You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
Updates the WooCommerce spam-orders experience by integrating the plugin’s “blocked orders” table into the native WooCommerce Orders admin screen (HPOS), aligning columns/styles with WooCommerce UI, and adjusting checkout handling to support storing/redirecting blocked checkouts.
Changes:
Reworks the spam orders list table UI (new columns, totals, status views integration, pagination/sorting tweaks).
Hooks into the WooCommerce HPOS orders screen to add “Spam”/“On hold” status links and to replace the renderer when viewing Spam.
Adds a helper for counting stored spam orders and updates admin/settings links to point at the WooCommerce orders screen spam view.
Reviewed changes
Copilot reviewed 7 out of 8 changed files in this pull request and generated 5 comments.
Same issue as the AJAX checkout path: returning early here skips the spam check for Store API checkouts when data__wc_store_blocked_orders is off, even though the setting is documented as “store blocked orders” (not “disable protection”).
if ( ! $apbct->settings['data__wc_store_blocked_orders'] ) {
// The checkout is left to WooCommerce as is: no check, no blocked order to store.
return;
}
❌ Patch coverage is 41.64524% with 227 lines in your changes missing coverage. Please review.
✅ Project coverage is 32.03%. Comparing base (096bee4) to head (735d3a0).
❌ Your patch check has failed because the patch coverage (41.64%) is below the target coverage (70.00%). You can increase the patch coverage or adjust the target coverage.
…ocked order overview.
WooCommerce renders checkout/thankyou.php for the no-order confirmation page,
not checkout/order-received.php. The overview was never shown because of this
mismatch.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…m orders.
addOrdersListStatusViews() only integrates the 'Spam' view into the native
orders screen when wc_get_page_screen_id() reports the HPOS screen. Legacy
(posts table) installations render orders on the shared post-type screen
instead, so the option was lost when the old admin_menu submenu page was
removed. A conditional fallback page is registered again for that case,
reusing the existing renderSpamOrdersPage() renderer.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…al'.
calcOrderTotal() only sums the stored cart line items and their tax - shipping,
fees and other checkout charges are not persisted for a blocked order, so the
value was understated relative to a real order total. The label now reflects
what is actually shown; the underlying calculation is unchanged.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…) when a Closure is hooked to the orders page.
isset($callback['function'][0]) throws 'Cannot use object of type Closure
as array' when another plugin/theme hooks a Closure to the same orders page
hook, since Closure does not implement ArrayAccess. An is_array() guard is
added before the offset access.
Also adds unit tests for the admin/list-table hooks of the WooCommerce
integration: addOrdersListStatusViews, addOrdersListStatusLinks,
getOrdersListViews, keepOrdersListWhenSpamOrdersExist,
replaceOrdersListRenderer, addOrdersSpamStatus*, addSpamActionToBulk*
and renderSpamOrdersPage.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…ng the blocked order.
getStoreApiPassedResponse($order) was called after $order->delete(true),
which clears the in-memory order ID and data. The Store API client could
then receive order_id 0 and empty fields instead of a valid response.
The response is now captured right after handleBlockedOrder() and before
any cleanup, then emitted afterwards.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…t admin page on legacy installs.
The link always targeted the HPOS 'wc-orders' screen. On legacy
(non-HPOS) installations addLegacySpamOrdersMenuPage() registers
'apbct_wc_spam_orders' instead, so the link led to an unregistered
screen and left stored spam orders unreachable from Settings.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
addOrdersListStatusViews() registered the 'Spam' view/status links for
any user who could open the orders screen, without a capability check.
The row action buttons and the restore/details AJAX handlers already
required manage_options, so a Shop Manager (without manage_options)
could see the view but got a 403 trying to use it.
Now the view registration, the legacy admin menu page and the row
action handler all consistently require manage_options.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…ers page.
renderSpamOrdersPage() always built getOrdersListViews(), which links
to 'page=wc-orders' (HPOS only). It's also the callback for the legacy
'apbct_wc_spam_orders' fallback page (addLegacySpamOrdersMenuPage()),
so on non-HPOS installations the embedded views pointed at the wrong
screen. Now null is passed on legacy installs, so the list table
builds its own standalone (legacy-correct) views instead.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
When the migrated forms__wc_show_rejection_message option is enabled, classic checkout returns the legacy failure response, but this unconditional empty_cart() removes the customer's cart before that response. The previous failure path left the cart intact, and the new setting says the message lets the customer fix the issue; only clear the cart for the silent-redirect path.
This description says that all rejected orders are saved in the Spam folder, but handleBlockedOrder() stores them only when the separate data__wc_store_blocked_orders setting is enabled. When storage is off, the warning about duplicate saved orders is false and can mislead the administrator; make the statement conditional on that setting.
…cy mode.
The admin bar node always targeted the HPOS 'wc-orders' screen. On
legacy (non-HPOS) installations addLegacySpamOrdersMenuPage() registers
'apbct_wc_spam_orders' instead, so the link led to an unregistered
screen. Uses the same predicate as the settings action button.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…d confirmation page.
Block themes route the 'order-received' endpoint to the 'order-confirmation'
template built of the woocommerce/order-confirmation-* blocks. In that case
checkout/thankyou.php is never loaded, so woocommerce_after_template_part
never fired and the visitor saw a bare confirmation page with no details.
The markup building is extracted into getBlockedOrderOverviewHtml() and is
now reused by a render_block filter appending it to the status block, which
WooCommerce keeps rendering when no order stands behind the page. The classic
template path is left as it was.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
alexandergull
changed the title
Udp.Code.WooCommerce UI
Udp. Integration. Woocommerce. New spam oreders view and option to show message if spam rejected.
Sep 23, 2026
…s actions.
On HPOS installations the spam orders table is embedded into the WooCommerce
orders screen, where the HPOS page controller runs on the 'load-{page}' hook,
before the table is built. It inspects $_REQUEST['action'] and verifies it
against its own 'bulk-orders' nonce, so both the row delete link and the bulk
delete form were aborted with "The link you followed has expired". The same
controller also redirects to an URL stripped of '_wpnonce', dropping the nonce
of the row delete link.
Renaming the action and nonce parameters keeps our actions invisible to the
HPOS controller while leaving the legacy page untouched.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
alexandergull
changed the title
Udp. Integration. Woocommerce. New spam oreders view and option to show message if spam rejected.
Upd. Integration. Woocommerce. New spam oreders view and option to show message if spam rejected.
Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
https://app.doboard.com/1/task/54749