Commit Graph
92 Commits
Author SHA1 Message Date
objecttothis 24dfac410d docs: document core/plugin boundary rules
Add explicit guidance in AGENTS.md and app/Plugins/README.md
stating core code must never reference a specific plugin.

- Clarify no plugin name/path may appear in composer.json,
  package.json, app/Config/*, or other core files
- State plugins resolve solely via PSR-4 autoloading and
  PluginManager runtime auto-discovery
- Note installing/removing a plugin must never require
  editing files outside app/Plugins/<PluginName>/

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-15 12:06:56 +04:00
objecttothis 3b7b41e119 fix(bootstrap-table): resolve lang file mismatch and improve locale handling
- Add `editable` override support in `bootstrap_tables_locale.php` to fix misaligned language file lookups for plugins.
- Update documentation explaining the issue and providing a resolution.
- Adjust `Sales` and `Attribute` logic for clearer naming (`sale_type` to `saleType`) and better attribute mapping (`attribute_id` added).

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-08 13:47:14 +04:00
Joshua Fernandes a97e579635 feat(plugins): add sale document view hooks, webhook CSRF exemption, and WhatsApp plugin
Add three missing plugin hook points for sale documents so plugins can
inject buttons into invoice, quote, and work order views alongside the
existing receipt hook. All four pass ['saleId' => $sale_id_num] and
follow the same naming pattern (view:sales_{type}_buttons).

Exempt plugins/*/webhook from CSRF filtering to support server-to-server
provider callbacks. Also convert the CSRF except list from a string to an
array — the previous 'login|migrate' string produced a single unanchored
pattern, making login/anything CSRF-exempt. Separate array entries anchor
each one individually. Plugin webhook handlers are responsible for their
own authentication.

Add WhatsApp Business Cloud API plugin (app/Plugins/WhatsAppPlugin/):
- Free-form messaging page registered as the 'whatsapp' office module
  with its own permission, plus per-customer modal and thread view
- "Send via WhatsApp" button on all four sale document types via the new
  hooks; renders only when the customer has a phone number
- PDF delivery using the same sales/{type}_email view core uses for email
- Inbound webhook at plugins/whatsapp/webhook authenticated by
  X-Hub-Signature-256 HMAC; fails closed on missing/bad signature;
  always returns 200 to suppress Meta retries
- Out-of-order status callbacks cannot downgrade sent → delivered → read
- Conversation log table via plugin migration; dropped on uninstall with
  version reset so re-install recreates it cleanly
- Access token and app secret encrypted at rest in plugin_config; no
  writes to app_config or initial_schema.sql
- utf8mb4_unicode_520_ci collation throughout (MySQL and MariaDB compat)
- Language file stubs for all existing locales; English strings complete
- README covering credentials, install, webhook setup, and uninstall
2026-09-07 12:32:37 +04:00
objecttothis dfec4b2fe4 docs(migrations): add guidelines for schema changes post-release
Document best practices for handling schema changes in plugins after release, emphasizing the need for creating new migration files instead of editing existing ones to ensure proper application of changes.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-03 15:36:53 +04:00
objecttothis fe33cb8e3f docs(plugins): document logging, API response, and flash-data patterns
Expand README with guidance drawn from recurring plugin review issues.

- Clarify that 'debug' is a log level, not a toggle — debug-only
  log lines must be gated behind a plugin's own debug_mode setting,
  and real errors belong in the standard log, not a named channel
- Warn that successfully parsed JSON does not mean an HTTP API call
  succeeded — branch on HTTP status code before trusting the body
- Note that PHP session flash data only works for forms that
  navigate to a new page; add a new section covering non-navigating
  AJAX/modal forms (e.g. item_saved, customer_saved), showing how to
  store the outcome, expose it via an endpoint, and poll/toast it
  from the injected view partial

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-03 15:03:49 +04:00
objecttothis 4a4ec6558e feat(items): add plugin hook for item form fields
Add new view hook `item_form_plugin_fields` to item add/edit
form, letting plugins inject custom UI controls (checkboxes,
inputs, etc.) into that form. Multiple plugins may register
callbacks for this hook.

- app/Views/items/form.php: call pluginContent() with item
  context after main item fields
- app/Plugins/README.md: document new hook in hook reference
  table

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-03 13:34:24 +04:00
Travis Garrison 184b483103 refactor(tests): move PluginTestCase to Tests\\Support namespace
- Relocate PluginTestCase from App\\Libraries\\Plugins to Tests\\Support
- Update all references in AGENTS.md, README.md, and test files
- Add TestModulePlugin fixture for module registration tests
- Add PluginModuleRegistrationTest covering namespace registration
- Add plugin_data_helper.js for zero-JS plugin form field collection

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-30 13:46:46 +04:00
Travis Garrison 59aa7f1ec2 refactor(plugins): enforce plugin id naming convention and auto-cleanup on uninstall
- Add `idMatchesPluginConvention()` guard to `BasePlugin` — rejects
  module/permission ids that don't match `{plugin_id}` or `{plugin_id}_*`
- Add `unregisterPluginModules()` to `PluginManager` — called automatically
  on uninstall; removes all modules and sub-permissions by convention prefix
- Plugins no longer need to call `unregisterModule()` in `uninstall()`
- Update README to document enforced naming convention, auto-cleanup
  behavior, and corrected language key / file location guidance

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-29 17:48:51 +04:00
Travis Garrison e58f56f8f0 fix(plugins): correct saleType parameter type from string to int
Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-29 13:46:40 +04:00
Travis Garrison 2340eab489 Merge remote-tracking branch 'OpensourcePOS/plugin-system-fresh' into plugin-system-fresh 2026-07-29 12:52:21 +04:00
Travis Garrison 87fa74749a feat(plugins): add module icon support and fix CSS ordering
- Add `view:module_icon_{module_id}` event for custom plugin icons
- Document icon injection pattern in README with 3-step example
- Add CSS rules for home/office module list image sizing (64px)
- Reorder CSS rules for logical grouping

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-29 12:52:04 +04:00
Joshua FernandesandJoshua Fernandes 6bdeb4f3e1 Plugin system: sale document view hooks and a webhook CSRF exemption (#4605)
* feat(plugins): add sale document view hooks and a webhook CSRF exemption

Plugins can already inject buttons into the receipt via
view:sales_receipt_buttons, but the invoice, quote and work order views have
no hook point, so a plugin that delivers sale documents can only reach one of
the four. Add the matching hooks, keeping the same name/data shape:

  view:sales_invoice_buttons
  view:sales_quote_buttons
  view:sales_work_order_buttons

Each passes ['saleId' => $sale_id_num] and sits in the same position as the
existing receipt hook, so one plugin callback can serve all four and branch on
the document type.

Also allow a plugin to expose an inbound provider webhook. A server-to-server
delivery carries no CSRF token and no session, so the global csrf filter now
excludes the pattern plugins/*/webhook. Plugins are responsible for
authenticating such requests themselves (typically by verifying the provider's
signature header against a shared secret) — this is documented alongside the
change.

While editing that line, the except list becomes an array. CodeIgniter matches
every entry as \A<pattern>\z, so the previous 'login|migrate' string produced a
single pattern whose inner alternatives were unanchored: 'login/anything' was
CSRF-exempt. Listing the entries separately anchors each one, which closes that
and keeps the new plugin pattern tight — plugins/whatsapp/webhook is exempt
while plugins/whatsapp/send is not.

* refactor(plugins): drop explanatory comments from csrf filter exceptions

---------

Co-authored-by: Joshua Fernandes <“joshua.1234511@yahoo.in”>
2026-07-29 03:06:31 +04:00
Travis Garrison 01f332ecb5 docs(plugins): add plugin test infrastructure and update AGENTS.md conventions
- Add Plugins testsuite to phpunit.xml.dist for auto-discovery
- Document PluginTestCase base class and test directory convention in README.md and AGENTS.md
- Tests resolve via existing App\\ PSR-4 mapping; no composer.json changes needed

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-28 15:49:49 +04:00
Travis Garrison b5ce31397b feat(plugins): add user_logged_in event and return_completed event
- Fire user_logged_in event on successful login authentication
- Add return_completed event distinct from sale_completed for return mode
- Update README with new events and clarify sale_completed fires non-return only
- Import CodeIgniter\\Events\\Events in Login controller

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-27 23:48:15 +04:00
Travis Garrison a6036cb082 feat(plugins): add registerModule helper and replace asset injection with explicit CSS links
- Add BasePlugin::registerModule() to register permission-system modules,
  auto-grant to admin (person_id=1), idempotent via INSERT IGNORE
- Replace inject:css/js placeholders in header.php with explicit versioned
  asset links for reliable loading outside build pipeline
- Update home.php module icons to use pluginContent() hook with SVG fallback,
  enabling plugins to override module icons

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-22 17:02:42 +04:00
Travis Garrison 1159d7d572 feat(plugins): add $pluginData support for events and form submissions
- Add `$pluginData` parameter to `Events::trigger` calls for key events (e.g., `sale_completed`, `customer_saved`)
- Update core views to include `data-plugin-form` attribute for plugin-field serialization
- Bundle `plugin_data_helper.js` to handle form field extraction for plugins
- Extend README.md with comprehensive documentation on using `$pluginData`
- Refactor language files to support `install` translations and streamline UI labels
- Add new view hooks for sales receipt and register UI extension

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-09 15:32:27 +04:00
Travis Garrison 584d38426c feat(plugins): add uninstall confirmation modal and soft-delete uninstall
- Intercept uninstall action to show confirmation modal before AJAX call
- Change uninstall to soft-delete: set installed=0 instead of purging all config
- Add deleteAllNonControlForPlugin to preserve control rows on uninstall
- Add isPluginInstalled helper to PluginManager for installed state checks
- Fix isInstalled guard to treat installed=0 as not installed

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-07 17:54:18 +04:00
Travis Garrison 376b351f17 feat(MailchimpPlugin): add none_selected_text key to all language files
Add missing `none_selected_text` translation key to all locale files
and prepend a blank \"none selected\" option to the subscription status
dropdown in the customer tab view.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-07 12:40:48 +04:00
Travis GarrisonandClaude Sonnet 4.6 e3b2359b4d Add CASPOSPlugin migration and update plugin migration docs
- Add first CASPOSPlugin migration: adds named FK caspos_sale_id_foreign
  and converts table collation to utf8mb4_0900_ai_ci
- Document plugin migration system in app/Plugins/README.md (directory
  structure, naming convention, class example, version tracking table)
- Add plugin system bullet to README.md feature list

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
2026-06-26 16:58:32 +04:00
objec 7dde48c0ed Plugin logger
- Create log_plugin_message() to prevent plugin logs from spamming the core logs
- Create ability to log to different logs or a base log if parameter is not specified.
- Update README.md
- Change BasePlugin::log() wrapper function to log to log_plugin_message() and add logTo() to log to a specific plugin log.
- Add plugin logger service to keep the logger loaded.

Signed-off-by: objec <objecttothis@gmail.com>
2026-06-12 00:57:35 +04:00
objec 0e10a85248 Change tense on trigger name for consistency
Signed-off-by: objec <objecttothis@gmail.com>
2026-05-29 15:15:50 +04:00
objec ad901f9c2d Add Receiving type to receiving_complete event trigger
- The type isn't found in the db, so send it to plugins.
- Update documentation

