Commit Graph
223 Commits
Author SHA1 Message Date
objecttothis 3b7b41e119 fix(bootstrap-table): resolve lang file mismatch and improve locale handling
- Add `editable` override support in `bootstrap_tables_locale.php` to fix misaligned language file lookups for plugins.
- Update documentation explaining the issue and providing a resolution.
- Adjust `Sales` and `Attribute` logic for clearer naming (`sale_type` to `saleType`) and better attribute mapping (`attribute_id` added).

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-08 13:47:14 +04:00
objecttothis 73ae557688 fix(items): move plugin fields, sync plugin_data on change
- Move item_form_plugin_fields render point in form.php from top of
  fieldset to bottom, near closing form_close(), so plugin fields
  render after core item fields.
- Rework plugin_data_helper.js to sync plugin_data hidden field on
  every change/click of a [data-plugin-field] element, not just on
  form submit. Needed because some forms use jQuery Validate's
  submitHandler, which bypasses native submit event and would leave
  plugin_data stale.
- Refactor sync logic into reusable syncPluginData() helper invoked
  on initial load, on field change/click, and on submit.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-03 14:36:31 +04:00
objecttothis 4a4ec6558e feat(items): add plugin hook for item form fields
Add new view hook `item_form_plugin_fields` to item add/edit
form, letting plugins inject custom UI controls (checkboxes,
inputs, etc.) into that form. Multiple plugins may register
callbacks for this hook.

- app/Views/items/form.php: call pluginContent() with item
  context after main item fields
- app/Plugins/README.md: document new hook in hook reference
  table

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-03 13:34:24 +04:00
objecttothis 5e4632d55d Merge remote-tracking branch 'OpensourcePOS/master' into plugin-system-fresh
# Conflicts:
#	app/Controllers/Sales.php
#	app/Models/Sale.php
2026-09-02 11:35:39 +04:00
objecttothis 6db3dde491 Bugfix tax names (#4677)
bugfix(items, validation): reject unsafe tax names and fix payments temp table collision

- Add unicode_alpha_numeric_punct rule (OSPOSRules) to allow accented/CJK
  chars in text fields while blocking HTML-unsafe chars (<, >) as
  defense-in-depth against injection
- Items controller: extract validateItemFields/validateBulkUpdateFields,
  validate tax_names on save and bulk update using new rule; add shared
  validateFields helper in Secure_Controller to DRY up validation +
  JSON error response
- Escape tax_group output in sales/quote.php and receipt_email.php views
  to harden output encoding at render time
- Rename sales_payments_temp -> sales_report_payments_temp (Summary_report)
  and -> sales_search_payments_temp (Sale model) to avoid name collision
  between concurrently-created temp tables
- AGENTS.md: document alignment rule for => columns when inserting new
  language keys

Tests:
- Add ItemsControllerTest covering postSave/bulkupdate tax_names validation
- Reject <, > in tax_names on /items/save and /items/bulkupdate
- Verify unicode and apostrophe-containing tax names are accepted
- Cover CSV import helpers: header generation (basic, multiple locations,
  attributes), stock-location/attribute header builders, get_csv_file
  parsing (plain, BOM-prefixed, multi-row)
- Validate required-header detection for import templates
- Remove outdated tax name test from SalesControllerTest
- Simplify Database class references in SalesControllerTest

i18n:
- Add tax_name_invalid translation to Items.php for 20+ locales, inserted
  alphabetically after tax_category in each file
- Normalize quote style in ar-EG/Items.php to single quotes
- Add ka/Items.php Georgian locale scaffold

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-09-01 10:59:29 +04:00
objecttothis 459610cded Merge branch 'master' into plugin-system-fresh 2026-08-31 16:18:59 +04:00
objecttothis 84bddcdd88 Feature admin account safeguards (#4657)
fix(employees): harden permissions UI and access control

- Prevent admins from removing their own minimum module grants (employees, home, office)
- Add session_status check before session regeneration
- Disable submit button and return no_access view for AJAX requests
- Replace fade class with active-only for Bootstrap compatibility
- Update permission toggle selectors to .module-toggle
- Add error_cannot_remove_own_minimum_grant translations for Armenian, Bulgarian, Georgian, Swedish, and Ukrainian

---------

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-27 11:29:32 +04:00
objecttothis a9526a6334 Merge remote-tracking branch 'OpensourcePOS/master' into plugin-system-fresh
# Conflicts:
#	app/Controllers/Items.php
#	app/Models/Item_quantity.php
#	app/Models/Sale.php
2026-08-20 11:18:18 +04:00
objecttothis 29a9b1a7e7 Bugfix: Resolve Race Condition in Rewards and Gift Card Spending (#4640)
* Implement atomic updates for gift card and reward point decrements, enhance error handling for insufficient balances, and add regression tests for concurrency safety.

