Compare commits
12
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
985f53efa2 | ||
|
|
23643db996 | ||
|
|
099271e0a8 | ||
|
|
01c49485be | ||
|
|
935b1d02f9 | ||
|
|
8fdaeda0ba | ||
|
|
f416e207eb | ||
|
|
c55019d04a | ||
|
|
910d4c5df0 | ||
|
|
f1a0322d3f | ||
|
|
6025ea4304 | ||
|
|
2b8fe5764c |
@@ -4,6 +4,100 @@ All notable changes to this project will be documented in this file.
|
||||
|
||||
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
||||
|
||||
## [0.22.0] - 2026-09-25
|
||||
|
||||
### Added
|
||||
- `Modules\Core\Customer\Services\CustomerEmailChangeService` — changing an account's login
|
||||
email (core's login is passwordless, so the email IS the login): `request()` validates the new
|
||||
address is free and throttled (3 codes/10min), `confirm()` allows 5 wrong guesses per code,
|
||||
re-checks the address is still free, switches it, notifies the old address (masked new
|
||||
address), and claims guest orders for the new email. The pending change lives on the user's
|
||||
own row (`pending_email`/`pending_email_code_hash`/`pending_email_expires_at`/
|
||||
`pending_email_attempts` — new migration), the same convention as the existing OTP login
|
||||
columns, rather than the session — a code arrives by email and is often opened on a different
|
||||
device/session than the one that requested it. New core-owned mailables
|
||||
(`Auth\Mail\EmailChangeCodeMail`/`EmailChangedNoticeMail`) with default views, overridable
|
||||
per-app the same way `UserOtpMail`'s already is. Dispatches a new `Auth\Events\
|
||||
UserEmailChanged` event.
|
||||
- `Modules\Core\Customer\Services\CustomerAccountService::setRecoveryConsent()` — the account's
|
||||
standing "email me a reminder if I don't finish my order" opt-in, written to the customer's
|
||||
meta in the same shape `Checkout\Services\CheckoutService::setRecoveryConsent()` already writes
|
||||
on the cart. Skips the write when nothing changed; dispatches a new `Customer\Events\
|
||||
CustomerRecoveryConsentSet` event (also wired into the existing account-activity audit log).
|
||||
3dealer's own duplicated implementations in `CheckoutController`/`AccountController` now call
|
||||
this instead.
|
||||
- `terms_accepted_at`/`terms_version`/`privacy_policy_version` columns on `users` — recorded once,
|
||||
by a new `Auth\Listeners\RecordLegalAcceptanceForNewUser` (listening on `UserCreated`), the
|
||||
moment a genuinely new signup requests their first OTP code; never touched again for an
|
||||
existing user. Included in the User-scope privacy export (`CustomerDataProvider::
|
||||
exportForUser()`).
|
||||
- ~90 previously-unseeded `storefront.*` translation keys (login/OTP copy, account profile and
|
||||
email-change flow, order history, contact form, product custom-fields and stock-error
|
||||
messages, reviews, wishlist) added to `Localization\Services\StorefrontLabels` — these were
|
||||
already called via `__()`/`trans_choice()` across a consuming app's views with no seeded
|
||||
value at all, silently rendering the raw translation key in production.
|
||||
|
||||
### Fixed
|
||||
- `CustomerAccountService::WRITABLE_PROFILE_FIELDS` listed `vat_no`, but Lunar's `customers`
|
||||
column has been `tax_identifier` since a 2025 Lunar migration — passing `vat_no` was silently
|
||||
dropped by the allowlist, and `tax_identifier` couldn't be written through `updateProfile()` at
|
||||
all. Consuming code was working around this with a separate direct `$customer->update(...)`
|
||||
call that bypassed `CustomerProfileUpdated`'s audit trail entirely; that workaround is no
|
||||
longer needed now that the field is correctly allowlisted.
|
||||
|
||||
## [0.21.1] - 2026-09-25
|
||||
|
||||
### Changed
|
||||
- `GuestOrderClaimer` and its `UserAuthenticated` listener moved from 3dealer's own
|
||||
`App\Services`/`App\Listeners` into `Modules\Core\Customer\Services\GuestOrderClaimer` /
|
||||
`Listeners\ClaimGuestOrdersOnLogin`, registered in `CustomerServiceProvider` — attaching a
|
||||
placed guest order to an account once its billing `contact_email` case-insensitively matches
|
||||
the account's email (only ever safe right after the shopper has proved they own that email: a
|
||||
login code, or 3dealer's own email-change confirmation) was already core-appropriate logic
|
||||
with no 3dealer-specific behavior. `Account\EmailController::verify()` now calls the core
|
||||
service directly.
|
||||
|
||||
## [0.21.0] - 2026-09-25
|
||||
|
||||
### Added
|
||||
- `Modules\Core\File` — a generic, storage-backend-agnostic file registry: `Models\File` (a
|
||||
`files` table row per stored file — disk, path, original name, mime, size, a `purpose` tag,
|
||||
and a nullable polymorphic owner), `Services\FileService` (store/retrieve/download/exists/
|
||||
delete/list/`pruneUnowned`, delegating every actual byte-level operation to a
|
||||
`Contracts\FileAdapterInterface` resolved per disk — `Adapters\LocalFileAdapter` today, the
|
||||
same contextual-binding pattern `Shipping\Contracts\CarrierFulfillmentInterface` already uses
|
||||
per carrier, so a future `S3FileAdapter` is one class and one more match arm, nothing else
|
||||
changes), and `Http\Controllers\DownloadFileController` — a signed-URL-only route
|
||||
(`files.download`) any consuming app can mint a link to, serving either inline (a preview) or
|
||||
as a forced download (`?download=1`).
|
||||
- `Modules\Core\File\Http\Controllers\UploadFileController` — an abstract base for "accept an
|
||||
upload, validate it, store it via `FileService`, return its id" endpoints. Which
|
||||
extensions/sizes are acceptable is deliberately left to a concrete subclass's own
|
||||
`purpose()`/`validationRules()` overrides (ordinary server-side PHP, never trusting anything
|
||||
the request itself claims about its own limits) — a real policy decision that can differ per
|
||||
site and even per product/field, not something a shared base class or config file could
|
||||
express safely.
|
||||
- `boboko:file:prune-unowned {purpose}` — deletes every unowned `File` of a given purpose past
|
||||
its grace period (`--hours`, default 24). Generic: any consuming app schedules it once per
|
||||
purpose string it stores files under.
|
||||
- `Modules\Core\Cart\Events\CartLineAdded`/`Checkout\Events\OrderPlaced` listeners
|
||||
(`File\Listeners\AttachCustomFieldFileToCartLine`/`TransferCustomFieldFileOwnership`) that
|
||||
re-point a `File`'s ownership from unowned → the real `CartLine` once one exists, then from
|
||||
that `CartLine` → the `OrderLine` an order is placed with — so a File referenced by a product
|
||||
custom field survives the cart it originated from being cleared, without ever being copied.
|
||||
|
||||
### Changed
|
||||
- The admin order-lines table's collapsible details dropdown (next to the existing price
|
||||
breakdown) now shows a product's custom-field answers (`OrderLine.meta.custom_fields`) — a
|
||||
bordered table matching the existing price-breakdown one, with a thumbnail preview and a
|
||||
download-icon link for a file answer, resolved through `File\Services\FileService`'s signed
|
||||
route. Previously never shown anywhere in the admin.
|
||||
- 3dealer's product custom-field photo upload (`CustomFieldUploadController`), cart line meta
|
||||
(`CartController::customFieldsMeta()`), and pruning (formerly its own `PruneCustomFieldUploads`
|
||||
command) now go through `Modules\Core\File` instead of a bespoke `Crypt::encryptString({disk,
|
||||
path, name, mime})` reference scheme — a cart/order line's file answer is now just a `File`
|
||||
row's `file_id`, with `File` as the single source of truth for every other detail.
|
||||
|
||||
## [0.20.2] - 2026-09-25
|
||||
|
||||
### Changed
|
||||
|
||||
+2
-1
@@ -2,7 +2,7 @@
|
||||
"name": "boboko/core",
|
||||
"description": "Core module — authentication and shared panel behaviour",
|
||||
"type": "library",
|
||||
"version": "0.20.2",
|
||||
"version": "0.22.0",
|
||||
"autoload": {
|
||||
"psr-4": {
|
||||
"Modules\\Core\\": "src/"
|
||||
@@ -43,6 +43,7 @@
|
||||
"Modules\\Core\\Providers\\CatalogServiceProvider",
|
||||
"Modules\\Core\\Providers\\CartServiceProvider",
|
||||
"Modules\\Core\\Providers\\ReviewServiceProvider",
|
||||
"Modules\\Core\\Providers\\FileServiceProvider",
|
||||
"Modules\\Core\\Providers\\ShippingServiceProvider",
|
||||
"Modules\\Core\\Providers\\OrderServiceProvider",
|
||||
"Modules\\Core\\Providers\\PrivacyServiceProvider"
|
||||
|
||||
@@ -125,6 +125,17 @@ return [
|
||||
'generation_limit' => 3,
|
||||
'generation_decay_minutes' => 10,
|
||||
],
|
||||
|
||||
// Modules\Core\Customer\Services\CustomerEmailChangeService — same
|
||||
// shape/reasoning as auth.otp above, independent limits since this
|
||||
// is a separate flow (changing an existing account's login email,
|
||||
// not logging in).
|
||||
'email_change' => [
|
||||
'max_attempts' => 5,
|
||||
'generation_limit' => 3,
|
||||
'generation_decay_minutes' => 10,
|
||||
'expiry_minutes' => 10,
|
||||
],
|
||||
],
|
||||
|
||||
];
|
||||
|
||||
@@ -0,0 +1,50 @@
|
||||
<?php
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
|
||||
/**
|
||||
* A generic, storage-backend-agnostic file registry — Modules\Core\File\
|
||||
* Services\FileService's own backing table. `disk`/`path` are whatever
|
||||
* Laravel's Storage facade already understands (local, s3, ...); this
|
||||
* table adds what Flysystem itself has no concept of: who a file
|
||||
* belongs to, why it was uploaded, and whether anything still needs it.
|
||||
*
|
||||
* `owner_type`/`owner_id` are nullable — a file can (and, for a product
|
||||
* custom-field photo, always does) exist before anything owns it yet: a
|
||||
* shopper picks a photo on the product page and it's uploaded immediately
|
||||
* (see 3dealer's CustomFieldUploadController), well before add-to-cart
|
||||
* gives it a CartLine to belong to. FileService::attachOwner() re-points
|
||||
* these columns once an owner exists, rather than creating a second row
|
||||
* for the same physical file.
|
||||
*
|
||||
* `purpose` (e.g. 'custom-field-upload') lets one table serve unrelated
|
||||
* future features without collision — FileService itself has no
|
||||
* knowledge of what a purpose means, callers scope their own queries by
|
||||
* it.
