[SC] Purchasable Resource

[SC] Purchasable Resource 2.5.2

Update description:

Version 2.5.2 delivers an important collection of security, licensing, purchase-limit, and reliability improvements. This update is recommended for every installation.

Changelog:

  • Fixed download limits being bypassable by repeatedly restarting a download during the transfer grace period.
  • The 15-minute download grace period now expires correctly and can no longer reset indefinitely.
  • Expired purchases no longer count toward a resource’s maximum-purchase limit.
  • Customers can purchase time-limited resources again after their previous access expires.
  • Added a per-resource option to use either the global marketplace commission or a custom commission.
  • Resources can now be configured with a genuine 0% commission.
  • Hardened website ownership verification against DNS-rebinding and internal-network request attacks.
  • Verification requests are now restricted to validated public internet addresses and standard web ports.
  • Unified license activation-limit calculations across the public licensing service and REST API.
  • Activation limits now consistently respect the purchased quantity and enforce a minimum of one activation.
  • Added database-enforced uniqueness for generated license keys.
  • Existing unlicensed purchases are migrated safely without receiving unwanted license keys.
  • Improved renewal processing when payment callbacks do not provide their normal request or transaction reference.
  • Added configuration-time validation for automatically licensed XenForo add-on ZIPs.
  • Licensed archives must contain a valid XenForo <span>addon.json</span> structure before they can be enabled.
  • Improved error messages when a licensed download archive cannot be personalized.
  • Preserved XenForo’s native <span>hashes.json</span> file-health verification support.
  • Updated all package hashes and release metadata.
Upgrade instructions:

Upgrade directly from your existing version. Do not uninstall the previous version first.

Upload the new files, overwrite the existing add-on files, and run the XenForo upgrade from AdminCP. Existing resources, purchases, licenses, activations, and configuration data will be preserved.
This maintenance update improves the new automatic licensing system and cleans up the customer licensing interface.

Changes in version 2.4.8:

  • Fixed an empty red DEBUG panel appearing below an active or owner license status.
  • Buyers now receive a cleaner licensing panel with the license-server URL securely hidden.
  • Personalized customer downloads attempt to activate automatically after installation.
  • The manual license-key field appears only when automatic activation is unavailable.
  • The manual license-key field is automatically hidden after successful activation.
  • Saved fallback license keys remain securely preserved when the field is hidden.
  • The activation button is hidden once the installation is successfully licensed.
  • Added support for a verified “Owner installation — Active” state without consuming a customer license.
  • Improved compatibility with XenForo’s custom option-rendering system.
  • Retains the previous licensing endpoint, purchase-history, receipt-email and Admin CP interface fixes.
Customers upgrading from an earlier version can install version 2.4.8 directly over their existing installation.
Version 2.3.2 introduces a redesigned administration experience and additional control over archived resource versions.

Admin Control Panel Redesign

  • Redesigned the Purchasable Resources page using a responsive card layout.
  • Each resource card now displays its price, status, delivery method, access period, download limit, and licensing configuration.
  • Added cleaner Edit and Purchase History actions.
  • Added improved visual separation between resources.
  • Added responsive layouts for desktop, tablet, and mobile screens.
  • Styling automatically follows XenForo Admin control panel colors.
Sales Dashboard Improvements

  • Replaced the basic statistics list with dedicated statistic cards.
  • Added polished cards for active sales, enabled resources, and protected downloads.
  • Added currency-specific revenue cards.
  • Revenue cards now clearly display daily revenue, monthly revenue, lifetime gross revenue, platform fees, and seller earnings.
  • Redesigned recent-sales entries with clearer buyer, date, amount, seller earnings, and payout information.
  • Added side-by-side Top Resources and Top Sellers ranking cards.
  • Added useful empty states when no sales, revenue, resource, or seller data is available.
  • Improved spacing, alignment, shadows, borders, and responsive behavior throughout the dashboard.
Previous Version Controls

  • Added a new per-resource “Show previous versions to buyers” option.
  • Administrators can hide the entire Previous versions section from the purchase panel.
  • The option is available in both the regular XFRM resource editor and the Admin control panel resource editor.
  • Hiding previous versions does not delete archived files.
  • The option can be enabled again later to restore access to archived versions.
  • Existing resources retain their current behavior after upgrading because the option is enabled by default.
Upgrade Notes

  • Upgrade directly over the previous version.
  • Do not uninstall the add-on before upgrading.
  • Existing purchases, protected files, licenses, activations, and archived versions are preserved.
This major update expands [SC] Purchasable Resource with a complete licensing system, improved sales management, stronger download protection, and several reliability fixes.