* Add translations for insufficient gift card balance and reward points error messages across all supported languages.

* Reorder `clear_suspended_sale_detail` call to ensure transactional consistency.

* Reorder `clear_all` call to align with success and error handling logic.

* Ensure soft-deleted gift cards are excluded in balance updates.

* Refactor change_quantity logic with atomic upserts, improve error handling for insufficient stock, and update related tests and constants.

* Added check for NEW_ENTRY

* Added unit tests to test changes.

* Fix class name casing in ItemQuantityTest for consistency.

* Fix Bulgarian translations for insufficient balance error messages in Sales module.

* Fix Greek translations for insufficient balance error messages in Sales module.

* Fix Armenian translations for insufficient balance error messages in Sales module.

* Fix Tamil translations for insufficient balance error messages in Sales module.

* Implement race condition testing for database methods with concurrent process support.

* Fix class name casing in ItemTest for consistency.

* Improve concurrent process handling in race condition tests; add readiness and synchronization barriers.

* Improve handling of process I/O streams and timeout management in race condition tests.

* Add test for decrementing gift card value when marked as deleted

* Add `finally` block to ensure proper cleanup in async database race condition tests

* Improve error handling and timeout management in async database race condition tests.

* Refactor test utilities to use shared `EmployeeFixtureTrait` and `ItemFixtureTrait`.

* Track process exit codes explicitly in race condition tests for improved error detection and debugging.

* Improve error handling in `ConcurrentDbRaceTrait` by adding exceptions for `mysqli_poll` and `mysqli_reap_async_query`.

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>

---------

Signed-off-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
2026-08-20 02:24:23 +04:00
objecttothisandTravis Garrison 5c9b1b81e6 fix(xss): remove redundant escaping that double-encoded item attribute values (#4628)
* fix(xss): remove redundant escaping that double-encoded item attribute values

- Remove esc()/html_entity_decode() calls now that output is escaped
  at render time by the framework, preventing double-encoding of
  special characters in attribute names, units, and definition values
- Fix employee_name form_input value fields to stop pre-escaping
  before form_input applies its own escaping
- Reorder Items.php use statements and add missing BaseConnection import
- Change items/manage.php start_date from let to plain assignment for
  proper reassignment scope

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* test(sales): add regression tests for permission checks on sales endpoints

- Ensure role-based permissions correctly restrict access to sensitive actions like price edits, receipt/invoice views, and report generation.
- Add tests for both granted and restricted user scenarios to validate the behavior.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* fix(attributes): validate `attribute_value` before processing

- Add checks to ensure `attribute_value` is a non-empty string in `postSaveAttributeValue` and `postDeleteDropdownAttributeValue` methods.
- Return error response if validation fails to prevent invalid data handling.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* fix(attributes): improve error handling and optimize affected items processing

- Use `array_column` for extracting item IDs to streamline logic.
- Add JSON validation with `JSON_THROW_ON_ERROR` and return proper error response for invalid `definition_values`.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* test(sales): enable database refresh for consistent test state

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* test(sales): assert unauthorized message is displayed on restricted access

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* refactor(attributes): use camelCase for `attributeValue` in controller methods

- Standardize variable naming in `postSaveAttributeValue` and `postDeleteDropdownAttributeValue` methods by switching to camelCase.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

---------

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-09 11:37:38 +04:00
objecttothisandTravis Garrison f5ba1709eb fix(security): sanitize filenames and escape logo path in config (#4630)
* fix(security): sanitize filenames and escape logo path in config

- Sanitize uploaded filename in Config.php via preg_replace, strip
  chars outside [a-zA-Z0-9_-] before storing raw_name
- Escape $logo_src with esc(..., 'attr') in info_config.php view to
  prevent XSS via crafted logo path/filename

