dolibarr 21.0.0-beta
paymentko.php
Go to the documentation of this file.
1<?php
2/* Copyright (C) 2001-2002 Rodolphe Quiedeville <rodolphe@quiedeville.org>
3 * Copyright (C) 2006-2013 Laurent Destailleur <eldy@users.sourceforge.net>
4 * Copyright (C) 2012 Regis Houssin <regis.houssin@inodbox.com>
5 * Copyright (C) 2024 Frédéric France <frederic.france@free.fr>
6 * Copyright (C) 2024 MDW <mdeweerd@users.noreply.github.com>
7 *
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 3 of the License, or
11 * (at your option) any later version.
12 *
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
17 *
18 * You should have received a copy of the GNU General Public License
19 * along with this program. If not, see <https://www.gnu.org/licenses/>.
20 */
21
30if (!defined('NOLOGIN')) {
31 define("NOLOGIN", 1); // This means this output page does not require to be logged.
32}
33if (!defined('NOCSRFCHECK')) {
34 define("NOCSRFCHECK", 1); // We accept to go on this page from external web site.
35}
36if (!defined('NOIPCHECK')) {
37 define('NOIPCHECK', '1'); // Do not check IP defined into conf $dolibarr_main_restrict_ip
38}
39if (!defined('NOBROWSERNOTIF')) {
40 define('NOBROWSERNOTIF', '1');
41}
42
43// For MultiCompany module.
44// Do not use GETPOST here, function is not defined and this test must be done before including main.inc.php
45// Because 2 entities can have the same ref.
46$entity = (!empty($_GET['e']) ? (int) $_GET['e'] : (!empty($_POST['e']) ? (int) $_POST['e'] : 1));
47if (is_numeric($entity)) {
48 define("DOLENTITY", $entity);
49}
50
51'@phan-var-force CommonObject $object';
52
53// Load Dolibarr environment
54require '../../main.inc.php';
55require_once DOL_DOCUMENT_ROOT.'/core/lib/company.lib.php';
56require_once DOL_DOCUMENT_ROOT.'/core/lib/payments.lib.php';
57
58if (isModEnabled('paypal')) {
59 require_once DOL_DOCUMENT_ROOT.'/paypal/lib/paypal.lib.php';
60 require_once DOL_DOCUMENT_ROOT.'/paypal/lib/paypalfunctions.lib.php';
61}
62
73$langs->loadLangs(array("main", "other", "dict", "bills", "companies", "paybox", "paypal", "stripe"));
74
75if (isModEnabled('paypal')) {
76 $PAYPALTOKEN = GETPOST('TOKEN');
77 if (empty($PAYPALTOKEN)) {
78 $PAYPALTOKEN = GETPOST('token');
79 }
80 $PAYPALPAYERID = GETPOST('PAYERID');
81 if (empty($PAYPALPAYERID)) {
82 $PAYPALPAYERID = GETPOST('PayerID');
83 }
84}
85if (isModEnabled('paybox')) {
86}
87if (isModEnabled('stripe')) {
88}
89
90$FULLTAG = GETPOST('FULLTAG');
91if (empty($FULLTAG)) {
92 $FULLTAG = GETPOST('fulltag');
93}
94
95$suffix = GETPOST("suffix", 'aZ09');
96
97
98// Detect $paymentmethod
99$paymentmethod = '';
100$reg = array();
101if (preg_match('/PM=([^\.]+)/', $FULLTAG, $reg)) {
102 $paymentmethod = $reg[1];
103}
104if (empty($paymentmethod)) {
105 dol_print_error(null, 'The back url does not contain a parameter fulltag that should help us to find the payment method used');
106 exit;
107} else {
108 dol_syslog("paymentmethod=".$paymentmethod);
109}
110
111// Detect $ws
112$ws = preg_match('/WS=([^\.]+)/', $FULLTAG, $reg_ws) ? $reg_ws[1] : 0;
113if ($ws) {
114 dol_syslog("Paymentko.php page is invoked from a website with ref ".$ws.". It performs actions and then redirects back to this website. A page with ref paymentko must be created for this website.", LOG_DEBUG, 0, '_payment');
115}
116
117
118$validpaymentmethod = getValidOnlinePaymentMethods($paymentmethod);
119
120// Security check
121if (empty($validpaymentmethod)) {
122 httponly_accessforbidden('No valid payment mode');
123}
124
125
126$object = new stdClass(); // For triggers
129/*
130 * Actions
131 */
132
133// None
134
135
136
137/*
138 * View
139 */
140
141// Check if we have redirtodomain to do.
