{"id":341283,"date":"2026-07-21T10:29:48","date_gmt":"2026-07-21T10:29:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/myf-fleet-booking-widget\/"},"modified":"2026-07-21T10:29:17","modified_gmt":"2026-07-21T10:29:17","slug":"myf-fleet-booking-widget","status":"publish","type":"plugin","link":"https:\/\/ru.wordpress.org\/plugins\/myf-fleet-booking-widget\/","author":23533646,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.8","stable_tag":"1.0.8","tested":"7.0.2","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"MYF Fleet Booking Widget","header_author":"MyFleet","header_description":"Hero banner cab-booking widget for MYF fleet services. Visitors search fares and confirm bookings across Outstation, Local, One-Way, and Airport categories. Credentials stay server-side; all API calls are proxied through WordPress.","assets_banners_color":"","last_updated":"2026-07-21 10:29:17","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/mindyourfleet.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":42,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.8":{"tag":"1.0.8","author":"myfleet","date":"2026-07-21 10:29:17"}},"upgrade_notice":{"1.0.8":"<p>Security update. The REST proxy endpoints now require a valid nonce in their permission_callback; the widget refreshes the nonce automatically so cached pages keep working.<\/p>","1.0.7":"<p>Recommended update. Clarifies the public REST proxy endpoints&#039; permission handling and keeps the nonce as a CSRF check inside the handlers.<\/p>","1.0.6":"<p>Recommended update. UI polish for the sheet close button, service-tab hover, and field handling when switching trip types.<\/p>","1.0.5":"<p>Recommended update. Fixes the results sheet backdrop not covering the full screen when another widget embed is present.<\/p>","1.0.4":"<p>Recommended update. Fixes an empty results sheet when another widget with the same element ids is present on the page.<\/p>","1.0.3":"<p>Recommended update. Bump clears cached scripts\/styles from the previous version.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":{"myf-fleet-booking-widget\/booking-widget":{"name":"myf-fleet-booking-widget\/booking-widget","title":"MYF Fleet Booking Widget"}},"tagged_versions":["1.0.8"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3616878,"resolution":"1","location":"assets","locale":"","width":1907,"height":701},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3616878,"resolution":"2","location":"assets","locale":"","width":1919,"height":879},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3616878,"resolution":"3","location":"assets","locale":"","width":1919,"height":876},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3616878,"resolution":"4","location":"assets","locale":"","width":1919,"height":870},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3616878,"resolution":"5","location":"assets","locale":"","width":1905,"height":880}},"screenshots":{"1":"Hero banner widget (light theme) \u2014 Outstation tab","2":"Available cabs bottom sheet","3":"Booking details form","4":"Confirmation screen","5":"Plugin settings page (wp-admin)"}},"plugin_section":[],"plugin_tags":[229753,269,233891,15365,249],"plugin_category":[39,40],"plugin_contributors":[272600],"plugin_business_model":[],"class_list":["post-341283","plugin","type-plugin","status-publish","hentry","plugin_tags-airport-transfer","plugin_tags-booking","plugin_tags-cab-booking","plugin_tags-taxi","plugin_tags-travel","plugin_category-business","plugin_category-calendar-and-events","plugin_contributors-myfleet","plugin_committers-myfleet"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/myf-fleet-booking-widget.svg","icon_2x":false,"generated":true},"screenshots":[{"src":"https:\/\/ps.w.org\/myf-fleet-booking-widget\/assets\/screenshot-1.png?rev=3616878","caption":"Hero banner widget (light theme) \u2014 Outstation tab"},{"src":"https:\/\/ps.w.org\/myf-fleet-booking-widget\/assets\/screenshot-2.png?rev=3616878","caption":"Available cabs bottom sheet"},{"src":"https:\/\/ps.w.org\/myf-fleet-booking-widget\/assets\/screenshot-3.png?rev=3616878","caption":"Booking details form"},{"src":"https:\/\/ps.w.org\/myf-fleet-booking-widget\/assets\/screenshot-4.png?rev=3616878","caption":"Confirmation screen"},{"src":"https:\/\/ps.w.org\/myf-fleet-booking-widget\/assets\/screenshot-5.png?rev=3616878","caption":"Plugin settings page (wp-admin)"}],"raw_content":"<!