Prevents stored XSS and path traversal from unsanitized filenames
used in config uploads.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* fix(config): sanitize uploaded config filenames

Replace inline regex filename sanitization with sanitize_filename()
helper to prevent path traversal via crafted upload filenames.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

---------

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-07 20:30:02 +04:00
objecttothisandTravis Garrison 0808ffae0d fix(sales): escape quote number in email template to prevent XSS (#4625)
Wrap $quote_number output with esc() in quote_email.php. Raw
interpolation allowed injected HTML/JS via quote number field.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-07 02:21:19 +04:00
2c69dc0c34 fix(config): validate theme param to prevent XSS via invalid theme (#4620)
* fix(config): validate theme param to prevent XSS via invalid theme

Add validation rule for theme field before batch save, rejecting
requests with unrecognized theme values. Add test coverage for
theme validation in postSaveGeneral.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* Update app/Config/Validation/OSPOSRules.php

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

---------

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-08-07 02:18:44 +04:00
6e273a2fb1 refactor: Replace var with let/const in JavaScript files (#4503)
* refactor: Replace var with let/const in JavaScript files

- Replace var with let for variables that are reassigned
- Replace var with const for variables that are never reassigned
- Modernize manage_tables.js and nominatim.autocomplete.js
- Skip third-party libraries (imgpreview.full.jquery.js, clipboard.min.js)

Closes #4491

* refactor: Replace var with let/const in inline JavaScript

- Fixed CodeRabbit review: changed enable_actions and load_success
  from const to let in manage_tables.js (they are reassigned in init)
- Replaced all var declarations in inline JavaScript in Views with
  let (for reassigned) or const (for never reassigned)
- Modernized 48 additional files with inline JavaScript

* refactor: Replace var with let/const in remaining JS files

- Modernized gulpfile.js: 3 var declarations replaced
- Modernized app/Views/errors/html/debug.js: all var declarations replaced
- Used const for never-reassigned, let for reassigned variables

* fix: Replace remaining var declarations in Views

- Changed var  to const in sales/register.php
- Changed var  to const in configs/receipt_config.php

These were missed in the initial pass.

* fix: Replace remaining var declarations in gulpfile.js

- Converted 12 remaining var declarations to const
- All variables are function-scoped and never reassigned
- Complete coverage for this file now

* fix: Address CodeRabbit review comments

- items/manage.php: Remove duplicate let declaration for start_date
  (partial/daterangepicker already declares it)
- header_js.php: Escape CSRF hash in JavaScript context
- tax_jurisdictions.php: Fix mismatched selector (remove_tax_jurisdictions
  -> remove_tax_jurisdiction)

* style(views): Replace var with let/const and fix comment casing

- Convert var to let in items/manage.php for JS modernization
- Capitalize \"Submit\" in validation comments across tax view files

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

---------

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Ollama <ollama@steganos.dev>
Co-authored-by: objecttothis <17935339+objecttothis@users.noreply.github.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-06 12:15:45 +04:00
Travis Garrison 2a8e82a050 Merge remote-tracking branch 'OpensourcePOS/master' into plugin-system-fresh 2026-08-05 12:30:42 +04:00
objecttothisandTravis Garrison 734c7d291c chore(deps): add xlsx via SheetJS CDN and upgrade tableexport plugin (#4615)
- Add xlsx 0.20.3 from SheetJS CDN via package overrides
- Bump tableexport.jquery.plugin from ^1.30.0 to ^1.33.0
- Add xlsx bundle to gulp JS pipeline before tableexport

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-08-04 17:57:41 +04:00
Joshua FernandesandJoshua Fernandes 6bdeb4f3e1 Plugin system: sale document view hooks and a webhook CSRF exemption (#4605)
* feat(plugins): add sale document view hooks and a webhook CSRF exemption

Plugins can already inject buttons into the receipt via
view:sales_receipt_buttons, but the invoice, quote and work order views have
no hook point, so a plugin that delivers sale documents can only reach one of
the four. Add the matching hooks, keeping the same name/data shape:

  view:sales_invoice_buttons
  view:sales_quote_buttons
  view:sales_work_order_buttons

Each passes ['saleId' => $sale_id_num] and sits in the same position as the
existing receipt hook, so one plugin callback can serve all four and branch on
the document type.

