Merge branch 'master' into Privacy
This commit is contained in:
@@ -0,0 +1,25 @@
|
||||
<?php
|
||||
|
||||
use Modules\Core\Catalog\Recommendations\RandomRule;
|
||||
use Modules\Core\Catalog\Recommendations\SameCategoryRule;
|
||||
|
||||
return [
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| Product recommendation rules
|
||||
|--------------------------------------------------------------------------
|
||||
|
|
||||
| Tried in order by Modules\Core\Catalog\Services\RecommendationService —
|
||||
| the first rule that returns at least one product wins. The order here IS
|
||||
| the fallback chain: SameCategoryRule first, then RandomRule as a
|
||||
| last-resort so a product page is never left with zero recommendations
|
||||
| (as long as the store has more than one product). A consuming app can
|
||||
| reorder, add, or remove rules freely — nothing about the chain shape is
|
||||
| hardcoded in the service itself.
|
||||
|
|
||||
*/
|
||||
'recommendation_rules' => [
|
||||
SameCategoryRule::class,
|
||||
RandomRule::class,
|
||||
],
|
||||
];
|
||||
@@ -45,4 +45,78 @@ return [
|
||||
'grace_period_days' => 30,
|
||||
],
|
||||
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| Cart Abandonment Threshold
|
||||
|--------------------------------------------------------------------------
|
||||
|
|
||||
| How long a cart (that hasn't converted to a placed order) can go without
|
||||
| activity before Modules\Core\Cart\Filament\Resources\CartResource treats
|
||||
| it as "Abandoned" rather than "Ongoing". Anything DateInterval::createFromDateString()
|
||||
| accepts works, e.g. '1 hour', '30 minutes', '2 days'.
|
||||
|
|
||||
*/
|
||||
|
||||
'cart' => [
|
||||
'abandoned_after' => '1 hour',
|
||||
|
||||
/*
|
||||
|----------------------------------------------------------------------
|
||||
| Unrecoverable Cap
|
||||
|----------------------------------------------------------------------
|
||||
|
|
||||
| Beyond this age, a stale cart stops being treated as an active
|
||||
| "Abandoned Cart"/"Abandoned Checkout" (Modules\Core\Cart\Services\
|
||||
| CartLifecycleService) — too old to be a realistic recovery target
|
||||
| (pricing/stock/tax likely stale by then). This is about the
|
||||
| abandoned-cart pipeline only, not data retention — no rows are
|
||||
| deleted or pruned based on this value.
|
||||
|
|
||||
*/
|
||||
|
||||
'unrecoverable_after' => '90 days',
|
||||
],
|
||||
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| Order Return Window
|
||||
|--------------------------------------------------------------------------
|
||||
|
|
||||
| How many days after a carrier order is delivered (Order::fulfillment_status
|
||||
| becomes 'return_window_open') before Modules\Core\Order\Commands\
|
||||
| CloseExpiredReturnWindows auto-completes it, if no return was requested.
|
||||
| Store-pickup orders have no return-window step and are unaffected by
|
||||
| this value (see Modules\Core\Order\Listeners\CompleteOrderOnPickedUp).
|
||||
|
|
||||
*/
|
||||
|
||||
'order' => [
|
||||
'return_window_days' => 14,
|
||||
],
|
||||
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| Storefront OTP Login
|
||||
|--------------------------------------------------------------------------
|
||||
|
|
||||
| Modules\Core\Auth\Services\UserOtpService's passwordless login.
|
||||
| max_attempts caps how many wrong codes a shopper can guess against ONE
|
||||
| generated code before it's invalidated outright. generation_limit/
|
||||
| generation_decay_minutes cap how often a NEW code can be requested for
|
||||
| the same email — independent of max_attempts, since generating a fresh
|
||||
| code also resets the guess count, so an attempt cap alone doesn't stop
|
||||
| an attacker from just requesting a new code every few tries. This same
|
||||
| limit is also what stands between a malicious/careless caller and
|
||||
| mail-bombing one inbox.
