Settings¶
Returns Portal keeps its settings in OpenCart's own setting table, under the
module_returns_portal group. You set them at
Admin > Extensions > Extensions > Modules > Returns Portal.
Each key below carries where it applies. per store means a multi-store install can hold a different answer per storefront, and both are honoured: a read takes what that store holds, then what the default store holds, then the shipped default. install-wide means one thing serves every storefront, and the key's own description names that one thing.
Scope¶
| Key | Default | What it does |
|---|---|---|
module_returns_portal_statusper store |
0 |
Whether the portal is enabled. Set by the Status switch on this extension's own settings screen. While it is on, OpenCart's own return form stops accepting submissions and every link pointing at it points here instead; switching it off restores core's behaviour exactly, because no core file was changed. |
module_returns_portal_api_enabledinstall-wide |
0 |
Whether the extension answers API requests at all. Off, every API route answers 404 api_disabled in the API's own JSON envelope, so an extension with its API off is shaped like one that has none. Read once for the whole installation from the default store rather than per store, because the credential it checks is OpenCart's own API user, which has no store of its own. |
Guest lookup¶
| Key | Default | What it does |
|---|---|---|
module_returns_portal_guest_enabledper store |
1 |
Whether somebody with no account may reach the portal by giving an order id and the email address the order confirmation went to. Off refuses the lookup on the server, not merely hides the form. |
module_returns_portal_horizon_daysper store |
104 |
How far back an order stays reachable by a guest lookup, in days. Inside it a proved identity is told why a return is refused; outside it every answer is the same generic refusal, whether or not the order exists. Defaults to the return window plus 90 days. |
module_returns_portal_captchaper store |
empty | Which captcha extension guards the guest lookup, by its code. Empty means none, in which case a lookup that has passed the soft threshold falls straight through to the hard refusal. |
module_returns_portal_throttle_ip_softper store |
5 |
Lookups from one IP address within the window after which the captcha is rendered whether or not it was switched on. |
module_returns_portal_throttle_ip_hardper store |
20 |
Lookups from one IP address within the window after which every answer is the generic refusal. The message never says so: a lockout the caller can detect is an oracle of its own. |
module_returns_portal_throttle_ip_windowper store |
3600 |
The window both IP thresholds are counted over, in seconds. |
module_returns_portal_throttle_order_limitper store |
5 |
Lookups against one order id within its window after which every answer is the generic refusal. Counted on the order and never on the email address, which is the attacker's variable and would let anybody lock a real customer out. |
module_returns_portal_throttle_order_windowper store |
86400 |
The window the per-order threshold is counted over, in seconds. |
Eligibility¶
| Key | Default | What it does |
|---|---|---|
module_returns_portal_return_window_daysper store |
14 |
How many days after the clock starts a line stays returnable, counted to the end of that day in the store's own timezone. At least 1; there is no value meaning unlimited, because a window that never closes is a policy a merchant should have to write down rather than one an extension offers as a number. |
module_returns_portal_clock_status_idper store |
0 |
The order status whose first arrival starts the return window. Zero, or a status the order never reached, falls back to the date the order was placed — the stricter direction, and what settles orders that predate the install with no second code path. First arrival wins and the clock never restarts, so nothing a merchant does later moves a customer's deadline in either direction. |
module_returns_portal_eligible_status_idsper store |
empty | The order statuses a return may be asked for from. Seeded at install from this store's own Complete Status. Empty means nothing is returnable, which is safe but reads as the portal being broken — hence the fallback to store 0's value before the default. |
module_returns_portal_excluded_product_idsper store |
empty | Products that may never be returned. The line still appears on the picker, greyed, with its reason: hiding it is cheaper to build and produces a customer who mails support asking where their item went. |
module_returns_portal_excluded_category_idsper store |
empty | Categories whose products may never be returned. Matching descends the category tree, so naming a parent excludes everything under it. |
Requests¶
| Key | Default | What it does |
|---|---|---|
module_returns_portal_show_estimateper store |
1 |
Whether the customer sees the refund estimate and its breakdown. Off hides it from the customer only; the merchant always sees it, because the merchant is who a wrong figure has to be visible to. |
module_returns_portal_auto_approveper store |
0 |
Whether a submitted request is approved without anybody looking at it. A request is still born submitted and then approved through the same code path, so the history shows arrival and then approval rather than a request born approved with no record of when it came in. |
module_returns_portal_photos_enabledper store |
1 |
Whether a customer may attach photos to a line. Off removes the control and refuses the endpoint on the server. |
module_returns_portal_auto_creditper store |
off |
When store credit is issued without anybody clicking: off, on_approval or on_close. Only ever for a request whose requested resolution is store credit, and never for a guest, who has no account to credit. |
