develop to main - #481
Closed
sridharkalaibala wants to merge 174 commits into
Closed
develop to main#481sridharkalaibala wants to merge 174 commits into
sridharkalaibala wants to merge 174 commits into
Conversation
Bumps the api-patch-and-minor group with 16 updates in the /api directory: | Package | From | To | | --- | --- | --- | | [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1111.0` | `3.1121.0` | | [axios](https://github.com/axios/axios) | `1.19.0` | `1.20.0` | | [html-to-text](https://github.com/html-to-text/node-html-to-text) | `10.0.0` | `10.0.1` | | [joi](https://github.com/hapijs/joi) | `18.2.3` | `18.2.5` | | [mongodb](https://github.com/mongodb/node-mongodb-native) | `7.5.0` | `7.6.0` | | [mongoose](https://github.com/Automattic/mongoose) | `9.9.2` | `9.9.4` | | [morgan](https://github.com/expressjs/morgan) | `1.11.0` | `1.12.0` | | [multer](https://github.com/expressjs/multer) | `2.2.0` | `2.3.0` | | [nodemailer](https://github.com/nodemailer/nodemailer) | `9.0.5` | `9.0.6` | | [pdfkit](https://github.com/foliojs/pdfkit) | `0.19.1` | `0.20.1` | | [unzipper](https://github.com/ZJONSSON/node-unzipper) | `0.10.14` | `0.12.5` | | [uuid](https://github.com/uuidjs/uuid) | `14.0.1` | `14.0.2` | | [@redocly/cli](https://github.com/Redocly/redocly-cli) | `2.46.1` | `2.49.0` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.2.0` | `26.4.0` | | [eslint](https://github.com/eslint/eslint) | `10.8.1` | `10.9.1` | | [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) | `30.4.2` | `30.5.0` | Updates `@aws-sdk/client-s3` from 3.1111.0 to 3.1121.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1121.0/clients/client-s3) Updates `axios` from 1.19.0 to 1.20.0 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.19.0...v1.20.0) Updates `html-to-text` from 10.0.0 to 10.0.1 - [Changelog](https://github.com/html-to-text/node-html-to-text/blob/master/CHANGELOG.md) - [Commits](html-to-text/node-html-to-text@10.0.0...10.0.1) Updates `joi` from 18.2.3 to 18.2.5 - [Commits](hapijs/joi@v18.2.3...v18.2.5) Updates `mongodb` from 7.5.0 to 7.6.0 - [Release notes](https://github.com/mongodb/node-mongodb-native/releases) - [Changelog](https://github.com/mongodb/node-mongodb-native/blob/main/HISTORY.md) - [Commits](mongodb/node-mongodb-native@v7.5.0...v7.6.0) Updates `mongoose` from 9.9.2 to 9.9.4 - [Release notes](https://github.com/Automattic/mongoose/releases) - [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md) - [Commits](Automattic/mongoose@9.9.2...9.9.4) Updates `morgan` from 1.11.0 to 1.12.0 - [Release notes](https://github.com/expressjs/morgan/releases) - [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md) - [Commits](expressjs/morgan@1.11.0...1.12.0) Updates `multer` from 2.2.0 to 2.3.0 - [Release notes](https://github.com/expressjs/multer/releases) - [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md) - [Commits](expressjs/multer@v2.2.0...v2.3.0) Updates `nodemailer` from 9.0.5 to 9.0.6 - [Release notes](https://github.com/nodemailer/nodemailer/releases) - [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md) - [Commits](nodemailer/nodemailer@v9.0.5...v9.0.6) Updates `pdfkit` from 0.19.1 to 0.20.1 - [Release notes](https://github.com/foliojs/pdfkit/releases) - [Changelog](https://github.com/foliojs/pdfkit/blob/master/CHANGELOG.md) - [Commits](foliojs/pdfkit@v0.19.1...v0.20.1) Updates `unzipper` from 0.10.14 to 0.12.5 - [Release notes](https://github.com/ZJONSSON/node-unzipper/releases) - [Commits](https://github.com/ZJONSSON/node-unzipper/commits) Updates `uuid` from 14.0.1 to 14.0.2 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v14.0.1...v14.0.2) Updates `@redocly/cli` from 2.46.1 to 2.49.0 - [Release notes](https://github.com/Redocly/redocly-cli/releases) - [Commits](https://github.com/Redocly/redocly-cli/compare/@redocly/cli@2.46.1...@redocly/cli@2.49.0) Updates `@types/node` from 26.2.0 to 26.4.0 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `eslint` from 10.8.1 to 10.9.1 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.8.1...v10.9.1) Updates `jest` from 30.4.2 to 30.5.0 - [Release notes](https://github.com/jestjs/jest/releases) - [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md) - [Commits](https://github.com/jestjs/jest/commits/v30.5.0/packages/jest) --- updated-dependencies: - dependency-name: "@aws-sdk/client-s3" dependency-version: 3.1121.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: axios dependency-version: 1.20.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: html-to-text dependency-version: 10.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api-patch-and-minor - dependency-name: joi dependency-version: 18.2.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api-patch-and-minor - dependency-name: mongodb dependency-version: 7.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: mongoose dependency-version: 9.9.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api-patch-and-minor - dependency-name: morgan dependency-version: 1.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: multer dependency-version: 2.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: nodemailer dependency-version: 9.0.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api-patch-and-minor - dependency-name: pdfkit dependency-version: 0.20.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: unzipper dependency-version: 0.12.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: uuid dependency-version: 14.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api-patch-and-minor - dependency-name: "@redocly/cli" dependency-version: 2.49.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: "@types/node" dependency-version: 26.4.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: eslint dependency-version: 10.9.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: jest dependency-version: 30.5.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: api-patch-and-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Ansari Ibrahim <ansarifahad.7577@gmail.com>
Same fault that stopped backups on the estate for 39 hours: files authored on Windows are committed 100644 because git's core.fileMode is false there, so a script looks executable locally and is not once anything checks it out. chmod +x on the server holds until the next deploy overwrites it. Nothing here is broken today, but the shapes are identical and two of them matter: scripts/sandbox/reset.sh is run by cron on the develop box, and scripts/install-server.sh is a script strangers are told to run as root. 34 files re-committed executable, plus the same test the Intranet now carries - it fails if any *.sh, or anything carrying a shebang, is committed without the bit. A test rather than a convention, because on the machine that matters the failure is silent.
…-minor-a5bd3e6f71
…-minor-a5bd3e6f71
### Changes & Verification - Documented the exact bundled MongoDB release and clarified package details as per #52. - Verified that the installer scripts (`download-mongodb.bat` and `download-mongodb.sh`) pin MongoDB to version `7.0.14`, matching the notice. - Restored the missing final newline at the end of `THIRD-PARTY-NOTICES.md`. Signed-off-by:Ansari Ibrahim<ansarifahad.7577@gmail.com>
Signed-off-by:Ansari Ibrahim<ansarifahad.7577@gmail.com>
Signed-off-by: ShravyaHegade <hegdeshrav22@gmail.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.7. - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.5...v3.1.7) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.7 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@xmldom/xmldom](https://github.com/xmldom/xmldom) from 0.8.13 to 0.8.15. - [Release notes](https://github.com/xmldom/xmldom/releases) - [Changelog](https://github.com/xmldom/xmldom/blob/master/CHANGELOG.md) - [Commits](xmldom/xmldom@0.8.13...0.8.15) --- updated-dependencies: - dependency-name: "@xmldom/xmldom" dependency-version: 0.8.15 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Two things, the second found on the way. A super_admin on a Cloud shop now gets "Posnic Account" beside My Profile, opening posnic.com/account in a new tab. My Profile is this person's profile inside this shop; this is the shop's account with us - the subscription, the bill, the other tills. Different things, so different words. Who sees it is decided by the SERVER, through a new features.account on /api/runtime-info, and the reason is a trap. resolveMode() answers 'desktop' before it looks at anything else, so a till PAIRED TO CLOUD - a paying customer, standing at their own counter - reports edition 'community'. A frontend test on edition would hide the link from precisely the people it exists for. So the flag is true for a provisioned tenant OR a paired till, and only the desktop shell can know the second: it reads posnic-cloud.json once at startup and sets POSNIC_SYNC_PAIRED, because /api/runtime-info is unauthenticated, is hit before login, and must stay cheap. False is the default and the safe answer. A community shop sent to an account page that greets it with "no account found" is worse off than one never offered the link. A white-labelled build always answers false: that shop was sold something with somebody else's name on it. The item ships with display:none and is revealed only when the server agrees AND the user is a super_admin - a cashier has no business seeing the bill. One bug worth naming, because it would have shipped dead: the page is served from /public, so a relative 'api/runtime-info' resolves to /public/api/runtime-info, 404s, lands in the catch, and hides the link forever without anybody noticing. It uses API_URL, and a test pins that. AND, unrelated: develop was red before any of this. guide-tour.test.js asserted that `_tourAfterSave = true;` be IMMEDIATELY followed by saveIntro(), and a later change inserted `_settingsAfterSave = false;` between them. Both pull requests were green alone and their merge was red - the behaviour never changed, only the spacing. The assertion now reads the whole click handler and checks what it means: the flag is raised, the save happens, and the flag comes first. Checked by removing the flag: three assertions fail.
