Skip to content

v1.2.2

Latest

Choose a tag to compare

@dbltoe dbltoe released this 27 Aug 22:36

A hardening and correctness release. Recommended for everyone, though nothing here is urgent the way v1.2.1's fixes were.

Security

  • Customer names in the admin's own confirmation messages are now escaped where they're shown. The names this plugin writes were already stripped of < and > on the way in, so this was never a problem for them. But the Resend the Welcome E-Mail message doesn't only show those — its drop-down lists every customer still awaiting activation, including ones who registered through the storefront on an approval-required store, or whose details were edited elsewhere in the admin. This plugin can't vouch for names it didn't write, so it no longer tries to: they're escaped at the point of display, which is correct whatever their origin.

    Reaching this needed an unusual combination — an approval-required store, a customer created outside this plugin with markup in their name, and an admin using Resend on that customer — so it is hardening rather than an open door.

Corrections

  • The sign-up sheets were documented as something you had to supply. readme.html said "you supply them yourself" and pdf/README.txt said "Add exactly these two files here before deploying", but both PDFs have shipped with the plugin since v1.0.0. Anyone following those instructions would have gone looking for files already sitting in their download. Both now say the sheets ship and work on install, and explain how to replace either with your own.

  • E-Mail, the way Zen Cart spells it. The Welcome E-Mail Header Image heading and its E-Mail Header to Import: field said "Email" where core writes "E-Mail" (core's own ENTRY_EMAIL_ADDRESS is "E-Mail Address:"). Both now match, along with everything quoting them. The readme and CSV guide also mis-quoted core's Minimum Values->E-Mail Address setting.

  • "recognised" → "recognized" in the bad-CSV-header message, matching the American spelling used everywhere else.

  • pluginId is declared as an integer rather than a quoted string, matching how Zen Cart's own bundled plugins declare theirs. Nothing behaved differently either way; the value (2445) is unchanged.

No database schema changes from v1.2.1.

See readme.html for full installation instructions and the complete version history.