142if ($ws) {
143 $doactionsthenredirect = 1;
144}
145
146
147dol_syslog("Callback url when an online payment is refused or canceled. query_string=".(empty($_SERVER["QUERY_STRING"]) ? '' : $_SERVER["QUERY_STRING"])." script_uri=".(empty($_SERVER["SCRIPT_URI"]) ? '' : $_SERVER["SCRIPT_URI"]), LOG_DEBUG, 0, '_payment');
148
149$tracepost = "";
150foreach ($_POST as $k => $v) {
151 if (is_scalar($k) && is_scalar($v)) {
152 $tracepost .= "$k - $v\n";
153 }
154}
155dol_syslog("POST=".$tracepost, LOG_DEBUG, 0, '_payment');
156
157
158// Set $appli for emails title
159$appli = $mysoc->name;
160$error = 0;
161
162
163if (!empty($_SESSION['ipaddress'])) { // To avoid to make action twice
164 // Get on url call
165 $fulltag = $FULLTAG;
166 $onlinetoken = empty($PAYPALTOKEN) ? $_SESSION['onlinetoken'] : $PAYPALTOKEN;
167 $payerID = empty($PAYPALPAYERID) ? $_SESSION['payerID'] : $PAYPALPAYERID;
168 // Set by newpayment.php
169 $paymentType = $_SESSION['PaymentType'];
170 $currencyCodeType = $_SESSION['currencyCodeType'];
171 $FinalPaymentAmt = $_SESSION['FinalPaymentAmt'];
172 // From env
173 $ipaddress = $_SESSION['ipaddress'];
174 $errormessage = $_SESSION['errormessage'];
175
176 if (is_object($object) && method_exists($object, 'call_trigger')) {
177 // Call trigger @phan-suppress-next-line PhanUndeclaredMethod
178 $result = $object->call_trigger('PAYMENTONLINE_PAYMENT_KO', $user);
179 if ($result < 0) {
180 $error++;
181 }
182 // End call triggers
183 }
184
185 // Send an email
186 $sendemail = getDolGlobalString('ONLINE_PAYMENT_SENDEMAIL');
187
188 // Send warning of error to administrator
189 if ($sendemail) {
190 $companylangs = new Translate('', $conf);
191 $companylangs->setDefaultLang($mysoc->default_lang);
192 $companylangs->loadLangs(array('main', 'members', 'bills', 'paypal', 'paybox', 'stripe'));
193
194 $from = getDolGlobalString('MAILING_EMAIL_FROM', getDolGlobalString("MAIN_MAIL_EMAIL_FROM"));
195 $sendto = $sendemail;
196
197 $urlback = $_SERVER["REQUEST_URI"];
198 $topic = '['.$appli.'] '.$companylangs->transnoentitiesnoconv("NewOnlinePaymentFailed");
199 $content = "";
200 $content .= '<span style="color: orange">'.$companylangs->transnoentitiesnoconv("ValidationOfOnlinePaymentFailed")."</span>\n";
201
202 $content .= "<br><br>\n";
203 $content .= '<u>'.$companylangs->transnoentitiesnoconv("TechnicalInformation").":</u><br>\n";
204 $content .= $companylangs->transnoentitiesnoconv("OnlinePaymentSystem").': <strong>'.$paymentmethod."</strong><br>\n";
205 $content .= $companylangs->transnoentitiesnoconv("ReturnURLAfterPayment").': '.$urlback."<br>\n";
206 $content .= $companylangs->transnoentitiesnoconv("Error").': '.$errormessage."<br>\n";
207 $content .= "<br>\n";
208 $content .= "tag=".$fulltag." token=".$onlinetoken." paymentType=".$paymentType." currencycodeType=".$currencyCodeType." payerId=".$payerID." ipaddress=".$ipaddress." FinalPaymentAmt=".$FinalPaymentAmt;
209
210 $ishtml = dol_textishtml($content); // May contain urls
211
212 require_once DOL_DOCUMENT_ROOT.'/core/class/CMailFile.class.php';
213 $mailfile = new CMailFile($topic, $sendto, $from, $content, array(), array(), array(), '', '', 0, $ishtml ? 1 : 0);
214
215 $result = $mailfile->sendfile();
216 if ($result) {
217 dol_syslog("EMail sent to ".$sendto, LOG_DEBUG, 0, '_payment');
218 } else {
219 dol_syslog("Failed to send EMail to ".$sendto, LOG_ERR, 0, '_payment');
220 }
221 }
222
223 unset($_SESSION['ipaddress']);
224}
225
226// Show answer page
227if (empty($doactionsthenredirect)) {
228 $head = '';
229 if (getDolGlobalString('ONLINE_PAYMENT_CSS_URL')) {
230 $head = '<link rel="stylesheet" type="text/css" href="' . getDolGlobalString('ONLINE_PAYMENT_CSS_URL').'?lang='.$langs->defaultlang.'">'."\n";
231 }
232
233 $conf->dol_hide_topmenu = 1;
234 $conf->dol_hide_leftmenu = 1;
235
236 $replacemainarea = (empty($conf->dol_hide_leftmenu) ? '<div>' : '').'<div>';
237 llxHeader($head, $langs->trans("PaymentForm"), '', '', 0, 0, '', '', '', 'onlinepaymentbody', $replacemainarea);
238
239
240 // Show ko message
241 print '<span id="dolpaymentspan"></span>'."\n";
242 print '<div id="dolpaymentdiv" align="center">'."\n";
243
244 // Show logo (search order: logo defined by PAYMENT_LOGO_suffix, then PAYMENT_LOGO, then small company logo, large company logo, theme logo, common logo)
245 // Define logo and logosmall
246 $logosmall = $mysoc->logo_small;
247 $logo = $mysoc->logo;
248 $paramlogo = 'ONLINE_PAYMENT_LOGO_'.$suffix;
249 if (getDolGlobalString($paramlogo)) {
250 $logosmall = getDolGlobalString($paramlogo);
251 } elseif (getDolGlobalString('ONLINE_PAYMENT_LOGO')) {
252 $logosmall = getDolGlobalString('ONLINE_PAYMENT_LOGO');
253 }
254 //print '<!-- Show logo (logosmall='.$logosmall.' logo='.$logo.') -->'."\n";
255 // Define urllogo
256 $urllogo = '';
257 $urllogofull = '';
258 if (!empty($logosmall) && is_readable($conf->mycompany->dir_output.'/logos/thumbs/'.$logosmall)) {
259 $urllogo = DOL_URL_ROOT.'/viewimage.php?modulepart=mycompany&amp;entity='.$conf->entity.'&amp;file='.urlencode('logos/thumbs/'.$logosmall);
260 $urllogofull = $dolibarr_main_url_root.'/viewimage.php?modulepart=mycompany&entity='.$conf->entity.'&file='.urlencode('logos/thumbs/'.$logosmall);
261 } elseif (!empty($logo) && is_readable($conf->mycompany->dir_output.'/logos/'.$logo)) {
262 $urllogo = DOL_URL_ROOT.'/viewimage.php?modulepart=mycompany&amp;entity='.$conf->entity.'&amp;file='.urlencode('logos/'.$logo);
263 $urllogofull = $dolibarr_main_url_root.'/viewimage.php?modulepart=mycompany&entity='.$conf->entity.'&file='.urlencode('logos/'.$logo);
264 }
265
266 // Output html code for logo
267 if ($urllogo) {
268 print '<div class="backgreypublicpayment">';
269 print '<div class="logopublicpayment">';
270 print '<img id="dolpaymentlogo" src="'.$urllogo.'"';
271 print '>';
272 print '</div>';
273 if (!getDolGlobalString('MAIN_HIDE_POWERED_BY')) {
274 print '<div class="poweredbypublicpayment opacitymedium right"><a class="poweredbyhref" href="https://www.dolibarr.org?utm_medium=website&utm_source=poweredby" target="dolibarr" rel="noopener">'.$langs->trans("PoweredBy").'<br><img class="poweredbyimg" src="'.DOL_URL_ROOT.'/theme/dolibarr_logo.svg" width="80px"></a></div>';
275 }
276 print '</div>';
277 }
278 if (getDolGlobalString('MAIN_IMAGE_PUBLIC_PAYMENT')) {
