← Modules

Module

DivisionDesk Storefront

Online products, shopping carts, checkout, inventory, orders, fulfillment, and integrated payments.

About

Integrated commerce for DivisionDesk organizations. Manage products and categories, persistent shopping carts, inventory, membership-restricted products, checkout, shipping, merchant fees, orders, fulfillment, refunds, and payment processing through DivisionDesk Finance.

Features

  • Products and categories
  • Persistent shopping carts
  • Inventory management
  • Membership-restricted products
  • Online checkout
  • Shipping charges
  • Merchant convenience fees
  • Order and fulfillment management
  • Refund handling
  • DivisionDesk Finance integration

What's New in 2.6.0

View full package changelog
# Storefront 2.6.0 QA

- Added configurable shipping calculations: flat per order, per item, first + additional, first + second + additional, and free shipping.
- Existing free-shipping threshold and local pickup remain supported.
- Product shipping classes can override the default calculation using per-class rules.
- Existing installations remain on flat-per-order behavior by default.
- Stabilized Storefront catalog layout above and within the product grid to reduce /shop cumulative layout shift (CLS).

# Storefront v2.6.0

- Uses Core 4.6.56 responsive-image derivatives for product cards: cached proportional WebP variants at quality 50 with `srcset` and `sizes`.
- First visible product image is eager/high-priority for LCP; remaining product-card images use native lazy loading and async decoding.
- Added accessible labels for Storefront search and sort controls.
- Preserves master images, product URLs, catalog data, cart, checkout, Finance, Membership, and commerce behavior.

# Storefront v2.5.8

- Removed only the public shop hero section (`sf-hero`) from the Storefront shop renderer for mobile/LCP performance testing.
- Preserves the trust strip, category section, product controls/grid, cart, checkout, product pages, settings, and all commerce behavior.
- No schema, migration, database, entitlement, Finance, or Membership changes.

# Storefront v2.5.7

- Fixed Storefront administration on current Core by using `RoleManager::can()` / `RoleManager::requirePermission()` for runtime authorization.
- Retains a guarded compatibility fallback for older Core builds that exposed `Capability::can()` / `Capability::require()`.
- Finance remains the required commerce/payment authority, but Storefront administration and catalog management do not require a configured merchant account merely to load.

# Storefront v2.5.6

- Fixed Storefront refunds by using Finance 1.2.6's stable source-refund API.
- Full remaining Storefront refunds now also return the remaining Finance convenience fee to the payer.
- Full order refunds restore tracked inventory exactly once.
- Cart and checkout now disclose Subtotal, Shipping, Convenience Fee, and Total before payment; discount/tax rows appear when applicable.
- Checkout totals update when the shopper switches between Standard Shipping and Local Pickup.
- Storefront stores the verified Finance convenience-fee amount after payment for order/report visibility.

# Storefront 2.5.5

- Fixed Finance 1.2.x checkout contract: Storefront now supplies explicit `fund_id`, `account_id`, and allocation line IDs.
- Added Storefront Settings selectors for active Finance Fund and Store Sales Income Account via Finance's stable public integration API.
- Checkout now fails early with a Storefront-specific configuration message instead of Finance's generic missing-account error.
- No direct Finance-table access was added to Storefront.

# Changelog

## 2.5.4 — 2026-08-30
- Identifies and addresses the live "no changes taking effect" condition as stale addon OPcache bytecode.
- Adds a brand-new migration that executes before Update.php / Addon.php and force-invalidates every Storefront PHP file in OPcache.
- This directly compensates for Core 4.4.4's module installer replacing addon files without addon OPcache invalidation, while the Core updater already invalidates Core PHP files.
- Adds live runtime markers so the loaded Storefront code can be verified conclusively instead of inferred from the package version card.
- No Storefront 2.6.x bump; patch remains on the user-mandated 2.5.x line.


## 2.5.4 — 2026-08-30
- Full Storefront stabilization pass; no incremental test builds are being delivered between 2.4.0 and this package.
- Moves the critical Core registration path into a minimal `Registration` class loaded directly by root Addon.php.
- Registers Website → Content → Storefront, six public components, and six public pages before any optional integration can run.
- Public component renderer now points to the always-loaded Registration class, eliminating custom-autoloader dependency from Core page rendering.
- Optional setup, widgets, search, Finance event listener, Smart Actions, jobs, dashboard, help and capability refresh are isolated so they cannot make the module disappear.
- Adds explicit deterministic Runtime loading for the complete Storefront codebase.
- Reprovisions only Storefront-owned module pages in migration 120 before registration; Core `/store` remains untouched.
- Fixes Finance completion reconciliation request key on the public order page.
- Retains the approved navy/gold Storefront visual system and all catalog/cart/checkout/admin functionality.


## 2.5.4 — 2026-08-30
- Full Core 4.4.4 contract rebuild using the actual uploaded Core source, Developer Platform 1.1.1, Publishing 1.0.5, and Rosters 1.3.5.
- Corrects Storefront administration registration to the exact working Publishing pattern: moduleAdmin('main') plus Registry::admin() under Website / Content.
- Corrects module component registration to Core 4.4.4's actual Registry::component(string,array) contract with `renderer` = `Class::method`.
- Corrects public module-page keys to local keys (`shop`, `product`, etc.) and keeps fully-qualified component IDs.
- Corrects the Store parent navigation key to `storefront:storefront.shop`, matching Rosters' working nested-page contract.
- Moves stale Storefront system-page cleanup into a real Core ModuleMigration so it executes before Addon::register().
- Preserves Core's required `/store` page unconditionally.
- Corrects Update lifecycle method to `Update::update()`.
- Corrects Core CSRF and capability calls to `Csrf::verify()` and `Capability::can/require()`.
- Corrects admin handler, dashboard, widget, event-listener, search-provider, scheduler and setup-wizard signatures.
- Corrects Membership Manager integration to current Addons\Rosters\MemberSession / MemberRepository / DuesCalculator APIs.


## 2.5.4 — 2026-08-30
- Fixes `SQLSTATE[23000] UNIQUE constraint failed: pages.slug` during upgrades from rejected Storefront builds.
- Moves stale-page reconciliation before all new public module-page registration.
- Uses supported Core page cleanup APIs first when available.
- Adds schema-aware direct cleanup fallback that deletes only rows whose Storefront ownership can be proven.
- Reconciles canonical `/shop*` and historical `store-product` / `store-category` Storefront rows.
- Explicitly and permanently excludes Core `/store` from every cleanup path.
- Adds duplicate-slug, DB-fallback, unrelated-user-page, and Core `/store` preservation regression harnesses.


## 2.5.4 — 2026-08-30
- Aligns Storefront with the package-qualified Core component/page IDs documented by working Publishing 1.0.5.
- Keeps callable component registration and `/shop` public root.
- Explicitly preserves Core's required `/store`.
- Adds best-effort cleanup of obsolete Storefront-owned page IDs only through a Core-exposed page cleanup API.
- Reasserts Website / Content / Novice admin placement and module-admin dispatcher/search metadata.


## 2.5.4 — 2026-08-30
- Fixes live admin discovery/navigation and unavailable public component issues after 2.3.1 installed successfully.
- Uses Core ownership-local registration IDs instead of pre-qualified `storefront.*` IDs.
- Registers public module components as callables, matching the active Core component contract.
- Adds signature-aware compatibility for array-metadata and three-argument component registries.
- Moves the public storefront from `/store` to `/shop` because `/store` is reserved by Core for the package Store.
- Adds `page=main` to the standard module-admin dispatcher URL and supplies Website / Content navigation/search metadata.
- Changes Storefront-owned cart/checkout/order slugs to `/shop-cart`, `/shop-checkout`, and `/shop-order` to avoid generic Core/module route collisions.


## 2.5.4 — 2026-08-30
- Corrects the live Core 4.4.4 `Module page requires component.` install failure.
- Registers six Storefront module components before registering their six Core public module pages.
- Public page descriptors now use the required `component` field instead of incorrectly using `handler`.
- Adds an exact regression harness that rejects a page lacking `component` and rejects a page that references an unavailable component.
- Adds compatibility coverage for Core builds exposing the component registry as `component()` rather than `moduleComponent()`.
- Retains the 2.3.0 full commerce/security/migration fixes.


## 2.5.4 — 2026-08-30
- Full corrective audit after live Core 4.4.4 exposed the invalid Registry bulk capability call.
- Removed the nonexistent bulk capability-registration API and rebuilt the live regression harness without it.
- Fixed checkout RecoveryService namespace fatal, server-side repricing/revalidation, shipping-method/address enforcement, Finance handoff cart preservation, exact-once Finance completion, cumulative refunds, tracked-inventory handling, fail-closed auth/CSRF, manual-order inventory, cart maintenance, category cycles and input/URL validation.
- Added refunded-cents upgrade accounting and expanded the release gate to 39 PASS / 0 FAIL.
- Retains Core-owned Store/Category/Product/Cart/Checkout/Order pages, admin/search, Finance 1.2.3 boundary, membership restrictions, persistent carts, layouts and approved public visual structure.


## 2.3.0 — 2026-08-29
- Rebuilt Storefront registration around the current Core 4.4.4 ownership lifecycle.
- Root class is exactly `Addons\\Storefront\\Addon`; `Register.php` is passive and never eagerly registers.
- Uses current `App\\Core\\Registry::moduleAdmin()` with required title/handler/capability and `Registry::modulePage()` for Core-owned Store pages.
- Uses `App\\Core\\Database::connection()` and `App\\Core\\Url::to()` so subdirectory installations work correctly.
- Removed guessed universal/split registry discovery, direct package API routing, and direct package asset URL assumptions.
- Added MySQL/SQLite-aware schema self-healing for fresh installs and upgrades while retaining Storefront data.
- Retains categories, variants, images, product layouts, member restrictions/member pricing, persistent carts, Save for Later, coupons, Finance checkout, merchant fee policy, order fulfillment/tracking/refunds, digital downloads, promotions, reports, receipts and fulfillment notifications.
- Fixed persistent-cart token reuse, variant inventory/price enforcement, and cross-engine inventory decrement SQL.
- Added current-Core lifecycle/registration regression testing and subdirectory URL assertions.
- All prior 2.1.x artifacts are rejected test builds and should not be promoted.

Release History

2.6.0 development published
2026-09-24T20:11:42+00:00
2.5.9 development published
2026-09-16T03:17:23+00:00
2.5.8 development published
2026-09-16T02:48:44+00:00
2.5.7 development published
2026-09-13T14:14:17+00:00
2.5.6 development published
2026-09-13T06:32:16+00:00