Files
3dealer/app/Http/Controllers/Checkout/CheckoutController.php
T

506 lines
22 KiB
PHP
Raw Normal View History

2026-09-08 20:41:49 +03:00
<?php
namespace App\Http\Controllers\Checkout;
use App\Http\Controllers\Controller;
2026-09-09 13:51:00 +03:00
use Illuminate\Http\JsonResponse;
2026-09-09 19:16:20 +03:00
use Illuminate\Http\RedirectResponse;
2026-09-08 20:41:49 +03:00
use Illuminate\Http\Request;
2026-09-09 13:51:00 +03:00
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\Validator;
use Illuminate\Validation\Rule;
2026-09-08 20:41:49 +03:00
use Illuminate\View\View;
2026-09-09 19:16:20 +03:00
use Lunar\Exceptions\Carts\CartException;
use Lunar\Exceptions\FingerprintMismatchException;
use Lunar\Facades\CartSession;
2026-09-09 13:51:00 +03:00
use Lunar\Models\Cart;
2026-09-08 20:41:49 +03:00
use Lunar\Models\Country;
2026-09-09 19:16:20 +03:00
use Lunar\Models\Order;
2026-09-09 13:51:00 +03:00
use Lunar\Models\State;
2026-09-08 20:41:49 +03:00
use Modules\Core\Cart\Services\CartService;
use Modules\Core\Checkout\Exceptions\InvalidShippingOptionException;
2026-09-09 19:16:20 +03:00
use Modules\Core\Checkout\Exceptions\TermsNotAcceptedException;
use Modules\Core\Checkout\Exceptions\UnknownPaymentTypeException;
2026-09-08 20:41:49 +03:00
use Modules\Core\Checkout\Services\CheckoutService;
2026-09-09 19:16:20 +03:00
use Modules\Core\Payment\Enums\PaymentResultStatus;
use Modules\Core\Payment\Models\PaymentMethod;
2026-09-08 20:41:49 +03:00
/**
2026-09-09 13:51:00 +03:00
* The checkout page — one page, sections (contact / billing / shipping /
* shipping method), reviewed against boboko-core's CheckoutService. Stops
* short of payment for this slice (see project memory).
2026-09-08 20:41:49 +03:00
*
2026-09-09 13:51:00 +03:00
* The address form and the shipping-method radios **autosave** — no submit
* buttons. `saveAddress()` / `selectShippingOption()` are called by
* bbk-checkout-form (debounced fetch) and return a JSON envelope of
* server-rendered fragments (shipping options + order summary) plus any
* field errors, rather than redirecting. Address validation is deliberately
* lenient — nothing is rejected mid-typing; required-field enforcement is the
* job of the (not-yet-built) "Continue to payment" gate.
*
* Guest-only for now — the Contact section's login tab is UI only.
*
* Single-country store: STORE_COUNTRY_ISO3 fixes the country to Greece (hidden
* field, forced server-side). Set it to null for the full country picker (the
* portable path for a multi-country boboko store).
2026-09-08 20:41:49 +03:00
*/
class CheckoutController extends Controller
{
2026-09-09 13:51:00 +03:00
private const STORE_COUNTRY_ISO3 = 'GRC';
2026-09-08 20:41:49 +03:00
public function __construct(
private readonly CartService $cart,
private readonly CheckoutService $checkout,
) {}
public function show(string $locale): View
{
$cart = $this->cart->current();
$lines = $cart ? $this->cart->activeLines($cart) : collect();
2026-09-09 13:51:00 +03:00
$storeCountry = $this->storeCountry();
2026-09-08 20:41:49 +03:00
2026-09-09 13:51:00 +03:00
$shippingOptions = collect();
2026-09-08 20:41:49 +03:00
2026-09-09 13:51:00 +03:00
if ($cart?->shippingAddress) {
2026-09-15 19:20:59 +03:00
// Nothing recreates the address row in this path — its own current
// value is the correct "previous" to carry forward if still valid.
