dolibarr 25.0.0-alpha
paymentko.php
Go to the documentation of this file.
1<?php
2/* Copyright (C) 2001-2002 Rodolphe Quiedeville <rodolphe@quiedeville.org>
3 * Copyright (C) 2006-2013 Laurent Destailleur <eldy@users.sourceforge.net>
4 * Copyright (C) 2012 Regis Houssin <regis.houssin@inodbox.com>
5 * Copyright (C) 2024-2025 Frédéric France <frederic.france@free.fr>
6 * Copyright (C) 2024-2025 MDW <mdeweerd@users.noreply.github.com>
7 *
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 3 of the License, or
11 * (at your option) any later version.
12 *
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
17 *
18 * You should have received a copy of the GNU General Public License
19 * along with this program. If not, see <https://www.gnu.org/licenses/>.
20 */
21
30if (!defined('NOLOGIN')) {
31 define("NOLOGIN", 1); // This means this output page does not require to be logged.
32}
33if (!defined('NOCSRFCHECK')) {
34 define("NOCSRFCHECK", 1); // We accept to go on this page from external web site.
35}
36if (!defined('NOIPCHECK')) {
37 define('NOIPCHECK', '1'); // Do not check IP defined into conf $dolibarr_main_restrict_ip
38}
39if (!defined('NOBROWSERNOTIF')) {
40 define('NOBROWSERNOTIF', '1');
41}
42
43if (!defined('XFRAMEOPTIONS_ALLOWALL')) {
44 define('XFRAMEOPTIONS_ALLOWALL', '1');
45}
46
47// For MultiCompany module.
48// Do not use GETPOST here, function is not defined and this test must be done before including main.inc.php
49// Because 2 entities can have the same ref.
50$entity = (!empty($_GET['e']) ? (int) $_GET['e'] : (!empty($_POST['e']) ? (int) $_POST['e'] : 1));
51if (is_numeric($entity)) {
52 define("DOLENTITY", $entity);
53}
54
55'@phan-var-force CommonObject $object';
56
57// Load Dolibarr environment
58require '../../main.inc.php';
59require_once DOL_DOCUMENT_ROOT.'/core/lib/company.lib.php';
60require_once DOL_DOCUMENT_ROOT.'/core/lib/payments.lib.php';
61require_once DOL_DOCUMENT_ROOT.'/core/lib/security2.lib.php';
62if (isModEnabled('paypal')) {
63 require_once DOL_DOCUMENT_ROOT.'/paypal/lib/paypal.lib.php';
64 require_once DOL_DOCUMENT_ROOT.'/paypal/lib/paypalfunctions.lib.php';
65}
66
78// Hook to be used by external payment modules (ie Payzen, ...)
79$hookmanager = new HookManager($db);
80
81$hookmanager->initHooks(array('newpayment'));
82
83$langs->loadLangs(array("main", "other", "dict", "bills", "companies", "paypal", "stripe"));
84
85$PAYPALTOKEN = "";
86$PAYPALPAYERID = "";
87if (isModEnabled('paypal')) {
88 $PAYPALTOKEN = GETPOST('TOKEN');
89 if (empty($PAYPALTOKEN)) {
90 $PAYPALTOKEN = GETPOST('token');
91 }
92 $PAYPALPAYERID = GETPOST('PAYERID');
93 if (empty($PAYPALPAYERID)) {
94 $PAYPALPAYERID = GETPOST('PayerID');
95 }
96}
97
98$FULLTAG = GETPOST('FULLTAG');
99if (empty($FULLTAG)) {
100 $FULLTAG = GETPOST('fulltag');
101}
102
103$suffix = GETPOST("suffix", 'aZ09');
104
105
106// Detect $paymentmethod
107$paymentmethod = '';
108$reg = array();
109if (preg_match('/PM=([^\.]+)/', $FULLTAG, $reg)) {
110 $paymentmethod = $reg[1];
111}
112if (empty($paymentmethod)) {
113 // Missing/invalid fulltag is a malformed client request, not a server failure: answer 400
114 // with a plain message instead of dol_print_error (which implies an internal error and
115 // returns a misleading 202 status).
