Recent Activities
This page shows what are we working on.
-
head
-
Add AJAX controller for fetching product labels and update label handling logic 33072b
-
-
1.0.10
-
Version 1.0.10 b8b88d
-
Fix child labels ignoring schedule, store and product status
- Skip expired labels and pass active period to frontend
- Filter index by store view, skip disabled and out-of-website children
- Validate $mode before using it in SQL column names
- Require swissup/module-pro-labels ^1.10.0 (active period columns) 3074b5
-
-
head
-
1.0.0
-
Use category path in breadcrumbs #50 317f00
-
-
head
-
Subscription archive: link Reorder to order page instead of sales/order/reorder #53 c42992
-
Stores using: add srcset with PageSpeed 0.5x/0.75x variants and sizes for store images #49 d8a112
-
Product Page: Add section Stores using ceed62
-
Fix Red Hat Display font preload 70dfce
-
Product page: keep product name from jumping when ProLabels label is inserted ed8eef
-
Fix listing grid columns for 1column layout: use current Breeze variable names #52 4c81d9
-
Blog: replace FontAwesome list icon with SVG, style wp-block-code like Prism 7febcd
-
Use category path in breadcrumbs #50 4b10c4
-
-
1.3.3
-
Version 1.3.3 0f8d9f
-
Security and robustness fixes (#9)
- Restrict update-config to developer mode and validate values
- Censor sensitive request data in Flare reports
- Open the error modal only for Ignition error responses
- Keep the store's error reporting level
- Fix Magento coding standard errors in copy-buttons.js
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> d86e96 -
Security and robustness fixes
- Restrict update-config to developer mode and validate values
- Censor sensitive request data in Flare reports
- Open the error modal only for Ignition error responses
- Keep the store's error reporting level
- Fix Magento coding standard errors in copy-buttons.js
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> e15a70 -
Strip query from Referer header in Flare reports
The Referer header could contain tokens, e.g. a password reset link.
Also use explode() instead of strtok(), which skips a leading "?".
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> 09d9c8 -
Fix Magento coding standard errors in copy-buttons.js
Avoid self-closing tags with non-void elements in the SVG icons.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> 20f4b7 -
Keep the store's error reporting level
Ignition::register() without arguments forces error_reporting(-1), which
overrode the level set in app/bootstrap.php or by the store. Stores that
exclude deprecations (E_ALL & ~E_DEPRECATED) got 500 errors on every
deprecation once the module was installed.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> d98949 -
Open error modal only for responses marked by Plugin\App
The modal opened for any failed ajax response containing the
"window.ignite(window.data)" marker, including cross-origin responses
and error responses that reflect user input, which allowed XSS.
Plugin\App now sends an X-Ignition-Error-Page header with the error page
and the modal requires it. Also fixes a JS error on Breeze network errors,
where the fail callback receives no xhr.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> d733c5 -
Censor cookies in Flare JS error reports
The Flare JS client sent all cookies readable by JS (form_key and others)
with every error report. Replace their values before submitting.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> 22f466 -
Censor sensitive data in Flare reports
Production reports sent to Flare included the full request: cookies,
Authorization header, passwords and card data from the POST body, tokens
in the URL, and stack frame arguments.
- Add CensorSensitiveData middleware: censors cookies, sensitive headers,
and sensitive keys in body and query string (nested keys included),
and strips the query from the request URL.
- Disable stack frame arguments in production.
- Keep user provided context when copying the report, otherwise
middleware changes were lost.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> c5a9d0 -
Fix stored XSS via unauthenticated update-config endpoint
The endpoint was available in all modes without authentication and saved
arbitrary values, which the error page renders unescaped (theme). Now it
works in developer mode only and accepts known values only.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> abcc71
-
-
0.1.2
-
0.1.1
-
1.21.0
-
Version 1.21.0 28f0bf
-
fix(installer): do not enable Advanced JS Bundling by default 19fc09
-
Merge pull request #134 from swissup/feat/extract-advanced-js-bundling
refactor: move Advanced JS Bundling to swissup/module-advanced-js-bundling 343655 -
fix: keep deprecated config path constants, skip the order test without the new module
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 9d53ff -
Merge master into feat/extract-advanced-js-bundling
# Conflicts:
# composer.json 1714b2
-
-
1.20.1
-
Version 1.20.1 de757e
-
Merge pull request #136 from swissup/fix/security-audit-135
fix(security): audit findings (#135) 8aa502 -
fix(critical-css): reject any markup in critical CSS and share the POST script (#135)
- assertSafeCss rejects every markup start (<link>, <svg>, <img>, ...), not only
style/script/comment; saveConfig() runs the same check
- move the duplicated getPostScript() into PostScriptTrait
- DebugModeDefaultTest asserts config.xml loaded
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 406f33 -
fix(csp): whitelist www.googleapis.com for the admin area only (#135)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> bab7ee -
fix(critical-css): generate actions accept POST with form key only (#135)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 46e02b -
fix(critical-css): use https and reject markup in the API response (#135)
The response is printed unescaped into a <style> tag, so a response that
closes the tag or opens a script is refused.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> aecc4f -
