Version History

1.4.0

Changelog

EN/DE – English · Deutsch


English

All notable changes to the cs_roi_calculator package. The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[1.4.0] – 2026-09-24

Changed

  • Edit dialog reorganised for large calculators:
    • Tabs General / Parameters / Results; tab labels show the number of entries, the Results tab a red badge with the number of faulty formulas.
    • Every parameter, heading and result is a collapsible card whose header shows a summary (name, key, type/range or formula, unit), a warning icon for faulty formulas and the ↑/↓ and Remove buttons – entries can be reviewed and reordered while collapsed. Existing entries start collapsed, new ones open; the open state survives moving and re-rendering.
    • "Expand all" / "Collapse all" per tab.
    • All fields are labelled (previously many fields only had placeholders, which disappear once a value is entered); headings have a tinted header.
  • No changes to the frontend or the stored data.

[1.3.0] – 2026-09-24

Added

  • Live formula check in the edit dialog: while typing, result formulas are marked red with a hint for unknown variables or {{ Display names }}, syntax errors, circular references (A → B → A) and empty formulas of named results. Warning only – saving is still possible. The check uses the same formula preprocessing as the frontend (e.g. round(x, 2), decimal comma), so valid formulas are not flagged.
  • Labels for the result format fields (decimal places, thousands separator, decimal separator, CSS class) plus an example hint – previously only truncated placeholders.

[1.2.1] – 2026-09-24

Fixed

  • Unknown {{ Display name }} was silently replaced with 0 – e.g. a typo or a reference to a result further down produced a wrong number without any warning. It is now an error (NaN, reason in the browser console), like an unknown key.
  • Order of results no longer matters for chaining: results are calculated in dependency order (and still displayed in the editor's order), so a result can reference results below it. Circular references and results that depend on a failed result are reported as errors.
  • Negative values and precedence: substituted values are now wrapped in parentheses, so x^2 with x = -5 gives 25 instead of -25.

[1.2.0] – 2026-09-24

Added

  • Custom CSS class per parameter, heading and result: new "CSS class" field in the edit dialog. The class is added to the element's wrapper in all three templates and on the result cards, e.g. to show "costs before" in red and "costs after" in green via the theme CSS. Only letters, digits, _, - and spaces are kept.

Security

  • Default template: block data was embedded in an inline <script> with JSON_UNESCAPED_SLASHES, so a </script> in a name or description ended the script block early (broken page / script injection by editors). The JSON is now encoded with JSON_HEX_TAG | JSON_HEX_AMP; the modern and neo templates and the edit dialog use the same flags for consistency.

[1.1.1] – 2026-09-24

Added

  • Sort order in the edit dialog: parameters (including headings) and results can be moved up and down with ↑/↓ buttons – e.g. to place a heading that was added later. Note: a result can only reference results above it.

[1.1.0] – 2026-09-24

Added

  • Number format per result: decimal places, thousands separator and decimal separator can be set in the edit dialog (e.g. 60.012,50). Formatting only affects the display; chained formulas keep using the raw number. Formulas still cannot call JavaScript methods such as toLocaleString().
  • Parameter type "Heading / group": inserts section headings with an optional description between the inputs, in all three templates (default, modern, neo).

Documentation

  • Block README: configuration section now matches the actual features (the previously listed currency prefix/suffix option did not exist), support contact filled in.

[1.0.9] – 2026-09-24

Fixed

  • Editor: "Remove" deleted two entries at once. ConcreteCMS re-executes the editor script (js/view.js) every time the edit dialog opens, so the click/input/blur listeners on document were registered multiple times. From the second opening on, clicking "Remove" deleted the selected entry and the one that moved up into its place. The listeners are now bound only once per page.
  • Block controller used a short PHP open tag. blocks/cs_roi_calculator/controller.php started with <? instead of <?php and did not work on servers with short_open_tag = Off.

Security

  • Expression parser updated: expr-eval (unmaintained, affected by CVE-2025-12735 and CVE-2025-13204 – code execution via crafted expressions / prototype pollution) replaced with expr-eval-fork 3.0.3. Formula helper functions (round, floor, ceil, abs, min, max, round2, if) are now registered in parser.functions, as required by the new version. Existing formulas calculate unchanged.

Documentation

  • CSP note corrected: the block evaluates formulas via parse() + evaluate() and does not require unsafe-eval.
  • Block README: broken special characters (arrows, heading) repaired, version requirements corrected to "≥", vendor filled in.
  • THIRD_PARTY_LICENSES.TXT converted to UTF-8 and updated to expr-eval-fork.
  • Package README translated to English; changelog now bilingual (EN/DE).

[1.0.8] and earlier

Released before this changelog was introduced; changes are not documented.


Deutsch

Alle nennenswerten Änderungen am Paket cs_roi_calculator. Format angelehnt an Keep a Changelog, Versionierung nach SemVer.

[1.4.0] – 24.09.2026

Geändert

  • Bearbeitungsdialog für große Rechner neu gegliedert:
    • Tabs General / Parameters / Results; die Tab-Beschriftung zeigt die Anzahl der Einträge, der Results-Tab ein rotes Badge mit der Zahl fehlerhafter Formeln.
    • Jeder Parameter, jede Überschrift und jedes Ergebnis ist eine aufklappbare Karte; die Kopfzeile zeigt eine Zusammenfassung (Name, Key, Typ/Bereich bzw. Formel, Einheit), ein Warnsymbol bei fehlerhaften Formeln sowie ↑/↓ und Remove – Einträge lassen sich auch zugeklappt prüfen und sortieren. Bestehende Einträge starten zugeklappt, neue offen; der Zustand bleibt beim Verschieben erhalten.
    • „Expand all“ / „Collapse all“ pro Tab.
    • Alle Felder beschriftet (vorher oft nur Platzhalter, die nach der Eingabe verschwinden); Überschriften haben eine farbig abgesetzte Kopfzeile.
  • Keine Änderungen am Frontend oder an den gespeicherten Daten.

[1.3.0] – 24.09.2026

Neu

  • Formelprüfung im Bearbeitungsdialog: Schon beim Tippen werden Formeln rot markiert und mit Hinweis versehen bei unbekannten Variablen oder {{ Anzeigenamen }}, Syntaxfehlern, Kreisbezügen (A → B → A) und leeren Formeln bei benannten Ergebnissen. Nur Warnung – Speichern bleibt möglich. Die Prüfung nutzt dieselbe Formel-Vorverarbeitung wie das Frontend (z. B. round(x, 2), Dezimalkomma), gültige Formeln werden also nicht markiert.
  • Beschriftungen für die Formatfelder der Ergebnisse (Nachkommastellen, Tausender-, Dezimaltrennzeichen, CSS-Klasse) plus Beispielhinweis – vorher nur abgeschnittene Platzhalter.

[1.2.1] – 24.09.2026

Behoben

  • Unbekannter {{ Anzeigename }} wurde still durch 0 ersetzt – z. B. ein Tippfehler oder ein Verweis auf ein Ergebnis weiter unten lieferte ohne Warnung eine falsche Zahl. Das ist jetzt ein Fehler (NaN, Grund in der Browser-Konsole), wie bei einem unbekannten Key.
  • Reihenfolge der Ergebnisse spielt für Verkettungen keine Rolle mehr: Ergebnisse werden in Abhängigkeitsreihenfolge berechnet (und weiterhin in der Reihenfolge des Editors angezeigt); ein Ergebnis kann also auch auf Ergebnisse darunter zugreifen. Kreisbezüge und Ergebnisse, die von einem fehlerhaften Ergebnis abhängen, werden als Fehler gemeldet.
  • Negative Werte und Rangfolge: eingesetzte Werte werden jetzt geklammert, x^2 mit x = -5 ergibt 25 statt -25.

