Releases: craftcms/commerce
Releases · craftcms/commerce
Release list
5.7.5
- Fixed a bug where the
dateAuthorizedorder query param incorrectly filtered on thedatePaid. - Fixed a bug where currency-based order condition rules could show the incorrect currency. (#4368)
- Fixed an error that could occur on order edit pages, for orders belonging to a non-primary store. (#4370)
- Fixed an error that could occur when deleting a completed order that contained a custom line item. (#4371)
- Fixed a moderate-severity authorization bypass vulnerability. (GHSA-wwpp-9fw2-4cxh)
5.7.4
- Fixed a bug where custom order fields with a visibility condition based on order attributes couldn’t be saved. (#4198)
- Fixed a bug where the Payment Amount field on order edit pages could get reformatted incorrectly per the user’s formatting locale. (#4109)
- Fixed a PHP error that could occur when using a date/time attribute in an order-related object template. (#4255)
- Fixed a PHP error on the Dashboard that could occur for users without edit permissions for any site. (#4347)
- Fixed a high-severity RCE vulnerability. (GHSA-w9pv-3qgc-2pq2)
- Fixed moderate-severity authorization bypass vulnerabilities. (GHSA-wr49-2q4p-354w, GHSA-jx83-gwwg-84gf, GHSA-w2cw-phpj-gcgw, GHSA-fw8v-h534-cqw2, GHSA-wfxq-r2hv-px5r)
4.12.4
- Fixed moderate-severity authorization bypass vulnerabilities. (GHSA-wr49-2q4p-354w, GHSA-jx83-gwwg-84gf, GHSA-w2cw-phpj-gcgw)
5.7.3
- Fixed a bug where
craft\commerce\elements\Order::setShippingAddress()andsetBillingAddress()weren’t setting custom field values. (#4353) - Fixed a bug where variants’ auto-generated SKUs would be incorrect if the SKU Format contained
{id}. - Fixed a bug where adding a new site via project config apply could cause additional project config changes. (#4348)
- Fixed a deprecation warning that was getting logged when accessing
/admin/commerce. (#4349)
4.12.3
- Craft Commerce now supports
dompdf/dompdf3.x, in addition to 2.x.
4.12.2
- Fixed a bug where inactive carts’ search index rows weren’t being purged. (#4344)
5.7.2
- Fixed a bug where inactive carts’ search index rows weren’t being purged. (#4344)
- Fixed a bug where saving the transfer field layout would override the order field layout. (#4345)
- Fixed a bug where generating a PDF or cart-load URL from a console request returned a blank URL. (#4343)
- Fixed a bug where completed orders could unintentionally have their recalculation mode set to “all”. (#4342)
- Fixed a low-severity business logic vulnerability. (GHSA-gcqr-xrx9-grcf)
4.12.1
- Fixed a bug where generating a PDF or cart-load URL from a console request returned a blank URL. (#4343)
5.7.1
- Fixed a bug where guest customers couldn’t load credentialed carts with a valid token. (#4225)
- Fixed a bug where Quantity fields’ input values could become jumbled within inventory modals. (#3920)
- Fixed a bug where the “Variant Search” product condition rule wasn’t returning any results. (#4339)
- Fixed a bug where variant field layout tabs displayed incorrectly within slideouts. (#4335)
- Fixed a PHP error that could occur when serializing a line item object. (#4337)
- Fixed a performance issue that occurred when resaving products in multi-site installs. (#4305)
5.7.0
Store Management
- Order edit screens now show notices to store administrators if there was a fluke with the order, such as a coupon/discount’s total usage being exceeded or inventory dropping below zero.
- Added the “Contains Purchasables” order condition rule. (#4242)
- Added the “Has Admin Notices” order condition rule.
- Added deletion blockers for users with existing orders or subscriptions.
- The “Share cart…” order element action now generates a secure tokenized URL.
- The inventory screen now has a “View” menu for showing/hiding table columns. (#4193)
Administration
- Craft Commerce user permissions are now organized into conceptual groups.
- Product permissions have been split into separate “View”, “Create”, “Save”, and “Delete” permissions.
- Added the
loadCartUrlExpirysetting, for controlling how long cart load links remain valid (seven days by default).
Development
- The
commerce/cart/get-cartaction now supports apeekparam, which returns cart info without creating a new cart or setting cookies. (#4263) - The
commerce/cart/load-cartaction now returns JSON responses forapplication/jsonrequests.