runtime-info.test.js pinned features to {}, so adding the first flag read as a
regression. It now asserts what clients actually depend on: features is always
an object they can read unconditionally, and a bare environment grants nothing
- every flag defaults false.
Owner: "when invoice toggle on, suggest user to switch on quote also. its
useful. if he said yes then switch on that too."
A shop that prices work before doing it also bills for it afterwards. The quote
is the promise, the invoice is the claim, and the same customer sees both - but
somebody who finds one switch has usually not thought about the other, and
finds it months later or never.
The risk in a suggestion is that it turns into nagging, and nagging is never
reported: people just close it more angrily each time. Three rules keep it an
offer, and each is pinned by a test.
Only on the way ON. Switching Invoices off says nothing about Quotes, and
asking then is a question about something the person did not do.
Only when the other is off, or there is nothing to offer.
Only once per visit. "Not now" is an answer. Toggling a switch off and on
again must not reopen a question somebody already declined.
Saying yes goes through .trigger('change') rather than setting the property,
because the change handler is what marks the form dirty and repaints the card -
setting the box quietly would leave a switch that looks on and saves off.
Nothing is written here either way: the switch is feedback, Save is what saves,
which is the rule every other card on this page follows.
The two switches cannot ask each other in a loop, because the already-on guard
runs before the trigger. That ordering is the thing that terminates it, so a
test asserts the order rather than the behaviour.
Cancel gets its own handler: SweetAlert v6 REJECTS on cancel, and without one
"Not now" is an unhandled rejection on a screen where nothing went wrong - the
same trap confirmDemoOff documents a few lines below.
Owner: "branch default icon is very bad. make it very decent and professional." It was a black-and-white clipart storefront with the word STORE on the awning, 1000x993 - not square, so every place that sizes it to a box was stretching it slightly - and 83KB. The replacement is drawn to match the other defaults in the same folder rather than invented: the same 50-unit box, the same soft #e5e9fb disc, and the same indigo (#506ee4) that user.svg and category.svg already use. A shop that has not uploaded a logo should look like it belongs to the software. 512x512, square, 16KB. The SVG is committed beside the PNG as the source it was rendered from, so the next person to change it edits shapes rather than pixels. The PNG is what ships, and the NAME is why: 'store.png' is a sentinel, not just a file - branches.js reads `d.logo !== 'store.png'` to mean "no logo was uploaded", and every existing branch record stores that string. Renaming it would have meant a data migration for a picture.
Signed-off-by: atomnoid <aayushs2580@gmail.com>
Two problems, one of them the opposite of what it looked like.
The shop decided owner-versus-support by exact-matching a sentence:
claims.reason === 'owner sign-in from posnic.com'
web-api is a different repository that deploys on its own. Rewording that
sentence there would have silently reclassified every owner sign-in as support
and stopped recording any of them. Nothing would have failed; the console would
simply have started reporting that customers never open their shops. The actor
is now a signed claim, with the sentence kept as a fallback so tokens minted by
a web-api that has not deployed yet are still honoured.
Then the part that matters more. Signing up sends the owner straight into their
new shop, and that writes an activity row exactly like any other session. The
owner suspected these were NOT being recorded; they are, and that is the
problem. Counting them makes "has this customer opened their shop" answer yes
for everybody the instant they sign up, so the one number the business page
exists to show stops measuring their interest and starts measuring our redirect.
The row now carries source: 'signup' when we opened the shop on their behalf,
and nothing at all on an ordinary sign-in, which is the vast majority of rows
and needs no field. The value is bounded before it is written: a string
arriving from a token is still input, however signed.
Support sign-ins are still not logged as the shop being used, which was the
original rule and is unchanged.
The owner asked for a poster promoting the desktop till during a web
session, picked all three designs, and asked for one at random.
One of three is chosen per browser and recorded, because "all three are
good" is only answerable afterwards if we know what each shop saw. The
posters argue different things on purpose: the hardware a browser cannot
reach, selling through a dead line, and the plain three-reason case.
Most of this change is about where it must stay silent, and each of
those is a way of getting an in-product advertisement wrong that is
invisible from the file itself:
inside the desktop app the one audience guaranteed to be insulted
on the public demo the standing no-blocking-notifications rule
on a self-hosted server mode 'local' means the browser is a LAN client
of the shop's own server, and the desktop app
is a separate till with its own database. That
advice is how one shop's rows end up in
another's, which is the bug this week fixed.
over a live sale busy defers, it never cancels
Shown once per browser ever, marked done at render rather than at close
so navigating away mid-poster does not earn a second one, and skipped
entirely for anyone who already dismissed the card under the login form.
The tests drive the real module in jsdom and assert what a shopkeeper
would see. Reading the source would have passed happily while the
poster covered a customer being billed.
The owner's rule: "never use -- this. very annoying it shows is ai text.
overall account tell not to use that."
Eighty-seven lines across forty-one files, replaced with the plain hyphen
the codebase already uses everywhere else, so the house voice does not
change. A few read better rewritten than punctuated, and were: "Public
demo. Everything resets on the hour" rather than a dash in the middle.
Two things are deliberately left alone.
The lone dash between quotes or tags is not prose, it is the conventional
glyph for an empty cell:
'<td>' + esc(r.user_name || '—') + '</td>'
There are around thirty of those. Banning them too would mean thirty
pointless edits and a rule nobody keeps.
hsn.json and quotes.json are exempt because they are not our writing. The
first carries the government's published goods classification verbatim,
and rewriting its punctuation would put our tax codes out of step with
the schedule they have to match. The second carries famous sayings with
their standard attribution dash.
Pinned by a test, because this is a rule about how the product sounds and
those decay silently: the next dash will be written by somebody who never
read this commit. The test also checks its own detector, since every
other assertion in the file passes when the detector is broken.
The Hardware Manager asked for a Branch ID: a 24 character ObjectId, typed by hand, correctly, before a kitchen printer would work. It also polled the API every five seconds asking whether anything needed printing, and the answer was almost always no. Both are leftovers from when Hardware Manager was a separate application. Then it had no choice: a different process, possibly a different machine, so it had to ask repeatedly, and being an outsider it had to say whose tickets it wanted. It is not an outsider any more. server.js is require()d into the main process, so the code that saves a KOT sale and the code that prints it share memory and were talking to each other over HTTP on a timer. So the sale announces itself instead. Both paths emit: a new order and an amended table order, because a table adding a course needs a ticket as much as a new table does, and missing the second would mean half the orders never reach the kitchen. `process` carries the event on purpose. The API ships outside the ASAR archive while kot-manager.js lives inside it, so the two cannot rely on require() returning the same module instance - a shared constant would quietly become two constants and the event would go nowhere. Both halves already have `process`. Since nothing then enforces that the two string literals match, a test compares them; that failure is otherwise invisible, because tickets simply stop printing and nobody finds out until service. Nothing in the notifier can throw. The customer has already paid by the time a ticket prints, and a printer problem must not become a failed sale. Polling stays, at thirty seconds instead of five. It is no longer how a ticket normally arrives, but it is still what recovers one written while the app was starting, or one whose print failed. Losing an order is worse than printing it late. The branch is now looked up rather than demanded. It comes from the local database directly, because the branches route sits behind `protect` and that window has no session to present. One branch, which is nearly every shop, is chosen outright; several, and the screen offers names in a dropdown. The raw id box survives only for a till whose database is not up yet, and it is hidden whenever the list can be read. Events are debounced by 250ms: a table sending six courses fires six events, and each poll already fetches every pending ticket, so one pass prints them all rather than six passes racing for the same printer.
Two faults, each hiding the other. The table-ordering app finds the till by asking every address on the shop Wi-Fi whether it is a Posnic server. /api/runtime-info is the only endpoint that answers that honestly, and it - with /api/healthz and /api/readyz - is registered near the top of app.js on purpose, several hundred lines above the CORS middleware. Every one of the three answered a cross-origin caller with no Access-Control-Allow-Origin header, so the browser discarded the reply. Discovery fell back to "something replied on port 5555", which a printer's status page satisfies as readily as a till. The origin rules move to their own module and are mounted straight after helmet, above the endpoints that needed them. Preflights now short-circuit before the session middleware, which is both correct and cheaper. A packaged app shell's origin (http://localhost, capacitor://localhost) is allowed explicitly; "null" is not, because a sandboxed iframe sends it too. And kioskMobileLogin authenticated a user properly, then handed back no credential. Every screen past the branch list calls a route behind protectOrKioskKey, so the phone signed in and then loaded nothing. It now returns the same JWT the browser sign-in issues, for the same user, read back by optionalProtect from the Authorization header - nothing granted that signing in at the till would not grant. It also returns a shop key: a truncated hash of the tenant licence, identical on the till and in its synced cloud copy, so the app can tell that a server it found on the Wi-Fi holds the same shop before it moves itself onto it. The licence itself never leaves the server.
Packaging checks have been failing on every branch since new advisories were published. develop's own last green run was 8 September on the same commit these branches sit on, so nothing in the code changed - the advisory database did. Four of the seven were nodemailer, and they are the ones that mattered for a product that emails receipts and invoices: GHSA-wmmp-3585-3rmp IDN/Punycode allow-list bypass, delivery to an attacker-controlled domain GHSA-cc9r-2j5m-2m83 RFC 5322 comment mis-parsing, same outcome GHSA-8m3c-c648-2xjj resolveContent() bypasses disableFileAccess and disableUrlAccess on the legacy signature GHSA-2x7j-588g-ccc2 quadratic addressparser, remote denial of service The lockfile held 9.0.5 while package.json already asked for ^9.0.6, so it was behind its own declared range. 9.1.1 is inside that range and clears all four: a lockfile catching up, not a version bump. Two more were js-yaml (GHSA-2883-xcg3-v3hh), reached twice: through electron-updater in the desktop app and through puppeteer's cosmiconfig in the API. 4.3.2 fixes it and is one patch above what was installed, so an override in both manifests closes it without touching a major version. That leaves one that cannot be fixed: extract-zip GHSA-7pqw-9j4j-h8q3. 2.0.1 is still the latest published release, and the package is reached only as whatsapp-web.js -> puppeteer -> @puppeteer/browsers, which uses it to unpack a Chromium build fetched from Google over HTTPS. Triggering a symlink write means controlling that download, and an attacker who can do that has better options. CI never runs it at all - ci.yml sets PUPPETEER_SKIP_DOWNLOAD=1. It is accepted with that reasoning and an expiry of 2027-02-01, matching GHSA-jmr9-qjv8-65gv directly below it, which is the same flaw in the same package on the same path. Six fixed, one documented. Accepting all seven would have been quicker and would have left mail delivery to an attacker-controlled domain sitting behind a comment.
The kiosk sign-in endpoint returned 404 for everything: a wrong password,
a locked-out device, and a database that could not be reached. 404 means
there is no such endpoint, so the one thing a client could not work out
from the response was which of those had happened - and the confusion it
produces is exactly the one a handset hits when it has been pointed at the
wrong address in the first place.
It also echoed error.message straight out on the failure path, handing a
stranger the shape of an internal fault.
Now:
400 MISSING_CREDENTIALS an empty submission, refused before it costs a
database round trip and a bcrypt comparison
401 INVALID_CREDENTIALS failed authentication
429 TOO_MANY_ATTEMPTS with Retry-After, so the client knows how long
500 SERVER_ERROR our fault, and no internal detail
The success body is a bearer-token grant rather than the house PHP
envelope: tokenType, token, expiresIn, shopKey, user, branches. Its one
consumer is the table-ordering app, rewritten alongside this, so there is
nothing to keep compatible and no reason to carry a 2014 envelope onto a
surface being built today.
expiresIn comes from api/src/utils/token-lifetime.js, which the signers
also read. A client that has to guess its own expiry either refreshes far
more often than it needs to, or finds out it has expired in the middle of
taking an order. Its own dependency-free file so the number in the token
and the number the client is told cannot drift, and so it is testable
without installing the API.
languages/server/_english.json regenerated for the two new sentences
(node tests/tools/i18n-server-text.js --write).
The CI lint job runs prettier --check over api/src, and the rewrite did not match it. ESLint is clean: 0 errors.
The formatting check gates now that the tree is clean, and my one-line call was over the width. Prettier touched nothing else in the file.
Every test here proved the sale emits. None proved anything acts on it, so deleting the subscription in kot-manager.js would have left the suite green and the kitchen silent until the fallback poll came round - the exact failure this change exists to remove. The new test drives a real KOTManager, stubbing electron through the module loader since it is pulled in at require time. It fires six events, the way one table sending six courses does, and asserts one print pass rather than six racing for the same printer, and that the branch is taken from the sale rather than typed by the shopkeeper. Checked by breaking it: with the process.on line removed the test fails.
Let a phone find the shop's server, and give it something to present
Clear seven production advisories, six of them by fixing
Bumps [sharp](https://github.com/lovell/sharp) from 0.35.3 to 0.35.4. - [Release notes](https://github.com/lovell/sharp/releases) - [Commits](lovell/sharp@v0.35.3...v0.35.4) --- updated-dependencies: - dependency-name: sharp dependency-version: 0.35.4 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
Update translation for lang_Addexpensing : correct Tamil lang_Addexpe…
Bumps the desktop-patch-and-minor group with 3 updates in the / directory: [mongodb](https://github.com/mongodb/node-mongodb-native), [pdf-to-printer](https://github.com/artiebits/pdf-to-printer) and [sharp](https://github.com/lovell/sharp). Updates `mongodb` from 7.5.0 to 7.6.0 - [Release notes](https://github.com/mongodb/node-mongodb-native/releases) - [Changelog](https://github.com/mongodb/node-mongodb-native/blob/main/HISTORY.md) - [Commits](mongodb/node-mongodb-native@v7.5.0...v7.6.0) Updates `pdf-to-printer` from 5.8.0 to 5.8.1 - [Release notes](https://github.com/artiebits/pdf-to-printer/releases) - [Changelog](https://github.com/artiebits/pdf-to-printer/blob/master/CHANGELOG.md) - [Commits](artiebits/pdf-to-printer@v5.8.0...v5.8.1) Updates `sharp` from 0.35.3 to 0.35.4 - [Release notes](https://github.com/lovell/sharp/releases) - [Commits](lovell/sharp@v0.35.3...v0.35.4) --- updated-dependencies: - dependency-name: mongodb dependency-version: 7.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: desktop-patch-and-minor - dependency-name: pdf-to-printer dependency-version: 5.8.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: desktop-patch-and-minor - dependency-name: sharp dependency-version: 0.35.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: desktop-patch-and-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps the api-patch-and-minor group with 10 updates in the /api directory: | Package | From | To | | --- | --- | --- | | [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1121.0` | `3.1127.0` | | [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `8.6.2` | `8.7.0` | | [joi](https://github.com/hapijs/joi) | `18.2.5` | `18.2.8` | | [mongoose](https://github.com/Automattic/mongoose) | `9.9.4` | `9.9.5` | | [pdfkit](https://github.com/foliojs/pdfkit) | `0.20.1` | `0.20.2` | | [@redocly/cli](https://github.com/Redocly/redocly-cli) | `2.49.0` | `2.51.2` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.4.0` | `26.5.0` | | [eslint](https://github.com/eslint/eslint) | `10.9.1` | `10.10.0` | | [globals](https://github.com/sindresorhus/globals) | `17.11.0` | `17.12.0` | | [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) | `30.5.0` | `30.5.1` | Updates `@aws-sdk/client-s3` from 3.1121.0 to 3.1127.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1127.0/clients/client-s3) Updates `express-rate-limit` from 8.6.2 to 8.7.0 - [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases) - [Commits](express-rate-limit/express-rate-limit@v8.6.2...v8.7.0) Updates `joi` from 18.2.5 to 18.2.8 - [Commits](hapijs/joi@v18.2.5...v18.2.8) Updates `mongoose` from 9.9.4 to 9.9.5 - [Release notes](https://github.com/Automattic/mongoose/releases) - [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md) - [Commits](Automattic/mongoose@9.9.4...9.9.5) Updates `pdfkit` from 0.20.1 to 0.20.2 - [Release notes](https://github.com/foliojs/pdfkit/releases) - [Changelog](https://github.com/foliojs/pdfkit/blob/master/CHANGELOG.md) - [Commits](foliojs/pdfkit@v0.20.1...v0.20.2) Updates `@redocly/cli` from 2.49.0 to 2.51.2 - [Release notes](https://github.com/Redocly/redocly-cli/releases) - [Commits](https://github.com/Redocly/redocly-cli/compare/@redocly/cli@2.49.0...@redocly/cli@2.51.2) Updates `@types/node` from 26.4.0 to 26.5.0 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `eslint` from 10.9.1 to 10.10.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.9.1...v10.10.0) Updates `globals` from 17.11.0 to 17.12.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.11.0...v17.12.0) Updates `jest` from 30.5.0 to 30.5.1 - [Release notes](https://github.com/jestjs/jest/releases) - [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md) - [Commits](https://github.com/jestjs/jest/commits/v30.5.1/packages/jest) --- updated-dependencies: - dependency-name: "@aws-sdk/client-s3" dependency-version: 3.1127.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: "@redocly/cli" dependency-version: 2.51.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: "@types/node" dependency-version: 26.4.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: api-patch-and-minor - dependency-name: eslint dependency-version: 10.10.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: express-rate-limit dependency-version: 8.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: globals dependency-version: 17.12.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: api-patch-and-minor - dependency-name: jest dependency-version: 30.5.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: api-patch-and-minor - dependency-name: joi dependency-version: 18.2.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api-patch-and-minor - dependency-name: mongoose dependency-version: 9.9.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api-patch-and-minor - dependency-name: pdfkit dependency-version: 0.20.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: api-patch-and-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…atch-and-minor-23d65134bc Bump the desktop-patch-and-minor group across 1 directory with 3 updates
…atch-and-minor-684b88fb06 Bump the api-patch-and-minor group across 1 directory with 10 updates
Print kitchen tickets when the sale happens, not five seconds later
Bump sharp from 0.35.3 to 0.35.4
Bumps [lint-staged](https://github.com/lint-staged/lint-staged) from 16.4.0 to 17.5.0. - [Release notes](https://github.com/lint-staged/lint-staged/releases) - [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md) - [Commits](lint-staged/lint-staged@v16.4.0...v17.5.0) --- updated-dependencies: - dependency-name: lint-staged dependency-version: 17.4.1 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [nodemailer](https://github.com/nodemailer/nodemailer) from 9.1.1 to 10.0.1. - [Release notes](https://github.com/nodemailer/nodemailer/releases) - [Changelog](https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md) - [Commits](nodemailer/nodemailer@v9.1.1...v10.0.1) --- updated-dependencies: - dependency-name: nodemailer dependency-version: 10.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…ailer-10.0.0 Bump nodemailer from 9.1.1 to 10.0.1 in /api
…ed-17.4.1 Bump lint-staged from 16.4.0 to 17.5.0
|
|
||
| // In development, allow all origins | ||
| if (process.env.NODE_ENV !== 'production') { | ||
| res.header('Access-Control-Allow-Origin', origin || '*'); |
| if (process.env.NODE_ENV !== 'production') { | ||
| res.header('Access-Control-Allow-Origin', origin || '*'); | ||
| } else if (origin && isAllowedOrigin(origin, req)) { | ||
| res.header('Access-Control-Allow-Origin', origin); |
A restaurant wants two tickets to the pass and one to the kitchen, or a
counter roll and an A4 copy for the file. Neither screen could say so.
Receipt offered one printer and a paper size that applied to it alone.
KOT offered several printers, no copy count, and hardcoded 80mm for all
of them - so a kitchen on a 58mm roll was handed an 80mm page and left
to the driver to shrink.
The print layer already supported copies and seven paper sizes. Only the
screens were missing, which is why this is mostly wiring.
A target is now a printer plus its own settings, and both paths read the
same shape: { name, copies, pageSize }. Size has to be per printer
rather than global - once several can be selected, an 80mm roll and an
A4 sheet cannot share one setting, and choosing either ruins the other.
WHAT THIS FIXES BEYOND THE FEATURE.
A printer named POS-80C was rewritten to '' before printing, which sent
the job to the SYSTEM DEFAULT instead of the printer the shop chose. It
is the factory name on a great many generic 80mm printers, so a shop
that never renamed theirs was printing somewhere else with no way to
tell. An unreachable printer failing loudly is recoverable; printing
silently elsewhere is not.
silentPrint also carried an unreachable webContents.print block after a
return, left by an earlier refactor.
COMPATIBILITY, WHICH IS THE RISK HERE.
Every shape already sitting in a config file keeps working:
{ printerName, paperSize } from the receipt tab, { printerNames: [] }
from KOT, bare strings, and nothing at all - which resolves to one
unnamed target, the system default, because a shop that never configured
a printer must keep printing exactly as it did. Those are pinned by
tests harder than the new shape is, since they are what a till opens
with at seven in the morning after an overnight upgrade.
Saving also writes the two legacy keys, set to the first printer, so a
till still running the previous build does not stop printing the moment
this is saved.
The paper catalogue is sent to the screen over IPC rather than copied
into the HTML. Two lists drift, and the one that drifts is never the one
under test.
Details worth knowing: the drawer pulses once per sale rather than once
per copy; jobs go to a printer serially because two at once interleave on
one roll; copies are capped at 20, since a mistyped 300 empties the roll
mid-service; and column width follows the paper, because rendering 48
columns onto a 58mm roll pushes the total onto its own line and reads as
a rounding bug on paper.
Sizes offered: 44, 50, 57, 58, 76 (impact), 80, 100 and 112mm rolls,
A4, A5, A6, Letter and Legal.
The packaging check caught this, which is the whole reason it exists: src/printer-targets.js is a new module required by both print paths, and build.files is an explicit allowlist rather than a directory. Left out, the app installs cleanly and then throws "Cannot find module" the first time a customer prints - the failure landing on their counter rather than in CI.
Give every printer its own paper and its own copy count
…ently email.test.js mocks nodemailer away. That is right for testing our own logic, and it means the library is never loaded - so a breaking change in it cannot fail the build. Not hypothetical: Dependabot moved nodemailer 9.1.1 to 10.0.1, a major version, and CI went green without ever constructing a transport. I had to check compatibility by hand, outside the repo, to find out whether the bump was safe. Email carries invoices, receipts and password resets. A transport that stops constructing fails at the moment somebody is waiting for a reset link, so this drives the real Email.newTransport() through all three of its branches against the real library: the SendGrid preset a major version could drop, the shop SMTP path where the port arrives from env as a string a stricter validator would reject, and the development fallback, which is exercised end to end because jsonTransport serialises instead of connecting. Nothing is sent anywhere.
Formatting gates in this repo now that the tree is clean; the makeEmail call was over the width. Prettier touched nothing else.
Load the real nodemailer in one test, so a major bump cannot pass silently
Contributor
Author
|
Closing this stale develop-to-main release PR because its diff contains obsolete Posnic website metadata. The canonical correction is reviewed separately in #490, which changes root-domain website and discovery links to https://www.posnic.com/. A fresh release PR should be opened after #490 is merged into develop. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Acceptance criteria covered
How was it tested?
npm startfor the desktop app, ornpm run devfor a browser at http://localhost:3000)npm run build) if build/packaging was toucheddocs/CONTRIBUTOR_QUICKSTART.mdChecklist
git commit -s, DCO)