moodle/enrol/authorize/authorizenetlib.php

360 lines
12 KiB
PHP
Raw Normal View History

2006-01-19 14:57:23 +00:00
<?php // $Id$
if (!defined('MOODLE_INTERNAL')) {
die('Direct access to this script is forbidden.');
}
2006-01-06 12:14:17 +00:00
define('AN_APPROVED', '1');
define('AN_DECLINED', '2');
define('AN_ERROR', '3');
define('AN_DELIM', '|');
define('AN_ENCAP', '"');
2006-07-25 17:38:32 +00:00
require_once($CFG->dirroot.'/enrol/authorize/const.php');
require_once($CFG->dirroot.'/enrol/authorize/enrol.php');
2005-12-14 15:47:37 +00:00
2005-12-22 15:24:05 +00:00
/**
* Gets settlement date and time
*
* @param int $time Time processed, usually now.
* @return int Settlement date and time
2005-12-22 15:24:05 +00:00
*/
function authorize_getsettletime($time)
2005-12-22 15:24:05 +00:00
{
global $CFG;
2006-02-10 12:41:56 +00:00
$cutoff = intval($CFG->an_cutoff);
$mins = $cutoff % 60;
$hrs = ($cutoff - $mins) / 60;
2005-12-22 15:24:05 +00:00
$cutofftime = strtotime("$hrs:$mins", $time);
if ($cutofftime < $time) {
$cutofftime = strtotime("$hrs:$mins", $time + (24 * 3600));
}
return $cutofftime;
}
/**
* Is order settled? Status must be auth_captured or credited.
*
* @param object $order Order details
* @return bool true, if settled, false otherwise.
*/
function authorize_settled($order)
2005-12-22 15:24:05 +00:00
{
2006-01-02 09:30:35 +00:00
return (($order->status == AN_STATUS_AUTHCAPTURE || $order->status == AN_STATUS_CREDIT) &&
2006-01-19 14:57:23 +00:00
($order->settletime > 0) && ($order->settletime < time()));
2005-12-22 15:24:05 +00:00
}
/**
* Is order expired? 'Authorized/Pending Capture' transactions are expired after 30 days.
*
* @param object &$order Order details.
* @return bool true, transaction is expired, false otherwise.
*/
function authorize_expired(&$order)
{
static $timediff30;
if ($order->status == AN_STATUS_EXPIRE) {
return true;
}
elseif ($order->status != AN_STATUS_AUTH) {
return false;
}
if (empty($timediff30)) {
$timediff30 = authorize_getsettletime(time()) - (30 * 24 * 3600);
}
$isexpired = (authorize_getsettletime($order->timecreated) < $timediff30);
if ($isexpired) {
$order->status = AN_STATUS_EXPIRE;
update_record('enrol_authorize', $order);
}
return $isexpired;
}
/**
* Performs an action on authorize.net and updates/inserts records. If record update fails,
* sends email to admin.
*
2006-01-02 09:30:35 +00:00
* @param object &$order Which transaction data will be sent. See enrol_authorize table.
* @param string &$message Information about error message if this function returns false.
* @param object &$extra Extra data that used for refunding and credit card information.
* @param int $action Which action will be performed. See AN_ACTION_*
* @return bool true Transaction was successful, false otherwise. Use $message for reason.
* @author Ethem Evlice <ethem a.t evlice d.o.t com>
* @uses $CFG
*/
function authorize_action(&$order, &$message, &$extra, $action=AN_ACTION_NONE)
{
global $CFG;
static $conststring;
$test = !empty($CFG->an_test);
2005-12-22 15:24:05 +00:00
if (!isset($conststring)) {
$consdata = array(
'x_version' => '3.1',
'x_delim_data' => 'True',
'x_delim_char' => AN_DELIM,
'x_encap_char' => AN_ENCAP,
2006-01-06 12:14:17 +00:00
'x_relay_response' => 'FALSE',
2005-12-22 15:24:05 +00:00
'x_method' => 'CC',
'x_login' => $CFG->an_login,
'x_test_request' => $test ? 'TRUE' : 'FALSE'
);
$str = '';
2005-12-14 15:47:37 +00:00
foreach($consdata as $ky => $vl) {
$str .= $ky . '=' . urlencode($vl) . '&';
}
$str .= (!empty($CFG->an_tran_key)) ?