What’s new in version 2.3.0:

License Management

  • Added a dedicated License Management dashboard in the Admin control panel.
  • View generated licenses, active licenses, current activations, and licenses at their activation limit.
  • View buyer, resource, transaction, purchase date, expiration date, and license status information.
  • View and copy individual license keys.
  • View and copy activated instance keys and labels.
  • View activation and last-check dates.
  • Search by license key, buyer, resource, transaction, instance key, or instance label.
  • Generate missing license keys for older eligible purchases.
  • Copy ready-to-use DELETE API requests.
  • Release individual activations directly from the dashboard.
  • Release every activation associated with a license.
  • Added direct access to License Management under the XFRM section of the Admin control panel.
License API

  • Added automatic unique license-key generation after verified purchases.
  • Added configurable activation limits per resource.
  • Added license activation and validation through the XenForo REST API.
  • Added instance labels for identifying customer websites, installations, or devices.
  • Added API support for releasing existing activations.
  • License keys are displayed in buyer purchase history and purchase receipt emails.
Sales and Purchase Management

  • Added a full sales dashboard with active sales, enabled resources, downloads, revenue, marketplace fees, and seller earnings.
  • Added recent-sales reporting.
  • Added top-selling resource and seller reports.
  • Added purchase filtering by status, user ID, and transaction ID.
  • Added CSV sales export.
  • Added purchase alerts and optional email receipts.
  • Purchase records now retain historical resource titles when a resource is deleted.
  • Historical purchase relationships no longer disappear when related resources or payment profiles are removed.
Coupons and Promotions

  • Added fixed-amount and percentage discount coupons.
  • Added resource-specific and marketplace-wide coupons.
  • Added coupon start and expiration dates.
  • Added maximum-use limits and usage tracking.
  • Added coupon entry during checkout.
Seller Earnings and Commissions

  • Added configurable marketplace commission percentages.
  • Added seller-earnings calculations.
  • Added platform-fee accounting.
  • Added pending, paid, and void payout states.
  • Added administrator payout management.
Access and Download Controls

  • Added configurable purchase-access durations.
  • Added configurable download limits.
  • Added lifetime-access support.
  • Added buyer-only, public, or standard XFRM description-access settings.
  • Added optional guest access for explicitly free resources.
  • Added protected previous-version downloads for entitled buyers.
  • Added partial-content and byte-range download support.
  • Added download throttling and security logging.
  • Added configurable download-log retention.
  • Added stronger filename and Content-Disposition sanitization.
Upload and File Security

  • Added shared upload validation for public and administrator uploads.
  • Added configurable allowed file extensions.
  • Added blocked executable-extension protection.
  • Added MIME-type security checks.
  • Added transactional protected-file replacement.
  • Failed validation or database saves no longer remove the existing protected file.
  • Failed replacements are cleaned up to prevent orphaned files.
  • Previous protected files are safely archived when publishing updates.
  • Protected files are removed during complete add-on uninstallation.
Administration and Diagnostics

  • Added a configuration health-check page.
  • Added payment-profile, protected-storage, callback, logging, and telemetry checks.
  • Added clear telemetry controls and an administrator opt-out option.
  • Added dedicated Admin control panel navigation for sales, resources, coupons, licenses, and diagnostics.
Fixes

  • Fixed a PHP parse error in the purchase upsert query.
  • Fixed administrator upload forms not using multipart file uploads.
  • Fixed unsafe file-replacement behavior during failed saves.
  • Fixed inconsistent extension validation between administrator and public uploads.
  • Fixed protected filename handling.
  • Fixed purchase history becoming unavailable when related records were deleted.
  • Fixed payment-profile purchasable lookup behavior.
  • Improved duplicate payment-callback handling and purchase idempotency.
  • Improved cleanup of protected files and expired download logs.
Compatibility

  • XenForo 2.3.7 or newer
  • XenForo Resource Manager 2.3.7 or newer
  • PHP versions supported by XenForo 2.3
  • Supports XenForo-compatible payment profiles, including PayPal and Stripe
This update improves versioning support for Purchasable Resources.

  • Added an initial version-number field when creating a Purchasable Resource in a version-enabled category.
  • Added protected file uploads when using “Release new version” on the Post an update page.
  • Added protected external URL replacement for externally delivered resources.
  • Fixed the missing version-number field on the Edit resource page.
  • Protected files remain private and are only available to authorized purchasers.
  • Regular resources and ordinary fileless resources are unaffected.
  • Back
    Top