Recent Activities

This page shows what are we working on.

breezefront / theme-frontend-breeze-enterprise-eir

31 minutes ago success
  • head
    • Add layout styles for layered navigation and blocks; update variables 8b00ba

    • Improved out-of-stock and bundle products styles 56e102

    • Added Sold Together styles 4ad53f

    • Sticky media and info blocks on product page on desktop e6754a

    • Improved filter dropdown styles 61da32

    • Move ECI after description 4bf01c

    • Few minor changes to shop by dropdown 22fc09

    • Enhance header slideout menu. Adjust top offset. 75cdb2

    • Related product block. Fix issue incorrectly placed button when critical CSS enabled. 63d63b

    • Added testimonials and FAQ blocks to the product page e95221

    • Remove listing banners except for the first one 0b5f7c

    • Added ECI config, layout, and styles 9823dd

    • Updated styles and scripts to work with Qty Switcher module 59ad66

    • Minicart. Update slideout positioning and add scroll tracking for dropdown dialogs 96fbb9

    • Update header panel styles for pagebuilder slider. 4967ce

    • Refactor header panel: remove EasySlide integration, add header panel info block, and update styles for header panel slider 662724

    • Remove EasySlide configuration and related HTML content ea5c76

    • Add noEscape directive to continue shopping button URL ac4b9c

    • Update listing gap variable to use defined spacing 41f0ca

    • Add CSS class to main title in checkout cart layout dc41f6

    • Shopping cart page is done. c1d6d0

    • Shopping cart page in progress 8ca297

    • Shopping cart page 9fa558

    • Enhance quantity input styling and functionality. Apply border-radius to buttons and ensure step attribute is valid. 1bcebb

    • Add padding variable for navigation link caret. aa8d04

    • Quantity wrapper component. f57c8d

    • Product page. Adjustments for related products layout. aa27ee

    • Product page. Add new layout container. Place BCB marquee content there. a2fe52

    • Product page. Enhance gallery configuration and update layout variables for improved styling and responsiveness. b89117

    • Product page. Add grid area for price information and implement gallery layout for improved product display. 76b0b3

    • Product page. Add focus ring styling for checkboxes in related products block to enhance accessibility. ab2227

    • Product page. Refactor related products layout for improved responsiveness and styling consistency. 5aa789

    • Product page. Update quantity button icons to use mask images for better scalability and styling. 9576ee

    • Product page. Related products block. 7ed6de

    • Product page. Implement review popup for full review text display and enhance accessibility. d38885

    • Product page. Add toggle for "Write Your Own Review" form and adjust styles for review list 9973d8

    • Product page. Revies list is done. Revie form next. 5bf007

    • Theme Editor: added Listing, Animations, and Advanced sections a4451d

    • Theme Editor: added Colors section 390891

    • Product page. Reviews in progress... e13b99

    • Theme Editor: added Layout, Typography, Overlay Header, Border Radius, Color and Font Palettes ff5e62

    • Productpage. Review in progress... 7059e9

    • Productpage. Review in progress. 669824

    • BCB featured product component. 0651cf

    • Add styles for featured product details, SKU, and price row in BCB d65f2d

    • BCB accordion styles at product info main. 1a262b

    • Installer. Add accordion for products. 466a5b

    • Add padding to swatch options in product add form for improved layout f10f77

    • Product main info ... in progress bf5c3f

    • Enhance product quantity input with increment/decrement buttons and update styles for better usability 72192e

    • Update product page medium image dimensions to 590x590 012c72

    • Fix minicart styles: set empty counter opacity to 0 79fcd1

    • Increased h2 bottom margin dff6ea

    • Product page action buttons. d008f0

    • Updated footer content links and section titles for improved clarity and user experience 241039

    • BCB homepage: fixed wrong image name b1a4f4

    • Rating stars styles in product listing f17a0f

    • BCB homepage: updated full width banner and sections spacings 2076c7

    • Fixed sort order of product details inside grid listing 9ad360

    • BCB homepage: updated Videos and full width banner sections 072733

    • Product page title font-size. d0987c

    • Footer. Minor fix for ring reval animation. Restore missing divider in footer. (#3) 54cdc4

    • Footer ring reveal animation added (#3) 4a8be8

    • BCB homepage: added animated badges to top banners grid 197e37

    • BCB homepage: added rotation animation for Full Width Banner 1420f9

    • BCB homepage: top banner updated a53bd5

    • Update favicon color 5ea666

    • Update favicon 18d8dc

    • Slightly update footer background. 5fcbfc

    • Footer content update. Add contact block (#3) dea42e

    • Fixed missing minicart overlay on first open (#2) 54feaa

    • BCB homepage: updated Browse categories block dbfa89

    • Breadcrumbs 196469

    • Done with search (#2) d8e0f3

    • Enhance minisearch functionality with slideout behavior and styling adjustments without Ajaxsearch (#2) 8c4a9d

    • Minisearch styles when ajaxsearch disabled... in progress (#2) 259fac

    • Remove unused styles from viewcart action and update empty subtitle styles in minicart (#2) dba7a5

    • Minicart complete (#2) 56efd2

    • Search on desktop (#2) 9c587e

    • BCB homepage: added videos section 7ee864

    • Minicart inprogress (only buttons to adjust)... (#2) c1be91

    • Minicart update in progress.... c3d18b

    • Minicart update in progress... (#2) 55e7b9

    • INstaller. Create dummy CMS block header_panel_info to allow user add custom content (#2) f70d58

    • Adjust minicart counter (#2) 03e843

    • BCB homepage: Added brand logos section b905f1

    • BCB homepage: Added testimonials section 2ab2cf

    • Update newsletter styles: adjust input border and add consent positioning (#2) 02d37d

    • Header. Update search behaviou and look of the result dropown. 993432

    • BCB homepage: Added FAQ a0bfde

    • Add focused search styles. d80f88

    • BCB homepage: added new sections 875068

    • BCB homepage: added ECI and full-width banner d40cfa

    • Top navigation added. 8fa9a3

    • Remove color from menu links dec081

    • Clone currency and store switchers in header slideout menu for improved functionality de36e3

    • Enhance header and newsletter styles for improved layout and responsiveness in header slideout menu. b63dd0

    • Installer. Update header slideout menu styles. 825795

    • Update footer top content HTML to enhance newsletter section styling.
      Don't set font familiy for header in Page Builder ba0b81

    • BCB homepage WIP b228af

    • Basic navpro slideout styles 75ac0e

    • Refactor header slideout menu and newsletter styles for improved layout and consistency 3b42ff

swissup / module-pro-labels

1 hour ago success
  • head
    • Implement label content validation and enhance security for label rendering b73f5a

    • Merge tag '1.10.2'

      1.10.2 d539b4

  • 1.10.2
    • Version 1.10.2 2fd21f

    • Restrict round method to allowed values and add missing ACL checks f974cb

    • Enhance image upload safety by improving file name validation and ensuring safe relative path retrieval d10521

    • Secure label variables rendering. 271155

    • Implement locking mechanism in buildIndexes method to prevent duplicate index rows (close #49) cb44f9

swissup / module-pagespeed

6 hours ago success
  • head
    • Merge pull request #136 from swissup/fix/security-audit-135

      fix(security): audit findings (#135) 8aa502

    • fix(critical-css): reject any markup in critical CSS and share the POST script (#135)

      - assertSafeCss rejects every markup start (<link>, <svg>, <img>, ...), not only
      style/script/comment; saveConfig() runs the same check
      - move the duplicated getPostScript() into PostScriptTrait
      - DebugModeDefaultTest asserts config.xml loaded

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 406f33

    • fix(csp): whitelist www.googleapis.com for the admin area only (#135)

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> bab7ee

    • fix(critical-css): generate actions accept POST with form key only (#135)

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 46e02b

    • fix(critical-css): use https and reject markup in the API response (#135)

      The response is printed unescaped into a <style> tag, so a response that
      closes the tag or opens a script is refused.

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> aecc4f

    • fix(debug): disable debug mode by default (#135)

      The ?pagespeed= switch and the debug console output were open to every
      visitor on a fresh install. They stay available once debug mode is
      enabled on purpose.

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 933453

    • test: run ProductionHeadOrderTest against the Bundles block of the new module

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> cb52e3

    • refactor: move Advanced JS Bundling to swissup/module-advanced-js-bundling

      Config keys and the bundle path are unchanged; the new package is required.

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> b964d6

  • 1.20.0
    • Version 1.20.0 04d9f8

    • feat(webp): debug report for CSS background images with a WebP sibling (#128) (#132)

      * feat(webp): debug report for CSS background images with a WebP sibling (#128)

      In debug mode (PAGESPEED_DEBUG) log to the browser console every
      jpg/jpeg/png url() in inline style attributes and <style> blocks that
      has a WebP file next to it, with the resolved WebP URL and a
      ready-to-paste image-set() snippet. Report only, nothing is rewritten.

      Fixes #128

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

      * fix(webp): CSS background report review fixes (#128)

      - Resolve WebP without the query string: UrlResolver takes the
      extension from the full URL, so "bg.jpg?v=2" never resolved. The
      suffix is put back on the reported WebP URL.
      - Match image-set() quote-aware, so a parenthesis inside a quoted URL
      no longer breaks the "already in image-set()" skip.
      - Strip CSS comments before extracting url().

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

      ---------

      Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> 951b11

    • fix(webp): CSS background report review fixes (#128)

      - Resolve WebP without the query string: UrlResolver takes the
      extension from the full URL, so "bg.jpg?v=2" never resolved. The
      suffix is put back on the reported WebP URL.
      - Match image-set() quote-aware, so a parenthesis inside a quoted URL
      no longer breaks the "already in image-set()" skip.
      - Strip CSS comments before extracting url().

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> e2ade8

    • feat(webp): debug report for CSS background images with a WebP sibling (#128)

      In debug mode (PAGESPEED_DEBUG) log to the browser console every
      jpg/jpeg/png url() in inline style attributes and <style> blocks that
      has a WebP file next to it, with the resolved WebP URL and a
      ready-to-paste image-set() snippet. Report only, nothing is rewritten.

      Fixes #128

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> 66ee62

    • fix(webp): keep srcset descriptors and sizes on <source> (#130) (#131)

      * fix(webp): keep srcset descriptors and sizes on <source> (#130)

      The picture tag got one <source> per src/srcset, built from bare URLs:
      w/x descriptors and sizes were lost, and the src-based <source> came
      first, so browsers always loaded the smallest WebP.

      Emit a single <source>, from srcset when present (URLs replaced in
      place with strtr, descriptors kept), from src otherwise, and copy sizes
      from the <img>. Skip the <source> when any srcset candidate has no WebP
      variant instead of dropping the candidate.

      Fixes #130

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

      * fix(webp): skip <source> when srcset parser misses a candidate (#130)

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

      ---------

      Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> 6f288d

    • fix(webp): skip <source> when srcset parser misses a candidate (#130)

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> 16991b

    • fix(webp): keep srcset descriptors and sizes on <source> (#130)

      The picture tag got one <source> per src/srcset, built from bare URLs:
      w/x descriptors and sizes were lost, and the src-based <source> came
      first, so browsers always loaded the smallest WebP.

      Emit a single <source>, from srcset when present (URLs replaced in
      place with strtr, descriptors kept), from src otherwise, and copy sizes
      from the <img>. Skip the <source> when any srcset candidate has no WebP
      variant instead of dropping the candidate.

      Fixes #130

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> 5005e9

    • feat(webp): separate "Replace WebP in inline JS" option (#126) (#129)

      * feat(webp): separate "Replace WebP in inline JS" option (#126)

      New config pagespeed/image/optimize_webp_js_replace (default 1) lets the
      inline JS WebP rewrite be turned off on its own; isReplaceWebPInJs() now
      reads it.

      With "Add picture tag" on and the JS rewrite off, <img> inside <picture>
      keeps the original jpg/png src/srcset and WebP goes only into
      <source type="image/webp">, giving browsers without WebP (Safari/iOS < 14)
      a real fallback. Defaults keep the current markup: <img> still carries the
      WebP URL that Breeze gallery matches against the rewritten gallery JSON.

      Fixes #126

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

      * refactor(webp): resolve WebP variants once per img in keep-original mode (#126)

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

      * fix(webp): keep inline JS replace on without picture tag (#126)

      Without the picture tag <img> always gets the WebP URL, so turning off
      the inline JS rewrite left the Breeze gallery JSON on jpg/png and the
      gallery lost the image. The option now only takes effect together with
      "Add picture tag" and is hidden in admin otherwise.

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

      ---------

      Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> 65e702

    • fix(webp): keep inline JS replace on without picture tag (#126)

      Without the picture tag <img> always gets the WebP URL, so turning off
      the inline JS rewrite left the Breeze gallery JSON on jpg/png and the
      gallery lost the image. The option now only takes effect together with
      "Add picture tag" and is hidden in admin otherwise.

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> e20abd

    • fix(lazyload): stop choosing offset by User-Agent (#125) (#127)

      getOffset() picked lazyload_mobile_offset or lazyload_offset from the
      request User-Agent, but the optimizer runs before FPC/Varnish store the
      page. The first visitor after a purge chose the offset for every device:
      a phone warming the cache lazy-loaded desktop above-the-fold images,
      while desktop cache warmers made the mobile offset dead.

      The offset now always comes from lazyload_offset. The mobile offset
      config path, constant and getter stay for BC and are marked deprecated;
      the admin field says it has no effect.

      Fixes #125

      Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> 1a6b60

    • refactor(webp): resolve WebP variants once per img in keep-original mode (#126)

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> a5c8db

    • feat(webp): separate "Replace WebP in inline JS" option (#126)

      New config pagespeed/image/optimize_webp_js_replace (default 1) lets the
      inline JS WebP rewrite be turned off on its own; isReplaceWebPInJs() now
      reads it.

      With "Add picture tag" on and the JS rewrite off, <img> inside <picture>
      keeps the original jpg/png src/srcset and WebP goes only into
      <source type="image/webp">, giving browsers without WebP (Safari/iOS < 14)
      a real fallback. Defaults keep the current markup: <img> still carries the
      WebP URL that Breeze gallery matches against the rewritten gallery JSON.

      Fixes #126

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> 5fb521

    • fix(lazyload): stop choosing offset by User-Agent (#125)

      getOffset() picked lazyload_mobile_offset or lazyload_offset from the
      request User-Agent, but the optimizer runs before FPC/Varnish store the
      page. The first visitor after a purge chose the offset for every device:
      a phone warming the cache lazy-loaded desktop above-the-fold images,
      while desktop cache warmers made the mobile offset dead.

      The offset now always comes from lazyload_offset. The mobile offset
      config path, constant and getter stay for BC and are marked deprecated;
      the admin field says it has no effect.

      Fixes #125

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> f96d9b

breezefront / module-breeze

6 hours ago success
  • head
    • Prevent infinite loop when head contains invalid stylesheet link 582a77

    • Fixed incorrect magnifier image when using expanded gallery fc2f6b

    • Prevent auth popup form submit when recaptcha is not ready yet
      Closes #101 740ada

    • Fixed incorrectly marked lazyload when main image is not the first one d5cd6b

    • Do not add dom duplicates to $.registry 84beb6

  • 2.32.0
    • Version 2.32.0 62d26e

    • Remove unused `lazyAsync` function 98e9d8

    • Gallery: Fixes slider fallback for mobile devices for `expanded` option eb5ff6

    • Center dots when using expanded layout (on mobile) 88f78f

    • Gallery: Restore proper tabindex in destructor 19bb81

    • Gallery: Use slider fallback for mobile devices for `expanded` option 7847d1

    • Improved slider destructor to cleanup listeners and markup dd8400

    • Remove unused code 6292c3

    • Do not close accordion when multipleCollapsible is used b1b4a7

    • LazyAsync 9e0a37

    • Removed redundant 'contentUpdated' dead1b

    • Faster DOM traversal after contentUpdated event 9c2d61

    • Simplify quotedScope from prev commit 37a7b7

    • Improve scope binding match logic
      minicart_content should not match x_minicart_content;
      minicart.content should not match minicart_content 5e9bca

    • Speculation rules: fixed not working exclude rules c78263

    • Added missing destructor to pagebuilderCarousel 81d228

    • Do not close dropdownDialog when dragging the slider inside eed793

swissup / module-pdf-invoice

8 hours ago success

swissup / module-helpdesk

8 hours ago success
  • head
    • Merge pull request #66 from swissup/fix/attachment-path-traversal-65

      fix(file): close arbitrary file read via client-controlled attachment path (#65) ef4e71

    • fix(file): match whole attachment entries, not substrings, when authorising download (#65)

      The download check used LIKE %path%, so a visitor could attach
      '/a/b/ab.png.mine.png' and fetch another visitor's '/a/b/ab.png' with
      their own message hash. Now the path must equal one entry of the
      ';' separated list, case-sensitively.

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 5b6ebd

    • Merge remote-tracking branch 'origin/master' into fix/attachment-path-traversal-65 8bc6e2

    • Merge pull request #68 from swissup/fix/laminas-mail-dependency-67

      fix(deps): suggest laminas/laminas-mail for inbound email (#67) 00ecdf

    • fix(email-storage): clear error when laminas-mail has no Xoauth2 support (#67)

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> d31dde

    • fix(upload): spend registered attachments only after a successful save (#65)

      filter() no longer mutates the registry; markUsed() runs after the save, so
      a validation error or exception does not force the visitor to re-upload.
      register() now ignores non-string values.

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 4c69a8

    • fix(file): use explicit LIKE ESCAPE that ignores NO_BACKSLASH_ESCAPES (#65)

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 2289d7

    • fix(cron): skip e-mail pickup with a log message when laminas-mail is missing (#67)

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 2af508

    • fix(deps): suggest laminas-mail instead of requiring it (#67)

      laminas-mail 2.25.1 caps PHP at 8.3, so a hard require makes the module
      uninstallable on PHP 8.4. Suggest it (and the oroinc PHP 8.4 fork) instead.

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> ca9ad8

    • fix(email-storage): initialise $authResponse before by-ref readLine (#67)

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> a0a990

    • fix(deps): declare laminas/laminas-mail ^2.20 (#67)

      Magento 2.4.8 mails via symfony/mailer and no longer requires it, but
      inbound email uses Laminas\Mail, including Xoauth2 classes added in 2.20.0.

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 7b43d6

    • fix(upload): accept only attachments uploaded in the visitor's own session (#65)

      Ticket and message forms posted any string as the attachment path.
      Now the upload endpoint registers each stored file in the session and the
      save controllers keep only registered, not yet used, files.

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> e0cb82

    • feat(security): add session registry of uploaded attachments (#65)

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 86ced9

    • fix(message): do not build download links for unsafe stored paths (#65)

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 761eed

    • fix(file): reject unsafe paths in download and escape LIKE wildcards (#65)

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> a34414

    • fix(file): add attachment path validator to FileInfo (#65)

      Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> 7e53d7

swissup / module-social-login

8 hours ago success
  • head
    • A social account is now permanently tied to one customer, linked accounts stored in separate table 46e8bd

swissup / module-recaptcha

8 hours ago success
  • head
    • Protect place order API endpoints with recaptcha

      Checkout recaptcha was validated only on payment-information services.
      Orders could be placed without recaptcha via:
      - PUT /V1/guest-carts/:cartId/order
      - PUT /V1/carts/mine/order
      - the same services over async REST (incl. bulk) and SOAP

      Validate these endpoints in a ServiceInputProcessor plugin, which runs
      only for API input, so internal placeOrder() calls are not affected.

      Validation logic moved from AbstractValidation to
      Model\Checkout\PaymentValidator, shared by both plugins.

      Also:
      - enable module in webapi_soap area (same services as REST);
      - skip recaptcha for admin and integration tokens;
      - missing recaptcha response returns error instead of TypeError.

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> b43c58

swissup / module-easyflags

8 hours ago success
  • head
    • Fix stored XSS and path traversal in flag image handling (#9)

      Fix stored XSS and path traversal in flag image handling
      - Escape flag image URL in frontend and admin grid templates
      - basename() the posted image name before moveFileFromTmp
      - Add allowedMimeTypes to the image uploader
      - Escape switcher mode class, placeholder text and AMP link href
      * Mark JSON output in url-variants as safe for coding standard
      * Drop support of Magento < 2.3 317f01

    • Drop support of Magento < 2.3 7b86b0

    • Mark JSON output in url-variants as safe for coding standard

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> 3a52b2

    • Fix stored XSS and path traversal in flag image handling

      - Escape flag image URL in frontend and admin grid templates
      - basename() the posted image name before moveFileFromTmp
      - Add allowedMimeTypes to the image uploader
      - Escape switcher mode class, placeholder text and AMP link href

      Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> fd83d1

breezefront / module-breeze-layout-builder

12 hours ago error
  • head
    • More secure component id rendering 20e0f3

    • Added signed preview token e26e52

    • Fixed header/footer issues with containers toggle, undo/redo, versions and publishing d3cd7e

    • Fixed missing background on Classic header layout on Eir theme aad26a

    • Fixed preview issue after previous commit ea8cea

    • Updating page selector links when store view switched 0d3d12

    • Added page visibility control and installer support for header/footer content 796f48

    • Fixed not working theme editor colors for overlay header 2660ce

    • Do not show overlay header toggles for native layout b000f5

    • WIP. Header layouts: added overlay mode support 8122c9

    • Correct page cleanup when BLB is closed 45b825

    • Improved header/footer preview 07c294

    • Header/Footer management with Header Layouts 7a0a82

  • 1.2.0
    • Version 1.2.0 24fff8

    • Added Contact Us page support d64e46

    • Config option for upcoming TaxVAT switcher in theme header 7f31bd