Also allow a plugin to expose an inbound provider webhook. A server-to-server
delivery carries no CSRF token and no session, so the global csrf filter now
excludes the pattern plugins/*/webhook. Plugins are responsible for
authenticating such requests themselves (typically by verifying the provider's
signature header against a shared secret) — this is documented alongside the
change.

While editing that line, the except list becomes an array. CodeIgniter matches
every entry as \A<pattern>\z, so the previous 'login|migrate' string produced a
single pattern whose inner alternatives were unanchored: 'login/anything' was
CSRF-exempt. Listing the entries separately anchors each one, which closes that
and keeps the new plugin pattern tight — plugins/whatsapp/webhook is exempt
while plugins/whatsapp/send is not.

* refactor(plugins): drop explanatory comments from csrf filter exceptions

---------

Co-authored-by: Joshua Fernandes <“joshua.1234511@yahoo.in”>
2026-07-29 03:06:31 +04:00
Travis Garrison a6036cb082 feat(plugins): add registerModule helper and replace asset injection with explicit CSS links
- Add BasePlugin::registerModule() to register permission-system modules,
  auto-grant to admin (person_id=1), idempotent via INSERT IGNORE
- Replace inject:css/js placeholders in header.php with explicit versioned
  asset links for reliable loading outside build pipeline
- Update home.php module icons to use pluginContent() hook with SVG fallback,
  enabling plugins to override module icons

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-22 17:02:42 +04:00
Travis Garrison 1a03706c05 Merge remote-tracking branch 'OpensourcePOS/master' into plugin-system-fresh
Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

# Conflicts:
#	app/Controllers/Sales.php
#	app/Language/ar-EG/Config.php
#	app/Language/ar-EG/Sales.php
#	app/Language/ar-LB/Config.php
#	app/Language/ar-LB/Sales.php
#	app/Language/az/Config.php
#	app/Language/az/Sales.php
#	app/Language/bg/Config.php
#	app/Language/bg/Sales.php
#	app/Language/bs/Config.php
#	app/Language/bs/Sales.php
#	app/Language/ckb/Config.php
#	app/Language/ckb/Sales.php
#	app/Language/cs/Config.php
#	app/Language/cs/Sales.php
#	app/Language/da/Config.php
#	app/Language/da/Sales.php
#	app/Language/de-CH/Config.php
#	app/Language/de-CH/Sales.php
#	app/Language/de-DE/Config.php
#	app/Language/de-DE/Sales.php
#	app/Language/el/Config.php
#	app/Language/el/Sales.php
#	app/Language/en-GB/Config.php
#	app/Language/en-GB/Sales.php
#	app/Language/en/Config.php
#	app/Language/en/Sales.php
#	app/Language/es-ES/Config.php
#	app/Language/es-ES/Sales.php
#	app/Language/es-MX/Config.php
#	app/Language/es-MX/Sales.php
#	app/Language/fa/Config.php
#	app/Language/fa/Sales.php
#	app/Language/fr/Config.php
#	app/Language/fr/Sales.php
#	app/Language/he/Config.php
#	app/Language/he/Sales.php
#	app/Language/hr-HR/Config.php
#	app/Language/hr-HR/Sales.php
#	app/Language/hu/Config.php
#	app/Language/hu/Sales.php
#	app/Language/hy/Config.php
#	app/Language/hy/Sales.php
#	app/Language/id/Config.php
#	app/Language/id/Sales.php
#	app/Language/it/Config.php
#	app/Language/it/Sales.php
#	app/Language/km/Config.php
#	app/Language/km/Sales.php
#	app/Language/lo/Config.php
#	app/Language/lo/Sales.php
#	app/Language/ml/Config.php
#	app/Language/ml/Sales.php
#	app/Language/nb/Config.php
#	app/Language/nb/Sales.php
#	app/Language/nl-BE/Config.php
#	app/Language/nl-BE/Sales.php
#	app/Language/nl-NL/Config.php
#	app/Language/nl-NL/Sales.php
#	app/Language/pl/Config.php
#	app/Language/pl/Sales.php
#	app/Language/pt-BR/Config.php
#	app/Language/pt-BR/Sales.php
#	app/Language/ro/Config.php
#	app/Language/ro/Sales.php
#	app/Language/ru/Config.php
#	app/Language/ru/Sales.php
#	app/Language/sv/Config.php
#	app/Language/sv/Sales.php
#	app/Language/sw-KE/Config.php
#	app/Language/sw-KE/Sales.php
#	app/Language/sw-TZ/Config.php
#	app/Language/sw-TZ/Sales.php
#	app/Language/ta/Config.php
#	app/Language/ta/Sales.php
#	app/Language/th/Config.php
#	app/Language/th/Sales.php
#	app/Language/tl/Config.php
#	app/Language/tl/Sales.php
#	app/Language/tr/Config.php
#	app/Language/tr/Sales.php
#	app/Language/uk/Config.php
#	app/Language/uk/Sales.php
#	app/Language/ur/Config.php
#	app/Language/ur/Sales.php
#	app/Language/vi/Config.php
#	app/Language/vi/Sales.php
#	app/Language/zh-Hans/Config.php
#	app/Language/zh-Hans/Sales.php
#	app/Language/zh-Hant/Config.php
#	app/Language/zh-Hant/Sales.php
#	app/Libraries/Sale_lib.php
#	app/Models/Sale.php
2026-07-10 14:28:45 +04:00
objecttothisandTravis Garrison 9c542efaf6 Feature: Payment reference code (#4587)
* Add `reference_code` to sale payment queries and group by statements