|
||||
*/
|
||||
return new class extends Migration
|
||||
{
|
||||
public function up(): void
|
||||
{
|
||||
Schema::create('files', function (Blueprint $table) {
|
||||
$table->id();
|
||||
$table->string('disk');
|
||||
$table->string('path');
|
||||
$table->string('original_name')->nullable();
|
||||
$table->string('mime')->nullable();
|
||||
$table->unsignedBigInteger('size')->nullable();
|
||||
$table->string('purpose');
|
||||
$table->nullableMorphs('owner');
|
||||
$table->timestamps();
|
||||
|
||||
$table->index(['purpose', 'owner_type', 'owner_id']);
|
||||
});
|
||||
}
|
||||
|
||||
public function down(): void
|
||||
{
|
||||
Schema::dropIfExists('files');
|
||||
}
|
||||
};
|
||||
@@ -0,0 +1,37 @@
|
||||
<?php
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
|
||||
/**
|
||||
* Which terms/privacy policy version an account was created under — the
|
||||
* storefront login page shows a notice ("By continuing, you accept the
|
||||
* Terms of Use and have read the Privacy Policy") that a new signup
|
||||
* implicitly agrees to just by requesting an OTP code, so this is
|
||||
* recorded the moment Modules\Core\Auth\Services\UserOtpService::
|
||||
* generateAndSend()'s firstOrCreate() actually creates the row — never
|
||||
* for an existing user, whose original acceptance (whatever version was
|
||||
* live at the time) must not be silently overwritten by a later config
|
||||
* value. Nullable: every user created before this migration has none of
|
||||
* the three, which is the honest answer ("we don't know what they saw"),
|
||||
* not something to backfill with today's config values.
|
||||
*/
|
||||
return new class extends Migration
|
||||
{
|
||||
public function up(): void
|
||||
{
|
||||
Schema::table('users', function (Blueprint $table) {
|
||||
$table->timestamp('terms_accepted_at')->nullable()->after('otp_attempts');
|
||||
$table->string('terms_version')->nullable()->after('terms_accepted_at');
|
||||
$table->string('privacy_policy_version')->nullable()->after('terms_version');
|
||||
});
|
||||
}
|
||||
|
||||
public function down(): void
|
||||
{
|
||||
Schema::table('users', function (Blueprint $table) {
|
||||
$table->dropColumn(['terms_accepted_at', 'terms_version', 'privacy_policy_version']);
|
||||
});
|
||||
}
|
||||
};
|
||||
@@ -0,0 +1,39 @@
|
||||
<?php
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
|
||||
/**
|
||||
* Backs Modules\Core\Customer\Services\CustomerEmailChangeService — the
|
||||
* pending new-email change lives on the user's own row, same convention
|
||||
* as the existing otp_code/otp_expires_at/otp_attempts columns (Auth\
|
||||
* Services\UserOtpService), rather than the session: a change requested
|
||||
* on one device/session must still be confirmable from another (a code
|
||||
* arrives by email, which is often opened somewhere else entirely), and
|
||||
* a request-scoped session can't survive that.
|
||||
*/
|
||||
return new class extends Migration
|
||||
{
|
||||
public function up(): void
|
||||
{
|
||||
Schema::table('users', function (Blueprint $table) {
|
||||
$table->string('pending_email')->nullable()->after('privacy_policy_version');
|
||||
$table->string('pending_email_code_hash')->nullable()->after('pending_email');
|
||||
$table->timestamp('pending_email_expires_at')->nullable()->after('pending_email_code_hash');
|
||||
$table->unsignedTinyInteger('pending_email_attempts')->default(0)->after('pending_email_expires_at');
|
||||
});
|
||||
}
|
||||
|
||||
public function down(): void
|
||||
{
|
||||
Schema::table('users', function (Blueprint $table) {
|
||||
$table->dropColumn([
|
||||
'pending_email',
|
||||
'pending_email_code_hash',
|
||||
'pending_email_expires_at',
|
||||
'pending_email_attempts',
|
||||
]);
|
||||
});
|
||||
}
|
||||
};
|
||||
@@ -0,0 +1,17 @@
|
||||
@extends('emails.layout')
|
||||
|
||||
@section('content')
|
||||
<p style="margin: 0 0 24px 0;">Use the code below to confirm this address as your account's new email.</p>
|
||||
|
||||
<table role="presentation" cellpadding="0" cellspacing="0" border="0" width="100%" style="margin: 0 0 24px 0; background-color: #f7f6f5; border-radius: 8px;">
|
||||
<tr>
|
||||
<td style="padding: 16px 20px; text-align: center; font-size: 28px; font-weight: bold; letter-spacing: 0.25rem;">
|
||||
{{ $code }}
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
<p style="margin: 0 0 16px 0;">This code expires in 10 minutes.</p>
|
||||
|
||||
<p style="margin: 0;">If you didn't request this change, you can ignore this email — nothing will change.</p>
|
||||
@endsection
|
||||
@@ -0,0 +1,9 @@
|
||||
@extends('emails.layout')
|
||||
|
||||
@section('content')
|
||||
<p style="margin: 0 0 16px 0;">Your account's login email was changed to <strong>{{ $maskedEmail }}</strong>.</p>
|
||||
|
||||
<p style="margin: 0 0 24px 0;">From now on, login codes will be sent to the new address.</p>
|
||||
|
||||
<p style="margin: 0;">If you didn't make this change, please contact us right away.</p>
|
||||
@endsection
|
||||
@@ -0,0 +1,19 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\Auth\Events;
|
||||
|
||||
use Illuminate\Contracts\Auth\Authenticatable;
|
||||
|
||||
/**
|
||||
* Dispatched by Customer\Services\CustomerEmailChangeService::confirm()
|
||||
* once a login-email change actually takes effect — $oldEmail is what the
|
||||
* account's login used to be, already overwritten on $user by the time
|
||||
* this fires.
|
||||
*/
|
||||
class UserEmailChanged
|
||||
{
|
||||
public function __construct(
|
||||
public readonly Authenticatable $user,
|
||||
public readonly string $oldEmail,
|
||||
) {}
|
||||
}
|
||||
@@ -0,0 +1,28 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\Auth\Listeners;
|
||||
|
||||
use Modules\Core\Auth\Events\UserCreated;
|
||||
|
||||
/**
|
||||
* The storefront login page shows a terms/privacy notice ("By continuing,
|
||||
* you accept the Terms of Use and have read the Privacy Policy") that
|
||||
* requesting an OTP code implicitly accepts — recorded once, right here,
|
||||
* for a genuinely new signup only (UserCreated fires exactly once per
|
||||
* user, from Auth\Services\UserOtpService::generateAndSend()'s own
|
||||
* wasRecentlyCreated check). An existing user's original acceptance
|
||||
* (whatever version was live when THEY signed up) must never be
|
||||
* overwritten by whatever config('legal.*') says today, which is exactly
|
||||
* why this only ever runs from UserCreated and nowhere else.
|
||||
*/
|
||||
class RecordLegalAcceptanceForNewUser
|
||||
{
|
||||
public function handle(UserCreated $event): void
|
||||
{
|
||||
$event->user->forceFill([
|
||||
'terms_accepted_at' => now(),
|
||||
'terms_version' => config('legal.terms_version'),
|
||||
'privacy_policy_version' => config('legal.privacy_policy_version'),
|
||||
])->save();
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,31 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\Auth\Mail;
|
||||
|
||||
use Illuminate\Mail\Mailable;
|
||||
use Illuminate\Mail\Mailables\Content;
|
||||
use Illuminate\Mail\Mailables\Envelope;
|
||||
|
||||
/**
|
||||
* Sent to the NEW address a shopper is trying to switch their login email
|
||||
* to (Customer\Services\CustomerEmailChangeService::request()) — proves
|
||||
* they can actually receive mail there before the switch takes effect.
|
||||
* View overridable per-app the same way UserOtpMail's is (resources/
|
||||
* views/vendor/core/auth/mail/email-change-code.blade.php).
|
||||
*/
|
||||
class EmailChangeCodeMail extends Mailable
|
||||
{
|
||||
public function __construct(
|
||||
public readonly string $code,
|
||||
) {}
|
||||
|
||||
public function envelope(): Envelope
|
||||
{
|
||||
return new Envelope(subject: 'Confirm your new email address');
|
||||
}
|
||||
|
||||
public function content(): Content
|
||||
{
|
||||
return new Content(view: 'core::auth.mail.email-change-code');
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\Auth\Mail;
|
||||
|
||||
use Illuminate\Mail\Mailable;
|
||||
use Illuminate\Mail\Mailables\Content;
|
||||
use Illuminate\Mail\Mailables\Envelope;
|
||||
|
||||
/**
|
||||
* Sent to the OLD address once a login-email change actually takes
|
||||
* effect (Customer\Services\CustomerEmailChangeService::confirm()) — lets
|
||||
* the previous owner notice if someone else changed it from a hijacked
|
||||
* session. Shows the new address masked (first character + domain only),
|
||||
* never the full new address — this notice's whole point is alerting the
|
||||
* OLD owner, not handing them the new address outright. View overridable
|
||||
* per-app the same way UserOtpMail's is (resources/views/vendor/core/
|
||||
* auth/mail/email-changed-notice.blade.php).
|
||||
*/
|
||||
class EmailChangedNoticeMail extends Mailable
|
||||
{
|
||||
public readonly string $maskedEmail;
|
||||
|
||||
public function __construct(string $newEmail)
|
||||
{
|
||||
[$local, $domain] = explode('@', $newEmail, 2);
|
||||
|
||||
$this->maskedEmail = mb_substr($local, 0, 1).'•••@'.$domain;
|
||||
}
|
||||
|
||||
public function envelope(): Envelope
|
||||
{
|
||||
return new Envelope(subject: 'Your account email was changed');
|
||||
}
|
||||
|
||||
public function content(): Content
|
||||
{
|
||||
return new Content(view: 'core::auth.mail.email-changed-notice');
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,25 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\Customer\Events;
|
||||
|
||||
use Illuminate\Contracts\Auth\Authenticatable;
|
||||
use Modules\Core\Customer\Models\Customer;
|
||||
|
||||
/**
|
||||
* Customer-side sibling of Checkout\Events\RecoveryConsentSet — dispatched
|
||||
* by CustomerAccountService::setRecoveryConsent() every time the account's
|
||||
* standing promotional/abandoned-cart-recovery opt-in changes, including
|
||||
* an explicit opt-OUT, not just an opt-in. $consent is the new value,
|
||||
* already written to Customer::meta by the time this fires. Distinct from
|
||||
* RecoveryConsentSet, which fires for the current CART's own opt-in
|
||||
* (CheckoutService::setRecoveryConsent()) — the two write the same meta
|
||||
* shape onto different models and can fire independently of each other.
|
||||
*/
|
||||
class CustomerRecoveryConsentSet
|
||||
{
|
||||
public function __construct(
|
||||
public readonly Customer $customer,
|
||||
public readonly bool $consent,
|
||||
public readonly Authenticatable $causer,
|
||||
) {}
|
||||
}
|
||||
@@ -0,0 +1,19 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\Customer\Exceptions;
|
||||
|
||||
use RuntimeException;
|
||||
|
||||
/**
|
||||
* Thrown by Modules\Core\Customer\Services\CustomerEmailChangeService when
|
||||
* the requested new email already belongs to a different user — checked
|
||||
* both up front (request()) and again at confirm() time, since someone
|
||||
* else could sign up with that address in the window between the two.
|
||||
*/
|
||||
class EmailAlreadyTakenException extends RuntimeException
|
||||
{
|
||||
public function __construct()
|
||||
{
|
||||
parent::__construct('That email address is already in use.');
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,21 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\Customer\Exceptions;
|
||||
|
||||
use RuntimeException;
|
||||
|
||||
/**
|
||||
* Thrown by Modules\Core\Customer\Services\CustomerEmailChangeService::
|
||||
* confirm() for a wrong, expired, or already-burned (too many wrong
|
||||
* guesses) code — deliberately one exception for all three, the same way
|
||||
* Auth\Services\UserOtpService::validate() collapses them into a single
|
||||
* null return, so a caller can't distinguish "wrong code" from "no
|
||||
* pending change at all" and use that to probe for one.
|
||||
*/
|
||||
class InvalidEmailChangeCodeException extends RuntimeException
|
||||
{
|
||||
public function __construct()
|
||||
{
|
||||
parent::__construct('That code is invalid or has expired.');
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,24 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\Customer\Listeners;
|
||||
|
||||
use Modules\Core\Auth\Events\UserAuthenticated;
|
||||
use Modules\Core\Customer\Services\GuestOrderClaimer;
|
||||
|
||||
/**
|
||||
* Registered from Providers\CustomerServiceProvider — UserAuthenticated
|
||||
* only fires after a valid login code, which is what makes matching
|
||||
* placed guest orders by email safe (see GuestOrderClaimer's own
|
||||
* docblock).
|
||||
*/
|
||||
class ClaimGuestOrdersOnLogin
|
||||
{
|
||||
public function __construct(
|
||||
private readonly GuestOrderClaimer $claimer,
|
||||
) {}
|
||||
|
||||
public function handle(UserAuthenticated $event): void
|
||||
{
|
||||
$this->claimer->claim($event->user);
|
||||
}
|
||||
}
|
||||
@@ -8,6 +8,7 @@ use Modules\Core\Customer\Events\CustomerAddressCreated;
|
||||
use Modules\Core\Customer\Events\CustomerAddressDeleted;
|
||||
use Modules\Core\Customer\Events\CustomerAddressUpdated;
|
||||
use Modules\Core\Customer\Events\CustomerProfileUpdated;
|
||||
use Modules\Core\Customer\Events\CustomerRecoveryConsentSet;
|
||||
use Modules\Core\Logging\ActivityLogService;
|
||||
|
||||
/**
|
||||
@@ -62,4 +63,21 @@ class LogCustomerAccountActivity implements ShouldQueue
|
||||
$event->causer,
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* CustomerRecoveryConsentSet carries only the new value, not a
|
||||
* before/after snapshot the way CustomerProfileUpdated does — but
|
||||
* CustomerAccountService::setRecoveryConsent() only ever dispatches it
|
||||
* once the value has actually changed, so "old" is trivially the
|
||||
* opposite of $event->consent.
|
||||
*/
|
||||
public function handleRecoveryConsentSet(CustomerRecoveryConsentSet $event): void
|
||||
{
|
||||
$this->activityLog->updated(
|
||||
$event->customer,
|
||||
['recovery_consent' => ! $event->consent],
|
||||
['recovery_consent' => $event->consent],
|
||||
$event->causer,
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -66,6 +66,9 @@ class CustomerDataProvider implements PersonalDataProvider
|
||||
'id' => $user->id,
|
||||
'name' => $user->name,
|
||||
'email' => $user->email,
|
||||
'terms_accepted_at' => $user->terms_accepted_at,
|
||||
'terms_version' => $user->terms_version,
|
||||
'privacy_policy_version' => $user->privacy_policy_version,
|
||||
'customers' => $user->customers->map(fn (Customer $customer) => [
|
||||
'id' => $customer->id,
|
||||
'company_name' => $customer->company_name,
|
||||
|
||||
@@ -13,6 +13,7 @@ use Modules\Core\Customer\Events\CustomerAddressCreated;
|
||||
use Modules\Core\Customer\Events\CustomerAddressDeleted;
|
||||
use Modules\Core\Customer\Events\CustomerAddressUpdated;
|
||||
use Modules\Core\Customer\Events\CustomerProfileUpdated;
|
||||
use Modules\Core\Customer\Events\CustomerRecoveryConsentSet;
|
||||
use Modules\Core\Customer\Exceptions\AddressNotFoundException;
|
||||
use Modules\Core\Customer\Exceptions\OrderNotFoundException;
|
||||
use Modules\Core\Customer\Models\Customer;
|
||||
@@ -72,7 +73,7 @@ class CustomerAccountService
|
||||
];
|
||||
|
||||
private const WRITABLE_PROFILE_FIELDS = [
|
||||
'title', 'first_name', 'last_name', 'company_name', 'vat_no',
|
||||
'title', 'first_name', 'last_name', 'company_name', 'tax_identifier',
|
||||
];
|
||||
|
||||
public function customer(Authenticatable $user): ?Customer
|
||||
@@ -235,6 +236,43 @@ class CustomerAccountService
|
||||
return $customer;
|
||||
}
|
||||
|
||||
/**
|
||||
* The account's standing "email me a reminder if I don't finish my
|
||||
* order" opt-in — same meta shape Checkout\Services\CheckoutService::
|
||||
* setRecoveryConsent() writes on the current CART (recovery_consent,
|
||||
* recovery_consent_at, recovery_consent_policy_version), written here
|
||||
* onto the CUSTOMER instead, so it survives across carts/sessions as a
|
||||
* standing account preference. The two are independent: opting out on
|
||||
* the customer doesn't retroactively change a cart already opted in,
|
||||
* and vice versa — a caller that wants both kept in sync (e.g. 3dealer
|
||||
* applying a customer's standing preference to the current cart too)
|
||||
* calls both services itself.
|
||||
*
|
||||
* A no-op (no write, no event) when $consent already matches what's
|
||||
* stored — unlike updateProfile()'s address/profile writes, which
|
||||
* always write and dispatch even when nothing actually changed.
|
||||
*/
|
||||
public function setRecoveryConsent(Authenticatable $user, bool $consent): Customer
|
||||
{
|
||||
$customer = $this->customerOrFail($user);
|
||||
|
||||
if ((bool) data_get($customer->meta, 'recovery_consent') === $consent) {
|
||||
return $customer;
|
||||
}
|
||||
|
||||
$customer->meta = [
|
||||
...($customer->meta?->toArray() ?? []),
|
||||
'recovery_consent' => $consent,
|
||||
'recovery_consent_at' => $consent ? now()->toIso8601String() : null,
|
||||
'recovery_consent_policy_version' => $consent ? config('legal.privacy_policy_version') : null,
|
||||
];
|
||||
$customer->save();
|
||||
|
||||
Event::dispatch(new CustomerRecoveryConsentSet($customer, $consent, $user));
|
||||
|
||||
return $customer;
|
||||
}
|
||||
|
||||
/**
|
||||
* @throws LogicException if $user has no paired Customer at all —
|
||||
* distinct from AddressNotFoundException/OrderNotFoundException
|
||||
|
||||
@@ -0,0 +1,163 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\Customer\Services;
|
||||
|
||||
use Illuminate\Contracts\Auth\Authenticatable;
|
||||
use Illuminate\Support\Facades\DB;
|
||||
use Illuminate\Support\Facades\Event;
|
||||
use Illuminate\Support\Facades\Hash;
|
||||
use Illuminate\Support\Facades\Mail;
|
||||
use Illuminate\Support\Facades\RateLimiter;
|
||||
use Modules\Core\Auth\Events\UserEmailChanged;
|
||||
use Modules\Core\Auth\Exceptions\OtpThrottledException;
|
||||
use Modules\Core\Auth\Mail\EmailChangeCodeMail;
|
||||
use Modules\Core\Auth\Mail\EmailChangedNoticeMail;
|
||||
use Modules\Core\Customer\Exceptions\EmailAlreadyTakenException;
|
||||
use Modules\Core\Customer\Exceptions\InvalidEmailChangeCodeException;
|
||||
|
||||
/**
|
||||
* Changing an account's login email — core's login is passwordless, so
|
||||
* the email IS the login, and it only ever changes once the shopper has
|
||||
* proved they can receive mail at the new address (a typo can never lock
|
||||
* them out of their own account). The pending change (new address, a
|
||||
* hash of the code, expiry, wrong-guess count) lives on the user's own
|
||||
* row (see the migration adding pending_email/pending_email_code_hash/
|
||||
* pending_email_expires_at/pending_email_attempts) — the same convention
|
||||
* Auth\Services\UserOtpService's otp_code/otp_expires_at/otp_attempts
|
||||
* already use — rather than the session, since a code arrives by email
|
||||
* and is often opened on a different device/session than the one that
|
||||
* requested it; a session-scoped pending change couldn't be confirmed
|
||||
* from there at all.
|
||||
*
|
||||
* Two independent throttles, both configured under core.auth.email_change
|
||||
* (same shape/reasoning as core.auth.otp): max_attempts caps wrong
|
||||
* guesses against ONE code; generation_limit/generation_decay_minutes cap
|
||||
* how often a NEW code can be requested at all.
|
||||
*/
|
||||
class CustomerEmailChangeService
|
||||
{
|
||||
/**
|
||||
* @throws OtpThrottledException if this account has requested too
|
||||
* many codes within core.auth.email_change.generation_decay_minutes
|
||||
* @throws EmailAlreadyTakenException if $newEmail already belongs to
|
||||
* a different user
|
||||
*/
|
||||
public function request(Authenticatable $user, string $newEmail): void
|
||||
{
|
||||
$newEmail = strtolower(trim($newEmail));
|
||||
|
||||
if ($user->newQuery()->where('email', $newEmail)->whereKeyNot($user->getKey())->exists()) {
|
||||
throw new EmailAlreadyTakenException;
|
||||
}
|
||||
|
||||
$limiterKey = $this->generationLimiterKey($user);
|
||||
$maxGenerations = (int) config('core.auth.email_change.generation_limit', 3);
|
||||
|
||||
if (RateLimiter::tooManyAttempts($limiterKey, $maxGenerations)) {
|
||||
throw new OtpThrottledException(RateLimiter::availableIn($limiterKey));
|
||||
}
|
||||
|
||||
RateLimiter::hit($limiterKey, (int) config('core.auth.email_change.generation_decay_minutes', 10) * 60);
|
||||
|
||||
$code = str_pad((string) random_int(0, 999999), 6, '0', STR_PAD_LEFT);
|
||||
|
||||
$user->forceFill([
|
||||
'pending_email' => $newEmail,
|
||||
'pending_email_code_hash' => Hash::make($code),
|
||||
'pending_email_expires_at' => now()->addMinutes((int) config('core.auth.email_change.expiry_minutes', 10)),
|
||||
'pending_email_attempts' => 0,
|
||||
])->save();
|
||||
|
||||
Mail::to($newEmail)->send(new EmailChangeCodeMail($code));
|
||||
}
|
||||
|
||||
/**
|
||||
* @throws InvalidEmailChangeCodeException for a wrong, expired, or
|
||||
* already-burned (too many wrong guesses) code, or when there is no
|
||||
* pending change at all
|
||||
* @throws EmailAlreadyTakenException if someone else has since signed
|
||||
* up with the pending address, in the window between request() and
|
||||
* confirm()
|
||||
*/
|
||||
public function confirm(Authenticatable $user, string $code): void
|
||||
{
|
||||
$model = $user::class;
|
||||
|
||||
// lockForUpdate() + a transaction make the read-check-increment-save
|
||||
// below atomic across concurrent requests — same reasoning as
|
||||
// Auth\Services\UserOtpService::validate(), which this mirrors.
