| @@ -3,8 +3,9 @@ | ||
| 3 | 3 | > **The biggest WCPOS release ever.** Almost three months of work, ~330 substantive PRs. Highlights below. |
| 4 | 4 | |
| 5 | 5 | ## Unreleased |
| 6 | 6 | |
| 7 | +- Fixed: a payment gateway that sends the customer to its own hosted checkout (Dintero, Mollie, PayPal, Klarna and others) jumped the till to the receipt before a payment method was chosen, since 1.10.20. The fix for pay-later gateways shipped in that version applied the gateway's POS order status as soon as the gateway returned success, which a hosted gateway also does at the moment it redirects, before any money has moved; marking the order Completed there made Dintero bounce it to On hold ("missing a transaction ID"), and the till reads either as a finished sale. The status is now applied only when the gateway redirects to the order's own received page, the way a quote, invoice or purchase-order gateway does, and only for a gateway that does not declare WooCommerce's refund capability. A few refund-capable gateways (Mollie's Pay by Bank with its payment screen skipped, an async "received" result from a hosted provider) also return the customer to the received page while the money is still on its way, and nothing in that redirect tells them apart from a quote gateway; the refund capability does, because a gateway that can give money back is one that collects it. Hosted gateways are left open and settle from their callback as before. Merchants on 1.10.20–1.10.22 with such a gateway should update, or roll back to 1.10.19 until they can. | |
| 7 | 8 | - Fixed (security): on WooCommerce below 9.9 a cashier could change a customer's role to Shop manager or any other role through WordPress's own user update routes — and to Administrator while WooCommerce was deactivated — because the Cashier role holds `edit_users` and (on older WooCommerce) `promote_users` and nothing limited which roles it may hand out. A till user can now assign only the Customer role, and a shop manager only what WooCommerce's own shop-manager list allows, wherever WordPress checks a role change (`editable_roles`, and the multisite invite). Reported by the WordPress.org automated security review of 1.10.21. |
| 8 | 9 | - Added (developers): `GET /wcpos/v2/products?per_page=-1&_fields=id,date_modified_gmt,stock_quantity,stock_status` answers every published product the listing would return (products hidden from the POS excluded; `include`, `exclude`, `modified_after` and `dates_are_gmt` honoured) from one database query instead of hydrating each product. Stock values are read from each product's own stock fields, exactly as the product reports them. `GET /wcpos/v2/status` now lists `capabilities`, starting with `products_id_fast_path`. (#2113) |
| 9 | 10 | - Fixed: Changing or resetting a user's password signs that user out of the POS on every device. Logging out of WordPress in a browser ends the POS session in that browser only; the user's other tills stay signed in. (#2102) |
| 10 | 11 | - Fixed: Cashiers can only edit customer accounts. Any account with a staff role, other cashiers included, is out of their reach through the POS and through WordPress's own user screens and API. A cashier who also holds the Shop manager role keeps that role's rights. (#2104) |