 822 | */ |
||
| 823 | public function retry_after_error( $response, $order, $retry, $force_save_source, $previous_error, $use_order_source ) { |
||
| 824 | if ( ! $retry ) { |
||
| 825 | $localized_message = __( 'Sorry, we are unable to process your payment at this time. Please retry later.', 'woocommerce-gateway-stripe' ); |
||
| 826 | $order->add_order_note( $localized_message ); |
||
| 827 | throw new WC_Stripe_Exception( print_r( $response, true ), $localized_message ); // phpcs:ignore WordPress.PHP.DevelopmentFunctions. |
||
| 828 | } |
||
| 829 | |||
| 830 | // Don't do anymore retries after this. |
||
| 831 | if ( 5 <= $this->retry_interval ) { |
||
| 832 | return $this->process_payment( $order->get_id(), false, $force_save_source, $response->error, $previous_error ); |
||
| 833 | } |
||
| 834 | |||
| 835 | sleep( $this->retry_interval ); |
||
| 836 | $this->retry_interval++; |
||
| 837 | |||
| 838 | return $this->process_payment( $order->get_id(), true, $force_save_source, $response->error, $previous_error, $use_order_source ); |
||
| 839 | } |
||
| 840 | |||
| 841 | /** |
||
| 842 | * Adds the necessary hooks to modify the "Pay for order" page in order to clean |
||
| 843 | * it up and prepare it for the Stripe PaymentIntents modal to confirm a payment. |
||
| 844 | * |
||
| 845 | * @since 4.2 |
||
| 846 | * @param WC_Payment_Gateway[] $gateways A list of all available gateways. |
||
| 847 | * @return WC_Payment_Gateway[] Either the same list or an empty one in the right conditions. |
||
| 848 | */ |
||
| 849 | public function prepare_order_pay_page( $gateways ) { |
||
| 850 | if ( ! is_wc_endpoint_url( 'order-pay' ) || ! isset( $_GET['wc-stripe-confirmation'] ) ) { // wpcs: csrf ok. |
||
| 851 | return $gateways; |
||
| 852 | } |
||
| 853 | |||
| 854 | try { |
||
| 855 | $this->prepare_intent_for_order_pay_page(); |
||
| 856 | } catch ( WC_Stripe_Exception $e ) { |
||
| 857 | // Just show the full order pay page if there was a problem preparing the Payment Intent |
||
| 858 | return $gateways; |
||
| 859 | } |
||
| 860 | |||
| 861 | add_filter( 'woocommerce_checkout_show_terms', '__return_false' ); |
||
| 862 | add_filter( 'woocommerce_pay_order_button_html', '__return_false' ); |
||
| 863 | add_filter( 'woocommerce_available_payment_gateways', '__return_empty_array' ); |
||
| 864 | add_filter( 'woocommerce_no_available_payment_methods_message', array( $this, 'change_no_available_methods_message' ) ); |
||
| 865 | add_action( 'woocommerce_pay_order_after_submit', array( $this, 'render_payment_intent_inputs' ) ); |
||
| 866 | |||
| 867 | return array(); |
||
| 868 | } |
||
| 869 | |||
| 870 | /** |
||
| 871 | * Changes the text of the "No available methods" message to one that indicates |
||
| 872 | * the need for a PaymentIntent to be confirmed. |
||
| 873 | * |
||
| 874 | * @since 4.2 |
||
| 875 | * @return string the new message. |
||
| 876 | */ |
||
| 877 | public function change_no_available_methods_message() { |
||
| 878 | return wpautop( __( "Almost there!\n\nYour order has already been created, the only thing that still needs to be done is for you to authorize the payment with your bank.", 'woocommerce-gateway-stripe' ) ); |
||
| 879 | } |
||
| 880 | |||
| 881 | /** |
||