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* Refactor `Sales` controller to improve payment handling readability and replace snake_case with camelCase variables

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* Add missing translations for `Sales` language file and include new keys like `must_enter_rrn` and `reference_code`

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* Refactor `Sales` payment handling to use camelCase and extend `addPayment` with `referenceCode` support

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* Refactor `Sales` models, controllers, and libraries to adopt camelCase naming conventions and improve readability

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* Add translations and updates for `must_enter_reference_code` and `reference_code` across language files and update `Sales` controller to replace `must_enter_rrn` with the new key

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* feat(sales): add reference code input and payment type helper

- Add `get_reference_code_payment_types()` to locale_helper as single
  source of truth for card-requiring payment types
- Add reference code row to register view, shown/hidden via JS based
  on selected payment type
- Fix payment type dropdown width to 100% for consistent layout
- Add min-width to payment buttons and right-padding to button group

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* feat(config): add payment reference code length configuration

- Add payment_reference_code_min and payment_reference_code_max fields
  to Config controller save logic
- Add translation keys for reference code length limits across all
  language files (min/max label + section header)
- Align array key formatting in Config controller for readability

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* style(lang): normalize string delimiters to single quotes across all language files

Convert double-quoted array keys and values to single quotes in all
app/Language/*/Config.php and app/Language/*/Sales.php variants.
No translation content changed — formatting only.

Also add Localization section to AGENTS.md documenting language file
conventions for new keys and fallback behavior.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* feat(lang): add payment reference code length translations

Add localized strings for payment_reference_code_length_limits,
payment_reference_code_length_max_label, and
payment_reference_code_length_min_label across all supported locales.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* test(config,sales): add payment reference code min/max validation tests

- Add baseLocalePayload() helper in ConfigTest for postSaveLocale tests
- Add testSaveLocale_AcceptsValidReferenceCodeMinMax and related boundary tests
- Add Sale_libPaymentTest for payment reference code validation in Sale_lib

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* fix(sales): add type-specific validation for amount_tendered

Gift card payments use amount_tendered as giftcard number (integer);
cash/other payments require decimal_locale format. Apply correct
validation rule per payment type instead of generic required.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* fix(lang): replace self-closing </br> with <br> in all locales

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* fix(sales): use configurable precision in discount comparison

Replace hardcoded precision 2 with totals_decimals() when comparing
discount against item total via bccomp/bcmul, so discount validation
respects the configured decimal precision setting.

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* fix(lang): correct Azerbaijani translations in Config.php

Replace placeholder/mismatched strings with accurate translations:
- email_mailpath, email_smtp_pass, invoice_email_message
- number_locale_invalid/required, receipt_template
- reward_configuration, right, tax_decimals, theme

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* feat(sales): add reference code support to payment edit flow

- Add reference_code field to new payment row in sale edit form
- Persist reference_code on insert in Sale model
- Validate reference_code_new in Sales controller using configurable min/max length rules

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* feat(lang): add Georgian (ka) language stubs for Config and Sales

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* Match the fallback maximum reference_code length to the maximum of the field in the db