|
||||
|
|
||||
*/
|
||||
|
||||
'auth' => [
|
||||
'otp' => [
|
||||
'max_attempts' => 5,
|
||||
'generation_limit' => 3,
|
||||
'generation_decay_minutes' => 10,
|
||||
],
|
||||
],
|
||||
|
||||
];
|
||||
|
||||
@@ -0,0 +1,21 @@
|
||||
<?php
|
||||
|
||||
return [
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| Policy versions
|
||||
|--------------------------------------------------------------------------
|
||||
|
|
||||
| Plain version strings, bumped by whoever edits the corresponding legal
|
||||
| page — recorded alongside every consent/acceptance so a later dispute
|
||||
| ("what did the shopper actually agree to?") can be answered from the
|
||||
| order/cart itself rather than a live lookup against whatever the pages
|
||||
| say TODAY. Not tied to any CMS/database row on purpose — this stays a
|
||||
| plain config value the same way payment.php's cart_pipeline is a plain
|
||||
| cross-cutting setting, not a per-instance one.
|
||||
|
|
||||
*/
|
||||
'privacy_policy_version' => env('LEGAL_PRIVACY_POLICY_VERSION', '2026-01-01'),
|
||||
|
||||
'terms_version' => env('LEGAL_TERMS_VERSION', '2026-01-01'),
|
||||
];
|
||||
@@ -0,0 +1,28 @@
|
||||
<?php
|
||||
|
||||
use Modules\Core\Payment\Pipelines\Cart\ApplyPaymentMethodFee;
|
||||
|
||||
return [
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| Lunar cart pipeline additions
|
||||
|--------------------------------------------------------------------------
|
||||
|
|
||||
| Appended to config('lunar.cart.pipelines.cart') after ApplyShipping so
|
||||
| the selected payment method's own fee (if any) is added to the
|
||||
| shipping total before the final Calculate step sums everything up.
|
||||
|
|
||||
| This is the one thing left in this file — everything about WHICH
|
||||
| payment methods exist (driver mapping, capture_mode, statuses) moved
|
||||
| onto Modules\Core\Payment\Models\PaymentMethod's own row (see
|
||||
| docs/payments.md): that's a per-instance, merchant decision, not a
|
||||
| store-wide-singular setting, so it never belonged in config at all.
|
||||
| This pipeline registration IS genuinely cross-cutting — every store
|
||||
| using this driver gets the same cart-pipeline wiring, regardless of
|
||||
| how many payment methods it configures.
|
||||
|
|
||||
*/
|
||||
'cart_pipeline' => [
|
||||
ApplyPaymentMethodFee::class,
|
||||
],
|
||||
];
|
||||
@@ -0,0 +1,50 @@
|
||||
<?php
|
||||
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| ACS Courier credentials
|
||||
|--------------------------------------------------------------------------
|
||||
|
|
||||
| ACS requires two credential mechanisms simultaneously: an AcsApiKey
|
||||
| HTTP header (gates the REST gateway itself) and four account fields
|
||||
| (Company_ID/Company_Password/User_ID/User_Password) sent in every
|
||||
| request body. Both are supplied by ACS when your account is set up.
|
||||
|
|
||||
| Set these via environment variables — never commit real values.
|
||||
|
|
||||
| ACS_BASE_URL Root REST endpoint (unversioned, single URL for
|
||||
| every ACSAlias call).
|
||||
| ACS_API_KEY The AcsApiKey header value.
|
||||
| ACS_COMPANY_ID Company_ID body field.
|
||||
| ACS_COMPANY_PASSWORD Company_Password body field.
|
||||
| ACS_USER_ID User_ID body field.
|
||||
| ACS_USER_PASSWORD User_Password body field.
|
||||
| ACS_BILLING_CODE Your ACS credit/billing code, used for price
|
||||
| calculation and voucher creation.
