Skip to content

Releases: TonyMerlin/M2-ProductFinder

Version 2.1.4

Choose a tag to compare

@TonyMerlin TonyMerlin released this 07 Aug 11:51
5ba9e67

v2.1.4

Security

Fix: Resolved GitHub CodeQL js/xss-through-dom warning within the frontend Product Finder.

Fix: Added strict validation for attribute set profile image URLs before assigning them to frontend <img> elements.

Fix: Restricted profile images to same-origin HTTP(S) URLs within /media/merlin_productfinder/, preventing untrusted URLs from being rendered.

Changed

Change: Refactored frontend image rendering to validate image URLs before assigning the src property.

Fix: Invalid image URLs are now safely ignored, preventing unsafe DOM injection while preserving existing functionality.

Fix: Replaced malformed em-dash characters in progressive AJAX status messages with Unicode escape sequences to prevent character encoding issues.

Version 2.1.3

Choose a tag to compare

@TonyMerlin TonyMerlin released this 07 Aug 11:35
33d67e8

Version 2.1.3

Security

  • Resolved CodeQL warning js/xss-through-dom affecting profile image previews within the admin Profile Builder (view/adminhtml/web/js/profiles.js).
  • Added strict validation for profile image URLs before assigning them to the preview <img> element.
  • Profile image previews now only accept same-origin HTTP(S) URLs within /media/merlin_productfinder/.
  • Applied the same validation to both existing profile images and newly uploaded images before rendering them in the admin UI.

Changed

  • Switched profile image preview updates from jQuery .attr('src', ...) to .prop('src', ...) after URL validation.
  • Improved upload error handling to provide clearer feedback when invalid image URLs are returned.
  • Internal JavaScript hardening only.
  • No functional or configuration changes for administrators.

Version 2.1.2

Security

  • Resolved CodeQL warning js/incomplete-sanitization within the admin Profile Builder (view/adminhtml/web/js/profiles.js).
  • Removed dynamic CSS selector generation for attribute set lookups.
  • Attribute set names are now resolved using direct DOM value comparison instead of escaped selector strings, eliminating the need for manual sanitisation and improving code robustness.

Changed

  • Internal JavaScript refactoring only.
  • No changes to functionality, configuration, or the administrator user experience.

Version 2.1.1

Choose a tag to compare

@TonyMerlin TonyMerlin released this 24 Nov 16:41
d8a7b4c

Fix: Fix form issue since adding configurable products.

Version 2.1.0

Choose a tag to compare

@TonyMerlin TonyMerlin released this 24 Nov 16:39
adcdeae

#v2.1.0

Add: Add configurable product support

Fix: Fix type error in results constructor

Version 2.0.6

Choose a tag to compare

@TonyMerlin TonyMerlin released this 24 Nov 10:22
2fb152c

Fix on/off switch to actually turn off the frontend form.

Version 2.0.5

Choose a tag to compare

@TonyMerlin TonyMerlin released this 21 Nov 15:58
beec0e1

Fix: Fix widget.xml and clean-up

Version 2.0.4

Choose a tag to compare

@TonyMerlin TonyMerlin released this 21 Nov 10:49
d56dc79

Fix: Element 'show_in_wysiwyg': This element is not expected.

Version 2.0.2

Choose a tag to compare

@TonyMerlin TonyMerlin released this 19 Nov 13:53
9dedd27

#v2.0.2

Fix: Currency symbol clean-up, encoding mismatch and a broken literal in JavaScript.

Add: Support multi select attributes

Add: default html values for pre and post form content

Version 2.0.1

Choose a tag to compare

@TonyMerlin TonyMerlin released this 19 Nov 10:24
4310836

Fix attribute set image upload

Version 2.0.0

Choose a tag to compare

@TonyMerlin TonyMerlin released this 18 Nov 15:24
60668f7

New: Refactor the admin attribute set wizard with a drag and drop interface for building out the product finder quickly.

Fix: Clean-up the frontend UX and results page

Fix: Clean-up the configuration page removing all legacy options.