| @@ -1318,10 +1318,17 @@ | ||
| 1318 | 1318 | |
| 1319 | 1319 | if ($invoice_id) { |
| 1320 | 1320 | // Always use WordPress permalink |
| 1321 | 1321 | $invoice_url = get_permalink($invoice_id); |
| 1322 | - // If Pro and secure link available, use secure link | |
| 1323 | - if (class_exists('\EasyInvoicePro\Addons\SecureLinks\Controllers\PermalinkController')) { | |
| 1322 | + // A signed URL only when the site asked for signed URLs. This | |
| 1323 | + // used to test for the class alone, which is loadable whenever | |
| 1324 | + // Pro is installed — so accepting a quote sent the client to | |
| 1325 | + // /secure-invoice/<hash>/, and minted the hash on the way, on | |
| 1326 | + // sites that had Secure Links switched off or never enabled. | |
| 1327 | + // Every other caller (emails, shortcodes, reminders) reads the | |
| 1328 | + // setting first; this one did not. | |
| 1329 | + $secure_links_enabled = get_option('easy_invoice_pro_enable_secure_links', 'no') === 'yes'; | |
| 1330 | + if ($secure_links_enabled && class_exists('\EasyInvoicePro\Addons\SecureLinks\Controllers\PermalinkController')) { | |
| 1324 | 1331 | $secure_url = \EasyInvoicePro\Addons\SecureLinks\Controllers\PermalinkController::getInvoiceSecureLinkUrl($invoice_id); |
| 1325 | 1332 | if ($secure_url) { |
| 1326 | 1333 | $invoice_url = $secure_url; |
| 1327 | 1334 | } |