|
||||
| ACS_SENDER_* Static sender details reused on every voucher.
|
||||
|
|
||||
*/
|
||||
|
||||
return [
|
||||
|
||||
'base_url' => env('ACS_BASE_URL', 'https://webservices.acscourier.net/ACSRestServices/api/ACSAutoRest'),
|
||||
|
||||
'api_key' => env('ACS_API_KEY'),
|
||||
|
||||
'company_id' => env('ACS_COMPANY_ID'),
|
||||
'company_password' => env('ACS_COMPANY_PASSWORD'),
|
||||
'user_id' => env('ACS_USER_ID'),
|
||||
'user_password' => env('ACS_USER_PASSWORD'),
|
||||
|
||||
'billing_code' => env('ACS_BILLING_CODE'),
|
||||
|
||||
'sender' => [
|
||||
'name' => env('ACS_SENDER_NAME'),
|
||||
'address' => env('ACS_SENDER_ADDRESS'),
|
||||
'zip_code' => env('ACS_SENDER_ZIP'),
|
||||
'phone' => env('ACS_SENDER_PHONE'),
|
||||
],
|
||||
|
||||
'timeout' => env('ACS_HTTP_TIMEOUT', 10),
|
||||
|
||||
];
|
||||
@@ -0,0 +1,47 @@
|
||||
<?php
|
||||
|
||||
/*
|
||||
|--------------------------------------------------------------------------
|
||||
| Box Now credentials
|
||||
|--------------------------------------------------------------------------
|
||||
|
|
||||
| Box Now uses OAuth2 client-credentials: exchange BOXNOW_CLIENT_ID /
|
||||
| BOXNOW_CLIENT_SECRET for a Bearer access token (POST /auth-sessions,
|
||||
| ~1hr expiry), then attach it as an Authorization header on every call.
|
||||
| Unlike ACS, there is no separate per-request credential body — the
|
||||
| token alone authorizes all calls once obtained.
|
||||
|
|
||||
| Set these via environment variables — never commit real values.
|
||||
|
|
||||
| BOXNOW_BASE_URL Root REST endpoint for delivery-requests/parcels.
|
||||
| BOXNOW_LOCATION_API_URL Separate, faster endpoint for origins/destinations
|
||||
| lookups (Box Now recommends this over the main
|
||||
| base URL for those two calls specifically).
|
||||
| BOXNOW_CLIENT_ID OAuth2 client id.
|
||||
| BOXNOW_CLIENT_SECRET OAuth2 client secret.
|
||||
| BOXNOW_ORIGIN_LOCATION_ID Your warehouse's Box Now locationId, used as
|
||||
| the pickup origin on every delivery request.
|
||||
| BOXNOW_SENDER_* Static sender contact details reused on every
|
||||
| delivery request.
|
||||
|
|
||||
*/
|
||||
|
||||
return [
|
||||
|
||||
'base_url' => env('BOXNOW_BASE_URL', 'https://api-production.boxnow.gr/api/v1'),
|
||||
'location_api_url' => env('BOXNOW_LOCATION_API_URL', 'https://locationapi-production.boxnow.gr/api/v1'),
|
||||
|
||||
'client_id' => env('BOXNOW_CLIENT_ID'),
|
||||
'client_secret' => env('BOXNOW_CLIENT_SECRET'),
|
||||
|
||||
'origin_location_id' => env('BOXNOW_ORIGIN_LOCATION_ID'),
|
||||
|
||||
'sender' => [
|
||||
'name' => env('BOXNOW_SENDER_NAME'),
|
||||
'email' => env('BOXNOW_SENDER_EMAIL'),
|
||||
'phone' => env('BOXNOW_SENDER_PHONE'),
|
||||
],
|
||||
|
||||
'timeout' => env('BOXNOW_HTTP_TIMEOUT', 10),
|
||||
|
||||
];
|
||||
Reference in New Issue
Block a user