=== CatCode Bank of Georgia and TBC Payments for WooCommerce ===
Contributors: catcode
Tags: woocommerce, bank of georgia, tbc, georgia, installments
Requires at least: 6.2
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Accept cards, Apple Pay and Google Pay in Georgia through Bank of Georgia and TBC E-Commerce: server-side confirmation, bank callbacks, HPOS and block checkout. Pro: installments, refunds, pre-authorization.

== Description ==

One plugin for both Georgian bank gateways:

* **Bank of Georgia** — BOG Payments API (card, Apple Pay, Google Pay, BOG internet bank transfer, MR/Plus points, gift cards).
* **TBC Bank** — TBC E-Commerce / TBC Checkout (card, Apple Pay, Google Pay, internet bank login, Web QR).

How an order is confirmed:

* The buyer pays on the bank's own page; the plugin never sees card data.
* When the buyer returns, when the bank sends its callback and when the thank-you page loads, the shop asks the bank for the payment itself with its own credentials. The payment id, currency and amount must match the order before it is marked paid; a mismatch puts the order on hold.
* Bank of Georgia callbacks are checked against the bank's RSA signature (SHA256withRSA); a forged callback is refused.
* A buyer who opened the payment page twice is handled: a later payment for an earlier attempt still settles the order, a failed earlier attempt never fails the current one.
* Classic and block checkout, HPOS, GEL / USD / EUR (and GBP for Bank of Georgia) — each method hides itself for currencies its bank does not take.
* Client secrets and the TBC API key are stored encrypted. "Check credentials" asks the bank for a token without creating a payment.

Pro (one licence for both banks):

* **Installments.** Bank of Georgia installment plan and Buy Now Pay Later with the bank's own term calculator at checkout; TBC online installment with the basket sent as installment products that always add up to the total.
* **Refunds from the order screen**, full and partial, for both banks.
* **Pre-authorization.** Block the amount at checkout, then "Capture payment" or "Release the blocked amount" from the order actions (card, Apple Pay, Google Pay).
* **Payment journal** with bank status, method, card, refunds and a one-click re-check.

== Installation ==

1. Upload the plugin and activate it.
2. WooCommerce → Settings → Payments → **Bank of Georgia (CatCode)**: paste the client ID and client secret issued by Bank of Georgia, save, press "Check credentials".
3. WooCommerce → Settings → Payments → **TBC Bank (CatCode)**: paste the client ID and client secret from the TBC merchant dashboard (ecom.tbcpayments.ge → Website Management → Details) and the API key of your app on developers.tbcbank.ge, save, press "Check credentials".
4. For TBC, also paste the callback URL shown in the settings into the merchant dashboard (Website Management → Callback).
5. Pro: activate a licence key or start the 7-day trial in either method's settings, then enable the installment methods.

== Frequently Asked Questions ==

= Is there a test mode? =
There is no separate switch: both banks issue test or live credentials to a registered business, and you paste whichever you received into the same fields.

= The buyer paid but the order is still pending. =
The order settles on the buyer's return, on the bank callback or on the thank-you page. Make sure your site is reachable over HTTPS and, for TBC, that POST requests from TBC's addresses reach the callback URL. With Pro, the journal re-checks a payment in one click.

= Which currencies are supported? =
Bank of Georgia: GEL, USD, EUR, GBP. TBC: GEL, USD, EUR. Installments: GEL only.

= Free and Pro =
Taking payments, server-side verification and callbacks are free with no time limit. Pro features unlock with a licence key from catcode.com.ua. The 7-day trial starts only when you click it.

== External services ==

This plugin connects to the payment services the shop owner enables:

* Bank of Georgia Payments API (oauth2.bog.ge, api.bog.ge) — to create payments, read their status, refund, capture and release pre-authorized payments. Order total, currency, basket (product names, quantities, prices), buyer name, order number and return URLs are sent when a payment is created. Service documentation: https://api.bog.ge/docs/en/payments/introduction
* Bank of Georgia calculator script (webstatic.bog.ge, bog-sdk.js) — loaded on the checkout page only when the Bank of Georgia installment method is enabled with the calculator; it receives the client ID and the cart total.
* TBC E-Commerce (api.tbcbank.ge) — the same operations for TBC. Order total, currency, shipping and tax amounts, the buyer's IP address, order id, a short description and, for installments, the basket are sent. Service documentation: https://developers.tbcbank.ge/docs/checkout-overview
* CatCode licence server (catcode.com.ua) — only when the owner activates a key or starts the trial, and once a day while a key is stored: the key and the site address are sent (plus the e-mail typed for a trial).

== Changelog ==

= 1.0.1 =
* Stored API keys and passwords are encrypted with AES-256-CBC + HMAC instead of a character-by-character XOR loop. Hosting antivirus scanners flagged the XOR loop as obfuscated code and deleted the file, which took the whole plugin down. Values saved by 1.0.0 are still read; they are re-encrypted the next time the settings are saved.

= 1.0.0 =
* First release: Bank of Georgia and TBC payment methods with server-side verification, signed Bank of Georgia callbacks, TBC callbacks, retry-safe attempts, block checkout, HPOS.
* Pro: Bank of Georgia and TBC installments, refunds, pre-authorization with capture and release, payment journal.