| 882 | * Prepares the Payment Intent for it to be completed in the "Pay for Order" page. |
||
| 883 | * |
||
| 884 | * @param WC_Order|null $order Order object, or null to get the order from the "order-pay" URL parameter |
||
| 885 | * |
||
| 886 | * @throws WC_Stripe_Exception |
||
| 887 | * @since 4.3 |
||
| 888 | */ |
||
| 889 | public function prepare_intent_for_order_pay_page( $order = null ) { |
||
| 890 | View Code Duplication | if ( ! isset( $order ) || empty( $order ) ) { |
|
| 891 | $order = wc_get_order( absint( get_query_var( 'order-pay' ) ) ); |
||
| 892 | } |
||
| 893 | $intent = $this->get_intent_from_order( $order ); |
||
| 894 | |||
| 895 | if ( ! $intent ) { |
||
| 896 | throw new WC_Stripe_Exception( 'Payment Intent not found', __( 'Payment Intent not found for order #' . $order->get_id(), 'woocommerce-gateway-stripe' ) ); |
||
| 897 | } |
||
| 898 | |||
| 899 | if ( 'requires_payment_method' === $intent->status && isset( $intent->last_payment_error ) |
||
| 900 | && 'authentication_required' === $intent->last_payment_error->code ) { |
||
| 901 | $level3_data = $this->get_level3_data_from_order( $order ); |
||
| 902 | $intent = WC_Stripe_API::request_with_level3_data( |
||
| 903 | array( |
||
| 904 | 'payment_method' => $intent->last_payment_error->source->id, |
||
| 905 | ), |
||
| 906 | 'payment_intents/' . $intent->id . '/confirm', |
||
| 907 | $level3_data, |
||
| 908 | $order |
||
| 909 | ); |
||
| 910 | |||
| 911 | if ( isset( $intent->error ) ) { |
||
| 912 | throw new WC_Stripe_Exception( print_r( $intent, true ), $intent->error->message ); |
||
| 913 | } |
||
| 914 | } |
||
| 915 | |||
| 916 | $this->order_pay_intent = $intent; |
||
| 917 | } |
||
| 918 | |||
| 919 | /** |
||
| 920 | * Renders hidden inputs on the "Pay for Order" page in order to let Stripe handle PaymentIntents. |
||
| 921 | * |
||
| 922 | * @param WC_Order|null $order Order object, or null to get the order from the "order-pay" URL parameter |
||
| 923 | * |
||
| 924 | * @throws WC_Stripe_Exception |
||
| 925 | * @since 4.2 |
||
| 926 | */ |
||
| 927 | public function render_payment_intent_inputs( $order = null ) { |
||
| 928 | View Code Duplication | if ( ! isset( $order ) || empty( $order ) ) { |
|
| 929 | $order = wc_get_order( absint( get_query_var( 'order-pay' ) ) ); |
||
| 930 | } |
||
| 931 | if ( ! isset( $this->order_pay_intent ) ) { |
||
| 932 | $this->prepare_intent_for_order_pay_page( $order ); |
||
| 933 | } |
||
| 934 | |||
| 935 | $verification_url = add_query_arg( |
||
| 936 | array( |
||
| 937 | 'order' => $order->get_id(), |
||
| 938 | 'nonce' => wp_create_nonce( 'wc_stripe_confirm_pi' ), |
||
| 939 | 'redirect_to' => rawurlencode( $this->get_return_url( $order ) ), |
||
| 940 | 'is_pay_for_order' => true, |
||
| 941 | ), |
||
| 942 | WC_AJAX::get_endpoint( 'wc_stripe_verify_intent' ) |
||
| 943 | ); |
||
| 944 | |||
| 945 | echo '<input type="hidden" id="stripe-intent-id" value="' . esc_attr( $this->order_pay_intent->client_secret ) . '" />'; |
||
| 946 | echo '<input type="hidden" id="stripe-intent-return" value="' . esc_attr( $verification_url ) . '" />'; |
||
| 947 | } |
||
| 948 | |||
| 949 | /** |
||
| 950 | * Adds an error message wrapper to each saved method. |
||
| 951 | * |
||
| 952 | * @since 4.2.0 |
||
| 953 | * @param WC_Payment_Token $token Payment Token. |