2005-12-22 15:24:05 +00:00
'x_tran_key=' . urlencode($CFG->an_tran_key):
'x_password=' . urlencode($CFG->an_password);
$conststring = $str;
}
$action = intval($action);
if (empty($order) or empty($order->id)) {
2006-01-19 14:57:23 +00:00
$message = "Check order->id!";
return false;
}
elseif ($action <= AN_ACTION_NONE or $action > AN_ACTION_VOID) {
$message = "Invalid action!";
return false;
}
$poststring = $conststring;
2005-12-22 15:24:05 +00:00
switch ($action) {
case AN_ACTION_AUTH_ONLY:
case AN_ACTION_CAPTURE_ONLY:
case AN_ACTION_AUTH_CAPTURE:
{
if ($order->status != AN_STATUS_NONE) {
2006-01-19 14:57:23 +00:00
$message = "Order status must be AN_STATUS_NONE(0)!";
return false;
}
elseif (empty($extra)) {
2006-01-19 14:57:23 +00:00
$message = "Need extra fields!";
return false;
}
elseif (($action == AN_ACTION_CAPTURE_ONLY) and empty($extra->x_auth_code)) {
$message = "x_auth_code is required for capture only transactions!";
return false;
}
$ext = (array)$extra;
$poststring .= '&x_type=' . (($action==AN_ACTION_AUTH_ONLY)
? 'AUTH_ONLY' :( ($action==AN_ACTION_CAPTURE_ONLY)
? 'CAPTURE_ONLY' : 'AUTH_CAPTURE'));
foreach($ext as $k => $v) {
2005-12-22 15:24:05 +00:00
$poststring .= '&' . $k . '=' . urlencode($v);
}
break;
}
case AN_ACTION_PRIOR_AUTH_CAPTURE:
{
if ($order->status != AN_STATUS_AUTH) {
2006-01-19 14:57:23 +00:00
$message = "Order status must be authorized!";
return false;
}
if (authorize_expired($order)) {
$message = "Transaction must be captured within 30 days. EXPIRED!";
return false;
}
2005-12-22 15:24:05 +00:00
$poststring .= '&x_type=PRIOR_AUTH_CAPTURE&x_trans_id=' . urlencode($order->transid);
break;
}
case AN_ACTION_CREDIT:
{
2005-12-22 15:24:05 +00:00
if ($order->status != AN_STATUS_AUTHCAPTURE) {
2006-01-19 14:57:23 +00:00
$message = "Order status must be authorized/captured!";
2005-12-22 15:24:05 +00:00
return false;
}
if (!authorize_settled($order)) {
2006-01-19 14:57:23 +00:00
$message = "Order must be settled. Try VOID, check Cut-Off time if it fails!";
return false;
}
$timenowsettle = authorize_getsettletime(time());
2005-12-22 15:24:05 +00:00
$timediff = $timenowsettle - (120 * 3600 * 24);
if ($order->settletime < $timediff) {
2006-01-19 14:57:23 +00:00
$message = "Order must be credited within 120 days!";
return false;
}
2005-12-22 15:24:05 +00:00
if (empty($extra)) {
$message = "Need extra fields to REFUND!";
2005-12-22 15:24:05 +00:00
return false;
}
2006-01-19 14:57:23 +00:00
$total = floatval($extra->sum) + floatval($extra->amount);
2005-12-14 15:47:37 +00:00
if (($extra->amount == 0) || ($total > $order->amount)) {
$message = "Can be credited up to original amount.";
return false;
}
2005-12-22 15:24:05 +00:00
$poststring .= '&x_type=CREDIT&x_trans_id=' . urlencode($order->transid);
$poststring .= '&x_card_num=' . sprintf("%04d", intval($order->cclastfour));
$poststring .= '&x_currency_code=' . urlencode($order->currency);
$poststring .= '&x_amount=' . urlencode($extra->amount);
break;
}
case AN_ACTION_VOID:
{
2005-12-14 15:47:37 +00:00
if ($order->status == AN_STATUS_AUTH) {
if (authorize_expired($order)) {
2006-01-19 14:57:23 +00:00
$message = "Authorized transaction must be voided within 30 days. EXPIRED!";
2005-12-14 15:47:37 +00:00
return false;
}
2005-12-22 15:24:05 +00:00
}
elseif ($order->status == AN_STATUS_AUTHCAPTURE or $order->status == AN_STATUS_CREDIT) {
if (authorize_settled($order)) {
2005-12-22 15:24:05 +00:00
$message = "Settled transaction cannot be voided. Check Cut-Off time!";
2005-12-14 15:47:37 +00:00
return false;
}
}
2005-12-22 15:24:05 +00:00
else {
$message = "Order status must be authorized/pending capture or captured-refunded/pending settlement!";
2005-12-22 15:24:05 +00:00
return false;
}
$poststring .= '&x_type=VOID&x_trans_id=' . urlencode($order->transid);
break;
}
2006-01-19 14:57:23 +00:00
default: {
$message = "Invalid action: $action";
return false;
}
}
2006-01-19 14:57:23 +00:00
$referer = '';
2005-12-22 15:24:05 +00:00
if (! (empty($CFG->an_referer) || $CFG->an_referer == "http://")) {
2006-01-19 14:57:23 +00:00
$referer = "Referer: $CFG->an_referer\r\n";
}
$host = $test ? 'certification.authorize.net' : 'secure.authorize.net';
$fp = fsockopen("ssl://$host", 443, $errno, $errstr, 60);
if (!$fp) {
$message = "no connection: $errstr ($errno)";
return false;
}
// critical section
@ignore_user_abort(true);
if (intval(ini_get('max_execution_time')) > 0) {
@set_time_limit(300);
}
fwrite($fp, "POST /gateway/transact.dll HTTP/1.0\r\n" .