116 dol_syslog("***** paymentko.php was called with a non valid parameter FULLTAG=".$FULLTAG, LOG_WARNING, 0, '_payment');
117 http_response_code(400);
118 print 'Bad request: the back url does not contain a valid fulltag parameter, required to find the payment method used.';
119 exit;
120} else {
121 dol_syslog("paymentko.php: paymentmethod=".$paymentmethod, LOG_DEBUG, 0, '_payment');
122}
123
124// Detect $ws
125$reg_ws = array();
126$ws = preg_match('/WS=([^\.]+)/', $FULLTAG, $reg_ws) ? $reg_ws[1] : 0;
127if ($ws) {
128 dol_syslog("paymentko.php: page is invoked from a website with ref ".$ws.". It performs actions and then redirects back to this website. A page with ref paymentko must be created for this website.", LOG_DEBUG, 0, '_payment');
129}
130
131
132$validpaymentmethod = getValidOnlinePaymentMethods($paymentmethod);
133
134// Security check
135if (empty($validpaymentmethod)) {
136 httponly_accessforbidden('No valid payment mode');
137}
138
139
140$object = new stdClass(); // For triggers
143$error = 0;
144
145// Check if we have redirtodomain to do.
146$ws_virtuelhost = null;
147$ws_id = 0;
148$doactionsthenredirect = 0;
149if ($ws) {
150 $doactionsthenredirect = 1;
151 include_once DOL_DOCUMENT_ROOT.'/website/class/website.class.php';
152 $website = new Website($db);
153 $result = $website->fetch(0, $ws);
154 if ($result > 0) {
155 $ws_virtuelhost = $website->virtualhost;
156 $ws_id = $website->id;
157 }
158}
159
160
161/*
162 * Actions
163 */
164
165// None
166
167
168/*
169 * View
170 */
171
172dol_syslog("Callback url when an online payment is refused or canceled. query_string=".(empty($_SERVER["QUERY_STRING"]) ? '' : $_SERVER["QUERY_STRING"])." script_uri=".(empty($_SERVER["SCRIPT_URI"]) ? '' : $_SERVER["SCRIPT_URI"]), LOG_DEBUG, 0, '_payment');
173
174$tracepost = "";
175foreach ($_POST as $k => $v) {
176 if (is_scalar($k) && is_scalar($v)) {
177 $tracepost .= "$k - $v\n";
178 }
179}
180dol_syslog("POST=".$tracepost, LOG_DEBUG, 0, '_payment');
181
182dol_syslog("paymentkosessioncode=".GETPOST('paymentkosessioncode')." SESSION['paymentkosessioncode']=".$_SESSION['paymentkosessioncode'], LOG_DEBUG, 0, '_payment');
183
184// Set $appli for emails title
185$appli = $mysoc->name;
186$error = 0;
187$FinalPaymentAmt = 0;
188
189
190if (!empty($_SESSION['ipaddress'])) { // To avoid to make action twice
191 // Get on url call
192 $fulltag = $FULLTAG;
193 $onlinetoken = empty($PAYPALTOKEN) ? $_SESSION['onlinetoken'] : $PAYPALTOKEN;
194 $payerID = empty($PAYPALPAYERID) ? $_SESSION['payerID'] : $PAYPALPAYERID;
195 // Set by newpayment.php
196 $paymentType = $_SESSION['PaymentType'] ?? '';
197 $currencyCodeType = $_SESSION['currencyCodeType'];
198 $FinalPaymentAmt = $_SESSION['FinalPaymentAmt'];
199 // From env
200 $ipaddress = $_SESSION['ipaddress'];
201 $errormessage = $_SESSION['errormessage'];
202
203 // @phpstan-ignore-next-line
204 if (is_object($object) && method_exists($object, 'call_trigger')) {
205 // Call trigger @phan-suppress-next-line PhanUndeclaredMethod
206 $result = $object->call_trigger('PAYMENTONLINE_PAYMENT_KO', $user);
207 if ($result < 0) {
208 $error++;
209 }
210 // End call triggers
211 }
212
213 // Send an email
214 $sendemail = getDolGlobalString('ONLINE_PAYMENT_SENDEMAIL');
215
216 // Send warning of error to administrator
217 if ($sendemail) {
218 // Get default language to use for the company for supervision emails
219 $myCompanyDefaultLang = (string) $mysoc->default_lang;
220 if (empty($myCompanyDefaultLang) || $myCompanyDefaultLang === 'auto') {
221 // We must guess the language from the company country. We must not use the language of the visitor. This is a technical email for supervision
222 // so it must always be into the same language.
