| @@ -2,11 +2,11 @@ | ||
| 2 | 2 | |
| 3 | 3 | Plugin Name: s2Member Framework |
| 4 | 4 | Plugin URI: https://s2member.com/ |
| 5 | 5 | Tags: membership, content restriction, paid subscriptions, members only, paid access |
| 6 | -Version: 260917 | |
| 7 | -Stable tag: 260917 | |
| 8 | -Tested up to: 7.2-alpha-63608 | |
| 6 | +Version: 261001 | |
| 7 | +Stable tag: 261001 | |
| 8 | +Tested up to: 7.2-alpha-64027 | |
| 9 | 9 | Requires at least: 4.2 |
| 10 | 10 | Requires PHP: 5.6.2 |
| 11 | 11 | Tested up to PHP: 8.5.9 |
| 12 | 12 | License: GNU General Public License v2 or later. |
| @@ -175,13 +175,83 @@ | ||
| 175 | 175 | Please see: <http://s2member.com/r/translations/> |
| 176 | 176 | |
| 177 | 177 | == Upgrade Notice == |
| 178 | 178 | |
| 179 | -= v260917 = | |
| 179 | += v261001 = | |
| 180 | 180 | |
| 181 | 181 | (SECURITY RELEASE) UPGRADE IMMEDIATELY. v260215 included a CRITICAL VULNERABILITY fix, and you shouldn't wait any longer to update if you're behind. |
| 182 | 182 | |
| 183 | 183 | == Changelog == |
| 184 | + | |
| 185 | += v261001 = | |
| 186 | + | |
| 187 | +- (Framework) **Improvement:** PayPal Checkout buttons now keep a recoverable record of each checkout, allowing s2Member to complete a subscription signup even if the customer closes the page or loses their connection before the final confirmation. PayPal's verified webhook can finish the signup using the original purchase details, while checkout retries reuse the same subscription instead of creating another. Thanks to Felix for reporting the issue. See [thread #13627](https://f.wpsharks.com/t/13627). | |
| 188 | + | |
| 189 | +- (Framework) **Fix:** When a PayPal Checkout Buy Now payment succeeded but the browser lost the final response, the customer could see a payment error despite having been charged. s2Member now recovers the completed checkout and continues to the registration instructions without capturing the payment again. | |
| 190 | + | |
| 191 | +- (Framework) **Fix:** Corrected JavaScript issues that could prevent PayPal Checkout buttons from appearing, including incorrectly encoded characters and problems loading the PayPal SDK. | |
| 192 | + | |
| 193 | +- (Framework) **Fix:** Corrected an edge case where PayPal Checkout returns could fall back to the legacy site-wide proxy handler. Checkout returns now consistently use their transaction-specific return flow, with returned values normalized before downstream processing. | |
| 194 | + | |
| 195 | +- (Pro) **Security:** Hardened Remote Operations API authentication by using timing-safe comparisons when validating API keys. | |
| 196 | + | |
| 197 | +- (Pro) **Fix:** Improved legacy Multisite Membership-Only registration after WordPress core updates. s2Member now restores its required patches after successful automatic/background upgrades, while avoiding unnecessary rewrites when files are already patched. Thanks to Tim for reporting the issue. See [thread #13641](https://f.wpsharks.com/t/13641). | |
| 198 | + | |
| 199 | +- (Framework) **Compatibility:** Updated admin JSON handling to use WordPress's bundled JSON compatibility script instead of maintaining a separate bundled copy. | |
| 200 | + | |
| 201 | +- (Framework) **Maintenance:** Added missing direct-access safeguards to Markdown, AWeber, and IP utility files that are only intended to load through WordPress/s2Member. | |
| 202 | + | |
| 203 | +- (Framework) **Maintenance:** Removed obsolete inactive code that previously prevented automatic Framework updates when Pro was installed. | |
| 204 | + | |
| 205 | +- (Framework) **Maintenance:** Aligned the plugin's GPL license declaration with the existing GPLv2-or-later declaration in the readme. | |
| 206 | + | |
| 207 | +- (Pro) **Maintenance:** Added the existing GPLv2-or-later license declaration to the installer-compatible Pro plugin header. | |
| 208 | + | |
| 209 | +- (Framework) **Maintenance:** Updated release packaging so the internal language-generation marker remains available in the source repository without being included in the distributed ZIP build. | |
| 210 | + | |
| 211 | += v260927 = | |
| 212 | + | |
| 213 | +- (Pro) **Fix:** Improved Stripe 3D Secure recovery when browser and webhook processing overlap, or when the browser loses the final checkout response after successful authentication. s2Member now reconciles those recovery paths using the saved checkout state so successful signups can finish correctly without repeating fulfillment. Thanks to Felix for reporting it. See [thread #13627](https://f.wpsharks.com/t/13627). | |
| 214 | + | |
| 215 | +- (Framework) **Fix:** Improved Gateway Checkout state handling so concurrent recovery paths can safely patch independent checkout data and explicitly reload newly committed state without stale request-local cache values. | |
| 216 | + | |
| 217 | +- (Pro) **Fix:** Improved Stripe subscription recovery for new customers when payment authentication continues after the initial Pro-Form request. s2Member now keeps the pending WordPress account linked to the checkout, allowing browser or webhook recovery to complete the correct signup without losing its account association. | |
| 218 | + | |
| 219 | +- (Pro) **Fix:** In a rare Stripe pending-payment recovery case, membership processing could already be complete while the original checkout request still saw an older cached copy of the member's data and continued showing a processing state. s2Member now refreshes that data before deciding whether fulfillment has completed. | |
| 220 | + | |