2006-01-19 14:57:23 +00:00
"Host: $host\r\n" . $referer .
2005-12-22 15:24:05 +00:00
"Content-type: application/x-www-form-urlencoded\r\n" .
"Connection: close\r\n" .
"Content-length: " . strlen($poststring) . "\r\n\r\n" .
$poststring . "\r\n"
);
$tmpstr = '';
while(!feof($fp) && !stristr($tmpstr, 'content-length')) {
$tmpstr = fgets($fp, 4096);
}
if (!stristr($tmpstr, 'content-length')) {
$message = "content-length error";
@fclose($fp);
return false;
}
2005-12-22 15:24:05 +00:00
$length = trim(substr($tmpstr, strpos($tmpstr,'content-length')+15));
fgets($fp, 4096);
$data = fgets($fp, $length);
@fclose($fp);
$response = explode(AN_ENCAP.AN_DELIM.AN_ENCAP, $data);
if ($response === false) {
$message = "response error";
return false;
}
$rcount = count($response) - 1;
if ($response[0]{0} == AN_ENCAP) {
$response[0] = substr($response[0], 1);
}
if (substr($response[$rcount], -1) == AN_ENCAP) {
$response[$rcount] = substr($response[$rcount], 0, -1);
}
2005-12-22 15:24:05 +00:00
if ($response[0] == AN_APPROVED)
{
2006-01-19 14:57:23 +00:00
$transid = intval($response[6]);
if ($test || $transid == 0) {
return true; // don't update original transaction in test mode.
}
switch ($action) {
case AN_ACTION_AUTH_ONLY:
case AN_ACTION_CAPTURE_ONLY:
case AN_ACTION_AUTH_CAPTURE:
2005-12-22 15:24:05 +00:00
case AN_ACTION_PRIOR_AUTH_CAPTURE:
{
2006-01-19 14:57:23 +00:00
$order->transid = $transid;
2005-12-22 15:24:05 +00:00
if ($action == AN_ACTION_AUTH_ONLY) {
$order->status = AN_STATUS_AUTH;
// dont't update settletime
} else {
$order->status = AN_STATUS_AUTHCAPTURE;
$order->settletime = authorize_getsettletime(time());
2005-12-22 15:24:05 +00:00
}
if (! update_record('enrol_authorize', $order)) {
enrolment_plugin_authorize::email_to_admin("Error while trying to update data " .
"in table enrol_authorize. Please edit manually this record: ID=$order->id.", $order);
}
2005-12-22 15:24:05 +00:00
break;
}
2005-12-22 15:24:05 +00:00
case AN_ACTION_CREDIT:
{
// Credit generates new transaction id.
// So, $extra must be updated, not $order.
$extra->status = AN_STATUS_CREDIT;
2006-01-19 14:57:23 +00:00
$extra->transid = $transid;
$extra->settletime = authorize_getsettletime(time());
unset($extra->sum); // this is not used in refunds table.
if (! $extra->id = insert_record('enrol_authorize_refunds', $extra)) {
enrolment_plugin_authorize::email_to_admin("Error while trying to insert data " .
"into table enrol_authorize_refunds. Please add manually this record:", $extra);
}
2005-12-22 15:24:05 +00:00
break;
}
case AN_ACTION_VOID:
2005-12-22 15:24:05 +00:00
{
$tableupdate = 'enrol_authorize';
if ($order->status == AN_STATUS_CREDIT) {
$tableupdate = 'enrol_authorize_refunds';
}
2005-12-22 15:24:05 +00:00
// dont't update settletime
$order->status = AN_STATUS_VOID;
if (! update_record($tableupdate, $order)) {
enrolment_plugin_authorize::email_to_admin("Error while trying to update data " .
"in table $tableupdate. Please edit manually this record: ID=$order->id.", $order);
}
2005-12-22 15:24:05 +00:00
break;
}
default: return false;
}
return true;
}
2005-12-22 15:24:05 +00:00
else
{
2006-01-19 14:57:23 +00:00
$reason = "reason" . $response[2];
$message = get_string($reason, "enrol_authorize");
if ($message == '[[' . $reason . ']]') {
$message = isset($response[3]) ? $response[3] : 'unknown error';
}
if (!empty($CFG->an_avs)) {
$avs = "avs" . strtolower($response[5]);
$stravs = get_string($avs, "enrol_authorize");
$message .= "<br />" . get_string("avsresult", "enrol_authorize", $stravs);
2006-01-19 14:57:23 +00:00
}
return false;
}
}
?>