PluginProbe
WCPOS – Point of Sale (POS) plugin for WooCommerce / 1.10.21
WCPOS – Point of Sale (POS) plugin for WooCommerce v1.10.21
1.10.24 1.10.23 1.10.22 1.10.21 1.10.20 1.10.19 1.10.18 1.10.17 1.10.16 1.10.15 1.10.13 1.10.14 1.10.12 1.10.11 1.10.10 1.10.9 1.10.8 untagged-3d9b7ccddc54df87c672 1.10.7 1.10.6 1.10.5 1.10.3 1.10.4 1.10.2 1.10.1 All 168 releases
← All changes | CHANGELOG.md +22 -0 1.10.0 → 1.10.21 View file →
@@ -3,8 +3,29 @@
3 3 > **The biggest WCPOS release ever.** Almost three months of work, ~330 substantive PRs. Highlights below.
4 4
5 5 ## Unreleased
6 6
7 +- Added (developers): `GET /wcpos/v2/products?per_page=-1&_fields=id,date_modified_gmt,stock_quantity,stock_status` answers every published product the listing would return (products hidden from the POS excluded; `include`, `exclude`, `modified_after` and `dates_are_gmt` honoured) from one database query instead of hydrating each product. Stock values are read from each product's own stock fields, exactly as the product reports them. `GET /wcpos/v2/status` now lists `capabilities`, starting with `products_id_fast_path`. (#2113)
8 +- Fixed: Changing or resetting a user's password signs that user out of the POS on every device. Logging out of WordPress in a browser ends the POS session in that browser only; the user's other tills stay signed in. (#2102)
9 +- Fixed: Cashiers can only edit customer accounts. Any account with a staff role, other cashiers included, is out of their reach through the POS and through WordPress's own user screens and API. A cashier who also holds the Shop manager role keeps that role's rights. (#2104)
10 +- Fixed: a payment gateway that never sets a customer-facing title showed a blank name in **POS → Settings → Checkout** and at the till. WCPOS now falls back to the name WooCommerce shows on its own Payments screen, and then to the gateway ID, and does the same for the description. A title you have set for the POS still wins. (#2122)
11 +- Fixed: a cashier whose role lacks `edit_others_shop_orders` (or `delete_others_shop_orders`) could not edit or delete their **own** sales. "Own" was decided from the order's WordPress post author, which WooCommerce sets to user #1 on classic order storage and to whoever was logged in when the row was created on HPOS — neither is the cashier. The POS now treats the cashier an order is assigned to (the one shown on the order in WooCommerce admin) as its owner, on both storage modes; web orders belong to no cashier and still need the `others` capability. Stores using the default Cashier role, which holds `edit_others_shop_orders`, see no change.
12 +
13 +- Changed: the `wcpos/v2` service map is now derived from the v1 controller map, so a plugin replacing a v1 service through `woocommerce_pos_rest_api_controllers` answers under `wcpos/v2` as well without registering a v2 twin. The fifteen `WCPOS\WooCommercePOS\API\V2\*` pass-through classes are gone and their names alias the v1 classes; a class registered through `woocommerce_pos_rest_api_v2_controllers` no longer needs its own `$namespace`. Outside the registry, subclasses of those aliases inherit the v1 namespace and must set their own.
14 +
15 +- Fixed: tills could keep showing **Online Only** products that the store had hidden from the POS. From 1.10.1 to 1.10.14 the POS product search could return a hidden product (fixed in 1.10.15), and a till that searched during that window stored it locally; the one-time removal notice that 1.10.1 wrote for hidden products predates those copies, and the catalogue change stream never mentions a hidden record again, so the copies stayed on the till until the client's own existence audit reached them — which on a host reporting sustained load runs only a little at a time. Upgrading now writes a fresh removal notice for every hidden product and variation, and every till drops its stale copies on its next ordinary sync, no reset or manual sync needed.
16 +- Fixed: the **POS Only** and **Online Only** counts above the WooCommerce products list counted trashed and auto-draft products, so the count could exceed the rows the view opens to. They now count the same statuses as WordPress's own "All" view. Note that, like "All", these counts include private, draft and scheduled products, so an Online Only count is expected to be larger than the published Online Only products the POS excludes; add `&post_status=publish` to the view's URL to see the published subset.
17 +- Changed: v2 product search requires every typed word to match in any order across title, SKU and barcode; variations search SKU and barcode only. This change pairs with the client release.
18 +
19 +- Fixed: removing a **variation** from a cart that had already been saved to the server did not stick — the next save brought the variation back, with the store's totals jumping to match. A 1.10.0 regression: the `wcpos/v2` order forward drops the product identity from a variation line whose binding has not changed, so WooCommerce does not duplicate its attribute meta on every re-save, but the till's remove-this-line marker (`product_id: null` on the full settled line) was mistaken for such an unchanged binding and the marker was stripped along with it. Removed variation lines are now forwarded with their marker intact and WooCommerce removes them. Simple products were never affected.
20 +- Added: receipt discount rows now expose `discount_type`, the WooCommerce coupon type behind each row (`fixed_cart`, `percent`, `fixed_product`, or a type registered by another plugin), so templates and extensions can tell different kinds of coupon apart. Receipt Data schema version is now 1.2.0. Fiscal snapshots captured before this version do not carry the field.
21 +- Added: `woocommerce_pos_receipt_data` filter on the canonical receipt payload, applied for live receipts, fiscal snapshots, PDF downloads and legacy PHP templates alike. Extensions can add their own keys to any section or adjust labels — the way WooCommerce lets plugins filter order item totals — instead of WCPOS carrying vendor-specific fields. The filter receives the payload, the order and the receipt mode.
22 +- Fixed: exact SKU and configured-barcode matches now rank ahead of partial matches in POS product search.
23 +- Fixed: sorting the POS product **or variation** grid by SKU, barcode, stock quantity or stock status hid records instead of just reordering them. The sort was applied as a WordPress `meta_key` sort, which inner-joins the postmeta table, so any product with no value for that field dropped out of the results entirely — and because the barcode field defaults to WooCommerce's GTIN field, which most catalogues never fill in, sorting by barcode returned an **empty grid** on a default store. Sorting by SKU silently hid every product without a SKU, and the same happened inside a category filter. All four sorts now keep every product and every variation, placing the records with no value last whichever way the column is sorted, on both the `wcpos/v1` and `wcpos/v2` lanes. (#1779, #1799)
24 +- Fixed: the `_woocommerce_pos_refresh_tokens` user meta grew without bound. Every login appended a session record (user agent plus parsed device info) and nothing was ever removed except on an explicit revoke, so a client that logs in programmatically eventually produced a row `get_user_meta()` could no longer unserialize inside the PHP memory limit — a fatal that rendered as an empty HTTP 200, after which that user could never log in again. WCPOS now keeps up to 200 sessions per user and, once past that, tidies away only sessions that have gone **unseen for a week** — a device that is in use is never signed out to make room, even if that means holding more than 200 for a while. Every authenticated request marks its session as active, so a till working through the day cannot look idle. A row so large it can no longer be read at all (past 6 MB) is still detected by its stored length and discarded before it is loaded, because the alternative is a user who can never log in again; anything smaller is simply trimmed. (#1776, #1798)
25 +- Fixed: sorting the POS product grid by SKU, barcode, stock quantity or stock status failed on the `wcpos/v2` sync lane. `wcpos/v1` has implemented those four sorts since 1.9, but the v2 catalogue proxy forwarded them to WooCommerce's own products endpoint, whose `orderby` enum rejected them with a 400 — so every server-side page fetch for those columns failed and the grid showed only what the till had already downloaded. The four sorts are now declared once in `Sync\Collection_Rules` and applied on both Read Lanes, with the same NULL-last handling for products that do not manage stock. (#1779)
26 +- Fixed: `wcpos/v2` product search matched product descriptions, a 1.10 regression from the 1.9 `wcpos/v1` title/SKU/barcode search, so stores where many descriptions mention a brand word saw fewer POS results than existed. It now searches title, SKU and barcode only, as before. (#1777)
27 +- Fixed: deleting a product or coupon from the till permanently deleted it — the `wcpos/v2` push forwarded every catalogue delete as `force=true` and ignored the envelope's `force`. A delete without `force` now asks WooCommerce to trash the record and deletes permanently only where WooCommerce has no trash (categories, brands, tags, customers, variations); an explicit `force` is forwarded as sent. (#1741)
7 28 - **Breaking (developers):** `Init::remove_license_transient()` and its `pre_update_option_woocommerce_pos_pro_settings_license` hook are removed. The Pro licence option and both caches it cleared (`woocommerce_pos_pro_license_status` and `update_plugins`) belong to WCPOS Pro, which owns the licence Settings Section since wcpos/woocommerce-pos-pro#452 and now registers the handler itself (`Services\License_Cache`). A free-only install never had the option to watch, so nothing changes there; Pro installs run the bundled copy of this plugin and pick up both halves together.
