Skip to content

fix: require the policy consent on the block checkout - #16

Open
YvesCesar wants to merge 2 commits into
refactor/decisions-in-srcfrom
fix/block-checkout-terms
Open

YvesCesar wants to merge 2 commits into
refactor/decisions-in-srcfrom
fix/block-checkout-terms

Conversation

@YvesCesar

@YvesCesar YvesCesar commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

The store checkout is the WooCommerce checkout block, and nothing on it asked for the policy consent. inc/checkout.php hooked into woocommerce_get_terms_and_conditions_checkbox_text and woocommerce_after_checkout_validation, which only the classic shortcode checkout runs: the checkout block places the order through the Store API, which calls neither. The terms block on the checkout page has no checkbox, and its text ("By proceeding with your purchase you agree to our Terms and Conditions and Privacy Policy") had no links, since the store has no terms page and the WordPress privacy page is unpublished.

Changes

  • Consent checkbox: a required additional checkout field, libresign/policy-consent, of type checkbox in the order section: "I agree to the terms and privacy policy before placing the order." WooCommerce validates required additional fields on the server, in the Store API, and saves the value on the order, so the consent is recorded like the workspace terms consent.
  • Policy link: the terms block reads its text from a data-text attribute; the theme sets it to "Read the terms and privacy policy.", linking to https://libresign.coop/privacy-policy, the same page as the footer and the workspace form.
  • Classic checkout path: WooCommerce still answers ?wc-ajax=checkout, which runs WC_Checkout::process_checkout() and does not validate the block fields. No page of the store prints its nonce, but the Stripe express checkout (Apple Pay, Google Pay) does when it is enabled, and places its orders through that path. The theme keeps refusing an order there without terms, as it did before. Only the classic terms checkbox text filter is removed, since there is no classic checkout form to show it.

Verification

On the local SaaS stack, with a plan in the cart:

  • The checkout shows the consent checkbox under "Additional order information" and the linked policy text above the place order button.
  • A Store API checkout without the consent, with it set to false, or with additional_fields empty is refused (rest_missing_callback_param / rest_invalid_param). With the consent, the request passes validation and reaches the payment step.
  • composer ci passes.

Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant