# v1.0.9 โ Security Hardening (BOLT11 validation + guest-order authorization)
### Summary
This release closes three security gaps identified in a plugin review: invoices were accepted without being validated against the order's network/amount/expiry, guest orders had no ownership check on the payment AJAX handlers, and `save_ndebit` trusted a client-supplied subscription ID.
Download and install from:
- GitHub

GitHub
Release WooCLINK v1.0.9 ยท WoompaLoompa/woo-clink
v1.0.9 โ Security Hardening (BOLT11 validation + guest-order authorization)
Summary
This release closes three security gaps identified in a plugi...
- Wordpress
Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) – WordPress plugin | WordPress.org
### Security fixes
- **Strict BOLT11 invoice validation** โ the invoice is parsed server-side (bech32 checksum, HRP network, amount, expiry) before payment is confirmed. Invoices that are invalid, on the wrong network, for an amount that doesn't match the order total (within 1 sat), or that expire in under 60 seconds are rejected in the checkout UI.
- **Guest order-key authorization** โ all four payment AJAX handlers (`check_payment`, `confirm_payment`, `mark_paid`, `save_ndebit`) now require the matching order key for guest orders; logged-in users must match the order's customer ID. Previously guests could confirm/mark any order.
- **Server-side subscription binding** โ `save_ndebit` no longer accepts a client-supplied `subscription_id`; subscription IDs are derived server-side from the verified order.
### New
- **Network setting** (`mainnet` / `testnet` / `regtest`) added to the gateway configuration; invoices from a different network are rejected.
- Parsed invoice amount is recorded as `_clink_invoice_amount_sats` order meta.
### Install / Update
1. Upload/install `clink-gateway-for-woocommerce.zip` (attached) or update from the WordPress.org plugin page.
2. WordPress 5.8+ / WooCommerce 3.0+ / PHP 7.4+ (tested up to WP 7.0.2).
3. If you're on testnet or regtest, set **Bitcoin Network** in **WooCommerce โ Settings โ Payments โ Lightning (CLINK)** so invoices are validated against the right chain.
