Downloadable changelog

  1. 1.0.1

    Stable

    Added

    • Download counts the merchant can see. Every download served is now counted on the file as well as on the customer's link, so each product carries a lifetime total that survives the expired-token cleanup. The product edit form's Downloads tab shows the count beside every file, and a new Show Download Count plugin option (off by default) adds "N downloads" to the product page summary bar next to the sold count. The update seeds the per-file figure from the tokens still on record; downloads whose tokens the cleanup task had already purged cannot be recovered, so on a store that has been running the task the seeded number is a floor.
    • A Downloads panel on the admin order page. An order that holds download links gets a panel listing every link with its downloads used against the limit, the time of its last download (recorded from this release on), its expiry, and the same Available / Awaiting Payment / Link Expired / Limit Reached status the customer sees on their account page.
    • Reset Counter and Extend Expiry on that panel, for the two support requests digital goods generate. Reset returns a link's counter to zero so the customer gets the full limit again; the file's lifetime total is left alone. Extend adds a number of days to the current expiry — or to today when the link has already expired, so an extension always yields a working link — and 0 removes the expiry. Both require the Solidshop Manage Orders permission, act on one link without touching the product's settings, and leave a note on the order's activity timeline naming the file and the change. Until now the only remedy was a fresh zero-priced order.

    Changed

    • The plugin's AJAX endpoint authorises per action: file management (list, upload, delete, reorder) keeps requiring Manage Products, while the new link actions require Manage Orders, matching the screens each sits on.
    • Schema: download_count on #__sshop_download_files and last_downloaded_at on #__sshop_download_tokens (migration 1.0.1.sql). The minimum Solidshop version stays at 1.4.0.
  2. 1.0.0

    Stable

    First public release of Downloadable Products for Solidshop (pkg_solidshopdownloadable), the free package that adds a Downloadable product type to a Solidshop store and delivers the files through token-secured links. It holds two extensions: the feature plugin plg_solidshop_downloadable and the scheduler plugin plg_task_solidshopdownloads, which purges expired download tokens and installs disabled. Establishes the baseline that all future changelog entries are deltas against.

    Added

    • A Downloadable product type, registered through the product-type registry so it joins Physical in the product-type picker the moment the plugin is enabled. It is not shippable and does not track stock by default; everything else about the product — price, tax class, categories, custom fields, translations, SEO, listings, cart and checkout — is unchanged.
    • A Downloads tab on the product edit form: as many files as the product needs, each with an optional display name separate from the name on disk, reordered by drag handle. Uploads, renames, deletes and reordering happen inline without a page reload. Files belong to the product as a whole and are delivered for every variant of it.
    • Per-product download limit (downloads per file, per purchase; 0 for unlimited) and download expiry (seconds after purchase; 0 for never). Both are per purchase: a later order for the same product issues fresh links with a fresh counter and expiry, and links already issued keep the terms they were sold under when the product's numbers change.
    • Token-secured delivery. Order placement mints one random 64-character token per file, per order line, each with its own counter, limit and expiry. The download endpoint checks the token, the expiry and the remaining count, increments the counter and streams the file as an attachment; the file's location on disk appears in no URL. An expired or exhausted link answers "gone" rather than serving the file.
    • Downloads unlock on payment. Tokens exist from the moment the order is placed, but nothing is served until the order's payment status is Paid, so bank-transfer and cash-on-delivery orders show an Awaiting payment badge and no button until then. A partial refund leaves access intact; a full refund removes it. The paid/expired/limit verdict lives in the core library (Solidshop\Lib\Download\DownloadAvailability, Core 1.4.0), so the account page and the download endpoint cannot disagree.
    • An Account → Downloads page listing every file the logged-in customer is entitled to across all their orders, with the product, the order, the remaining downloads and the expiry date. Exhausted and expired rows stay in the list with the reason shown. Served by a site model (DownloadModel); the template is an ordinary Joomla layout override target, with Bootstrap markup for Cassiopeia and a Foundra override.
    • A "Your downloads" block in the order emails — the order confirmation and the payment-received email — listing every file as a direct link grouped by order line. The token is the credential, so the links work without a login and guest checkouts are delivered properly. If payment is still pending when the confirmation goes out, the block says so and the same links start working once the order is marked paid. For orders that carry downloads the payment-received email is sent even when it is switched off for ordinary orders, and an order with nothing to ship no longer promises a shipping confirmation.
    • Storefront presentation: a Download info tab on the product page (instant download, downloads per purchase, link validity), plus a dedicated Downloadable option in the product's Layout dropdown that renders the same summary inline.
    • Storage inside the Joomla installation, under files/shop/{store}/downloads/ by default and anywhere else via the plugin's storage-path setting. Filenames are sanitised and given a random 16-character suffix; deny-all guard files (.htaccess, web.config, a blank index.html) are created automatically and re-created if they go missing. On nginx, which honours neither, the random suffix is the protection — deny the directory in a location block or move the storage path outside the web root.
    • Two upload safeguards: a configurable extension allowlist (PDFs, archives, audio, video, eBooks, office documents and installers by default) and a server-side content-type check that rejects server-executable files regardless of extension. Uploading requires the Solidshop Manage Products permission.
    • The companion scheduler plugin plg_task_solidshopdownloads, which registers a Solidshop: Expired Download Token Cleanup task type that deletes tokens whose expiry has passed. Expired links answer correctly whether or not it runs; the task only stops the token table growing.
    • Shipped as one Joomla package with blockChildUninstall, so the plugin and its task companion install, update and uninstall as a unit. The package owns the update stream; the package installer refuses to run against a Solidshop older than 1.4.0 before either plugin is touched. Uninstalling drops both tables and leaves the uploaded files on disk.
    • Twenty-three administrator locales.