|
||||
$valid = DB::transaction(function () use ($model, $user, $code) {
|
||||
/** @var Authenticatable $locked */
|
||||
$locked = $model::whereKey($user->getKey())->lockForUpdate()->first();
|
||||
|
||||
if (! $locked->pending_email
|
||||
|| ! $locked->pending_email_code_hash
|
||||
|| ! $locked->pending_email_expires_at
|
||||
|| now()->isAfter($locked->pending_email_expires_at)) {
|
||||
return false;
|
||||
}
|
||||
|
||||
if (! Hash::check($code, $locked->pending_email_code_hash)) {
|
||||
$locked->pending_email_attempts++;
|
||||
|
||||
if ($locked->pending_email_attempts >= (int) config('core.auth.email_change.max_attempts', 5)) {
|
||||
$locked->pending_email_code_hash = null;
|
||||
$locked->pending_email_expires_at = null;
|
||||
$locked->pending_email_attempts = 0;
|
||||
}
|
||||
|
||||
$locked->save();
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
return true;
|
||||
});
|
||||
|
||||
if (! $valid) {
|
||||
throw new InvalidEmailChangeCodeException;
|
||||
}
|
||||
|
||||
$user->refresh();
|
||||
$newEmail = $user->pending_email;
|
||||
|
||||
// Someone may have signed up with this address since request() ran.
|
||||
if ($user->newQuery()->where('email', $newEmail)->whereKeyNot($user->getKey())->exists()) {
|
||||
$user->forceFill([
|
||||
'pending_email' => null,
|
||||
'pending_email_code_hash' => null,
|
||||
'pending_email_expires_at' => null,
|
||||
'pending_email_attempts' => 0,
|
||||
])->save();
|
||||
|
||||
throw new EmailAlreadyTakenException;
|
||||
}
|
||||
|
||||
$oldEmail = $user->email;
|
||||
|
||||
$user->forceFill([
|
||||
'email' => $newEmail,
|
||||
'email_verified_at' => now(),
|
||||
'pending_email' => null,
|
||||
'pending_email_code_hash' => null,
|
||||
'pending_email_expires_at' => null,
|
||||
'pending_email_attempts' => 0,
|
||||
])->save();
|
||||
|
||||
RateLimiter::clear($this->generationLimiterKey($user));
|
||||
|
||||
// Lets the previous owner notice if someone else changed it from a
|
||||
// hijacked session.
|
||||
Mail::to($oldEmail)->send(new EmailChangedNoticeMail($newEmail));
|
||||
|
||||
// The code just proved they own the new address too.
|
||||
app(GuestOrderClaimer::class)->claim($user);
|
||||
|
||||
Event::dispatch(new UserEmailChanged($user, $oldEmail));
|
||||
}
|
||||
|
||||
private function generationLimiterKey(Authenticatable $user): string
|
||||
{
|
||||
return 'email-change:'.$user->getKey();
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,41 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\Customer\Services;
|
||||
|
||||
use Illuminate\Contracts\Auth\Authenticatable;
|
||||
use Lunar\Base\LunarUser;
|
||||
use Lunar\Models\Order;
|
||||
|
||||
/**
|
||||
* Attaches placed guest orders to an account when their billing email
|
||||
* matches the account's email, case-insensitively. Only ever called right
|
||||
* after the shopper has proved they own that email — a login code
|
||||
* (Auth\Events\UserAuthenticated), or the code confirming an email change
|
||||
* (a consuming app's own email-change flow, e.g. 3dealer's Account\
|
||||
* EmailController::verify()) — which is what makes matching on email safe.
|
||||
*
|
||||
* Only orders with no customer_id AND no user_id are touched: an order
|
||||
* already attached to any account (guest or otherwise) is left alone.
|
||||
*/
|
||||
class GuestOrderClaimer
|
||||
{
|
||||
public function claim(Authenticatable&LunarUser $user): int
|
||||
{
|
||||
$customer = $user->latestCustomer();
|
||||
|
||||
if (! $customer || ! $user->email) {
|
||||
return 0;
|
||||
}
|
||||
|
||||
return Order::query()
|
||||
->whereNotNull('placed_at')
|
||||
->whereNull('customer_id')
|
||||
->whereNull('user_id')
|
||||
->whereHas('billingAddress', fn ($query) => $query
|
||||
->whereRaw('lower(contact_email) = ?', [strtolower($user->email)]))
|
||||
->update([
|
||||
'customer_id' => $customer->id,
|
||||
'user_id' => $user->id,
|
||||
]);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,48 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\File\Adapters;
|
||||
|
||||
use Illuminate\Contracts\Filesystem\Filesystem;
|
||||
use Illuminate\Http\UploadedFile;
|
||||
use Modules\Core\File\Contracts\FileAdapterInterface;
|
||||
use Symfony\Component\HttpFoundation\StreamedResponse;
|
||||
|
||||
/**
|
||||
* Wraps Laravel's own 'local' Storage disk — see FileAdapterInterface's
|
||||
* own docblock for why this exists as a named adapter rather than every
|
||||
* caller reaching for Storage::disk('local') directly: swapping to a
|
||||
* different backend later (S3FileAdapter, say) means adding one class and
|
||||
* one contextual-binding entry, touching nothing that already uses
|
||||
* FileService.
|
||||
*/
|
||||
class LocalFileAdapter implements FileAdapterInterface
|
||||
{
|
||||
public function __construct(
|
||||
private readonly Filesystem $disk,
|
||||
) {}
|
||||
|
||||
public function store(UploadedFile $file, string $directory): string
|
||||
{
|
||||
return $this->disk->putFile($directory, $file);
|
||||
}
|
||||
|
||||
public function exists(string $path): bool
|
||||
{
|
||||
return $this->disk->exists($path);
|
||||
}
|
||||
|
||||
public function delete(string $path): void
|
||||
{
|
||||
$this->disk->delete($path);
|
||||
}
|
||||
|
||||
public function retrieve(string $path, ?string $name = null): StreamedResponse
|
||||
{
|
||||
return $this->disk->response($path, $name);
|
||||
}
|
||||
|
||||
public function download(string $path, ?string $name = null): StreamedResponse
|
||||
{
|
||||
return $this->disk->download($path, $name);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,32 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\File\Commands;
|
||||
|
||||
use Illuminate\Console\Command;
|
||||
use Modules\Core\File\Services\FileService;
|
||||
|
||||
/**
|
||||
* Generic wrapper around FileService::pruneUnowned() — see that method's
|
||||
* own docblock for what "unowned" means and why the grace period exists.
|
||||
* Any caller (3dealer's product custom-field photo uploads today, some
|
||||
* other future upload feature tomorrow, in this app or another consuming
|
||||
* app) schedules this once per purpose string it stores files under; this
|
||||
* command itself has no opinion about what any given purpose means.
|
||||
*/
|
||||
class PruneUnownedFilesCommand extends Command
|
||||
{
|
||||
protected $signature = 'boboko:file:prune-unowned {purpose} {--hours=24 : Only delete unowned files older than this}';
|
||||
|
||||
protected $description = 'Delete unowned files of a given purpose past their grace period';
|
||||
|
||||
public function handle(FileService $files): int
|
||||
{
|
||||
$purpose = $this->argument('purpose');
|
||||
|
||||
$deleted = $files->pruneUnowned($purpose, now()->subHours((int) $this->option('hours')));
|
||||
|
||||
$this->info("Deleted {$deleted} unowned file(s) of purpose \"{$purpose}\".");
|
||||
|
||||
return self::SUCCESS;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,46 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\File\Contracts;
|
||||
|
||||
use Illuminate\Http\UploadedFile;
|
||||
use Symfony\Component\HttpFoundation\StreamedResponse;
|
||||
|
||||
/**
|
||||
* One storage backend's actual byte-level operations — a disk name (see
|
||||
* Modules\Core\File\Models\File::$disk) resolves to exactly one
|
||||
* implementation of this via Modules\Core\File\Services\FileService's own
|
||||
* contextual binding (see Providers\FileServiceProvider), the same
|
||||
* pattern Shipping\Contracts\CarrierFulfillmentInterface uses to pick an
|
||||
* AcsFulfillmentService/BoxNowFulfillmentService per carrier. FileService
|
||||
* itself never touches a disk directly — every backend-specific detail
|
||||
* (a local path, an S3 bucket/region, ...) lives entirely inside one
|
||||
* adapter, so adding a new backend never touches FileService or any of
|
||||
* its callers.
|
||||
*/
|
||||
interface FileAdapterInterface
|
||||
{
|
||||
/**
|
||||
* Stores the file under $directory, returning the path to record on
|
||||
* the File row (Models\File::$path) — backend-specific (a relative
|
||||
* local path, an S3 object key, ...), meaningful only to this same
|
||||
* adapter.
|
||||
*/
|
||||
public function store(UploadedFile $file, string $directory): string;
|
||||
|
||||
public function exists(string $path): bool;
|
||||
|
||||
public function delete(string $path): void;
|
||||
|
||||
/**
|
||||
* Streams the file at $path straight to the browser, inline (the
|
||||
* browser renders/previews it directly rather than prompting to save).
|
||||
*/
|
||||
public function retrieve(string $path, ?string $name = null): StreamedResponse;
|
||||
|
||||
/**
|
||||
* Same bytes as retrieve(), but as a forced attachment — the browser
|
||||
* always prompts to save, even for a type it could otherwise preview
|
||||
* (an image inline in a new tab).
|
||||
*/
|
||||
public function download(string $path, ?string $name = null): StreamedResponse;
|
||||
}
|
||||
@@ -0,0 +1,45 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\File\Http\Controllers;
|
||||
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Routing\Controller;
|
||||
use Modules\Core\File\Models\File;
|
||||
use Modules\Core\File\Services\FileService;
|
||||
use Symfony\Component\HttpFoundation\StreamedResponse;
|
||||
|
||||
/**
|
||||
* Streams a File's bytes straight to the browser — inline by default (a
|
||||
* browser-previewable type like an image opens/displays directly), or as
|
||||
* a forced download with ?download=1 (e.g. an explicit "Download" button
|
||||
* distinct from a thumbnail/preview link pointing at the same file). Only
|
||||
* reachable via a short-lived signed URL — same auth model as
|
||||
* Modules\Core\Shipping\Http\Controllers\DownloadShipmentLabelController
|
||||
* (a valid signature IS the auth check, no separate staff/customer
|
||||
* session check here) — so any caller that can mint a signed URL to this
|
||||
* route (the storefront's own custom-field upload flow, or the admin
|
||||
* order-line display) can hand a viewer a working link without this
|
||||
* controller knowing anything about who they are or why they're allowed
|
||||
* to see this particular file.
|
||||
*
|
||||
* Looks the File up manually from a plain {file} id rather than relying
|
||||
* on implicit route-model-binding — registered via loadRoutesFrom() with
|
||||
* no middleware group (see Providers\FileServiceProvider::boot()), so
|
||||
* SubstituteBindings never runs and a type-hinted File parameter would
|
||||
* silently resolve to an empty, non-existent model instead of 404ing.