$shippingOptions = $this->syncShipping($cart, $cart->shippingAddress->shipping_option);
2026-09-15 15:04:40 +03:00
// Cart's CachesProperties::refresh() explicitly nulls total/
// subTotal/shippingTotal/etc. back to their defaults — every
// Lunar call site pairs it with recalculate() for exactly that
// reason. Bare refresh() here was leaving $cart->total null on
// reload, which fed a 0 amount straight into the Stripe Element.
$cart->refresh()->recalculate();
2026-09-09 13:51:00 +03:00
}
2026-09-08 20:41:49 +03:00
return view('checkout::page', [
'cart' => $cart,
'lines' => $lines,
2026-09-09 13:51:00 +03:00
'billingAddress' => $cart?->billingAddress,
'shippingAddress' => $cart?->shippingAddress,
2026-09-08 20:41:49 +03:00
'shippingOptions' => $shippingOptions,
2026-09-09 19:16:20 +03:00
'paymentMethods' => $this->checkout->getPaymentMethods(),
2026-09-09 13:51:00 +03:00
'shipToBilling' => (bool) data_get($cart, 'meta.ship_to_billing', true),
'storeCountry' => $storeCountry,
'countries' => $storeCountry
? collect()
: Country::orderBy('name')->get(['id', 'name']),
'regions' => $storeCountry
? State::where('country_id', $storeCountry->id)->orderBy('name')->get(['id', 'name'])
: collect(),
2026-09-08 20:41:49 +03:00
]);
}
2026-09-09 13:51:00 +03:00
public function saveAddress(string $locale, Request $request): JsonResponse
2026-09-08 20:41:49 +03:00
{
2026-09-09 13:51:00 +03:00
$storeCountry = $this->storeCountry();
2026-09-08 20:41:49 +03:00
$sameAsBilling = $request->boolean('same_as_billing');
2026-09-09 13:51:00 +03:00
// Only the fields shipping rates resolve against — if none of these
// changed (shopper edited their name, phone, email, …) there's no point
// re-quoting shipping or re-rendering the summary.
2026-09-15 19:20:59 +03:00
$addressBefore = $this->cart->current()?->shippingAddress;
$rateKeyBefore = $addressBefore?->only(['postcode', 'state', 'country_id']);
// setShippingAddress() below always deletes + recreates this row (see
// syncShipping()'s docblock) — capture what was selected NOW, before
// it's gone, so it can be carried forward onto the fresh row.
$previousOption = $addressBefore?->shipping_option;
2026-09-09 13:51:00 +03:00
$stateRule = $storeCountry
? ['nullable', 'string', Rule::exists((new State)->getTable(), 'name')->where('country_id', $storeCountry->id)]
: ['nullable', 'string', 'max:255'];
$countryRule = $storeCountry
? ['nullable']
: ['nullable', 'integer', 'exists:'.(new Country)->getTable().',id'];
2026-09-08 20:41:49 +03:00
2026-09-09 13:51:00 +03:00
// Lenient — only format checks. Anything that fails is simply left out
// of what gets persisted, and reported back for inline display.