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* Bug fixes

- Add validation of UI settings to prevent overridden values from being passed.
- Correct maximum value in JS for payment_reference_code maximum length to 40.
- Fix bug causing copy_entire_sale() to incorrectly copy the reference code and cash_adjustment

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

---------

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-10 13:49:05 +04:00
Travis Garrison 1159d7d572 feat(plugins): add $pluginData support for events and form submissions
- Add `$pluginData` parameter to `Events::trigger` calls for key events (e.g., `sale_completed`, `customer_saved`)
- Update core views to include `data-plugin-form` attribute for plugin-field serialization
- Bundle `plugin_data_helper.js` to handle form field extraction for plugins
- Extend README.md with comprehensive documentation on using `$pluginData`
- Refactor language files to support `install` translations and streamline UI labels
- Add new view hooks for sales receipt and register UI extension

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-09 15:32:27 +04:00
Travis Garrison 584d38426c feat(plugins): add uninstall confirmation modal and soft-delete uninstall
- Intercept uninstall action to show confirmation modal before AJAX call
- Change uninstall to soft-delete: set installed=0 instead of purging all config
- Add deleteAllNonControlForPlugin to preserve control rows on uninstall
- Add isPluginInstalled helper to PluginManager for installed state checks
- Fix isInstalled guard to treat installed=0 as not installed

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-07 17:54:18 +04:00
objecttothisandTravis Garrison b4b22863be Forgotten commit from login migration branch (#4592)
- suppress JSInitializingVariableWithUndefined inspection warning
- Add checks to not require username/password when isNewInstall is true

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-07 13:20:46 +04:00
Travis Garrison 2714ab2a84 chore(login): add JS comment and update asset references
Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-07 12:49:18 +04:00
Travis Garrison 00490d2ff2 Merge remote-tracking branch 'OpensourcePOS/master' into plugin-system-fresh 2026-07-07 12:00:43 +04:00
objecttothisandTravis Garrison dec736ad6c Bugfix: Fix problems with migration UI in login (#4589)
* refactor(login): rename methods and keys to camelCase, add initialization keys

- Rename snake_case methods to camelCase in MY_Migration and callers:
  is_latest() → isLatest(), migrate_to_ci4() → migrateToCI4(),
  get_latest_migration() → getLatestMigration(),
  get_current_version() → getCurrentVersion()
- Rename snake_case array keys to camelCase in Login controller:
  has_errors → hasErrors, is_new_install → isNewInstall,
  is_latest → isLatest, latest_version → latestVersion,
  gcaptcha_enabled → gcaptchaEnabled
- Add initialization_required, initialization_message, initialize keys
  to all language files to support new install flow messaging

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

* refactor(login): move auth validation before migration, reorder language keys alphabetically

- Validate credentials with login_check rule before attempting migration
- Return 401 with invalid credentials message on validation failure
- Alphabetically reorder and align language file keys across all locales
- Add new migration status keys: migrating_database, migration_complete,
  migration_complete_login, migration_complete_migrate
- Remove deprecated keys: migration_needed, migration_initializing,
  migration_running, migration_required

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>

---------

Signed-off-by: Travis Garrison <travis@chiraqbookstore.com>
Co-authored-by: Travis Garrison <travis@chiraqbookstore.com>
2026-07-07 10:35:25 +04:00
Travis Garrison 96e1f49ed1 Merge remote-tracking branch 'OpensourcePOS/master' into plugin-system-fresh 2026-06-29 12:05:37 +04:00
objec 11ece3f1a3 Add plugin hook to sales receipt buttons
Signed-off-by: objec <objecttothis@gmail.com>
2026-06-26 16:17:59 +04:00
jekkos 6342d4513a fix(security): Escape attribute value in register 2026-06-19 22:12:29 +02:00
objec 6dea8ed710 Merge remote-tracking branch 'OpensourcePOS/master' into plugin-system-fresh
# Conflicts:
#	app/Controllers/Customers.php
2026-06-10 14:44:11 +04:00
jekkosandOllama 4d6ebbafdd fix: tax rate inputs blank with comma-decimal locales (#4555)
* fix: tax rate inputs blank with comma-decimal locales

The to_tax_decimals() function returns locale-formatted values
(e.g. "18,00" for comma-decimal locales like fr_FR, de_DE).
Browsers reject comma-decimal values in <input type="number">
and render the field blank.

