| @@ -3,8 +3,9 @@ | ||
| 3 | 3 | > **The biggest WCPOS release ever.** Almost three months of work, ~330 substantive PRs. Highlights below. |
| 4 | 4 | |
| 5 | 5 | ## Unreleased |
| 6 | 6 | |
| 7 | +- Fixed (security): on WooCommerce below 9.9 a cashier could change a customer's role to Shop manager or any other role through WordPress's own user update routes — and to Administrator while WooCommerce was deactivated — because the Cashier role holds `edit_users` and (on older WooCommerce) `promote_users` and nothing limited which roles it may hand out. A till user can now assign only the Customer role, and a shop manager only what WooCommerce's own shop-manager list allows, wherever WordPress checks a role change (`editable_roles`, and the multisite invite). Reported by the WordPress.org automated security review of 1.10.21. | |
| 7 | 8 | - Added (developers): `GET /wcpos/v2/products?per_page=-1&_fields=id,date_modified_gmt,stock_quantity,stock_status` answers every published product the listing would return (products hidden from the POS excluded; `include`, `exclude`, `modified_after` and `dates_are_gmt` honoured) from one database query instead of hydrating each product. Stock values are read from each product's own stock fields, exactly as the product reports them. `GET /wcpos/v2/status` now lists `capabilities`, starting with `products_id_fast_path`. (#2113) |
| 8 | 9 | - Fixed: Changing or resetting a user's password signs that user out of the POS on every device. Logging out of WordPress in a browser ends the POS session in that browser only; the user's other tills stay signed in. (#2102) |
| 9 | 10 | - Fixed: Cashiers can only edit customer accounts. Any account with a staff role, other cashiers included, is out of their reach through the POS and through WordPress's own user screens and API. A cashier who also holds the Shop manager role keeps that role's rights. (#2104) |
| 10 | 11 | - Fixed: a payment gateway that never sets a customer-facing title showed a blank name in **POS → Settings → Checkout** and at the till. WCPOS now falls back to the name WooCommerce shows on its own Payments screen, and then to the gateway ID, and does the same for the description. A title you have set for the POS still wins. (#2122) |