# Changelog

## 1.0.17 - 2026-10-05

- Fixed the mandatory popup reopening after a successful area selection by removing authentication ownership and Storefront-resolution timing from the browser-confirmation decision.
- Added a dedicated host-scoped **browser-session cookie** that stores only the selected area ID with expiry `0`. It is validated against the active/selectable service-area table on every read, so a forged or stale value cannot select an invalid area.
- The browser-session marker is now the stable source of truth across the selector POST and redirected GET. Native CS-Cart session state and the historical `fn_set_session_data()` mirrors are synchronized from it instead of being allowed to invalidate it.
- The selected browser area now remains valid whether the same visitor is a guest or logged in, matching the requested browser-session behavior. The existing per-customer remembered preference is still updated when enabled, but it is no longer required for popup persistence.
- Added migration behavior for already-confirmed 1.0.16 sessions: a valid confirmed server-session selection is promoted to the new browser-session marker.
- Clearing browser/session cookies removes the marker and restores the mandatory popup. Changing the area replaces the marker with the newly selected valid area.
- Preserved Full Page Cache bypass, catalog/vendor filtering, product-detail SQL fix, cart/checkout revalidation, floating icon behavior, area hierarchy, vendor assignments, and database schema.

## 1.0.16 - 2026-10-05

- Fixed the mandatory storefront popup reopening immediately after a successful area selection when the selector POST and redirected GET resolved different Storefront/host session aliases.
- Added one coherent active browser-session record containing `area_id`, owner, confirmation state, Storefront ID, normalized host, and change timestamp; this record is now authoritative while the historical per-alias keys remain only as backward-compatible migration fallbacks.
- Normalized storefront hosts consistently (case, port, trailing dot, and `www.` prefix) so canonical-host redirects do not split one browser session into two VSA contexts.
- Added a CS-Cart settings-session JSON mirror for the coherent state so it can be restored if the nested native-session structure is unavailable while the same CS-Cart session is still alive.
- Prevented stale legacy selection/confirmation aliases from overriding a newer coherent selection after redirect.
- When CS-Cart Full Page Cache / Performance Booster is enabled, a confirmed area now sets the standard session-scoped `disable_cache=Y` bypass cookie. This prevents a guest with a geographic session from receiving cached popup/catalog HTML belonging to the unselected/shared state.
- Preserved the mandatory-popup behavior after genuine browser/session data loss, per-customer remembered preference, account isolation, floating icon, area hierarchy, vendor assignments, catalog filtering, cart/checkout rules, and database schema.

## 1.0.15 - 2026-10-05

- Fixed a storefront product-detail SQL failure (`Unknown column 'products.company_id'`) by using the native `?:products` table reference for the `get_product_data` hook, where CS-Cart does not alias the base products table as `products`.
- Resolved the `?:products` placeholder before injecting the condition as raw SQL, preserving compatibility with custom database table prefixes.
- Fixed the latent master-products subquery table placeholder in the same condition builder by resolving the products table name before composition.
- Guarded `VSA_SESSION_KEY` in `config.php` to prevent duplicate-constant warnings when CS-Cart loads the add-on config/init paths more than once in the same request.

## 1.0.14 - 2026-10-05
- Replaced the storefront side drawer with a centered popup while preserving the existing floating map-pin icon, icon style setting, icon size setting, LTR/RTL edge placement, and `index:body.post` zero-layout-footprint render point.
- Added a dedicated per-browser-session confirmation marker, separate from the remembered `?:vsa_customer_areas` preference. A remembered logged-in preference may preselect the popup, but cannot suppress the mandatory prompt after browser/session data is cleared.
- When no valid area has been confirmed for the current guest/account session, the popup opens automatically and cannot be dismissed by the close control, backdrop, or Escape key.
- Removed **All areas** from the storefront selector and reject `area_id=0` in `vendor_service_areas.select`, preventing the mandatory selector from being bypassed.
- After a valid selection, the existing floating icon opens the same popup in optional-change mode; it can then be dismissed normally without changing the saved area.
- Kept the native PHP-session authority, Storefront/host aliases, legacy `fn_set_session_data()` mirrors, per-user remembered preference, account isolation, catalog scope, cart/checkout rules, backend area management, vendor mappings, and database schema intact.

## 1.0.13
- Fixed storefront area selection for authenticated administrator/vendor sessions: geographic context now depends on `AREA=C`, not `auth.user_type`.
- Removed the inconsistency where the floating selector was visible to these logged-in storefront sessions but the resolver/filtering layer silently skipped them.
- Backend (`AREA=A`) remains fully excluded from customer geographic filtering.

## 1.0.12 - 2026-10-03
- Fixed the authenticated selector fallback to **All areas** by removing a stale-session-alias precedence bug found during full code-path review.
- Native session state may contain both `host:<domain>` and `storefront:<id>` aliases for the same storefront. Earlier releases returned the first matching alias; a stale `storefront:<id>` value of `0` could therefore override a newer host-based selection after redirect.
- Session reads now evaluate every matching alias and select the newest entry. Legacy same-second conflicts prefer the host alias because it is stable across selector POST and redirected GET requests.
- Session writes now carry microsecond-resolution `changed_at` metadata and update the Storefront ID supplied by the selector form as an explicit alias when the numeric Storefront context is not yet available during POST.
- Legacy `fn_set_session_data()` mirrors are also written under the hinted Storefront ID for backward compatibility.
- Selection persistence is written before session aliases are synchronized, so the remembered customer preference and immediate request/session state cannot diverge.
- Added regression tests that reproduce the exact stale-alias scenario and verify both newest-alias resolution and hinted-Storefront writes.
- No database schema, area hierarchy/scope, vendor mappings, catalog filtering, cart/checkout, multilingual data, backend UI, drawer UI, or icon settings changed.

## 1.0.11 - 2026-10-03
- Fixed authenticated customer area selection still falling back to **All areas** after redirect.
- Reworked only the customer-selection persistence layer: the selected area is now stored in the native CS-Cart PHP session as the authoritative request/session state, while the legacy `fn_set_session_data()` keys remain mirrored for backward compatibility.
- Added stable per-storefront session aliases using both resolved Storefront ID and current host, preventing a selector POST and its redirected GET from reading different keys when Storefront context is initialized at different moments.
- Hardened Storefront ID resolution: resolved Storefront object first, `runtime.storefront_id` second, and Storefront repository lookup by current host as a final fallback.
- Added a hidden Storefront ID hint to the existing selector form; it is used for customer preference persistence only if the server cannot resolve a Storefront ID during the POST request.
- Preserved account isolation: guest choices can still be adopted on login, another account's session choice is discarded, and **All areas** remains an explicit logged-in selection.
- No database schema, area hierarchy/scope, vendor mappings, catalog filtering, cart/checkout, multilingual data, backend UI, drawer UI, or icon settings changed.

## 1.0.10 - 2026-10-03
- Fixed logged-in customer area selection reverting to **All areas** after submit.
- Kept the 1.0.9 late storefront view refresh for selector visibility, but made it presentation-only: `dispatch_before_display` now reads the geographic area already resolved/staged in runtime instead of invoking the customer-area resolver a second time.
- Preserved the single source of truth for selection state: `before_dispatch` resolves persisted/session state; `vendor_service_areas.select` may change it during the request; final display only renders that resulting runtime state.
- No database schema, area hierarchy/scope, vendor mappings, All areas behavior, catalog filtering, cart/checkout, multilingual data, backend UI, drawer UI, or icon settings changed.

## 1.0.9 - 2026-10-03
- Fixed storefront selector visibility after customer authentication. Selector presentation data is now refreshed on the native `dispatch_before_display` hook, after authentication and controller processing are fully resolved.
- Kept geographic runtime initialization in `before_dispatch`, so product/vendor filtering continues to occur before catalog SQL is built.
- Separated selector presentation from the customer-filter eligibility check: the floating selector can be rendered on storefront requests without altering the existing admin/vendor catalog-bypass semantics.
- Hardened the selector setting fallback so only an explicit `N` disables the floating selector; a missing inherited storefront/company value no longer hides it for an authenticated customer.
- No database schema, area hierarchy, vendor mappings, customer saved selections, catalog-scope rules, cart/checkout behavior, multilingual data, backend UI, icon editor, or drawer interaction changed.

## 1.0.8 - 2026-10-03
- Changed no-selection storefront behavior: when a guest or customer has no selected service area, geographic filtering is disabled and the full catalog/vendor set is shown.
- Added an **All areas** option to the storefront drawer. Selecting it clears the current session selection and any persisted per-storefront selection for a logged-in customer.
- Preserved the existing parent-inheritance rule and extended it symmetrically: selecting a parent area now includes vendors/products assigned to every active descendant below it as well as assignments on the selected area and its active ancestors.
- Updated direct product/vendor integrity checks, native catalog SQL, vendor lists, Common Products handling, cart revalidation, and block-cache context to use the same new scope semantics.
- No database schema, area IDs, vendor mappings, multilingual descriptions, backend vendor editor, icon UI, or side-drawer interaction structure changed.

## 1.0.7 - 2026-10-03
- The storefront service-area drawer now always starts closed on initial page load, including when area selection is required and no area has been selected yet. The required-area catalog restriction remains unchanged; customers open the drawer explicitly from the floating map-pin icon.
- Removed **Vendor area assignments** from the backend side navigation.
- Removed the standalone Vendor area assignments shortcut from the Service Areas page; vendor-area selection is managed through the existing **Service Areas** tab inside each vendor's native edit page.
- Kept the legacy standalone assignment controller/view in the package for backward-compatible direct requests, but it is no longer exposed in normal administration navigation.
- No database schema, vendor mappings, catalog filtering, cart/checkout, multilingual, cache, or icon-editor behavior changed.

## 1.0.6 - 2026-10-03
- Removed the floating selector markup from the `index:content` flow entirely. The legacy `content.pre.tpl` hook is now intentionally empty and the selector renders from `index:body.post`, so it cannot reserve an empty top-bar/content row.
- Added a zero-footprint fixed root container as an additional safeguard against theme/layout spacing.
- Added a new add-on settings section **Icon editor** / **تحرير الأيقونة**.
- Added three black SVG map-pin styles: Filled pin, Outline pin, and Outline pin with center dot.
- Added configurable icon size in pixels, validated to 18–40 px with a safe 28 px fallback.
- Preserved all service-area data, vendor mappings, filtering, cart/checkout, multilingual, cache, and persistence behavior; no database schema changed.

## 1.0.5 - 2026-10-03
- Replaced the storefront top service-area bar with a floating black SVG map-pin selector.
- Positioned the selector on the logical start edge: left for LTR storefronts and right for RTL storefronts.
- Added a same-edge sliding side drawer for the existing area-selection form, with overlay, close control, Escape-key support, keyboard interaction, and reduced-motion handling.
- The floating pin moves with the drawer edge while open, creating a connected open/close interaction.
- Preserved automatic guidance when an area is required: if no area is selected, the drawer starts open.
- Kept the existing `show_selector_bar` setting ID for upgrade compatibility while changing its visible label to "Show the floating service-area selector".
- No database schema, vendor-area mapping, geographic filtering, multilingual data, cart, checkout, cache, or persistence behavior was changed.

## 1.0.4 - 2026-10-03
- Fixed backend menu highlighting so editing a service area keeps **Service Areas** active instead of **Vendor area assignments**.
- Added a native **Service Areas** tab to the standard vendor edit page (`companies.update`) for marketplace administrators.
- Added the same vendor-area editor to a vendor administrator's own vendor edit page, with ownership checks that prevent editing another vendor's assignments.
- Persisted vendor-area changes through the native `update_company_pre` / `update_company` hooks, while stripping add-on-only fields before the core company database update. No core table or core file is modified.
- Normalized the standalone Vendor area assignments form to submit area IDs directly.
- Centralized vendor-area reads and vendor counters on the same `?:vsa_vendor_areas` mapping table, fixing the Service Areas vendor count after assignments are saved.
- Standalone vendor assignments now verify persisted IDs before showing a success notification, preventing false-positive saves.
- No database-schema, storefront filtering, multilingual-area, cart, checkout, cache, or catalog behavior was changed.

## 1.0.3 - 2026-10-03
- Added the native CS-Cart content-language selector to service-area edit pages.
- Service-area names now load and save strictly in the selected `DESCR_SL` language.
- Preserved the selected content language across saves, edit/list links, delete redirects, and vendor-assignment pages.
- New areas now remain on the edit page after the first save so translations can be entered immediately; the language selector appears once the area has an ID, matching native CS-Cart entity behavior.
- Added content-language selectors to the service-area list and vendor-assignment pages so translated area names can be reviewed without changing the backend UI language.

## 1.0.2 - 2026-10-03
- Rebuilt both PO headers to match the exact CS-Cart Scheme 3.0 header form (`msgstr "Project-Id-Version: tygh"`).
- Added explicit locale metadata (`en_US` / `ar_EG`) instead of a bare Arabic language code.
- Removed generic gettext-only header fields that CS-Cart does not emit in its documented add-on PO example.
- Added a non-destructive Arabic PO hotfix artifact for already-installed stores.

## 1.0.1 - 2026-10-03
- Fixed CS-Cart PO parser compatibility for English and Arabic translation headers.
- Translation headers now use canonical multiline gettext structure used by CS-Cart language packs.

## 1.0.0 — 2026-10-03

- Initial production release.
- Added hierarchical service areas and multilingual descriptions.
- Added vendor-to-area assignments.
- Added storefront area selector for guests and registered customers.
- Added per-storefront persisted customer area.
- Added server-side catalog and vendor scoping.
- Added direct product/vendor protection.
- Added cart and checkout revalidation.
- Added native block-cache area context and HTTP cache variation.
- Added Common Products for Vendors support.
- Added Searchanise conflict for fail-closed geographic visibility.
- Added Arabic and English translations.
