Download the PHP package ejosterberg/opensalestax-opencart without Composer

On this page you can find all versions of the php package ejosterberg/opensalestax-opencart. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package opensalestax-opencart

OpenSalesTax for OpenCart

v0.2.0 — installable; 106 unit tests + SonarQube green; per-jurisdiction tax-line surface (opt-in) and cURL IP-pinning against DNS rebinding. Cart-signature cache key, customer-group exemptions, and an admin "Test Connection" button (all shipped in v0.1.1) remain. Not yet end-to-end validated on a live OpenCart storefront. See specs/ for the build plan and roadmap.

Tax calculations are provided as-is for convenience. The merchant is solely responsible for tax-collection accuracy and remittance to the appropriate jurisdictions. Verify against your state Department of Revenue before remitting.

A free, self-hostable OpenCart 4.x extension that swaps OpenCart's geo-zone-based tax tables for the OpenSalesTax engine on US-destination, USD checkouts. No per-transaction fees, no SaaS lock-in — merchants run both OpenCart and OpenSalesTax on their own infrastructure.

What this extension does

What this extension does NOT do

Compatibility matrix

OpenCart PHP Status
4.0.x 8.0 / 8.1 / 8.2 / 8.3 Targeted by v0.1 (live integration test pending)
4.1.x 8.1 / 8.2 / 8.3 Targeted by v0.1 (live integration test pending)
3.0.x 7.4 / 8.0 Not supported. v0.2 backport candidate.
2.x — Not supported.

Requirements

Install

From the GitHub Releases .ocmod.zip (recommended)

  1. Download the latest opensalestax-opencart-vX.Y.Z.ocmod.zip from Releases.
  2. In your OpenCart admin: Extensions → Installer → Upload. Select the file.
  3. Extensions → Extensions, choose Order Totals in the dropdown, find OpenSalesTax, click the green + install button.
  4. Click Edit to open the settings page (see "Configure" below).

From source

Configure

Admin → Extensions → Extensions → Order Totals → OpenSalesTax → Edit

Field Default Purpose
Enabled No Master switch.
Engine base URL (empty) Base URL of your OST engine, e.g. https://ost.example.com. Required when enabled.
API key (optional) (empty) Bearer token if your engine requires authentication.
HTTP timeout (seconds) 10 Per-request timeout.
Verify TLS certificate Yes Strongly recommended ON. Disable only for self-signed engine certs.
Allow private network engines No Permit RFC1918 / loopback / link-local hosts. Required if your engine is on the same LAN as OpenCart.
Block checkout on engine error No When ON, an unreachable engine throws an error. When OFF (default), OpenCart's built-in tax handles the cart.
Cache TTL (seconds) 86400 Per-ZIP cache lifetime. The cache key also includes a stable signature of the cart's (category, amount) tuples, so mixed-category carts at the same ZIP don't share cached results.
Exempt customer groups (empty) Comma-separated OpenCart customer-group IDs (e.g. 2,3) that bypass real-time tax calculation. Typical use: B2B / wholesale / nonprofit groups already mapped to OpenCart's tax classes. Leave blank for no exemptions.
Show tax breakdown per jurisdiction No When ON, the cart shows a separate total line per jurisdiction (state / county / city / special) labeled like "Minnesota State Tax", "Hennepin County Tax". When OFF (default), a single aggregate "Sales Tax" line.
Nexus states (comma-separated) (empty) v0.3 (CP-3): Comma-separated US 2-letter state codes (e.g. MN,WI,IA) the merchant has nexus in. When set, the engine is only called for carts shipping to these states; carts to any other state short-circuit to OpenCart's built-in tax tables (typically: no tax). Leave blank to call the engine for every US/USD cart (pre-v0.3 behavior). Missing or unresolvable destination state with the filter active is fail-closed.

Click Test Connection at the bottom of the settings form to verify your engine URL / API key / TLS settings without putting a cart together. The button calls your engine's /v1/health and reports ok / engine version (or the failure reason). The button is ACL-gated to the same modify permission as the save action.

While the extension is disabled or base_url is empty, OpenCart's built-in tax flow runs unmodified.

How it works

  1. At checkout, OpenCart's Cart\Total::getTotals() walks the enabled order-total extensions. Our catalog/model/extension/opensalestax/total/opensalestax::getTotal() is invoked.
  2. We inspect the cart products + the session's shipping address. If the cart is empty, the currency isn't USD, the shipping country isn't US, or the ZIP isn't 5 digits, we return without touching the totals.
  3. The base URL is validated (SSRF-defending — RFC1918 / loopback / link-local / CGNAT / multicast all rejected by default; opt-in toggle for private-LAN engines).
  4. We cache-lookup the engine response keyed by ZIP-5. On miss, we call POST /v1/calculate via the ejosterberg/opensalestax PHP SDK and store the response.
  5. The engine's tax_total is added as a top-level total line (code: opensalestax) — visible in the cart, checkout, and order summary screens.

If any step fails (gate, network, malformed response), the default fail-soft policy logs a structured warning and lets OpenCart's built-in tax flow continue. Fail-hard mode rethrows the error, blocking the cart.

Logging

All engine interactions log structured metadata (ZIP-5, RTT in ms, line count) via OpenCart's \Log. Customer addresses and full payloads are never logged. The API key (if configured) flows in memory only — never to logs.

Development

See CONTRIBUTING.md for branch model, DCO sign-off, and the quality gate.

Security

Found a vulnerability? See SECURITY.md. Don't open public GitHub issues for security bugs.

The threat model and current findings are in docs/SECURITY-REVIEW.md.

Roadmap

Shipped:

Related projects

License

Dual-licensed under your choice of LICENSE. DCO sign-off (git commit -s) required on every commit.

OpenCart core is GPL-3.0. Both Apache-2.0 and GPL-2.0-or-later are compatible with GPL-3.0 (per the FSF compatibility chart); this extension is delivered as a separate package that runs inside OpenCart's plugin contract.


All versions of opensalestax-opencart with dependencies

PHP Build Version
Package Version
Requires php Version >=8.2
ejosterberg/opensalestax Version ^0.3.0
guzzlehttp/guzzle Version ^7.8
psr/log Version ^1.0 || ^2.0 || ^3.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package ejosterberg/opensalestax-opencart contains the following files

Loading the files please wait ...