=== Payments.lk for WooCommerce ===
Contributors: paymentslk
Tags: woocommerce, payment gateway, sri lanka, lkr, credit card
Requires at least: 6.6
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 0.1.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Take card payments on your WooCommerce store through Payments.lk, the Sri Lankan gateway.

== Description ==

Payments.lk is a Sri Lankan payment gateway, the startup brand of Payable, which has run payments infrastructure in Sri Lanka since 2016.

Your customer presses Pay, goes to a Payments.lk hosted page, pays by card, and comes back to your store. No card number ever touches your server, which keeps your own compliance burden as small as it can be.

The order is marked paid by a signed notification sent from Payments.lk to your store, not by the customer's browser returning. That is what keeps your order records right even when a customer closes the tab at the wrong moment.

= What it does =

* Card payments on the hosted checkout
* Refunds from the WooCommerce order screen, full or partial
* Works with both the classic checkout and the Cart and Checkout blocks
* Compatible with High Performance Order Storage
* A sandbox mode with test cards, so you can try everything before you are live

= What you need =

A Payments.lk account. Sandbox keys are issued the day you apply, so you can build and test while underwriting runs. Live keys arrive when your application is approved and activated.

The store currency must be Sri Lankan rupees. The gateway hides itself otherwise rather than failing at the last step.

== Installation ==

1. Install and activate the plugin.
2. Go to WooCommerce, Settings, Payments, and open Payments.lk.
3. Choose Sandbox, and paste your sandbox secret key from the Payments.lk dashboard under Developers.
4. In the Payments.lk dashboard under Developers, add a webhook endpoint for Sandbox events pointing at the callback address shown on the settings screen, then paste its signing secret into Sandbox webhook signing secret. The gateway stays hidden at checkout until it is in.
5. Place a test order and pay with a test card.
6. When you are approved, switch the mode to Live and paste your live secret key. Add a second endpoint at the same address for Live events and paste its own signing secret into Live webhook signing secret. The sandbox secret does not verify live events, so the gateway stays hidden in live mode until both are in.

== Frequently Asked Questions ==

= Do card details reach my server? =

No. The customer pays on a page hosted by Payments.lk. Your store only ever sees an amount, an order reference and the result.

= Why is nothing marked paid? =

Almost always the webhook. Check that you added an endpoint in the Payments.lk dashboard for the mode you are using, that it points at the callback address on the settings screen, and that its signing secret is pasted into the field for that mode. Sandbox and live endpoints each have their own secret. The plugin refuses every notification it cannot verify, and one signed with one mode's secret that says it is from the other mode, on purpose. The log under WooCommerce, Status, Logs says which.

= Can I take payments in another currency? =

Not yet. Payments.lk settles in Sri Lankan rupees, so the gateway is hidden when the store currency is anything else.

= Does it support subscriptions? =

Not in this version. Keeping a card on file to charge later needs Payable's Advanced plan, and it will come once that path is routine.

== Changelog ==

= 0.1.2 =
* A customer's phone number is sent only when it is a Sri Lankan number the API accepts (0771234567, +94771234567, or 94771234567 read as +94771234567). Any other number is left out. Before, a foreign or partly typed number made the API refuse the whole checkout, so the customer could not pay.
* A name shorter than two characters is left out for the same reason.
* The payment method says what the hosted checkout takes: cards. The default title is now "Pay by card"; a store still showing the old default, "Card, LankaQR or LankaPay", shows the new one without a settings change, and a title you wrote yourself is kept.
* A webhook signing secret for each mode. The dashboard gives sandbox and live their own endpoints, each with its own secret, and sends sandbox events only to sandbox endpoints. With one field, a store that went live and kept its sandbox secret refused every live notification, so paid orders stayed pending. On updating, the secret you had moves into the field for the mode the store is in, once. It stays where it was too, so going back to 0.1.1 still works.
* A notification has to be signed with one mode's secret and say it is from that mode, and the order it matches has to have been made in that mode. Otherwise it is refused or ignored.
* The gateway is offered at checkout only when the current mode has both its secret key and its webhook signing secret, and the settings screen says what is missing.
* An order is matched only through a checkout or a payment this store created for it. Before, a notification whose reference was a number was taken as the order with that number, so another store on the same Payments.lk account, or a payment link with such a reference, could reach the wrong order. Every checkout an order has had is kept, so a customer who pays on an earlier one that is still open is recognised. A refund notification has to name the order's own payment.
* A failed payment or an expired checkout changes an order only while the order is still waiting on that checkout, so a late notification no longer moves a held, cancelled or refunded order to failed. A notification delivered twice changes nothing, and a second payment for an order already paid is noted for you to check.
* The customer is sent only to a Payments.lk address: https, on payments.lk or a host under it. Any other address, whether the API gave it or it was kept on the order, is refused with an order note and an entry in the error log, and the customer is asked to try again.

= 0.1.1 =
* Corrected the refund notes in the code: sandbox refunds are queued for Payable's sandbox, as live refunds are for Payable, and settle when the processor confirms. Nothing the plugin does changed.

= 0.1.0 =
* First release: hosted checkout, refunds, signed webhooks, Cart and Checkout blocks, High Performance Order Storage.