|
||||
*/
|
||||
class DownloadFileController extends Controller
|
||||
{
|
||||
public function __invoke(Request $request, int $file, FileService $files): StreamedResponse
|
||||
{
|
||||
if (! $request->hasValidSignature()) {
|
||||
abort(401);
|
||||
}
|
||||
|
||||
$file = File::findOrFail($file);
|
||||
|
||||
abort_unless($files->exists($file), 404);
|
||||
|
||||
return $request->boolean('download') ? $files->download($file) : $files->retrieve($file);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,76 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\File\Http\Controllers;
|
||||
|
||||
use Illuminate\Http\JsonResponse;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Routing\Controller;
|
||||
use Illuminate\Support\Facades\Validator;
|
||||
use Modules\Core\File\Services\FileService;
|
||||
|
||||
/**
|
||||
* The generic "accept an upload, validate it, store it via FileService,
|
||||
* return its id" flow — what varies per use case (which extensions/sizes
|
||||
* are acceptable) is deliberately NOT configurable here, and NEVER trusts
|
||||
* anything the request itself claims about its own limits: a client could
|
||||
* simply lie about them. purpose()/validationRules() are protected hooks
|
||||
* a concrete subclass overrides instead — an ordinary PHP method a caller
|
||||
* writes once per upload policy, not request input, so the actual limit
|
||||
* enforced is always whatever server-side code says it is. Different
|
||||
* products can even need different limits (a 3D-print reference photo
|
||||
* vs. a video upload, say) — that's still a subclass's own store()
|
||||
* override deciding which rule set applies to a given request, not
|
||||
* something this base class or a shared config file could express.
|
||||
*/
|
||||
abstract class UploadFileController extends Controller
|
||||
{
|
||||
/**
|
||||
* The File row's `purpose` tag (see Models\File) — also the storage
|
||||
* directory it lands under (FileService::store()'s single $purpose
|
||||
* param doubles as both).
|
||||
*/
|
||||
abstract protected function purpose(): string;
|
||||
|
||||
/**
|
||||
* Laravel validation rules for the incoming request, keyed exactly as
|
||||
* $request->all() would be. Must include a 'file' rule accepting an
|
||||
* uploaded file — this class always reads the file from that key.
|
||||
*
|
||||
* @return array<string, array<int, mixed>>
|
||||
*/
|
||||
abstract protected function validationRules(Request $request): array;
|
||||
|
||||
public function store(Request $request, FileService $files): JsonResponse
|
||||
{
|
||||
$validator = Validator::make(
|
||||
$request->all(),
|
||||
$this->validationRules($request),
|
||||
$this->validationMessages($request),
|
||||
$this->validationAttributes($request),
|
||||
);
|
||||
|
||||
if ($validator->fails()) {
|
||||
return response()->json(['error' => $validator->errors()->first('file')], 422);
|
||||
}
|
||||
|
||||
$file = $files->store($request->file('file'), $this->purpose());
|
||||
|
||||
return response()->json(['file_id' => $file->id]);
|
||||
}
|
||||
|
||||
/**
|
||||
* @return array<string, string>
|
||||
*/
|
||||
protected function validationMessages(Request $request): array
|
||||
{
|
||||
return [];
|
||||
}
|
||||
|
||||
/**
|
||||
* @return array<string, string>
|
||||
*/
|
||||
protected function validationAttributes(Request $request): array
|
||||
{
|
||||
return [];
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,44 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\File\Listeners;
|
||||
|
||||
use Modules\Core\Cart\Events\CartLineAdded;
|
||||
use Modules\Core\File\Models\File;
|
||||
use Modules\Core\File\Services\FileService;
|
||||
|
||||
/**
|
||||
* A custom-field photo is uploaded (and gets its own File row, unowned)
|
||||
* the moment a shopper picks it on the product page — before add-to-cart
|
||||
* even runs (see 3dealer's CustomFieldUploadController). The storefront's
|
||||
* add-to-cart request only carries that File's `id` in its custom_fields
|
||||
* answer (see CartController::customFieldsMeta()); this is what actually
|
||||
* gives the File an owner, once the real CartLine it belongs to exists.
|
||||
*
|
||||
* Listens for Cart\Events\CartLineAdded rather than reaching back into
|
||||
* the cart after CartService::addLine() returns — that event already
|
||||
* carries the exact CartLine Lunar resolved/created, with no need to
|
||||
* re-match it by meta (ambiguous whenever two lines share a purchasable +
|
||||
* similar meta).
|
||||
*/
|
||||
class AttachCustomFieldFileToCartLine
|
||||
{
|
||||
public function __construct(
|
||||
private readonly FileService $files,
|
||||
) {}
|
||||
|
||||
public function handle(CartLineAdded $event): void
|
||||
{
|
||||
$fileIds = collect($event->line->meta['custom_fields'] ?? [])
|
||||
->pluck('file_id')
|
||||
->filter()
|
||||
->all();
|
||||
|
||||
if ($fileIds === []) {
|
||||
return;
|
||||
}
|
||||
|
||||
File::query()
|
||||
->whereIn('id', $fileIds)
|
||||
->each(fn (File $file) => $this->files->attachOwner($file, $event->line));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,62 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\File\Listeners;
|
||||
|
||||
use Lunar\Models\OrderLine;
|
||||
use Modules\Core\Checkout\Events\OrderPlaced;
|
||||
use Modules\Core\File\Models\File;
|
||||
use Modules\Core\File\Services\FileService;
|
||||
|
||||
/**
|
||||
* Lunar\Pipelines\Order\Creation\CreateOrderLines copies a CartLine's
|
||||
* meta (custom_fields included) onto its new OrderLine verbatim — so an
|
||||
* order's custom-field file answer keeps the exact same `file_id` its
|
||||
* originating cart line's meta already had (see 3dealer's CartController::
|
||||
* customFieldsMeta(), which stores only that id — File is the single
|
||||
* source of truth for disk/path/name/mime, never duplicated into meta).
|
||||
* That id is enough to find the File row directly, with no need to match
|
||||
* an OrderLine back to "the" CartLine it came from.
|
||||
*
|
||||
* Re-points ownership (not a copy — the same File row) from whatever
|
||||
* CartLine owned it to this OrderLine, so a customer's placed order keeps
|
||||
* its file even after the cart it came from is later cleared (see
|
||||
* Modules\Core\Cart\Services\CartService, or a checkout-complete cart
|
||||
* reset) — FileService::pruneUnowned() only ever removes UNOWNED files,
|
||||
* but a File left pointing at a since-deleted CartLine would be just as
|
||||
* orphaned in practice; this listener is what keeps that from ever
|
||||
* happening for a real, placed order.
|
||||
*
|
||||
* Listens for Checkout\Events\OrderPlaced, not an OrderLine model event —
|
||||
* that's the one place in this codebase an order is reliably known to be
|
||||
* placed exactly once (see that event's own docblock), and it hands over
|
||||
* the whole Order with every line already loaded.
|
||||
*/
|
||||
class TransferCustomFieldFileOwnership
|
||||
{
|
||||
public function __construct(
|
||||
private readonly FileService $files,
|
||||
) {}
|
||||
|
||||
public function handle(OrderPlaced $event): void
|
||||
{
|
||||
foreach ($event->order->lines as $line) {
|
||||
$this->transferLine($line);
|
||||
}
|
||||
}
|
||||
|
||||
private function transferLine(OrderLine $line): void
|
||||
{
|
||||
$fileIds = collect($line->meta['custom_fields'] ?? [])
|
||||
->pluck('file_id')
|
||||
->filter()
|
||||
->all();
|
||||
|
||||
if ($fileIds === []) {
|
||||
return;
|
||||
}
|
||||
|
||||
File::query()
|
||||
->whereIn('id', $fileIds)
|
||||
->each(fn (File $file) => $this->files->attachOwner($file, $line));
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,28 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\File\Models;
|
||||
|
||||
use Illuminate\Database\Eloquent\Model;
|
||||
use Illuminate\Database\Eloquent\Relations\MorphTo;
|
||||
|
||||
/**
|
||||
* A row per physical file Modules\Core\File\Services\FileService has
|
||||
* stored — see that migration's own docblock for why `owner_type`/
|
||||
* `owner_id` are nullable and what `purpose` is for.
|
||||
*/
|
||||
class File extends Model
|
||||
{
|
||||
protected $guarded = [];
|
||||
|
||||
protected function casts(): array
|
||||
{
|
||||
return [
|
||||
'size' => 'integer',
|
||||
];
|
||||
}
|
||||
|
||||
public function owner(): MorphTo
|
||||
{
|
||||
return $this->morphTo();
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,135 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\File\Services;
|
||||
|
||||
use Illuminate\Contracts\Container\Container;
|
||||
use Illuminate\Database\Eloquent\Model;
|
||||
use Illuminate\Http\UploadedFile;
|
||||
use Illuminate\Support\Carbon;
|
||||
use Illuminate\Support\Collection;
|
||||
use Modules\Core\File\Contracts\FileAdapterInterface;
|
||||
use Modules\Core\File\Models\File;
|
||||
use Symfony\Component\HttpFoundation\StreamedResponse;
|
||||
|
||||
/**
|
||||
* Orchestrates the `files` table (ownership, purpose, cleanup — see that
|
||||
* migration's own docblock) on top of whichever FileAdapterInterface a
|
||||
* disk resolves to (see Providers\FileServiceProvider's contextual
|
||||
* binding) — never touches a disk or a raw path itself. Knows nothing
|
||||
* about custom fields, carts, or orders specifically; every caller
|
||||
* (3dealer's custom-field upload flow today, some other future
|
||||
* file-upload need tomorrow) supplies its own `purpose` string and owner
|
||||
* model, and scopes its own queries by them.
|
||||
*
|
||||
* `purpose` also doubles as the storage directory a file lands under
|
||||
* (store() passes it straight through as the adapter's own $directory) —
|
||||
* one string to name both, rather than every caller supplying two
|
||||
* near-identical values for what's really the same distinction ("which
|
||||
* kind of upload is this").
|
||||
*/
|
||||
class FileService
|
||||
{
|
||||
public function __construct(
|
||||
private readonly Container $container,
|
||||
) {}
|
||||
|
||||
public function store(UploadedFile $file, string $purpose, string $disk = 'local'): File
|
||||
{
|
||||
$path = $this->adapter($disk)->store($file, $purpose);
|
||||
|
||||
return File::create([
|
||||
'disk' => $disk,
|
||||
'path' => $path,
|
||||
'original_name' => $file->getClientOriginalName(),
|
||||
'mime' => $file->getMimeType(),
|
||||
'size' => $file->getSize(),
|
||||
'purpose' => $purpose,
|
||||
]);
|
||||
}
|
||||
|
||||
/**
|
||||
* Re-points an existing File at its owner — called once an owner
|
||||
* actually exists (e.g. a shopper's picked-but-not-yet-added photo
|
||||
* gets a CartLine the moment it's added to the cart). Never creates a
|
||||
* second row for the same physical file.
