Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
55 changes: 47 additions & 8 deletions lib/GaletteHelloasso/Controllers/HelloassoController.php
Original file line number Diff line number Diff line change
Expand Up @@ -92,15 +92,38 @@ public function formCheckout(Request $request, Response $response): Response
$helloasso_request = $request->getParsedBody();
$helloasso = new Helloasso($this->zdb, $this->preferences);
$adherent = new Adherent($this->zdb);
$contribution_type = new ContributionsTypes($this->zdb, (int)$helloasso_request['item_id']);

// Check the amount
$item_id = $helloasso_request['item_id'];
// Only reasons proposed to the current user can be paid
$item_id = (int)($helloasso_request['item_id'] ?? 0);
$helloasso_amounts = $helloasso->getAmounts($this->login);
$amount = $helloasso_request['amount'];
if (!isset($helloasso_amounts[$item_id])) {
$this->flash->addMessage(
'error_detected',
_T("You have to select an option.", "helloasso")
);

return $response
->withStatus(301)
->withHeader('Location', $this->routeparser->urlFor('helloasso_form'));
}
$contribution_type = new ContributionsTypes($this->zdb, $item_id);

// Check the amount, accepting a decimal comma
$amount = $helloasso_request['amount'] ?? '';
$amount = is_string($amount) ? str_replace(',', '.', trim($amount)) : '';
if (!is_numeric($amount)) {
$this->flash->addMessage(
'error_detected',
_T("Please enter an amount.", "helloasso")
);

return $response
->withStatus(301)
->withHeader('Location', $this->routeparser->urlFor('helloasso_form'));
}
$amount_check = $helloasso_amounts[$item_id]['amount'];

if ($amount < $amount_check) {
if ((float)$amount < (float)$amount_check) {
$this->flash->addMessage(
'error_detected',
_T("The amount you've entered is lower than the minimum amount for the selected option. Please choose another option or change the amount.", "helloasso")
Expand All @@ -122,7 +145,7 @@ public function formCheckout(Request $request, Response $response): Response

$contains_donation = $contribution_type->isExtension() ? false : true;

$checkout = $helloasso->checkout($metadata, $amount * 100, $contains_donation);
$checkout = $helloasso->checkout($metadata, (float)$amount * 100, $contains_donation);

if (!$checkout) {
$this->flash->addMessage(
Expand All @@ -134,6 +157,13 @@ public function formCheckout(Request $request, Response $response): Response
->withStatus(301)
->withHeader('Location', $this->routeparser->urlFor('helloasso_form'));
} else {
//the return page will only display checkouts started here
if (isset($checkout['id'])) {
$checkouts = $this->session->helloasso_checkouts ?? [];
$checkouts[] = (string)$checkout['id'];
$this->session->helloasso_checkouts = array_slice($checkouts, -10);
}

return $response
->withStatus(301)
->withHeader('Location', $checkout['redirectUrl']);
Expand Down Expand Up @@ -319,8 +349,9 @@ public function storePreferences(Request $request, Response $response): Response
if (isset($post['helloasso_client_id'])) {
$helloasso->setClientId($post['helloasso_client_id']);
}
if (isset($post['helloasso_client_secret'])) {
$helloasso->setClientSecret($post['helloasso_client_secret']);
//secret is never displayed, an empty value keeps the current one
if (isset($post['helloasso_client_secret']) && trim($post['helloasso_client_secret']) !== '') {
$helloasso->setClientSecret(trim($post['helloasso_client_secret']));
}
}
if (isset($post['inactives'])) {
Expand Down Expand Up @@ -501,6 +532,14 @@ public function returnUrl(Request $request, Response $response): Response
throw new HttpNotFoundException($request);
}

if (!in_array((string)$checkout_id, $this->session->helloasso_checkouts ?? [], true)) {
Analog::log(
'HelloAsso checkout #' . $checkout_id . ' has not been started from this session, its details are not displayed.',
Analog::WARNING
);
throw new HttpForbiddenException($request);
}

try {
$helloasso = new Helloasso($this->zdb, $this->preferences);
$tokens = $helloasso->getTokens();
Expand Down
2 changes: 1 addition & 1 deletion templates/default/helloasso_history.html.twig
Original file line number Diff line number Diff line change
Expand Up @@ -205,7 +205,7 @@
<span class="icon-only">
<i class="exclamation triangle orange icon" aria-hidden="true"></i>
<span class="visually-hidden">
{{ _T("Duplicate", "helloasso") }}
{{ _T("Duplicate entry", "helloasso") }}
</span>
</span>
{% endif %}
Expand Down
9 changes: 6 additions & 3 deletions templates/default/helloasso_preferences.html.twig
Original file line number Diff line number Diff line change
Expand Up @@ -54,11 +54,14 @@
required: true
} %}

{% include "components/forms/text.html.twig" with {
{% include "components/forms/input.html.twig" with {
type: 'password',
id: 'helloasso_client_secret',
value: helloasso.getClientSecret(),
value: null,
label: _T("Your clientSecret", "helloasso"),
required: true
required: helloasso.getClientSecret() == '',
autocomplete: 'off',
placeholder: helloasso.getClientSecret() != '' ? _T("Leave empty to keep the current one") : ''
} %}

{% include "components/forms/checkbox.html.twig" with {
Expand Down
Loading
Loading