Signed-off-by: objec <objecttothis@gmail.com>
2026-05-21 13:13:48 +04:00
objec 388c8ad631 Add Receivings event trigger
Signed-off-by: objec <objecttothis@gmail.com>
2026-05-21 12:47:53 +04:00
objec 705c61b48c Update documentation
Signed-off-by: objec <objecttothis@gmail.com>
2026-05-20 23:09:58 +04:00
objec 50eead4da4 Updating customers save triggers to pass an array
- Customer CSV import will potentially have many customerIds to send to.
- Rework mailchimp onCustomerSaved() to receive an array of ids instead of a single ID

Signed-off-by: objec <objecttothis@gmail.com>
2026-05-20 19:41:38 +04:00
objec 4c7ac7b5d0 Thin contract triggers
- send only bare required data to trigger callbacks.
- Plugins for now access model, library and helpers but in the future access REST APIs only for data.

Signed-off-by: objec <objecttothis@gmail.com>
2026-05-20 19:27:36 +04:00
objec bed8a1c34d Error checking and validation
Signed-off-by: objec <objecttothis@gmail.com>
2026-05-20 19:05:23 +04:00
objec 10588867c4 Update configuration form to improve the UI
Signed-off-by: objec <objecttothis@gmail.com>
2026-05-20 17:57:34 +04:00
objec f650f17181 Push missing language strings file changes and HomeTest
Signed-off-by: objec <objecttothis@gmail.com>
2026-05-19 16:16:27 +04:00
objec 445a506ea8 Plugin Changes
- Remove unneeded language line from MailchimpPlugin
- Update README.md
- Normalized fields_required_message

Signed-off-by: objec <objecttothis@gmail.com>
2026-05-18 16:08:33 +04:00
objec e5fdea85f3 Update README.md to clarify plugin
Signed-off-by: objec <objecttothis@gmail.com>
2026-05-05 16:00:15 +04:00
objec cd91ac3ff3 Fix bugs
- Add missing `MailchimpPlugin.` prefix to lang() calls.
- Do not subscribe customer if consent is not true.
- Escape output in tabular_helper.php
- Removed testConnection() as unneeded code
- Fix activity count logic
- Whitelist Sort Column Headers for Plugins.php
- Store encrypted API key as base64 instead of raw binary to prevent truncation
- Rollback on batchSave partial failure.
- Remove dead code.
- Disable plugin before uninstalling it.
- Fix getPluginSettings() internal key leak
- Add action column to plugin headers function
- Automatically add grant to all admins in case person_id 1 is not active

Signed-off-by: objec <objecttothis@gmail.com>
2026-05-05 15:06:04 +04:00
objec 4d266c9b5e Correct mailchimp deletion issues and response codes
- Add function to correctly interpret subscription status from the API
- Error validation on customer deletion.
- Corrected PHPDoc to reflect reponse codes.
- Pass complete data to synchronize subscription function
- Rework request function to properly interpret response
- Add data to trigger
- Unsubscribe customer before deleting them from Mailchimp to prevent error.

Signed-off-by: objec <objecttothis@gmail.com>
2026-05-05 13:04:30 +04:00
objec f71af765f8 Add missing customer_tab_nav file for MailchimpPlugin
Signed-off-by: objec <objecttothis@gmail.com>
2026-04-30 14:12:55 +04:00
objec 4246a915c4 - Correct README.md reference to views and information about renderView()
- Fix the output of pluginContent in the pluginHelper
- Register view injection events
- Correct the parameter type in getMailchimpViewData
- Correct the statusOptions creation business logic
- Removed unnecessary view injection point
- Corrected which variable was passed to the customer_saved event
- Assigned $customer_data['person_id'] on customer update
- Added renderView() function to BasePlugin.php

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-30 14:11:54 +04:00
objec d2d0c8bf37 Add routes file to MailchimpPlugin to handle custom routes
Signed-off-by: objec <objecttothis@gmail.com>
2026-04-30 11:23:56 +04:00
objec 6c55526479 Settings fixes for MailchimpPlugin
- Add PHPdoc including @noinspection to prevent AJAX function from causing a warning.
- Add lists array to settings retrieval in MailchimpPlugin.php
- Close modal window on Submit
- Don't check API key on empty value

