Information not being saved on Order/Customer entries

After updating to v3.0, a common issue folks run into is that information submitted in your cart-related forms aren't being saved onto the order/customer entries as you'd expect.

The reason for this is due to the new Field Whitelisting feature in Simple Commerce. Essentially, field whitelisting is a 'whitelist' of fields that are allowed to be updated via Simple Commerce's forms.

Field Whitelisting was added to prevent your users from adding their own <input> fields to Simple Commerce forms which would let them save whatever they want onto your orders/customers.

There's a few different 'whitelists':

  • Orders
  • Line Items
  • Customer

The Orders whitelist is for any kind of data you want saved directly on the Order entry.

The Line Items whitelist is for any bits of metadata you wish to save onto Line Items. You can update Line Item Metadata in the {{ sc:cart:addItem }} and {{ sc:cart:updateItem }} forms.

And, finally, the Customer whitelist is for any kind of data you wish to be saved onto the Customer entry (if one exists). You can save data onto the customer entry by using the customer array syntax on your forms:

1{{ sc:cart:update }}
2 <input type="date" name="customer[dob]">
3{{ /sc:cart:update }}

The above example saves to the dob field on the related Customer entry.

You can configure the whitelisted fields for each of the 'whitelists' in your Simple Commerce config file:

1// config/simple-commerce.php
2 
3/*
4|--------------------------------------------------------------------------
5| Field Whitelist
6|--------------------------------------------------------------------------
7|
8| You may configure the fields you wish to be editable via front-end forms
9| below. Wildcards are not accepted due to security concerns.
10|
11| https://simple-commerce.duncanmcclean.com/tags#field-whitelisting
12|
13*/
14 
15'field_whitelist' => [
16 'orders' => [
17 'shipping_name', 'shipping_address', 'shipping_address_line1', 'shipping_address_line2', 'shipping_city',
18 'shipping_region', 'shipping_postal_code', 'shipping_country', 'shipping_note', 'shipping_method',
19 'use_shipping_address_for_billing', 'billing_name', 'billing_address', 'billing_address_line2',
20 'billing_city', 'billing_region', 'billing_postal_code', 'billing_country',
21 ],
22 
23 'line_items' => [],
24 
25 'customers' => ['name', 'email'],
26],