| Server IP : 38.190.208.107 / Your IP : 216.73.216.219 Web Server : nginx/1.28.1 System : Linux ht2026040333114 6.1.0-10-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.37-1 (2023-07-03) x86_64 User : www ( 1000) PHP Version : 8.2.28 Disable Function : passthru,exec,system,putenv,chroot,chgrp,chown,shell_exec,popen,proc_open,pcntl_exec,ini_alter,ini_restore,dl,openlog,syslog,readlink,symlink,popepassthru,pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,imap_open,apache_setenv,eval,assert,passthru,system,exec,shell_exec,popen,proc_open MySQL : OFF | cURL : ON | WGET : OFF | Perl : OFF | Python : OFF | Sudo : OFF | Pkexec : OFF Directory : /www/wwwroot/wp.3/wp-content/plugins/wpforms-lite/src/Integrations/Square/Api/ |
Upload File : |
<?php
namespace WPForms\Integrations\Square\Api;
use RuntimeException;
use WPForms\Integrations\Square\Helpers;
use WPForms\Vendor\Square\Utils\WebhooksHelper;
/**
* Webhook event handler.
*
* @since 1.9.5
*/
class WebhookEvent {
/**
* Construct and validate the Square webhook event.
*
* @since 1.9.5
*
* @param string $payload The raw JSON payload from Square.
* @param string $signature The Square webhook signature from headers.
* @param string $webhook_secret The webhook signing secret from Square Developer Dashboard.
*
* @return object The decoded event data.
*
* @throws RuntimeException If the webhook payload structure is invalid.
*/
public static function construct_event( string $payload, string $signature, string $webhook_secret ) {
// Validate the webhook signature.
if ( ! WebhooksHelper::isValidWebhookEventSignature( $payload, $signature, $webhook_secret, Helpers::get_webhook_url() ) ) {
throw new RuntimeException( 'Invalid webhook signature. Possible unauthorized request.' );
}
// Decode JSON payload.
$event = json_decode( $payload, false );
// Check for JSON decoding errors.
if ( json_last_error() !== JSON_ERROR_NONE ) {
throw new RuntimeException( 'Invalid JSON payload' );
}
if ( ! $event || ! isset( $event->type, $event->data ) ) {
throw new RuntimeException( 'Invalid webhook payload structure.' );
}
return $event;
}
}