Stripe changelog
-
1.0.0
StableFirst public release of the Stripe payment plugin for Solidshop (
plg_solidshoppayment_stripe). Establishes the baseline that all future changelog entries are deltas against.Added
- Stripe's Payment Element at checkout — one integration surfaces every method enabled in the merchant's Stripe account (cards with 3-D Secure, Apple Pay, Google Pay, Klarna, Affirm, Afterpay/Clearpay, iDEAL, SEPA Direct Debit, ACH and more), picked per visitor by region, currency and device.
- Side-by-side test and live credentials with a per-store test-mode switch. A mode with no keys saved hides Stripe at checkout rather than stranding the shopper on a Payment Element that cannot initialise.
- Stripe Connect — an optional connected account ID per mode, sent as the
Stripe-Accountheader. - Every currency Stripe supports, converted using Stripe's own zero- and three-decimal lists rather than ISO precision (the two disagree on HUF and TWD).
- Webhook reconciliation on a signed, per-store callback endpoint (
payment_intent.succeeded,charge.refunded), with the URL to paste into Stripe shown as a copyable field on the payment settings. - Asynchronous methods (SEPA Direct Debit, ACH) finish checkout as processing; the webhook marks the order paid and sends the confirmation email once the money has actually moved. Redirect and BNPL methods return through a tokened
payment.finishURL, so an approval that outlives the checkout session still lands on the right order. - Refunds from the admin order screen, full or partial, with an idempotency key keyed on the refund sequence. Refunds issued in the Stripe dashboard reconcile back through
charge.refundedby comparing cumulativeamount_refundedagainst the local ledger, which self-dedupes admin echoes and redeliveries. - Charges are named in the Stripe dashboard (store name plus order reference), and captures are logged on the order's Activity Timeline from both the inline confirm and the webhook, deduplicated on transaction id.
- Configurable payment surcharge per store, confirmation emails enqueued only once payment is confirmed, and a dedicated Joomla log for every payment event and rejection.
- Bundled admin translations for 23 languages, including full RTL support (Arabic, Hebrew, Persian).
Security
- Every AJAX call carries an HMAC order token, so no shopper can drive another's order through the payment endpoints; webhooks are verified against the signing secret and re-checked against the store ID in the callback URL.
- A confirmation is accepted only when the intent ID, currency and amount all match the order — a stale intent left by an admin order edit records a partial payment instead of marking the order paid in full — and confirming an already-paid order is treated as an idempotent replay, which is what happens whenever the webhook wins the race against the browser.
Requires Joomla 6.x+, PHP 8.4+, and Solidshop 1.3.1+ (enforced at install by the plugin's installer scriptfile).