Improvements and security updates to be used in production.
Added
Launch Checklist with a progress badge in the admin nav to guide first-time setup
Added
Pay What You Want & Tipping product mode (schema v58)
Fixed
Fixed a Stripe Payment Intent bug where the order wasn’t being passed through
Fixed
Fixed Stripe Connect popup looping on the Payments tab
Updated
Replaced the hardcoded REST API key with capability-only authentication
Updated
Restricted REST CORS to same-origin
Updated
Scoped public cart and order endpoints to the named ID (prevents enumeration)
Updated
Locked down generic Data API permission callbacks
Updated
/shipping/buy endpoint now requires capability
Updated
SVG uploads now sanitized via enshrined/svg-sanitize before being saved
Removed production console logs from the storefront JS bundle & Tested with WordPress 7.0.
Feel free to text me or message me on discord
(480) 573-7714
[email protected]
Discord