Validate the guest e-mail before the booking is saved

An address like "asdf" used to be accepted: the field was type="text" with
only `required`, and there was no server-side check. createBooking() runs
long before sendEmail(), so the failure was silent rather than loud -
reproduced end to end on test:

  - the booking row WAS created, with a manage_token
  - PHPMailer's addAddress() threw, so nothing was ever sent
  - the Location header was already queued, so the guest was redirected to
    the normal "booking finished" page and saw success
  - Evelin is a CC on that same message, so the salon was not told either
  - the guest had no manage link, so they could not cancel

Fixes
- booking_process() rejects an empty or malformed address BEFORE any write,
  returning invalid_email / HTTP 400. Message added in all three languages,
  worded to say why it matters (the confirmation and the manage link go
  there). filter_var is equal-or-stricter than PHPMailer's own validator -
  checked against it on ten cases - so anything accepted here cannot throw
  later.
- The three public booking forms use type="email", so most typos never
  reach the server.
- Removed three debug echoes from User_model::sendEmail() that leaked $lang
  and Hungarian strings ("Üzenet elküldve", "Üzenetküldési hiba. Mailer
  Error: ...") into the guest-facing response.

Scope
- Public flow only. 508 existing bookings have an empty guest_email because
  admin-created block bookings legitimately have none; those go through
  Admin::booking_process(), which is untouched, and its form stays
  type="text".
- Not covered: a valid address whose SMTP delivery fails still leaves the
  booking created and the guest seeing success, logged only via
  log_message(). Different failure mode, needs a separate decision.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Ubuntu
2026-08-15 09:55:33 +00:00
co-authored by Claude Opus 5
parent 7f51a795a5
commit 35115404be
8 changed files with 28 additions and 7 deletions
+4 -3
View File
@@ -132,7 +132,6 @@ class User_model extends CI_Model {
public function sendEmail($addressList, $lang, $subpage){
// Import PHPMailer classes into the global namespace
// These must be at the top of your script, not inside a function
echo $lang;
if(!empty($addressList)){
foreach($addressList as $addressListItem){
// Instantiation and passing `true` enables exceptions
@@ -179,7 +178,6 @@ class User_model extends CI_Model {
//$mail->AltBody = strip_tags($answer_message);
$mail->send();
echo 'Üzenet elküldve';
if($subpage != ''){
header('location:'.base_url().$lang.'/booking-finished/'.$subpage);
}
@@ -187,7 +185,10 @@ class User_model extends CI_Model {
} catch (Exception $e) {
//header('location:'.base_url().'manage-applicants/?email-sent=false&error='.$mail->ErrorInfo);
log_message('error', 'sendEmail FAILED: ' . $mail->ErrorInfo);
echo "Üzenetküldési hiba. Mailer Error: {$mail->ErrorInfo}";
// Do NOT echo the mailer error. This runs after the booking is
// saved and after the redirect header is queued, so it only leaks
// Hungarian internals into a response the guest never reads.
// The log_message() above is the record.
}
}