E_LIMIT ) { $this->send_verification_email( $user_id ); $this->redirect_with_result( 'sent' ); } $this->redirect_with_result( 'throttled' ); } /** * Return whether the verification prompt should be shown for the current user. * * This cannot depend on whether matching guest orders exist, since that would disclose order * existence before the customer proves they control the email address. * * @since 11.0.0 * * @return bool */ public function should_show_prompt(): bool { $user_id = get_current_user_id(); if ( ! $user_id || $this->service->is_verified( $user_id ) ) { return false; } $email_setting = get_option( 'woocommerce_customer_verify_email_settings', array() ); $email_enabled = 'yes' === ( $email_setting['enabled'] ?? 'yes' ); $should_show = $email_enabled && wc_string_to_bool( get_option( 'woocommerce_enable_guest_checkout' ) ); // A temporary-password account already has a set-password link (which also verifies on use), // surfaced by the temporary-password notice, so skip a second prompt alongside it. $should_show = $should_show && ! get_user_option( 'default_password_nag', $user_id ); /** * Filter whether to show the verification prompt for an unverified user. * * @since 11.1.0 * * @param bool $should_show Whether to show the prompt, before this filter runs. * @param int $user_id The WordPress user ID of the customer. */ return (bool) apply_filters( 'woocommerce_customer_email_verification_should_show_prompt', $should_show, $user_id ); } /** * Render the verification prompt notice on the My Account "Orders" panel. * * Within the rate-limit window a link was sent recently, so the prompt points the customer to their * inbox and offers no immediate resend; otherwise it carries the "confirm email" call to action. * * @internal * @since 11.0.0 */ public function render_prompt(): void { if ( ! $this->should_show_prompt() ) { return; } $user_id = get_current_user_id(); $seconds_since = $this->service->seconds_since_last_key( $user_id ); if ( null !== $seconds_since && $seconds_since <= self::SEND_RATE_LIMIT ) { // A just-sent/throttled result notice (from the redirect) already points to the inbox this // page load, so don't print a second "check your inbox" alongside it. // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- display-only, no state change. if ( ! isset( $_GET[ self::NOTICE_PARAM ] ) ) { wc_print_notice( esc_html__( 'Confirm your email address to check for past orders. A confirmation link was sent recently — please check your inbox.', 'woocommerce' ), 'notice' ); } return; } $send_url = wp_nonce_url( add_query_arg( self::SEND_PARAM, '1', wc_get_account_endpoint_url( 'orders' ) ), self::SEND_NONCE_ACTION ); $notice = sprintf( '%3$s %1$s', esc_html__( 'Confirm your email address to check for past orders and link them to your account.', 'woocommerce' ), esc_url( $send_url ), esc_html__( 'Confirm email address', 'woocommerce' ) ); wc_print_notice( $notice, 'notice' ); } /** * Print the one-off result notice carried by the {@see self::NOTICE_PARAM} query arg, if any. * * Send/confirm actions redirect here with a result code rather than queuing a session notice, so the * page shows exactly the current request's outcome — re-running an action can't stack notices. * * @internal * @since 11.0.0 */ public function print_result_notice(): void { // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- display-only, no state change. $code = isset( $_GET[ self::NOTICE_PARAM ] ) ? sanitize_key( wp_unslash( $_GET[ self::NOTICE_PARAM ] ) ) : ''; $notice = $this->result_notice( $code ); if ( null !== $notice ) { wc_print_notice( esc_html( $notice[0] ), $notice[1] ); } } /** * Map a redirect result code to its [ message, notice type ], or null for an unknown code. * * @param string $code Result code from a send/confirm redirect. * @return array{0: string, 1: string}|null */ private function result_notice( string $code ): ?array { switch ( $code ) { case 'sent': return array( __( 'A confirmation link has been sent to your email address. Please check your inbox.', 'woocommerce' ), 'success' ); case 'throttled': return array( __( 'A confirmation link was sent recently. Please check your inbox, or wait a moment before requesting a new one.', 'woocommerce' ), 'notice' ); case 'confirmed': return array( __( 'Your email address has been confirmed.', 'woocommerce' ), 'success' ); case 'expired': return array( __( 'This confirmation link is invalid or has expired. Please request a new one.', 'woocommerce' ), 'error' ); case 'mismatch': return array( __( 'Unable to confirm this email while you are logged in to a different account. Please log out and open the link again.', 'woocommerce' ), 'error' ); case 'invalid': return array( __( 'Invalid request. Please try again.', 'woocommerce' ), 'error' ); default: return null; } } /** * Redirect to the orders section carrying a one-off result code, then exit. * * @param string $code Result code understood by {@see self::result_notice()}. * @return never */ private function redirect_with_result( string $code ): void { wp_safe_redirect( add_query_arg( self::NOTICE_PARAM, $code, wc_get_account_endpoint_url( 'orders' ) ) ); exit; } /** * Validate a key and verify the user. * * @since 11.0.0 * * @param int $user_id User ID. * @param string $key Plaintext verification key. * @return bool True when verification succeeded. */ public function process_verification( int $user_id, string $key ): bool { if ( ! $user_id || '' === $key ) { return false; } if ( ! $this->service->check_verification_key( $user_id, $key ) ) { return false; } $this->service->mark_verified( $user_id ); return true; } /** * Send (or resend) a verification email to a user. * * @since 11.0.0 * * @param int $user_id User ID. */ public function send_verification_email( int $user_id ): void { $user = get_user_by( 'id', $user_id ); if ( ! $user ) { return; } $verify_url = $this->service->build_verification_url( $user_id ); WC()->mailer(); /** * Triggers sending of the customer email-verification email. * * @param int $user_id The WordPress user ID of the customer. * @param string $verify_url The one-time verification URL to include in the email. * * @since 11.0.0 */ do_action( 'woocommerce_customer_verify_email_notification', $user_id, $verify_url ); } }