[1.2.0] – 24.09.2026

Neu

  • Eigene CSS-Klasse pro Parameter, Überschrift und Ergebnis: neues Feld „CSS class“ im Bearbeitungsdialog. Die Klasse wird in allen drei Templates am jeweiligen Element und an den Ergebnis-Karten gesetzt – z. B. um „Kosten vorher“ rot und „Kosten danach“ grün über das Theme-CSS darzustellen. Erlaubt sind nur Buchstaben, Ziffern, _, - und Leerzeichen.

Sicherheit

  • Standard-Template: Die Blockdaten wurden mit JSON_UNESCAPED_SLASHES in ein Inline-<script> eingebettet; ein </script> in Name oder Beschreibung beendete den Skriptblock vorzeitig (kaputte Seite / Skript-Einschleusung durch Redakteur:innen). Das JSON wird jetzt mit JSON_HEX_TAG | JSON_HEX_AMP kodiert; modern, neo und der Bearbeitungsdialog nutzen einheitlich dieselben Flags.

[1.1.1] – 24.09.2026

Neu

  • Reihenfolge im Bearbeitungsdialog: Parameter (inkl. Überschriften) und Ergebnisse lassen sich per ↑/↓-Buttons verschieben – z. B. um eine nachträglich hinzugefügte Überschrift an die richtige Stelle zu setzen. Hinweis: Ein Ergebnis kann nur auf Ergebnisse zugreifen, die darüber stehen.

[1.1.0] – 24.09.2026

Neu

  • Zahlenformat pro Ergebnis: Nachkommastellen, Tausender- und Dezimaltrennzeichen lassen sich im Bearbeitungsdialog einstellen (z. B. 60.012,50). Die Formatierung betrifft nur die Anzeige; verkettete Formeln rechnen weiter mit der unformatierten Zahl. JavaScript-Methoden wie toLocaleString() sind in Formeln weiterhin nicht erlaubt.
  • Parameter-Typ „Heading / group“: fügt Zwischenüberschriften mit optionaler Beschreibung zwischen den Eingaben ein, in allen drei Templates (default, modern, neo).

Dokumentation

  • Block-README: Abschnitt „Konfiguration“ entspricht jetzt dem tatsächlichen Funktionsumfang (die dort genannte Option Währungspräfix/-suffix gab es nicht), Support-Kontakt eingetragen.

[1.0.9] – 24.09.2026

Behoben

  • Editor: „Remove“ löschte zwei Einträge auf einmal. ConcreteCMS führt das Editor-Skript (js/view.js) bei jedem Öffnen des Bearbeitungsdialogs erneut aus; die Klick-/Input-/Blur-Listener auf document wurden dadurch mehrfach registriert. Ab dem zweiten Öffnen entfernte ein Klick auf „Remove“ den gewählten und den nachrückenden Eintrag. Die Listener werden jetzt nur einmal pro Seite gebunden.
  • Block-Controller mit kurzem PHP-Open-Tag. blocks/cs_roi_calculator/controller.php begann mit <? statt <?php und funktionierte auf Servern mit short_open_tag = Off nicht.

Sicherheit

  • Ausdrucks-Parser aktualisiert: expr-eval (nicht mehr gepflegt, betroffen von CVE-2025-12735 und CVE-2025-13204 – Code-Ausführung über manipulierte Ausdrücke/Prototype Pollution) ersetzt durch expr-eval-fork 3.0.3. Hilfsfunktionen für Formeln (round, floor, ceil, abs, min, max, round2, if) werden nun in parser.functions registriert, wie es die neue Version verlangt. Bestehende Formeln rechnen unverändert.

Dokumentation

  • CSP-Hinweis korrigiert: Der Block wertet Formeln über parse() + evaluate() aus und benötigt kein unsafe-eval.
  • Block-README: kaputte Sonderzeichen (Pfeile, Überschrift) repariert, Versionsangaben auf „≥“ korrigiert, Anbieter eingetragen.
  • THIRD_PARTY_LICENSES.TXT auf UTF-8 umgestellt und auf expr-eval-fork aktualisiert.
  • Paket-README ins Englische übersetzt; Changelog jetzt zweisprachig (EN/DE).

