Skip to content

Releases: craftcms/commerce

5.7.5

Choose a tag to compare

@github-actions github-actions released this 23 Sep 15:13
7db348c
  • Fixed a bug where the dateAuthorized order query param incorrectly filtered on the datePaid.
  • Fixed a bug where currency-based order condition rules could show the incorrect currency. (#4368)
  • Fixed an error that could occur on order edit pages, for orders belonging to a non-primary store. (#4370)
  • Fixed an error that could occur when deleting a completed order that contained a custom line item. (#4371)
  • Fixed a moderate-severity authorization bypass vulnerability. (GHSA-wwpp-9fw2-4cxh)

5.7.4

Choose a tag to compare

@github-actions github-actions released this 15 Sep 23:14
a74df2f
  • Fixed a bug where custom order fields with a visibility condition based on order attributes couldn’t be saved. (#4198)
  • Fixed a bug where the Payment Amount field on order edit pages could get reformatted incorrectly per the user’s formatting locale. (#4109)
  • Fixed a PHP error that could occur when using a date/time attribute in an order-related object template. (#4255)
  • Fixed a PHP error on the Dashboard that could occur for users without edit permissions for any site. (#4347)
  • Fixed a high-severity RCE vulnerability. (GHSA-w9pv-3qgc-2pq2)
  • Fixed moderate-severity authorization bypass vulnerabilities. (GHSA-wr49-2q4p-354w, GHSA-jx83-gwwg-84gf, GHSA-w2cw-phpj-gcgw, GHSA-fw8v-h534-cqw2, GHSA-wfxq-r2hv-px5r)

4.12.4

Choose a tag to compare

@github-actions github-actions released this 15 Sep 23:15
2a8fb1c
  • Fixed moderate-severity authorization bypass vulnerabilities. (GHSA-wr49-2q4p-354w, GHSA-jx83-gwwg-84gf, GHSA-w2cw-phpj-gcgw)

5.7.3

Choose a tag to compare

@github-actions github-actions released this 02 Sep 14:08
5.7.3
c0bdc09
  • Fixed a bug where craft\commerce\elements\Order::setShippingAddress() and setBillingAddress() weren’t setting custom field values. (#4353)
  • Fixed a bug where variants’ auto-generated SKUs would be incorrect if the SKU Format contained {id}.
  • Fixed a bug where adding a new site via project config apply could cause additional project config changes. (#4348)
  • Fixed a deprecation warning that was getting logged when accessing /admin/commerce. (#4349)

4.12.3

Choose a tag to compare

@github-actions github-actions released this 22 Aug 02:18
  • Craft Commerce now supports dompdf/dompdf 3.x, in addition to 2.x.

4.12.2

Choose a tag to compare

@github-actions github-actions released this 13 Aug 00:58
  • Fixed a bug where inactive carts’ search index rows weren’t being purged. (#4344)

5.7.2

Choose a tag to compare

@github-actions github-actions released this 12 Aug 14:18
5.7.2
5fff937
  • Fixed a bug where inactive carts’ search index rows weren’t being purged. (#4344)
  • Fixed a bug where saving the transfer field layout would override the order field layout. (#4345)
  • Fixed a bug where generating a PDF or cart-load URL from a console request returned a blank URL. (#4343)
  • Fixed a bug where completed orders could unintentionally have their recalculation mode set to “all”. (#4342)
  • Fixed a low-severity business logic vulnerability. (GHSA-gcqr-xrx9-grcf)

4.12.1

Choose a tag to compare

@github-actions github-actions released this 12 Aug 13:30
4.12.1
40ad302
  • Fixed a bug where generating a PDF or cart-load URL from a console request returned a blank URL. (#4343)

5.7.1

Choose a tag to compare

@github-actions github-actions released this 22 Jul 14:19
5.7.1
b27440a
  • Fixed a bug where guest customers couldn’t load credentialed carts with a valid token. (#4225)
  • Fixed a bug where Quantity fields’ input values could become jumbled within inventory modals. (#3920)
  • Fixed a bug where the “Variant Search” product condition rule wasn’t returning any results. (#4339)
  • Fixed a bug where variant field layout tabs displayed incorrectly within slideouts. (#4335)
  • Fixed a PHP error that could occur when serializing a line item object. (#4337)
  • Fixed a performance issue that occurred when resaving products in multi-site installs. (#4305)

5.7.0

Choose a tag to compare

@github-actions github-actions released this 16 Jul 06:20

Store Management

  • Order edit screens now show notices to store administrators if there was a fluke with the order, such as a coupon/discount’s total usage being exceeded or inventory dropping below zero.
  • Added the “Contains Purchasables” order condition rule. (#4242)
  • Added the “Has Admin Notices” order condition rule.
  • Added deletion blockers for users with existing orders or subscriptions.
  • The “Share cart…” order element action now generates a secure tokenized URL.
  • The inventory screen now has a “View” menu for showing/hiding table columns. (#4193)

Administration

  • Craft Commerce user permissions are now organized into conceptual groups.
  • Product permissions have been split into separate “View”, “Create”, “Save”, and “Delete” permissions.
  • Added the loadCartUrlExpiry setting, for controlling how long cart load links remain valid (seven days by default).

Development

  • The commerce/cart/get-cart action now supports a peek param, which returns cart info without creating a new cart or setting cookies. (#4263)
  • The commerce/cart/load-cart action now returns JSON responses for application/json requests.

