Pagazul plugin
The fixed Dashboard renders Plugin settings from returned key_plugin configuration categories. Pagazul category presence, schema, 3DS, timing, and payment behavior are external/deployed boundaries.
Historical schema evidence
Preserved project evidence recorded Pagazul 3DS enabled, Expiration time (seconds), and a maximum of 2100. These external-schema observations do not establish current presence, value, default, minimum, required state, validation, units beyond the label, or provider behavior.
No source-backed claim is made about cardholder verification, expiration, authorization, callback, transaction, reporting, order, or customer effects.
Fixed category and mutation boundary
AllSettings passes returned plugin categories to SettingsMenuOptions; a numeric category opens generic SettingsList. Config edits stage locally and Save persists changed items sequentially; type-5 image configs save immediately. API-core config routes do not establish Pagazul schema or payment behavior. The separate Developers → Plugins manager owns install/root/iframe actions. None ran.
Credentials, merchant/account IDs, callback/webhook data, transactions, customers, payments, cards, wallet/value, refunds, orders, and provider responses remain excluded.
Source-only boundary
/all-settingsis level-0 routed; Plugin settings requires returned plugin categories.- The retained screenshot is sanitized historical navigation evidence, not current installation/configuration proof.
- No runtime/GET/HEAD, credential/webhook, payment/billing/wallet/value/refund, config/image write, plugin-manager action, job, provider, order, customer, or outbound call ran.
- Re-entry requires immutable Dashboard/API and Pagazul serving receipts plus a credential-free synthetic category/payment fixture with all config reads/writes, provider egress, payments, orders, callbacks, and customer data intercepted.
Related guides: Online payments · Developers · Plugin settings