223 $myCompanyDefaultLang = (string) getLanguageCodeFromCountryCode($mysoc->country_code);
224 }
225
226 $companylangs = new Translate('', $conf);
227 $companylangs->setDefaultLang($myCompanyDefaultLang);
228 $companylangs->loadLangs(array('main', 'members', 'bills', 'paypal', 'stripe'));
229
230 $from = getDolGlobalString("MAIN_MAIL_EMAIL_FROM");
231 $sendto = $sendemail;
232
233 $urlback = $_SERVER["REQUEST_URI"];
234 $topic = '['.$appli.'] '.$companylangs->transnoentitiesnoconv("NewOnlinePaymentFailed");
235 $content = "";
236 $content .= '<span style="color: orange">'.$companylangs->transnoentitiesnoconv("ValidationOfOnlinePaymentFailed")."</span>\n";
237
238 $content .= "<br><br>\n";
239 $content .= '<u>'.$companylangs->transnoentitiesnoconv("TechnicalInformation").":</u><br>\n";
240 $content .= $companylangs->transnoentitiesnoconv("OnlinePaymentSystem").': <strong>'.$paymentmethod."</strong><br>\n";
241 $content .= $companylangs->transnoentitiesnoconv("ReturnURLAfterPayment").': '.$urlback."<br>\n";
242 $content .= $companylangs->transnoentitiesnoconv("Error").': '.$errormessage."<br>\n";
243 $content .= "<br>\n";
244 $content .= "tag=".$fulltag." token=".$onlinetoken." paymentType=".$paymentType." currencycodeType=".$currencyCodeType." payerId=".$payerID." ipaddress=".$ipaddress." FinalPaymentAmt=".$FinalPaymentAmt;
245
246 $ishtml = dol_textishtml($content); // May contain urls
247
248 require_once DOL_DOCUMENT_ROOT.'/core/class/CMailFile.class.php';
249 $mailfile = new CMailFile($topic, $sendto, $from, $content, array(), array(), array(), '', '', 0, $ishtml ? 1 : 0);
250
251 $result = $mailfile->sendfile();
252 if ($result) {
253 dol_syslog("EMail sent to ".$sendto, LOG_DEBUG, 0, '_payment');
254 } else {
255 dol_syslog("Failed to send EMail to ".$sendto, LOG_ERR, 0, '_payment');
256 }
257 }
258
259 unset($_SESSION['ipaddress']);
260}
261
262// Show answer page
263if (empty($doactionsthenredirect)) {
264 $head = '';
265 if (getDolGlobalString('ONLINE_PAYMENT_CSS_URL')) {
266 $head = '<link rel="stylesheet" type="text/css" href="' . getDolGlobalString('ONLINE_PAYMENT_CSS_URL').'?lang='.$langs->defaultlang.'">'."\n";
267 }
268
269 $conf->dol_hide_topmenu = 1;
270 $conf->dol_hide_leftmenu = 1;
271
272 $replacemainarea = (empty($conf->dol_hide_leftmenu) ? '<div>' : '').'<div>';
273 llxHeader($head, $langs->trans("PaymentForm"), '', '', 0, 0, '', '', '', 'onlinepaymentbody', $replacemainarea);
274
275
276 // Show ko message
277 print '<span id="dolpaymentspan"></span>'."\n";
278 print '<div id="dolpaymentdiv" align="center">'."\n";
279
280 // Show logo (search order: logo defined by PAYMENT_LOGO_suffix, then PAYMENT_LOGO, then small company logo, large company logo, theme logo, common logo)
281 // Define logo and logosmall
282 $logosmall = $mysoc->logo_small;
283 $logo = $mysoc->logo;
284 $paramlogo = 'ONLINE_PAYMENT_LOGO_'.$suffix;
285 if (getDolGlobalString($paramlogo)) {
286 $logosmall = getDolGlobalString($paramlogo);
287 } elseif (getDolGlobalString('ONLINE_PAYMENT_LOGO')) {
288 $logosmall = getDolGlobalString('ONLINE_PAYMENT_LOGO');
289 }
290 //print '<!-- Show logo (logosmall='.$logosmall.' logo='.$logo.') -->'."\n";
291 // Define urllogo
292 $urllogo = '';
293 $urllogofull = '';
294 if (!empty($logosmall) && is_readable($conf->mycompany->dir_output.'/logos/thumbs/'.$logosmall)) {
295 $urllogo = DOL_URL_ROOT.'/viewimage.php?modulepart=mycompany&amp;entity='.$conf->entity.'&amp;file='.urlencode('logos/thumbs/'.$logosmall);
296 $urllogofull = $dolibarr_main_url_root.'/viewimage.php?modulepart=mycompany&entity='.$conf->entity.'&file='.urlencode('logos/thumbs/'.$logosmall);
297 } elseif (!empty($logo) && is_readable($conf->mycompany->dir_output.'/logos/'.$logo)) {
298 $urllogo = DOL_URL_ROOT.'/viewimage.php?modulepart=mycompany&amp;entity='.$conf->entity.'&amp;file='.urlencode('logos/'.$logo);
299 $urllogofull = $dolibarr_main_url_root.'/viewimage.php?modulepart=mycompany&entity='.$conf->entity.'&file='.urlencode('logos/'.$logo);
300 }
301
302 // Output html code for logo
303 if ($urllogo) {
304 print '<div class="backgreypublicpayment">';
305 print '<div class="logopublicpayment">';
306 print '<img id="dolpaymentlogo" src="'.$urllogo.'"';
307 print '>';
308 print '</div>';
309 if (!getDolGlobalString('MAIN_HIDE_POWERED_BY')) {
310 print '<div class="poweredbypublicpayment opacitymedium right"><a class="poweredbyhref" href="https://www.dolibarr.org?utm_medium=website&utm_source=poweredby" target="dolibarr" rel="noopener">'.$langs->trans("PoweredBy").'<br><img class="poweredbyimg" src="'.DOL_URL_ROOT.'/theme/dolibarr_logo.svg" width="80px"></a></div>';
311 }
312 print '</div>';
313 }
314 if (getDolGlobalString('MAIN_IMAGE_PUBLIC_PAYMENT')) {
315 print '<div class="backimagepublicpayment">';
316 print '<img id="idMAIN_IMAGE_PUBLIC_PAYMENT" src="' . getDolGlobalString('MAIN_IMAGE_PUBLIC_PAYMENT').'">';
317 print '</div>';
318 }
319
320
321 print '<br><br>';
322
323
324 print $langs->trans("YourPaymentHasNotBeenRecorded")."<br><br>";
325
326 $key = 'ONLINE_PAYMENT_MESSAGE_KO';
327 if (getDolGlobalString($key)) {
328 print $conf->global->$key;
329 }
330
331 $type = GETPOST('s', 'alpha');
332 $ref = GETPOST('ref', 'alphanohtml');
333 $tag = GETPOST('tag', 'alpha');
334 require_once DOL_DOCUMENT_ROOT.'/core/lib/payments.lib.php';
335 if ($type || $tag) {
336 $urlsubscription = getOnlinePaymentUrl(0, ($type ? $type : 'free'), $ref, $FinalPaymentAmt, $tag);
337
338 print $langs->trans("ClickHereToTryAgain", $urlsubscription);
339 }
340
341 print "\n</div>\n";
342
343
344 htmlPrintOnlineFooter($mysoc, $langs, 0, $suffix);
345
346 llxFooter('', 'public');
347}
348
349
350$db->close();
351
352
353// If option to do a redirect somewhere else is defined.
