Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions inc/cleantalk-ajax.php
Original file line number Diff line number Diff line change
Expand Up @@ -118,6 +118,9 @@
/* The Fluent Form have the direct integration */
$_cleantalk_hooked_actions[] = 'fluentform_submit';

/* WooCommerce Stripe UPE confirms the card on Add payment method. Direct integration. */
$_cleantalk_hooked_actions[] = 'wc_stripe_create_and_confirm_setup_intent';

/* Estimation Forms have the direct integration */
if ( class_exists('LFB_Core') ) {
$_cleantalk_hooked_actions[] = 'send_email';
Expand Down
35 changes: 35 additions & 0 deletions inc/cleantalk-public-validate-skip-functions.php
Original file line number Diff line number Diff line change
Expand Up @@ -54,6 +54,7 @@ function skip_for_ct_contact_form_validate_postdata()
apbct_is_in_uri('/wc-api') ||
apbct_is_in_uri('wc-api=WC_Gateway_Tpay_Basic') || // Tpay payment Gateway plugin
(isset($_POST['wc_reset_password'], $_POST['_wpnonce'], $_POST['_wp_http_referer'])) || //WooCommerce recovery password form
apbct_is_woocommerce_add_payment_method_form() || // WooCommerce Add payment method, checked as an order
(isset($_POST['woocommerce-login-nonce'], $_POST['login'], $_POST['password'], $_POST['_wp_http_referer'])) || //WooCommerce login form
(isset($_POST['provider'], $_POST['authcode']) && $_POST['provider'] === 'Two_Factor_Totp') || //TwoFactor authorization
(isset($_GET['wc-ajax']) && $_GET['wc-ajax'] === 'sa_wc_buy_now_get_ajax_buy_now_button') || //BuyNow add to cart
Expand All @@ -74,6 +75,38 @@ function skip_for_ct_contact_form_validate_postdata()
return false;
}

/**
* Real WooCommerce "Add payment method" submit.
*
* The dedicated check sends the account email as an order. Skipping it here keeps the
* general checker from marking the request done. A single POST field is not enough:
* the request must hit this endpoint and carry the form nonce.
*
* @return bool
*/
function apbct_is_woocommerce_add_payment_method_form()
{
if (
! apbct_is_plugin_active('woocommerce/woocommerce.php') ||
! apbct_is_in_uri('add-payment-method') ||
Comment thread
svedge marked this conversation as resolved.
! isset($_POST['woocommerce_add_payment_method'], $_POST['payment_method'])
) {
return false;
}

$nonce = '';
if (
isset($_REQUEST['woocommerce-add-payment-method-nonce']) &&
is_string($_REQUEST['woocommerce-add-payment-method-nonce'])
) {
$nonce = $_REQUEST['woocommerce-add-payment-method-nonce'];
} elseif ( isset($_REQUEST['_wpnonce']) && is_string($_REQUEST['_wpnonce']) ) {
$nonce = $_REQUEST['_wpnonce'];
}

return wp_verify_nonce($nonce, 'woocommerce-add-payment-method') !== false;
}

/**
* Function for skip in ct_contact_form_validate(). Returns false if no exclusions found, or the key of the exclusion.
* @return false|string
Expand Down Expand Up @@ -304,6 +337,8 @@ function skip_for_ct_contact_form_validate()
(isset($_POST['pass']) && isset($_POST['_pass']))
)
),
// WooCommerce Add payment method. Direct check uses the account email and type "order".
'103' => apbct_is_woocommerce_add_payment_method_form(),
);

foreach ( $exclusions as $exclusion_key => $state ) {
Expand Down
12 changes: 12 additions & 0 deletions inc/cleantalk-public-validate.php
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,18 @@ function ct_contact_form_validate()
Get::getString('wc-ajax') === 'wc_stripe_normalize_address' &&
apbct_is_plugin_active('woocommerce-gateway-stripe/woocommerce-gateway-stripe.php') &&
1 == check_ajax_referer('wc-stripe-express-checkout-normalize-address', 'security', false)
) ||
// Add payment method is checked on its own, with the account email and type "order".
(
apbct_is_plugin_active('woocommerce/woocommerce.php') &&
! empty($_POST) &&
apbct_is_plugin_active('woocommerce-gateway-stripe/woocommerce-gateway-stripe.php') &&
apbct_is_in_referer('add-payment-method') &&
Comment thread
svedge marked this conversation as resolved.
(
Get::getString('wc-ajax') === 'wc_stripe_create_setup_intent' ||
Get::getString('wc-ajax') === 'wc_stripe_init_setup_intent' ||
Post::getString('action') === 'wc_stripe_create_and_confirm_setup_intent'
)
)
) {
do_action('apbct_skipped_request', __FILE__ . ' -> ' . __FUNCTION__ . '():' . 'WOOCOMMERCE_SERVICES', $_POST);
Expand Down
2 changes: 1 addition & 1 deletion inc/cleantalk-settings.php
Original file line number Diff line number Diff line change
Expand Up @@ -471,7 +471,7 @@ function apbct_settings__set_fields()
'data__protect_logged_in' => array(
'title' => __("Protect logged in Users", 'cleantalk-spam-protect'),
'description' => __(
'Turn this option on to check for spam any submissions (comments, contact forms and etc.) from registered Users.',
'Turn this option on to check for spam any submissions (comments, contact forms and etc.) from registered Users. WooCommerce Add payment method is checked as an order.',
'cleantalk-spam-protect'
),
),
Expand Down
2 changes: 1 addition & 1 deletion js/apbct-public-bundle.min.js

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion js/apbct-public-bundle_ext-protection.min.js

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion js/apbct-public-bundle_ext-protection_gathering.min.js

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion js/apbct-public-bundle_full-protection.min.js

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion js/apbct-public-bundle_full-protection_gathering.min.js

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion js/apbct-public-bundle_gathering.min.js

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion js/apbct-public-bundle_int-protection.min.js

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion js/apbct-public-bundle_int-protection_gathering.min.js

Large diffs are not rendered by default.

7 changes: 7 additions & 0 deletions js/prebuild/apbct-public-bundle.js
Original file line number Diff line number Diff line change
Expand Up @@ -4488,6 +4488,13 @@ class ApbctHandler {
sourceSign.keepUnwrapped = true;
}

// WooCommerce Stripe UPE confirms the card on Add payment method before the form is posted.
// Keep the token unwrapped: PHP reads the top-level POST field.
if ( dataString.indexOf('action=wc_stripe_create_and_confirm_setup_intent') !== -1 ) {
sourceSign.found = 'action=wc_stripe_create_and_confirm_setup_intent';
sourceSign.keepUnwrapped = true;
}

// woocommerce add to cart is based on URL
if ( typeof ajaxObject.url === 'string' && ajaxObject.url.indexOf('wc-ajax=add_to_cart') !== -1 ) {
sourceSign.found = 'wc-ajax=add_to_cart';
Expand Down
7 changes: 7 additions & 0 deletions js/prebuild/apbct-public-bundle_ext-protection.js
Original file line number Diff line number Diff line change
Expand Up @@ -4488,6 +4488,13 @@ class ApbctHandler {
sourceSign.keepUnwrapped = true;
}

// WooCommerce Stripe UPE confirms the card on Add payment method before the form is posted.
// Keep the token unwrapped: PHP reads the top-level POST field.
if ( dataString.indexOf('action=wc_stripe_create_and_confirm_setup_intent') !== -1 ) {
sourceSign.found = 'action=wc_stripe_create_and_confirm_setup_intent';
sourceSign.keepUnwrapped = true;
}

// woocommerce add to cart is based on URL
if ( typeof ajaxObject.url === 'string' && ajaxObject.url.indexOf('wc-ajax=add_to_cart') !== -1 ) {
sourceSign.found = 'wc-ajax=add_to_cart';
Expand Down
7 changes: 7 additions & 0 deletions js/prebuild/apbct-public-bundle_ext-protection_gathering.js
Original file line number Diff line number Diff line change
Expand Up @@ -4488,6 +4488,13 @@ class ApbctHandler {
sourceSign.keepUnwrapped = true;
}

// WooCommerce Stripe UPE confirms the card on Add payment method before the form is posted.
// Keep the token unwrapped: PHP reads the top-level POST field.
if ( dataString.indexOf('action=wc_stripe_create_and_confirm_setup_intent') !== -1 ) {
sourceSign.found = 'action=wc_stripe_create_and_confirm_setup_intent';
sourceSign.keepUnwrapped = true;
}

// woocommerce add to cart is based on URL
if ( typeof ajaxObject.url === 'string' && ajaxObject.url.indexOf('wc-ajax=add_to_cart') !== -1 ) {
sourceSign.found = 'wc-ajax=add_to_cart';
Expand Down
7 changes: 7 additions & 0 deletions js/prebuild/apbct-public-bundle_full-protection.js
Original file line number Diff line number Diff line change
Expand Up @@ -4488,6 +4488,13 @@ class ApbctHandler {
sourceSign.keepUnwrapped = true;
}

// WooCommerce Stripe UPE confirms the card on Add payment method before the form is posted.
// Keep the token unwrapped: PHP reads the top-level POST field.
if ( dataString.indexOf('action=wc_stripe_create_and_confirm_setup_intent') !== -1 ) {
sourceSign.found = 'action=wc_stripe_create_and_confirm_setup_intent';
sourceSign.keepUnwrapped = true;
}

// woocommerce add to cart is based on URL
if ( typeof ajaxObject.url === 'string' && ajaxObject.url.indexOf('wc-ajax=add_to_cart') !== -1 ) {
sourceSign.found = 'wc-ajax=add_to_cart';
Expand Down
7 changes: 7 additions & 0 deletions js/prebuild/apbct-public-bundle_full-protection_gathering.js
Original file line number Diff line number Diff line change
Expand Up @@ -4488,6 +4488,13 @@ class ApbctHandler {
sourceSign.keepUnwrapped = true;
}

// WooCommerce Stripe UPE confirms the card on Add payment method before the form is posted.
// Keep the token unwrapped: PHP reads the top-level POST field.
if ( dataString.indexOf('action=wc_stripe_create_and_confirm_setup_intent') !== -1 ) {
sourceSign.found = 'action=wc_stripe_create_and_confirm_setup_intent';
sourceSign.keepUnwrapped = true;
}

// woocommerce add to cart is based on URL
if ( typeof ajaxObject.url === 'string' && ajaxObject.url.indexOf('wc-ajax=add_to_cart') !== -1 ) {
sourceSign.found = 'wc-ajax=add_to_cart';
Expand Down
7 changes: 7 additions & 0 deletions js/prebuild/apbct-public-bundle_gathering.js
Original file line number Diff line number Diff line change
Expand Up @@ -4488,6 +4488,13 @@ class ApbctHandler {
sourceSign.keepUnwrapped = true;
}

// WooCommerce Stripe UPE confirms the card on Add payment method before the form is posted.
// Keep the token unwrapped: PHP reads the top-level POST field.
if ( dataString.indexOf('action=wc_stripe_create_and_confirm_setup_intent') !== -1 ) {
sourceSign.found = 'action=wc_stripe_create_and_confirm_setup_intent';
sourceSign.keepUnwrapped = true;
}

// woocommerce add to cart is based on URL
if ( typeof ajaxObject.url === 'string' && ajaxObject.url.indexOf('wc-ajax=add_to_cart') !== -1 ) {
sourceSign.found = 'wc-ajax=add_to_cart';
Expand Down
7 changes: 7 additions & 0 deletions js/prebuild/apbct-public-bundle_int-protection.js
Original file line number Diff line number Diff line change
Expand Up @@ -4488,6 +4488,13 @@ class ApbctHandler {
sourceSign.keepUnwrapped = true;
}

// WooCommerce Stripe UPE confirms the card on Add payment method before the form is posted.
// Keep the token unwrapped: PHP reads the top-level POST field.
if ( dataString.indexOf('action=wc_stripe_create_and_confirm_setup_intent') !== -1 ) {
sourceSign.found = 'action=wc_stripe_create_and_confirm_setup_intent';
sourceSign.keepUnwrapped = true;
}

// woocommerce add to cart is based on URL
if ( typeof ajaxObject.url === 'string' && ajaxObject.url.indexOf('wc-ajax=add_to_cart') !== -1 ) {
sourceSign.found = 'wc-ajax=add_to_cart';
Expand Down
7 changes: 7 additions & 0 deletions js/prebuild/apbct-public-bundle_int-protection_gathering.js
Original file line number Diff line number Diff line change
Expand Up @@ -4488,6 +4488,13 @@ class ApbctHandler {
sourceSign.keepUnwrapped = true;
}

// WooCommerce Stripe UPE confirms the card on Add payment method before the form is posted.
// Keep the token unwrapped: PHP reads the top-level POST field.
if ( dataString.indexOf('action=wc_stripe_create_and_confirm_setup_intent') !== -1 ) {
sourceSign.found = 'action=wc_stripe_create_and_confirm_setup_intent';
sourceSign.keepUnwrapped = true;
}

// woocommerce add to cart is based on URL
if ( typeof ajaxObject.url === 'string' && ajaxObject.url.indexOf('wc-ajax=add_to_cart') !== -1 ) {
sourceSign.found = 'wc-ajax=add_to_cart';
Expand Down
7 changes: 7 additions & 0 deletions js/src/public-1-main.js
Original file line number Diff line number Diff line change
Expand Up @@ -1741,6 +1741,13 @@ class ApbctHandler {
sourceSign.keepUnwrapped = true;
}

// WooCommerce Stripe UPE confirms the card on Add payment method before the form is posted.
// Keep the token unwrapped: PHP reads the top-level POST field.
if ( dataString.indexOf('action=wc_stripe_create_and_confirm_setup_intent') !== -1 ) {
sourceSign.found = 'action=wc_stripe_create_and_confirm_setup_intent';
sourceSign.keepUnwrapped = true;
}

// woocommerce add to cart is based on URL
if ( typeof ajaxObject.url === 'string' && ajaxObject.url.indexOf('wc-ajax=add_to_cart') !== -1 ) {
sourceSign.found = 'wc-ajax=add_to_cart';
Expand Down
Loading
Loading