||
| 954 | * @return string Generated payment method HTML |
||
| 955 | */ |
||
| 956 | public function get_saved_payment_method_option_html( $token ) { |
||
| 957 | $html = parent::get_saved_payment_method_option_html( $token ); |
||
| 958 | $error_wrapper = '<div class="stripe-source-errors" role="alert"></div>'; |
||
| 959 | |||
| 960 | return preg_replace( '~</(\w+)>\s*$~', "$error_wrapper</$1>", $html ); |
||
| 961 | } |
||
| 962 | |||
| 963 | /** |
||
| 964 | * Attempt to manually complete the payment process for orders, which are still pending |
||
| 965 | * before displaying the View Order page. This is useful in case webhooks have not been set up. |
||
| 966 | * |
||
| 967 | * @since 4.2.0 |
||
| 968 | * @param int $order_id The ID that will be used for the thank you page. |
||
| 969 | */ |
||
| 970 | public function check_intent_status_on_order_page( $order_id ) { |
||
| 971 | if ( empty( $order_id ) || absint( $order_id ) <= 0 ) { |
||
| 972 | return; |
||
| 973 | } |
||
| 974 | |||
| 975 | $order = wc_get_order( absint( $order_id ) ); |
||
| 976 | |||
| 977 | if ( ! $order ) { |
||
| 978 | return; |
||
| 979 | } |
||
| 980 | |||
| 981 | $this->verify_intent_after_checkout( $order ); |
||
| 982 | } |
||
| 983 | |||
| 984 | /** |
||
| 985 | * Attached to `woocommerce_payment_successful_result` with a late priority, |
||
| 986 | * this method will combine the "naturally" generated redirect URL from |
||
| 987 | * WooCommerce and a payment/setup intent secret into a hash, which contains both |
||
| 988 | * the secret, and a proper URL, which will confirm whether the intent succeeded. |
||
| 989 | * |
||
| 990 | * @since 4.2.0 |
||
| 991 | * @param array $result The result from `process_payment`. |
||
| 992 | * @param int $order_id The ID of the order which is being paid for. |
||
| 993 | * @return array |
||
| 994 | */ |
||
| 995 | public function modify_successful_payment_result( $result, $order_id ) { |
||
| 996 | if ( ! isset( $result['payment_intent_secret'] ) && ! isset( $result['setup_intent_secret'] ) ) { |
||
| 997 | // Only redirects with intents need to be modified. |
||
| 998 | return $result; |
||
| 999 | } |
||
| 1000 | |||
| 1001 | // Put the final thank you page redirect into the verification URL. |
||
| 1002 | $verification_url = add_query_arg( |
||
| 1003 | array( |
||
| 1004 | 'order' => $order_id, |
||
| 1005 | 'nonce' => wp_create_nonce( 'wc_stripe_confirm_pi' ), |
||
| 1006 | 'redirect_to' => rawurlencode( $result['redirect'] ), |
||
| 1007 | ), |
||
| 1008 | WC_AJAX::get_endpoint( 'wc_stripe_verify_intent' ) |
||
| 1009 | ); |
||
| 1010 | |||
| 1011 | if ( isset( $result['payment_intent_secret'] ) ) { |
||
| 1012 | $redirect = sprintf( '#confirm-pi-%s:%s', $result['payment_intent_secret'], rawurlencode( $verification_url ) ); |
||
| 1013 | } else if ( isset( $result['setup_intent_secret'] ) ) { |
||
| 1014 | $redirect = sprintf( '#confirm-si-%s:%s', $result['setup_intent_secret'], rawurlencode( $verification_url ) ); |
||
| 1015 | } |
||
| 1016 | |||
| 1017 | return array( |
||
| 1018 | 'result' => 'success', |
||
| 1019 | 'redirect' => $redirect, |
||
|
0 ignored issues
–
show
The variable
$redirect does not seem to be defined for all execution paths leading up to this point.
If you define a variable conditionally, it can happen that it is not defined for all execution paths. Let’s take a look at an example: function myFunction($a) {
switch ($a) {
case 'foo':
$x = 1;
break;
case 'bar':
$x = 2;
break;
}
// $x is potentially undefined here.
echo $x;
}
In the above example, the variable $x is defined if you pass “foo” or “bar” as argument for $a. However, since the switch statement has no default case statement, if you pass any other value, the variable $x would be undefined. Available Fixes
Loading history...
|
|||
| 1020 | ); |
||
| 1021 | } |
||
| 1022 | |||
| 1023 | /** |
||
| 1024 | * Proceed with current request using new login session (to ensure consistent nonce). |
||
| 1025 | */ |
||
| 1026 | public function set_cookie_on_current_request( $cookie ) { |
||
| 1027 | $_COOKIE[ LOGGED_IN_COOKIE ] = $cookie; |
||
| 1028 | } |
||
| 1029 | |||
| 1030 | /** |
||
| 1031 | * Executed between the "Checkout" and "Thank you" pages, this |
||
| 1032 | * method updates orders based on the status of associated PaymentIntents. |
||
| 1033 | * |
||
| 1034 | * @since 4.2.0 |
||
| 1035 | * @param WC_Order $order The order which is in a transitional state. |
||
| 1036 | */ |
||
| 1037 | public function verify_intent_after_checkout( $order ) { |
||
| 1038 | $payment_method = $order->get_payment_method(); |
||
| 1039 | if ( $payment_method !== $this->id ) { |
||
| 1040 | // If this is not the payment method, an intent would not be available. |
||
| 1041 | return; |
||
| 1042 | } |
||
| 1043 | |||
| 1044 | $intent = $this->get_intent_from_order( $order ); |
||
| 1045 | if ( ! $intent ) { |
||
| 1046 | // No intent, redirect to the order received page for further actions. |
||
| 1047 | return; |
||
| 1048 | } |
||
| 1049 | |||
| 1050 | // A webhook might have modified or locked the order while the intent was retreived. This ensures we are reading the right status. |
||
| 1051 | clean_post_cache( $order->get_id() ); |
||
| 1052 | $order = wc_get_order( $order->get_id() ); |
||
| 1053 | |||
| 1054 | if ( ! $order->has_status( array( 'pending', 'failed' ) ) ) { |
||
| 1055 | // If payment has already been completed, this function is redundant. |
||
| 1056 | return; |
||
| 1057 | } |
||
| 1058 | |||
| 1059 | if ( $this->lock_order_payment( $order, $intent ) ) { |
||
| 1060 | return; |
||
| 1061 | } |
||
| 1062 | |||
| 1063 | if ( 'setup_intent' === $intent->object && 'succeeded' === $intent->status ) { |
||
| 1064 | WC()->cart->empty_cart(); |
||
| 1065 | if ( WC_Stripe_Helper::is_pre_orders_exists() && WC_Pre_Orders_Order::order_contains_pre_order( $order ) ) { |
||
| 1066 | WC_Pre_Orders_Order::mark_order_as_pre_ordered( $order ); |
||
| 1067 | } else { |
||
| 1068 | $order->payment_complete(); |
||
| 1069 | } |
||
| 1070 | } else if ( 'succeeded' === $intent->status || 'requires_capture' === $intent->status ) { |
||
| 1071 | // Proceed with the payment completion. |
||
| 1072 | $this->handle_intent_verification_success( $order, $intent ); |
||
| 1073 | } else if ( 'requires_payment_method' === $intent->status ) { |
||
| 1074 | // `requires_payment_method` means that SCA got denied for the current payment method. |
||
| 1075 | $this->handle_intent_verification_failure( $order, $intent ); |
||
| 1076 | } |
||
| 1077 | |||
| 1078 | $this->unlock_order_payment( $order ); |
||
| 1079 | } |
||
| 1080 | |||
| 1081 | /** |
||
| 1082 | * Called after an intent verification succeeds, this allows |
||
| 1083 | * specific APNs or children of this class to modify its behavior. |
||