|
||||
*/
|
||||
public function attachOwner(File $file, Model $owner): File
|
||||
{
|
||||
$file->update([
|
||||
'owner_type' => $owner->getMorphClass(),
|
||||
'owner_id' => $owner->getKey(),
|
||||
]);
|
||||
|
||||
return $file;
|
||||
}
|
||||
|
||||
public function retrieve(File $file): StreamedResponse
|
||||
{
|
||||
return $this->adapter($file->disk)->retrieve($file->path, $file->original_name);
|
||||
}
|
||||
|
||||
/**
|
||||
* Same file as retrieve(), forced as a download (Content-Disposition:
|
||||
* attachment) rather than served inline — for a button distinct from
|
||||
* a preview link/thumbnail pointing at the same File.
|
||||
*/
|
||||
public function download(File $file): StreamedResponse
|
||||
{
|
||||
return $this->adapter($file->disk)->download($file->path, $file->original_name);
|
||||
}
|
||||
|
||||
public function exists(File $file): bool
|
||||
{
|
||||
return $this->adapter($file->disk)->exists($file->path);
|
||||
}
|
||||
|
||||
public function delete(File $file): void
|
||||
{
|
||||
$this->adapter($file->disk)->delete($file->path);
|
||||
|
||||
$file->delete();
|
||||
}
|
||||
|
||||
/**
|
||||
* @return Collection<int, File>
|
||||
*/
|
||||
public function list(string $purpose, ?Model $owner = null): Collection
|
||||
{
|
||||
return File::query()
|
||||
->where('purpose', $purpose)
|
||||
->when($owner, fn ($query) => $query
|
||||
->where('owner_type', $owner->getMorphClass())
|
||||
->where('owner_id', $owner->getKey()))
|
||||
->get();
|
||||
}
|
||||
|
||||
/**
|
||||
* Deletes every File of the given purpose that has no owner yet and
|
||||
* is older than $olderThan — the grace period covers a shopper still
|
||||
* on the page with a picked-but-not-yet-added file. An owned File
|
||||
* (whatever the owner type) is never touched here; callers that want
|
||||
* owned files gone too should delete() them explicitly wherever that
|
||||
* ownership itself ends (e.g. a CartLine being removed).
|
||||
*
|
||||
* @return int number of files deleted
|
||||
*/
|
||||
public function pruneUnowned(string $purpose, Carbon $olderThan): int
|
||||
{
|
||||
$files = File::query()
|
||||
->where('purpose', $purpose)
|
||||
->whereNull('owner_type')
|
||||
->where('created_at', '<', $olderThan)
|
||||
->get();
|
||||
|
||||
foreach ($files as $file) {
|
||||
$this->delete($file);
|
||||
}
|
||||
|
||||
return $files->count();
|
||||
}
|
||||
|
||||
private function adapter(string $disk): FileAdapterInterface
|
||||
{
|
||||
return $this->container->make(FileAdapterInterface::class, ['disk' => $disk]);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,7 @@
|
||||
<?php
|
||||
|
||||
use Illuminate\Support\Facades\Route;
|
||||
use Modules\Core\File\Http\Controllers\DownloadFileController;
|
||||
|
||||
Route::get('files/{file}/download', DownloadFileController::class)
|
||||
->name('files.download');
|
||||
@@ -85,6 +85,180 @@ class StorefrontLabels
|
||||
'shop.apply' => ['en' => 'Apply', 'el' => 'Εφαρμογή'],
|
||||
'shop.availability' => ['en' => 'Availability', 'el' => 'Διαθεσιμότητα'],
|
||||
'shop.in_stock_only' => ['en' => 'In-stock products only', 'el' => 'Μόνο διαθέσιμα προϊόντα'],
|
||||
|
||||
// Passwordless login (Auth\Services\UserOtpService)
|
||||
'auth.login_intro' => [
|
||||
'en' => 'Enter your email and we\'ll send you a code to sign in — no password needed.',
|
||||
'el' => 'Γράψε το email σου και θα σου στείλουμε έναν κωδικό σύνδεσης — δεν χρειάζεται κωδικός πρόσβασης.',
|
||||
],
|
||||
'auth.email' => ['en' => 'Email', 'el' => 'Email'],
|
||||
'auth.terms_notice' => [
|
||||
'en' => 'By continuing, you accept the <a href=":terms">Terms of Use</a> and have read the <a href=":privacy">Privacy Policy</a>.',
|
||||
'el' => 'Συνεχίζοντας, αποδέχεσαι τους <a href=":terms">Όρους Χρήσης</a> και έχεις διαβάσει την <a href=":privacy">Πολιτική Απορρήτου</a>.',
|
||||
],
|
||||
'auth.send_code' => ['en' => 'Send code', 'el' => 'Αποστολή κωδικού'],
|
||||
'auth.enter_code' => ['en' => 'Enter the code', 'el' => 'Εισάγετε τον κωδικό'],
|
||||
'auth.code_sent_to' => ['en' => 'We sent a code to', 'el' => 'Στείλαμε έναν κωδικό στο'],
|
||||
'auth.code' => ['en' => 'Code', 'el' => 'Κωδικός'],
|
||||
'auth.resend_code' => ['en' => 'Resend code', 'el' => 'Επαναποστολή κωδικού'],
|
||||
'auth.code_resent' => ['en' => 'A new code was sent.', 'el' => 'Στάλθηκε νέος κωδικός.'],
|
||||
'auth.change_email' => ['en' => 'Use a different email', 'el' => 'Χρήση διαφορετικού email'],
|
||||
'auth.invalid_code' => ['en' => 'That code is invalid or has expired.', 'el' => 'Ο κωδικός δεν είναι έγκυρος ή έχει λήξει.'],
|
||||
'auth.too_many_codes' => [
|
||||
'en' => 'Too many attempts. Please wait a few minutes and try again.',
|
||||
'el' => 'Πολλές προσπάθειες. Περίμενε λίγα λεπτά και ξαναδοκίμασε.',
|
||||
],
|
||||
|
||||
// Account profile page (account/show.blade.php)
|
||||
'account.nav_profile' => ['en' => 'Profile', 'el' => 'Προφίλ'],
|
||||
'account.nav_orders' => ['en' => 'Orders', 'el' => 'Παραγγελίες'],
|
||||
'account.nav_wishlist' => ['en' => 'Wishlist', 'el' => 'Λίστα επιθυμιών'],
|
||||
'account.email_heading' => ['en' => 'Login email', 'el' => 'Email σύνδεσης'],
|
||||
'account.email_change' => ['en' => 'Change email', 'el' => 'Αλλαγή email'],
|
||||
'account.details_heading' => ['en' => 'Your details', 'el' => 'Τα στοιχεία σου'],
|
||||
'account.first_name' => ['en' => 'First name', 'el' => 'Όνομα'],
|
||||
'account.last_name' => ['en' => 'Last name', 'el' => 'Επώνυμο'],
|
||||
'account.invoice' => ['en' => 'I need an invoice', 'el' => 'Χρειάζομαι τιμολόγιο'],
|
||||
'account.company_name' => ['en' => 'Company name', 'el' => 'Επωνυμία εταιρείας'],
|
||||
'account.tax_identifier' => ['en' => 'Tax ID (VAT)', 'el' => 'ΑΦΜ'],
|
||||
'account.address_heading' => ['en' => 'Address', 'el' => 'Διεύθυνση'],
|
||||
'account.line_one' => ['en' => 'Address', 'el' => 'Διεύθυνση'],
|
||||
'account.city' => ['en' => 'City', 'el' => 'Πόλη'],
|
||||
'account.postcode' => ['en' => 'Postcode', 'el' => 'Ταχυδρομικός κώδικας'],
|
||||
'account.state' => ['en' => 'Region', 'el' => 'Περιοχή'],
|
||||
'account.state_placeholder' => ['en' => 'Select a region', 'el' => 'Επίλεξε περιοχή'],
|
||||
'account.phone' => ['en' => 'Phone', 'el' => 'Τηλέφωνο'],
|
||||
'account.emails_heading' => ['en' => 'Emails', 'el' => 'Ειδοποιήσεις email'],
|
||||
'account.recovery_consent' => [
|
||||
'en' => 'Email me a reminder if I don\'t finish my order',
|
||||
'el' => 'Στείλε μου υπενθύμιση αν δεν ολοκληρώσω την παραγγελία μου',
|
||||
],
|
||||
'account.save' => ['en' => 'Save changes', 'el' => 'Αποθήκευση'],
|
||||
'account.saved' => ['en' => 'Your details were saved.', 'el' => 'Τα στοιχεία σου αποθηκεύτηκαν.'],
|
||||
'account.delete_heading' => ['en' => 'Delete account', 'el' => 'Διαγραφή λογαριασμού'],
|
||||
'account.delete_text' => [
|
||||
'en' => 'This permanently deletes your account and personal data. This cannot be undone.',
|
||||
'el' => 'Αυτό διαγράφει οριστικά τον λογαριασμό και τα προσωπικά σου δεδομένα. Δεν μπορεί να αναιρεθεί.',
|
||||
],
|
||||
'account.delete' => ['en' => 'Delete my account', 'el' => 'Διαγραφή λογαριασμού'],
|
||||
'account.delete_confirm_heading' => ['en' => 'Are you sure?', 'el' => 'Είσαι σίγουρος/η;'],
|
||||
'account.delete_confirm_text' => [
|
||||
'en' => 'This cannot be undone. Your account and personal data will be permanently deleted.',
|
||||
'el' => 'Αυτό δεν μπορεί να αναιρεθεί. Ο λογαριασμός και τα προσωπικά σου δεδομένα θα διαγραφούν οριστικά.',
|
||||
],
|
||||
'account.delete_confirm' => ['en' => 'Yes, delete my account', 'el' => 'Ναι, διαγραφή λογαριασμού'],
|
||||
'account.delete_cancel' => ['en' => 'Cancel', 'el' => 'Ακύρωση'],
|
||||
'account.deletion_requested' => [
|
||||
'en' => 'Your account deletion has been requested.',
|
||||
'el' => 'Ζητήθηκε η διαγραφή του λογαριασμού σου.',
|
||||
],
|
||||
|
||||
// Account email-change flow (account/email.blade.php, account/email-code.blade.php)
|
||||
'account.email_change_heading' => ['en' => 'Change your email', 'el' => 'Αλλαγή email'],
|
||||
'account.email_current' => ['en' => 'Your current email is', 'el' => 'Το τρέχον email σου είναι'],
|
||||
'account.email_new' => ['en' => 'New email', 'el' => 'Νέο email'],
|
||||
'account.email_new_hint' => [
|
||||
'en' => 'We\'ll send a code to this address to confirm it\'s yours.',
|
||||
'el' => 'Θα στείλουμε έναν κωδικό σε αυτή τη διεύθυνση για να επιβεβαιώσουμε ότι είναι δική σου.',
|
||||
],
|
||||
'account.email_confirm' => ['en' => 'Confirm', 'el' => 'Επιβεβαίωση'],
|
||||
'account.email_same' => [
|
||||
'en' => 'That\'s already your current email.',
|
||||
'el' => 'Αυτό είναι ήδη το τρέχον email σου.',
|
||||
],
|
||||
'account.email_taken' => [
|
||||
'en' => 'That email address is already in use.',
|
||||
