Event Tickets
Fixes
- Corrected the ticket sale duration date picker so it closes when clicking elsewhere in the editor, and gave new tickets a one day sale window when the event has no dates saved yet, instead of an invalid end date.
- Kept an event's payment provider when its ticket settings are saved, and left the provider selectable until the first ticket (not an RSVP) is created.
Security
- Hardened the permission and state handling of QR code check-in notices.
- Strengthened validation of RSVP orders placed through the REST API.
- Tightened the permission checks for regenerating the QR code API key.
Tweaks
- Centered the labels of the secondary buttons in the ticket admin panels, including the settings button icon, so they line up vertically within the button.
Languages
- 3 new strings added, 64 updated, 0 fuzzied, and 0 obsoleted.
Fixes
- Prevented the Tickets metabox from losing fields in the Classic Editor when the RSVP metabox is placed above it.
Features
- Changed where RSVPs are stored to agree with Tickets. This will happen after you manually start a migration and only if you are using RSVPs already.
Languages
- 60 new strings added, 336 updated, 3 fuzzied, and 8 obsoleted.
Security
- Tightened the permission checks when creating and updating tickets through the REST API.
Tweaks
- Added actions:
tec_tickets_commerce_cart_process,tec_tickets_rsvp_after_save,tec_tickets_rsvp_after_meta_update,tec_tickets_rsvp_before_delete,tec_tickets_rsvp_after_delete,tec_tickets_commerce_attendee_before_delete,tec_tickets_commerce_attendee_after_delete,tec_tickets_attendee_registration_before_meta_form_fields,tec_tickets_attendee_registration_after_save,tec_tickets_commerce_single_order_details_metabox_before,tec_tickets_commerce_single_order_details_metabox_after,tribe_events_rsvp_pre_edit,tec_event_tickets_rsvp_form__start,tec_event_tickets_rsvp_metabox_edit_main,tec_event_tickets_rsvp_post_options,tec_event_tickets_rsvp_bottom,tec_tickets_my_tickets_ticket_information_after_ticket_name,event_tickets_user_details_tickets,tec_tickets_user_details_tickets - Added filters:
tec_tickets_enabled_ticket_forms,tec_tickets_build_ticket_properties,tec_tickets_rest_ticket_upsert_params,tec_tickets_rsvp_enabled,tec_tickets_rsvp_version,tec_tickets_rsvp_v2_initial_ticket,tec_tickets_commerce_cart_add_full_item_params,tec_tickets_rsvp_v2_classic_save_data,tec_tickets_commerce_get_ticket_legacy,tec_tickets_rsvp_v2_cart_upsert_item_args,tec_tickets_rsvp_v2_render_step_template_args_pre_process,tec_tickets_rsvp_v2_render_step_template_args,tec_tickets_rsvp_v2_show_attendees_list_optout,tec_tickets_rsvp_process_ticket_fields,tec_tickets_rsvp_process_additional_fields,tec_tickets_editor_list_tickets,tec_tickets_rsvp_show_attendees_list,tec_tickets_rsvp_get_attendees_by_id_pre,tec_tickets_rsvp_get_attendees_by_user_id_pre,tribe_tickets_attendee_activity_log_data,tribe_tickets_has_meta_enabled,tribe_tickets_rsvp_form_email,tribe_tickets_rsvp_form_full_name - Changed views:
tickets/email,tickets/my-tickets/orders-list,tickets/my-tickets/ticket-information,tickets/my-tickets/tickets-list,tickets/my-tickets/user-details,tickets/orders-rsvp,tickets/orders-tc-tickets,v2/commerce/rsvp,v2/commerce/rsvp/actions,v2/commerce/rsvp/actions/full,v2/commerce/rsvp/actions/rsvp,v2/commerce/rsvp/actions/rsvp/going,v2/commerce/rsvp/actions/rsvp/not-going,v2/commerce/rsvp/actions/success,v2/commerce/rsvp/actions/success/title,v2/commerce/rsvp/actions/success/toggle,v2/commerce/rsvp/actions/success/tooltip,v2/commerce/rsvp/ari,v2/commerce/rsvp/ari/form,v2/commerce/rsvp/ari/form/buttons,v2/commerce/rsvp/ari/form/error,v2/commerce/rsvp/ari/form/fields,v2/commerce/rsvp/ari/form/fields/email,v2/commerce/rsvp/ari/form/fields/meta,v2/commerce/rsvp/ari/form/fields/name,v2/commerce/rsvp/ari/form/guest-template,v2/commerce/rsvp/ari/form/guest,v2/commerce/rsvp/ari/form/template/fields,v2/commerce/rsvp/ari/form/template/title,v2/commerce/rsvp/ari/form/title,v2/commerce/rsvp/ari/sidebar,v2/commerce/rsvp/ari/sidebar/guest-list,v2/commerce/rsvp/ari/sidebar/guest-list/guest-template,v2/commerce/rsvp/ari/sidebar/guest-list/guest,v2/commerce/rsvp/ari/sidebar/quantity,v2/commerce/rsvp/ari/sidebar/quantity/input,v2/commerce/rsvp/ari/sidebar/quantity/minus,v2/commerce/rsvp/ari/sidebar/quantity/plus,v2/commerce/rsvp/ari/sidebar/title,v2/commerce/rsvp/attendees,v2/commerce/rsvp/attendees/attendee,v2/commerce/rsvp/attendees/attendee/name,v2/commerce/rsvp/attendees/attendee/rsvp,v2/commerce/rsvp/attendees/title,v2/commerce/rsvp/content-inactive,v2/commerce/rsvp/content,v2/commerce/rsvp/details,v2/commerce/rsvp/details/attendance,v2/commerce/rsvp/details/availability,v2/commerce/rsvp/details/availability/days-to-rsvp,v2/commerce/rsvp/details/availability/full,v2/commerce/rsvp/details/availability/remaining,v2/commerce/rsvp/details/availability/unlimited,v2/commerce/rsvp/details/description,v2/commerce/rsvp/details/title,v2/commerce/rsvp/form/buttons,v2/commerce/rsvp/form/fields,v2/commerce/rsvp/form/fields/cancel,v2/commerce/rsvp/form/fields/email,v2/commerce/rsvp/form/fields/name,v2/commerce/rsvp/form/fields/quantity,v2/commerce/rsvp/form/fields/submit,v2/commerce/rsvp/form/form,v2/commerce/rsvp/form/going/title,v2/commerce/rsvp/form/not-going/title,v2/commerce/rsvp/form/title,v2/commerce/rsvp/messages/error,v2/commerce/rsvp/messages/must-login,v2/commerce/rsvp/messages/success,v2/commerce/rsvp/messages/success/going,v2/commerce/rsvp/messages/success/not-going,v2/commerce/rsvp/my-tickets/ticket-status,v2/commerce/rsvp/my-tickets/user-details,v2/rsvp/actions/rsvp,v2/rsvp/actions/success,v2/rsvp/content,v2/rsvp/details/availability/remaining,v2/rsvp/messages/must-login - Removed filters:
tribe_rsvp_email_subject,tribe_rsvp_non_attendance_email_content
Security
- Hardened the validation of assigned seating reservations.
Languages
- 0 new strings added, 39 updated, 0 fuzzied, and 0 obsoleted.
Security
- Hardened the validation of the sort parameters used when ordering the tickets reports.
- Tightened validation on assigned seating reservation and session handling. Props to "sequence_X0" for the report!
Fixes
- Dropped the cached calendar-view ticket data when tickets are sold and when the plugin updates, instead of rebuilding it mid-order, resolving an issue where sold-out events kept showing the remaining ticket count on calendar and list views.
- Fixed an issue where a custom ticket sale end date set during ticket creation in the block editor reverted to the event start date after saving the event.
- Renewed the Square access token ahead of its expiration and retried a rejected request once against the fresh one, which kept Tickets Commerce checkout from failing about 30 days after connecting to Square. Where Square would neither renew the credentials nor accept the stored token, the gateway reported itself as disconnected with an admin notice instead of showing a healthy connection while live charges failed.
- Resolved a fatal error that could occur while rendering the Move Attendees dialog when another plugin listened on the admin_enqueue_scripts action.
- Resolved an issue where the tickets and attendees REST API archives could return a JSON object instead of an array when an entry could not be formatted, preventing the Event Tickets Plus App from listing attendees.
- Stripe checkout could return a server error and never charge the buyer when a coupon changed the cart total, because the application fee left on the Payment Intent no longer matched the discounted amount.
Languages
- 7 new strings added, 153 updated, 0 fuzzied, and 1 obsoleted.
Security
- Tightened the handling of Assigned Seating reservations, covering the seat labels stored against attendees and the session tokens reservations are filed under.
Fixes
- Resolved a fatal error that could be triggered in the Tickets Commerce cart when the decoded ticket data was null.
- Prevented the cart-to-checkout redirect and the checkout page from being stored by full-page and edge caches, resolving an issue where the Tickets Commerce checkout could show 'Oops, no tickets!' after selecting tickets.
Languages
- 5 new strings added, 75 updated, 0 fuzzied, and 9 obsoleted.
Security
- Enforced ticket sale start and end dates server-side, and capped RSVP quantities to the maximum allowed per purchase.
Security
- Hardened attendee details rendering.
- Hardened validation of the ticket parameters.
Fixes
- Resolved an issue where a Stripe checkout could leave the buyer on an endless spinner with their payment taken but no order completed.
Performance
- Stopped resolving the current user during bootstrap on front-end requests to decide whether the admin Attendees screens should be registered.
Languages
- 1 new strings added, 16 updated, 0 fuzzied, and 0 obsoleted.
Fixes
- Prevented a fatal error on the WooCommerce order edit screen when attendee data was read from a generator, so orders containing tickets open normally again.
Languages
- 0 new strings added, 15 updated, 0 fuzzied, and 0 obsoleted.