Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
34 commits
Select commit Hold shift + click to select a range
db1e1bb
feat: Release ClientXCMS v2.15, introducing new features, improvement…
martindev-fr Feb 28, 2026
b91ea12
fix: proxmox typo
martindev-fr Mar 13, 2026
f7a2a50
feat: add binance docs
martindev-fr Mar 13, 2026
94d8904
feat: add square docs
martindev-fr Mar 13, 2026
82bbba1
feat: add sumup docs
martindev-fr Mar 13, 2026
a10c021
feat: add quote_manager addon
martindev-fr Mar 13, 2026
86af63e
feat: add helpdesk autoreply extensions
martindev-fr Mar 17, 2026
2593140
feat: add support for backups in Proxmox documentation
martindev-fr Mar 21, 2026
ce015d7
deps: bump the all-dependencies group across 1 directory with 2 updat…
dependabot[bot] Mar 29, 2026
2f07b69
docs: add documentation for Microsoft, Minecraft, Twitch, and ClientX…
martindev-fr Mar 29, 2026
33c2a9f
feat: publish March 2026 update blog post
martindev-fr Mar 29, 2026
052f8c4
chore: remove google-gtag and cookie-consent plugins from documentati…
martindev-fr Mar 29, 2026
4b51963
feat: v2.15.1
martindev-fr Apr 6, 2026
cae912f
Merge branch 'V2' into preprod
martindev-fr Apr 11, 2026
8f0b8de
fix: update authors' GitHub URLs and correct ctxmailer service discon…
martindev-fr Apr 12, 2026
f077c36
feat: add automatic update documentation, override webpack version, a…
martindev-fr Apr 16, 2026
83faf17
chore: remove redocusaurus API documentation integration and references
martindev-fr Apr 16, 2026
7742338
feat: add documentation for knowledgebase and how-did-you-find-us pub…
martindev-fr Apr 19, 2026
ba157ec
deps: bump brace-expansion (#207)
dependabot[bot] Apr 19, 2026
5b8ee24
feat: add late fees addon
martindev-fr May 15, 2026
eebaa09
feat: Add CLI options for creating extensions and themes, enhance Doc…
martindev-fr Jun 6, 2026
f0045d0
fix: update links to the ideas platform across multiple documents
martindev-fr Jun 6, 2026
c05ddf3
feat: add Service Pack documentation and related images for product c…
martindev-fr Jun 6, 2026
babfba1
feat(installation): documenter le script d'installation en une comman…
alexwrite Jun 28, 2026
85963d8
deps: bump brace-expansion (#208)
dependabot[bot] Jun 28, 2026
ab73750
Merge branch 'V2' into preprod
martindev-fr Jun 28, 2026
6831c0a
fix: remove used docker workflow
martindev-fr Jun 28, 2026
47ebcb2
deps: update Docusaurus and related packages to latest versions
martindev-fr Jul 11, 2026
023b41d
feat(idea-addon): add documentation and images for Idea addon functio…
martindev-fr Jul 11, 2026
aade06d
feat: add marketplace publication guides for addons, modules, and the…
martindev-fr Jul 14, 2026
2eb7fbc
feat: add ClientXCMS 2.16 release notes and documentation; include ne…
martindev-fr Jul 18, 2026
e59555e
deps: bump typescript in the all-dependencies group across 1 director…
dependabot[bot] Jul 19, 2026
db3580e
Merge branch 'V2' into preprod
martindev-fr Jul 19, 2026
fb0ac32
fix: update titles for clarity on account management features in rele…
martindev-fr Jul 19, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
136 changes: 136 additions & 0 deletions blog/2026-07-13-clientxcms-v2-16-security-privacy-billing.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,136 @@
---
slug: clientxcms-v2-16-security-privacy-billing
title: "ClientXCMS 2.16: Security, Privacy and sub users Management"
authors: [martindev]
tags: [release, security, privacy, billing, cloud, v2.16]
translated: true
---
**ClientXCMS 2.16** is one of our most important updates yet. At the heart of this release are delegated account access with sub-users and a complete credit-note workflow, alongside a redesigned profile, stronger security, and new privacy tools.

![Interface for inviting a sub-user and configuring delegated permissions](/img/blog/v2.16/invite_users.png)

<!-- truncate -->

## Sub-Users: Invite People and Delegate Access

Customers can now invite another person from their profile. The recipient receives the invitation by email and can accept it to access the account.

Fine-grained permissions determine exactly what each sub-user can do. For example, they can be allowed to access selected services or pay invoices without receiving unrestricted access to the main account.

This major feature is ideal for teams, companies, and customers who need to safely share operational or billing responsibilities.

## Credit Notes: Clearer Refund and Balance Management

Version 2.16 introduces **credit notes**, another major feature for billing teams. Administrators can create a credit note for a customer, properly record a refund, and credit the corresponding amount to the customer's balance.

![Customer credit-note list in the administration panel](/img/blog/v2.16/customers_credit_notes.png)

This provides a clearer audit trail and a much cleaner workflow than applying manual balance adjustments.

## A Completely Redesigned Profile

The profile has been reorganized into clear tabs so that personal information, security settings, delegated users, and privacy tools are easier to find. Customers, administrators, and staff members can also add a profile avatar.

![The redesigned ClientXCMS profile interface with tabbed navigation](/img/blog/v2.16/new_profile_interface.png)

This redesign is more than a visual refresh: it creates a clearer foundation for all the new account-management features introduced in 2.16.

## Stronger Security for Every Account

When enabled by the administrator, users can protect their account with two-factor authentication by **email or SMS**. ClientXCMS supports **OVH SMS and Twilio** as SMS providers.

Trusted devices make strong authentication less intrusive: a recognized device can be remembered and managed directly from the security area. Security questions can now be translated too, so each user receives consistent protection in their own language.

![List of trusted devices in the account security area](</img/blog/v2.16/device%20securities.png>)

All these protections are also available for **administrator and staff accounts**, where access to sensitive information makes account security especially important.

## GDPR-Friendly by Design

Respecting privacy regulations is a priority for us. ClientXCMS now gives every user the ability to:

- export their personal data;
- delete their account;
- review the information associated with their profile.

![Profile privacy tools for exporting personal data and deleting an account](/img/blog/v2.16/export_profile.png)

Administrators can also automatically delete accounts that have been inactive for **three years by default**. The retention period is configurable from **Administration panel > Settings > Security settings**, allowing each organization to adapt the policy to its legal obligations.

These tools make ClientXCMS fully GDPR-friendly and help administrators apply a clear data-retention policy.

## Find Invoices and Records Faster

Invoice lists can now be filtered by payment date and due date. The same date-filtering approach is available for customer registration, service creation, tickets, and other records.

![Invoice filters for payment date and due date](/img/blog/v2.16/filter_invoices.png)

Whether you are looking for an invoice from a specific accounting period or reviewing customers created during a campaign, the relevant records are now only a few clicks away.

## Control Which Countries Appear During Registration

Administrators can choose which countries are available in the registration form from the language settings. This keeps the list relevant to the markets you serve and simplifies registration for customers.

![Country selection settings for the registration form](/img/blog/v2.16/choice_countries.png)

The default allowlist contains: **France, Belgium, Switzerland, Luxembourg, Canada, United States, United Kingdom, Germany, Spain, Italy, Portugal, Netherlands, Ireland, Austria, Morocco, Algeria, Tunisia, Senegal, Ivory Coast, and Cameroon**.

## Automatically Apply a Coupon from Your Website

A coupon can now be passed in the product configuration URL:

```text
https://your-client-area.example/store/basket/config/2?coupon=NEWGEN
```

![Product settings for automatically applying a coupon code](/img/blog/v2.16/add_product_coupon.png)

The code is automatically applied during product configuration. This is especially useful for linking a promotional campaign or a showcase website directly to a ready-to-order offer.

## Flexible Service Cancellation Rules

Each cancellation reason can now trigger one of three workflows:

- cancel the service immediately;
- cancel it when the current service period expires;
- redirect the customer to ticket creation for manual processing.

![Cancellation reason settings with the available cancellation rules](/img/blog/v2.16/cancellation_rules.png)

For manual cancellations, the `cancellation_message` setting lets you prefill the support ticket with instructions or the information your team needs.

![Predefined support-ticket message for a manual cancellation request](/img/blog/v2.16/cancellation_message.png)

## Clearer Product Groups

Product groups can now display badges, helping you highlight a popular, new, or recommended category in the storefront.

![Badge configuration for a product group](/img/blog/v2.16/store_group_badge.png)

## Full Plesk Access for Cloud Offers

ClientXCMS Cloud customers can now enable complete **Plesk access** and manage their hosting environment, files, and databases. To enable it, go to **clientxcms.com > Services > Cloud > Enable Plesk**.

:::warning
Enabling Plesk locks extension changes for the Cloud service. Check your selected extensions before activation.
:::

## Domain Management: Providers Wanted for Testing

* [ ] We have also developed domain-management functionality, but it is **not officially released yet**. Before opening it to everyone, we want to test it with more domain providers and validate the integrations in real-world conditions.

If you are a provider or would like to help test this feature, please contact us. Your feedback will help us prepare a reliable official release.

