Files
studiobeve.no/application/views/pages/includes/booking-error-form-en.php
T
UbuntuandClaude Opus 5 35115404be Validate the guest e-mail before the booking is saved
An address like "asdf" used to be accepted: the field was type="text" with
only `required`, and there was no server-side check. createBooking() runs
long before sendEmail(), so the failure was silent rather than loud -
reproduced end to end on test:

  - the booking row WAS created, with a manage_token
  - PHPMailer's addAddress() threw, so nothing was ever sent
  - the Location header was already queued, so the guest was redirected to
    the normal "booking finished" page and saw success
  - Evelin is a CC on that same message, so the salon was not told either
  - the guest had no manage link, so they could not cancel

Fixes
- booking_process() rejects an empty or malformed address BEFORE any write,
  returning invalid_email / HTTP 400. Message added in all three languages,
  worded to say why it matters (the confirmation and the manage link go
  there). filter_var is equal-or-stricter than PHPMailer's own validator -
  checked against it on ten cases - so anything accepted here cannot throw
  later.
- The three public booking forms use type="email", so most typos never
  reach the server.
- Removed three debug echoes from User_model::sendEmail() that leaked $lang
  and Hungarian strings ("Üzenet elküldve", "Üzenetküldési hiba. Mailer
  Error: ...") into the guest-facing response.

Scope
- Public flow only. 508 existing bookings have an empty guest_email because
  admin-created block bookings legitimately have none; those go through
  Admin::booking_process(), which is untouched, and its form stays
  type="text".
- Not covered: a valid address whose SMTP delivery fails still leaves the
  booking created and the guest seeing success, logged only via
  log_message(). Different failure mode, needs a separate decision.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-15 09:55:33 +00:00

30 lines
2.0 KiB
PHP
Executable File

<?php
$bookingErrorMessages = array(
'slot_taken' => 'This time slot was taken while you were filling in the form. Please choose another time.',
'worker_unavailable' => 'The selected staff member is not working on this day. Please choose another day.',
'outside_schedule' => 'The selected time is outside the staff member\'s working hours. Please choose another time.',
'alternate_week' => 'The selected staff member only works every second week. Please choose another day.',
'after_hours' => 'The treatment would not finish before closing time. Please choose an earlier time.',
'too_far' => 'Bookings can only be made up to 3 months in advance.',
'category_mismatch' => 'The selected staff member does not perform the chosen services. Please start again.',
'single_service_only' => 'Only one treatment can be booked at a time. Please select just one.',
'invalid_email' => 'That e-mail address does not look valid. Please check it - your confirmation and the link to manage your booking are sent there.',
'no_service' => 'No service was selected. Please choose at least one service.',
'default' => 'Something went wrong with your booking. Please try again.',
);
$shownError = isset($bookingErrorCode) && isset($bookingErrorMessages[$bookingErrorCode])
? $bookingErrorMessages[$bookingErrorCode]
: $bookingErrorMessages['default'];
$backSubpage = isset($subpage) && $subpage != '' ? $subpage : 'barber';
$backUrl = SITEURL.'en/booking/'.$backSubpage;
?>
<div class="bookingContainer" style="min-height:500px;">
<div class="bookingThankYouTitle">This time is no longer available</div>
<div class="bookingThankYouMessageTitle"><?php echo $shownError;?></div>
<div style="text-align:center; margin-top:30px;">
<a href="<?php echo $backUrl;?>" style="display:inline-block; padding:12px 28px; background:#000; color:#fff; text-decoration:none; border-radius:5px; font-size:16px;">Back to booking</a>
</div>
</div>