[1.0.8] und älter

Vor Einführung dieses Changelogs veröffentlicht; Änderungen nicht dokumentiert.

1.0.9

Changelog

EN/DE – English · Deutsch


English

All notable changes to the cs_roi_calculator package. The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[1.0.9] – 2026-09-24

Fixed

  • Editor: "Remove" deleted two entries at once. ConcreteCMS re-executes the editor script (js/view.js) every time the edit dialog opens, so the click/input/blur listeners on document were registered multiple times. From the second opening on, clicking "Remove" deleted the selected entry and the one that moved up into its place. The listeners are now bound only once per page.
  • Block controller used a short PHP open tag. blocks/cs_roi_calculator/controller.php started with <? instead of <?php and did not work on servers with short_open_tag = Off.

Security

  • Expression parser updated: expr-eval (unmaintained, affected by CVE-2025-12735 and CVE-2025-13204 – code execution via crafted expressions / prototype pollution) replaced with expr-eval-fork 3.0.3. Formula helper functions (round, floor, ceil, abs, min, max, round2, if) are now registered in parser.functions, as required by the new version. Existing formulas calculate unchanged.

Documentation

  • CSP note corrected: the block evaluates formulas via parse() + evaluate() and does not require unsafe-eval.
  • Block README: broken special characters (arrows, heading) repaired, version requirements corrected to "≥", vendor filled in.
  • THIRD_PARTY_LICENSES.TXT converted to UTF-8 and updated to expr-eval-fork.
  • Package README translated to English; changelog now bilingual (EN/DE).

Deutsch

Alle nennenswerten Änderungen am Paket cs_roi_calculator. Format angelehnt an Keep a Changelog, Versionierung nach SemVer.

[1.0.9] – 24.09.2026

Behoben

  • Editor: „Remove“ löschte zwei Einträge auf einmal. ConcreteCMS führt das Editor-Skript (js/view.js) bei jedem Öffnen des Bearbeitungsdialogs erneut aus; die Klick-/Input-/Blur-Listener auf document wurden dadurch mehrfach registriert. Ab dem zweiten Öffnen entfernte ein Klick auf „Remove“ den gewählten und den nachrückenden Eintrag. Die Listener werden jetzt nur einmal pro Seite gebunden.
  • Block-Controller mit kurzem PHP-Open-Tag. blocks/cs_roi_calculator/controller.php begann mit <? statt <?php und funktionierte auf Servern mit short_open_tag = Off nicht.

Sicherheit

  • Ausdrucks-Parser aktualisiert: expr-eval (nicht mehr gepflegt, betroffen von CVE-2025-12735 und CVE-2025-13204 – Code-Ausführung über manipulierte Ausdrücke/Prototype Pollution) ersetzt durch expr-eval-fork 3.0.3. Hilfsfunktionen für Formeln (round, floor, ceil, abs, min, max, round2, if) werden nun in parser.functions registriert, wie es die neue Version verlangt. Bestehende Formeln rechnen unverändert.

Dokumentation

  • CSP-Hinweis korrigiert: Der Block wertet Formeln über parse() + evaluate() aus und benötigt kein unsafe-eval.
  • Block-README: kaputte Sonderzeichen (Pfeile, Überschrift) repariert, Versionsangaben auf „≥“ korrigiert, Anbieter eingetragen.
  • THIRD_PARTY_LICENSES.TXT auf UTF-8 umgestellt und auf expr-eval-fork aktualisiert.
  • Paket-README ins Englische übersetzt; Changelog jetzt zweisprachig (EN/DE).

1.0.8

v1.0.8 — 2025-10-06

Changed: Database table name from btRoiCalculator to btCsRoiCalculator to match the schema. Removed: Bundled locale translations; localization is now managed via https://translate.concretecms.org. Fixed: Minor bugs and cleanups (including block handler naming consistency).