30if (!defined(
'NOLOGIN')) {
33if (!defined(
'NOCSRFCHECK')) {
34 define(
"NOCSRFCHECK", 1);
36if (!defined(
'NOIPCHECK')) {
37 define(
'NOIPCHECK',
'1');
39if (!defined(
'NOBROWSERNOTIF')) {
40 define(
'NOBROWSERNOTIF',
'1');
43if (!defined(
'XFRAMEOPTIONS_ALLOWALL')) {
44 define(
'XFRAMEOPTIONS_ALLOWALL',
'1');
50$entity = (!empty($_GET[
'e']) ? (int) $_GET[
'e'] : (!empty($_POST[
'e']) ? (int) $_POST[
'e'] : 1));
51if (is_numeric($entity)) {
52 define(
"DOLENTITY", $entity);
55'@phan-var-force CommonObject $object';
58require
'../../main.inc.php';
59require_once DOL_DOCUMENT_ROOT.
'/core/lib/company.lib.php';
60require_once DOL_DOCUMENT_ROOT.
'/core/lib/payments.lib.php';
61require_once DOL_DOCUMENT_ROOT.
'/core/lib/security2.lib.php';
63 require_once DOL_DOCUMENT_ROOT.
'/paypal/lib/paypal.lib.php';
64 require_once DOL_DOCUMENT_ROOT.
'/paypal/lib/paypalfunctions.lib.php';
81$hookmanager->initHooks(array(
'newpayment'));
83$langs->loadLangs(array(
"main",
"other",
"dict",
"bills",
"companies",
"paypal",
"stripe"));
88 $PAYPALTOKEN =
GETPOST(
'TOKEN');
89 if (empty($PAYPALTOKEN)) {
90 $PAYPALTOKEN =
GETPOST(
'token');
92 $PAYPALPAYERID =
GETPOST(
'PAYERID');
93 if (empty($PAYPALPAYERID)) {
94 $PAYPALPAYERID =
GETPOST(
'PayerID');
103$suffix =
GETPOST(
"suffix",
'aZ09');
109if (preg_match(
'/PM=([^\.]+)/', $FULLTAG, $reg)) {
110 $paymentmethod = $reg[1];
112if (empty($paymentmethod)) {
116 dol_syslog(
"***** paymentko.php was called with a non valid parameter FULLTAG=".$FULLTAG, LOG_WARNING, 0,
'_payment');
117 http_response_code(400);
118 print
'Bad request: the back url does not contain a valid fulltag parameter, required to find the payment method used.';
121 dol_syslog(
"paymentko.php: paymentmethod=".$paymentmethod, LOG_DEBUG, 0,
'_payment');
126$ws = preg_match(
'/WS=([^\.]+)/', $FULLTAG, $reg_ws) ? $reg_ws[1] : 0;
128 dol_syslog(
"paymentko.php: page is invoked from a website with ref ".$ws.
". It performs actions and then redirects back to this website. A page with ref paymentko must be created for this website.", LOG_DEBUG, 0,
'_payment');
132$validpaymentmethod = getValidOnlinePaymentMethods($paymentmethod);
135if (empty($validpaymentmethod)) {
146$ws_virtuelhost =
null;
148$doactionsthenredirect = 0;
150 $doactionsthenredirect = 1;
151 include_once DOL_DOCUMENT_ROOT.
'/website/class/website.class.php';
153 $result = $website->fetch(0, $ws);
155 $ws_virtuelhost = $website->virtualhost;
156 $ws_id = $website->id;
172dol_syslog(
"Callback url when an online payment is refused or canceled. query_string=".(empty($_SERVER[
"QUERY_STRING"]) ?
'' : $_SERVER[
"QUERY_STRING"]).
" script_uri=".(empty($_SERVER[
"SCRIPT_URI"]) ?
'' : $_SERVER[
"SCRIPT_URI"]), LOG_DEBUG, 0,
'_payment');
175foreach ($_POST as $k => $v) {
176 if (is_scalar($k) && is_scalar($v)) {
177 $tracepost .=
"$k - $v\n";
180dol_syslog(
"POST=".$tracepost, LOG_DEBUG, 0,
'_payment');
182dol_syslog(
"paymentkosessioncode=".
GETPOST(
'paymentkosessioncode').
" SESSION['paymentkosessioncode']=".$_SESSION[
'paymentkosessioncode'], LOG_DEBUG, 0,
'_payment');
190if (!empty($_SESSION[
'ipaddress'])) {
193 $onlinetoken = empty($PAYPALTOKEN) ? $_SESSION[
'onlinetoken'] : $PAYPALTOKEN;
194 $payerID = empty($PAYPALPAYERID) ? $_SESSION[
'payerID'] : $PAYPALPAYERID;
196 $paymentType = $_SESSION[
'PaymentType'] ??
'';
197 $currencyCodeType = $_SESSION[
'currencyCodeType'];
198 $FinalPaymentAmt = $_SESSION[
'FinalPaymentAmt'];
200 $ipaddress = $_SESSION[
'ipaddress'];
201 $errormessage = $_SESSION[
'errormessage'];
204 if (is_object($object) && method_exists($object,
'call_trigger')) {
206 $result =
$object->call_trigger(
'PAYMENTONLINE_PAYMENT_KO', $user);
219 $myCompanyDefaultLang = (string)
$mysoc->default_lang;
220 if (empty($myCompanyDefaultLang) || $myCompanyDefaultLang ===
'auto') {
227 $companylangs->setDefaultLang($myCompanyDefaultLang);
228 $companylangs->loadLangs(array(
'main',
'members',
'bills',
'paypal',
'stripe'));
231 $sendto = $sendemail;
233 $urlback = $_SERVER[
"REQUEST_URI"];
234 $topic =
'['.$appli.
'] '.$companylangs->transnoentitiesnoconv(
"NewOnlinePaymentFailed");
236 $content .=
'<span style="color: orange">'.$companylangs->transnoentitiesnoconv(
"ValidationOfOnlinePaymentFailed").
"</span>\n";
238 $content .=
"<br><br>\n";
239 $content .=
'<u>'.$companylangs->transnoentitiesnoconv(
"TechnicalInformation").
":</u><br>\n";
240 $content .= $companylangs->transnoentitiesnoconv(
"OnlinePaymentSystem").
': <strong>'.$paymentmethod.
"</strong><br>\n";
241 $content .= $companylangs->transnoentitiesnoconv(
"ReturnURLAfterPayment").
': '.$urlback.
"<br>\n";
242 $content .= $companylangs->transnoentitiesnoconv(
"Error").
': '.$errormessage.
"<br>\n";
243 $content .=
"<br>\n";
244 $content .=
"tag=".$fulltag.
" token=".$onlinetoken.
" paymentType=".$paymentType.
" currencycodeType=".$currencyCodeType.
" payerId=".$payerID.
" ipaddress=".$ipaddress.
" FinalPaymentAmt=".$FinalPaymentAmt;
248 require_once DOL_DOCUMENT_ROOT.
'/core/class/CMailFile.class.php';
249 $mailfile =
new CMailFile($topic, $sendto, $from, $content, array(), array(), array(),
'',
'', 0, $ishtml ? 1 : 0);
251 $result = $mailfile->sendfile();
253 dol_syslog(
"EMail sent to ".$sendto, LOG_DEBUG, 0,
'_payment');
255 dol_syslog(
"Failed to send EMail to ".$sendto, LOG_ERR, 0,
'_payment');
259 unset($_SESSION[
'ipaddress']);
263if (empty($doactionsthenredirect)) {
266 $head =
'<link rel="stylesheet" type="text/css" href="' .
getDolGlobalString(
'ONLINE_PAYMENT_CSS_URL').
'?lang='.$langs->defaultlang.
'">'.
"\n";
269 $conf->dol_hide_topmenu = 1;
270 $conf->dol_hide_leftmenu = 1;
272 $replacemainarea = (empty(
$conf->dol_hide_leftmenu) ?
'<div>' :
'').
'<div>';
273 llxHeader($head, $langs->trans(
"PaymentForm"),
'',
'', 0, 0,
'',
'',
'',
'onlinepaymentbody', $replacemainarea);
277 print
'<span id="dolpaymentspan"></span>'.
"\n";
278 print
'<div id="dolpaymentdiv" align="center">'.
"\n";
282 $logosmall =
$mysoc->logo_small;
284 $paramlogo =
'ONLINE_PAYMENT_LOGO_'.$suffix;
294 if (!empty($logosmall) && is_readable(
$conf->mycompany->dir_output.
'/logos/thumbs/'.$logosmall)) {
295 $urllogo = DOL_URL_ROOT.
'/viewimage.php?modulepart=mycompany&entity='.
$conf->entity.
'&file='.urlencode(
'logos/thumbs/'.$logosmall);
296 $urllogofull =
$dolibarr_main_url_root.
'/viewimage.php?modulepart=mycompany&entity='.
$conf->entity.
'&file='.urlencode(
'logos/thumbs/'.$logosmall);
297 } elseif (!empty($logo) && is_readable(
$conf->mycompany->dir_output.
'/logos/'.$logo)) {
298 $urllogo = DOL_URL_ROOT.
'/viewimage.php?modulepart=mycompany&entity='.
$conf->entity.
'&file='.urlencode(
'logos/'.$logo);
304 print
'<div class="backgreypublicpayment">';
305 print
'<div class="logopublicpayment">';
306 print
'<img id="dolpaymentlogo" src="'.$urllogo.
'"';
310 print
'<div class="poweredbypublicpayment opacitymedium right"><a class="poweredbyhref" href="https://www.dolibarr.org?utm_medium=website&utm_source=poweredby" target="dolibarr" rel="noopener">'.$langs->trans(
"PoweredBy").
'<br><img class="poweredbyimg" src="'.DOL_URL_ROOT.
'/theme/dolibarr_logo.svg" width="80px"></a></div>';
315 print
'<div class="backimagepublicpayment">';
316 print
'<img id="idMAIN_IMAGE_PUBLIC_PAYMENT" src="' .
getDolGlobalString(
'MAIN_IMAGE_PUBLIC_PAYMENT').
'">';
324 print $langs->trans(
"YourPaymentHasNotBeenRecorded").
"<br><br>";
326 $key =
'ONLINE_PAYMENT_MESSAGE_KO';
328 print
$conf->global->$key;
332 $ref =
GETPOST(
'ref',
'alphanohtml');
333 $tag =
GETPOST(
'tag',
'alpha');
334 require_once DOL_DOCUMENT_ROOT.
'/core/lib/payments.lib.php';
336 $urlsubscription = getOnlinePaymentUrl(0, ($type ? $type :
'free'), $ref, $FinalPaymentAmt, $tag);
338 print $langs->trans(
"ClickHereToTryAgain", $urlsubscription);
354if (!empty($doactionsthenredirect)) {
357 $_SESSION[
'paymentkosessionkey'] = $randomseckey;
360 if (!defined(
'USEDOLIBARRSERVER') && !empty($ws_virtuelhost)) {
361 $ext_urlko = $ws_virtuelhost .
'/paymentko.php?paymentkosessioncode='.urlencode($randomseckey).
'&fulltag='.$FULLTAG;
363 $ext_urlko = DOL_URL_ROOT.
'/public/website/index.php?paymentkosessioncode='.urlencode($randomseckey).
'&website='.urlencode($ws).
'&pageref=paymentko&fulltag='.$FULLTAG;
366 dol_syslog(
"Now do a redirect using Location : ".$ext_urlko, LOG_DEBUG, 0,
'_payment');
367 header(
"Location: ".$ext_urlko);
if(! $sortfield) if(! $sortorder) $object
global $dolibarr_main_url_root
llxFooter($comment='', $zone='private', $disabledoutputofmessages=0)
Empty footer.
if(!defined('NOREQUIRESOC')) if(!defined( 'NOREQUIRETRAN')) if(!defined('NOTOKENRENEWAL')) if(!defined( 'NOREQUIREMENU')) if(!defined('NOREQUIREHTML')) if(!defined( 'NOREQUIREAJAX')) llxHeader($head='', $title='', $help_url='', $target='', $disablejs=0, $disablehead=0, $arrayofjs='', $arrayofcss='', $morequerystring='', $morecssonbody='', $replacemainareaby='', $disablenofollow=0, $disablenoindex=0)
Empty header.
Class to send emails (with attachments or not) Usage: $mailfile = new CMailFile($subject,...
Class to manage translations.
htmlPrintOnlineFooter($fromcompany, $langs, $addformmessage=0, $suffix='', $object=null)
Show footer of company in HTML public pages.
getLanguageCodeFromCountryCode($countrycode)
Return default language from country code.
GETPOST($paramname, $check='alphanohtml', $method=0, $filter=null, $options=null, $noreplace=0, $nodefault=0)
Return value of a param into GET or POST supervariable.
dol_textishtml($msg, $option=0)
Return if a text is a html content.
getDolGlobalString($key, $default='')
Return a Dolibarr global constant string value.
isModEnabled($module)
Is Dolibarr module enabled.
dol_syslog($message, $level=LOG_INFO, $ident=0, $suffixinfilename='', $restricttologhandler='', $logcontext=null)
Write log message into outputs.
getRandomPassword($generic=false, $replaceambiguouschars=null, $length=32)
Return a generated password using default module.
httponly_accessforbidden($message='1', $http_response_code=403, $stringalreadysanitized=0)
Show a message to say access is forbidden and stop program.