$validator = Validator::make($request->all(), [
'contact_email' => ['nullable', 'email'],
'billing_first_name' => ['nullable', 'string', 'max:255'],
'billing_last_name' => ['nullable', 'string', 'max:255'],
2026-09-08 20:41:49 +03:00
'billing_company_name' => ['nullable', 'string', 'max:255'],
'billing_tax_identifier' => ['nullable', 'string', 'max:255'],
2026-09-09 13:51:00 +03:00
'billing_line_one' => ['nullable', 'string', 'max:255'],
2026-09-08 20:41:49 +03:00
'billing_line_two' => ['nullable', 'string', 'max:255'],
2026-09-09 13:51:00 +03:00
'billing_city' => ['nullable', 'string', 'max:255'],
'billing_state' => $stateRule,
'billing_postcode' => ['nullable', 'string', 'max:20'],
'billing_country_id' => $countryRule,
2026-09-08 20:41:49 +03:00
'billing_contact_phone' => ['nullable', 'string', 'max:50'],
2026-09-09 13:51:00 +03:00
'shipping_first_name' => ['nullable', 'string', 'max:255'],
'shipping_last_name' => ['nullable', 'string', 'max:255'],
'shipping_company_name' => ['nullable', 'string', 'max:255'],
'shipping_line_one' => ['nullable', 'string', 'max:255'],
'shipping_line_two' => ['nullable', 'string', 'max:255'],
'shipping_city' => ['nullable', 'string', 'max:255'],
'shipping_state' => $stateRule,
'shipping_postcode' => ['nullable', 'string', 'max:20'],
'shipping_country_id' => $countryRule,
'shipping_contact_phone' => ['nullable', 'string', 'max:50'],
2026-09-08 20:41:49 +03:00
'shipping_delivery_instructions' => ['nullable', 'string', 'max:1000'],
2026-09-09 13:51:00 +03:00
]);
2026-09-08 20:41:49 +03:00
2026-09-09 13:51:00 +03:00
$errors = $validator->errors()->toArray();
$data = $validator->valid();
2026-09-08 20:41:49 +03:00
2026-09-09 13:51:00 +03:00
$billingCountryId = $storeCountry?->id ?? ($data['billing_country_id'] ?? null);
$shippingCountryId = $storeCountry?->id ?? ($data['shipping_country_id'] ?? $billingCountryId);
2026-09-08 20:41:49 +03:00
$billing = [
2026-09-09 13:51:00 +03:00
'first_name' => $data['billing_first_name'] ?? null,
'last_name' => $data['billing_last_name'] ?? null,
2026-09-08 20:41:49 +03:00
'company_name' => $data['billing_company_name'] ?? null,
'tax_identifier' => $data['billing_tax_identifier'] ?? null,
2026-09-09 13:51:00 +03:00
'line_one' => $data['billing_line_one'] ?? null,
2026-09-08 20:41:49 +03:00
'line_two' => $data['billing_line_two'] ?? null,
2026-09-09 13:51:00 +03:00
'city' => $data['billing_city'] ?? null,
2026-09-08 20:41:49 +03:00
'state' => $data['billing_state'] ?? null,
2026-09-09 13:51:00 +03:00
'postcode' => $data['billing_postcode'] ?? null,
'country_id' => $billingCountryId,
'contact_email' => $data['contact_email'] ?? null,
2026-09-08 20:41:49 +03:00
'contact_phone' => $data['billing_contact_phone'] ?? null,
];
$shipping = $sameAsBilling
? [...$billing, 'delivery_instructions' => $data['shipping_delivery_instructions'] ?? null]
: [
2026-09-09 13:51:00 +03:00
'first_name' => $data['shipping_first_name'] ?? null,
'last_name' => $data['shipping_last_name'] ?? null,
2026-09-08 20:41:49 +03:00
'company_name' => $data['shipping_company_name'] ?? null,
2026-09-09 13:51:00 +03:00
'line_one' => $data['shipping_line_one'] ?? null,
2026-09-08 20:41:49 +03:00
'line_two' => $data['shipping_line_two'] ?? null,
2026-09-09 13:51:00 +03:00
'city' => $data['shipping_city'] ?? null,
2026-09-08 20:41:49 +03:00
'state' => $data['shipping_state'] ?? null,
2026-09-09 13:51:00 +03:00
'postcode' => $data['shipping_postcode'] ?? null,
'country_id' => $shippingCountryId,
'contact_email' => $data['contact_email'] ?? null,
2026-09-08 20:41:49 +03:00
'contact_phone' => $data['shipping_contact_phone'] ?? null,
'delivery_instructions' => $data['shipping_delivery_instructions'] ?? null,
];
$this->checkout->setBillingAddress($billing);
2026-09-09 13:51:00 +03:00
$cart = $this->checkout->setShippingAddress($shipping);
2026-09-08 20:41:49 +03:00
$cart->meta = [...($cart->meta?->toArray() ?? []), 'ship_to_billing' => $sameAsBilling];
2026-09-09 13:51:00 +03:00
$cart->save();
// Abandoned-cart-recovery opt-in — boboko-core owns the record (bool +
// timestamp + policy version on Cart::meta, RecoveryConsentSet event).
// Deliberately its own scope, not merged with any future newsletter opt-in.