module_returns_portal_stale_daysinstall-wide |
14 |
How long an approved request may wait for its parcel before the returns queue calls it overdue. It changes nothing about the request: no state moves, no mail goes out, and nothing is closed. What it changes is the count in the Awaiting parcel tab's header, which is the whole point of it — a merchant who has decided everything and lands on an empty Needs a decision is told what is quietly waiting rather than being sent to a tab that happens to have rows in it today. Counted from the day the request was approved. |
module_returns_portal_restockinstall-wide |
0 |
Whether closing a request puts its accepted lines back in stock. On, the close control lists every accepted line with a Put back in stock box, ticked by default, and closing adds each ticked line's returned quantity to the same counters OpenCart took it off at checkout: the product, its master where it is a variant, and each option value, wherever that counter is set to subtract stock. A line whose stock is not tracked is shown as such and gets nothing. The stock then follows the order's status: while the order sits on a status OpenCart has taken its stock off for, the returned units are on the shelf, and when the order moves to one it has put everything back for, such as Refunded, the returned units are taken off again so nothing is counted twice. A request closed while this is off is never restocked later. Read once for the whole installation from the default store, because the stock it writes belongs to no store. |
Alerts¶
| Key | Default | What it does |
|---|---|---|
module_returns_portal_alertper store |
1 |
Whether the merchant is mailed when a request arrives. The customer's own mails are not switchable: a switch suppressing the submission mail is a data-loss toggle dressed as a preference, and for a guest that mail is the only record of the request that exists. |
module_returns_portal_alert_emailper store |
empty | Where the merchant alert goes, as a comma-separated list. Empty falls back to this store's own config_email, then store 0's. |
What the customer is told¶
| Key | Default | What it does |
|---|---|---|
module_returns_portal_return_addressper store |
empty | Where the customer is told to post the parcel, printed on the RMA slip and in the submission mail. The extension generates no carrier label and calls no carrier API, so this is the address the whole return runs through. |
module_returns_portal_copyper store |
empty | The sentences the merchant writes in their own words, one set per language: what a customer is told beside an excluded line, what else to do with the parcel, the estimate's caveat and the mail's greeting. A language nobody has written is absent and a field left empty is ours, so what is stored here is only ever the merchant's own wording. Written from the wording panel on this screen rather than typed as a key. |
Advanced¶
| Key | Default | What it does |
|---|---|---|
module_returns_portal_diary_verbose_untilinstall-wide |
0 |
When detailed logging stops, as a unix timestamp, and 0 is off. Turning Detailed logging on from this extension's settings form stores the moment two days from now; the writer compares that against the clock every time it is asked for a DEBUG line, so the window closes on its own with no scheduled task and nothing to clean up. While it is open this extension records what it did in far more detail, and the shared diary consequently holds less history. |
What you cannot change, and why¶
These are fixed on purpose. Each one is a decision with a reason beside it rather than a setting nobody got round to adding.
Requests¶
Photos can be switched off entirely. When they are on, these are the rules, and none of them is configurable — a second set of limits is how two screens learn to contradict each other.
| Rule | Value |
|---|---|
| Largest one photo, in bytes | 5242880 |
| Most per line | 3 |
| Most per request | 10 |
| An unsubmitted upload is swept after | 24 |
Which image formats a customer may attach: five extensions and four MIME types, listed on the photos reference page and taken from the constants the running code checks against. Shorter than OpenCart's own list on purpose — a merchant widening theirs does not widen this — and there is no SVG and there will not be, because it is XML and it is the one image format that can execute when a browser opens it. The contents decide rather than the name, so a list a merchant could add to would be a list they could add an executable to.
Guest lookup¶
How long a proved identity lasts. It is the length of one submission — long enough to photograph a damaged item, short enough that a shared or borrowed machine does not leave somebody else's order open — and a merchant lengthening it is lengthening the window in which a guessed order id stays useful.
| Rule | Value |
|---|---|
| A proved identity lasts, in seconds | 1800 |
Requests¶
Stock is put back when a request is closed and never when it is approved. Before the parcel arrives there is nothing on the shelf, and stock put back on approval is stock a customer can buy before it exists. Closing is the merchant saying the parcel is here.
Scope¶
While the portal is on, OpenCart's own return form stops accepting submissions, unconditionally and with no switch of its own. The module's status flag is already that switch and it is the coherent one: turn the module off and core's route, its links and its behaviour are untouched, because no core file was changed. A second, narrower switch would create a supported configuration in which the portal is enabled and netting-off is bypassable by design rather than by accident.