279 print '<div class="backimagepublicpayment">';
280 print '<img id="idMAIN_IMAGE_PUBLIC_PAYMENT" src="' . getDolGlobalString('MAIN_IMAGE_PUBLIC_PAYMENT').'">';
281 print '</div>';
282 }
283
284
285 print '<br><br>';
286
287
288 print $langs->trans("YourPaymentHasNotBeenRecorded")."<br><br>";
289
290 $key = 'ONLINE_PAYMENT_MESSAGE_KO';
291 if (getDolGlobalString($key)) {
292 print $conf->global->$key;
293 }
294
295 $type = GETPOST('s', 'alpha');
296 $ref = GETPOST('ref', 'alphanohtml');
297 $tag = GETPOST('tag', 'alpha');
298 require_once DOL_DOCUMENT_ROOT.'/core/lib/payments.lib.php';
299 if ($type || $tag) {
300 $urlsubscription = getOnlinePaymentUrl(0, ($type ? $type : 'free'), $ref, $FinalPaymentAmt, $tag);
301
302 print $langs->trans("ClickHereToTryAgain", $urlsubscription);
303 }
304
305 print "\n</div>\n";
306
307
308 htmlPrintOnlineFooter($mysoc, $langs, 0, $suffix);
309
310 llxFooter('', 'public');
311}
312
313
314$db->close();
315
316
317// If option to do a redirect somewhere else is defined.
318if (!empty($doactionsthenredirect)) {
319 // Redirect to an error page
320 // Paymentko page must be created for the specific website
321 $ext_urlko = DOL_URL_ROOT.'/public/website/index.php?website='.urlencode($ws).'&pageref=paymentko&fulltag='.$FULLTAG;
322 print "<script>window.top.location.href = '".dol_escape_js($ext_urlko)."';</script>";
323}
if( $user->socid > 0) if(! $user->hasRight('accounting', 'chartofaccount')) $object
Definition card.php:66
if(!defined('NOREQUIRESOC')) if(!defined( 'NOREQUIRETRAN')) if(!defined('NOTOKENRENEWAL')) if(!defined( 'NOREQUIREMENU')) if(!defined('NOREQUIREHTML')) if(!defined( 'NOREQUIREAJAX')) llxHeader($head='', $title='', $help_url='', $target='', $disablejs=0, $disablehead=0, $arrayofjs='', $arrayofcss='', $morequerystring='', $morecssonbody='', $replacemainareaby='', $disablenofollow=0, $disablenoindex=0)
Empty header.
Definition wrapper.php:71
Class to send emails (with attachments or not) Usage: $mailfile = new CMailFile($subject,...
Class to manage translations.
htmlPrintOnlineFooter($fromcompany, $langs, $addformmessage=0, $suffix='', $object=null)
Show footer of company in HTML pages.
llxFooter()
Footer empty.
Definition document.php:107
dol_textishtml($msg, $option=0)
Return if a text is a html content.
GETPOST($paramname, $check='alphanohtml', $method=0, $filter=null, $options=null, $noreplace=0)
Return value of a param into GET or POST supervariable.
dol_print_error($db=null, $error='', $errors=null)
Displays error message system with all the information to facilitate the diagnosis and the escalation...
getDolGlobalString($key, $default='')
Return a Dolibarr global constant string value.
dol_syslog($message, $level=LOG_INFO, $ident=0, $suffixinfilename='', $restricttologhandler='', $logcontext=null)
Write log message into outputs.
global $conf
The following vars must be defined: $type2label $form $conf, $lang, The following vars may also be de...
Definition member.php:79
httponly_accessforbidden($message='1', $http_response_code=403, $stringalreadysanitized=0)
Show a message to say access is forbidden and stop program.