$this->checkout->setRecoveryConsent($request->boolean('recovery_consent'));
2026-09-09 13:51:00 +03:00
$rateKeyAfter = $cart->shippingAddress?->only(['postcode', 'state', 'country_id']);
2026-09-15 15:04:40 +03:00
$rateChanged = $rateKeyAfter != $rateKeyBefore;
// setShippingAddress() above always deletes and recreates the
// CartAddress row (Lunar's AddAddress action), which drops whatever
// shipping_option was previously selected — regardless of whether the
// rate-determining fields actually changed. So this always has to run
// to restore/re-validate it, even on a save that only touched e.g. the
// phone number. Only the fragment RE-RENDER is skippable when nothing
// rate-relevant moved — the re-select itself is not optional.
2026-09-15 19:20:59 +03:00
$options = $this->syncShipping($cart, $previousOption);
2026-09-15 15:04:40 +03:00
if (! $rateChanged) {
2026-09-09 13:51:00 +03:00
return $this->fragments($cart, null, $errors);
}
2026-09-15 15:04:40 +03:00
return $this->fragments($cart, $options, $errors);
2026-09-08 20:41:49 +03:00
}
2026-09-09 13:51:00 +03:00
public function selectShippingOption(string $locale, Request $request): JsonResponse
2026-09-08 20:41:49 +03:00
{
2026-09-09 13:51:00 +03:00
$identifier = (string) $request->input('shipping_option');
2026-09-08 20:41:49 +03:00
try {
2026-09-09 13:51:00 +03:00
$this->checkout->selectShippingOption($identifier);
2026-09-08 20:41:49 +03:00
} catch (InvalidShippingOptionException) {
2026-09-09 13:51:00 +03:00
// Re-render with whatever is currently valid; no hard error surfaced.
}
$cart = $this->cart->current();
$options = $cart?->shippingAddress
? $this->checkout->getShippingOptions()
: collect();
return $this->fragments($cart, $options);
}
2026-09-09 19:16:20 +03:00
/**
* Autosave-select a payment method (radio change). Persists it via
* CheckoutService (which also records it on Cart::meta and re-snapshots
* the fingerprint) so ApplyCashOnDeliveryFee etc. show in the summary.
*/
public function selectPaymentMethod(string $locale, Request $request): JsonResponse
{
$type = (string) $request->input('payment_type');
try {
$this->checkout->selectPaymentMethod($type);
} catch (UnknownPaymentTypeException) {
// Radio value out of sync with what's offered — ignore, the summary
// just won't reflect a method fee. place-order re-checks properly.
}
return response()->json([
'summaryHtml' => view('checkout::partials.cart-body')->render(),
]);
}
/**
* The real submit — the hard gate. Re-selects the payment method (fresh
* fingerprint), then hands off to CheckoutService::initiatePayment(), which
* creates the draft order, records terms acceptance, and charges the driver.
* Returns JSON the bbk-payment controller routes on:
* { redirect } — placed, go to confirmation
* { status: 'pending', clientSecret }— 3-D Secure; client does handleNextAction then polls
* { status: 'failed', message } — declined
* { status: 'invalid'|'stale', ... } — cart incomplete / changed since selection
*/
public function placeOrder(string $locale, Request $request): JsonResponse
{
if (! $request->boolean('terms_accepted')) {
return response()->json(['error' => __('checkout.page.terms_required')], 422);
}
try {
$this->checkout->selectPaymentMethod((string) $request->input('payment_type'));
} catch (UnknownPaymentTypeException) {
return response()->json(['error' => __('checkout.page.choose_payment_method')], 422);
}
2026-09-15 19:20:59 +03:00
$cart = $this->cart->current();
// Captured now, before initiatePayment() can place the order — Lunar's
// CartSessionManager::fetchOrCreate() silently swaps the session onto a
// BRAND NEW empty cart the moment the current one hasCompletedOrders()
// (i.e. has an order with placed_at set), which happens synchronously
// for an immediately-captured payment. Any later $this->cart->current()
// call in this same flow (here, or in a subsequent orderStatus() poll
// once the 3-D Secure webhook sets placed_at) would then resolve to
// that fresh, order-less cart instead of the one that was just placed.