'el' => 'Αυτή η διεύθυνση email χρησιμοποιείται ήδη.',
|
||||
],
|
||||
'account.email_changed' => ['en' => 'Your email was changed.', 'el' => 'Το email σου άλλαξε.'],
|
||||
|
||||
// Order history (account/orders/index.blade.php, account/orders/show.blade.php)
|
||||
'orders.empty' => ['en' => 'You have no orders yet.', 'el' => 'Δεν έχεις παραγγελίες ακόμα.'],
|
||||
'orders.shop_now' => ['en' => 'Shop now', 'el' => 'Αγόρασε τώρα'],
|
||||
'orders.date' => ['en' => 'Date', 'el' => 'Ημερομηνία'],
|
||||
'orders.number' => ['en' => 'Order', 'el' => 'Παραγγελία'],
|
||||
'orders.status' => ['en' => 'Status', 'el' => 'Κατάσταση'],
|
||||
'orders.total' => ['en' => 'Total', 'el' => 'Σύνολο'],
|
||||
'orders.view' => ['en' => 'View', 'el' => 'Προβολή'],
|
||||
'orders.view_order' => ['en' => 'View order :number', 'el' => 'Προβολή παραγγελίας :number'],
|
||||
'orders.order_title' => ['en' => 'Order :number', 'el' => 'Παραγγελία :number'],
|
||||
'orders.back' => ['en' => 'Back to orders', 'el' => 'Πίσω στις παραγγελίες'],
|
||||
'orders.payment' => ['en' => 'Payment method', 'el' => 'Τρόπος πληρωμής'],
|
||||
'orders.shipping_method' => ['en' => 'Shipping method', 'el' => 'Τρόπος αποστολής'],
|
||||
'orders.tracking' => ['en' => 'Tracking', 'el' => 'Παρακολούθηση αποστολής'],
|
||||
'orders.items' => ['en' => 'Items', 'el' => 'Προϊόντα'],
|
||||
'orders.subtotal' => ['en' => 'Subtotal', 'el' => 'Μερικό σύνολο'],
|
||||
'orders.discount' => ['en' => 'Discount', 'el' => 'Έκπτωση'],
|
||||
'orders.shipping' => ['en' => 'Shipping', 'el' => 'Μεταφορικά'],
|
||||
'orders.tax' => ['en' => 'Tax', 'el' => 'ΦΠΑ'],
|
||||
'orders.shipping_to' => ['en' => 'Shipping to', 'el' => 'Αποστολή σε'],
|
||||
'orders.billing' => ['en' => 'Billing details', 'el' => 'Στοιχεία τιμολόγησης'],
|
||||
|
||||
// Contact form (contact.blade.php, ContactController, emails.contact-confirmation)
|
||||
'contact.sent' => [
|
||||
'en' => 'Your message was sent — we\'ll get back to you soon.',
|
||||
'el' => 'Το μήνυμά σου στάλθηκε — θα σου απαντήσουμε σύντομα.',
|
||||
],
|
||||
'contact.send_failed' => [
|
||||
'en' => 'Something went wrong sending your message. Please try again.',
|
||||
'el' => 'Κάτι πήγε στραβά κατά την αποστολή. Παρακαλούμε δοκίμασε ξανά.',
|
||||
],
|
||||
'contact.too_many' => [
|
||||
'en' => 'Too many messages sent. Please wait a while before trying again.',
|
||||
'el' => 'Στάλθηκαν πολλά μηνύματα. Περίμενε λίγο πριν ξαναδοκιμάσεις.',
|
||||
],
|
||||
'contact.confirmation_subject' => ['en' => 'We received your message', 'el' => 'Λάβαμε το μήνυμά σου'],
|
||||
'contact.confirmation_preheader' => [
|
||||
'en' => 'Thanks for reaching out — here\'s a copy of your message.',
|
||||
'el' => 'Ευχαριστούμε για την επικοινωνία — εδώ είναι ένα αντίγραφο του μηνύματός σου.',
|
||||
],
|
||||
'contact.confirmation_heading' => ['en' => 'We received your message', 'el' => 'Λάβαμε το μήνυμά σου'],
|
||||
'contact.confirmation_body' => [
|
||||
'en' => 'Thanks for getting in touch. We\'ll reply as soon as we can.',
|
||||
'el' => 'Ευχαριστούμε που επικοινώνησες μαζί μας. Θα απαντήσουμε το συντομότερο δυνατό.',
|
||||
],
|
||||
'contact.confirmation_footer' => [
|
||||
'en' => 'This is a copy of the message you sent us.',
|
||||
'el' => 'Αυτό είναι ένα αντίγραφο του μηνύματος που μας έστειλες.',
|
||||
],
|
||||
|
||||
// Product page — custom fields, add-to-cart failure (product/show.blade.php,
|
||||
// components/product-custom-fields.blade.php)
|
||||
'product.personalize' => ['en' => 'Personalize', 'el' => 'Εξατομίκευση'],
|
||||
'product.custom_field_photo_hint' => [
|
||||
'en' => 'Max file size: :size MB.',
|
||||
'el' => 'Μέγιστο μέγεθος αρχείου: :size MB.',
|
||||
],
|
||||
'product.custom_field_uploading' => ['en' => 'Uploading…', 'el' => 'Μεταφόρτωση…'],
|
||||
'product.custom_field_upload_failed' => [
|
||||
'en' => 'Upload failed. Please try again.',
|
||||
'el' => 'Η μεταφόρτωση απέτυχε. Παρακαλούμε δοκίμασε ξανά.',
|
||||
],
|
||||
'product.add_to_cart_failed' => [
|
||||
'en' => '{0} Sorry, that\'s out of stock|{1} Only :count left in stock|[2,*] Only :count left in stock',
|
||||
'el' => '{0} Λυπούμαστε, εξαντλήθηκε|{1} Απομένει μόνο :count κομμάτι|[2,*] Απομένουν μόνο :count κομμάτια',
|
||||
],
|
||||
|
||||
// Reviews (components/review-form.blade.php, review-card.blade.php, product/show.blade.php)
|
||||
'review.rating_required' => ['en' => 'Please select a rating.', 'el' => 'Παρακαλούμε επίλεξε βαθμολογία.'],
|
||||
'review.reply' => ['en' => 'Reply', 'el' => 'Απάντηση'],
|
||||
'review.thank_you' => [
|
||||
'en' => 'Thanks for your review!',
|
||||
'el' => 'Ευχαριστούμε για την αξιολόγησή σου!',
|
||||
],
|
||||
|
||||
// Wishlist (components/wishlist-button.blade.php, wishlist/guest.blade.php, wishlist/list.blade.php)
|
||||
'wishlist.add' => ['en' => 'Add to wishlist', 'el' => 'Προσθήκη στη λίστα επιθυμιών'],
|
||||
'wishlist.remove' => ['en' => 'Remove from wishlist', 'el' => 'Αφαίρεση από τη λίστα επιθυμιών'],
|
||||
'wishlist.added' => ['en' => 'Added to wishlist', 'el' => 'Προστέθηκε στη λίστα επιθυμιών'],
|
||||
'wishlist.removed' => ['en' => 'Removed from wishlist', 'el' => 'Αφαιρέθηκε από τη λίστα επιθυμιών'],
|
||||
'wishlist.empty' => ['en' => 'Your wishlist is empty.', 'el' => 'Η λίστα επιθυμιών σου είναι άδεια.'],
|
||||
'wishlist.guest_hint' => [
|
||||
'en' => 'Log in to keep your wishlist across devices.',
|
||||
'el' => 'Συνδέσου για να κρατήσεις τη λίστα επιθυμιών σου σε όλες τις συσκευές.',
|
||||
],
|
||||
'wishlist.remove_named' => ['en' => 'Remove :name from wishlist', 'el' => 'Αφαίρεση :name από τη λίστα επιθυμιών'],
|
||||
'wishlist.remove_short' => ['en' => 'Remove', 'el' => 'Αφαίρεση'],
|
||||
];
|
||||
}
|
||||
}
|
||||
|
||||
@@ -3,22 +3,60 @@
|
||||
namespace Modules\Core\Order\Filament\Extensions;
|
||||
|
||||
use Filament\Actions\BulkAction;
|
||||
use Filament\Support\Colors\Color;
|
||||
use Filament\Support\Exceptions\Halt;
|
||||
use Filament\Tables\Columns\Layout\Panel;
|
||||
use Filament\Tables\Columns\TextColumn;
|
||||
use Filament\Tables\Table;
|
||||
use Illuminate\Support\Facades\Blade;
|
||||
use Illuminate\Support\Facades\URL;
|
||||
use Illuminate\Support\HtmlString;
|
||||
use Lunar\Admin\Support\Extending\BaseExtension;
|
||||
use Lunar\Models\OrderLine;
|
||||
use Modules\Core\File\Models\File;
|
||||
|
||||
/**
|
||||
* Same fix as OrderActionsExtension, applied to the order lines
|
||||
* table's "bulk_refund" toolbar action (Lunar\Admin\...\OrderItemsTable::
|
||||
* getBulkRefundAction()) — see that class's docblock for the underlying
|
||||
* Filament bug (failureNotification()+failure()+halt() never actually
|
||||
* sends the notification, because halt()'s Halt exception is caught before
|
||||
* Filament reaches the code that would send it).
|
||||
* extendTable() has two unrelated jobs: the "bulk_refund" toolbar-action
|
||||
* fix (see fixFailureNotification()'s own docblock — a genuine Filament
|
||||
* bug), and adding a "Custom Fields" entry to each order line's own
|
||||
* collapsible details dropdown (Lunar\Admin\...\OrderItemsTable::
|
||||
* getOrderLinesTableColumns()'s Panel — the same one already showing
|
||||
* stock level, notes, and the price_breakdowns table) — the shopper's
|
||||
* answers to Product::$custom_fields (a reference photo, personalization
|
||||
* text, ...), stored on OrderLine.meta by 3dealer's CartController::
|
||||
* customFieldsMeta() and, until now, never shown anywhere in the admin.
|
||||
*
|
||||
* Finds that Panel via $table->getCollapsibleColumnsLayout() — NOT
|
||||
* $table->getColumns(), which two earlier attempts at this both reached
|
||||
* for. HasColumns::pushColumns() flattens every Panel/Split into leaf
|
||||
* columns at table-build time and stores THAT flat list as
|
||||
* $this->columns (what getColumns() returns); the original nested
|
||||
* Panel/Stack objects actually used for rendering are kept separately —
|
||||
* in $this->columnsLayout for a non-collapsible layout component, or
|
||||
* $this->collapsibleColumnsLayout for one that IS collapsible (this
|
||||
* order-lines Panel is, via ->collapsible()). So `$column instanceof
|
||||
* Panel` over getColumns() can never match anything — Panel/Split
|
||||
* instances simply never appear in that array at all — and a fix built
|
||||
* on that check silently mutated nothing. A first attempt building a
|
||||
* brand new Panel and re-calling $table->columns() on top of the
|
||||
* existing setup fixed nothing either and instead rendered as a stray
|
||||
* empty extra column outside the dropdown (caught by actually opening
|
||||
* the order page). Mutates the found Panel's Stack in place via
|
||||
* Stack::schema(), the one part of both earlier attempts that actually
|
||||
* worked once the right object was found.
