An address like "asdf" used to be accepted: the field was type="text" with
only `required`, and there was no server-side check. createBooking() runs
long before sendEmail(), so the failure was silent rather than loud -
reproduced end to end on test:
- the booking row WAS created, with a manage_token
- PHPMailer's addAddress() threw, so nothing was ever sent
- the Location header was already queued, so the guest was redirected to
the normal "booking finished" page and saw success
- Evelin is a CC on that same message, so the salon was not told either
- the guest had no manage link, so they could not cancel
Fixes
- booking_process() rejects an empty or malformed address BEFORE any write,
returning invalid_email / HTTP 400. Message added in all three languages,
worded to say why it matters (the confirmation and the manage link go
there). filter_var is equal-or-stricter than PHPMailer's own validator -
checked against it on ten cases - so anything accepted here cannot throw
later.
- The three public booking forms use type="email", so most typos never
reach the server.
- Removed three debug echoes from User_model::sendEmail() that leaked $lang
and Hungarian strings ("Üzenet elküldve", "Üzenetküldési hiba. Mailer
Error: ...") into the guest-facing response.
Scope
- Public flow only. 508 existing bookings have an empty guest_email because
admin-created block bookings legitimately have none; those go through
Admin::booking_process(), which is untouched, and its form stays
type="text".
- Not covered: a valid address whose SMTP delivery fails still leaves the
booking created and the guest seeing success, logged only via
log_message(). Different failure mode, needs a separate decision.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
30 lines
2.2 KiB
PHP
Executable File
30 lines
2.2 KiB
PHP
Executable File
<?php
|
|
$bookingErrorMessages = array(
|
|
'slot_taken' => 'Ezt az időpontot sajnos lefoglalták, amíg az űrlapot kitöltötte. Kérjük, válasszon másik időpontot.',
|
|
'worker_unavailable' => 'A kiválasztott kolléga ezen a napon nem dolgozik. Kérjük, válasszon másik napot.',
|
|
'outside_schedule' => 'A kiválasztott időpont a kolléga munkaidején kívül esik. Kérjük, válasszon másik időpontot.',
|
|
'alternate_week' => 'A kiválasztott kolléga csak kéthetente dolgozik. Kérjük, válasszon másik napot.',
|
|
'after_hours' => 'A kezelés nem érne véget zárásig. Kérjük, válasszon korábbi időpontot.',
|
|
'too_far' => 'Foglalás legfeljebb 3 hónappal előre adható le.',
|
|
'category_mismatch' => 'A kiválasztott kolléga nem végzi a kiválasztott szolgáltatásokat. Kérjük, válasszon újra.',
|
|
'single_service_only' => 'Egyszerre csak egy kezelés foglalható. Kérjük, csak egyet válasszon.',
|
|
'invalid_email' => 'Az e-mail cím nem tűnik érvényesnek. Kérjük, ellenőrizze - a visszaigazolást és a foglalás kezelésére szolgáló linket erre a címre küldjük.',
|
|
'no_service' => 'Nem választott ki szolgáltatást. Kérjük, válasszon legalább egyet.',
|
|
'default' => 'Hiba történt a foglalás során. Kérjük, próbálja újra.',
|
|
);
|
|
|
|
$shownError = isset($bookingErrorCode) && isset($bookingErrorMessages[$bookingErrorCode])
|
|
? $bookingErrorMessages[$bookingErrorCode]
|
|
: $bookingErrorMessages['default'];
|
|
|
|
$backSubpage = isset($subpage) && $subpage != '' ? $subpage : 'barber';
|
|
$backUrl = SITEURL.'hu/booking/'.$backSubpage;
|
|
?>
|
|
<div class="bookingContainer" style="min-height:500px;">
|
|
<div class="bookingThankYouTitle">Ez az időpont már nem foglalható</div>
|
|
<div class="bookingThankYouMessageTitle"><?php echo $shownError;?></div>
|
|
<div style="text-align:center; margin-top:30px;">
|
|
<a href="<?php echo $backUrl;?>" style="display:inline-block; padding:12px 28px; background:#000; color:#fff; text-decoration:none; border-radius:5px; font-size:16px;">Vissza a foglaláshoz</a>
|
|
</div>
|
|
</div>
|