Use raw float value instead - PHP serializes floats with period
decimal regardless of locale. The parse_tax() on the save side
already handles locale-aware parsing, so round-tripping works
correctly.

Fixes #4553
Regression from commit 42ba39d29

* fix: tax rate input locale handling - save path

The display fix (using (float) instead of to_tax_decimals()) was
correct but incomplete. The save path in Config.php also needed
fixing because parse_tax() misinterprets dot-decimal values from
type="number" inputs when locale uses comma as decimal separator.

Root cause: Browsers submit type="number" inputs as dot-decimal
(e.g., "5.5") regardless of locale. With comma-decimal locales
like de_DE, parse_tax() treats the dot as thousands separator,
causing 5.5 to be saved as 5.

Fix: Replace parse_tax() with direct (float) cast for these
inputs since type="number" already guarantees dot-decimal format.

Includes tests for tax rate handling with various decimal values.

Fixes #4553

* revert: remove type=number from tax rate inputs

Resolution from PR #4555 review: Revert to text inputs for locale-specific
tax rate fields.

The type='number' attribute was added in commit 42ba39d29, but it caused
issues with locale-specific decimal separators. Browsers submit type='number'
inputs as dot-decimal regardless of locale, which breaks comma-decimal locales.

Solution: Revert to text inputs which use to_tax_decimals() for display
and parse_tax() for saving, correctly handling locale-specific formatting.

Changes:
- tax_config.php: Remove type='number', step, min, max attributes
- tax_config.php: Restore to_tax_decimals() for value display
- Config.php: Restore parse_tax() for tax rate parsing
- ConfigTest.php: Remove tests added for the type='number' approach

Fixes #4553

---------

Co-authored-by: Ollama <ollama@steganos.dev>
2026-06-06 22:50:51 +02:00
objecttothis df24ef5193 Merge branch 'master' into plugin-system-fresh 2026-05-18 16:25:10 +04:00
objec ad097adccd Refactor get_info to getInfo
Signed-off-by: objec <objecttothis@gmail.com>
2026-05-18 16:12:38 +04:00
objec 5d608ec873 Refactoring and bugfixes
- Pass an array to QueryBuilder->whereNotIn()
- Refactor function names for PSR compliance
- Add explanatory PHPdocs and corrections
- Correct bug with items_taxes model
- Refactor local variables for PSR compliance

Signed-off-by: objec <objecttothis@gmail.com>
2026-05-18 16:06:23 +04:00
jekkosandOllama 2f51c4ef52 fix(security): SQL injection and path traversal vulnerabilities (#4539)
Security fixes for two vulnerabilities:

1. SQL Injection in Summary Sales Taxes Report (GHSA-5j9m-2f98-cjqw)
   - Fixed unsanitized user input concatenation in getData() method
   - Applied proper escaping using $this->db->escape() for start_date/end_date
   - Consistent with existing _where() method implementation

2. Path Traversal in Receipt Template (GHSA-h6wm-fhw2-m3q3)
   - Added ALLOWED_RECEIPT_TEMPLATES whitelist constant
   - Added isValidReceiptTemplate() validation method
   - Validate receipt_template before saving in Config controller
   - Validate receipt_template before rendering in receipt view
   - Default to 'receipt_default' for invalid values
   - Consistent with invoice_type fix pattern (commit 31d25e06d)

Affected files:
- app/Models/Reports/Summary_sales_taxes.php
- app/Libraries/Sale_lib.php
- app/Controllers/Config.php
- app/Views/sales/receipt.php

Co-authored-by: Ollama <ollama@steganos.dev>
2026-05-15 23:10:04 +02:00
BudsieBuds ef91e6a9df chore: sync project files to match upstream templates (#4537)
- updated some files to match the official CodeIgniter 4 skeleton.
- rebuilt package.json from a clean init and modernized metadata and formatting
- rebuilt composer.json with modernized metadata and formatting
- replaced code of conduct text with markdown
- updated Dockerfile to replace deprecated instruction
2026-05-12 15:55:36 +02:00
BudsieBuds 42ba39d290 chore: miscellaneous updates and improvements (#4530)
- reinstated 'update-licenses' task in gulp (accidentally removed in 3e844f2f89)
- updated bootstrap, bootswatch, and various dev dependencies
- refinded text across UI
- applied consistency fixes
- added 'number' and 'tel' input types to relevant settings
- improved system info layout (still room for improvement, but better)
- updated and fixed changelog
2026-05-08 09:07:52 +02:00
WShellsandWShells 81213f0434 Assignable Keyboard Shortcuts Updates (#4532)
* Add configurable sales shortcuts