// Storing the real cart id ourselves, under our own session key,
// sidesteps CartSession entirely for the rest of the placement flow.
session(['checkout.cart_id' => $cart?->id]);
// Lunar's own ValidateCartForOrderCreation (order_create validator)
// never checks for this — an empty cart with a valid billing address
// sails straight through it and would place a real, zero-line order.
// The disabled "place order" button is only the client-side half of
// this fix; this is the half that actually matters.
if ($cart === null || $this->cart->activeLines($cart)->isEmpty()) {
return response()->json([
'status' => 'invalid',
'message' => __('checkout.page.cart_empty'),
], 422);
}
2026-09-15 19:20:59 +03:00
// The one incomplete-cart case worth a specific message + pointing the
// shopper at the right section: a region resolving 2+ methods needs an
// explicit pick (no auto-select), easy to miss since nothing else on
// the page demands it. Everything else CartException catches below.
if ($cart?->shippingAddress && ! $cart->shippingAddress->shipping_option) {
return response()->json([
'status' => 'invalid',
'message' => __('checkout.page.shipping_method_required'),
'field' => 'shipping_option',
], 422);
}
$fingerprint = (string) ($cart?->meta['checkout_fingerprint'] ?? '');
2026-09-09 19:16:20 +03:00
$data = $request->filled('payment_method')
? ['payment_method' => (string) $request->input('payment_method')]
: [];
try {
$result = $this->checkout->initiatePayment(
$fingerprint,
termsAccepted: true,
policyVersion: (string) config('legal.terms_version'),
data: $data,
);
} catch (FingerprintMismatchException) {
return response()->json(['status' => 'stale', 'message' => __('checkout.page.payment_cart_changed')], 409);
} catch (CartException $e) {
return response()->json([
'status' => 'invalid',
'message' => __('checkout.page.payment_incomplete_details'),
'errors' => collect($e->errors()->toArray())->map(fn ($m) => is_array($m) ? ($m[0] ?? null) : $m)->all(),
], 422);
} catch (TermsNotAcceptedException) {
return response()->json(['error' => __('checkout.page.terms_required')], 422);
}
// Pending with no continuation (cash-on-delivery, or any other
// deferred/offline method) means CheckoutService::initiatePayment()
// already created the placed order — money just hasn't changed
// hands yet. Only a Pending WITH a continuation (Stripe's client
// secret) means the shopper still has something to do before the
// order exists as far as the storefront is concerned.
return match (true) {
$result->status === PaymentResultStatus::Succeeded => $this->orderPlacedResponse($locale),
$result->status === PaymentResultStatus::Pending && $result->continuation === null => $this->orderPlacedResponse($locale),
$result->status === PaymentResultStatus::Pending => response()->json([
2026-09-09 19:16:20 +03:00
'status' => 'pending',
'clientSecret' => $result->continuation?->value,
]),
default => response()->json([
2026-09-09 19:16:20 +03:00
'status' => 'failed',
'message' => $result->failureReason ?: __('checkout.page.payment_failed'),
'retriable' => $result->retriable,
], 422),
};
}
/**
* Poll target for the 3-D Secure path: has the webhook placed the order yet?
* boboko-core's StripeWebhookController -> handleCallback -> PaymentCaptured
* -> ApplyResolvedPaymentStatus sets placed_at.
*/
public function orderStatus(string $locale): JsonResponse
{
$order = $this->placedOrder();
if (! $order) {
return response()->json(['placed' => false]);
}
session(['checkout.order_id' => $order->id]);
CartSession::forget();
return response()->json(['placed' => true, 'redirect' => route('checkout.confirmation', $locale)]);
}
public function confirmation(string $locale): View|RedirectResponse
{
$orderId = session('checkout.order_id');
$order = $orderId
? Order::with(['lines.purchasable.product', 'shippingAddress', 'billingAddress'])->find($orderId)
2026-09-09 19:16:20 +03:00
: null;
if (! $order) {
return redirect()->route('products', $locale);
}
// Looked up by type rather than a stored relation — the method may since
// have been disabled/deleted, but the order still needs to show what was
// actually used at the time.
$paymentMethodName = PaymentMethod::where('type', $order->meta['payment_method'] ?? null)
->first()
?->translate('name');
return view('checkout::confirmation', [
'order' => $order,
'paymentMethodName' => $paymentMethodName,
]);
2026-09-09 19:16:20 +03:00
}
private function orderPlacedResponse(string $locale): JsonResponse
{
if ($order = $this->placedOrder()) {
session(['checkout.order_id' => $order->id]);
}
CartSession::forget();
return response()->json(['redirect' => route('checkout.confirmation', $locale)]);
}
private function placedOrder(): ?Order
{
$cartId = session('checkout.cart_id');
if ($cartId === null) {
return null;
}
return Order::where('cart_id', $cartId)
2026-09-09 19:16:20 +03:00
->whereNotNull('placed_at')
->latest('placed_at')
->first();
}
2026-09-09 13:51:00 +03:00
/**
* Re-resolve shipping options for the cart's current address and keep the
2026-09-15 19:20:59 +03:00
* selection sane: auto-select when exactly one resolves, or carry a
* previous pick forward when it's still among the resolved options.
*
* $previousOption must be captured by the CALLER before setShippingAddress()
* runs — Lunar's AddAddress action always deletes and recreates the
* CartAddress row on every save (see saveAddress()), so by the time this
* runs, $address->shipping_option is unconditionally null regardless of
* what was selected a moment ago. There is nothing meaningful left to read
* off $address itself; $previousOption is the only source of truth for
* "what was chosen before this save wiped the row." show() passes the
* address's own (not-just-wiped) current value, since nothing recreated
* anything in that path.
*
* Always (re-)applies the resolved target via selectShippingOption() rather
* than comparing against the (always-blank, post-recreation) current value
* — the fresh row needs the write regardless of whether the decision
* "which option" actually changed.
2026-09-09 13:51:00 +03:00
*
* @return Collection<int, \Lunar\DataTypes\ShippingOption>
*/
2026-09-15 19:20:59 +03:00
private function syncShipping(Cart $cart, ?string $previousOption): Collection
2026-09-09 13:51:00 +03:00
{
2026-09-15 19:20:59 +03:00
if (! $cart->shippingAddress) {
2026-09-09 13:51:00 +03:00
return collect();
}
$options = $this->checkout->getShippingOptions();
2026-09-15 19:20:59 +03:00
$target = match (true) {
$options->count() === 1 => $options->first()->identifier,
$previousOption !== null && $options->contains(fn ($option) => $option->identifier === $previousOption) => $previousOption,
default => null,
};
2026-09-09 13:51:00 +03:00
2026-09-15 19:20:59 +03:00
if ($target !== null) {
try {
$this->checkout->selectShippingOption($target);
} catch (InvalidShippingOptionException) {
// $target came from $options itself — shouldn't happen, stay defensive
2026-09-09 13:51:00 +03:00
}
}
return $options;
}
/**
* $options === null means "nothing money-relevant changed" — acknowledge the
* save (and any field errors) without re-rendering the shipping options or
* the order summary, so a plain name/phone edit is a cheap round-trip.
*/
private function fragments(?Cart $cart, ?Collection $options, array $errors = []): JsonResponse
{
return response()->json([
'errors' => collect($errors)
->map(fn ($messages) => is_array($messages) ? ($messages[0] ?? null) : $messages)
->all(),
'shippingOptionsHtml' => $options === null ? null : view('checkout::partials.shipping-options', [
'shippingAddress' => $cart?->shippingAddress,
'shippingOptions' => $options,
])->render(),
// Composer (CheckoutModuleServiceProvider) fills $cart / $lines.
'summaryHtml' => $options === null ? null : view('checkout::partials.cart-body')->render(),
]);
}
private function storeCountry(): ?Country
{
if (self::STORE_COUNTRY_ISO3 === null) {
return null;
2026-09-08 20:41:49 +03:00
}
2026-09-09 13:51:00 +03:00
return Country::where('iso3', self::STORE_COUNTRY_ISO3)->first();
2026-09-08 20:41:49 +03:00
}
}