| 221 | +- (Pro) **Fix:** Stripe one-time (Buy Now) Pro-Form purchases requiring 3D Secure could lose the password entered during the initial checkout when the form resumed after authentication. s2Member now keeps the same pending WordPress account through authentication and completes it with the password the customer originally chose. | |
| 222 | + | |
| 223 | +- (Pro) **Fix:** Closed a remaining failed-3D-Secure cleanup case where Stripe.js could return an authentication error without the PaymentIntent details used by s2Member's cleanup flow. s2Member now recovers the PaymentIntent ID from the existing Stripe client secret when needed so the incomplete subscription can still be cleaned up correctly. | |
| 224 | + | |
| 225 | +- (Pro) **Fix:** Failed card authentication during Stripe free-trial subscription checkout could leave the pending subscription active in a trialing state at Stripe. s2Member now cancels the incomplete subscription generation so unsuccessful authentication attempts do not leave orphaned trial subscriptions behind. | |
| 226 | + | |
| 227 | +- (Pro) **Fix:** Immediately retrying a Stripe free-trial subscription with another card after failed authentication could overlap with cleanup of the previous attempt or fail to continue correctly. s2Member now safely finishes that cleanup, confirms the retried authentication when needed, and starts a fresh subscription attempt without browser and webhook recovery interfering with each other. | |
| 228 | + | |
| 229 | +- (Pro) **Compatibility:** Improved Stripe SDK loading so s2Member does not accidentally trigger another plugin's dormant Stripe autoloader. This prevents an older Stripe library registered by another plugin from loading before s2Member Pro's bundled Stripe SDK. | |
| 230 | + | |
| 231 | +- (Pro) **Fix:** Prevented a PHP warning during Stripe Buy Now checkouts for existing members when determining whether a previous recurring subscription should be cancelled. | |
| 232 | + | |
| 233 | +- (Framework) **Compatibility:** Expanded no-cache support for caching solutions that use their own page-exclusion APIs or signals in addition to the commonly supported WordPress no-cache conventions. Added explicit compatibility for LiteSpeed Cache, FlyingPress, Super Page Cache for Cloudflare, WP Fastest Cache, and Cloudflare APO, helping prevent dynamic/private s2Member pages from being cached. | |
| 234 | + | |
| 235 | +- (Pro) **Fix:** When `[s2Member-List]` used `rlc_satisfy="ANY"` with multiple Levels, Roles, or Custom Capabilities, additional filtering on the member list could cause unrelated members to appear. Membership filters are now grouped correctly, so only members matching the requested criteria are returned. Thanks to Philip for reporting this. | |
| 236 | + | |
| 237 | +- (Framework) **Fix:** PayPal IPN domain checks could fail on some server setups when the incoming request did not provide a usable domain, for example with some reverse-proxy setups where something like Nginx, Cloudflare, a load balancer, etc. sits in front of WordPress and affects the request host. s2Member now falls back to the site's configured domain when needed. | |
| 238 | + | |
| 239 | +- (Framework) **Fix:** Some unexpected PayPal proxy values could cause notifications to fail and be ignored. These values are now normalized before the notification is processed. | |
| 240 | + | |
| 241 | +- (Framework) **Fix:** PayPal proxy notifications could fail on sites where their domain differs from the site's configured domain. s2Member now uses the appropriate site domain more consistently in these cases. | |
| 242 | + | |
| 243 | +- (Framework) **Fix:** Corrected the timeout value passed to the Mailchimp API client, preventing an invalid HTTP stream configuration that could interfere with list subscription requests. | |
| 244 | + | |
| 245 | +- (Framework) **Fix:** Avoided calling WordPress's deprecated `force_ssl_login()` helper on current WordPress versions when determining login and RPC URL schemes, preventing deprecation notices while preserving the same SSL behavior and compatibility with older WordPress versions. | |
| 246 | + | |
| 247 | +- (Framework) **Fix:** Prevented PHP notices from the `[s2Member-Security-Badge /]` shortcode when the optional `v` attribute is omitted. The shortcode now applies its default badge version before validating the value. | |
| 248 | + | |
| 249 | +- (Framework) **Fix:** Prevented PHP notices from the `[s2Stream /]` shortcode when the optional `player` attribute is omitted. Existing player defaults and behavior are unchanged. | |
| 250 | + | |
| 251 | +- (Framework & Pro) **UI:** Shortcode whitelist security notices are now more compact and easier to review, grouping detected user fields and template paths instead of repeating each shortcode occurrence, and listing the affected pages once with direct links. Thanks to Sherry for her feedback on these. _WP Admin > s2Member > General Options > Shortcode User Fields Whitelist_ and _Pro Shortcode Templates Whitelist_ | |
| 252 | + | |
| 253 | +- (Framework) **UI:** Corrected several PayPal Button Generator shortcode attribute descriptions to match current PayPal Checkout behavior, particularly the `output` and `image` attributes. | |
| 184 | 254 | |
| 185 | 255 | = v260917 = |
| 186 | 256 | |
| 187 | 257 | - (Framework) **Performance:** Further improved searching on the _WP Admin > Users_ screen, building on the performance improvements introduced in v260909. Searches across user profiles and s2Member membership data now require substantially less database work, with the biggest benefit on sites with large member databases. This can make member administration noticeably faster while preserving the same searchable fields, sorting, and pagination. |