* Fix sales shortcut payment flow

* Resolve shortcut keys review comment

* Sanitize shortcut config notifications

* Clarify keyboard shortcut configuration labels

---------

Co-authored-by: WShells <26513147+WShells@users.noreply.github.com>
2026-05-07 22:53:25 +04:00
objec 478934321d Merge remote-tracking branch 'origin/master' into plugin-system-fresh
# Conflicts:
#	app/Language/th/Sales.php
2026-05-05 13:09:43 +04:00
objec 4246a915c4 - Correct README.md reference to views and information about renderView()
- Fix the output of pluginContent in the pluginHelper
- Register view injection events
- Correct the parameter type in getMailchimpViewData
- Correct the statusOptions creation business logic
- Removed unnecessary view injection point
- Corrected which variable was passed to the customer_saved event
- Assigned $customer_data['person_id'] on customer update
- Added renderView() function to BasePlugin.php

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-30 14:11:54 +04:00
objec fe331c34dd Mailchimp Bugfixes
- Update README.md to reflect information about routes
- Add registerAllNamespaces() function to correctly load plugin  namespaces
- center text in modal title
- Properly decrypt the api key
- Refactor getAllLists to getLists
- Naming simplification of strings when mailchimp_ is redundant or unnecessary
- Do not attempt to decrypt a plaintext api_key pasted into the form
- Register namespaces early on in system init

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-29 18:25:21 +04:00
objec cbabe1d56c Bugfix: Fix recursive view call
- Fix bug causing all plugin views to be rendered on every page.
- Simplify code
- Refactor manage.php view to use bootstrap tables

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-29 15:02:48 +04:00
objec 97adee0c28 Language changes
- Refactor Plugins.php language keys
- Correct spacing between key and `=>`
- Replaced `"` with `'` to avoid calling the PHP string parser
- Propagated Plugins.php language string file to other languages
- removed redundant `plugin_` from key names

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-29 11:28:26 +04:00
objec 32997d48c0 Fix persistence problem with plugin registration.
- Move the PluginManager creation to a service.
- Move plugin discovery to creation.
- Create static discovery and namespaces variables in the PluginManager.php library
- Refactor persistent namespace declarations
- Refactor redundant code to private function.
- Remove whitespace
- Remove enable setting from MailchimpPlugin. That is handled by the PluginManager.php
- Update Events.php to call the pluginManager service
- Correct typo in enabled setting for BasePlugin to accurately reflect the database naming.

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-29 10:31:04 +04:00
objec c796b52c22 Correct mistakes in plugin code related to loading.
- Add plugin module to list of required admin modules.
- Don't trigger autoloader in plugin discovery.
- Delete plugins_config.php which is no longer needed for managing plugins.
- Remove references to plugins_configuration in config views.
- Correct the form submission URL path.

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-23 12:42:34 +04:00
objec bae361c637 Langauge file changes
- Added phrase to MailchimpPlugin.php language files
- updated calls to lang to call the correct phrases

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-22 15:32:05 +04:00
objec db180d134e Views
- Added injection point into Customers Controller.
- Registered event listeners for the view hook.
- created initial customer tab view.
- Removed unnecessary comments

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-18 00:13:55 +04:00
jekkosandOllama 97ca738b2d fix: Escape dynamic output and fix CSS property in barcode_sheet.php (#4501)
- Add esc() for dynamic output in HTML attributes and URLs
- Cast numeric values to int for CSS properties
- Fix invalid 'borderspacing' CSS property to 'border-spacing'
- Add quotes around class attribute

Closes #4487

Co-authored-by: Ollama <ollama@steganos.dev>
2026-04-16 19:37:06 +00:00
objec 9fc918b53d Refactor integrations to plugins
Signed-off-by: objec <objecttothis@gmail.com>
2026-04-14 18:05:57 +04:00
objec 65fb6339d7 Translations
- Deleted Mailchimp string from de-DE Sales langugage file.
- Finished translating missing phrases

Signed-off-by: objec <objecttothis@gmail.com>
2026-04-14 17:57:23 +04:00