What's New in Infigo | September 2026

What's New in Infigo | September 2026

Welcome to the September 2026 release of Infigo. Here is a round-up of everything we have shipped this month, gathered in one place so you can see what is new and how to put it to work.

This month is about giving you more hands-on control of your storefronts. A new visual, drag-and-drop page builder lets you compose and edit pages directly on the live site, MegaEdit gains a dedicated SVG shape field for vector design, and custom names now work across every product type, including stock products. Around that creative core, we have made products easier to find with richer search terms and extended search fields, sped up image delivery with CDN and WebP conversion, and strengthened security and support with in-admin screen recordings, login IP auditing, and upload hardening. A set of integration updates across MIS, PunchOut, and fulfilment partners rounds out the release.

Scroll down for the highlights, each with a short description and, where it helps, a visual or a walkthrough of the feature in action.

If you'd like the full technical breakdown of everything released this month, you'll still find the complete release notes by clicking the button below.

Contents

Build Storefront Pages Visually with the Drag-and-Drop Page Builder

A new visual page builder lets administrators compose and edit storefront page content directly on the live page, without navigating to the back-office. Enable the content overlay, click any editable area, and a full-screen builder opens with a component palette, a live canvas and a properties panel so you can build layouts in context and publish them with a single click.

Content components -- titles, images, buttons, text blocks, sliders, embeds, sections and columns -- can be dragged onto the canvas and configured visually. The builder supports undo, redo, duplication, removal, reordering and a preview mode with desktop, tablet and mobile breakpoints.

[[SCREENSHOT: Editor.gif]]

step7_builder_editor.jpg

MegaEdit SVG Field

MegaEdit now includes a dedicated SVG Shape field, letting customers place vector shapes on the canvas and recolour them per element without touching any raw markup. Three base shapes - circle, rectangle and triangle - are available out of the box, and storefronts can grow their own libraries by uploading SVGs to User Media and Clipart categories.

Dropped shapes are created as General Shape fields, giving the full set of visual controls: move, scale, rotate, colour and tiling. All labels and descriptions are localisable, and every uploaded SVG passes through a new server-side validation service that rejects scripts, event handlers, external references, embedded text and other unsafe elements before the file is accepted. Shapes also render server-side, so they output correctly in cross-sell previews, headless processing and generated PDFs.

The SVG Shape Field is delivered as a MegaEdit script that is available to all storefronts. Apply it globally from the MegaEdit Scripts page, or per product from the Scripts tab when editing that product's MegaEdit settings in the Infigo admin. Products launched with the script applied will have the new SVG Shape fields available.

svg_shape_field_dropzone.jpg

Capture and share screen recordings for support from the Admin area

Admins can now record their screen and microphone directly from the Admin area and share a secure link with Infigo Customer Support, without needing any external recording tools. This makes it much easier to show support exactly what you are seeing when you raise an issue.

A new Support Recordings page lists every recording made on your storefront, showing who made it, its file size, its duration, and its creation time. Each recording offers Download, Copy Link, and Delete actions. The recorder runs in its own window, so it keeps recording even while you navigate the rest of Admin, and the list refreshes automatically when a new recording is saved.

  • Admin-only, and available on your storefront by default.
step1_recordings_list.jpg

Custom names for all product types, including stock products

Custom names can now be assigned to any product type, including stock products. Controls are visible to manage these within the Catalogue Settings area of your admin panel.

Four settings under the Custom names section of Configuration > Settings > Catalogue Settings let you enable custom names, make them mandatory (including specifically on stock products), and choose whether custom names replace product names in admin and print views. You can also link a product attribute to the custom name field, so the customer sets the name on the product page and the value is carried straight through to the order line.

ac480-07-basket-custom-names-in-action.png

Control how category tag filters combine product results

A new per-storefront setting gives you control over how the category tag filter combines the tags a customer selects. Previously, selecting tags from different groups widened the result set because every selected tag was combined as a single any-match query. You can now switch to a mode where products must satisfy every group the customer has selected from, making it far easier to narrow results by multiple attributes.

The setting is applied per storefront and defaults to the existing behaviour, so no storefront is affected on deployment until an administrator opts in. Changes take effect immediately with no restart or reindex, and both the standard and Elasticsearch search paths return consistent results.

The two available modes are:

  • Any selected tag — returns products matching any ticked tag across all tag categories (the default, preserving existing behaviour).
  • All tag categories must match — returns only products carrying at least one ticked tag from every tag category that has at least one selection.
step2_tag_filter_combination.jpg

Reset the right password when accounts share an email address

On storefronts where several accounts share one email address, password resets previously resolved to the first account registered against that address, making self-service resets unreliable. You can now reset the password for the exact account intended, either through a username and keyphrase self-service flow, or through an administrator-generated, account-specific reset link.

For storefronts with usernames enabled, the forgot password page asks for a username and a keyphrase. The keyphrase is chosen at request time, embedded in the reset link, and must be re-entered before the password can be changed. Administrators can also generate a reset link directly from a customer's record and share it through a trusted channel.

  • A new Enable forgot password page setting controls whether the self-service reset request page is accessible.
  • Admin-generated links are tied to one account, replace any earlier link for that account, and expire after one day.
  • A Password Changed notification email and an activity log entry for link generation are seeded automatically on deployment.
AC-481_storefront_forgot_password_username_keyphrase.jpg

Improve product discoverability with Search Terms and extended search fields

This enhancement makes product search smarter. Administrators can now assign custom search keywords to any product using a new Search Terms field, so shoppers can find items by terms that may not appear in the product name or SKU.

The product search index has also been enriched with additional product data. When the extended-search setting is enabled, searches also match against SEO meta fields, teaser content, and product group names, giving more relevant results across your catalogue. The new Search Terms field is also included in product import, export, and the copy product function.

  • New Search Terms field for adding custom keywords per product.
  • New catalogue setting to include SEO fields, teaser content, and product group name in search.
  • A detailed article is available covering how to configure and verify these options.
step2_search_terms_field.jpg

Pictures: S3 migration, CDN delivery with responsive srcset and WebP auto-conversion

Storefront product image delivery has been upgraded to improve performance and visual quality across all devices. Product images can now be served through a content delivery network (CDN) rather than directly from application servers, and storefront pages emit responsive image sets so each browser selects the best resolution for its screen size and pixel density.

Newly uploaded product images are automatically stored in cloud storage as part of the standard upload action, and a background task gradually backfills existing images without removing the originals from disk. Lazy loading is applied to below-the-fold images to further improve perceived load time.

  • Faster image delivery via a global CDN, reducing load on application servers.
  • Responsive image variants so browsers download only the size needed for each viewport.
  • Automatic cloud storage of newly uploaded product images.
  • Background backfill of existing images, with disk originals retained as a permanent backup.
  • Lazy loading for below-the-fold images.

The new delivery method is disabled by default and is enabled per deployment once the required cloud infrastructure has been provisioned. There is no customer-facing configuration to manage, and no action is required to benefit from the change once it is switched on.


Choosing the default MIS plugin in the Connect Link popup

Administrators can now choose which MIS plugin is pre-selected when the Connect Link popup opens.

This is controlled by a new dropdown, Default Connect plugin in external reference popup, on the Connect Settings page. It pre-selects your preferred plugin on records that have no existing external reference, and automatically falls back to the first available plugin if the chosen one is later disabled or removed. Records that already have a linked plugin keep their current selection.

step2_default_plugin_dropdown.jpg

Viewing login IP addresses for security auditing

Login activity on your platform now includes the IP address recorded at the time of each sign-in. This gives administrators and security teams network-level audit data to support investigations into suspicious access and to help meet compliance auditing requirements.

The IP address is captured for every new login event and is also copied into Infigo Insights, where it can be queried and included in dashboards and reports. This applies to all new logins going forward; existing historical login records will not contain IP data.

The feature is enabled automatically and needs no configuration.

  • New login events record the visitor IP address, resolved correctly behind load balancers and proxies.
  • Login IP data is available in Metabase Insights for querying and reporting.
  • No action required; historical records are unaffected.

Hide the "Product Details" button per product type

Infigo now lets you configure which product types display the Product Details button on your storefront product listing pages. The "Hide Product details button for" setting in Catalogue Settings has been expanded from covering only Static products to offering an individual checkbox for each product type enabled on your instance.

The checkboxes shown depend on which product types are active on your instance. Stock and Static are always available, with the remaining types appearing when they are enabled:

  • Stock and Static (always shown)
  • Other product types shown when the product type is enabled

Any existing configuration is preserved automatically on deployment, so no manual action is required.

step2_hide_details_checkboxes.jpg

DuplicateJob API call updates

You can now duplicate any job through the API regardless of its current workflow state. Previously, the V2 duplicate job endpoint only worked for jobs that were part of a placed order, which prevented reuse of jobs held in other states. The endpoint now supports jobs that are in a basket, saved as projects, unattached, or part of an existing order.

Each duplicated job is returned with a new, unique Job ID, and the original job is left unchanged in every case. When no order is associated with the source job, the original job owner details are used. You can also choose to have the duplicated job created directly in in-basket status.


Using the Connect Link popup to map records to your MIS

The Connect Link popup used to link platform records to connected MIS integrations has been restyled for clarity across all MIS plugins and record types.

The popup title is now standardised to Connect Link: {EntityType} - {EntityName}, resolved from the record's friendly display name with a graceful fallback to the record ID where a name cannot be determined. Help text fields in printIQ configuration forms now wrap across multiple lines and render as plain text, and a visual empty white box often visible in the popup has been resolved. These clarity improvements require no configuration.

connect_link_title_customer.jpg

PunchOut Extrinsic Value Sent to Siteflow

The PunchOut and HP Siteflow plugins can now work together to place a code from your procurement system onto the shipping label produced for each order. The PunchOut plugin captures a named value from the incoming PunchOut session and stores it as a checkout attribute on the order, and the Siteflow plugin composes that value into the order identifier it submits, where it surfaces on the label for mailroom identification and internal billing.

Configuration is handled entirely through two new plugin settings.

  • PunchOut plugin: new Extrinsic to checkout attribute mapping setting (supports multiple mappings).
  • Siteflow plugin: new Source order id format (Infigo placeholders) setting.
step2_punchout_mapping.jpg

Automatic purchase orders for PrintIQ products whose artwork is managed in PrintIQ

You can now configure a PrintIQ-connected storefront so that purchase orders are raised automatically when a customer places an order for a product whose artwork is managed within PrintIQ. Previously, artwork completion was not confirmed to PrintIQ at quote acceptance, so PrintIQ could not raise the purchase order without manual action.

With the new setting enabled, quote acceptance also confirms to PrintIQ that the artwork is submitted and ready to process, but only for order lines where the artwork is held in PrintIQ rather than uploaded from Infigo. Lines where your team supplies the artwork are evaluated separately and are not affected. The setting defaults to off, so no existing storefront changes until it is deliberately enabled.

  • New setting: Mark artwork as submitted on quote acceptance (PrintIQ plugin, Artwork group).
  • Applies only to products whose artwork is managed in PrintIQ and that have outsource supplier details configured in PrintIQ.
step2_setting_located.jpg

Veracore updates for easier configuration

The Veracore integration settings in your admin panel are now easier to configure. Checkout attribute fields that previously required you to type attribute names by hand have been replaced with dropdown menus populated from the checkout attributes already defined in your system, reducing setup errors and saving time.

The delivery mapping table now uses a simplified editor with descriptive column labels, so it is always clear which Infigo delivery method maps to which Veracore Freight Code. Placeholder-enabled settings also link directly to the Placeholders reference page in the admin panel for quick access.

step1_property_mapping.jpg

Capturing Google Analytics data for Punchout orders

Analytics events are now captured for orders placed through the Punchout checkout flow. Previously, the checkout redirected to the procurement system before Google Tag Manager tracking scripts could execute, so purchase events for Punchout orders were silently dropped and never reached your analytics.

The checkout now waits for tracking to complete before redirecting the buyer, ensuring Google Analytics and Google Tag Manager events are recorded. Two safety timeouts guarantee the checkout never stalls if tracking is slow, unavailable, or blocked, and when Google Tag Manager is not configured the redirect happens immediately, preserving the original behaviour.


New Common Carrier / FOB Destination shipping tax code (FR025000) in Avalara AvaTax

A new shipping tax code, Common Carrier / FOB Destination (FR025000), is now available in the Avalara AvaTax provider configuration. It applies to shipments where the customer has a separate contract for shipping.

The code is selectable from the existing Shipping tax code dropdown, so no new configuration panel is introduced. Selecting it lets Avalara apply the correct tax treatment for this shipping arrangement during checkout, aligning the plugin with the full Avalara AvaTax shipping and handling reference list.

step3_shipping_tax_code_dropdown.jpg

Prevent stored XSS from uploaded files — serve-time CSP hardening + upload sanitiser

This release adds protection against a class of stored cross-site scripting attack in which an uploaded SVG or XML file could carry hidden code that runs in the browser of anyone viewing the storefront. Two independent layers of protection now guard against this.

First, when an SVG or XML file is uploaded it is automatically parsed and any script-capable elements or dangerous style constructs are stripped before the file is stored. Second, when these files are served to a browser they are delivered with a restrictive security header that prevents any embedded code from accessing the storefront origin or loading external resources, so a file that somehow bypassed sanitisation still cannot execute.

Both protections are enabled by default and take effect automatically on deployment. There is no admin panel setting to configure and no action is required from storefront administrators.


Incomplete