8 29 - **Breaking (developers):** the `WCPOS\WooCommercePOS\API\Settings` REST controller is now an alias of `API\V1\Settings`, which serves every settings section through `get_section_settings()` / `update_section_settings()`. The per-section public methods (`get_general_settings()`, `update_access_settings()`, `get_general_endpoint_args()`, `remove_license_transient()`, …) are removed without compatibility wrappers; the REST routes and `woocommerce_pos_*` filters are unchanged, and the `Services\Settings` read API (`get_general_settings()`, `get_checkout_settings()`, …) is retained as supported public surface. Code that called or overrode the per-section controller methods must move to the section API; the licence-transient clear has moved out of this plugin entirely (see the `Init::remove_license_transient()` entry above).
9 30 - **Breaking (developers):** `Services\Settings::save_settings()` no longer persists settings ids that have no registered Settings Section. Previously any id fell through to a generic `woocommerce_pos_settings_{id}` option write carrying the `woocommerce_pos_pre_save_{id}_settings` filter and `woocommerce_pos_saved_{id}_settings` action; it now returns a `woocommerce_pos_settings_error` (HTTP 400) and writes nothing. Extensions that stored their own settings group this way must register it via the `woocommerce_pos_register_settings_sections` action — both hooks still fire for registered sections, under the same names. Reads are unaffected: `get_settings()` never resolved unregistered third-party ids.
10 31 - Added: anonymous analytics identifier (`wcpos_anon_id`) for the admin welcome screen — random UUID, no store data, deleted on uninstall, manageable via `wp wcpos anon-id rotate|delete`. Landing data contract `schema_version` bumped to 2.
@@ -10,8 +31,9 @@
10 31 - Added: anonymous analytics identifier (`wcpos_anon_id`) for the admin welcome screen — random UUID, no store data, deleted on uninstall, manageable via `wp wcpos anon-id rotate|delete`. Landing data contract `schema_version` bumped to 2.
11 32 - Added: `woocommerce_pos_consent_copy` filter so the tracking-consent prompt copy can be overridden.
12 33 - Added: `woocommerce_pos_get_anon_id()` accessor (used by the Pro licence-activation request).
13 34 - **Changed:** the till's customer list now includes every user on the site, not only those holding the `customer` role. Searching or browsing customers in WCPOS will now turn up administrators, shop managers, cashiers and any other user account. This is how the customer list has always behaved on the `wcpos/v2` sync lane and on the bulk-id pull the client syncs against — the older `wcpos/v1` list endpoint was the one place staff users were hidden, so the same search gave two different answers depending on which lane served it. Pass `role=customer` (or `roles[]=customer`) to narrow the list yourself.
35 +- Fixed: with **Enable decimal quantities** on, every product save forced the stock status of non-stock-managed products back to "In stock" — a manually selected "Out of stock" or "On backorder" was reverted on wp-admin update (present since 1.5.0). WCPOS now leaves the manual stock status untouched when "Manage stock" is unchecked, matching WooCommerce. Note: POS checkout's out-of-stock validation now also applies to such manually-out-of-stock products on decimal-quantity stores, as it always did with the setting off.
14 36 - Fixed: the `roles` (multi-role) filter and `modified_after` were silently ignored on the `wcpos/v2` customer lane — both were forwarded to WooCommerce's own customer endpoint, which has neither parameter and drops unknown ones without complaint. A narrowed request came back unnarrowed, and a `modified_after` customer pull re-fetched the whole customer list every tick.
15 37
16 38 ### 🌐 REST CORS contract
17 39