Fix securekey for new online payment form

This commit is contained in:
Laurent Destailleur 2018-05-12 11:23:40 +02:00
parent 94ccb44673
commit 63ed5dcccc
4 changed files with 26 additions and 23 deletions

View File

@ -244,7 +244,7 @@ if (empty($reshook))
$substitutionarray['__SECUREKEYPAYMENT_CONTRACTLINE__']=dol_hash($conf->global->PAYMENT_SECURITY_TOKEN . 'contractline' . $obj->source_id, 2); $substitutionarray['__SECUREKEYPAYMENT_CONTRACTLINE__']=dol_hash($conf->global->PAYMENT_SECURITY_TOKEN . 'contractline' . $obj->source_id, 2);
} }
} }
/* For backward compatibility */ /* For backward compatibility, deprecated */
if (! empty($conf->paypal->enabled) && ! empty($conf->global->PAYPAL_SECURITY_TOKEN)) if (! empty($conf->paypal->enabled) && ! empty($conf->global->PAYPAL_SECURITY_TOKEN))
{ {
$substitutionarray['__SECUREKEYPAYPAL__']=dol_hash($conf->global->PAYPAL_SECURITY_TOKEN, 2); $substitutionarray['__SECUREKEYPAYPAL__']=dol_hash($conf->global->PAYPAL_SECURITY_TOKEN, 2);

View File

@ -35,8 +35,9 @@
* MEMBER_NEWFORM_FORCECOUNTRYCODE Force country * MEMBER_NEWFORM_FORCECOUNTRYCODE Force country
*/ */
define("NOLOGIN",1); // This means this output page does not require to be logged. if (! defined('NOLOGIN')) define("NOLOGIN",1); // This means this output page does not require to be logged.
define("NOCSRFCHECK",1); // We accept to go on this page from external web site. if (! defined('NOCSRFCHECK')) define("NOCSRFCHECK",1); // We accept to go on this page from external web site.
if (! defined('NOIPCHECK')) define('NOIPCHECK','1'); // Do not check IP defined into conf $dolibarr_main_restrict_ip
// For MultiCompany module. // For MultiCompany module.
// Do not use GETPOST here, function is not defined and define must be done before including main.inc.php // Do not use GETPOST here, function is not defined and define must be done before including main.inc.php
@ -356,7 +357,7 @@ if ($action == 'add')
if ($conf->global->MEMBER_NEWFORM_PAYONLINE == 'all') if ($conf->global->MEMBER_NEWFORM_PAYONLINE == 'all')
{ {
$urlback=DOL_MAIN_URL_ROOT.'/public/payment/newpayment.php?from=membernewform&source=membersubscription&ref='.urlencode($adh->ref); $urlback=DOL_MAIN_URL_ROOT.'/public/payment/newpayment.php?from=membernewform&source=membersubscription&ref='.urlencode($adh->ref);
if (price2num(GETPOST('amount'))) $urlback.='&amount='.price2num(GETPOST('amount')); if (price2num(GETPOST('amount','alpha'))) $urlback.='&amount='.price2num(GETPOST('amount','alpha'));
if (GETPOST('email')) $urlback.='&email='.urlencode(GETPOST('email')); if (GETPOST('email')) $urlback.='&email='.urlencode(GETPOST('email'));
if (! empty($conf->global->PAYMENT_SECURITY_TOKEN)) if (! empty($conf->global->PAYMENT_SECURITY_TOKEN))
{ {
@ -373,51 +374,51 @@ if ($action == 'add')
else if ($conf->global->MEMBER_NEWFORM_PAYONLINE == 'paybox') else if ($conf->global->MEMBER_NEWFORM_PAYONLINE == 'paybox')
{ {
$urlback=DOL_MAIN_URL_ROOT.'/public/paybox/newpayment.php?from=membernewform&source=membersubscription&ref='.urlencode($adh->ref); $urlback=DOL_MAIN_URL_ROOT.'/public/paybox/newpayment.php?from=membernewform&source=membersubscription&ref='.urlencode($adh->ref);
if (price2num(GETPOST('amount'))) $urlback.='&amount='.price2num(GETPOST('amount')); if (price2num(GETPOST('amount','alpha'))) $urlback.='&amount='.price2num(GETPOST('amount','alpha'));
if (GETPOST('email')) $urlback.='&email='.urlencode(GETPOST('email')); if (GETPOST('email')) $urlback.='&email='.urlencode(GETPOST('email'));
if (! empty($conf->global->PAYBOX_SECURITY_TOKEN)) if (! empty($conf->global->PAYMENT_SECURITY_TOKEN))
{ {
if (! empty($conf->global->PAYBOX_SECURITY_TOKEN_UNIQUE)) if (! empty($conf->global->PAYMENT_SECURITY_TOKEN_UNIQUE))
{ {
$urlback.='&securekey='.urlencode(dol_hash($conf->global->PAYBOX_SECURITY_TOKEN . 'membersubscription' . $adh->ref, 2)); $urlback.='&securekey='.urlencode(dol_hash($conf->global->PAYMENT_SECURITY_TOKEN . 'membersubscription' . $adh->ref, 2));
} }
else else
{ {
$urlback.='&securekey='.urlencode($conf->global->PAYBOX_SECURITY_TOKEN); $urlback.='&securekey='.urlencode($conf->global->PAYMENT_SECURITY_TOKEN);
} }
} }
} }
else if ($conf->global->MEMBER_NEWFORM_PAYONLINE == 'paypal') else if ($conf->global->MEMBER_NEWFORM_PAYONLINE == 'paypal')
{ {
$urlback=DOL_MAIN_URL_ROOT.'/public/paypal/newpayment.php?from=membernewform&source=membersubscription&ref='.urlencode($adh->ref); $urlback=DOL_MAIN_URL_ROOT.'/public/paypal/newpayment.php?from=membernewform&source=membersubscription&ref='.urlencode($adh->ref);
if (price2num(GETPOST('amount'))) $urlback.='&amount='.price2num(GETPOST('amount')); if (price2num(GETPOST('amount','alpha'))) $urlback.='&amount='.price2num(GETPOST('amount','alpha'));
if (GETPOST('email')) $urlback.='&email='.urlencode(GETPOST('email')); if (GETPOST('email')) $urlback.='&email='.urlencode(GETPOST('email'));
if (! empty($conf->global->PAYPAL_SECURITY_TOKEN)) if (! empty($conf->global->PAYMENT_SECURITY_TOKEN))
{ {
if (! empty($conf->global->PAYPAL_SECURITY_TOKEN_UNIQUE)) if (! empty($conf->global->PAYMENT_SECURITY_TOKEN_UNIQUE))
{ {
$urlback.='&securekey='.urlencode(dol_hash($conf->global->PAYPAL_SECURITY_TOKEN . 'membersubscription' . $adh->ref, 2)); $urlback.='&securekey='.urlencode(dol_hash($conf->global->PAYMENT_SECURITY_TOKEN . 'membersubscription' . $adh->ref, 2));
} }
else else
{ {
$urlback.='&securekey='.urlencode($conf->global->PAYPAL_SECURITY_TOKEN); $urlback.='&securekey='.urlencode($conf->global->PAYMENT_SECURITY_TOKEN);
} }
} }
} }
else if ($conf->global->MEMBER_NEWFORM_PAYONLINE == 'stripe') else if ($conf->global->MEMBER_NEWFORM_PAYONLINE == 'stripe')
{ {
$urlback=DOL_MAIN_URL_ROOT.'/public/stripe/newpayment.php?from=membernewform&source=membersubscription&ref='.$adh->ref; $urlback=DOL_MAIN_URL_ROOT.'/public/stripe/newpayment.php?from=membernewform&source=membersubscription&ref='.$adh->ref;
if (price2num(GETPOST('amount'))) $urlback.='&amount='.price2num(GETPOST('amount')); if (price2num(GETPOST('amount','alpha'))) $urlback.='&amount='.price2num(GETPOST('amount','alpha'));
if (GETPOST('email')) $urlback.='&email='.urlencode(GETPOST('email')); if (GETPOST('email')) $urlback.='&email='.urlencode(GETPOST('email'));
if (! empty($conf->global->STRIPE_SECURITY_TOKEN)) if (! empty($conf->global->PAYMENT_SECURITY_TOKEN))
{ {
if (! empty($conf->global->STRIPE_SECURITY_TOKEN_UNIQUE)) if (! empty($conf->global->PAYMENT_SECURITY_TOKEN_UNIQUE))
{ {
$urlback.='&securekey='.urlencode(dol_hash($conf->global->STRIPE_SECURITY_TOKEN . 'membersubscription' . $adh->ref, 2)); $urlback.='&securekey='.urlencode(dol_hash($conf->global->PAYMENT_SECURITY_TOKEN . 'membersubscription' . $adh->ref, 2));
} }
else else
{ {
$urlback.='&securekey='.urlencode($conf->global->STRIPE_SECURITY_TOKEN); $urlback.='&securekey='.urlencode($conf->global->PAYMENT_SECURITY_TOKEN);
} }
} }
} }