Extensibility

  • Added craft\commerce\base\ShippingMethod::clearMatchingShippingRuleCache().
  • Added craft\commerce\controllers\CartController::actionCartChallenge().
  • Added craft\commerce\controllers\CartController::actionCartSent().
  • Added craft\commerce\controllers\CartController::actionEmailChallenge().
  • Added craft\commerce\controllers\OrdersController::actionGetLoadCartUrl().
  • Added craft\commerce\controllers\OrdersController::actionGetShippingMethodOptions().
  • Added craft\commerce\controllers\OrdersController::actionReassign().
  • Added craft\commerce\controllers\OrdersController::actionReassignModal().
  • Added craft\commerce\controllers\OrdersController::actionRemoveCustomerData().
  • Added craft\commerce\controllers\OrdersController::actionRemoveCustomerDataModal().
  • Added craft\commerce\controllers\SubscriptionsController::actionDeleteSubscriptions().
  • Added craft\commerce\controllers\SubscriptionsController::actionDeleteSubscriptionsModal().
  • Added craft\commerce\db\Table::CATALOG_PRICING_QUEUE.
  • Added craft\commerce\elements\Order::getAdminNotices().
  • Added craft\commerce\elements\Order::getCustomerDeleted().
  • Added craft\commerce\elements\Order::hasAdminNotices().
  • Added craft\commerce\elements\Order::hasPurchasables().
  • Added craft\commerce\elements\Order::hasPurchasables().
  • Added craft\commerce\elements\Order::setCustomerDeleted().
  • Added craft\commerce\elements\conditions\orders\ContainsPurchasablesConditionRule.
  • Added craft\commerce\elements\conditions\orders\HasAdminNoticesConditionRule.
  • Added craft\commerce\elements\db\OrderQuery::$containsPurchasables.
  • Added craft\commerce\elements\db\OrderQuery::$containsPurchasables.
  • Added craft\commerce\elements\db\OrderQuery::$hasAdminNotices.
  • Added craft\commerce\elements\db\OrderQuery::containsPurchasables().
  • Added craft\commerce\elements\db\OrderQuery::containsPurchasables().
  • Added craft\commerce\elements\db\OrderQuery::hasAdminNotices().
  • Added craft\commerce\elements\deletionblockers\OrderCustomersDeletionBlocker.
  • Added craft\commerce\elements\deletionblockers\SubscriptionCustomersDeletionBlocker.
  • Added craft\commerce\enums\ContainsPurchasablesMatch.
  • Added craft\commerce\enums\ContainsPurchasablesMatch.
  • Added craft\commerce\enums\OrderNoticeType.
  • Added craft\commerce\events\PaymentCurrencyRateEvent.
  • Added craft\commerce\models\OrderNotice::$noticeType.
  • Added craft\commerce\models\Settings::$loadCartUrlExpiry.
  • Added craft\commerce\records\CatalogPricingQueue.
  • Added craft\commerce\services\Carts::getLoadCartUrl().
  • Added craft\commerce\services\Carts::peekCart().
  • Added craft\commerce\services\CatalogPricing::deleteCatalogPricingQueueRowById().
  • Added craft\commerce\services\CatalogPricing::releaseCatalogPricingQueueRowById().
  • Added craft\commerce\services\CatalogPricing::reserveCatalogPricingQueueRow().
  • Added craft\commerce\services\Orders::reassignOrders().
  • Added craft\commerce\services\Orders::removeCustomerData().
  • Added craft\commerce\services\PaymentCurrencies::EVENT_DEFINE_PAYMENT_CURRENCY_RATE.
  • Added craft\commerce\services\PaymentCurrencies::getRateFor().
  • Added craft\commerce\services\ProductTypes::getCreatableProductTypeIds().
  • Added craft\commerce\services\ProductTypes::getViewableProductTypeIds().
  • Added craft\commerce\services\ProductTypes::getViewableProductTypes().
  • Added craft\commerce\services\ShippingRuleCategories::getAllShippingRuleCategoriesData().
  • craft\commerce\elements\Order::clearNotices() now has a $noticeTypes argument.
  • craft\commerce\elements\Order::getLoadCartUrl() now returns a secure tokenized URL.
  • craft\commerce\elements\Order::getNotices() no longer returns admin notices. Use getAdminNotices() instead.
  • craft\commerce\elements\Subscription::getSubscriber() now returns ?User instead of User.
  • Deprecated craft\commerce\services\ProductTypes::getEditableProductTypeIds(). getViewableProductTypeIds() should be used instead.
  • Deprecated craft\commerce\services\ProductTypes::getEditableProductTypes(). getViewableProductTypes() should be used instead.
  • Deprecated craft\commerce\services\ProductTypes::hasPermission(). $user->can() should be used instead.

System

  • The commerce/cart/cart-challenge and commerce/downloads/pdf-challenge actions are now rate-limited based on IP.
  • Improved the performance of shipping method and rule matching.
  • Improved the performance of catalog pricing queue jobs.
  • Cart load URLs are now generated with time-limited security tokens, which are now required when loading carts from non-authenticated requests.
  • craft\commerce\services\Carts::getCart() now ensures the cart can always be recalculated. (#4332)
  • Craft Commerce now requires Craft CMS 5.10.0 or later.
  • Craft Commerce now requires ibericode/vat 2.0 or later.
  • Craft Commerce now supports dompdf/dompdf 3.x, in addition to 2.x.
  • Fixed a bug where variants with {id} in their Variant Title Format weren’t always getting created with the correct generated title. (#4308)