Skip to content

Release v0.4.25 - #119

Open
roncodes wants to merge 18 commits into
mainfrom
release/v0.4.25
Open

roncodes wants to merge 18 commits into
mainfrom
release/v0.4.25

Conversation

@roncodes

@roncodes roncodes commented Oct 6, 2026

Copy link
Copy Markdown
Member

Release branch for v0.4.25, cut from main. Versions are bumped in composer.json, extension.json and package.json, and RELEASE.md has the notes.

This branch collects:

Before merging

Merging this tags v0.4.25. The version comes from the branch name and is checked against the version files and the first line of RELEASE.md.

The S3 media bucket enforces bucket-owner object ownership and rejects PUTs that
carry an ACL, so put(..., 'public') returned false and no photo was stored.
…annel resolvers

- POST storefront/v1/customers/socket-token mints a customer principal (store key +
  Customer-Token); 404 while socket auth is disabled, 401 without a customer of the
  storefront's company.
- Checkout initialization responses carry socket_token (checkout kind, scp limited to
  checkout.{public_id}) when socket auth is enabled; absent otherwise.
- Register storefront and checkout channel resolvers with core-api's
  SocketChannelRegistry.
- QPay capture publishes {checkout, status, order, error} on checkout.{public_id}
  instead of the raw payment row; a publish failure no longer fails the callback.
- Require fleetbase/core-api ^1.6.69.
Listing a network's stores ran several queries per store and loaded the whole
network for distance sorting, so a page of stores could take minutes.

- Store resource: build category, networks, locations and media only when the
  field is requested (when() evaluated its value argument for every store)
- Preload the review average with withAvg() on the public and console store
  queries; the rating accessor uses it instead of one AVG query per store
- Console store list eager-loads logo and backdrop, and networks when the
  network category is requested
- Network category lookup reuses eager-loaded networks and resolves each
  network id once instead of once per store
- Ignore missing or unparseable locations instead of measuring from (0, 0):
  no in-memory sort of every store, and maximum_distance no longer filters
  out every store when no location is sent
- Index reviews.subject_uuid
…n-review delete

- Customers can review a store or product only for a completed order placed with
  that store or containing that product, once per order per subject. Reviews
  record the order (new reviews.order_uuid).
- GET reviews/eligibility tells the app whether the signed-in customer can review
  a subject, and why not.
- DELETE reviews/{id} now routes to delete() instead of find(), so customers can
  remove their own reviews.
- Ratings must be whole stars from 1 to 5; content is limited to 2000 characters
  and uploads to four image or video files.
- The review resource names the subject by public id instead of the internal row
  id, and adds subject_type, verified and is_mine.
…on public promotions

- Public promotions name the store or network running them (owner: type, id,
  name, logo_url) and list applies_to targets by public id instead of uuid.
- Code promotions show their code publicly when they have one reusable,
  unassigned, unexpired code; single-use batch codes are never exposed.
- Every promotion reports availability (live, scheduled, ended) and, when
  scheduled, next_starts_at from its date range and weekly hours.
- GET promotions?include=scheduled also lists promotions outside their weekly
  hours or before their start; GET promotions/{id} opens scheduled and ended
  promotions so links from notifications keep working.
- storefront/v1/orders/{id}/chat: show (starts the chat), messages (cursor
  pagination), send (text and up to four photos) and read (receipts), for the
  signed-in customer's own orders in this storefront.
- The chat is a core chat channel tagged with the order in its meta, so the
  driver sees it in Navigator; participants are kept to the customer and the
  currently assigned driver, and it is started when a driver is assigned.
- Customers can read but not send once the order is completed, canceled or
  expired.
- Driver messages are pushed to the customer through storefront push, the inbox
  and the customer's broadcast channel.
- Customer socket tokens include the customer's user uuid so they can subscribe
  to chat_channel.{uuid}, which core authorizes by participant.
@codecov

codecov Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (62af547) to head (ca4a2f6).
⚠️ Report is 3 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff              @@
##                main      #119    +/-   ##
============================================
  Coverage     100.00%   100.00%            
- Complexity      2282      2363    +81     
============================================
  Files            182       183     +1     
  Lines           9082      9269   +187     
============================================
+ Hits            9082      9269   +187     
Flag Coverage Δ
backend 100.00% <100.00%> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

fix(reviews): upload review photos without a public ACL
perf: speed up network and console store listings
feat(reviews): verified-purchase reviews, eligibility endpoint and own-review delete
feat(promotions): store attribution, shareable code and availability on public promotions
…-chat

# Conflicts:
#	server/tests/Unit/Routes/StorefrontRoutesTest.php
feat(chat): customer chat with the driver delivering their order
feat(products): expose add-on category limits on public product payloads
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant