HTML;
}
function has_postcode()
{
if (isset($_SESSION["postcode"])) {
return true;
}
return false;
}
function handle_postcode_modal($data)
{
$params = $data->get_params();
$nonce = $data->get_header("X-WP-Nonce");
// 1. Security
if (!wp_verify_nonce($nonce, "wp_rest")) {
echo json_encode(["status" => "error", "message" => "nononce"]);
exit();
}
// 2. Basis Validatie
if (!verify_postcode($params["postcode"])) {
echo json_encode(["status" => "error", "message" => "postcode"]);
exit();
}
if (!verify_huisnummer($params["huisnummer"])) {
echo json_encode(["status" => "error", "message" => "huisnummer"]);
exit();
}
// 3. API Call (Ruwe data)
$result = getStraatnaam($params["postcode"], $params["huisnummer"]);
// 4. Validatie & Logic
$hasError = isset($result["error"]);
$errorCode = null;
$errorMessage = null;
$candidates = [];
$straatnaam = null;
$woonplaats = null;
if ($hasError) {
$errorCode = $result["error"]["code"] ?? "UNKNOWN_ERROR";
$errorMessage = $result["error"]["message"] ?? "Onbekende fout";
$candidates = $result["error"]["details"]["candidates"] ?? [];
// SPECIAL CASE: HUISNUMMER_AMBIGUOUS
if ($errorCode === "HUISNUMMER_AMBIGUOUS" && !empty($candidates)) {
$plainMatch = null;
// Zoek naar candidate ZONDER toevoeging
foreach ($candidates as $candidate) {
if (
empty($candidate["huisletter"]) &&
empty($candidate["huisnummertoevoeging"])
) {
$plainMatch = $candidate;
break;
}
}
// Als we een 'platte' match hebben (bijv. 15), dan is het SUCCES
if ($plainMatch) {
$hasError = false; // Negeer de error
$straatnaam = $plainMatch["straat"];
$woonplaats = $plainMatch["woonplaats"];
}
}
} else {
// Normaal succes (geen error in response)
if (!empty($result["results"])) {
$straatnaam = $result["results"][0]["straat"];
$woonplaats = $result["results"][0]["woonplaats"];
} else {
// Edge case: geen error veld, maar ook geen results
$hasError = true;
$errorCode = "NO_RESULTS";
$errorMessage = "Adres niet gevonden";
}
}
// 5. Response sturen
if ($hasError) {
echo json_encode([
"status" => "error",
"code" => $errorCode,
"message" => $errorMessage,
"suggestions" => $result["error"]["details"]["suggestions"] ?? [],
"apirequest" => "openpostcode.nl",
]);
exit();
}
$cookie_val = postcode_in_range($params["postcode"]).'|'.$params["postcode"].'|'.$straatnaam.'|'.$params["huisnummer"].'|'.$woonplaats.'|';
// 6. Succes: Sessie opslaan & response
$_SESSION["postcode"] = $params["postcode"];
$_SESSION["huisnummer"] = $params["huisnummer"];
$_SESSION["straatnaam"] = $straatnaam;
$_SESSION["woonplaats"] = $woonplaats;
$_SESSION["postcode_is_local"] = postcode_in_range($params["postcode"]);
setcookie("PPPR", $cookie_val, [
'expires' => time() + 3600,
'path' => '/',
'domain' => $_SERVER['SERVER_NAME'],
'secure' => true, // Required for cross-origin fetch
'httponly' => true, // Prevents JavaScript access (XSS protection)
'samesite' => 'Lax' // Use 'None' for cross-origin, requires secure=true
]);
echo json_encode([
"status" => "success",
"message" => "all good",
]);
exit();
}
function register_modal_api()
{
register_rest_route("postcode-modal/v1", "submit", [
"methods" => "POST",
"callback" => "handle_postcode_modal",
]);
}
function verify_postcode($postcode)
{
if (!preg_match('/^[0-9]{4}\s?[A-Za-z]{2}$/', $postcode) === 1) {
return false;
}
return true;
}
function verify_huisnummer($huisnummer)
{
if (!preg_match('/^[0-9]{4}\s?[A-Za-z]{2}$/', $huisnummer) === 1) {
return false;
}
return true;
}
function getStraatnaam($postcode, $huisnummer)
{
$url =
"https://openpostcode.nl/api/v2/address?postcode=" .
urlencode($postcode) .
"&huisnummer=" .
urlencode($huisnummer);
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_TIMEOUT, 10);
curl_setopt($ch, CURLOPT_USERAGENT, "PHP/OpenPostcodeClient");
$response = curl_exec($ch);
$httpCode = curl_getinfo($ch, CURLINFO_HTTP_CODE);
if (curl_error($ch)) {
curl_close($ch);
return [
"error" => ["code" => "CURL_ERROR", "message" => curl_error($ch)],
];
}
curl_close($ch);
// Decodeer als associatieve array (true)
$data = json_decode($response, true);
// Als JSON decode faalt
if (json_last_error() !== JSON_ERROR_NONE) {
return [
"error" => [
"code" => "JSON_ERROR",
"message" => "Invalid JSON response",
],
];
}
// Geef de RUWE response terug (inclusief meta, error, results, etc.)
return $data;
}
function postcode_in_range($postcode)
{
$vals = get_option("local_postcodes_values", "");
$rows = preg_split("/\R/", $vals, -1, PREG_SPLIT_NO_EMPTY);
$pc_arr = [];
foreach ($rows as $row) {
$row = trim($row);
$postcode_range = explode("-", $row);
$pc_arr[] = [(int) $postcode_range[0], (int) $postcode_range[1]];
}
$cleanPostcode = strtoupper(preg_replace("/\s+/", "", $postcode));
if (!preg_match('/^\d{4}[A-Z]{2}$/', $cleanPostcode)) {
return false;
}
$numberPart = (int) substr($cleanPostcode, 0, 4);
foreach ($pc_arr as $pc_to_check) {
if ($numberPart >= $pc_to_check[0] && $numberPart <= $pc_to_check[1]) {
return true;
}
}
return false;
}
function modify_checkout_with_js()
{
if (
!is_checkout() ||
(is_wc_endpoint_url() && !is_wc_endpoint_url("order-received"))
) {
return;
}
$woonplaats = $_SESSION["woonplaats"];
$postcode = $formatted_postcode = preg_replace(
"/(\d+)([A-Z]+)/",
'$1 $2',
strtoupper($_SESSION["postcode"]),
);
$address =
$_SESSION["straatnaam"] . " " . strtoupper($_SESSION["huisnummer"]);
echo <<
jQuery(document).ready(function(\$) {
fillCheckoutFields();
\$(document.body).on('updated_checkout', fillCheckoutFields);
});
function fillCheckoutFields() {
if (typeof wp !== 'undefined' && wp.data && wp.data.dispatch) {
const store = 'wc/store/cart';
wp.data.dispatch(store).setShippingAddress({
first_name: '',
last_name: '',
address_1: '{$address}',
address_2: '',
city: '{$woonplaats}',
state: '',
postcode: '{$postcode}',
country: 'NL',
phone: '',
email: ''
});
//make fields READONLY and ppstcode reset.
setTimeout(() => {
// make prefilled fiields readonly.
\$('#shipping-postcode, #shipping-city, #shipping-address_1')
.prop('readonly', true)
.css('background', '#f9f9f9');
// create postcode reset button
const div = document.createElement("div");
div.setAttribute("class", "postcode-reset")
div.innerHTML = `