This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include
, or for example
via PHP's auto-loading mechanism.
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
1 | <?php |
||
2 | if ( ! defined( 'ABSPATH' ) ) { |
||
3 | exit; |
||
4 | } |
||
5 | |||
6 | /** |
||
7 | * Class that handles iDeal payment method. |
||
8 | * |
||
9 | * @extends WC_Gateway_Stripe |
||
10 | * |
||
11 | * @since 4.0.0 |
||
12 | */ |
||
13 | View Code Duplication | class WC_Gateway_Stripe_Ideal extends WC_Stripe_Payment_Gateway { |
|
0 ignored issues
–
show
|
|||
14 | /** |
||
15 | * Notices (array) |
||
16 | * @var array |
||
17 | */ |
||
18 | public $notices = array(); |
||
19 | |||
20 | /** |
||
21 | * Is test mode active? |
||
22 | * |
||
23 | * @var bool |
||
24 | */ |
||
25 | public $testmode; |
||
26 | |||
27 | /** |
||
28 | * Alternate credit card statement name |
||
29 | * |
||
30 | * @var bool |
||
31 | */ |
||
32 | public $statement_descriptor; |
||
33 | |||
34 | /** |
||
35 | * API access secret key |
||
36 | * |
||
37 | * @var string |
||
38 | */ |
||
39 | public $secret_key; |
||
40 | |||
41 | /** |
||
42 | * Api access publishable key |
||
43 | * |
||
44 | * @var string |
||
45 | */ |
||
46 | public $publishable_key; |
||
47 | |||
48 | /** |
||
49 | * Should we store the users credit cards? |
||
50 | * |
||
51 | * @var bool |
||
52 | */ |
||
53 | public $saved_cards; |
||
54 | |||
55 | /** |
||
56 | * Constructor |
||
57 | */ |
||
58 | public function __construct() { |
||
59 | $this->id = 'stripe_ideal'; |
||
60 | $this->method_title = __( 'Stripe iDeal', 'woocommerce-gateway-stripe' ); |
||
61 | /* translators: link */ |
||
62 | $this->method_description = sprintf( __( 'All other general Stripe settings can be adjusted <a href="%s">here</a>.', 'woocommerce-gateway-stripe' ), admin_url( 'admin.php?page=wc-settings&tab=checkout§ion=stripe' ) ); |
||
63 | $this->supports = array( |
||
64 | 'products', |
||
65 | 'refunds', |
||
66 | ); |
||
67 | |||
68 | // Load the form fields. |
||
69 | $this->init_form_fields(); |
||
70 | |||
71 | // Load the settings. |
||
72 | $this->init_settings(); |
||
73 | |||
74 | $main_settings = get_option( 'woocommerce_stripe_settings' ); |
||
75 | $this->title = $this->get_option( 'title' ); |
||
76 | $this->description = $this->get_option( 'description' ); |
||
77 | $this->enabled = $this->get_option( 'enabled' ); |
||
78 | $this->testmode = ( ! empty( $main_settings['testmode'] ) && 'yes' === $main_settings['testmode'] ) ? true : false; |
||
79 | $this->saved_cards = ( ! empty( $main_settings['saved_cards'] ) && 'yes' === $main_settings['saved_cards'] ) ? true : false; |
||
80 | $this->publishable_key = ! empty( $main_settings['publishable_key'] ) ? $main_settings['publishable_key'] : ''; |
||
81 | $this->secret_key = ! empty( $main_settings['secret_key'] ) ? $main_settings['secret_key'] : ''; |
||
82 | $this->statement_descriptor = ! empty( $main_settings['statement_descriptor'] ) ? $main_settings['statement_descriptor'] : ''; |
||
83 | |||
84 | if ( $this->testmode ) { |
||
85 | $this->publishable_key = ! empty( $main_settings['test_publishable_key'] ) ? $main_settings['test_publishable_key'] : ''; |
||
86 | $this->secret_key = ! empty( $main_settings['test_secret_key'] ) ? $main_settings['test_secret_key'] : ''; |
||
87 | } |
||
88 | |||
89 | add_action( 'woocommerce_update_options_payment_gateways_' . $this->id, array( $this, 'process_admin_options' ) ); |
||
90 | add_action( 'wp_enqueue_scripts', array( $this, 'payment_scripts' ) ); |
||
91 | } |
||
92 | |||
93 | /** |
||
94 | * Returns all supported currencies for this payment method. |
||
95 | * |
||
96 | * @since 4.0.0 |
||
97 | * @version 4.0.0 |
||
98 | * @return array |
||
99 | */ |
||
100 | public function get_supported_currency() { |
||
101 | return apply_filters( |
||
102 | 'wc_stripe_ideal_supported_currencies', |
||
103 | array( |
||
104 | 'EUR', |
||
105 | ) |
||
106 | ); |
||
107 | } |
||
108 | |||
109 | /** |
||
110 | * Checks to see if all criteria is met before showing payment method. |
||
111 | * |
||
112 | * @since 4.0.0 |
||
113 | * @version 4.0.0 |
||
114 | * @return bool |
||
115 | */ |
||
116 | public function is_available() { |
||
117 | if ( ! in_array( get_woocommerce_currency(), $this->get_supported_currency() ) ) { |
||
118 | return false; |
||
119 | } |
||
120 | |||
121 | return parent::is_available(); |
||
122 | } |
||
123 | |||
124 | /** |
||
125 | * Get_icon function. |
||
126 | * |
||
127 | * @since 1.0.0 |
||
128 | * @version 4.0.0 |
||
129 | * @return string |
||
130 | */ |
||
131 | public function get_icon() { |
||
132 | $icons = $this->payment_icons(); |
||
133 | |||
134 | $icons_str = ''; |
||
135 | |||
136 | $icons_str .= isset( $icons['ideal'] ) ? $icons['ideal'] : ''; |
||
137 | |||
138 | return apply_filters( 'woocommerce_gateway_icon', $icons_str, $this->id ); |
||
139 | } |
||
140 | |||
141 | /** |
||
142 | * payment_scripts function. |
||
143 | * |
||
144 | * Outputs scripts used for stripe payment |
||
145 | * |
||
146 | * @access public |
||
147 | */ |
||
148 | public function payment_scripts() { |
||
149 | if ( ! is_cart() && ! is_checkout() && ! isset( $_GET['pay_for_order'] ) && ! is_add_payment_method_page() ) { |
||
150 | return; |
||
151 | } |
||
152 | |||
153 | wp_enqueue_style( 'stripe_styles' ); |
||
154 | wp_enqueue_script( 'woocommerce_stripe' ); |
||
155 | } |
||
156 | |||
157 | /** |
||
158 | * Initialize Gateway Settings Form Fields. |
||
159 | */ |
||
160 | public function init_form_fields() { |
||
161 | $this->form_fields = require( WC_STRIPE_PLUGIN_PATH . '/includes/admin/stripe-ideal-settings.php' ); |
||
162 | } |
||
163 | |||
164 | /** |
||
165 | * Payment form on checkout page |
||
166 | */ |
||
167 | public function payment_fields() { |
||
168 | global $wp; |
||
169 | $user = wp_get_current_user(); |
||
0 ignored issues
–
show
$user is not used, you could remove the assignment.
This check looks for variable assignements that are either overwritten by other assignments or where the variable is not used subsequently. $myVar = 'Value';
$higher = false;
if (rand(1, 6) > 3) {
$higher = true;
} else {
$higher = false;
}
Both the ![]() |
|||
170 | $total = WC()->cart->total; |
||
171 | $description = $this->get_description(); |
||
172 | |||
173 | // If paying from order, we need to get total from order not cart. |
||
174 | if ( isset( $_GET['pay_for_order'] ) && ! empty( $_GET['key'] ) ) { |
||
175 | $order = wc_get_order( wc_clean( $wp->query_vars['order-pay'] ) ); |
||
176 | $total = $order->get_total(); |
||
177 | } |
||
178 | |||
179 | if ( is_add_payment_method_page() ) { |
||
180 | $pay_button_text = __( 'Add Payment', 'woocommerce-gateway-stripe' ); |
||
0 ignored issues
–
show
$pay_button_text is not used, you could remove the assignment.
This check looks for variable assignements that are either overwritten by other assignments or where the variable is not used subsequently. $myVar = 'Value';
$higher = false;
if (rand(1, 6) > 3) {
$higher = true;
} else {
$higher = false;
}
Both the ![]() |
|||
181 | $total = ''; |
||
182 | } else { |
||
183 | $pay_button_text = ''; |
||
0 ignored issues
–
show
$pay_button_text is not used, you could remove the assignment.
