Skip to content

Upd. Integration. Woocommerce. New spam oreders view and option to show message if spam rejected. - #867

Merged
alexandergull merged 30 commits into
devfrom
woo-commerce-update.ab-2
Sep 25, 2026
Merged

alexandergull merged 30 commits into
devfrom
woo-commerce-update.ab-2

Conversation

@alexander-b-clean

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the WooCommerce spam-orders experience by integrating the plugin’s “blocked orders” table into the native WooCommerce Orders admin screen (HPOS), aligning columns/styles with WooCommerce UI, and adjusting checkout handling to support storing/redirecting blocked checkouts.

Changes:

  • Reworks the spam orders list table UI (new columns, totals, status views integration, pagination/sorting tweaks).
  • Hooks into the WooCommerce HPOS orders screen to add “Spam”/“On hold” status links and to replace the renderer when viewing Spam.
  • Adds a helper for counting stored spam orders and updates admin/settings links to point at the WooCommerce orders screen spam view.

Reviewed changes

Copilot reviewed 7 out of 8 changed files in this pull request and generated 5 comments.

Show a summary per file
File Description
lib/Cleantalk/ApbctWP/WcSpamOrdersListTable.php Refactors table UI/columns, adds views/status/total calculation, updates delete URL building, and introduces page notices rendering.
lib/Cleantalk/ApbctWP/WcSpamOrdersFunctions.php Adds a DB-count helper for stored blocked orders.
lib/Cleantalk/ApbctWP/State.php Changes the default for storing blocked orders.
lib/Cleantalk/Antispam/IntegrationsByClass/Woocommerce.php Integrates spam orders into HPOS orders screen; adjusts blocked-checkout behavior and adds view/link logic.
inc/cleantalk-settings.php Updates settings-page action link target to the WooCommerce orders spam status view.
inc/cleantalk-admin.php Updates admin bar link target to the WooCommerce orders spam status view.
css/src/cleantalk-admin.css Adds styling to make the spam orders table match WooCommerce orders list UI.
css/cleantalk-admin.min.css Minified CSS update reflecting the new admin styling.
Files not reviewed (1)
  • css/cleantalk-admin.min.css: Generated file
Suppressed comments (1)

lib/Cleantalk/Antispam/IntegrationsByClass/Woocommerce.php:239

  • Same issue as the AJAX checkout path: returning early here skips the spam check for Store API checkouts when data__wc_store_blocked_orders is off, even though the setting is documented as “store blocked orders” (not “disable protection”).
        if ( ! $apbct->settings['data__wc_store_blocked_orders'] ) {
            // The checkout is left to WooCommerce as is: no check, no blocked order to store.
            return;
        }

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread lib/Cleantalk/ApbctWP/WcSpamOrdersListTable.php Outdated
Comment thread lib/Cleantalk/Antispam/IntegrationsByClass/Woocommerce.php Outdated
Comment thread lib/Cleantalk/Antispam/IntegrationsByClass/Woocommerce.php Outdated
Comment thread lib/Cleantalk/ApbctWP/WcSpamOrdersListTable.php
Comment thread lib/Cleantalk/ApbctWP/State.php
datorik and others added 5 commits August 24, 2026 13:46
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@codecov

codecov Bot commented Aug 24, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 41.64524% with 227 lines in your changes missing coverage. Please review.
✅ Project coverage is 32.03%. Comparing base (096bee4) to head (735d3a0).

Files with missing lines Patch % Lines
lib/Cleantalk/ApbctWP/WcSpamOrdersListTable.php 28.33% 129 Missing ⚠️
...ntalk/Antispam/IntegrationsByClass/Woocommerce.php 52.15% 89 Missing ⚠️
inc/cleantalk-admin.php 0.00% 4 Missing ⚠️
inc/cleantalk-settings.php 60.00% 4 Missing ⚠️
lib/Cleantalk/ApbctWP/WcSpamOrdersFunctions.php 80.00% 1 Missing ⚠️

❌ Your patch check has failed because the patch coverage (41.64%) is below the target coverage (70.00%). You can increase the patch coverage or adjust the target coverage.

Additional details and impacted files
@@             Coverage Diff              @@
##                dev     #867      +/-   ##
============================================
+ Coverage     30.62%   32.03%   +1.40%     
- Complexity     6651     6781     +130     
============================================
  Files           292      292              
  Lines         26507    26775     +268     
============================================
+ Hits           8119     8578     +459     
+ Misses        18388    18197     -191     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@AntonV1211
AntonV1211 requested review from alexandergull and removed request for AntonV1211 August 24, 2026 12:42
datorik and others added 5 commits September 8, 2026 23:45
# Conflicts:
#	lib/Cleantalk/Antispam/IntegrationsByClass/Woocommerce.php
#	lib/Cleantalk/ApbctWP/State.php
#	lib/Cleantalk/ApbctWP/Variables/AltSessions.php

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread lib/Cleantalk/Antispam/IntegrationsByClass/Woocommerce.php
Comment thread lib/Cleantalk/Antispam/IntegrationsByClass/Woocommerce.php Outdated
Comment thread lib/Cleantalk/Antispam/IntegrationsByClass/Woocommerce.php
Comment thread lib/Cleantalk/ApbctWP/WcSpamOrdersListTable.php
Comment thread lib/Cleantalk/ApbctWP/WcSpamOrdersListTable.php
alexandergull and others added 6 commits September 22, 2026 22:58
…ocked order overview.

WooCommerce renders checkout/thankyou.php for the no-order confirmation page,
not checkout/order-received.php. The overview was never shown because of this
mismatch.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…m orders.

addOrdersListStatusViews() only integrates the 'Spam' view into the native
orders screen when wc_get_page_screen_id() reports the HPOS screen. Legacy
(posts table) installations render orders on the shared post-type screen
instead, so the option was lost when the old admin_menu submenu page was
removed. A conditional fallback page is registered again for that case,
reusing the existing renderSpamOrdersPage() renderer.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…al'.

calcOrderTotal() only sums the stored cart line items and their tax - shipping,
fees and other checkout charges are not persisted for a blocked order, so the
value was understated relative to a real order total. The label now reflects
what is actually shown; the underlying calculation is unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…) when a Closure is hooked to the orders page.

isset($callback['function'][0]) throws 'Cannot use object of type Closure
as array' when another plugin/theme hooks a Closure to the same orders page
hook, since Closure does not implement ArrayAccess. An is_array() guard is
added before the offset access.

Also adds unit tests for the admin/list-table hooks of the WooCommerce
integration: addOrdersListStatusViews, addOrdersListStatusLinks,
getOrdersListViews, keepOrdersListWhenSpamOrdersExist,
replaceOrdersListRenderer, addOrdersSpamStatus*, addSpamActionToBulk*
and renderSpamOrdersPage.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved critical and moderate findings affect checkout responses, WooCommerce routing, migrations, permissions, and test reliability.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 3 High severity · 4 Medium severity

Open (7)
Resolved since last review (5)
Files not reviewed (1)
  • css/cleantalk-admin.min.css: Generated file

Comment thread lib/Cleantalk/Antispam/IntegrationsByClass/Woocommerce.php Outdated
Comment thread tests/Antispam/IntegrationsByClass/TestWoocommerceSimpleGetters.php
Comment thread inc/cleantalk-admin.php Outdated
Comment thread inc/cleantalk-settings.php Outdated
Comment thread lib/Cleantalk/Antispam/IntegrationsByClass/Woocommerce.php Outdated
Comment thread lib/Cleantalk/Antispam/IntegrationsByClass/Woocommerce.php Outdated
alexandergull and others added 4 commits September 22, 2026 23:38
…ng the blocked order.

getStoreApiPassedResponse($order) was called after $order->delete(true),
which clears the in-memory order ID and data. The Store API client could
then receive order_id 0 and empty fields instead of a valid response.
The response is now captured right after handleBlockedOrder() and before
any cleanup, then emitted afterwards.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…t admin page on legacy installs.

The link always targeted the HPOS 'wc-orders' screen. On legacy
(non-HPOS) installations addLegacySpamOrdersMenuPage() registers
'apbct_wc_spam_orders' instead, so the link led to an unregistered
screen and left stored spam orders unreachable from Settings.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
addOrdersListStatusViews() registered the 'Spam' view/status links for
any user who could open the orders screen, without a capability check.
The row action buttons and the restore/details AJAX handlers already
required manage_options, so a Shop Manager (without manage_options)
could see the view but got a 403 trying to use it.

Now the view registration, the legacy admin menu page and the row
action handler all consistently require manage_options.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…ers page.

renderSpamOrdersPage() always built getOrdersListViews(), which links
to 'page=wc-orders' (HPOS only). It's also the callback for the legacy
'apbct_wc_spam_orders' fallback page (addLegacySpamOrdersMenuPage()),
so on non-HPOS installations the embedded views pointed at the wrong
screen. Now null is passed on legacy installs, so the list table
builds its own standalone (legacy-correct) views instead.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved WooCommerce routing, checkout, migration, and test issues must be addressed before approval.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity · 3 Medium severity

Open (4)
Resolved since last review (7)
Files not reviewed (1)
  • css/cleantalk-admin.min.css: Generated file
Previously missed (2)

In code that hasn't changed since last review

Medium severity Unconditionally emptying cart breaks rejection-message checkout flow

lib/​Cleantalk/​Antispam/​IntegrationsByClass/​Woocommerce.php:408

When the migrated forms__wc_show_rejection_message option is enabled, classic checkout returns the legacy failure response, but this unconditional empty_cart() removes the customer's cart before that response. The previous failure path left the cart intact, and the new setting says the message lets the customer fix the issue; only clear the cart for the silent-redirect path.

Low severity Rejection description ignores disabled blocked-order storage

inc/​cleantalk-settings.php:378

This description says that all rejected orders are saved in the Spam folder, but handleBlockedOrder() stores them only when the separate data__wc_store_blocked_orders setting is enabled. When storage is off, the warning about duplicate saved orders is false and can mislead the administrator; make the statement conditional on that setting.

Comment thread lib/Cleantalk/Antispam/IntegrationsByClass/Woocommerce.php
Comment thread inc/cleantalk-settings.php
Comment thread lib/Cleantalk/Antispam/IntegrationsByClass/Woocommerce.php
Comment thread lib/Cleantalk/Antispam/IntegrationsByClass/Woocommerce.php
alexandergull and others added 2 commits September 23, 2026 11:01
…cy mode.

The admin bar node always targeted the HPOS 'wc-orders' screen. On
legacy (non-HPOS) installations addLegacySpamOrdersMenuPage() registers
'apbct_wc_spam_orders' instead, so the link led to an unregistered
screen. Uses the same predicate as the settings action button.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…d confirmation page.

Block themes route the 'order-received' endpoint to the 'order-confirmation'
template built of the woocommerce/order-confirmation-* blocks. In that case
checkout/thankyou.php is never loaded, so woocommerce_after_template_part
never fired and the visitor saw a bare confirmation page with no details.

The markup building is extracted into getBlockedOrderOverviewHtml() and is
now reused by a render_block filter appending it to the status block, which
WooCommerce keeps rendering when no order stands behind the page. The classic
template path is left as it was.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@alexandergull alexandergull changed the title Udp.Code.WooCommerce UI Udp. Integration. Woocommerce. New spam oreders view and option to show message if spam rejected. Sep 23, 2026
…s actions.

On HPOS installations the spam orders table is embedded into the WooCommerce
orders screen, where the HPOS page controller runs on the 'load-{page}' hook,
before the table is built. It inspects $_REQUEST['action'] and verifies it
against its own 'bulk-orders' nonce, so both the row delete link and the bulk
delete form were aborted with "The link you followed has expired". The same
controller also redirects to an URL stripped of '_wpnonce', dropping the nonce
of the row delete link.

Renaming the action and nonce parameters keeps our actions invisible to the
HPOS controller while leaving the legacy page untouched.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@alexandergull
alexandergull merged commit b6945e5 into dev Sep 25, 2026
7 of 8 checks passed
@alexandergull
alexandergull deleted the woo-commerce-update.ab-2 branch September 25, 2026 09:51
@alexandergull alexandergull changed the title Udp. Integration. Woocommerce. New spam oreders view and option to show message if spam rejected. Upd. Integration. Woocommerce. New spam oreders view and option to show message if spam rejected. Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants