-
Posts
181 -
Joined
-
Last visited
-
Days Won
9
Content Type
Profiles
Forums
Events
Hotfixes
Everything posted by string
-
The same here. The WHMCS marketplace, in its current form, exposes vendors to blackmail and reputation damage. After the last incident, we have removed all our products from the marketplace and shifted the business focus away from WHMCS. In the latest instance, it involved an individual using a nulled version of our product along with a nulled WHMCS version. Because their pirated version did not function correctly, they attempted to order a trial with the intention of cracking the new version. For obvious reasons, the order has been rejected. We check every order and require, among other criteria, that the customer does not use a nulled version of WHMCS. Out of frustration for not being able to proceed with their order, the individual left negative reviews. WHMCS, or more precisely, @WHMCS John, shows no willingness to even remotely check reviews, even when presented with crystal-clear evidence of fraudulent activity and the information that it is not expected that the removal of this fake review obligates to check other reviews, where the situation is not so clear. While it is understandable that WHMCS cannot check every reported review, action should be taken when the evidence is so clear. I had long suspected that it was only a matter of time until WHMCS comes up with such a sick idea. I am glad I made the decision a long time ago to no longer participate in the marketplace and realized that the marketplace doesn't really matter at all. The volume of orders has not decreased.
-
Description Stripe has announced that it will be increasing its payment fees starting April 10th, 2023. However, Stripe is offering a way to minimize transaction costs through its "Link" service (Stripe's one-click checkout). Link is currently advertised as having a transaction fee of 1.2% plus €0.25 per transaction. This gateway allows to accept one-time credit card payments via the Stripe Credit Card checkout. The module supports "Link". Order here (19.99 € / yearly) Screenshot Free Trial For all modules, a free trial is available. Click on the buy link on the top of the site to order. Please carefully note the requirements for a free trial on the page. Compatibility The module works with WHMCS v6.0 and above. PHP 5.6 - 8.1 is supported.
-
There is no official IDE helper, but there are at least two unofficial helpers: https://github.com/indicio-software/whmcs-ide-helper https://github.com/grizzlyware/salmon-whmcs
-
What is with this?
-
Only the online encoder supports PHP 8.1. I think it is safe to assume that WHMCS does not use the online encoder, but the "standalone" encoder product, for which no update has been published yet.
-
Confirmed 🙂
-
Oh, thanks for tagging me @Danse The module of wsa probably performs a similar task, so similarities in the description are normal, but yes, I also recognize a few "coincidences". The example you brought is awesome 😂. But don't worry, no matter if it's "wordspinned" like you say (the one section is obviously copied 1:1) or not, I'm happy if our modules (and textes) give inspiration. I really don't mind at all. The only reason I'm even going into this is because of this: So this is the first time I've heard that. The module is used well and when there were reports that something was not recognized, it was always due to the customer. There has been an enormous amount of time invested in self-developed tricks to trick the Google / Hotmail image proxy, for example, even with self-hosted domains and so on. First taking over the text (at least partially, see example of @Danse), and then making wild claims - I actually find that a bit cheeky. I would like to have examples with which provider our module doesn't work, but works with yours 🤷♂️.
-
Searching in past Support Ticket replies
string replied to TrippleEx's topic in Admin & Configuration Questions
If I don't find something right away, I search for it directly in the database. The SQL queries would be: SELECT * FROM `tbltickets` WHERE `message` LIKE '%123456%' SELECT * FROM `tblticketreplies` WHERE `message` LIKE '%123456%' SELECT * FROM `tblnotes` WHERE `note` LIKE '%123456%' Via phpMyAdmin this also works via the "Search" link in the navigation bar (see attachment). Based on the output, you will find the ID of the ticket / customer. While not as nice as a reasonably integrated search in WHMCS, this works well. -
Impossible to create the root directory: Permission Denied
string replied to kwood's topic in Developer Corner
The error message clearly indicates that PHP lacks the permission to create the directory. The most common explanation is that the owner (chown) or permission (chmod) is not correct. I don't think it's the permissions, since the permissions are usually set to 0755 for folders and 0644 for files by default. I'm also unsure why the health check would even attempt to create this directory. Since WHMCS is encrypted, I can't figure that out, but maybe the health check will do that if the configured cron directory does not exist. So I would recommend that you also double check the path you configured. -
Impossible to create the root directory: Permission Denied
string replied to kwood's topic in Developer Corner
Looks like a permission issue, probably an incorrect owner of the directories / files. First you should check under which user PHP runs, then check if the owner is correctly set for your WHMCS directory and fix it if not (`chown -R USER:GROUP /path/to/whmcs`). -
The problem is that the IDs of the rows in the table start again at 1. To solve the problem you have to adjust the ID of the affected accounts (probably in tblusers) and then you must adjust the AUTO_INCREMENT value of the table so that newly assigned IDs are automatically higher than the previous ones. However, I can't tell you exactly which tables you need to edit. Without insight into the current structure that would be a lot of guessing with multiple eventualities. If you are not familiar with the WHMCS database schema or don't have a good understanding of databases, it probably makes sense to import a working backup or contact an experienced database administrator. Unless you have solved the problem already, I can also imagine that sooner or later even more serious problems will occur. Because if an ID already exists in the database, which would actually be the ID of the next entry, WHMCS will abort in the middle of the action. By "in the middle of an action" I mean for example the creation of a customer account. WHMCS does not really have an error handling for such errors, which will cause even more inconsistencies in the database. But yes, here I am already guessing - it all depends on the exact changes made.
-
Here you go 🙂 Save this file under /includes/hooks/adminpageSkipSettingsAuth.php (you can change the filename however you want): https://pastebin.com/pRvVzbkn
-
Module function that returns json only
string replied to DennisHermannsen's question in Building Modules
Yes, that would be the way it should be done. As an alternative you can rebuild the WHMCS module params using this code: https://pastebin.com/SgaBKj2G ModuleBuildParams() should return exactly the same array as you see it in your module functions. But this function is not officially documentated, so I don't know if this function will be changed in a later version, or even exist at all. -
If the spam comes from unregistered users, you could enable the "Clients Only" option in each support department: https://docs.whmcs.com/Support_Departments This way, only logged in users will be able to send a contact request. WHMCS will not remove the "Contact Us" link, but when someone clicks on it, they have to log in to create a request.
-
Module function that returns json only
string replied to DennisHermannsen's question in Building Modules
I see 3 possible solutions: Output the json data at the _ClientArea function Output the json data using a newly created php file Output the json data using a hook Output the json data at the ClientArea function This is the easiest way. An example: https://pastebin.com/vSZ9Aie8 The disadvantage is the SSL checker from WHMCS. WHMCS checks for each _ClientArea function execution if a valid SSL certificate exists (and that can be very slow). However, I believe this check is only executed if the last check showed that no valid SSL certificate exists on the domain. And maybe the behavior has changed in the meantime - anyway, when the SSL checker came out there was this problem and personally I went over using the next option, which should also be somewhat less resource-heavy, because unwanted hooks are not executed. Not that it will make a significant performance difference, but well, if you're running this every few seconds and also possibly by multiple clients at the same time, it's certainly not wrong to pay attention to it as well, or at least be informed about it. Output the json data using a newly created php file You create a new file in your module directory, include the init.php of WHMCS (init.php is in the WHMCS root directory) so you can access all the WHMCS stuff (like the Eloquent ORM) and then call this file via XHR: https://pastebin.com/rYKTYLEk Important: Unlike the ClientArea function, you must ensure that the client has permission to access the service. So if you have a parameter for the service ID, you have to make sure that the user ID (e.g. $_S|E|S|S|I|O|N['uid'] (remove '|' - WHMCS WAF bypass, sorry)) belongs to this service. Otherwise, a customer could view the data of other customers by just changing the ID in the paramters. Personally, I think this is the best approach, because you avoid the mentioned SSL checker problem of WHMCS and it is quite likely that this will also work in future WHMCS versions without any problems. Output the json data using a hook It is also possible that you send output to the client via hook. Here is an example: https://pastebin.com/F9amWiJg I would not go this route if you have access to the source code of the module. It's easy to get the service model: https://pastebin.com/PBBxURX7 Side note Ideally, you create a small HTTP controller to handle the AJAX requests, otherwise it gets confusing if you send many different XHR requests. I'm sorry for posting the code samples on pastebin and to obfuscate some parts. The WHMCS web application firewall blocks my post every time no matter how I modify the examples. I have tried for 15 minutes to get it working. A tech board where you can't post code correctly. Ridiculous, I can't even write SESSION correctly with a dollar sign in front of it. 🤷♂️🤦♂️ -
No. You don't define the datetime, WHMCS does. While the second is stored in the database, WHMCS does not output it. Since the the module debug log page is not an editable template file, you cannot change the output value. Well, technically you can change it by JS, but that seems unreasonable to me. Instead, I would just store the timestamp somewhere else (action or request).
-
There is no addon for this because it is time-consuming to identify and fix all edge cases . Yes, a developer would probably see first successes quickly, but the edge cases will make up 99% of the work. And such special cases must be solved in cooperation with the buyer of such a module. And that's where the issues begin - often customers are uncooperative, throwing down any scraps of words as a "full issue description" and so on. And even if it's a problem, which happens maybe one in 100 times, an "ASAP" solution is expected when someone spends money on a module. So it's not really an option to say, "yeah, that's just the way it is" without risking that the client going nuts. In addition - and this is the real reason - the market for such an addon is too small and one can't charge a lot for it, otherwise no one of the few interested people would buy it. In short, it makes no economic sense to invest a lot of time in something like this. If such a module appears on the marketplace, it will probably be from someone who has solved the problem for himself and wants to sell the module. If you want a solution, you will have to find a developer. And you will certainly have to pay a certain amount of money for the development - i don't think developers are just waiting to take on this job, as it's a boring, time-consuming matter that needs to be paid accordingly. Sorry if this sounds too direct, but that's the way it is 😕. At least in this matter I can reassure you. Of course, we never know what WHMCS does next, but if things continue as usual, that module would rarely need updates once it is working as intended.
-
Pinkmare's answer is correct. If you want to encode your code with ionCube, you need the buy the encoder. The Licensing addon from WHMCS does not encode code, it only offers licensing options for your software. If you don't need to encrypt files on a regular basis, ionCube's online encoder may be an alternative. It is very cheap (starts at 0.50 USD per archive).
-
https://github.com/ovh/php-ovh/search?q=This+order+can't+be+paid&type=issues The error message seems to come from the OVH API. If the module logs the API requests to the WHMCS Module Debug Log, there may be more information there.
-
Error on ticket POP import after upgrade to 8.4GA
string replied to pKris's topic in Troubleshooting Issues
Ah, that is exemplary 🙂 -
Error on ticket POP import after upgrade to 8.4GA
string replied to pKris's topic in Troubleshooting Issues
I know this doesn't help you, but because there are critical bugs in practically every major WHMCS release, you should at least wait until the first patch to update. But yeah, someone with a lot of courage has to take the first step. 🤷♂️ Unfortunately there is a good chance that the cause of this problem is not up to you and can only be fixed by a hotfix. If I were you, I would first make sure that the new files has been uploaded correctly (esp. the file "pop.php") and if it does not solve the issue and the WHMCS support can't help either, restore the backup of the previous WHMCS version (if the import functionality is mission critical for you). As more and more data changes in the database over time (new orders, etc.), I would hurry with the recovery decision. -
403 / 504 errors - Modsecurity being triggered
string replied to nf_able's topic in Troubleshooting Issues
It is unlikely that the error reporting settings have any effect on whether ModSecurity blocks something or not. error reporting has no effect on the request / response, except that if there is an error in the response, the error is included. The problem with the OWASP ruleset is that they are quite restrictive. From my experience, even with widely used applications like WordPress. The solution to your problem is to either customize the rules in question, or disable them for the affected domain or URL. If you disable them, you should check if it is an important rule. If changing the rulesets is an option, I would recommend Atomicorp. The rules are really well maintained and the price is ok. Atomicorp also offers a free version of their rules, but not all rules are included and the free ruleset is not updated that often: https://atomicorp.com/atomic-modsecurity-rules/ -
Importing Clients from CSV
string replied to melotel's topic in Installation, Upgrade, and Import Support
I have made this script for importing products: That should give you a good sample which you can rewrite. Regarding adding clients, I wouldn't recommend a manual CSV import via phpMyAdmin, because you need to import data not only in tblclients, but also in tblusers. And you can't set the password via a MySQL import. Use the AddClient API instead. -
Add dedicated IP or hostname to the invoice.php page .
string replied to TimRef's topic in Developer Corner
Great work 🙂 pRieStaKos is right, the type should be checked. The problem is, for example, if the invoice line is about a domain and the domain ID matches with an ID in tblhosting, a wrong value will be inserted. And I have 2 general suggestions: Use type casting for integers. Some servers still uses old mysqlnd drivers, which returns everything as string, even if the column is a integer. However, because of the "if ($dedicatedIP === '') return;" check it doesn't matter in this case. I would trim the $dedicatedIP variable. While WHMCS automatically trims the IP field in newer versions, this was not the case in older versions and I think it is always a good idea to trim fields if it makes sense. And one never know what WHMCS admins do manually in the database. Whitespaces are conceivable. -
The AfterModuleCreate hook could be used too. It returns all relevant data. And there is also AfterModuleTerminate, which can be used to remove the tags from AC when the service is terminated. For domains, you can use PreDomainRegister / PreDomainTransfer. However, there is no hook that is executed when a domain has expired or transferred out. I guess it would be the best to do it via a cronjob, also because manual status changes are not captured at "AfterModuleTerminate", as the terminate module function is not triggered and a combination of serveral hooks would be necessary. A cronjob would ensure that the data in AC is always correct.