Extensibility
- Added
craft\commerce\base\ShippingMethod::clearMatchingShippingRuleCache(). - Added
craft\commerce\controllers\CartController::actionCartChallenge(). - Added
craft\commerce\controllers\CartController::actionCartSent(). - Added
craft\commerce\controllers\CartController::actionEmailChallenge(). - Added
craft\commerce\controllers\OrdersController::actionGetLoadCartUrl(). - Added
craft\commerce\controllers\OrdersController::actionGetShippingMethodOptions(). - Added
craft\commerce\controllers\OrdersController::actionReassign(). - Added
craft\commerce\controllers\OrdersController::actionReassignModal(). - Added
craft\commerce\controllers\OrdersController::actionRemoveCustomerData(). - Added
craft\commerce\controllers\OrdersController::actionRemoveCustomerDataModal(). - Added
craft\commerce\controllers\SubscriptionsController::actionDeleteSubscriptions(). - Added
craft\commerce\controllers\SubscriptionsController::actionDeleteSubscriptionsModal(). - Added
craft\commerce\db\Table::CATALOG_PRICING_QUEUE. - Added
craft\commerce\elements\Order::getAdminNotices(). - Added
craft\commerce\elements\Order::getCustomerDeleted(). - Added
craft\commerce\elements\Order::hasAdminNotices(). - Added
craft\commerce\elements\Order::hasPurchasables(). - Added
craft\commerce\elements\Order::hasPurchasables(). - Added
craft\commerce\elements\Order::setCustomerDeleted(). - Added
craft\commerce\elements\conditions\orders\ContainsPurchasablesConditionRule. - Added
craft\commerce\elements\conditions\orders\HasAdminNoticesConditionRule. - Added
craft\commerce\elements\db\OrderQuery::$containsPurchasables. - Added
craft\commerce\elements\db\OrderQuery::$containsPurchasables. - Added
craft\commerce\elements\db\OrderQuery::$hasAdminNotices. - Added
craft\commerce\elements\db\OrderQuery::containsPurchasables(). - Added
craft\commerce\elements\db\OrderQuery::containsPurchasables(). - Added
craft\commerce\elements\db\OrderQuery::hasAdminNotices(). - Added
craft\commerce\elements\deletionblockers\OrderCustomersDeletionBlocker. - Added
craft\commerce\elements\deletionblockers\SubscriptionCustomersDeletionBlocker. - Added
craft\commerce\enums\ContainsPurchasablesMatch. - Added
craft\commerce\enums\ContainsPurchasablesMatch. - Added
craft\commerce\enums\OrderNoticeType. - Added
craft\commerce\events\PaymentCurrencyRateEvent. - Added
craft\commerce\models\OrderNotice::$noticeType. - Added
craft\commerce\models\Settings::$loadCartUrlExpiry. - Added
craft\commerce\records\CatalogPricingQueue. - Added
craft\commerce\services\Carts::getLoadCartUrl(). - Added
craft\commerce\services\Carts::peekCart(). - Added
craft\commerce\services\CatalogPricing::deleteCatalogPricingQueueRowById(). - Added
craft\commerce\services\CatalogPricing::releaseCatalogPricingQueueRowById(). - Added
craft\commerce\services\CatalogPricing::reserveCatalogPricingQueueRow(). - Added
craft\commerce\services\Orders::reassignOrders(). - Added
craft\commerce\services\Orders::removeCustomerData(). - Added
craft\commerce\services\PaymentCurrencies::EVENT_DEFINE_PAYMENT_CURRENCY_RATE. - Added
craft\commerce\services\PaymentCurrencies::getRateFor(). - Added
craft\commerce\services\ProductTypes::getCreatableProductTypeIds(). - Added
craft\commerce\services\ProductTypes::getViewableProductTypeIds(). - Added
craft\commerce\services\ProductTypes::getViewableProductTypes(). - Added
craft\commerce\services\ShippingRuleCategories::getAllShippingRuleCategoriesData(). craft\commerce\elements\Order::clearNotices()now has a$noticeTypesargument.craft\commerce\elements\Order::getLoadCartUrl()now returns a secure tokenized URL.craft\commerce\elements\Order::getNotices()no longer returns admin notices. UsegetAdminNotices()instead.craft\commerce\elements\Subscription::getSubscriber()now returns?Userinstead ofUser.- Deprecated
craft\commerce\services\ProductTypes::getEditableProductTypeIds().getViewableProductTypeIds()should be used instead. - Deprecated
craft\commerce\services\ProductTypes::getEditableProductTypes().getViewableProductTypes()should be used instead. - Deprecated
craft\commerce\services\ProductTypes::hasPermission().$user->can()should be used instead.
System
- The
commerce/cart/cart-challengeandcommerce/downloads/pdf-challengeactions are now rate-limited based on IP. - Improved the performance of shipping method and rule matching.
- Improved the performance of catalog pricing queue jobs.
- Cart load URLs are now generated with time-limited security tokens, which are now required when loading carts from non-authenticated requests.
craft\commerce\services\Carts::getCart()now ensures the cart can always be recalculated. (#4332)- Craft Commerce now requires Craft CMS 5.10.0 or later.
- Craft Commerce now requires
ibericode/vat2.0 or later. - Craft Commerce now supports
dompdf/dompdf3.x, in addition to 2.x. - Fixed a bug where variants with
{id}in their Variant Title Format weren’t always getting created with the correct generated title. (#4308)