--section=description-->\n<p>MYF Fleet Booking Widget adds a self-contained cab-booking widget to any page or post. Visitors search live fares and confirm bookings across four service types:<\/p>\n\n<ul>\n<li><strong>Outstation<\/strong> \u2014 one-way or round trip, with per-km and daily-allowance breakdown<\/li>\n<li><strong>Local<\/strong> \u2014 hourly\/km packages<\/li>\n<li><strong>One Way<\/strong> \u2014 point-to-point on-demand rides<\/li>\n<li><strong>Airport<\/strong> \u2014 drop-to-airport or pickup-from-airport transfers, with a searchable airport\/station picker<\/li>\n<\/ul>\n\n<p>Key features:<\/p>\n\n<ul>\n<li>Insert via the <code>[myfboen_booking]<\/code> shortcode or the \"MYF Fleet Booking Widget\" Gutenberg block<\/li>\n<li>Google Places autocomplete for pickup\/drop addresses (requires your own Google Maps API key)<\/li>\n<li>Light\/dark theme and accent colour, configurable from Settings \u2192 MYF Fleet Booking Widget<\/li>\n<li>All calls to the MYF Fleet API are proxied through WordPress \u2014 your API token and signing salt are stored server-side and are never sent to the browser<\/li>\n<li>No build step for the frontend or block editor scripts \u2014 pure JavaScript against WordPress core globals<\/li>\n<\/ul>\n\n<h4>Requirements<\/h4>\n\n<p>You need an active MYF Fleet API account (token + security salt) to search fares and take bookings. Without credentials configured, the widget shows a setup notice to administrators instead of rendering.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to two external services:<\/p>\n\n<h4>MYF Fleet API<\/h4>\n\n<p>Used to search available cabs and confirm bookings. Requests are made server-side from your WordPress install; data sent includes the pickup\/drop coordinates, travel date\/time, and \u2014 for bookings \u2014 the traveller's name, mobile number and email address.\nAll calls are proxied through WordPress; your MYF token and salt never leave the server.<\/p>\n\n<ul>\n<li>API endpoint: https:\/\/carapi.myf.io\/w\/v1\/json\/marketplace (search: <code>...\/marketplace\/search<\/code>, booking: <code>...\/marketplace\/booking<\/code>)<\/li>\n<li>Terms of Service: https:\/\/mindyourfleet.com\/termandcondition.php<\/li>\n<li>Privacy Policy: https:\/\/mindyourfleet.com\/privacyandpolicy.php<\/li>\n<\/ul>\n\n<h4>Google Maps Places API<\/h4>\n\n<p>Used for location autocomplete in the booking form. The Google Maps JavaScript library is loaded in the visitor's browser only when a Google Maps API key has been entered in the plugin settings; the key itself is passed to the browser to initialise the Places library.<\/p>\n\n<ul>\n<li>Terms of Service: https:\/\/developers.google.com\/maps\/terms<\/li>\n<li>Privacy Policy: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>myf-fleet-booking-widget<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the plugin ZIP through <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> screen.<\/li>\n<li>Go to <strong>Settings \u2192 MYF Fleet Booking Widget<\/strong> and enter your MYF API token and security salt (and, optionally, a Google Places API key).<\/li>\n<li>Add the widget to a page using the <code>[myfboen_booking]<\/code> shortcode, or insert the \"MYF Fleet Booking Widget\" block from the block editor.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20a%20myf%20fleet%20account%20to%20use%20this%20plugin%3F\"><h3>Do I need a MYF Fleet account to use this plugin?<\/h3><\/dt>\n<dd><p>Yes. The widget searches fares and creates bookings against the MYF Fleet API, which requires an account token and security salt.<\/p><\/dd>\n<dt id=\"is%20my%20api%20token%20safe%3F\"><h3>Is my API token safe?<\/h3><\/dt>\n<dd><p>Yes. The token and salt are stored as WordPress options and are only ever used server-side, inside the REST proxy endpoints this plugin registers. They are never localized to JavaScript or otherwise sent to the browser.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20work%20without%20a%20google%20maps%20api%20key%3F\"><h3>Does this plugin work without a Google Maps API key?<\/h3><\/dt>\n<dd><p>The widget still functions, but address fields will not offer autocomplete suggestions \u2014 visitors must use the airport\/station search (which does not require Google Maps) or type addresses manually where supported.<\/p><\/dd>\n<dt id=\"can%20i%20change%20the%20widget%27s%20colours%20and%20copy%3F\"><h3>Can I change the widget's colours and copy?<\/h3><\/dt>\n<dd><p>Yes \u2014 headline, byline, customer care number, theme (light\/dark) and accent colour are all configurable under <strong>Settings \u2192 MYF Fleet Booking Widget<\/strong>.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.8<\/h4>\n\n<ul>\n<li>Require a valid <code>wp_rest<\/code> nonce in the <code>permission_callback<\/code> of the <code>\/search<\/code> and <code>\/booking<\/code> proxy endpoints, so authorization is enforced at the permission layer rather than as an optional in-handler check. A missing or invalid nonce is now rejected with 403.<\/li>\n<li>Add a public <code>GET \/myfboen\/v1\/nonce<\/code> endpoint that returns only a fresh nonce (no sensitive action) so full-page-cached pages can obtain a live nonce. The response is sent with no-store cache headers so proxies\/CDNs never cache it.<\/li>\n<li>Front-end now warms a fresh nonce on load and, on a 403, refreshes the nonce and retries the request once \u2014 keeping the widget working on aggressively cached sites. Requests send same-origin credentials so the nonce is always evaluated against the correct visitor.<\/li>\n<\/ul>\n\n<h4>1.0.7<\/h4>\n\n<ul>\n<li>Declare the REST proxy endpoints (<code>\/search<\/code>, <code>\/booking<\/code>) as intentionally public via <code>__return_true<\/code>, since the booking widget is used by anonymous visitors and has no user to authorize.<\/li>\n<li>Move the <code>wp_rest<\/code> nonce verification into the request handlers as a best-effort CSRF check (a present-but-invalid nonce is rejected; an absent nonce is allowed so full-page-cached pages keep working).<\/li>\n<\/ul>\n\n<h4>1.0.6<\/h4>\n\n<ul>\n<li>Centre the sheet close button icon regardless of theme button padding.<\/li>\n<li>Stop theme button hover\/focus colours bleeding onto the service tabs; hover now tints the tab's own text.<\/li>\n<li>Preserve entered fields when switching Outstation One Way \/ Round Trip, and swap them by role when switching Airport Drop \/ Pickup.<\/li>\n<li>Anchor the field grid so another embed can't override the From\/To column widths.<\/li>\n<\/ul>\n\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>Keep the results\/booking sheet overlays edge-to-edge even when another embed on the page defines a generic <code>.myfb<\/code> max-width.<\/li>\n<\/ul>\n\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>Scope all front-end DOM lookups to the widget's own root so a duplicate widget or a same-id element elsewhere on the page can no longer hijack the results sheet.<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Enqueue the widget config and admin styles via WordPress functions instead of inline tags.<\/li>\n<li>Prefix all declarations, globals, options, and the REST namespace with <code>myfboen<\/code>.<\/li>\n<li>Add full-width support (block \"Full width\" alignment and <code>[myfboen_booking full_width=\"1\"]<\/code>).<\/li>\n<li>Harden front-end CSS against theme\/plugin interference.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"A hero-banner cab-booking widget for MYF fleet services \u2014 outstation, local, one-way and airport transfers, right on your site.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/341283","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=341283"}],"author":[{"embeddable":true,"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/myfleet"}],"wp:attachment":[{"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=341283"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=341283"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=341283"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=341283"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=341283"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=341283"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}