PluginProbe
WCPOS – Point of Sale (POS) plugin for WooCommerce / 1.10.22
WCPOS – Point of Sale (POS) plugin for WooCommerce v1.10.22
1.10.25 1.10.24 1.10.23 1.10.22 1.10.21 1.10.20 1.10.19 1.10.18 1.10.17 1.10.16 1.10.15 1.10.13 1.10.14 1.10.12 1.10.11 1.10.10 1.10.9 1.10.8 untagged-3d9b7ccddc54df87c672 1.10.7 1.10.6 1.10.5 1.10.3 1.10.4 1.10.2 All 169 releases
← All changes | CHANGELOG.md +0 -1 1.10.23 → 1.10.22 View file →
@@ -3,9 +3,8 @@
3 3 > **The biggest WCPOS release ever.** Almost three months of work, ~330 substantive PRs. Highlights below.
4 4
5 5 ## Unreleased
6 6
7 -- Fixed: a payment gateway that sends the customer to its own hosted checkout (Dintero, Mollie, PayPal, Klarna and others) jumped the till to the receipt before a payment method was chosen, since 1.10.20. The fix for pay-later gateways shipped in that version applied the gateway's POS order status as soon as the gateway returned success, which a hosted gateway also does at the moment it redirects, before any money has moved; marking the order Completed there made Dintero bounce it to On hold ("missing a transaction ID"), and the till reads either as a finished sale. The status is now applied only when the gateway redirects to the order's own received page, the way a quote, invoice or purchase-order gateway does, and only for a gateway that does not declare WooCommerce's refund capability. A few refund-capable gateways (Mollie's Pay by Bank with its payment screen skipped, an async "received" result from a hosted provider) also return the customer to the received page while the money is still on its way, and nothing in that redirect tells them apart from a quote gateway; the refund capability does, because a gateway that can give money back is one that collects it. Hosted gateways are left open and settle from their callback as before. Merchants on 1.10.20–1.10.22 with such a gateway should update, or roll back to 1.10.19 until they can.
8 7 - Fixed (security): on WooCommerce below 9.9 a cashier could change a customer's role to Shop manager or any other role through WordPress's own user update routes — and to Administrator while WooCommerce was deactivated — because the Cashier role holds `edit_users` and (on older WooCommerce) `promote_users` and nothing limited which roles it may hand out. A till user can now assign only the Customer role, and a shop manager only what WooCommerce's own shop-manager list allows, wherever WordPress checks a role change (`editable_roles`, and the multisite invite). Reported by the WordPress.org automated security review of 1.10.21.
9 8 - Added (developers): `GET /wcpos/v2/products?per_page=-1&_fields=id,date_modified_gmt,stock_quantity,stock_status` answers every published product the listing would return (products hidden from the POS excluded; `include`, `exclude`, `modified_after` and `dates_are_gmt` honoured) from one database query instead of hydrating each product. Stock values are read from each product's own stock fields, exactly as the product reports them. `GET /wcpos/v2/status` now lists `capabilities`, starting with `products_id_fast_path`. (#2113)
10 9 - Fixed: Changing or resetting a user's password signs that user out of the POS on every device. Logging out of WordPress in a browser ends the POS session in that browser only; the user's other tills stay signed in. (#2102)
11 10 - Fixed: Cashiers can only edit customer accounts. Any account with a staff role, other cashiers included, is out of their reach through the POS and through WordPress's own user screens and API. A cashier who also holds the Shop manager role keeps that role's rights. (#2104)