fix(debug): disable debug mode by default (#135)
The ?pagespeed= switch and the debug console output were open to every
visitor on a fresh install. They stay available once debug mode is
enabled on purpose.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 933453 -
test: run ProductionHeadOrderTest against the Bundles block of the new module
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> cb52e3 -
refactor: move Advanced JS Bundling to swissup/module-advanced-js-bundling
Config keys and the bundle path are unchanged; the new package is required.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> b964d6
-
-
1.8.22
-
Version 1.8.22 9893b7
-
fix(providers): StructuredResponseException cause type breaks di:compile on 2.4.7 (#197) (#198)
* fix(providers): StructuredResponseException cause type breaks di:compile on 2.4.7 (#197)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
* style(providers): wrap the cause-type comment (#197)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> 1d4842 -
style(providers): wrap the cause-type comment (#197)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 602747 -
fix(providers): StructuredResponseException cause type breaks di:compile on 2.4.7 (#197)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> a961ae
-
-
1.8.21
-
Version 1.8.21 dbe743
-
Merge pull request #196 from breezefront/fix/security-audit-195
fix(security): audit findings (#195) a2f5c5 -
fix(content-builder): drop generated links with a script-capable scheme (#195)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 1bf8da -
fix(mcp): accept only http(s) for the GraphQL tool endpoint (#195)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 8c6483 -
fix(models): require the API key again when a model's Base URL host changes (#195)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 5d92ac -
fix(bulk): limit AI runs to offered fields and require content ACL (#195)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> ba0cda -
fix(mcp): accept only http(s) for the GraphQL tool endpoint (#195)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> e9ba06 -
fix(models): require the API key again when a model's Base URL host changes (#195)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 341743 -
fix(bulk): limit AI runs to offered fields and require content ACL (#195)
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 93da35 -
feat(search): a curated attribute and category vocabulary (#191) (#194)
* feat(search): a curated attribute and category vocabulary (#191)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(search): drop unreachable categories, widen invalidation (#191)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(search): reserve the category key, one blank rule (#191)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* feat(search): name the category key in the prompt, tag entries per store (#191)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* test(search): pin that a scoped flush evicts only its own store (#191)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(search): unique category paths, no cache for a short document (#191)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com> cf4f89 -
fix(search): unique category paths, no cache for a short document (#191)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> 0535ce -
test(search): pin that a scoped flush evicts only its own store (#191)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> e46386 -
feat(search): name the category key in the prompt, tag entries per store (#191)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> 088d93 -
fix(search): reserve the category key, one blank rule (#191)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> 0ec722 -
fix(search): drop unreachable categories, widen invalidation (#191)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> bc6ac2 -
feat(search): a curated attribute and category vocabulary (#191)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> 5807f1 -
feat(providers): structured output on ProviderInterface (#187) (#193)
* feat(providers): structured output on ProviderInterface (#187)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(providers): address review on the structured-output gate (#187)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* feat(providers): check the structured answer against its schema on every row (#187)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com> 962047 -
feat(providers): check the structured answer against its schema on every row (#187)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> 332f47 -
fix(providers): address review on the structured-output gate (#187)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> d1f17b -
feat(providers): structured output on ProviderInterface (#187)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> 538cae
-
-
1.4.3
-
1.4.2
-
head
-
Login customer form styles update. cbc7e9
-
Add layout styles for layered navigation and blocks; update variables 8b00ba
-
Improved out-of-stock and bundle products styles 56e102
-
Added Sold Together styles 4ad53f
-
Sticky media and info blocks on product page on desktop e6754a
-
Improved filter dropdown styles 61da32
-
Move ECI after description 4bf01c
-
Few minor changes to shop by dropdown 22fc09
-
Enhance header slideout menu. Adjust top offset. 75cdb2
-
Related product block. Fix issue incorrectly placed button when critical CSS enabled. 63d63b
-
Added testimonials and FAQ blocks to the product page e95221
-
Remove listing banners except for the first one 0b5f7c
-
Added ECI config, layout, and styles 9823dd
-
Updated styles and scripts to work with Qty Switcher module 59ad66
-
Minicart. Update slideout positioning and add scroll tracking for dropdown dialogs 96fbb9
-
Update header panel styles for pagebuilder slider. 4967ce
-
Refactor header panel: remove EasySlide integration, add header panel info block, and update styles for header panel slider 662724
-
Remove EasySlide configuration and related HTML content ea5c76
-
Add noEscape directive to continue shopping button URL ac4b9c
-
Update listing gap variable to use defined spacing 41f0ca
-
Add CSS class to main title in checkout cart layout dc41f6
-
Shopping cart page is done. c1d6d0
-
Shopping cart page in progress 8ca297
-
Shopping cart page 9fa558
-
Enhance quantity input styling and functionality. Apply border-radius to buttons and ensure step attribute is valid. 1bcebb
-
Add padding variable for navigation link caret. aa8d04
-
Quantity wrapper component. f57c8d
-
Product page. Adjustments for related products layout. aa27ee
-
Product page. Add new layout container. Place BCB marquee content there. a2fe52
-
Product page. Enhance gallery configuration and update layout variables for improved styling and responsiveness. b89117
-
Product page. Add grid area for price information and implement gallery layout for improved product display. 76b0b3
-
Product page. Add focus ring styling for checkboxes in related products block to enhance accessibility. ab2227
-
Product page. Refactor related products layout for improved responsiveness and styling consistency. 5aa789
-
Product page. Update quantity button icons to use mask images for better scalability and styling. 9576ee
-
Product page. Related products block. 7ed6de
-
Product page. Implement review popup for full review text display and enhance accessibility. d38885
-
Product page. Add toggle for "Write Your Own Review" form and adjust styles for review list 9973d8
-
Product page. Revies list is done. Revie form next. 5bf007
-
Theme Editor: added Listing, Animations, and Advanced sections a4451d
-
Theme Editor: added Colors section 390891
-
Product page. Reviews in progress... e13b99
-
Theme Editor: added Layout, Typography, Overlay Header, Border Radius, Color and Font Palettes ff5e62
-
Productpage. Review in progress... 7059e9
-
Productpage. Review in progress. 669824
-
BCB featured product component. 0651cf
-
Add styles for featured product details, SKU, and price row in BCB d65f2d
-
BCB accordion styles at product info main. 1a262b
-
Installer. Add accordion for products. 466a5b
-
Add padding to swatch options in product add form for improved layout f10f77
-
Product main info ... in progress bf5c3f
-
Enhance product quantity input with increment/decrement buttons and update styles for better usability 72192e
-
Update product page medium image dimensions to 590x590 012c72
-
Fix minicart styles: set empty counter opacity to 0 79fcd1
-
Increased h2 bottom margin dff6ea
-
Product page action buttons. d008f0
-
Updated footer content links and section titles for improved clarity and user experience 241039
-
BCB homepage: fixed wrong image name b1a4f4
-
Rating stars styles in product listing f17a0f
-
BCB homepage: updated full width banner and sections spacings 2076c7
-
Fixed sort order of product details inside grid listing 9ad360
-
BCB homepage: updated Videos and full width banner sections 072733
-
Product page title font-size. d0987c
-
Footer. Minor fix for ring reval animation. Restore missing divider in footer. (#3) 54cdc4
-
Footer ring reveal animation added (#3) 4a8be8
-
BCB homepage: added animated badges to top banners grid 197e37
-
BCB homepage: added rotation animation for Full Width Banner 1420f9
-
BCB homepage: top banner updated a53bd5
-
Update favicon color 5ea666
-
Update favicon 18d8dc
-
Slightly update footer background. 5fcbfc
-
Footer content update. Add contact block (#3) dea42e
-
Fixed missing minicart overlay on first open (#2) 54feaa
-
BCB homepage: updated Browse categories block dbfa89
-
Breadcrumbs 196469
-
Done with search (#2) d8e0f3
-
Enhance minisearch functionality with slideout behavior and styling adjustments without Ajaxsearch (#2) 8c4a9d
-
Minisearch styles when ajaxsearch disabled... in progress (#2) 259fac
-
Remove unused styles from viewcart action and update empty subtitle styles in minicart (#2) dba7a5
-
Minicart complete (#2) 56efd2
-
Search on desktop (#2) 9c587e
-
BCB homepage: added videos section 7ee864
-
Minicart inprogress (only buttons to adjust)... (#2) c1be91
-
Minicart update in progress.... c3d18b
-
Minicart update in progress... (#2) 55e7b9
-
INstaller. Create dummy CMS block header_panel_info to allow user add custom content (#2) f70d58
-
Adjust minicart counter (#2) 03e843
-
BCB homepage: Added brand logos section b905f1
-
BCB homepage: Added testimonials section 2ab2cf
-
Update newsletter styles: adjust input border and add consent positioning (#2) 02d37d
-
Header. Update search behaviou and look of the result dropown. 993432
-
BCB homepage: Added FAQ a0bfde
-
Add focused search styles. d80f88
-
BCB homepage: added new sections 875068
-
BCB homepage: added ECI and full-width banner d40cfa
-
Top navigation added. 8fa9a3
-
Remove color from menu links dec081
-
Clone currency and store switchers in header slideout menu for improved functionality de36e3
-
Enhance header and newsletter styles for improved layout and responsiveness in header slideout menu. b63dd0
-
Installer. Update header slideout menu styles. 825795
-
Update footer top content HTML to enhance newsletter section styling.
Don't set font familiy for header in Page Builder ba0b81 -
BCB homepage WIP b228af
-
Basic navpro slideout styles 75ac0e
-
Refactor header slideout menu and newsletter styles for improved layout and consistency 3b42ff
-
-
3.3.4
-
Version 3.3.4 289565
-
Fixed cart qty input style 5a9fba
-
Fixed wrong color id in theme editor settings 402ff7
-
Added width 100% for the contact form 4a1acf
-
Replaced PB footer top content with BCB version f1006d
-
Removed unused overlay header config bf9be6
-
Added Overlay Header settings to Theme Editor c859d3
-
Fixed layout shift when js is placed between price and swatches 7c4cc4
-
Move price styles to enterprise-blank 54a350
-
-
3.3.3