View File

@ -24,8 +24,9 @@
* \brief File to show a public card of a member * \brief File to show a public card of a member
*/ */
define("NOLOGIN",1); // This means this output page does not require to be logged. if (! defined('NOLOGIN')) define("NOLOGIN",1); // This means this output page does not require to be logged.
define("NOCSRFCHECK",1); // We accept to go on this page from external web site. if (! defined('NOCSRFCHECK')) define("NOCSRFCHECK",1); // We accept to go on this page from external web site.
if (! defined('NOIPCHECK')) define('NOIPCHECK','1'); // Do not check IP defined into conf $dolibarr_main_restrict_ip
// For MultiCompany module. // For MultiCompany module.
// Do not use GETPOST here, function is not defined and define must be done before including main.inc.php // Do not use GETPOST here, function is not defined and define must be done before including main.inc.php

View File

@ -24,8 +24,9 @@
* \brief File sample to list members * \brief File sample to list members
*/ */
define("NOLOGIN",1); // This means this output page does not require to be logged. if (! defined('NOLOGIN')) define("NOLOGIN",1); // This means this output page does not require to be logged.
define("NOCSRFCHECK",1); // We accept to go on this page from external web site. if (! defined('NOCSRFCHECK')) define("NOCSRFCHECK",1); // We accept to go on this page from external web site.
if (! defined('NOIPCHECK')) define('NOIPCHECK','1'); // Do not check IP defined into conf $dolibarr_main_restrict_ip
// For MultiCompany module. // For MultiCompany module.
// Do not use GETPOST here, function is not defined and define must be done before including main.inc.php // Do not use GETPOST here, function is not defined and define must be done before including main.inc.php