This check looks for variable assignements that are either overwritten by other assignments or where the variable is not used subsequently. $myVar = 'Value';
$higher = false;
if (rand(1, 6) > 3) {
$higher = true;
} else {
$higher = false;
}
Both the ![]() |
|||
184 | } |
||
185 | |||
186 | echo '<div |
||
187 | id="stripe-ideal-payment-data" |
||
188 | data-amount="' . esc_attr( WC_Stripe_Helper::get_stripe_amount( $total ) ) . '" |
||
189 | data-currency="' . esc_attr( strtolower( get_woocommerce_currency() ) ) . '">'; |
||
190 | |||
191 | if ( $description ) { |
||
192 | echo apply_filters( 'wc_stripe_description', wpautop( wp_kses_post( $description ) ), $this->id ); |
||
193 | } |
||
194 | |||
195 | echo '</div>'; |
||
196 | } |
||
197 | |||
198 | /** |
||
199 | * Creates the source for charge. |
||
200 | * |
||
201 | * @since 4.0.0 |
||
202 | * @version 4.0.0 |
||
203 | * @param object $order |
||
204 | * @return mixed |
||
205 | */ |
||
206 | public function create_source( $order ) { |
||
207 | $currency = $order->get_currency(); |
||
208 | $return_url = $this->get_stripe_return_url( $order ); |
||
209 | $post_data = array(); |
||
210 | $post_data['amount'] = WC_Stripe_Helper::get_stripe_amount( $order->get_total(), $currency ); |
||
211 | $post_data['currency'] = strtolower( $currency ); |
||
212 | $post_data['type'] = 'ideal'; |
||
213 | $post_data['owner'] = $this->get_owner_details( $order ); |
||
214 | $post_data['redirect'] = array( 'return_url' => $return_url ); |
||
215 | |||
216 | if ( ! empty( $this->statement_descriptor ) ) { |
||
217 | $post_data['statement_descriptor'] = WC_Stripe_Helper::clean_statement_descriptor( $this->statement_descriptor ); |
||
0 ignored issues
–
show
$this->statement_descriptor is of type boolean , but the function expects a string .
It seems like the type of the argument is not accepted by the function/method which you are calling. In some cases, in particular if PHP’s automatic type-juggling kicks in this might be fine. In other cases, however this might be a bug. We suggest to add an explicit type cast like in the following example: function acceptsInteger($int) { }
$x = '123'; // string "123"
// Instead of
acceptsInteger($x);
// we recommend to use
acceptsInteger((integer) $x);
![]() |
|||
218 | } |
||
219 | |||
220 | WC_Stripe_Logger::log( 'Info: Begin creating iDeal source' ); |
||
221 | |||
222 | return WC_Stripe_API::request( apply_filters( 'wc_stripe_ideal_source', $post_data, $order ), 'sources' ); |
||
223 | } |
||
224 | |||
225 | /** |
||
226 | * Process the payment |
||
227 | * |
||
228 | * @param int $order_id Reference. |
||
229 | * @param bool $retry Should we retry on fail. |
||
230 | * @param bool $force_save_source Force payment source to be saved. |
||
231 | * |
||
232 | * @throws Exception If payment will not be accepted. |
||
233 | * |
||
234 | * @return array|void |
||
235 | */ |
||
236 | public function process_payment( $order_id, $retry = true, $force_save_source = false ) { |
||
237 | try { |
||
238 | $order = wc_get_order( $order_id ); |
||
239 | |||
240 | // This will throw exception if not valid. |
||
241 | $this->validate_minimum_order_amount( $order ); |
||
242 | |||
243 | // This comes from the create account checkbox in the checkout page. |
||
244 | $create_account = ! empty( $_POST['createaccount'] ) ? true : false; |
||
245 | |||
246 | if ( $create_account ) { |
||
247 | $new_customer_id = $order->get_customer_id(); |
||
248 | $new_stripe_customer = new WC_Stripe_Customer( $new_customer_id ); |
||
249 | $new_stripe_customer->create_customer(); |
||
250 | } |
||
251 | |||
252 | $response = $this->create_source( $order ); |
||
253 | |||
254 | if ( ! empty( $response->error ) ) { |
||
255 | $order->add_order_note( $response->error->message ); |
||
256 | |||
257 | throw new WC_Stripe_Exception( print_r( $response, true ), $response->error->message ); |
||
258 | } |
||
259 | |||
260 | $order->update_meta_data( '_stripe_source_id', $response->id ); |
||
261 | $order->save(); |
||
262 | |||
263 | WC_Stripe_Logger::log( 'Info: Redirecting to iDeal...' ); |
||
264 | |||
265 | return array( |
||
266 | 'result' => 'success', |
||
267 | 'redirect' => esc_url_raw( $response->redirect->url ), |
||
268 | ); |
||
269 | } catch ( WC_Stripe_Exception $e ) { |
||
270 | wc_add_notice( $e->getLocalizedMessage(), 'error' ); |
||
271 | WC_Stripe_Logger::log( 'Error: ' . $e->getMessage() ); |
||
272 | |||
273 | do_action( 'wc_gateway_stripe_process_payment_error', $e, $order ); |
||
274 | |||
275 | if ( $order->has_status( array( 'pending', 'failed' ) ) ) { |
||
276 | $this->send_failed_order_email( $order_id ); |
||
277 | } |
||
278 | |||
279 | return array( |
||
280 | 'result' => 'fail', |
||
281 | 'redirect' => '', |
||
282 | ); |
||
283 | } |
||
284 | } |
||
285 | } |
||
286 |
Duplicated code is one of the most pungent code smells. If you need to duplicate the same code in three or more different places, we strongly encourage you to look into extracting the code into a single class or operation.
You can also find more detailed suggestions in the “Code” section of your repository.