|
||||
*
|
||||
* Its own TextColumn rather than reusing the Panel's existing KeyValue:
|
||||
* KeyValue's own Blade view HTML-escapes every value ({{ $value }}),
|
||||
* which can't render a clickable link for a file answer.
|
||||
*/
|
||||
class OrderItemsTableExtension extends BaseExtension
|
||||
{
|
||||
public function extendTable(Table $table): Table
|
||||
{
|
||||
if ($table->getCollapsibleColumnsLayout() instanceof Panel) {
|
||||
$this->addCustomFieldsColumn($table->getCollapsibleColumnsLayout());
|
||||
}
|
||||
|
||||
return $table->toolbarActions(
|
||||
array_map(
|
||||
fn ($action) => $action instanceof BulkAction && $action->getName() === 'bulk_refund'
|
||||
@@ -29,6 +67,88 @@ class OrderItemsTableExtension extends BaseExtension
|
||||
);
|
||||
}
|
||||
|
||||
private function addCustomFieldsColumn(Panel $panel): void
|
||||
{
|
||||
$stack = $panel->getComponents()[0] ?? null;
|
||||
|
||||
if ($stack === null) {
|
||||
return;
|
||||
}
|
||||
|
||||
$stack->schema([
|
||||
...$stack->getComponents(),
|
||||
TextColumn::make('custom_fields')
|
||||
->label('Custom Fields')
|
||||
->visible(fn (OrderLine $record) => filled($record->meta['custom_fields'] ?? null))
|
||||
->getStateUsing(fn (OrderLine $record) => $this->renderCustomFields($record))
|
||||
->html(),
|
||||
]);
|
||||
}
|
||||
|
||||
/**
|
||||
* Same table markup/classes as this Panel's own existing KeyValue
|
||||
* component (Lunar\Admin's price_breakdowns, right above this in the
|
||||
* dropdown — see lunarpanel::tables.components.key-value) for visual
|
||||
* consistency, rebuilt here rather than reused: KeyValue's Blade view
|
||||
* HTML-escapes every value ({{ $value }}), which can't render a
|
||||
* thumbnail/download link for a file answer.
|
||||
*/
|
||||
private function renderCustomFields(OrderLine $record): HtmlString
|
||||
{
|
||||
$rows = collect($record->meta['custom_fields'] ?? [])
|
||||
->map(fn (array $field) => sprintf(
|
||||
'<tr class="divide-x divide-gray-950/10 dark:divide-white/10"><td class="p-2 font-medium whitespace-nowrap">%s</td><td class="p-2">%s</td></tr>',
|
||||
e($field['label']),
|
||||
$field['type'] === 'file' ? $this->fileCell($field) : e($field['value'] ?? ''),
|
||||
))
|
||||
->implode('');
|
||||
|
||||
return new HtmlString(
|
||||
'<div class="w-full mt-2 overflow-hidden overflow-x-auto ring-1 ring-inset ring-gray-950/10 dark:ring-white/10 rounded bg-white/70 dark:bg-white/5">'
|
||||
.'<table class="min-w-full text-xs divide-y divide-gray-950/10 dark:divide-white/10"><tbody class="divide-y divide-gray-950/10 dark:divide-white/10">'
|
||||
.$rows
|
||||
.'</tbody></table></div>',
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* A thumbnail (previewable image types only — an inline-signed URL to
|
||||
* the same File; see FileService::retrieve()) alongside an icon-only
|
||||
* download link forcing Content-Disposition: attachment (FileService::
|
||||
* download()) — two separate signed URLs, not one reused with a query
|
||||
* string appended after signing, since a signature covers the exact
|
||||
* query parameters present when it was minted.
|
||||
*/
|
||||
private function fileCell(array $field): string
|
||||
{
|
||||
$file = File::find($field['file_id'] ?? null);
|
||||
|
||||
if ($file === null) {
|
||||
return __('lunarpanel::global.na');
|
||||
}
|
||||
|
||||
$previewUrl = URL::temporarySignedRoute('files.download', now()->addHours(2), ['file' => $file->id]);
|
||||
$downloadUrl = URL::temporarySignedRoute('files.download', now()->addHours(2), ['file' => $file->id, 'download' => 1]);
|
||||
$previewable = ['image/jpeg', 'image/png', 'image/webp', 'image/gif'];
|
||||
|
||||
$thumbnail = in_array($file->mime, $previewable, true)
|
||||
? sprintf(
|
||||
'<a href="%s" target="_blank" rel="noopener"><img src="%s" alt="" style="width:2.5rem;height:2.5rem;object-fit:cover;border-radius:0.375rem;vertical-align:middle"></a>',
|
||||
$previewUrl,
|
||||
$previewUrl,
|
||||
)
|
||||
: '';
|
||||
|
||||
return sprintf(
|
||||
'<div style="display:flex;align-items:center;gap:0.5rem">%s<span>%s</span><a href="%s" title="Download" style="color:rgb(%s);display:inline-flex">%s</a></div>',
|
||||
$thumbnail,
|
||||
e($file->original_name),
|
||||
$downloadUrl,
|
||||
Color::Blue[600],
|
||||
Blade::render('<x-filament::icon icon="heroicon-o-arrow-down-tray" style="width:1rem;height:1rem"/>'),
|
||||
);
|
||||
}
|
||||
|
||||
private function fixFailureNotification(BulkAction $action): BulkAction
|
||||
{
|
||||
$originalAction = $action->getActionFunction();
|
||||
|
||||
@@ -2,13 +2,18 @@
|
||||
|
||||
namespace Modules\Core\Providers;
|
||||
|
||||
use Illuminate\Support\Facades\Event;
|
||||
use Illuminate\Support\ServiceProvider;
|
||||
use Modules\Core\Auth\Events\UserCreated;
|
||||
use Modules\Core\Auth\Listeners\RecordLegalAcceptanceForNewUser;
|
||||
use Modules\Core\Command\CreateAdminCommand;
|
||||
|
||||
class AuthServiceProvider extends ServiceProvider
|
||||
{
|
||||
public function boot(): void
|
||||
{
|
||||
Event::listen(UserCreated::class, RecordLegalAcceptanceForNewUser::class);
|
||||
|
||||
if ($this->app->runningInConsole()) {
|
||||
$this->app->booted(fn () => $this->commands([CreateAdminCommand::class]));
|
||||
}
|
||||
|
||||
@@ -6,11 +6,14 @@ use Illuminate\Support\Facades\Event;
|
||||
use Illuminate\Support\ServiceProvider;
|
||||
use Lunar\Facades\ModelManifest;
|
||||
use Lunar\Models\Contracts\Customer as LunarCustomer;
|
||||
use Modules\Core\Auth\Events\UserAuthenticated;
|
||||
use Modules\Core\Auth\Events\UserCreated;
|
||||
use Modules\Core\Customer\Events\CustomerAddressCreated;
|
||||
use Modules\Core\Customer\Events\CustomerAddressDeleted;
|
||||
use Modules\Core\Customer\Events\CustomerAddressUpdated;
|
||||
use Modules\Core\Customer\Events\CustomerProfileUpdated;
|
||||
use Modules\Core\Customer\Events\CustomerRecoveryConsentSet;
|
||||
use Modules\Core\Customer\Listeners\ClaimGuestOrdersOnLogin;
|
||||
use Modules\Core\Customer\Listeners\CreateCustomerForUser;
|
||||
use Modules\Core\Customer\Listeners\LogCustomerAccountActivity;
|
||||
use Modules\Core\Customer\Models\Customer;
|
||||
@@ -35,10 +38,12 @@ class CustomerServiceProvider extends ServiceProvider
|
||||
$this->app->booted(fn () => ModelManifest::replace(LunarCustomer::class, Customer::class));
|
||||
|
||||
Event::listen(UserCreated::class, CreateCustomerForUser::class);
|
||||
Event::listen(UserAuthenticated::class, ClaimGuestOrdersOnLogin::class);
|
||||
|
||||
Event::listen(CustomerAddressCreated::class, [LogCustomerAccountActivity::class, 'handleAddressCreated']);
|
||||
Event::listen(CustomerAddressUpdated::class, [LogCustomerAccountActivity::class, 'handleAddressUpdated']);
|
||||
Event::listen(CustomerAddressDeleted::class, [LogCustomerAccountActivity::class, 'handleAddressDeleted']);
|
||||
Event::listen(CustomerProfileUpdated::class, [LogCustomerAccountActivity::class, 'handleProfileUpdated']);
|
||||
Event::listen(CustomerRecoveryConsentSet::class, [LogCustomerAccountActivity::class, 'handleRecoveryConsentSet']);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,51 @@
|
||||
<?php
|
||||
|
||||
namespace Modules\Core\Providers;
|
||||
|
||||
use Illuminate\Support\Facades\Event;
|
||||
use Illuminate\Support\Facades\Storage;
|
||||
use Illuminate\Support\ServiceProvider;
|
||||
use InvalidArgumentException;
|
||||
use Modules\Core\Cart\Events\CartLineAdded;
|
||||
use Modules\Core\Checkout\Events\OrderPlaced;
|
||||
use Modules\Core\File\Adapters\LocalFileAdapter;
|
||||
use Modules\Core\File\Commands\PruneUnownedFilesCommand;
|
||||
use Modules\Core\File\Contracts\FileAdapterInterface;
|
||||
use Modules\Core\File\Listeners\AttachCustomFieldFileToCartLine;
|
||||
use Modules\Core\File\Listeners\TransferCustomFieldFileOwnership;
|
||||
|
||||
class FileServiceProvider extends ServiceProvider
|
||||
{
|
||||
public function register(): void
|
||||
{
|
||||
// Same pattern as ShippingServiceProvider's CarrierFulfillmentInterface
|
||||
// binding — a plain param ('disk' here, 'carrier' there) picks which
|
||||
// concrete adapter Modules\Core\File\Services\FileService actually
|
||||
// talks to. Adding a real S3FileAdapter later is one class plus one
|
||||
// more match arm here; nothing that already calls FileService changes.
|
||||
$this->app->bind(FileAdapterInterface::class, function ($app, array $params) {
|
||||
$disk = $params['disk'] ?? 'local';
|
||||
|
||||
return match ($disk) {
|
||||
'local' => new LocalFileAdapter(Storage::disk($disk)),
|
||||
default => throw new InvalidArgumentException("No FileAdapterInterface available for disk \"{$disk}\"."),
|
||||
};
|
||||
});
|
||||
}
|
||||
|
||||
public function boot(): void
|
||||
{
|
||||
// Signed-URL auth only, same model as Shipping\Http\Controllers\
|
||||
// DownloadShipmentLabelController — see that route's own docblock.
|
||||
// Migrations live in the shared database/migrations directory
|
||||
// CoreServiceProvider already loads; nothing more to register here.
|
||||
$this->loadRoutesFrom(__DIR__.'/../File/routes/web.php');
|
||||
|
||||
Event::listen(CartLineAdded::class, AttachCustomFieldFileToCartLine::class);
|
||||
Event::listen(OrderPlaced::class, TransferCustomFieldFileOwnership::class);
|
||||
|
||||
if ($this->app->runningInConsole()) {
|
||||
$this->commands([PruneUnownedFilesCommand::class]);
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user