354if (!empty($doactionsthenredirect)) {
355 // Redirect to an error page
356 $randomseckey = getRandomPassword(true, null, 20);
357 $_SESSION['paymentkosessionkey'] = $randomseckey; // key between paymentok.php to another page like a paymentko of the website.
358
359 // Paymentko page must be created for the specific website
360 if (!defined('USEDOLIBARRSERVER') && !empty($ws_virtuelhost)) {
361 $ext_urlko = $ws_virtuelhost . '/paymentko.php?paymentkosessioncode='.urlencode($randomseckey).'&fulltag='.$FULLTAG;
362 } else {
363 $ext_urlko = DOL_URL_ROOT.'/public/website/index.php?paymentkosessioncode='.urlencode($randomseckey).'&website='.urlencode($ws).'&pageref=paymentko&fulltag='.$FULLTAG;
364 }
365
366 dol_syslog("Now do a redirect using Location : ".$ext_urlko, LOG_DEBUG, 0, '_payment');
367 header("Location: ".$ext_urlko);
368 exit;
369}
if(! $sortfield) if(! $sortorder) $object
Definition account.php:100
global $dolibarr_main_url_root
llxFooter($comment='', $zone='private', $disabledoutputofmessages=0)
Empty footer.
Definition wrapper.php:91
if(!defined('NOREQUIRESOC')) if(!defined( 'NOREQUIRETRAN')) if(!defined('NOTOKENRENEWAL')) if(!defined( 'NOREQUIREMENU')) if(!defined('NOREQUIREHTML')) if(!defined( 'NOREQUIREAJAX')) llxHeader($head='', $title='', $help_url='', $target='', $disablejs=0, $disablehead=0, $arrayofjs='', $arrayofcss='', $morequerystring='', $morecssonbody='', $replacemainareaby='', $disablenofollow=0, $disablenoindex=0)
Empty header.
Definition wrapper.php:73
Class to send emails (with attachments or not) Usage: $mailfile = new CMailFile($subject,...
Class to manage hooks.
Class to manage translations.
Class Website.
htmlPrintOnlineFooter($fromcompany, $langs, $addformmessage=0, $suffix='', $object=null)
Show footer of company in HTML public pages.
global $mysoc
if(!isModEnabled('ai')||!getDolGlobalString('AI_ASSISTANT_ENABLED')) global $conf
The main.inc.php has been included so the following variable are now defined:
getLanguageCodeFromCountryCode($countrycode)
Return default language from country code.
GETPOST($paramname, $check='alphanohtml', $method=0, $filter=null, $options=null, $noreplace=0, $nodefault=0)
Return value of a param into GET or POST supervariable.
dol_textishtml($msg, $option=0)
Return if a text is a html content.
getDolGlobalString($key, $default='')
Return a Dolibarr global constant string value.
isModEnabled($module)
Is Dolibarr module enabled.
dol_syslog($message, $level=LOG_INFO, $ident=0, $suffixinfilename='', $restricttologhandler='', $logcontext=null)
Write log message into outputs.
getRandomPassword($generic=false, $replaceambiguouschars=null, $length=32)
Return a generated password using default module.
httponly_accessforbidden($message='1', $http_response_code=403, $stringalreadysanitized=0)
Show a message to say access is forbidden and stop program.