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-30 11:22:59 +04:00
objec fe331c34dd Mailchimp Bugfixes
- Update README.md to reflect information about routes
- Add registerAllNamespaces() function to correctly load plugin  namespaces
- center text in modal title
- Properly decrypt the api key
- Refactor getAllLists to getLists
- Naming simplification of strings when mailchimp_ is redundant or unnecessary
- Do not attempt to decrypt a plaintext api_key pasted into the form
- Register namespaces early on in system init

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-29 18:25:21 +04:00
objec 6630fb56f6 Fix language discovery bugs
- Remove unneeded keys from Config.php
- Remove unneeded lang() function override from BasePlugin.php
- Update README.md to reflect changes to language loading
- Correct language file string
- Correct lang() function calls to remove `$this->` from the call since we aren't overriding it anymore.
- Add code to correctly register namespace so that languages load.
- Fix plugin view render bug

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-29 16:31:14 +04:00
objec 2f48e0499f Plugin discovery bugfix
- Fix namespace typo causing plugin to not load
- Code cleanup

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-29 15:20:08 +04:00
objec cbabe1d56c Bugfix: Fix recursive view call
- Fix bug causing all plugin views to be rendered on every page.
- Simplify code
- Refactor manage.php view to use bootstrap tables

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-29 15:02:48 +04:00
objec 8c1c9d85dc Language Refactor
- Correct key name in language files.
- Update translations.
- Correct key usage.

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-29 14:54:16 +04:00
objec 32997d48c0 Fix persistence problem with plugin registration.
- Move the PluginManager creation to a service.
- Move plugin discovery to creation.
- Create static discovery and namespaces variables in the PluginManager.php library
- Refactor persistent namespace declarations
- Refactor redundant code to private function.
- Remove whitespace
- Remove enable setting from MailchimpPlugin. That is handled by the PluginManager.php
- Update Events.php to call the pluginManager service
- Correct typo in enabled setting for BasePlugin to accurately reflect the database naming.

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-29 10:31:04 +04:00
objec 1a9e84bd37 Fix bugs preventing plugins from working
- Move Plugins controller and rename to reflect the rest of the code.
- Lazy load event registrations.
- Autoload classes so plugins are discovered.
- Remove TODO
- Remove unneeded use statement
- Correct typo in namespace of MailchimpConnector Library
- Add class names to autoload class map
- Move Plugin discovery to post_controller_constructor event

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-23 16:26:50 +04:00
objec c796b52c22 Correct mistakes in plugin code related to loading.
- Add plugin module to list of required admin modules.
- Don't trigger autoloader in plugin discovery.
- Delete plugins_config.php which is no longer needed for managing plugins.
- Remove references to plugins_configuration in config views.
- Correct the form submission URL path.

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-23 12:42:34 +04:00
objec f863be68f9 Plugins migration
- Remove blank line
- Add plugin SVG icon to gulpfile.js
- Add plugin details to SQL migration script

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-23 11:25:21 +04:00
objec 54c476a498 MailchimpPlugin simplifications.
- Removed use statements
- Refactored key name
- Refactored MailchimpLibrary.php functions
- Removed
- Refactored function name for clarity
- Removed calls to model functions
- Corrected alignment of `=>` in language files

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-22 18:32:44 +04:00
objec ec139c477a Removed unnecessary models since information will be fetched directly from the mailchimp API each time.
Signed-off-by: objec <objecttothis@gmail.com>
2026-04-22 17:00:34 +04:00
objec bae361c637 Langauge file changes
- Added phrase to MailchimpPlugin.php language files
- updated calls to lang to call the correct phrases

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-22 15:32:05 +04:00
objec dcfdc212da Language Strings refactor
- Add strings representing subscription statuses.
- Resort strings alphabetically per standard practice.
- Aligned strings.
- Corrected es_ES string error

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-21 18:21:03 +04:00