## A New Home for Your Ideas

The former `ideas.clientxcms.com` platform has been replaced by [clientxcms.com/ideas](https://clientxcms.com/ideas). Suggestions and feature requests are now managed directly in ClientXCMS through the new **Idea addon**, providing a more consistent experience for the entire community.

![Idea addon interface for browsing and submitting suggestions](https://cdn.clientxcms.com/ressources/addons/idea/front_index.png)

The Idea addon is available **free of charge** from the [ClientXCMS marketplace](https://clientxcms.com/resources/idea). You can install it on your own ClientXCMS website to collect, organize, and track your customers' suggestions.

## And Much More

Version 2.16 also brings support-department SLAs, service-status polling, better extension isolation, accessibility improvements, redesigned error pages, and numerous billing and stability fixes.

Read the [complete ClientXCMS 2.16 changelog](/blog/nouvelle-version-2.16) for every technical detail.
61 changes: 61 additions & 0 deletions blog/2026-07-14-nouvelle-version-2.16.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
---
slug: nouvelle-version-2.16
title: New Version 2.16
authors: [martindev]
tags: [release, security, privacy, billing, v2.16]
translated: true
---
# v2.16


![ClientXCMS version 2.16](/img/blog/versions/v2.16.png)

<!-- truncate -->

Discover the major new features and screenshots in our [complete overview of ClientXCMS 2.16](/blog/clientxcms-v2-16-security-privacy-billing).

### Additions

- ➕ Added invitations and delegated account access. Invited sub-users can access services and pay invoices according to the permissions granted to them.
- ➕ Added credit notes to record refunds and easily credit a customer's balance.
- ➕ Added profile avatars for clients, administrators, and staff members.
- ➕ Added SMS multi-factor authentication (MFA), with support for Twilio and OVH SMS providers.
- ➕ Added trusted-device management to avoid repeated verification on recognized devices.
- ➕ Added personal-data export and account deletion tools to meet GDPR requirements.
- ➕ Added automatic deletion of inactive accounts after a configurable retention period (three years by default).
- ➕ Added translatable security questions.
- ➕ Added an allowlist of countries displayed during registration, configurable from the language settings.
- ➕ Added date filters for invoices (payment and due dates), clients (registration date), services (creation date), tickets, and other lists.
- ➕ Added service-level agreements (SLA) for support departments, including ticket tracking and notifications for requests requiring attention.
- ➕ Added configurable cancellation behavior for each cancellation reason: immediate cancellation, cancellation at service expiry, or manual processing through a support ticket with a predefined message.
- ➕ Added automatic coupon application from the product configuration URL using the `coupon` query parameter.
- ➕ Added support for assigning products and groups to subdomains.
- ➕ Added product-group badges for clearer storefront navigation.
- ➕ Added service-status polling for deliveries and service changes.
- ➕ Added an extension sandbox loader so a faulty extension cannot crash the entire application.
- ➕ Developed the first version of domain management. It is not officially released yet, as we are looking for providers willing to help test integrations.

### Changes

- 🔄 Completely redesigned the client profile with a clearer tabbed interface.
- 🔄 Redesigned the product-group presentation and added visual badges.
- 🔄 Improved invoice creation, numbering sequence storage, renewals, refunds, and credit-note handling.
- 🔄 Redesigned the 403 and 500 error pages to provide clearer information to end users.
- 🔄 Improved accessibility across the interface, including navigation, readability, and interactions.
- 🔄 Improved the user experience across multiple client and administration screens.
- 🔄 ClientXCMS Cloud customers can now enable full Plesk access from **clientxcms.com > Services > Cloud > Enable Plesk** to manage hosting, files, and databases. Enabling Plesk prevents subsequent extension changes.
- 🔄 Replaced `ideas.clientxcms.com` with [clientxcms.com/ideas](https://clientxcms.com/ideas), powered by the new free [Idea addon available on the marketplace](https://clientxcms.com/resources/idea).

### Fixes

- 🔧 Fixed access-control and input-validation issues in several workflows.
- 🔧 Fixed edge cases affecting billing and service-management workflows.
- 🔧 Fixed several stability issues in the client and administration interfaces.
- 🔧 Prevented duplicate renewal invoices.

### Security

- 🔒 Added the option to enforce two-factor authentication by email for all users.
- 🔒 Added two-factor authentication by email or SMS.
- 🔒 Added trusted devices and controls for sensitive authentication, invitation, and public-endpoint workflows.
- 🔒 Made the same account-security features available to administrators and staff members.
12 changes: 2 additions & 10 deletions docs/developpers/extensions/extensions.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,14 +31,6 @@ Loaded extensions can be activated or deactivated on the Extensions page
## Choosing between a module and an addon

Simply put, modules are used for service delivery, for example to implement a management panel like Virtualizor, Plesk, or Pterodactyl. Addons are used to add additional features such as payment methods, logic, or custom pages.
## Request to add to the marketplace
## Publishing on the Marketplace

You can request to become a developer at [https://clientxcms.com/client/resources](https://clientxcms.com/client/ressources) and thus offer your extensions to the community.
![Screenshot of creating an extension](/img/blog/lancement-opensource/marketplace2.png)

From now on, each developer can:
- Create their own extensions
- Publish and share their creations via [clientxcms.com/client/ressources](https://clientxcms.com/client/ressources)
- Easily explore and install extensions shared by the community

This intuitive interface was designed to simplify management and encourage the collaborative ecosystem around CLIENTXCMS.
You can distribute your addon or module to the CLIENTXCMS community as a free or paid resource. Follow the [marketplace publication guide](../publish-resource) to activate your developer area and prepare the listing, then read [Publishing an Addon or Module](./publish-marketplace) for UUID, Service Provider, GitHub repository, packaging, and update requirements.
83 changes: 83 additions & 0 deletions docs/developpers/extensions/publish-marketplace.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,83 @@
---
sidebar_position: 5
translated: true
---

# Publishing an Addon or Module

Complete the [common marketplace publication guide](../publish-resource) before following this page.

CLIENTXCMS supports two extension types:

- a **module** delivers and manages a service through a provider such as Pterodactyl, Proxmox, or Plesk;
- an **addon** adds functionality such as a payment method, business logic, or custom pages.

If the extension has not been created yet, start with [Creating an Extension](./create).

## Identifier and Extension Type

Choose the same type in the marketplace as in your extension metadata. The marketplace UUID must remain identical across:

- the marketplace resource;
- the directory name, `modules/<uuid>` or `addons/<uuid>`;
- the `uuid` value in `module.json` or `addon.json`.

Use a lowercase, URL-safe UUID and keep it unchanged between releases. A mismatch prevents CLIENTXCMS from identifying the package reliably.

## Service Providers

In **Service providers**, declare every Laravel Service Provider that CLIENTXCMS must load for the addon or module. Enter its complete namespace, for example:

```text
App\Addons\AnnouncementBar\AnnouncementBarServiceProvider
```

Use **Add provider** when the extension requires more than one. Each declared class must exist in the submitted archive and respect Composer autoloading and PHP namespace capitalization.

The **Pricing** field defines the selling price of the extension. Paid pricing is available only to **certified developers**. You must request certification and confirm that you can issue invoices before CLIENTXCMS can pay out your earnings. Verify your certification and the amount before submitting the resource for validation.

![Service providers and extension pricing](/img/next_gen/developpers/marketplace/mettre-a-jour-extension.png)

## Preparing the GitHub Repository

Use a public GitHub repository to keep the source auditable and the history of every release accessible. The official [ClientXCMS Pterodactyl module](https://github.com/ClientXCMS/module-pterodactyl) is the reference layout: its `master` branch contains `modules/pterodactyl`, a bilingual README, and versioned GitHub releases.

Recommended module layout:

```text
module-example/
├── modules/
│ └── example/
│ ├── lang/
│ ├── database/
│ ├── routes/
│ ├── src/
│ ├── views/
│ ├── module.json
│ └── composer.json
├── README.md
├── LICENSE
└── .gitignore
```

For an addon, use the same principle with `addons/<uuid>` and `addon.json`.

The README should contain the resource name, purpose, features, requirements, installation and configuration instructions, support link, documentation link, and representative images. Clearly state compatibility and breaking changes.

:::warning Never publish secrets
Do not commit `.env` files, API keys, panel credentials, customer data, logs, caches, local dependencies, IDE configuration, or files copied from a production installation. Provide `.env.example` or documented placeholders when configuration examples are necessary.
:::

## Publishing an Extension Version

Marketplace versions are created from the CLIENTXCMS developer interface, not by creating a new marketplace listing. Follow [Creating a Version](../publish-resource#creating-a-version) to select an existing GitHub release or ask CLIENTXCMS to create the release dynamically from the changelog.

Before opening the version form:

1. Update the version in `module.json` or `addon.json` and keep it aligned with the version entered in CLIENTXCMS.
2. Test installation, activation, migrations, configuration, and removal on a clean compatible installation.
3. Push the final source to GitHub and ensure the package preserves `modules/<uuid>` or `addons/<uuid>` at its expected path.
4. Exclude `.git`, development caches, tests not required at runtime, local dependencies, secrets, and installation-specific files.
5. Open the existing resource in CLIENTXCMS, add the version, associate or dynamically create its GitHub release, complete the categorized changelog, and publish it.

Do not modify an already published version with different code. Publish a new version from CLIENTXCMS so users can identify releases safely.
Loading
Loading