Skip to content

Releases: patrickkivits/bunq-for-woocommerce

v1.6.4

Choose a tag to compare

@patrickkivits patrickkivits released this 18 Sep 19:57
99de77e

Do not warn about the other mode's client on the first settings save (#64)

  • Saving the gateway settings on a fresh install raised "Undefined array key "test_oauth_client_id"" (in test mode: "oauth_client_id"), and kept doing so on every save until the other mode had been saved once. The save handler read the other mode's OAuth client fields, which are not part of the form, straight from the settings array
  • A missing client id or secret now counts as "not set", which is what the reset of that mode's API key and context intended. No other change in behaviour

Also in this release: the plugin now has automated tests (#63). A unit suite runs without WordPress on PHP 7.3 through 8.5, and an integration suite runs the plugin inside a real WordPress and WooCommerce through the WordPress test suite on PHP 7.4 through 8.5. Both run on every push. The files the tests add are kept out of this zip through the new .gitattributes, which is now the one place listing what the release leaves out.

v1.6.3

Choose a tag to compare

@patrickkivits patrickkivits released this 18 Sep 18:41
1b9dcfb

Create refunds as bunq draft payments approved in the app (#62)

  • Refunding an order failed with bunq error 400 "Not enough permissions to create payment". The plugin authenticates with an OAuth access token, and bunq only lets OAuth-connected apps move money between the user's own accounts or create draft payments; a direct payment to the customer's IBAN is never permitted
  • Refund via bunq now creates a draft payment back to the customer's IBAN. It appears as a pending payment in the bunq app, and approving it there sends the money
  • The order note and log line say the refund is waiting for approval and carry the draft payment id (translated into Dutch, French and German)
  • Note that WooCommerce records the refund as soon as the draft is created, so an unapproved draft leaves the order marked as refunded while the customer has received nothing. The readme explains this

Refunds have been verified against a live bunq account. Verified on the WordPress compatibility matrix (WP 6.2/WC 8.1.0/PHP 7.4 through WP latest/WC latest/PHP 8.4) and on PHP 7.3 through 8.5.

v1.5.10

Choose a tag to compare

@patrickkivits patrickkivits released this 18 Sep 17:22
34965eb

Fix webhook order lookup, amount check and callback registration (#58)

  • The payment callback looked up the order with the bunq request id passed as meta_compare, so it always loaded the newest order that had any request id. When more than one order was pending, the older one could never complete. It now queries by meta_value and requires exactly one match
  • The paid amount was compared with the order total as strings; it is now compared as a decimal, so the number of decimals configured in the shop no longer matters
  • The callback URL was not registered at bunq when REMOTE_ADDR was loopback, which is the case behind reverse proxies, Docker and tunnels. The decision is now based on the callback URL's host
  • Registering the callback replaced all URL notification filters on the bunq account; existing filters are now read and posted together with ours
  • At checkout, an API context that can no longer be loaded is recreated from the saved API key before failing, and the customer sees a generic notice instead of the raw SDK error (#35)
  • The requirements check deactivated the wrong file, so an incompatible environment never actually deactivated the plugin
  • Incoming callbacks are validated and every ignored, rejected or completed notification is written to WooCommerce > Status > Logs (source bunq)

Verified on the WordPress compatibility matrix (WP 6.2/WC 8.1.0/PHP 7.4 through WP latest/WC latest/PHP 8.4) and on PHP 7.3 through 8.5.

v1.5.9

Choose a tag to compare

@patrickkivits patrickkivits released this 18 Sep 15:13
1daf9de

Always define the gateway settings fields outside admin (#53)

  • WC_Bunq_Gateway::init_form_fields() wrapped the entire form field definition in is_admin(), so on the checkout frontend and under WP-CLI $this->form_fields stayed empty and WC_Settings_API::get_option() could not fall back to a field's default for settings that were never saved
  • The field definitions are now always set; only the bank account lookup (bunq_get_bank_accounts() and its transient) stays gated on is_admin(), and outside admin the bank account select gets an empty options array
  • Restore the two form field checks in the WooCommerce compatibility smoke test that #52 had to drop

Verified on the WordPress compatibility matrix (WP 6.2/WC 8.1.0/PHP 7.4 through WP latest/WC latest/PHP 8.4) and on PHP 7.3 through 8.5.

v1.5.8

Choose a tag to compare

@patrickkivits patrickkivits released this 18 Sep 14:53
6c515f0

Declare PHP 7.3–8.5 support and restore the PHP 7.3 floor (#51)

  • Add the Requires PHP: 7.3 plugin header and raise the runtime requirements check from 7.0.13 to 7.3.0 to match composer.json
  • Pin the Composer platform to PHP 7.3.0; this downgrades only symfony/deprecation-contracts 3.7.1 => 2.5.4, whose 3.x branch used the PHP 8-only mixed type and made the plugin fail to parse on PHP 7.x
  • Guard two array reads that raised "Undefined array key" warnings on PHP 8 (missing payment method POST field, REMOTE_ADDR under CLI)
  • Add a GitHub Actions workflow that lints every PHP file and loads the vendored dependencies on PHP 7.3 through 8.5
  • Document the supported PHP range (7.3 up to and including 8.5) in the readme

The plugin and its dependencies (Guzzle 7.15.5, league/oauth2-client 2.9.1) run on PHP 8.5. The bunq SDK 1.28.0 still uses implicitly nullable parameters, which PHP 8.4+ reports as deprecation notices; these are not errors and WordPress hides them unless WP_DEBUG is on.

v1.5.7

Choose a tag to compare

@patrickkivits patrickkivits released this 18 Sep 14:20

Update Guzzle and OAuth client to fix all 13 open Dependabot alerts (1 high, 12 moderate)

  • guzzlehttp/guzzle 7.9.3 => 7.15.5
  • guzzlehttp/psr7 2.7.1 => 2.13.1
  • guzzlehttp/promises 2.2.0 => 2.5.3
  • league/oauth2-client 2.8.1 => 2.9.1 (adds declared PHP 8.5 support)
  • symfony/deprecation-contracts 3.6.0 => 3.7.1, adds symfony/polyfill-php80

Verified against the bunq sandbox and production API on PHP 8.5.

v1.5.6

Choose a tag to compare

@patrickkivits patrickkivits released this 18 Sep 14:15

Surface bunq errors during OAuth setup instead of swallowing them (#50, #1)

  • Show the bunq error as a notice on the plugin settings page after the OAuth redirect
  • Log details to WooCommerce > Status > Logs (source bunq)
  • Catch PHP errors as well as exceptions during API context creation
  • Verify the OAuth state via a transient (PHP sessions are never started by WordPress)
  • Build the redirect URI with remove_query_arg instead of a fixed substr
  • Mask the client secret in token request errors
  • Only handle the OAuth callback on the plugin settings page
  • Fix load_api_context reading a non-existent test_mode setting
  • Add uninstall.php to clear settings when the plugin is deleted
  • Add a troubleshooting section to the readme

v1.5.5

v1.5.5 Pre-release
Pre-release

Choose a tag to compare

@patrickkivits patrickkivits released this 03 Jun 18:11

Declare property payment_methods

v1.5.4

v1.5.4 Pre-release
Pre-release

Choose a tag to compare

@patrickkivits patrickkivits released this 03 May 02:16

Allow selection of payment methods to be enabled when using direct gateway

v1.5.2

v1.5.2 Pre-release
Pre-release

Choose a tag to compare

@patrickkivits patrickkivits released this 03 May 00:12

Add support for direct gateway (Allow your customers to directly select a payment method from the checkout page)