| 1084 | * |
||
| 1085 | * @param WC_Order $order The order whose verification succeeded. |
||
| 1086 | * @param stdClass $intent The Payment Intent object. |
||
| 1087 | */ |
||
| 1088 | protected function handle_intent_verification_success( $order, $intent ) { |
||
| 1089 | $this->process_response( end( $intent->charges->data ), $order ); |
||
| 1090 | } |
||
| 1091 | |||
| 1092 | /** |
||
| 1093 | * Called after an intent verification fails, this allows |
||
| 1094 | * specific APNs or children of this class to modify its behavior. |
||
| 1095 | * |
||
| 1096 | * @param WC_Order $order The order whose verification failed. |
||
| 1097 | * @param stdClass $intent The Payment Intent object. |
||
| 1098 | */ |
||
| 1099 | protected function handle_intent_verification_failure( $order, $intent ) { |
||
| 1100 | $this->failed_sca_auth( $order, $intent ); |
||
| 1101 | } |
||
| 1102 | |||
| 1103 | /** |
||
| 1104 | * Checks if the payment intent associated with an order failed and records the event. |
||
| 1105 | * |
||
| 1106 | * @since 4.2.0 |
||
| 1107 | * @param WC_Order $order The order which should be checked. |
||
| 1108 | * @param object $intent The intent, associated with the order. |
||
| 1109 | */ |
||
| 1110 | public function failed_sca_auth( $order, $intent ) { |
||
| 1111 | // If the order has already failed, do not repeat the same message. |
||
| 1112 | if ( $order->has_status( 'failed' ) ) { |
||
| 1113 | return; |
||
| 1114 | } |
||
| 1115 | |||
| 1116 | // Load the right message and update the status. |
||
| 1117 | $status_message = isset( $intent->last_payment_error ) |
||
| 1118 | /* translators: 1) The error message that was received from Stripe. */ |
||
| 1119 | ? sprintf( __( 'Stripe SCA authentication failed. Reason: %s', 'woocommerce-gateway-stripe' ), $intent->last_payment_error->message ) |
||
| 1120 | : __( 'Stripe SCA authentication failed.', 'woocommerce-gateway-stripe' ); |
||
| 1121 | $order->update_status( 'failed', $status_message ); |
||
| 1122 | } |
||
| 1123 | |||
| 1124 | /** |
||
| 1125 | * Preserves the "wc-stripe-confirmation" URL parameter so the user can complete the SCA authentication after logging in. |
||
| 1126 | * |
||
| 1127 | * @param string $pay_url Current computed checkout URL for the given order. |
||
| 1128 | * @param WC_Order $order Order object. |
||
| 1129 | * |
||
| 1130 | * @return string Checkout URL for the given order. |
||
| 1131 | */ |
||
| 1132 | public function get_checkout_payment_url( $pay_url, $order ) { |
||
| 1133 | global $wp; |
||
| 1134 | if ( isset( $_GET['wc-stripe-confirmation'] ) && isset( $wp->query_vars['order-pay'] ) && $wp->query_vars['order-pay'] == $order->get_id() ) { |
||
| 1135 | $pay_url = add_query_arg( 'wc-stripe-confirmation', 1, $pay_url ); |
||
| 1136 | } |
||
| 1137 | return $pay_url; |
||
| 1138 | } |
||
| 1139 | |||
| 1140 | /** |
||
| 1141 | * Checks whether new keys are being entered when saving options. |
||
| 1142 | */ |
||
| 1143 | public function process_admin_options() { |
||
| 1144 | // Load all old values before the new settings get saved. |
||
| 1145 | $old_publishable_key = $this->get_option( 'publishable_key' ); |
||
| 1146 | $old_secret_key = $this->get_option( 'secret_key' ); |
||
| 1147 | $old_test_publishable_key = $this->get_option( 'test_publishable_key' ); |
||
| 1148 | $old_test_secret_key = $this->get_option( 'test_secret_key' ); |
||
| 1149 | |||
| 1150 | parent::process_admin_options(); |
||
| 1151 | |||
| 1152 | // Load all old values after the new settings have been saved. |
