| @@ -3,11 +3,8 @@ | ||
| 3 | 3 | > **The biggest WCPOS release ever.** Almost three months of work, ~330 substantive PRs. Highlights below. |
| 4 | 4 | |
| 5 | 5 | ## Unreleased |
| 6 | 6 | |
| 7 | -- Fixed: removing a coupon from a cart that had already been saved to the server made the next Checkout or Save fail ("Coupon code is required", HTTP 400), so the sale could not be completed until the coupon was put back or the cart rebuilt. The till marks a saved coupon line for removal with the same `code: null` marker it uses for a removed product, fee or shipping line, but WooCommerce handles coupon lines by code rather than by id, so the marker reached it as a coupon line with no code. Both order lanes (`wcpos/v2` push and `wcpos/v1`) now read the marker as a removal: the coupon is taken off the order and the totals recalculated, and a marker for a coupon that is already gone is ignored. Reported 2026-10-07 and reproduced on the demo store. | |
| 8 | -- Fixed: a payment gateway that sends the customer to its own hosted checkout (Dintero, Mollie, PayPal, Klarna and others) jumped the till to the receipt before a payment method was chosen, since 1.10.20. The fix for pay-later gateways shipped in that version applied the gateway's POS order status as soon as the gateway returned success, which a hosted gateway also does at the moment it redirects, before any money has moved; marking the order Completed there made Dintero bounce it to On hold ("missing a transaction ID"), and the till reads either as a finished sale. The status is now applied only when the gateway redirects to the order's own received page, the way a quote, invoice or purchase-order gateway does, and only for a gateway that does not declare WooCommerce's refund capability. A few refund-capable gateways (Mollie's Pay by Bank with its payment screen skipped, an async "received" result from a hosted provider) also return the customer to the received page while the money is still on its way, and nothing in that redirect tells them apart from a quote gateway; the refund capability does, because a gateway that can give money back is one that collects it. Hosted gateways are left open and settle from their callback as before. Merchants on 1.10.20–1.10.22 with such a gateway should update, or roll back to 1.10.19 until they can. | |
| 9 | -- Fixed (security): on WooCommerce below 9.9 a cashier could change a customer's role to Shop manager or any other role through WordPress's own user update routes — and to Administrator while WooCommerce was deactivated — because the Cashier role holds `edit_users` and (on older WooCommerce) `promote_users` and nothing limited which roles it may hand out. A till user can now assign only the Customer role, and a shop manager only what WooCommerce's own shop-manager list allows, wherever WordPress checks a role change (`editable_roles`, and the multisite invite). Reported by the WordPress.org automated security review of 1.10.21. | |
| 10 | 7 | - Added (developers): `GET /wcpos/v2/products?per_page=-1&_fields=id,date_modified_gmt,stock_quantity,stock_status` answers every published product the listing would return (products hidden from the POS excluded; `include`, `exclude`, `modified_after` and `dates_are_gmt` honoured) from one database query instead of hydrating each product. Stock values are read from each product's own stock fields, exactly as the product reports them. `GET /wcpos/v2/status` now lists `capabilities`, starting with `products_id_fast_path`. (#2113) |
| 11 | 8 | - Fixed: Changing or resetting a user's password signs that user out of the POS on every device. Logging out of WordPress in a browser ends the POS session in that browser only; the user's other tills stay signed in. (#2102) |
| 12 | 9 | - Fixed: Cashiers can only edit customer accounts. Any account with a staff role, other cashiers included, is out of their reach through the POS and through WordPress's own user screens and API. A cashier who also holds the Shop manager role keeps that role's rights. (#2104) |
| 13 | 10 | - Fixed: a payment gateway that never sets a customer-facing title showed a blank name in **POS → Settings → Checkout** and at the till. WCPOS now falls back to the name WooCommerce shows on its own Payments screen, and then to the gateway ID, and does the same for the description. A title you have set for the POS still wins. (#2122) |