# woocommerce-pos/1.10.21/includes/Templates/Renderers/Logicless_Renderer.php

WCPOS – Point of Sale (POS) plugin for WooCommerce, version 1.10.21. 97 lines.

- Page: https://pluginprobe.com/plugins/woocommerce-pos/1.10.21/code/includes/Templates/Renderers/Logicless_Renderer.php
- Raw: https://pluginprobe.com/plugins/woocommerce-pos/1.10.21/raw/includes/Templates/Renderers/Logicless_Renderer.php
- Modified: 2026-06-09T13:55:26+00:00

Line numbers below start at 1. Link to a line or a range by appending a fragment to the
page URL, for example `https://pluginprobe.com/plugins/woocommerce-pos/1.10.21/code/includes/Templates/Renderers/Logicless_Renderer.php#L10-L20`.

```php
<?php
/**
 * Logicless receipt renderer.
 *
 * Uses Mustache.php to render templates with section blocks:
 *   {{#key}}...{{/key}}  — iterate arrays or show block for truthy values
 *   {{^key}}...{{/key}}  — show block when value is empty/falsy
 *   {{.}}                — current value (for arrays of scalars)
 *   {{key.path}}         — dot-path placeholder substitution
 *
 * Money fields are pre-formatted as currency before rendering.
 *
 * @package WCPOS\WooCommercePOS\Templates\Renderers
 */

namespace WCPOS\WooCommercePOS\Templates\Renderers;

use Mustache\Engine as Mustache_Engine;
use WCPOS\WooCommercePOS\Interfaces\Receipt_Renderer_Interface;
use WCPOS\WooCommercePOS\Services\Receipt_Data_Schema;
use WCPOS\WooCommercePOS\Templates\Barcode_Image;
use WC_Abstract_Order;

/**
 * Logicless_Renderer class.
 */
class Logicless_Renderer implements Receipt_Renderer_Interface {

	/**
	 * Render logicless template output.
	 *
	 * @param array                  $template     Template metadata/content.
	 * @param WC_Abstract_Order|null $order        Order object, or null for sample-data preview.
	 * @param array                  $receipt_data Canonical receipt payload.
	 */
	public function render( array $template, ?WC_Abstract_Order $order, array $receipt_data ): void {
		$content = isset( $template['content'] ) && \is_string( $template['content'] ) ? $template['content'] : '';

		if ( '' === $content ) {
			echo '<!-- Empty logicless receipt template -->';
			return;
		}

		$currency       = $receipt_data['order']['currency'] ?? 'USD';
		$formatted_data = Receipt_Data_Schema::format_money_fields( $receipt_data, $currency );

		// Safety net: if a template uses {{#t}}...{{/t}} markers (from gallery source),
		// setting t = true makes Mustache pass the inner text through unchanged.
		$formatted_data['t'] = true;

		// Strip HTML comments — wp_kses_post removes the delimiters but leaves the text.
		$content = preg_replace( '/<!--.*?-->/s', '', $content );

		$flags    = ENT_QUOTES | ENT_SUBSTITUTE;
		$mustache = new Mustache_Engine(
			array(
				'entity_flags' => $flags,
				'escape'       => function ( $value ) use ( $flags ) {
					if ( \is_array( $value ) ) {
						return '';
					}

					return htmlspecialchars( (string) $value, $flags, 'UTF-8' );
				},
			)
		);

		$output = $mustache->render( $content, $formatted_data );

		// Swap <barcode>/<qrcode> markup for placeholder tokens before sanitizing
		// (wp_kses_post would otherwise strip the unknown elements, leaving only the
		// bare value as text). The rasterized PNG <img> tags are spliced back in
		// after sanitization, so their data: image URI never has to be whitelisted
		// in kses. Mirrors the client-side preview renderer.
		$barcode_images = array();
		$output         = Barcode_Image::replace_markup( $output, $barcode_images );

		// Allow print-color-adjust in inline styles so background fills survive print.
		// wp_kses_post drops CSS properties not on the safe_style_css allowlist by default.
		$allow_print_color_adjust = function ( array $styles ): array {
			$styles[] = 'print-color-adjust';
			$styles[] = '-webkit-print-color-adjust';

			return $styles;
		};

		add_filter( 'safe_style_css', $allow_print_color_adjust );

		try {
			$sanitized = wp_kses_post( $output );
			echo $barcode_images ? strtr( $sanitized, $barcode_images ) : $sanitized; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- $sanitized is kses'd; spliced values are self-generated PNG <img> tags.
		} finally {
			remove_filter( 'safe_style_css', $allow_print_color_adjust );
		}
	}
}

```
