Conversation
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The store checkout is the WooCommerce checkout block, and nothing on it asked for the policy consent.
inc/checkout.phphooked intowoocommerce_get_terms_and_conditions_checkbox_textandwoocommerce_after_checkout_validation, which only the classic shortcode checkout runs: the checkout block places the order through the Store API, which calls neither. The terms block on the checkout page has no checkbox, and its text ("By proceeding with your purchase you agree to our Terms and Conditions and Privacy Policy") had no links, since the store has no terms page and the WordPress privacy page is unpublished.Changes
libresign/policy-consent, of type checkbox in the order section: "I agree to the terms and privacy policy before placing the order." WooCommerce validates required additional fields on the server, in the Store API, and saves the value on the order, so the consent is recorded like the workspace terms consent.data-textattribute; the theme sets it to "Read the terms and privacy policy.", linking tohttps://libresign.coop/privacy-policy, the same page as the footer and the workspace form.?wc-ajax=checkout, which runsWC_Checkout::process_checkout()and does not validate the block fields. No page of the store prints its nonce, but the Stripe express checkout (Apple Pay, Google Pay) does when it is enabled, and places its orders through that path. The theme keeps refusing an order there withoutterms, as it did before. Only the classic terms checkbox text filter is removed, since there is no classic checkout form to show it.Verification
On the local SaaS stack, with a plan in the cart:
false, or withadditional_fieldsempty is refused (rest_missing_callback_param/rest_invalid_param). With the consent, the request passes validation and reaches the payment step.composer cipasses.