||
| 1153 | $new_publishable_key = $this->get_option( 'publishable_key' ); |
||
| 1154 | $new_secret_key = $this->get_option( 'secret_key' ); |
||
| 1155 | $new_test_publishable_key = $this->get_option( 'test_publishable_key' ); |
||
| 1156 | $new_test_secret_key = $this->get_option( 'test_secret_key' ); |
||
| 1157 | |||
| 1158 | // Checks whether a value has transitioned from a non-empty value to a new one. |
||
| 1159 | $has_changed = function( $old_value, $new_value ) { |
||
| 1160 | return ! empty( $old_value ) && ( $old_value !== $new_value ); |
||
| 1161 | }; |
||
| 1162 | |||
| 1163 | // Look for updates. |
||
| 1164 | if ( |
||
| 1165 | $has_changed( $old_publishable_key, $new_publishable_key ) |
||
| 1166 | || $has_changed( $old_secret_key, $new_secret_key ) |
||
| 1167 | || $has_changed( $old_test_publishable_key, $new_test_publishable_key ) |
||
| 1168 | || $has_changed( $old_test_secret_key, $new_test_secret_key ) |
||
| 1169 | ) { |
||
| 1170 | update_option( 'wc_stripe_show_changed_keys_notice', 'yes' ); |
||
| 1171 | } |
||
| 1172 | } |
||
| 1173 | |||
| 1174 | View Code Duplication | public function validate_publishable_key_field( $key, $value ) { |
|
| 1175 | $value = $this->validate_text_field( $key, $value ); |
||
| 1176 | if ( ! empty( $value ) && ! preg_match( '/^pk_live_/', $value ) ) { |
||
| 1177 | throw new Exception( __( 'The "Live Publishable Key" should start with "pk_live", enter the correct key.', 'woocommerce-gateway-stripe' ) ); |
||
| 1178 | } |
||
| 1179 | return $value; |
||
| 1180 | } |
||
| 1181 | |||
| 1182 | View Code Duplication | public function validate_secret_key_field( $key, $value ) { |
|
| 1183 | $value = $this->validate_text_field( $key, $value ); |
||
| 1184 | if ( ! empty( $value ) && ! preg_match( '/^[rs]k_live_/', $value ) ) { |
||
| 1185 | throw new Exception( __( 'The "Live Secret Key" should start with "sk_live" or "rk_live", enter the correct key.', 'woocommerce-gateway-stripe' ) ); |
||
| 1186 | } |
||
| 1187 | return $value; |
||
| 1188 | } |
||
| 1189 | |||
| 1190 | View Code Duplication | public function validate_test_publishable_key_field( $key, $value ) { |
|
| 1191 | $value = $this->validate_text_field( $key, $value ); |
||
| 1192 | if ( ! empty( $value ) && ! preg_match( '/^pk_test_/', $value ) ) { |
||
| 1193 | throw new Exception( __( 'The "Test Publishable Key" should start with "pk_test", enter the correct key.', 'woocommerce-gateway-stripe' ) ); |
||
| 1194 | } |
||
| 1195 | return $value; |
||
| 1196 | } |
||
| 1197 | |||
| 1198 | View Code Duplication | public function validate_test_secret_key_field( $key, $value ) { |
|
| 1199 | $value = $this->validate_text_field( $key, $value ); |
||
| 1200 | if ( ! empty( $value ) && ! preg_match( '/^[rs]k_test_/', $value ) ) { |
||
| 1201 | throw new Exception( __( 'The "Test Secret Key" should start with "sk_test" or "rk_test", enter the correct key.', 'woocommerce-gateway-stripe' ) ); |
||
| 1202 | } |
||
| 1203 | return $value; |
||
| 1204 | } |
||
| 1205 | } |
||
| 1206 |
If you define a variable conditionally, it can happen that it is not defined for all execution paths.
Let’s take a look at an example:
In the above example, the variable $x is defined if you pass “foo” or “bar” as argument for $a. However, since the switch statement has no default case statement, if you pass any other value, the variable $x would be undefined.
Available Fixes
Check for existence of the variable explicitly:
Define a default value for the variable:
Add a value for the missing path: