Compare commits
132
Commits
d9fb3bbde6
...
master
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
207cb13363 | ||
|
|
5ff0d60f54 | ||
|
|
c455c8adf2 | ||
|
|
dcff693b99 | ||
|
|
3020bd070c | ||
|
|
162827dff7 | ||
|
|
cbb76070d9 | ||
|
|
966f099ffb | ||
|
|
b37ed69557 | ||
|
|
a8fe13e336 | ||
|
|
eadaf3a580 | ||
|
|
dbea4a8d69 | ||
|
|
cd3245df7b | ||
|
|
49ec4333af | ||
|
|
f411dec1da | ||
|
|
ebf8fd7571 | ||
|
|
536fe32e0d | ||
|
|
8293195395 | ||
|
|
d19fe1b6ea | ||
|
|
44a2ddda4a | ||
|
|
52f3036960 | ||
|
|
004f2382cb | ||
|
|
6cf142e35b | ||
|
|
47851d36ec | ||
|
|
c43682ef0c | ||
|
|
332bf92e44 | ||
|
|
cceeb83d5e | ||
|
|
1b06486b2b | ||
|
|
1a7e8704d0 | ||
|
|
6f6ae03428 | ||
|
|
9ce0c625ef | ||
|
|
40888bf197 | ||
|
|
e9d90418fc | ||
|
|
1bcc6acd27 | ||
|
|
359b645c62 | ||
|
|
d6c6bf6a1c | ||
|
|
57d7a716bc | ||
|
|
76b807d672 | ||
|
|
0797e3ab7a | ||
|
|
5f0dbbb734 | ||
|
|
839335ed3f | ||
|
|
0a6958eb9e | ||
|
|
d189a7559a | ||
|
|
7f2ddea240 | ||
|
|
45df93692a | ||
|
|
b806db611f | ||
|
|
c1874c277e | ||
|
|
05f00ed1fd | ||
|
|
569eb310e9 | ||
|
|
0387b38ab3 | ||
|
|
0a51d912a0 | ||
|
|
1214f9b748 | ||
|
|
effbce195c | ||
|
|
dca6944153 | ||
|
|
68ebe35b8e | ||
|
|
ee4d9b7952 | ||
|
|
e5679afa25 | ||
|
|
a55411aaf2 | ||
|
|
088d8cb809 | ||
|
|
492447be51 | ||
|
|
e7c896e168 | ||
|
|
309602fe93 | ||
|
|
9683a31c5e | ||
|
|
667e2ea2e5 | ||
|
|
fd3bbbe7de | ||
|
|
beb7d5faba | ||
|
|
547f07f01e | ||
|
|
ccab9bbb8e | ||
|
|
985f53efa2 | ||
|
|
23643db996 | ||
|
|
099271e0a8 | ||
|
|
01c49485be | ||
|
|
935b1d02f9 | ||
|
|
8fdaeda0ba | ||
|
|
f416e207eb | ||
|
|
c55019d04a | ||
|
|
910d4c5df0 | ||
|
|
f1a0322d3f | ||
|
|
6025ea4304 | ||
|
|
2b8fe5764c | ||
|
|
69fdd0b4b8 | ||
|
|
5347e01f0e | ||
|
|
78b46e5594 | ||
|
|
621381beaa | ||
|
|
8f4156cfe8 | ||
|
|
a9b993182b | ||
|
|
5a7fcd9f51 | ||
|
|
b4e9b8a4a9 | ||
|
|
c7035d6782 | ||
|
|
4c0974bf84 | ||
|
|
4e15d8ef8c | ||
|
|
1c7efc6e4d | ||
|
|
59c57b37fc | ||
|
|
37b49963f6 | ||
|
|
050204f063 | ||
|
|
c0ae9d8996 | ||
|
|
cc1cf6ea7f | ||
|
|
0437057e5d | ||
|
|
0c169daf55 | ||
|
|
609a63c2f4 | ||
|
|
12aaa43f10 | ||
|
|
dcdc998eee | ||
|
|
a55697ce82 | ||
|
|
a411e6bbc1 | ||
|
|
910fa94395 | ||
|
|
fdd1899c34 | ||
|
|
3ad3a1b4d6 | ||
|
|
68233f43ef | ||
|
|
027f7e8982 | ||
|
|
c084eb47cb | ||
|
|
58d165acc3 | ||
|
|
44ad943eec | ||
|
|
2cc6f5e5f0 | ||
|
|
0babc6a96d | ||
|
|
89a3d4bbad | ||
|
|
ccb2666495 | ||
|
|
97004234f0 | ||
|
|
ea73cc3562 | ||
|
|
02816fb9e7 | ||
|
|
910ce0205d | ||
|
|
e532c32cab | ||
|
|
6a51b672c8 | ||
|
|
956e9e88a6 | ||
|
|
4489475840 | ||
|
|
e4e008167a | ||
|
|
a5f3008ce2 | ||
|
|
409e8204f6 | ||
|
|
8472649905 | ||
|
|
e7784364fd | ||
|
|
59303cf25f | ||
|
|
af380a7fa0 | ||
|
|
9f540cbaa4 |
@@ -0,0 +1,41 @@
|
|||||||
|
{
|
||||||
|
"permissions": {
|
||||||
|
"allow": [
|
||||||
|
"Bash(find /home/konstantinos/Projects/RadicalElements/boboko-core/docs/scratch -iname \"*cart*\" 2>/dev/null; find /home/konstantinos/Projects/RadicalElements -iname \"*cart-feature*\" -o -iname \"*feature-survey*\" 2>/dev/null)",
|
||||||
|
"Read(//home/konstantinos/Projects/RadicalElements/**)",
|
||||||
|
"Bash(find /home/konstantinos/Projects/RadicalElements/3dealer -path \"*config/lunar/payments.php\" 2>/dev/null; find /home/konstantinos/Projects/RadicalElements -maxdepth 4 -iname \"*stripe*\" -type d 2>/dev/null)",
|
||||||
|
"Bash(grep -n 'process\\(\\\\|->using\\\\|\\\\$data' /home/konstantinos/Projects/RadicalElements/boboko-core/vendor/filament/actions/src/CreateAction.php)",
|
||||||
|
"Bash(php -l src/Order/Commands/CloseExpiredReturnWindows.php)",
|
||||||
|
"Bash(php -l config/core.php)",
|
||||||
|
"Bash(./bin/dc-core.sh exec *)",
|
||||||
|
"Bash(php -l src/Shipping/Extensions/OrderViewExtension.php)",
|
||||||
|
"Bash(php -l src/Cart/Filament/Resources/CartResource/Pages/ViewCart.php)",
|
||||||
|
"Bash(./bin/dc-core.sh exec app php artisan tinker '--execute= *)",
|
||||||
|
"Bash(mkdir -p /home/konstantinos/Projects/RadicalElements/boboko-core/src/Cart/Http/Controllers)",
|
||||||
|
"Bash(rmdir /home/konstantinos/Projects/RadicalElements/boboko-core/src/Checkout/routes)",
|
||||||
|
"Bash(mkdir -p /home/konstantinos/Projects/RadicalElements/boboko-core/src/Checkout/routes)",
|
||||||
|
"Bash(php -l src/Cart/Http/Controllers/CartController.php)",
|
||||||
|
"Bash(php -l src/Checkout/Http/Controllers/CheckoutController.php)",
|
||||||
|
"Bash(php -l src/Providers/CheckoutModuleServiceProvider.php)",
|
||||||
|
"Bash(php -l src/Providers/CheckoutServiceProvider.php)",
|
||||||
|
"Bash(php -l src/Checkout/routes/checkout.php)",
|
||||||
|
"Bash(php -l config/checkout.php)",
|
||||||
|
"Bash(cp /home/konstantinos/Projects/RadicalElements/3dealer/resources/css/checkout.css /home/konstantinos/Projects/RadicalElements/boboko-core/resources/css/)",
|
||||||
|
"Bash(cp /home/konstantinos/Projects/RadicalElements/3dealer/resources/js/checkout/*.js /home/konstantinos/Projects/RadicalElements/boboko-core/resources/js/checkout/)",
|
||||||
|
"Bash(rm /home/konstantinos/Projects/RadicalElements/3dealer/app/Providers/CheckoutModuleServiceProvider.php)",
|
||||||
|
"Bash(rm -rf /home/konstantinos/Projects/RadicalElements/3dealer/app/Http/Controllers/Checkout)",
|
||||||
|
"Bash(rm /home/konstantinos/Projects/RadicalElements/3dealer/routes/checkout.php)",
|
||||||
|
"Bash(rm -rf /home/konstantinos/Projects/RadicalElements/3dealer/resources/js/checkout)",
|
||||||
|
"Bash(rm /home/konstantinos/Projects/RadicalElements/3dealer/resources/css/checkout.css)",
|
||||||
|
"Bash(composer dump-autoload *)",
|
||||||
|
"Bash(curl -s -o /tmp/checkout_test.html -w \"%{http_code}\\\\n\" http://localhost:8091/en/checkout)",
|
||||||
|
"Read(//tmp/**)",
|
||||||
|
"Bash(curl -s -o /tmp/home_test.html -w \"%{http_code}\\\\n\" http://localhost:8091/en/)",
|
||||||
|
"Bash(php -l bootstrap/providers.php)"
|
||||||
|
],
|
||||||
|
"additionalDirectories": [
|
||||||
|
"/home/konstantinos/Projects/RadicalElements/3dealer/bootstrap",
|
||||||
|
"/home/konstantinos/Projects/RadicalElements/3dealer/config"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
+1439
-27
File diff suppressed because it is too large
Load Diff
+125
-12
@@ -1,35 +1,148 @@
|
|||||||
# Contributing to boboko-core
|
# Contributing to boboko-core
|
||||||
|
|
||||||
This is a Composer library, not a runnable app — you can't `php artisan serve` it directly. To develop and verify changes, you need a consumer app wired to a local checkout via a Composer path repository, plus a real database, since a large part of this package (Lunar models, migrations, Filament panel resources) can only be meaningfully verified against a live Lunar install.
|
This is a Composer library (and an npm package of the same name — see [JS/CSS](#jscss-a-real-npm-package)), not a runnable app — you can't `php artisan serve` it directly. To develop and verify changes, you need a consumer app wired to a local checkout, plus a real database, since a large part of this package (Lunar models, migrations, Filament panel resources) can only be meaningfully verified against a live Lunar install.
|
||||||
|
|
||||||
## Local dev setup
|
## Local dev setup
|
||||||
|
|
||||||
This works against any consumer app that follows the same convention — `boboko-test`, `boboko-starter`, `boboko-3dealer`, etc. — checked out next to this repo:
|
Consumer apps (`3dealer`, `boboko-test`, …) are checked out next to this repo:
|
||||||
|
|
||||||
```
|
```
|
||||||
RadicalElements/
|
RadicalElements/
|
||||||
├── boboko-core/ (this repo)
|
├── boboko-core/ (this repo)
|
||||||
└── boboko-test/ (or boboko-starter, boboko-3dealer, ... — consumer app, Docker-based)
|
└── 3dealer/ (or boboko-test, ... — consumer app, Docker-based)
|
||||||
```
|
```
|
||||||
|
|
||||||
Each of these consumer apps ships a `bin/dc-core.sh` helper that wraps the Docker Compose overlay needed to bind-mount a local `boboko-core` checkout into the app container:
|
### Two modes: local and repo
|
||||||
|
|
||||||
|
A consumer app can consume core in one of two modes, and carries the wiring for both. The inactive one is parked under an underscore-prefixed key:
|
||||||
|
|
||||||
|
| | **local** — your `../boboko-core` checkout | **repo** — tagged releases from the forge |
|
||||||
|
|---|---|---|
|
||||||
|
| `composer.json` | `repositories`: path repo `../boboko-core` (`"symlink": true`) | `repositories`: VCS repo `https://code.radical-elements.com/boboko/core.git` |
|
||||||
|
| `package.json` | `@boboko/core`: `file:../boboko-core` | `@boboko/core`: `git+https://code.radical-elements.com/boboko/core.git#semver:0.x` |
|
||||||
|
| Docker Compose | `bin/dc-core.sh` (dev + `docker-compose.core-dev.yml` overlay) | `bin/dc` (dev only) |
|
||||||
|
|
||||||
|
- **The committed state is always repo mode.** Local mode rewrites both lockfiles to point at `../boboko-core`, which doesn't exist on the server — never commit it.
|
||||||
|
- Both sides use an open `0.x` range: `"boboko/core": "0.*"` in Composer, `#semver:0.x` in npm. Don't use a caret: below 1.0.0, `^0.27.0` means `>=0.27.0 <0.28.0` in both tools, so it would silently refuse the next minor.
|
||||||
|
- `docker-compose.core-dev.yml` bind-mounts `../boboko-core` into the containers — at `/var/www/boboko-core` for `app`/`queue`/`scheduler` (where the path repo resolves from `/var/www/html`) and at `/boboko-core` for `vite` (where `file:../boboko-core` resolves from `/app`). Inside the app container, `vendor/boboko/core` is a symlink into that mount.
|
||||||
|
|
||||||
|
### Switching modes: `bin/core-mode`
|
||||||
|
|
||||||
|
Don't swap the keys by hand — each consumer app ships a `bin/core-mode` script:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
./bin/dc-core.sh exec app <command>
|
bin/core-mode # print the current mode
|
||||||
|
bin/core-mode local # work against ../boboko-core
|
||||||
|
bin/core-mode repo # back to tagged releases
|
||||||
```
|
```
|
||||||
|
|
||||||
This is shorthand for `docker compose -f docker-compose.dev.yml -f docker-compose.core-dev.yml exec app <command>`. Use `./bin/dc-core.sh` for everything below instead of typing the full compose invocation.
|
It swaps the `composer.json` / `package.json` wiring, runs `down` with the old mode's Compose wrapper and `up` with the new one, then waits until the entrypoints have re-resolved core. Running it for the mode you're already in skips the edits and just restarts the stack — in repo mode, that's how you pick up a newly pushed tag.
|
||||||
|
|
||||||
1. **Path repository.** In the consumer app's `composer.json`, the `repositories` array needs a path entry pointing at `../boboko-core`. If it only exists in a disabled block (e.g. `_repositories`), move it into the live array.
|
(`3dealer` has `bin/core-mode` and `bin/deploy`; they're app-agnostic, so other consumer apps can copy them as-is.)
|
||||||
2. **Relaxed version constraint.** The consumer app's `composer.json` should require `"boboko/core": "0.*"` (not a tight `^0.0.1` caret) — otherwise Composer rejects newer `0.0.x` versions resolved from the path repo.
|
|
||||||
3. **Bind mount.** The consumer app's `docker-compose.core-dev.yml` overlays `../boboko-core` into the container at `/var/www/boboko-core`, matching where the path repo resolves it relative to `/var/www/html`.
|
### Day to day in local mode
|
||||||
4. **Re-resolve after every change.** Composer's path repo does not hot-reload — after editing anything in `boboko-core` (including adding new files, which need autoload discovery), the container needs to re-run `composer update boboko/core`. In `boboko-test`, the entrypoint does this automatically on every dev boot (see `docker/entrypoint.sh`), so `./bin/dc-core.sh up` alone picks up local core changes. If a consumer app's entrypoint doesn't do this yet, run it manually:
|
|
||||||
|
Use `bin/dc-core.sh` for every Compose command (`bin/dc-core.sh exec app …`, `bin/dc-core.sh logs -f`, …) — plain `docker compose` or `bin/dc` leaves the core mount out.
|
||||||
|
|
||||||
|
The dev entrypoints re-resolve core on **every boot**: `docker/entrypoint.sh` runs `composer update "boboko/*"` and `docker/entrypoint-vite.sh` runs `npm update @boboko/core`. So:
|
||||||
|
|
||||||
|
- **Whatever branch is checked out in `../boboko-core` is what the app runs.** Switching core branches switches the app's code — check which branch you're on before debugging "missing" features.
|
||||||
|
- PHP edits to existing files show up immediately (it's a symlink). **New classes, new migrations, or `composer.json` changes** need a re-resolve: restart the stack, or run
|
||||||
|
|
||||||
|
```bash
|
||||||
|
bin/dc-core.sh exec app composer update boboko/core --with-all-dependencies
|
||||||
|
```
|
||||||
|
|
||||||
|
Skipping this is the most common cause of "my change isn't showing up."
|
||||||
|
- In `3dealer`, the app container's `vendor/` is a named Docker volume, so the host's `vendor/` directory is stale — inspect packages inside the container, not on the host.
|
||||||
|
|
||||||
|
## JS/CSS: a real npm package
|
||||||
|
|
||||||
|
Core's Stimulus controllers and CSS ship as the `@boboko/core` npm package, installed into the consumer's `node_modules` — as a symlink to `../boboko-core` in local mode, as a real copy of the tagged release in repo mode. It's a real package (rather than files read out of `vendor/`) so npm installs core's own dependencies (`leaflet`, `@hotwired/stimulus`) transitively, the same way Composer does for PHP.
|
||||||
|
|
||||||
|
Public entry points (`package.json` `exports`):
|
||||||
|
|
||||||
|
| Import | File |
|
||||||
|
|---|---|
|
||||||
|
| `@boboko/core` | `resources/js/index.js` — the stable barrel (`registerCheckout`, `registerWishlist`, …) |
|
||||||
|
| `@boboko/core/vite-plugin` | `vite-plugin.js` — `boboko()` |
|
||||||
|
| `@boboko/core/css/*` | `resources/css/*` |
|
||||||
|
| `@boboko/core/checkout`, `@boboko/core/checkout/*` | `resources/js/checkout/…` |
|
||||||
|
|
||||||
|
A consumer imports from the `@boboko/core` barrel only — not from a module's internal files — so the internal layout here can change without breaking every consumer:
|
||||||
|
|
||||||
|
```js
|
||||||
|
// consumer app's resources/js/app.js
|
||||||
|
import { registerCheckout, registerWishlist } from "@boboko/core";
|
||||||
|
registerCheckout(application);
|
||||||
|
registerWishlist(application);
|
||||||
|
```
|
||||||
|
|
||||||
|
```js
|
||||||
|
// consumer app's vite.config.js
|
||||||
|
import { boboko } from "@boboko/core/vite-plugin";
|
||||||
|
|
||||||
|
export default defineConfig({
|
||||||
|
plugins: [
|
||||||
|
laravel({
|
||||||
|
input: [
|
||||||
|
// Core's structural checkout styles load first, so the app's own theming wins.
|
||||||
|
"node_modules/@boboko/core/resources/css/checkout.css",
|
||||||
|
"resources/css/app.css",
|
||||||
|
"resources/js/app.js",
|
||||||
|
],
|
||||||
|
}),
|
||||||
|
boboko(),
|
||||||
|
],
|
||||||
|
});
|
||||||
|
```
|
||||||
|
|
||||||
|
```php
|
||||||
|
{{-- consumer app's layout --}}
|
||||||
|
@vite(['node_modules/@boboko/core/resources/css/checkout.css', 'resources/css/app.css', 'resources/js/app.js'])
|
||||||
|
```
|
||||||
|
|
||||||
|
`boboko()` owns the Vite settings the local-mode symlink needs, so consumers don't hand-copy them: it excludes `@boboko/core` from dependency pre-bundling (otherwise Vite serves a stale cached copy after you edit core), pre-bundles `leaflet`/`@hotwired/stimulus` explicitly, and turns on `resolve.preserveSymlinks` and `server.watch.followSymlinks` so bare imports resolve from the consumer's `node_modules` and core edits trigger HMR. All of it is a harmless no-op against a real installed copy in repo mode.
|
||||||
|
|
||||||
|
## Translations added in the UI
|
||||||
|
|
||||||
|
Default translation lines ship in core's seeders (`StorefrontTranslationsSeeder`, `CheckoutTranslationsSeeder`, `ValidationTranslationsSeeder`), which every app runs on boot and which only ever add missing keys. Lines added while building a storefront usually start in the Filament Language Lines UI instead. To move them into core:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
bin/dc-core.sh exec app php artisan boboko:translations:pull # local mode: writes into ../boboko-core
|
||||||
|
bin/dc exec app php artisan boboko:translations:pull --dry-run # any mode: just list them
|
||||||
|
```
|
||||||
|
|
||||||
|
It adds every `storefront` / `checkout` / `validation` key that's in the database but not in the matching seeder, appended at the end of `lines()` under a marker comment — move them into the right section before committing. Keys the seeder already has are never touched, even if their text was edited in the UI. `bin/deploy` runs it for you.
|
||||||
|
|
||||||
|
## Releasing a version
|
||||||
|
|
||||||
|
1. Bump `"version"` in **both** `composer.json` and `package.json` — they must match.
|
||||||
|
2. Add a `CHANGELOG.md` entry under the new version. While pre-1.0, a new capability for consuming apps is a **minor** bump (`0.27.x` → `0.28.0`); a fix, redesign or internal swap with no new capability is a **patch** bump.
|
||||||
|
3. Commit, tag `vX.Y.Z`, and push the commit **and** the tag:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
./bin/dc-core.sh exec app composer update boboko/core --with-all-dependencies
|
git tag v0.27.5
|
||||||
|
git push origin master v0.27.5
|
||||||
```
|
```
|
||||||
|
|
||||||
Skipping this step is the most common cause of "my change isn't showing up."
|
A tag alone changes nothing in production — each consumer app has to pick it up and deploy (below).
|
||||||
|
|
||||||
|
## Deploying a consumer app
|
||||||
|
|
||||||
|
Production only ever runs what the app's **committed lockfiles** pin. Each consumer app ships `bin/deploy`, which:
|
||||||
|
|
||||||
|
1. Refuses to run on the wrong branch, with uncommitted changes (other than the core wiring files), or behind `origin`.
|
||||||
|
2. Runs `php artisan boboko:translations:pull` (see [Translations added in the UI](#translations-added-in-the-ui)). In local mode, if it pulls any lines into `../boboko-core`, it stops — commit, tag and push core, then rerun. In repo mode it only checks, and stops if the database has lines core doesn't.
|
||||||
|
3. Runs `bin/core-mode repo` — switching from local mode if needed, restarting either way — so both lockfiles resolve the newest `0.x` tag. It warns if `../boboko-core` has a newer tag than what resolved (usually an unpushed tag).
|
||||||
|
4. Commits the lockfile bump (`Chore: Bumping boboko/core to X.Y.Z`) if there is one, shows what will be pushed, and asks for confirmation.
|
||||||
|
5. Pushes, then runs `vendor/bin/envoy run deploy` against the host in `.env.envoy`.
|
||||||
|
|
||||||
|
Envoy (`Envoy.blade.php`) then, on the server: `git reset --hard` + `git pull`, `docker compose build` (the `production` image target runs `composer install --no-dev` and `npm ci` from the committed lockfiles — this is where the core tag actually lands), `up -d`, caches config/routes/events, restarts `queue` and `scheduler`, and regenerates Stoic thumbnails. The production entrypoint skips Composer entirely and runs migrations (including core's), seeders, the Meilisearch sync, and `artisan optimize`.
|
||||||
|
|
||||||
|
After deploying you're left in repo mode — `bin/core-mode local` to go back.
|
||||||
|
|
||||||
|
When a change spans core and the app (e.g. a core migration plus an app model cast that depends on it), ship them together: tag core first, then commit the app change and deploy — `bin/deploy` bumps the lock to the new tag in the same deploy.
|
||||||
|
|
||||||
## Verifying changes against a real database
|
## Verifying changes against a real database
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,9 @@
|
|||||||
# Core Module
|
# Core Module
|
||||||
|
|
||||||
A Laravel module providing authentication, notifications, activity logging, CLI tooling, and functional types on top of the [Lunar](https://lunarphp.io) admin panel. Designed to be consumed as a standalone Composer package.
|
A Laravel module providing authentication, localization, product search/catalog, privacy/GDPR
|
||||||
|
tooling, notifications, activity logging, CLI tooling, and functional types on top of the
|
||||||
|
[Lunar](https://lunarphp.io) e-commerce package. Designed to be consumed as a standalone Composer
|
||||||
|
package by any Lunar-based e-shop.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -8,13 +11,83 @@ A Laravel module providing authentication, notifications, activity logging, CLI
|
|||||||
|
|
||||||
### OTP Authentication
|
### OTP Authentication
|
||||||
|
|
||||||
Passwordless login for both staff (Lunar panel) and customers via 6-digit codes delivered by email. Codes expire after 10 minutes. The Lunar panel login page is a two-step flow: email → OTP. Rate-limited to 5 attempts.
|
Passwordless login for both staff (Lunar panel) and customers via 6-digit codes delivered by
|
||||||
|
email. Codes expire after 10 minutes, rate-limited to 5 attempts. The Lunar panel login page is a
|
||||||
|
two-step flow (email → OTP) with a back button to return from the code step to the email step.
|
||||||
|
|
||||||
See [`docs/otp-auth.md`](docs/otp-auth.md).
|
See [`docs/otp-auth.md`](docs/otp-auth.md).
|
||||||
|
|
||||||
|
### Localization
|
||||||
|
|
||||||
|
Locale-prefixed routing (`Modules\Core\Localization\LocaleMiddleware`) — a `locale` route
|
||||||
|
middleware, opt-in per shop, that resolves and redirects to the correct language segment
|
||||||
|
(`/el/...`, `/en/...`) based on Lunar's own language list, with caching and rename-safe
|
||||||
|
translation migration. Also brings in storefront UI label translations
|
||||||
|
(`spatie/laravel-translation-loader`) with an admin-editable `LanguageLine` resource.
|
||||||
|
|
||||||
|
See [`docs/localization.md`](docs/localization.md).
|
||||||
|
|
||||||
|
### Product Search & Catalog
|
||||||
|
|
||||||
|
Two complementary services on top of Meilisearch:
|
||||||
|
|
||||||
|
- **`Modules\Core\Search\ProductSearchService`** — locale-aware full-text product search.
|
||||||
|
- **`Modules\Core\Catalog\ProductService`** — listing/filtering (by collection, brand, price
|
||||||
|
range) and single-product lookup by id or slug, reading directly from the Meilisearch index
|
||||||
|
rather than the database.
|
||||||
|
|
||||||
|
Both are backed by `Modules\Core\Search\ProductIndexer`, which extends Lunar's own indexer with
|
||||||
|
collections, price, variants, media, tags, and reviews — everything needed for both a listing
|
||||||
|
page and a full product detail page from one index.
|
||||||
|
|
||||||
|
See [`docs/product-search.md`](docs/product-search.md) and
|
||||||
|
[`docs/product-listing.md`](docs/product-listing.md).
|
||||||
|
|
||||||
|
### Product Reviews
|
||||||
|
|
||||||
|
`Modules\Core\Review\ProductReview` — ratings/reviews with staff replies, a Filament sub-navigation
|
||||||
|
page on the product edit screen, and automatic re-indexing (via `ReviewServiceProvider`) whenever
|
||||||
|
a review is created, updated, or deleted, so a product's Meilisearch document never goes stale.
|
||||||
|
|
||||||
|
### Privacy / GDPR Data-Subject Requests
|
||||||
|
|
||||||
|
Right of access (export) and right of erasure, built as an extensible contract
|
||||||
|
(`Modules\Core\Privacy\Contracts\PersonalDataProvider`) rather than a fixed table list — any
|
||||||
|
module can register its own data without core knowing it exists.
|
||||||
|
|
||||||
|
- **Two independent scopes**: erasing/exporting a Lunar `Customer` (business account) is never
|
||||||
|
the same operation as erasing/exporting a `User` (individual login) — a `Customer` erasure
|
||||||
|
never touches any linked `User`'s login, and a `User` erasure never touches a `Customer`
|
||||||
|
account's own data. See `docs/privacy.md` "User-scope vs Customer-scope".
|
||||||
|
- **Cancellable grace period** (default 30 days, configurable) before anything is actually
|
||||||
|
erased — logging back in during the window automatically reverts the request, mirroring
|
||||||
|
Shopify's own account-deletion flow. Immediate erasure exists but is staff-only by type, never
|
||||||
|
reachable from a self-service flow.
|
||||||
|
- **Sole-owner cascade**: erasing the last remaining `User` on a `Customer` also opens a (grace
|
||||||
|
period) erasure request for that now-orphaned `Customer`, so its PII doesn't sit unreachable
|
||||||
|
forever — traced back to the triggering request so login-reactivation can revert exactly that
|
||||||
|
cascade.
|
||||||
|
- **Queued export**: gathering data and writing a CSV-per-provider zip (via the generic,
|
||||||
|
reusable `Modules\Core\Export\CsvWriter`) runs as a background job; a consuming app hooks its
|
||||||
|
own notification onto the completion event via the Notification Registry (below).
|
||||||
|
|
||||||
|
See [`docs/privacy.md`](docs/privacy.md).
|
||||||
|
|
||||||
|
### Shopify Migration
|
||||||
|
|
||||||
|
`Modules\Core\MigrateImport\Shopify\ShopifyExportImporter` — imports a Shopify CSV product export
|
||||||
|
(products, variants, images, collections, tags, prices) into Lunar, idempotently re-runnable via
|
||||||
|
an `import_mappings` table. Part of a source-agnostic import framework
|
||||||
|
(`boboko:migrate:import`) designed to support additional sources later.
|
||||||
|
|
||||||
|
See [`docs/shopify-import.md`](docs/shopify-import.md).
|
||||||
|
|
||||||
### Notification Registry
|
### Notification Registry
|
||||||
|
|
||||||
An event-driven notification system. Each notification class declares which event it listens to and who to notify — the registry wires up the listener automatically. All notifications extend `BaseNotification` which implements `ShouldQueue`, so delivery is async. Supports optional delays.
|
An event-driven notification system. Each notification class declares which event it listens to
|
||||||
|
and who to notify — the registry wires up the listener automatically. All notifications extend
|
||||||
|
`BaseNotification`, which implements `ShouldQueue`, so delivery is async. Supports optional
|
||||||
|
delays.
|
||||||
|
|
||||||
**Creating a notification:**
|
**Creating a notification:**
|
||||||
|
|
||||||
@@ -33,9 +106,13 @@ class MyNotification extends BaseNotification
|
|||||||
NotificationRegistry::get()->register([MyNotification::class]);
|
NotificationRegistry::get()->register([MyNotification::class]);
|
||||||
```
|
```
|
||||||
|
|
||||||
|
See [`docs/notifications.md`](docs/notifications.md).
|
||||||
|
|
||||||
### Activity Logging
|
### Activity Logging
|
||||||
|
|
||||||
Thin wrapper around [Spatie Laravel Activity Log](https://github.com/spatie/laravel-activitylog). Four standardized methods: `created()`, `updated()`, `failed()`, `deleted()`. Logs to the `lunar` channel and auto-resolves the actor from the staff session.
|
Thin wrapper around [Spatie Laravel Activity Log](https://github.com/spatie/laravel-activitylog).
|
||||||
|
Four standardized methods: `created()`, `updated()`, `failed()`, `deleted()`. Logs to the `lunar`
|
||||||
|
channel and auto-resolves the actor from the staff session.
|
||||||
|
|
||||||
See [`docs/activity-log.md`](docs/activity-log.md).
|
See [`docs/activity-log.md`](docs/activity-log.md).
|
||||||
|
|
||||||
@@ -43,8 +120,11 @@ See [`docs/activity-log.md`](docs/activity-log.md).
|
|||||||
|
|
||||||
- Custom OTP login page replacing the default Lunar panel login
|
- Custom OTP login page replacing the default Lunar panel login
|
||||||
- `StaffResourceExtension` — removes password field from Lunar's staff resource
|
- `StaffResourceExtension` — removes password field from Lunar's staff resource
|
||||||
- `CustomerResourceExtension` — replaces default address relation manager with a custom implementation
|
- `CustomerResourceExtension` — replaces default address relation manager with a custom
|
||||||
- `CorePlugin` — configures panel path, branding, logos, navigation items, and activity log field exclusions for staff
|
implementation
|
||||||
|
- Table-rate shipping (`ShippingPlugin`) registered by default
|
||||||
|
- `CorePlugin` — configures panel path, branding, logos, navigation items, and activity log
|
||||||
|
field exclusions for staff
|
||||||
|
|
||||||
Register the plugin in your Lunar panel provider:
|
Register the plugin in your Lunar panel provider:
|
||||||
|
|
||||||
@@ -52,30 +132,36 @@ Register the plugin in your Lunar panel provider:
|
|||||||
->plugin(\Modules\Core\CorePlugin::make())
|
->plugin(\Modules\Core\CorePlugin::make())
|
||||||
```
|
```
|
||||||
|
|
||||||
|
See [`docs/lunar.md`](docs/lunar.md) for the full Lunar reference and non-obvious gotchas hit
|
||||||
|
while building against it.
|
||||||
|
|
||||||
### CLI Commands
|
### CLI Commands
|
||||||
|
|
||||||
| Command | Description |
|
| Command | Description |
|
||||||
|---|---|
|
|---|---|
|
||||||
| `core:create-admin` | Create a Lunar admin user |
|
| `boboko:anonymize` | Dummy-scrub personal data in `users`/`lunar_customers` for local dev safety (local environment only — **not** the GDPR erasure tool; see Privacy above for that) |
|
||||||
| `core:anonymize` | GDPR anonymization of users and customers (local only) |
|
| `boboko:export` | Dump database + storage files to a timestamped zip |
|
||||||
| `core:export` | Dump database + storage files to a timestamped zip |
|
| `boboko:import` | Restore from a `boboko:export` zip archive |
|
||||||
| `core:import` | Restore from a zip export (runs anonymize automatically, local only) |
|
| `boboko:export:cleanup` | Delete old export zips, keep N most recent |
|
||||||
| `core:export-cleanup` | Delete old export zips, keep N most recent |
|
| `boboko:migrate:import` | Import a vendor product catalog (Shopify, etc.) into Lunar |
|
||||||
|
| `boboko:privacy:process-erasure-requests` | Dispatch an erasure job for every due GDPR erasure request (wire into your own scheduler) |
|
||||||
|
| `lunar:create-admin` | Create a Lunar admin user (overrides Lunar's own command) |
|
||||||
|
| `lunar:install` | Seed default Lunar store data — countries, channel, currency, tax zone, attributes, product type (overrides Lunar's own command) |
|
||||||
|
|
||||||
### Functional Types
|
### Functional Types
|
||||||
|
|
||||||
Result and Option monads for explicit error handling without exceptions.
|
Result and Option types for explicit error handling without exceptions.
|
||||||
|
|
||||||
```php
|
```php
|
||||||
// Result<T, E>
|
// Result<T, E>
|
||||||
$result = Success::of($value);
|
$result = Success::create($value);
|
||||||
$result = Error::of('something went wrong');
|
$result = Error::create('something went wrong');
|
||||||
$result->map(fn($v) => ...)->flatMap(fn($v) => ...);
|
$result->map(fn($v) => ...)->flatMap(fn($v) => ...);
|
||||||
|
|
||||||
// Option<T>
|
// Option<T>
|
||||||
$option = Option::fromValue($nullableValue);
|
$option = Some::create($value);
|
||||||
$option->getOrElse('default');
|
$option = None::create();
|
||||||
$option->map(fn($v) => ...)->filter(fn($v) => $v > 0);
|
$option->map(fn($v) => ...);
|
||||||
```
|
```
|
||||||
|
|
||||||
---
|
---
|
||||||
@@ -102,17 +188,22 @@ Then run:
|
|||||||
|
|
||||||
```bash
|
```bash
|
||||||
composer require boboko/core
|
composer require boboko/core
|
||||||
|
php artisan vendor:publish --tag=core-config
|
||||||
php artisan vendor:publish --tag=core-assets
|
php artisan vendor:publish --tag=core-assets
|
||||||
php artisan migrate
|
php artisan migrate
|
||||||
```
|
```
|
||||||
|
|
||||||
|
For local core development alongside a consuming app (path-repo symlink + Docker mount), see
|
||||||
|
[`docs/modules.md`](docs/modules.md) "Docker Compose: the local-core mount".
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Requirements
|
## Requirements
|
||||||
|
|
||||||
- PHP 8.2+
|
- PHP 8.5+
|
||||||
- Laravel 11+
|
- Laravel 12+
|
||||||
- Lunar (lunarphp/lunar + lunarphp/admin)
|
- Lunar 1.3 (`lunarphp/lunar`)
|
||||||
|
- Meilisearch (for product search/listing/catalog)
|
||||||
- Spatie Laravel Activity Log
|
- Spatie Laravel Activity Log
|
||||||
|
|
||||||
---
|
---
|
||||||
@@ -120,7 +211,12 @@ php artisan migrate
|
|||||||
## Documentation
|
## Documentation
|
||||||
|
|
||||||
- [`docs/otp-auth.md`](docs/otp-auth.md) — OTP authentication flow
|
- [`docs/otp-auth.md`](docs/otp-auth.md) — OTP authentication flow
|
||||||
|
- [`docs/localization.md`](docs/localization.md) — Locale-prefixed routing and storefront translations
|
||||||
|
- [`docs/product-search.md`](docs/product-search.md) — Full-text product search
|
||||||
|
- [`docs/product-listing.md`](docs/product-listing.md) — Product listing/filtering/detail catalog service
|
||||||
|
- [`docs/privacy.md`](docs/privacy.md) — GDPR right of access/erasure, User-scope vs Customer-scope
|
||||||
|
- [`docs/shopify-import.md`](docs/shopify-import.md) — Shopify CSV → Lunar field mapping and import design
|
||||||
- [`docs/activity-log.md`](docs/activity-log.md) — Activity logging
|
- [`docs/activity-log.md`](docs/activity-log.md) — Activity logging
|
||||||
- [`docs/lunar.md`](docs/lunar.md) — Lunar framework reference
|
|
||||||
- [`docs/notifications.md`](docs/notifications.md) — Notification registry
|
- [`docs/notifications.md`](docs/notifications.md) — Notification registry
|
||||||
|
- [`docs/lunar.md`](docs/lunar.md) — Lunar framework reference and gotchas
|
||||||
- [`docs/modules.md`](docs/modules.md) — Module architecture, Customer/User pairing, provider registration pitfalls
|
- [`docs/modules.md`](docs/modules.md) — Module architecture, Customer/User pairing, provider registration pitfalls
|
||||||
|
|||||||
+10
-3
@@ -2,7 +2,7 @@
|
|||||||
"name": "boboko/core",
|
"name": "boboko/core",
|
||||||
"description": "Core module — authentication and shared panel behaviour",
|
"description": "Core module — authentication and shared panel behaviour",
|
||||||
"type": "library",
|
"type": "library",
|
||||||
"version": "0.17.1",
|
"version": "0.31.0",
|
||||||
"autoload": {
|
"autoload": {
|
||||||
"psr-4": {
|
"psr-4": {
|
||||||
"Modules\\Core\\": "src/"
|
"Modules\\Core\\": "src/"
|
||||||
@@ -18,7 +18,9 @@
|
|||||||
"lunarphp/search": "*",
|
"lunarphp/search": "*",
|
||||||
"lunarphp/meilisearch": "*",
|
"lunarphp/meilisearch": "*",
|
||||||
"spatie/laravel-translation-loader": "^2.8",
|
"spatie/laravel-translation-loader": "^2.8",
|
||||||
"lunarphp/stripe": "^1.5"
|
"stripe/stripe-php": "^16.6",
|
||||||
|
"picqer/php-barcode-generator": "^3.3",
|
||||||
|
"barryvdh/laravel-dompdf": "^3.1"
|
||||||
},
|
},
|
||||||
"require-dev": {
|
"require-dev": {
|
||||||
"fakerphp/faker": "^1.23",
|
"fakerphp/faker": "^1.23",
|
||||||
@@ -38,13 +40,18 @@
|
|||||||
"Modules\\Core\\Providers\\AuthServiceProvider",
|
"Modules\\Core\\Providers\\AuthServiceProvider",
|
||||||
"Modules\\Core\\Providers\\CustomerServiceProvider",
|
"Modules\\Core\\Providers\\CustomerServiceProvider",
|
||||||
"Modules\\Core\\Providers\\CheckoutServiceProvider",
|
"Modules\\Core\\Providers\\CheckoutServiceProvider",
|
||||||
|
"Modules\\Core\\Providers\\CheckoutModuleServiceProvider",
|
||||||
"Modules\\Core\\Providers\\PaymentServiceProvider",
|
"Modules\\Core\\Providers\\PaymentServiceProvider",
|
||||||
"Modules\\Core\\Providers\\LocalizationServiceProvider",
|
"Modules\\Core\\Providers\\LocalizationServiceProvider",
|
||||||
"Modules\\Core\\Providers\\CatalogServiceProvider",
|
"Modules\\Core\\Providers\\CatalogServiceProvider",
|
||||||
"Modules\\Core\\Providers\\CartServiceProvider",
|
"Modules\\Core\\Providers\\CartServiceProvider",
|
||||||
"Modules\\Core\\Providers\\ReviewServiceProvider",
|
"Modules\\Core\\Providers\\ReviewServiceProvider",
|
||||||
|
"Modules\\Core\\Providers\\FileServiceProvider",
|
||||||
"Modules\\Core\\Providers\\ShippingServiceProvider",
|
"Modules\\Core\\Providers\\ShippingServiceProvider",
|
||||||
"Modules\\Core\\Providers\\OrderServiceProvider"
|
"Modules\\Core\\Providers\\OrderServiceProvider",
|
||||||
|
"Modules\\Core\\Providers\\PrivacyServiceProvider",
|
||||||
|
"Modules\\Core\\Providers\\WishlistServiceProvider",
|
||||||
|
"Modules\\Core\\Providers\\StoreServiceProvider"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -0,0 +1,44 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Per-site settings for the cart + checkout module (see
|
||||||
|
* Modules\Core\Providers\CheckoutModuleServiceProvider). Publishable —
|
||||||
|
* artisan vendor:publish --tag=core-config.
|
||||||
|
*/
|
||||||
|
return [
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Name of the storefront's login route. The checkout's login tab and the
|
||||||
|
* confirmation page link to it with `?redirect=<checkout path>`, so the
|
||||||
|
* login page must send the shopper back there afterwards. null: no login
|
||||||
|
* offered in checkout at all.
|
||||||
|
*/
|
||||||
|
'login_route' => 'login',
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Name of the storefront's product-listing route — where confirmation()
|
||||||
|
* redirects a visit with no placed order to look at (session expired,
|
||||||
|
* direct navigation, a bookmark). route($this, $locale) must resolve.
|
||||||
|
*/
|
||||||
|
'products_route' => 'products',
|
||||||
|
|
||||||
|
/*
|
||||||
|
* ISO 3166-1 alpha-3 code fixing checkout to a single country (a hidden
|
||||||
|
* field, forced server-side — no country picker shown at all). null (the
|
||||||
|
* default) gives the full country/region picker, for a multi-country
|
||||||
|
* store.
|
||||||
|
*/
|
||||||
|
'store_country_iso3' => null,
|
||||||
|
|
||||||
|
/*
|
||||||
|
* The `purpose` tag CartController expects a product custom field's
|
||||||
|
* `file` answer to already carry (see Modules\Core\File\Models\File) —
|
||||||
|
* matches whatever purpose string the host's own upload endpoint
|
||||||
|
* (extending Modules\Core\File\Http\Controllers\UploadFileController)
|
||||||
|
* tags its stored files with. This module never reaches into that
|
||||||
|
* host controller directly; this config value is the one shared
|
||||||
|
* source of truth between the two.
|
||||||
|
*/
|
||||||
|
'custom_field_upload_purpose' => 'custom-field-upload',
|
||||||
|
|
||||||
|
];
|
||||||
@@ -16,6 +16,57 @@ return [
|
|||||||
|
|
||||||
'auto_create_customer_for_user' => true,
|
'auto_create_customer_for_user' => true,
|
||||||
|
|
||||||
|
/*
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
| Display Timezone
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| Timestamps are stored in the app timezone (UTC). This is the timezone
|
||||||
|
| they're shown in — the admin (Filament's display timezone), the
|
||||||
|
| storefront, emails and the order Timeline. (Carriers that report times
|
||||||
|
| without an offset — ELTA, ACS — are read as Greek time regardless.)
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
|
||||||
|
'display_timezone' => env('DISPLAY_TIMEZONE', 'Europe/Athens'),
|
||||||
|
|
||||||
|
/*
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
| Privacy / GDPR data-subject requests
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| 'providers' lists every Modules\Core\Privacy\Contracts\PersonalDataProvider
|
||||||
|
| that should be consulted for right-of-access/right-of-erasure requests. A
|
||||||
|
| module never needs to be known to core in advance — it just adds its own
|
||||||
|
| provider class here, the same way config('lunar.search.indexers') maps a
|
||||||
|
| model to its indexer. See docs/privacy.md.
|
||||||
|
|
|
||||||
|
| 'grace_period_days' is how long an erasure request stays cancellable
|
||||||
|
| (account deactivated, not yet erased) before it's actually processed by
|
||||||
|
| the privacy:process-erasure-requests scheduled command.
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
|
||||||
|
'privacy' => [
|
||||||
|
'providers' => [
|
||||||
|
// ActivityLogDataProvider MUST run before AddressDataProvider —
|
||||||
|
// it resolves which activity_log rows belong to this customer
|
||||||
|
// (including ones keyed by an Address id) before
|
||||||
|
// AddressDataProvider hard-deletes those Address rows. See that
|
||||||
|
// provider's own class docblock.
|
||||||
|
\Modules\Core\Logging\Privacy\ActivityLogDataProvider::class,
|
||||||
|
\Modules\Core\Customer\Privacy\CustomerDataProvider::class,
|
||||||
|
\Modules\Core\Customer\Privacy\AddressDataProvider::class,
|
||||||
|
\Modules\Core\Order\Privacy\OrderDataProvider::class,
|
||||||
|
\Modules\Core\Cart\Privacy\CartDataProvider::class,
|
||||||
|
\Modules\Core\Review\Privacy\ReviewDataProvider::class,
|
||||||
|
\Modules\Core\Payment\Privacy\PaymentDataProvider::class,
|
||||||
|
\Modules\Core\Auth\Privacy\UserSessionDataProvider::class,
|
||||||
|
],
|
||||||
|
|
||||||
|
'grace_period_days' => 30,
|
||||||
|
],
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|--------------------------------------------------------------------------
|
|--------------------------------------------------------------------------
|
||||||
| Cart Abandonment Threshold
|
| Cart Abandonment Threshold
|
||||||
@@ -65,4 +116,40 @@ return [
|
|||||||
'return_window_days' => 14,
|
'return_window_days' => 14,
|
||||||
],
|
],
|
||||||
|
|
||||||
|
/*
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
| Storefront OTP Login
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| Modules\Core\Auth\Services\UserOtpService's passwordless login.
|
||||||
|
| max_attempts caps how many wrong codes a shopper can guess against ONE
|
||||||
|
| generated code before it's invalidated outright. generation_limit/
|
||||||
|
| generation_decay_minutes cap how often a NEW code can be requested for
|
||||||
|
| the same email — independent of max_attempts, since generating a fresh
|
||||||
|
| code also resets the guess count, so an attempt cap alone doesn't stop
|
||||||
|
| an attacker from just requesting a new code every few tries. This same
|
||||||
|
| limit is also what stands between a malicious/careless caller and
|
||||||
|
| mail-bombing one inbox.
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
|
||||||
|
'auth' => [
|
||||||
|
'otp' => [
|
||||||
|
'max_attempts' => 5,
|
||||||
|
'generation_limit' => 3,
|
||||||
|
'generation_decay_minutes' => 10,
|
||||||
|
],
|
||||||
|
|
||||||
|
// Modules\Core\Customer\Services\CustomerEmailChangeService — same
|
||||||
|
// shape/reasoning as auth.otp above, independent limits since this
|
||||||
|
// is a separate flow (changing an existing account's login email,
|
||||||
|
// not logging in).
|
||||||
|
'email_change' => [
|
||||||
|
'max_attempts' => 5,
|
||||||
|
'generation_limit' => 3,
|
||||||
|
'generation_decay_minutes' => 10,
|
||||||
|
'expiry_minutes' => 10,
|
||||||
|
],
|
||||||
|
],
|
||||||
|
|
||||||
];
|
];
|
||||||
|
|||||||
@@ -13,12 +13,25 @@
|
|||||||
|
|
|
|
||||||
| Set these via environment variables — never commit real values.
|
| Set these via environment variables — never commit real values.
|
||||||
|
|
|
|
||||||
|
| Box Now has two environments (see their Partner API manual, section 2):
|
||||||
|
| Stage/Sandbox for testing, Production once live. Each has its own
|
||||||
|
| client_id/client_secret pair and its own base_url/location_api_url —
|
||||||
|
| there is no shared "switch an env var" flag, since stage credentials
|
||||||
|
| don't work against the production host or vice versa.
|
||||||
|
|
|
||||||
| BOXNOW_BASE_URL Root REST endpoint for delivery-requests/parcels.
|
| BOXNOW_BASE_URL Root REST endpoint for delivery-requests/parcels.
|
||||||
| BOXNOW_LOCATION_API_URL Separate, faster endpoint for origins/destinations
|
| BOXNOW_LOCATION_API_URL Separate, faster endpoint for origins/destinations
|
||||||
| lookups (Box Now recommends this over the main
|
| lookups (Box Now recommends this over the main
|
||||||
| base URL for those two calls specifically).
|
| base URL for those two calls specifically).
|
||||||
| BOXNOW_CLIENT_ID OAuth2 client id.
|
| BOXNOW_CLIENT_ID OAuth2 client id.
|
||||||
| BOXNOW_CLIENT_SECRET OAuth2 client secret.
|
| BOXNOW_CLIENT_SECRET OAuth2 client secret.
|
||||||
|
| BOXNOW_PARTNER_ID Numeric partnerId Box Now issues alongside your
|
||||||
|
| credentials. NOT used for REST API authentication
|
||||||
|
| (BoxNowClient authenticates with client_id/
|
||||||
|
| client_secret alone) — this is only consumed by
|
||||||
|
| the client-side Destination Map widget config
|
||||||
|
| (_bn_map_widget_config.partnerId), confirmed
|
||||||
|
| against Box Now's own WooCommerce plugin source.
|
||||||
| BOXNOW_ORIGIN_LOCATION_ID Your warehouse's Box Now locationId, used as
|
| BOXNOW_ORIGIN_LOCATION_ID Your warehouse's Box Now locationId, used as
|
||||||
| the pickup origin on every delivery request.
|
| the pickup origin on every delivery request.
|
||||||
| BOXNOW_SENDER_* Static sender contact details reused on every
|
| BOXNOW_SENDER_* Static sender contact details reused on every
|
||||||
@@ -33,6 +46,7 @@ return [
|
|||||||
|
|
||||||
'client_id' => env('BOXNOW_CLIENT_ID'),
|
'client_id' => env('BOXNOW_CLIENT_ID'),
|
||||||
'client_secret' => env('BOXNOW_CLIENT_SECRET'),
|
'client_secret' => env('BOXNOW_CLIENT_SECRET'),
|
||||||
|
'partner_id' => env('BOXNOW_PARTNER_ID'),
|
||||||
|
|
||||||
'origin_location_id' => env('BOXNOW_ORIGIN_LOCATION_ID'),
|
'origin_location_id' => env('BOXNOW_ORIGIN_LOCATION_ID'),
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,72 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
/*
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
| ELTA Courier credentials
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| ELTA's API is SOAP (unlike ACS's JSON gateway or Box Now's REST +
|
||||||
|
| OAuth2). Two operation families live at the same endpoint — see
|
||||||
|
| Modules\Core\Shipping\Carriers\Elta\EltaClient's docblock for why only
|
||||||
|
| the "*NEW" family (create/track/station/cancel) is used; the old
|
||||||
|
| family (including its label-print operation) is unreachable with this
|
||||||
|
| account and isn't called anywhere in this integration. Labels are
|
||||||
|
| rendered locally instead — see
|
||||||
|
| Modules\Core\Shipping\Carriers\Elta\EltaLabelRenderer — which is why
|
||||||
|
| sender identity (name/address, unlike PELVGNEW's request which needs
|
||||||
|
| only apost_code) is configured here.
|
||||||
|
|
|
||||||
|
| Set these via environment variables — never commit real values.
|
||||||
|
|
|
||||||
|
| ELTA_SERVICE_LOCATION SOAP endpoint (defaults to the live production
|
||||||
|
| host; only needed if ELTA gives you a separate
|
||||||
|
| sandbox host).
|
||||||
|
| ELTA_USER_CODE Account user code (pel_user_code / pel_user).
|
||||||
|
| ELTA_USER_PASS Account security code — not used by anything the
|
||||||
|
| *NEW family calls; kept only in case ELTA ever
|
||||||
|
| asks for it.
|
||||||
|
| ELTA_APOST_CODE Sender/account code (pel_apost_code).
|
||||||
|
| ELTA_APOST_SUB_CODE Sender sub-code (pel_apost_sub_code).
|
||||||
|
| ELTA_SENDER_NAME Sender name printed on the label — PELVGNEW's
|
||||||
|
| own request has no such field, so this only
|
||||||
|
| matters for our own locally-rendered label.
|
||||||
|
| ELTA_SENDER_ADDRESS Sender street address printed on the label.
|
||||||
|
| ELTA_SENDER_POSTCODE Sender postcode printed on the label.
|
||||||
|
| ELTA_SENDER_AREA Sender area/city printed on the label.
|
||||||
|
| ELTA_SENDER_PHONE Sender phone printed on the label.
|
||||||
|
| ELTA_ORIGIN_STATION_CODE This account's home ELTA station code — shown
|
||||||
|
| on the label as "Γ.Κατάθεσης"/"Από". ELTA's own
|
||||||
|
| client gets this from a PELLOGINNEW response
|
||||||
|
| (user_station); configured here instead so a
|
||||||
|
| label print doesn't need an extra API call.
|
||||||
|
| ELTA_LABEL_PAPER_SIZE "a4" (default, 3 copies per page) or "a6"
|
||||||
|
| (single thermal label) — matches the real
|
||||||
|
| client's own one-time printer-setup choice, not
|
||||||
|
| varied per shipment.
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
|
||||||
|
return [
|
||||||
|
|
||||||
|
// ELTA's current host, over HTTPS. The old 212.205.47.226:9003 still
|
||||||
|
// answers, but plain HTTP only (see docs/elta.md, A1).
|
||||||
|
'service_location' => env('ELTA_SERVICE_LOCATION', 'https://clients.elta-courier.gr'),
|
||||||
|
|
||||||
|
'user_code' => env('ELTA_USER_CODE'),
|
||||||
|
'user_pass' => env('ELTA_USER_PASS'),
|
||||||
|
|
||||||
|
'apost_code' => env('ELTA_APOST_CODE'),
|
||||||
|
'apost_sub_code' => env('ELTA_APOST_SUB_CODE'),
|
||||||
|
|
||||||
|
'sender_name' => env('ELTA_SENDER_NAME'),
|
||||||
|
'sender_address' => env('ELTA_SENDER_ADDRESS'),
|
||||||
|
'sender_postcode' => env('ELTA_SENDER_POSTCODE'),
|
||||||
|
'sender_area' => env('ELTA_SENDER_AREA'),
|
||||||
|
'sender_phone' => env('ELTA_SENDER_PHONE'),
|
||||||
|
'origin_station_code' => env('ELTA_ORIGIN_STATION_CODE'),
|
||||||
|
|
||||||
|
'label_paper_size' => env('ELTA_LABEL_PAPER_SIZE', 'a4'),
|
||||||
|
|
||||||
|
'timeout' => env('ELTA_HTTP_TIMEOUT', 15),
|
||||||
|
|
||||||
|
];
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->timestamp('deactivated_at')->nullable()->after('otp_expires_at');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('deactivated_at');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,56 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('data_erasure_requests', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
// Polymorphic, not a fixed customer_id — a request targets either a
|
||||||
|
// Lunar Customer (business account) or a User (individual), never
|
||||||
|
// both at once. See docs/privacy.md "User-scope vs Customer-scope".
|
||||||
|
$table->string('subject_type');
|
||||||
|
$table->unsignedBigInteger('subject_id');
|
||||||
|
// Snapshot, not a live-looked-up value — the subject's email may
|
||||||
|
// change or the record may be gone by the time this is read.
|
||||||
|
$table->string('email')->nullable();
|
||||||
|
// Who asked for this: the subject themselves (self-service deletion)
|
||||||
|
// or a staff member acting on their behalf. Plain nullable type+id
|
||||||
|
// columns rather than morphs() — only ever one of two concrete actor
|
||||||
|
// types, not an open-ended polymorphic set.
|
||||||
|
$table->string('requested_by_type');
|
||||||
|
$table->unsignedBigInteger('requested_by_id');
|
||||||
|
$table->string('status')->default('pending');
|
||||||
|
// Set only on a Customer-scoped request that was auto-created because
|
||||||
|
// erasing a User left them as the sole remaining user on that Customer
|
||||||
|
// (see Modules\Core\Privacy\Listeners\CascadeCustomerErasureListener).
|
||||||
|
// Null for every normal, directly-requested erasure. Lets login-
|
||||||
|
// reactivation find and revert exactly the Customer request THIS
|
||||||
|
// User's cancellation caused, without touching an unrelated,
|
||||||
|
// independently-requested Customer erasure the User happens to be
|
||||||
|
// linked to.
|
||||||
|
$table->foreignId('caused_by_request_id')->nullable()->constrained('data_erasure_requests')->nullOnDelete();
|
||||||
|
// now() + config('core.privacy.grace_period_days') at creation time —
|
||||||
|
// when privacy:process-erasure-requests will actually run this.
|
||||||
|
$table->timestamp('scheduled_for');
|
||||||
|
$table->timestamp('cancelled_at')->nullable();
|
||||||
|
$table->timestamp('completed_at')->nullable();
|
||||||
|
// Every provider's outcome, written once the request completes —
|
||||||
|
// see Modules\Core\Privacy\ErasureReport. Null until then.
|
||||||
|
$table->json('report')->nullable();
|
||||||
|
$table->timestamps();
|
||||||
|
|
||||||
|
$table->index(['status', 'scheduled_for']);
|
||||||
|
$table->index(['subject_type', 'subject_id']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('data_erasure_requests');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('data_export_requests', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
// Polymorphic, not a fixed customer_id — see data_erasure_requests
|
||||||
|
// for the same shape and reasoning.
|
||||||
|
$table->string('subject_type');
|
||||||
|
$table->unsignedBigInteger('subject_id');
|
||||||
|
// Snapshot, not a live lookup — same reasoning as
|
||||||
|
// data_erasure_requests.email (see that migration).
|
||||||
|
$table->string('email')->nullable();
|
||||||
|
$table->string('status')->default('pending');
|
||||||
|
// Storage path of the assembled export .zip, set once the queued job
|
||||||
|
// finishes. Null while pending.
|
||||||
|
$table->string('file_path')->nullable();
|
||||||
|
$table->timestamp('completed_at')->nullable();
|
||||||
|
$table->timestamps();
|
||||||
|
|
||||||
|
$table->index('status');
|
||||||
|
$table->index(['subject_type', 'subject_id']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('data_export_requests');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,46 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
use Lunar\Base\Migration;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* First-party copy of lunarphp/stripe's own create_stripe_payment_intents_table
|
||||||
|
* migration (package removed in favour of depending on stripe/stripe-php
|
||||||
|
* directly — see Modules\Core\Payment\Support\StripeManager and
|
||||||
|
* Modules\Core\Payment\Models\StripePaymentIntent, which replace the
|
||||||
|
* package's own classes over this same table). Timestamped to run just
|
||||||
|
* before this app's own add_context_to_stripe_payment_intents migration,
|
||||||
|
* which already alters this table.
|
||||||
|
*
|
||||||
|
* Guarded with hasTable(): on any environment that already ran
|
||||||
|
* lunarphp/stripe's own copy of this migration before the package was
|
||||||
|
* removed, the table already exists — this migration is only the one that
|
||||||
|
* actually creates it on a fresh install/database from now on.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
if (Schema::hasTable($this->prefix.'stripe_payment_intents')) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
Schema::create($this->prefix.'stripe_payment_intents', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
$table->foreignId('cart_id')->constrained($this->prefix.'carts');
|
||||||
|
$table->foreignId('order_id')->nullable()->constrained($this->prefix.'orders');
|
||||||
|
$table->string('intent_id')->index();
|
||||||
|
$table->string('status')->nullable();
|
||||||
|
$table->string('event_id')->index()->nullable();
|
||||||
|
$table->timestamp('processing_at')->nullable();
|
||||||
|
$table->timestamp('processed_at')->nullable();
|
||||||
|
$table->timestamps();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists($this->prefix.'stripe_payment_intents');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Caps brute-forcing a 6-digit OTP code (1M combinations, 10-minute
|
||||||
|
* window, previously uncapped) — see Modules\Core\Auth\Services\
|
||||||
|
* UserOtpService::validate(), which now invalidates the code entirely
|
||||||
|
* (forcing a fresh generateAndSend()) once otp_attempts reaches its max,
|
||||||
|
* rather than leaving a live code guessable indefinitely within its
|
||||||
|
* expiry window.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->unsignedTinyInteger('otp_attempts')->default(0)->after('otp_expires_at');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('otp_attempts');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A per-login session registry, independent of the actual session store
|
||||||
|
* driver (SESSION_DRIVER=redis in this app — no "sessions" table to
|
||||||
|
* purge by user_id the way the database driver would allow). Each
|
||||||
|
* successful OTP login (Modules\Core\Auth\Services\UserOtpService::
|
||||||
|
* validate()) records one row here and stamps the token into the
|
||||||
|
* Laravel session payload; Modules\Core\Auth\Http\Middleware\
|
||||||
|
* EnsureSessionNotRevoked checks it on every request. "Logout
|
||||||
|
* everywhere" (Modules\Core\Auth\Services\UserSessionService::
|
||||||
|
* revokeOtherSessions()) is then just marking every OTHER row
|
||||||
|
* revoked_at, no session-store-specific logic anywhere.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('user_sessions', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
$table->foreignId('user_id')->constrained()->cascadeOnDelete();
|
||||||
|
$table->string('token', 64)->unique();
|
||||||
|
$table->string('user_agent')->nullable();
|
||||||
|
$table->string('ip_address', 45)->nullable();
|
||||||
|
$table->timestamp('last_used_at');
|
||||||
|
$table->timestamp('revoked_at')->nullable();
|
||||||
|
$table->timestamps();
|
||||||
|
|
||||||
|
$table->index(['user_id', 'revoked_at']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('user_sessions');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,65 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Lunar\Models\Language;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* PaymentMethod.name becomes a locale-keyed JSON array (e.g.
|
||||||
|
* {"en": "Cash On Delivery", "el": "Αντικαταβολή"}), rendered in Filament
|
||||||
|
* via Lunar's own Lunar\Admin\Support\Forms\Components\TranslatedText —
|
||||||
|
* the same reusable component/data-shape Product/Collection names already
|
||||||
|
* use (Lunar\Base\Traits\HasTranslations), just applied directly to a
|
||||||
|
* plain column here rather than through attribute_data, since
|
||||||
|
* PaymentMethod is a merchant-configured settings row, not a translatable
|
||||||
|
* catalog attribute.
|
||||||
|
*
|
||||||
|
* Existing plain-string rows are preserved under the store's default
|
||||||
|
* Language code (falls back to 'en' if no Language row exists yet — this
|
||||||
|
* migration can run before lunar:install seeds one) rather than dropped,
|
||||||
|
* so an already-configured payment method's name isn't blanked out.
|
||||||
|
*
|
||||||
|
* Uses a raw `ALTER COLUMN ... TYPE` rather than Blueprint::change()
|
||||||
|
* (which requires doctrine/dbal — not installed in this project) —
|
||||||
|
* Postgres-specific (this project runs on `pgsql`, per its own docker
|
||||||
|
* setup), with an explicit USING clause since json isn't implicitly
|
||||||
|
* castable from varchar.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
$defaultLocale = Language::where('default', true)->value('code') ?? 'en';
|
||||||
|
|
||||||
|
$existing = DB::table('payment_methods')->pluck('name', 'id');
|
||||||
|
|
||||||
|
DB::statement('ALTER TABLE payment_methods ALTER COLUMN name DROP DEFAULT');
|
||||||
|
DB::statement("ALTER TABLE payment_methods ALTER COLUMN name TYPE json USING NULL");
|
||||||
|
|
||||||
|
foreach ($existing as $id => $name) {
|
||||||
|
if ($name === null) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
DB::table('payment_methods')
|
||||||
|
->where('id', $id)
|
||||||
|
->update(['name' => json_encode([$defaultLocale => $name])]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
$defaultLocale = Language::where('default', true)->value('code') ?? 'en';
|
||||||
|
|
||||||
|
$existing = DB::table('payment_methods')->pluck('name', 'id');
|
||||||
|
|
||||||
|
DB::statement('ALTER TABLE payment_methods ALTER COLUMN name TYPE varchar(255) USING NULL');
|
||||||
|
|
||||||
|
foreach ($existing as $id => $name) {
|
||||||
|
$decoded = json_decode((string) $name, true);
|
||||||
|
$flat = is_array($decoded) ? ($decoded[$defaultLocale] ?? reset($decoded) ?: null) : $name;
|
||||||
|
|
||||||
|
DB::table('payment_methods')->where('id', $id)->update(['name' => $flat]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,74 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Lunar\Base\Migration;
|
||||||
|
use Lunar\Models\Language;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* ShippingMethod.name becomes a locale-keyed JSON array (e.g.
|
||||||
|
* {"en": "Standard Delivery", "el": "Κανονική Παράδοση"}), rendered in
|
||||||
|
* Filament via Lunar's own Lunar\Admin\Support\Forms\Components\
|
||||||
|
* TranslatedText (Modules\Core\Shipping\Extensions\
|
||||||
|
* ShippingMethodResourceExtension::replaceNameField()) — same shape/
|
||||||
|
* resolution as PaymentMethod.name (see its own migration,
|
||||||
|
* 2026_09_15_000001_make_payment_methods_name_translatable.php) and
|
||||||
|
* Product/Collection names (Lunar\Base\Traits\HasTranslations).
|
||||||
|
*
|
||||||
|
* ShippingMethod is a vendor (lunarphp/table-rate-shipping) table, but
|
||||||
|
* converting a vendor column's type via a migration is no different from
|
||||||
|
* any other schema change this project already makes against a vendor
|
||||||
|
* table (see database/migrations/2026_08_31_000001_create_payment_methods_table.php's
|
||||||
|
* sibling migrations for the same pattern against PaymentMethod) — there
|
||||||
|
* was no good reason to route this through `data.name` instead, unlike
|
||||||
|
* `data.fulfillment_type` which is a genuinely NEW field the vendor table
|
||||||
|
* never had at all.
|
||||||
|
*
|
||||||
|
* Existing plain-string rows are preserved under the store's default
|
||||||
|
* Language code (falls back to 'en' if no Language row exists yet)
|
||||||
|
* rather than dropped.
|
||||||
|
*
|
||||||
|
* Uses a raw `ALTER COLUMN ... TYPE` rather than Blueprint::change()
|
||||||
|
* (requires doctrine/dbal — not installed in this project) — Postgres-
|
||||||
|
* specific (this project runs on `pgsql`), with an explicit USING clause
|
||||||
|
* since json isn't implicitly castable from varchar.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
$table = $this->prefix.'shipping_methods';
|
||||||
|
$defaultLocale = Language::where('default', true)->value('code') ?? 'en';
|
||||||
|
|
||||||
|
// The column is NOT NULL (vendor migration never marked it
|
||||||
|
// nullable) — converting via `USING NULL` first, then
|
||||||
|
// backfilling with a second UPDATE, violates that constraint
|
||||||
|
// before the backfill ever runs. json_build_object() converts
|
||||||
|
// each existing string in place, in the same statement, so the
|
||||||
|
// column is never transiently NULL. $defaultLocale is inlined
|
||||||
|
// (not bound) — parameter binding inside an ALTER TABLE ... USING
|
||||||
|
// expression isn't reliable across drivers; it's a Language::code
|
||||||
|
// value we control, not user input, so quote_literal-safe
|
||||||
|
// interpolation here is fine.
|
||||||
|
$quotedLocale = DB::getPdo()->quote($defaultLocale);
|
||||||
|
|
||||||
|
DB::statement("ALTER TABLE {$table} ALTER COLUMN name TYPE json USING json_build_object({$quotedLocale}, name)");
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
$table = $this->prefix.'shipping_methods';
|
||||||
|
$defaultLocale = Language::where('default', true)->value('code') ?? 'en';
|
||||||
|
|
||||||
|
// Same NOT NULL constraint applies going back — ->>'{locale}'
|
||||||
|
// extracts the default locale's text value directly in the
|
||||||
|
// USING clause, falling back to the first key present via
|
||||||
|
// COALESCE for any row missing that locale (e.g. one only ever
|
||||||
|
// filled in via a non-default language).
|
||||||
|
$quotedLocale = DB::getPdo()->quote($defaultLocale);
|
||||||
|
|
||||||
|
DB::statement(
|
||||||
|
"ALTER TABLE {$table} ALTER COLUMN name TYPE varchar(255) ".
|
||||||
|
"USING COALESCE(name->>{$quotedLocale}, (SELECT value FROM json_each_text(name) LIMIT 1))"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Per-product, customer-authored input fields — a personalized-statue
|
||||||
|
* product needing a reference photo upload and an optional engraving
|
||||||
|
* textarea, for example. Deliberately NOT modeled as a Lunar ProductOption
|
||||||
|
* (see Modules\Core\Catalog\Contracts\ProductOptionTypeInterface's own
|
||||||
|
* docblock): an option's values are a fixed, admin-authored list that
|
||||||
|
* define variants (Red/Green/Blue) — a photo upload has no such list, it's
|
||||||
|
* unique per order, and creates no variant at all. This is a genuinely
|
||||||
|
* different concept that happens to configure on the same product page.
|
||||||
|
*
|
||||||
|
* Array of {key, type: 'text'|'textarea'|'file', label, required} — `key`
|
||||||
|
* is what a submitted answer is keyed by in CartLine/OrderLine.meta (both
|
||||||
|
* already have a `meta` json column — see Modules\Core\Cart\Services\
|
||||||
|
* CartService::addLine()'s own $meta parameter), not a new table, since
|
||||||
|
* this is small, rarely-queried per-product config, the same reasoning
|
||||||
|
* ShippingMethod.data/PaymentMethod.data already follow for their own
|
||||||
|
* per-row settings.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table(config('lunar.database.table_prefix').'products', function (Blueprint $table) {
|
||||||
|
$table->json('custom_fields')->nullable()->after('attribute_data');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table(config('lunar.database.table_prefix').'products', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('custom_fields');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,50 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A generic, storage-backend-agnostic file registry — Modules\Core\File\
|
||||||
|
* Services\FileService's own backing table. `disk`/`path` are whatever
|
||||||
|
* Laravel's Storage facade already understands (local, s3, ...); this
|
||||||
|
* table adds what Flysystem itself has no concept of: who a file
|
||||||
|
* belongs to, why it was uploaded, and whether anything still needs it.
|
||||||
|
*
|
||||||
|
* `owner_type`/`owner_id` are nullable — a file can (and, for a product
|
||||||
|
* custom-field photo, always does) exist before anything owns it yet: a
|
||||||
|
* shopper picks a photo on the product page and it's uploaded immediately
|
||||||
|
* (see 3dealer's CustomFieldUploadController), well before add-to-cart
|
||||||
|
* gives it a CartLine to belong to. FileService::attachOwner() re-points
|
||||||
|
* these columns once an owner exists, rather than creating a second row
|
||||||
|
* for the same physical file.
|
||||||
|
*
|
||||||
|
* `purpose` (e.g. 'custom-field-upload') lets one table serve unrelated
|
||||||
|
* future features without collision — FileService itself has no
|
||||||
|
* knowledge of what a purpose means, callers scope their own queries by
|
||||||
|
* it.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('files', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
$table->string('disk');
|
||||||
|
$table->string('path');
|
||||||
|
$table->string('original_name')->nullable();
|
||||||
|
$table->string('mime')->nullable();
|
||||||
|
$table->unsignedBigInteger('size')->nullable();
|
||||||
|
$table->string('purpose');
|
||||||
|
$table->nullableMorphs('owner');
|
||||||
|
$table->timestamps();
|
||||||
|
|
||||||
|
$table->index(['purpose', 'owner_type', 'owner_id']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('files');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Which terms/privacy policy version an account was created under — the
|
||||||
|
* storefront login page shows a notice ("By continuing, you accept the
|
||||||
|
* Terms of Use and have read the Privacy Policy") that a new signup
|
||||||
|
* implicitly agrees to just by requesting an OTP code, so this is
|
||||||
|
* recorded the moment Modules\Core\Auth\Services\UserOtpService::
|
||||||
|
* generateAndSend()'s firstOrCreate() actually creates the row — never
|
||||||
|
* for an existing user, whose original acceptance (whatever version was
|
||||||
|
* live at the time) must not be silently overwritten by a later config
|
||||||
|
* value. Nullable: every user created before this migration has none of
|
||||||
|
* the three, which is the honest answer ("we don't know what they saw"),
|
||||||
|
* not something to backfill with today's config values.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->timestamp('terms_accepted_at')->nullable()->after('otp_attempts');
|
||||||
|
$table->string('terms_version')->nullable()->after('terms_accepted_at');
|
||||||
|
$table->string('privacy_policy_version')->nullable()->after('terms_version');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->dropColumn(['terms_accepted_at', 'terms_version', 'privacy_policy_version']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Backs Modules\Core\Customer\Services\CustomerEmailChangeService — the
|
||||||
|
* pending new-email change lives on the user's own row, same convention
|
||||||
|
* as the existing otp_code/otp_expires_at/otp_attempts columns (Auth\
|
||||||
|
* Services\UserOtpService), rather than the session: a change requested
|
||||||
|
* on one device/session must still be confirmable from another (a code
|
||||||
|
* arrives by email, which is often opened somewhere else entirely), and
|
||||||
|
* a request-scoped session can't survive that.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->string('pending_email')->nullable()->after('privacy_policy_version');
|
||||||
|
$table->string('pending_email_code_hash')->nullable()->after('pending_email');
|
||||||
|
$table->timestamp('pending_email_expires_at')->nullable()->after('pending_email_code_hash');
|
||||||
|
$table->unsignedTinyInteger('pending_email_attempts')->default(0)->after('pending_email_expires_at');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->dropColumn([
|
||||||
|
'pending_email',
|
||||||
|
'pending_email_code_hash',
|
||||||
|
'pending_email_expires_at',
|
||||||
|
'pending_email_attempts',
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* One product on a logged-in user's wishlist. A guest's wishlist lives in a
|
||||||
|
* cookie instead (see Modules\Core\Wishlist\Services\Wishlist) — nothing is
|
||||||
|
* written here until Modules\Core\Wishlist\Listeners\MergeGuestWishlistOnLogin
|
||||||
|
* moves the cookie's ids across on login.
|
||||||
|
*
|
||||||
|
* hasTable() guard: this table previously lived in each consuming app's own
|
||||||
|
* migrations (e.g. 3dealer's create_wishlist_items_table, extracted here) —
|
||||||
|
* Laravel's migrations table tracks by filename, so a consumer that already
|
||||||
|
* ran its own copy would otherwise hit "table already exists" the first time
|
||||||
|
* this migration runs. Skips creation entirely if the table is already
|
||||||
|
* there; a fresh install with no prior wishlist table gets it created here.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
if (Schema::hasTable('wishlist_items')) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
Schema::create('wishlist_items', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
$table->foreignId('user_id')->constrained()->cascadeOnDelete();
|
||||||
|
$table->foreignId('product_id')->constrained('lunar_products')->cascadeOnDelete();
|
||||||
|
$table->timestamps();
|
||||||
|
|
||||||
|
$table->unique(['user_id', 'product_id']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('wishlist_items');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A single-row table for the store's own contact/legal details — edited via
|
||||||
|
* the Filament "Store Details" settings page (Modules\Core\Store\Filament\
|
||||||
|
* Pages\ManageStoreDetails) and read via Modules\Core\Store\Services\
|
||||||
|
* StoreDetailsService. Not config, since a shop owner needs to change these
|
||||||
|
* (e.g. a new IBAN, a new address) without a code deploy.
|
||||||
|
*
|
||||||
|
* name/address/bank_transfer_instructions are locale-keyed JSON — same
|
||||||
|
* shape/resolution as Modules\Core\Payment\Models\PaymentMethod::$name (see
|
||||||
|
* that model's own docblock): $storeDetails->translate('name'). tax_identifier
|
||||||
|
* (ΑΦΜ) and registration_number (ΓΕΜΗ) are legal identifiers, not
|
||||||
|
* locale-dependent text, so they stay plain strings — same for phone.
|
||||||
|
*
|
||||||
|
* No seeder inserting the singleton row — StoreDetailsService::current()
|
||||||
|
* lazily creates it (all-null) on first read, same shape as any other
|
||||||
|
* firstOrCreate()-backed singleton in this codebase.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('store_details', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
$table->json('name')->nullable();
|
||||||
|
$table->json('address')->nullable();
|
||||||
|
$table->string('phone')->nullable();
|
||||||
|
$table->string('tax_identifier')->nullable();
|
||||||
|
$table->string('registration_number')->nullable();
|
||||||
|
$table->json('bank_transfer_instructions')->nullable();
|
||||||
|
$table->timestamps();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('store_details');
|
||||||
|
}
|
||||||
|
};
|
||||||
+57
@@ -0,0 +1,57 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
use Lunar\Models\Language;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* contact_email/mail_from_name join tax_identifier/registration_number/
|
||||||
|
* phone as plain, non-locale-dependent strings on the store_details
|
||||||
|
* singleton (see that table's own migration docblock).
|
||||||
|
*
|
||||||
|
* legal_name is locale-keyed JSON instead — same shape/resolution as
|
||||||
|
* name/address/bank_transfer_instructions (HasTranslations, see
|
||||||
|
* StoreDetails's own docblock) — since a registered company name can
|
||||||
|
* legitimately differ per locale (e.g. a transliterated/translated legal
|
||||||
|
* form). Distinct from the storefront-facing brand name in `name`.
|
||||||
|
*
|
||||||
|
* Backfills every translatable column (name/address/
|
||||||
|
* bank_transfer_instructions/legal_name) with an empty per-locale array
|
||||||
|
* on any row that's still genuinely NULL there — StoreDetailsService::
|
||||||
|
* firstOrCreate() only seeds columns on INSERT, so an existing singleton
|
||||||
|
* row (or one created before a Language row existed, leaving
|
||||||
|
* emptyPerLocale() an empty array at the time) could otherwise keep a
|
||||||
|
* translatable column NULL forever. That's the exact condition
|
||||||
|
* TranslatedText breaks on (see StoreDetailsService's own docblock: a
|
||||||
|
* NULL-starting translatable field silently drops every keystroke and
|
||||||
|
* never persists) — backfilled here for all four columns, not just the
|
||||||
|
* new one, so the same fix covers however the existing row got there.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('store_details', function (Blueprint $table) {
|
||||||
|
$table->string('contact_email')->nullable()->after('phone');
|
||||||
|
$table->string('mail_from_name')->nullable()->after('contact_email');
|
||||||
|
$table->json('legal_name')->nullable()->after('registration_number');
|
||||||
|
});
|
||||||
|
|
||||||
|
$emptyPerLocale = json_encode(
|
||||||
|
Language::query()->pluck('code')->mapWithKeys(fn (string $code) => [$code => ''])->all()
|
||||||
|
);
|
||||||
|
|
||||||
|
foreach (['name', 'address', 'bank_transfer_instructions', 'legal_name'] as $column) {
|
||||||
|
DB::table('store_details')->whereNull($column)->update([$column => $emptyPerLocale]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('store_details', function (Blueprint $table) {
|
||||||
|
$table->dropColumn(['contact_email', 'mail_from_name', 'legal_name']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* otp_code was stored in plaintext (a raw 6-digit string) and compared
|
||||||
|
* with hash_equals() against the plaintext guess in
|
||||||
|
* Modules\Core\Auth\Services\UserOtpService — hash_equals() only
|
||||||
|
* prevents a timing attack, it does nothing to protect the code itself
|
||||||
|
* from anyone with read access to the row. Replaced with a bcrypt hash,
|
||||||
|
* same pattern Modules\Core\Customer\Services\CustomerEmailChangeService
|
||||||
|
* already uses for its own pending_email_code_hash column.
|
||||||
|
*
|
||||||
|
* No backfill: any code mid-flight when this deploys is invalidated —
|
||||||
|
* codes expire in 10 minutes anyway, so the real-world impact is a
|
||||||
|
* shopper re-requesting one, not lost work.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->string('otp_code_hash')->nullable()->after('password');
|
||||||
|
});
|
||||||
|
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('otp_code');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->string('otp_code', 6)->nullable()->after('password');
|
||||||
|
});
|
||||||
|
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('otp_code_hash');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Same fix as 2026_09_30_000001_hash_otp_code_on_users_table.php, for
|
||||||
|
* staff logins — see that migration's own docblock. This path was
|
||||||
|
* additionally weaker: Modules\Core\Auth\Services\OtpService compared
|
||||||
|
* with a loose != rather than hash_equals(), so it had no timing-attack
|
||||||
|
* protection at all on top of the plaintext storage.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('lunar_staff', function (Blueprint $table) {
|
||||||
|
$table->string('otp_code_hash')->nullable()->after('password');
|
||||||
|
});
|
||||||
|
|
||||||
|
Schema::table('lunar_staff', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('otp_code');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('lunar_staff', function (Blueprint $table) {
|
||||||
|
$table->string('otp_code', 6)->nullable()->after('password');
|
||||||
|
});
|
||||||
|
|
||||||
|
Schema::table('lunar_staff', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('otp_code_hash');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* - tracking_reference becomes optional: some carriers only issue the
|
||||||
|
* voucher number when the label is printed (ELTA's pending vouchers).
|
||||||
|
* Still unique — Postgres allows any number of NULLs under a unique index.
|
||||||
|
* - order_id becomes optional: vouchers pulled from a carrier's own list
|
||||||
|
* can exist before they're linked to an order.
|
||||||
|
* - source records where the shipment came from: created (our admin, via
|
||||||
|
* the carrier's API), manual_voucher (an integrated carrier's voucher
|
||||||
|
* typed in by staff), manual (a carrier with no integration), synced
|
||||||
|
* (pulled from a carrier's voucher list).
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('shipments', function (Blueprint $table) {
|
||||||
|
$table->string('tracking_reference')->nullable()->change();
|
||||||
|
$table->unsignedBigInteger('order_id')->nullable()->change();
|
||||||
|
$table->string('source')->default('created')->index()->after('carrier');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('shipments', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('source');
|
||||||
|
$table->unsignedBigInteger('order_id')->nullable(false)->change();
|
||||||
|
$table->string('tracking_reference')->nullable(false)->change();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
+709
@@ -0,0 +1,709 @@
|
|||||||
|
# ELTA Courier — API and printing reference
|
||||||
|
|
||||||
|
A reference for designing the ELTA Courier integration, reconstructed from ELTA's own
|
||||||
|
desktop client ("ELTA Customer Client", `ELTA_PEL.exe`, client version `0032`), decompiled
|
||||||
|
from ELTA's official installer (`https://www.elta-courier.gr/app/ELTA_COURIER_SETUP.msi`).
|
||||||
|
The decompiled source lives next to this repo in `../elta-courier-decompiled/` (see its
|
||||||
|
README); file and line references below point there. Where something was confirmed by
|
||||||
|
calling ELTA's test account from our integration, it says so.
|
||||||
|
|
||||||
|
Two axes:
|
||||||
|
|
||||||
|
- **Part A — the API**: every SOAP operation, its inputs and outputs, the values the
|
||||||
|
client sends, and the business rules it enforces before calling.
|
||||||
|
- **Part B — printing**: what the client prints, when, from which data, with every
|
||||||
|
fixed text, every image and every formatting rule.
|
||||||
|
|
||||||
|
Part C lists where our current integration (`src/Shipping/Carriers/Elta/`) differs.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Part A — The API
|
||||||
|
|
||||||
|
## A1. Transport
|
||||||
|
|
||||||
|
| | |
|
||||||
|
|---|---|
|
||||||
|
| Host | **`https://clients.elta-courier.gr`** (port 443). Verified 2026-09-30: the hostname now resolves to `18.156.16.255` (AWS Frankfurt) and serves HTTPS with a valid certificate; answers are identical to the old host. |
|
||||||
|
| Old host | `212.205.47.226:9003` (the installer's `hosts-entry.txt`) — **plain HTTP only**: HTTPS there fails the TLS handshake (`SSL_ERROR_SYSCALL`), and `https://clients.elta-courier.gr:9003` fails with `wrong version number` (that port speaks HTTP). |
|
||||||
|
| Scheme | The client builds its URL as `"https://" + <first field of ip.txt>` (`Form1.cs:213`), i.e. HTTPS on the hostname. |
|
||||||
|
| Reliability | The HTTPS host was slower (~0.4–0.8 s vs ~0.2 s) and returned one transient HTTP 500 and one 15 s timeout during testing; retry on network errors / 5xx. |
|
||||||
|
| Protocol | SOAP 1.1, document/literal. One endpoint URL for every operation. |
|
||||||
|
| Namespace | Each operation has its own: `/<OPERATION>` (e.g. `/PELVGNEW`). |
|
||||||
|
| Body | `<READ>` element in that namespace, with each parameter as a child element. |
|
||||||
|
| SOAPAction | We send `Get` (works); the proxies' `SoapDocumentMethod` arguments weren't decodable. |
|
||||||
|
| Authentication | None at the HTTP/SOAP level. Account codes travel as ordinary body parameters. `PELLOGINNEW` checks the password; other operations take the account/user code without a password. |
|
||||||
|
| Proxy | Optional corporate HTTP proxy from `proxy.txt` (`ip;port;user;pass`), with `Expect100Continue = false`. Local-network only; nothing to do with ELTA auth. |
|
||||||
|
| WSDL | None published for these operations; the shapes come from the client's generated proxies (`ELTA_PEL.pel_*/`). |
|
||||||
|
|
||||||
|
**Every response** carries:
|
||||||
|
|
||||||
|
- `st_flag` — the return value of `READ` (declared `integer`). **`"0"` = success**; anything
|
||||||
|
else is an error.
|
||||||
|
- `st_title` — the message (Greek) to show on error, e.g. `Λάθος Τ.Κ.` (wrong postcode),
|
||||||
|
`Λάθος ΣΥΔΕΤΑ` (wrong voucher), `Δεν Επιτρέπεται! Εχει Γίνει Εκτύπωση` (not allowed,
|
||||||
|
already printed).
|
||||||
|
|
||||||
|
**Paging convention** (every list operation): a page is at most **100 rows**. If a page
|
||||||
|
comes back with exactly 100 rows, call again passing the last row's id as the cursor
|
||||||
|
(`in_id`, `pel_sub_code` or `a_paral_code`, depending on the operation); the client stops
|
||||||
|
when a page has fewer than 100 (or the 100th row is empty).
|
||||||
|
|
||||||
|
**Number formats**: amounts come back right-aligned in 9 characters (`" 0.00"`);
|
||||||
|
dates go in as `dd/MM/yyyy`; timestamps come back as `yyyyMMddHHmm[ss]` in Greek local time.
|
||||||
|
|
||||||
|
## A2. Operations at a glance
|
||||||
|
|
||||||
|
| Operation | Purpose | Client screen |
|
||||||
|
|---|---|---|
|
||||||
|
| `PELLOGINNEW` | Log in, get account details and the user's station | Login |
|
||||||
|
| `PELVERNEW` | Latest client version (triggers FTP self-update) | Login |
|
||||||
|
| `PELLISTNEW` | Sub-senders of a multi-sender account | Login |
|
||||||
|
| `PELSRV` | Service catalogue | Login |
|
||||||
|
| `PELSUR` | Surcharge catalogue | **Never called** (surcharges are hardcoded) |
|
||||||
|
| `PELPARALLIST1` | Saved recipients (address book) | Login |
|
||||||
|
| `PELTKNEW` | Postcode → station, default service, localities | Voucher entry |
|
||||||
|
| `PELTK` | Postcode → station, service (older/simpler) | Voucher entry, recipient pick |
|
||||||
|
| `PELTKBOX` | Postcode → PostBox station and service | Voucher entry (PostBox) |
|
||||||
|
| `PELTK1` | Is this postcode valid? | File/Excel import |
|
||||||
|
| `PELVGNEW` | **Create a voucher** (pending or issued) | Voucher entry |
|
||||||
|
| `PELVGUP` | Edit a pending voucher | Voucher entry (edit mode) |
|
||||||
|
| `PELVGINNEW` | Create a pending voucher, simplified (bulk) | File/Excel import |
|
||||||
|
| `PELVG01NEW1` | **Issue** a pending voucher (and re-print an issued one) | Batch processing |
|
||||||
|
| `PELVGDEL` | Delete a pending voucher | Batch processing |
|
||||||
|
| `PELPARALVGNEW1` | List pending (and optionally issued) vouchers | Batch processing |
|
||||||
|
| `PELTTNEW01` | Track one voucher (by voucher number **or reference**) | Tracking |
|
||||||
|
| `PELMANIF2` | Vouchers in a date range with latest status, by status | Multiple search |
|
||||||
|
| `PELMANIFNEW` | Index / manifest of vouchers in a date range, with totals | Index report |
|
||||||
|
| `PELPARALIN` / `PELPARALUP` / `PELPARALSE` | Address book: insert / update / fetch one | Recipients |
|
||||||
|
| `PELPARALDE` / `PELPARALDE1` | Address book: delete one / delete a code range | Recipients |
|
||||||
|
| `PELPARALCE` | Address book: check a code and postcode before import | Recipient Excel import |
|
||||||
|
|
||||||
|
## A3. Account and reference data
|
||||||
|
|
||||||
|
### `PELLOGINNEW` — log in
|
||||||
|
|
||||||
|
| In | |
|
||||||
|
|---|---|
|
||||||
|
| `pel_code` | Customer (account) code, e.g. test account `999999999` |
|
||||||
|
| `user_code` | User code (digits only in the client) |
|
||||||
|
| `user_pass` | Password |
|
||||||
|
|
||||||
|
| Out | |
|
||||||
|
|---|---|
|
||||||
|
| `st_title` | Error message |
|
||||||
|
| `pel_flag` | `"1"` = multi-sender account (has sub-senders, see `PELLISTNEW`); `"0"` = single sender |
|
||||||
|
| `pel_titles`, `pel_addres`, `pel_area`, `pel_tk`, `pel_tel_1`, `pel_tel_2` | Account name/address/area/postcode/phones — printed as the **sender** on single-sender accounts |
|
||||||
|
| `user_station` | The user's ELTA station code — sent as `sender_station` to the postcode lookups and to `PELVG01NEW1`, and printed as the deposit station (`Γρ.Κατάθεσης`) |
|
||||||
|
| `user_pel_code` | The account code to use in every later call (`pel_code` / `pel_apost_code`) |
|
||||||
|
|
||||||
|
After a successful login the client calls `PELVERNEW` (if an FTP address is configured);
|
||||||
|
if `ag_wupdate_version` > its own version (`0032`) it downloads an update over FTP and
|
||||||
|
stops. Then it loads the reference lists below.
|
||||||
|
|
||||||
|
### `PELVERNEW` — client version
|
||||||
|
No inputs. Out: `st_title`, `ag_wupdate_version`.
|
||||||
|
|
||||||
|
### `PELLISTNEW` — sub-senders (multi-sender accounts only)
|
||||||
|
In: `pel_code` (= `user_pel_code`), `pel_sub_code` (cursor: last code of the previous page,
|
||||||
|
`""` first). Out: `st_title`, `ag_rec_rec[]` (100/page), `ag_rec_counter`.
|
||||||
|
Row: `ag_code`, `ag_title`, `ag_adress`, `ag_area`, `ag_tk`, `ag_tel_1`, `ag_tel_2`,
|
||||||
|
`ag_st` (station), `ag_st_t` (station title).
|
||||||
|
Used to pick the **sender** of a voucher and the **return-to** party (see special handling).
|
||||||
|
|
||||||
|
### `PELSRV` — service catalogue
|
||||||
|
No inputs. Out: `st_title`, `ag_srv_rec[]` (up to 150: `ag_code`, `ag_title`), `ag_srv_counter`.
|
||||||
|
The service picker only offers services whose code starts with the **same two digits** as
|
||||||
|
the one the postcode lookup returned (same family).
|
||||||
|
|
||||||
|
### `PELSUR` — surcharge catalogue
|
||||||
|
No inputs. Out: `ag_sur_rec[]` (`ag_code`, `ag_title`). **The client never calls it**; its
|
||||||
|
surcharges are hardcoded (see A5).
|
||||||
|
|
||||||
|
### `PELPARALLIST1` — saved recipients
|
||||||
|
In: `pel_code`, `a_paral_code` (cursor). Out: `ag_rec_rec[]` (100/page: `ag_code`,
|
||||||
|
`ag_title`, `ag_adress`, `ag_area`, `ag_tk`, `ag_tel_1`, `ag_tel_2`), `ag_rec_counter`.
|
||||||
|
|
||||||
|
## A4. Postcode, station and service lookups
|
||||||
|
|
||||||
|
### `PELTKNEW` — the main lookup
|
||||||
|
In: `pel_tk` (postcode), `sender_station` (= `user_station`).
|
||||||
|
|
||||||
|
| Out | |
|
||||||
|
|---|---|
|
||||||
|
| `pel_fields.rec_station`, `rec_station_t` | Destination station code and title (`Γρ. Επίδοσης`) |
|
||||||
|
| `pel_fields.pel_service`, `pel_service_t` | Default service for that postcode |
|
||||||
|
| `pel_fields.pel_service_t201`, `pel_service_t231` | Titles of services 201 and 231 (see localities) |
|
||||||
|
| `a_lview_data[]` | Up to 300 **localities** within the postcode |
|
||||||
|
| `locations_counter` | Number of localities; `"0"` = none, use `pel_service` as is |
|
||||||
|
|
||||||
|
Locality row: `wloc_code`, `wloc_title`, `wloc_county`, `wloc_countyt`, `wloc_station`,
|
||||||
|
`wloc_stationt`, `wloc_distance` (decimal), `wloc_postal_code`, `wloc_coordinate_x`,
|
||||||
|
`wloc_coordinate_y`, `wloc_disp_flag`, `wloc_comments`.
|
||||||
|
|
||||||
|
**When a postcode has localities**, the user must pick one (`Sydeta.cs:3320`):
|
||||||
|
|
||||||
|
- the recipient **area** becomes `"<wloc_code>/<wloc_title>"`;
|
||||||
|
- `wloc_disp_flag = "1"` (hard to reach, `ΔΥΣΠΡΟΣΙΤΟ`) → service **`231`**
|
||||||
|
`ΠΟΛΗ ΠΟΛΗ -ΠΠ- ΔΥΣΠΡΟΣΙΤΟ`; otherwise service **`201`** `ΕΝΤΟΣ ΠΟΛΗΣ -ΠΠ- ΕΠΟΜΕΝΗ`.
|
||||||
|
|
||||||
|
### `PELTK` — simple lookup
|
||||||
|
In: `pel_tk`, `sender_station`. Out: `st_title`, `rec_station`, `rec_station_t`,
|
||||||
|
`pel_service`, `pel_service_t`. Used when a saved recipient is picked.
|
||||||
|
|
||||||
|
### `PELTKBOX` — PostBox lookup
|
||||||
|
In: `pel_tk`, `sender_station`. Out: `st_title`, `pel_fields` (`rec_station`,
|
||||||
|
`rec_station_t`, `pel_service`, `pel_service_t`). Used instead of `PELTKNEW` when
|
||||||
|
"ΕΠΙΔΟΣΗ POST BOX" is ticked; on error the PostBox option is unticked.
|
||||||
|
|
||||||
|
### `PELTK1` — validate a postcode
|
||||||
|
In: `pel_tk`. Out: `st_title` (`st_flag` ≠ 0 = invalid). Used by the bulk imports.
|
||||||
|
|
||||||
|
## A5. Vouchers (ΣΥ.ΔΕ.ΤΑ.)
|
||||||
|
|
||||||
|
### Lifecycle
|
||||||
|
|
||||||
|
```
|
||||||
|
PELVGNEW (pel_insert_flag "0") ─► pending: has pel_vg_id, no voucher number
|
||||||
|
│ │ editable (PELVGUP), deletable (PELVGDEL)
|
||||||
|
│ ▼
|
||||||
|
│ PELVG01NEW1 (issue) ─► issued: voucher number, OCR line,
|
||||||
|
│ stations, service; child numbers
|
||||||
|
└── (pel_insert_flag "1") ─► issued immediately, same outputs as PELVGNEW
|
||||||
|
```
|
||||||
|
|
||||||
|
- **Only pending vouchers can be deleted.** An issued one is refused (`Δεν Επιτρέπεται!
|
||||||
|
Εχει Γίνει Εκτύπωση`). Confirmed on the test account.
|
||||||
|
- In the client, **issuing = printing**: "Print" in batch processing calls `PELVG01NEW1`
|
||||||
|
and prints the result. It calls `PELVG01NEW1` for already-issued rows too, so it also
|
||||||
|
serves to **re-print** (ELTA returns the existing voucher's data).
|
||||||
|
- A **multi-parcel** send is **one** voucher record (`pel_temaxia` > 1). The extra parcels
|
||||||
|
get their own numbers (`vg_child_no[]`) only when the voucher is issued. They are not
|
||||||
|
separately listed, deletable or trackable (tracking an extra parcel's number returns
|
||||||
|
`Λάθος ΣΥΔΕΤΑ` — confirmed).
|
||||||
|
|
||||||
|
### `PELVGNEW` — create a voucher
|
||||||
|
|
||||||
|
The client's call (`Sydeta.cs:1550`), in order:
|
||||||
|
|
||||||
|
| # | Parameter | Client value | Notes / rules |
|
||||||
|
|---|---|---|---|
|
||||||
|
| 1 | `pel_apost_code` | Sender code: `user_pel_code` (single-sender), or the chosen sub-sender | Required |
|
||||||
|
| 2 | `pel_paral_name` | Recipient name | Required; up to 150 chars in the form |
|
||||||
|
| 3 | `pel_paral_address` | Recipient address | Required; up to 150 |
|
||||||
|
| 4 | `pel_paral_area` | Recipient area (or `"<wloc_code>/<wloc_title>"`) | Up to 40 |
|
||||||
|
| 5 | `pel_paral_tk` | Postcode | Required; 5 digits |
|
||||||
|
| 6 | `pel_paral_thl_1` | Phone | Digits only, up to 10. **At least one of the two phones is required** |
|
||||||
|
| 7 | `pel_paral_thl_2` | Mobile | Up to 10. PostBox: required, 10 digits, starting `69` |
|
||||||
|
| 8 | `pel_service` | Service code from the postcode lookup / picker | **Required** by the client (`Δεν Εχει Οριστεί Υπηρεσία`). We send `""` and ELTA assigns one on issue — works on the test account |
|
||||||
|
| 9 | `pel_baros` | Weight in kg, `.` decimal | **Required, > 0** |
|
||||||
|
| 10 | `pel_baros_xyz` | Volumetric weight: **X × Y × Z (cm) ÷ 5000**, 3 decimals | Only when dimensions are given |
|
||||||
|
| 11–13 | `pel_x`, `pel_y`, `pel_z` | Dimensions in cm, integers up to 3 digits | All three > 0 or none (`Λάθος Διαστάσεις`) |
|
||||||
|
| 14 | `pel_temaxia` | Number of pieces | **Required, 1–20** (`Μέγιστος Επιτρεπόμενος Αριθμός Τεμαχίων 20.`) |
|
||||||
|
| 15 | `pel_paral_sxolia` | Remarks **+ envelope/parcel flag**, see below | Remarks up to **90** chars |
|
||||||
|
| 16 | `pel_sur_1` | `002` special handling, or `917` PostBox | Fixed slot, see below |
|
||||||
|
| 17 | `pel_sur_2` | `003` set delivery time | Fixed slot |
|
||||||
|
| 18 | `pel_sur_3` | `004` Saturday delivery | Fixed slot |
|
||||||
|
| 19 | `pel_ant_poso` | **COD cash** amount | `.` decimal |
|
||||||
|
| 20–23 | `pel_ant_poso1`…`4` | COD **cheque** amounts (up to 4 cheques) | |
|
||||||
|
| 24–27 | `pel_ant_date1`…`4` | Each cheque's due date, `dd/MM/yyyy` | Required per cheque; **not in the past** |
|
||||||
|
| 28 | `pel_asf_poso` | Insured value | **The client always sends a single space `" "`** — it has no insurance input |
|
||||||
|
| 29 | `pel_user` | `user_code` | |
|
||||||
|
| 30 | `pel_ref_no` | "Reference No" | Up to 30 chars; printed on the voucher, searchable, trackable |
|
||||||
|
| 31 | `pel_insert_flag` | `"1"` = issue now ("Εκτύπωση ΣΥ.ΔΕ.ΤΑ." ticked), `"0"` = pending | We send `"0"` |
|
||||||
|
| 32 | `pel_paral_code` | Saved recipient's code, if picked from the address book | |
|
||||||
|
| 33 | `pel_retur_code` | Return-to party's code (special handling only) | See below |
|
||||||
|
|
||||||
|
**Envelope or parcel (mandatory).** The client makes the user choose `Φάκελος` (envelope)
|
||||||
|
or `Δέμα` (parcel) (`Δεν Εχει Επιλεγεί Είδος`), and encodes it **inside
|
||||||
|
`pel_paral_sxolia`**: the remarks right-aligned in 99 characters, then `"1"` (envelope) or
|
||||||
|
`"2"` (parcel) — 100 characters total (`Sydeta.cs:1530`):
|
||||||
|
|
||||||
|
```csharp
|
||||||
|
pel_paral_sxolia = $"{remarks.Trim(),99}" + "2"; // parcel
|
||||||
|
```
|
||||||
|
|
||||||
|
(Only `PELVGNEW` does this; `PELVGUP` and `PELVGINNEW` send the remarks plain.)
|
||||||
|
|
||||||
|
**Surcharges go in fixed slots**, not in order: special handling is always `pel_sur_1`, set
|
||||||
|
time always `pel_sur_2`, Saturday always `pel_sur_3`; PostBox (`917`) takes `pel_sur_1`.
|
||||||
|
The client's surcharges:
|
||||||
|
|
||||||
|
| Code | Surcharge | Slot |
|
||||||
|
|---|---|---|
|
||||||
|
| `002` | ΕΙΔΙΚΗ ΔΙΑΧΕΙΡΙΣΗ (special handling) | `pel_sur_1` |
|
||||||
|
| `003` | ΠΡΟΚΑΘΟΡΙΣΜΕΝΗ ΩΡΑ (set delivery time) | `pel_sur_2` |
|
||||||
|
| `004` | ΕΠΙΔΟΣΗ ΣΑΒΒΑΤΟΥ (Saturday delivery) | `pel_sur_3` |
|
||||||
|
| `917` | ΕΠΙΔΟΣΗ POST BOX (PostBox delivery) | `pel_sur_1` |
|
||||||
|
|
||||||
|
**Special handling (`002`) and the return-to party.** Ticking special handling sets a
|
||||||
|
return-to party (`pel_retur_code`), defaulting to the sender; multi-sender accounts can
|
||||||
|
pick another sub-sender. When ELTA then returns a **return voucher** (`return_vg`), the
|
||||||
|
client prints it (B6).
|
||||||
|
|
||||||
|
**Business rules the client enforces** (all before calling ELTA):
|
||||||
|
|
||||||
|
- name, address, postcode, service required; at least one phone; pieces 1–20; weight > 0;
|
||||||
|
- COD is **cash or cheques, never both** (`Δεν Επιτρέπεται Αντικαταβολή Μετρητά Και Επιταγή`);
|
||||||
|
- each cheque needs a due date, not in the past;
|
||||||
|
- **PostBox**: not with special handling (`Δεν Επιτρέπεται Post Box Με ειδική Διαχείρηση`),
|
||||||
|
not with COD (`Δεν Επιτρέπεται Post Box Με Αντικαταβολή`), and needs a 10-digit mobile
|
||||||
|
starting `69` (`Δεν Επιτρέπεται Post Box Χωρίς Κινητό Τηλέφωνο` / `...Λάθος Κινητό Τηλέφωνο`);
|
||||||
|
- envelope or parcel must be chosen.
|
||||||
|
|
||||||
|
**Outputs** (same set from `PELVG01NEW1`, plus stations/service there):
|
||||||
|
|
||||||
|
| Out | |
|
||||||
|
|---|---|
|
||||||
|
| `vg_code` | The voucher number, e.g. `NZ000987368GR` (empty when pending) |
|
||||||
|
| `vg_child_no[]` | One number per extra parcel of a multi-parcel send (up to 149) |
|
||||||
|
| `ocr_line` | OCR line, e.g. `>14260009873682< 17004> 1317759< 25>` — printed at the foot of the A4 payment stub; characters 2–14 are the 13-digit reference printed on the voucher |
|
||||||
|
| `return_vg`, `r_ocr_line` | Return voucher number and its OCR line (special handling) |
|
||||||
|
| `epitagh_vg`, `e_ocr_line` | Cheque-return voucher number and its OCR line (COD by cheque) |
|
||||||
|
| `date_time` | Issue time, `yyyyMMddHHmm` (Greek time). The client picks the report by it (≥ `202410` → current reports) |
|
||||||
|
|
||||||
|
`PELVGNEW` does **not** return the pending voucher's id (`pel_vg_id`); find it with
|
||||||
|
`PELPARALVGNEW1` (match `pel_ref_no`, empty `pel_paral_vg`, highest id).
|
||||||
|
|
||||||
|
### `PELVG01NEW1` — issue (and re-print)
|
||||||
|
In: `pel_id` (= `pel_vg_id`, declared `integer`), `sender_station` (= `user_station`).
|
||||||
|
Out: `st_title`, `return_vg`, `epitagh_vg`, `vg_code`, `vg_child_no[]`, `ocr_line`,
|
||||||
|
`r_ocr_line`, `e_ocr_line`, `date_time`, `rec_station`, `rec_station_t` (destination
|
||||||
|
station), `rec_srv`, `rec_srv_t` (the service ELTA settled on, e.g. `201` `ΠΟΛΗ ΠΟΛΗ - ΠΠ`).
|
||||||
|
|
||||||
|
### `PELVGUP` — edit a pending voucher
|
||||||
|
In: `pel_id`, then the same fields as `PELVGNEW` 1–30 and `pel_paral_code` (no
|
||||||
|
`pel_insert_flag`, no `pel_retur_code`; remarks sent plain). Out: `st_title`.
|
||||||
|
|
||||||
|
### `PELVGINNEW` — bulk insert (pending)
|
||||||
|
Used by the file/Excel imports. In: `pel_code` (sender), `user_code`, `paral_title`,
|
||||||
|
`paral_adress`, `paral_area`, `paral_tk`, `paral_thl1`, `paral_thl2`, `paral_tem`
|
||||||
|
(pieces), `paral_baros`, `paral_sxolia`, `paral_ant_m` (COD cash), `paral_ant_e` (COD
|
||||||
|
cheque), `paral_ant_date` (cheque due date), `paral_da` (always `""`), `paral_ref`,
|
||||||
|
`paral_sur_1`…`3`, `retour_code`. Out: `st_title`. No service, no envelope/parcel flag,
|
||||||
|
no dimensions — ELTA works them out.
|
||||||
|
|
||||||
|
### `PELVGDEL` — delete a pending voucher
|
||||||
|
In: `pel_vg_id` (the pending id, not the voucher number). Out: `st_title`. The client
|
||||||
|
only offers it for rows without a voucher number.
|
||||||
|
|
||||||
|
### `PELPARALVGNEW1` — list pending vouchers
|
||||||
|
In: `pel_code`, `pel_user_code`, `flag_1` (`"1"` = "Εμφάνιση Όλων": include issued ones),
|
||||||
|
`flag_2` (`"1"` = "Όλοι Οι Χρήστες": all the account's users), `in_id` (cursor: last
|
||||||
|
`pel_vg_id`, `"0"` first). Out: `st_title`, `vg_rec[]` (100/page), `vg_rec_counter`.
|
||||||
|
|
||||||
|
Row fields: `pel_vg_id`, `pel_apost_code`, `pel_paral_vg` (voucher number; empty =
|
||||||
|
pending), `pel_paral_code`, `pel_paral_name`, `pel_paral_address`, `pel_paral_area`,
|
||||||
|
`pel_paral_tk`, `pel_paral_thl_1`, `pel_paral_thl_2`, `pel_service`, `pel_baros`,
|
||||||
|
`pel_baros_xyz`, `pel_x`, `pel_y`, `pel_z`, `pel_temaxia`, `pel_paral_sxolia`,
|
||||||
|
`pel_ant_poso`, `pel_ant_poso1`…`4`, `pel_ant_date1`…`4`, `pel_asf_poso`, `pel_ref_no`,
|
||||||
|
`pel_sur_1`…`3`, `pel_retour`.
|
||||||
|
|
||||||
|
## A6. Tracking and search
|
||||||
|
|
||||||
|
### `PELTTNEW01` — track one voucher
|
||||||
|
In: `web_vg` — **a voucher number or our reference number** (the client's field is labelled
|
||||||
|
`ΣΥ.Δ.ΕΛ.ΤΑ./Reference No`), `pel_code`.
|
||||||
|
|
||||||
|
Out: `st_title`, `web_status[]` (up to 50 checkpoints), `web_status_counter`, `pel_rec`.
|
||||||
|
|
||||||
|
Checkpoint: `web_date_time` (`yyyyMMddHHmmss`, Greek time), `web_station`,
|
||||||
|
`web_status_name` (e.g. `ΔΗΜΙΟΥΡΓΙΑ ΣΥ.ΔΕ.ΤΑ. ΑΠΟ ΠΕΛΑΤΗ`, in unaccented capitals),
|
||||||
|
`web_sxolia` (e.g. `PEL CLIENT`). Empty rows pad the array; skip rows without a date.
|
||||||
|
|
||||||
|
`pel_rec` (the voucher record):
|
||||||
|
|
||||||
|
| Field | Meaning |
|
||||||
|
|---|---|
|
||||||
|
| `a_vg_3` | The voucher number |
|
||||||
|
| `a_vg_2` | Its **return** voucher — verified: a special-handling voucher's `return_vg` came back here |
|
||||||
|
| `a_vg_1` | Its **cheque** voucher (by elimination; the client's field labels suggested the opposite) |
|
||||||
|
| `a_ref` | Our reference |
|
||||||
|
| `a_rec_title`, `a_rec_address`, `a_rec_area`, `a_rec_postal`, `a_rec_tel_1`, `a_rec_tel_2` | Recipient |
|
||||||
|
| `a_rec_station`, `a_rec_station_t` | Destination station |
|
||||||
|
| `a_services` | Service (code/text) |
|
||||||
|
| `a_weight` (decimal), `a_no_of_packages` | Weight, pieces |
|
||||||
|
| `a_antik` (decimal), `a_antik_text` | COD amount and text |
|
||||||
|
| `a_antik1` (decimal), `a_antik_text1` | **Remittance** ("Απόδοση") — the COD paid back to the merchant |
|
||||||
|
| `a_sender_date` | Date sent |
|
||||||
|
| `a_rec_name` | **Delivered to** — the name of whoever received it |
|
||||||
|
| `a_rec_date_time` | **Delivered at** — blank until delivered |
|
||||||
|
| `a_apost`, `a_sxolia` | Sender, remarks |
|
||||||
|
|
||||||
|
### `PELMANIF2` — vouchers in a date range, by status ("Πολλαπλή Αναζήτηση")
|
||||||
|
In: `pel_code`, `date_1`, `date_2` (`dd/MM/yyyy`), `paral_code` (optional recipient),
|
||||||
|
`status_flag`, `in_id` (cursor: last `pel_col_id`).
|
||||||
|
|
||||||
|
| `status_flag` | |
|
||||||
|
|---|---|
|
||||||
|
| `0` | All (`Ολα`) |
|
||||||
|
| `1` | Delivered (`Παραδομένα`) |
|
||||||
|
| `2` | Undelivered (`Απαραδοτα`) |
|
||||||
|
| `3` | To be returned (`Προς Επιστροφή`) |
|
||||||
|
|
||||||
|
Row: `pel_col_1` voucher · `pel_col_2` reference · `pel_col_3` recipient · `pel_col_4`
|
||||||
|
postcode · `pel_col_5` station · `pel_col_6` last status · `pel_col_7` remarks/date ·
|
||||||
|
`pel_col_8` COD · `pel_col_id` cursor. Only main vouchers are listed.
|
||||||
|
|
||||||
|
### `PELMANIFNEW` — index / manifest ("Ευρετήριο")
|
||||||
|
In: `pel_code`, `date_1`, `date_2`, `paral_code`, `in_id` (cursor: last `pel_col_15`).
|
||||||
|
Out: `ag_pel_rec[]`, `ag_pel_counter`, **`spel_baros`** (total weight of the page, decimal),
|
||||||
|
**`spel_temaxia`** (total pieces of the page).
|
||||||
|
|
||||||
|
Row: `pel_col_1` voucher · `2` weight · `3` pieces · `4` recipient · `5` address ·
|
||||||
|
`6` postcode · `7` station · `8` sender · `9` reference · `10` COD · `11` **cheque
|
||||||
|
voucher** · `12` **return voucher** · `13` + `14` the two phones · `15` cursor.
|
||||||
|
|
||||||
|
## A7. Address book
|
||||||
|
|
||||||
|
| Operation | In | Out |
|
||||||
|
|---|---|---|
|
||||||
|
| `PELPARALIN` | `pel_code`, `paral_code`, `paral_title`, `paral_adress`, `paral_area`, `paral_tk`, `paral_thl1`, `paral_thl2` | `st_title` |
|
||||||
|
| `PELPARALUP` | same as `PELPARALIN` | `st_title` |
|
||||||
|
| `PELPARALSE` | `pel_code`, `paral_code` | the recipient's fields |
|
||||||
|
| `PELPARALDE` | `pel_code`, `paral_code` | `st_title` |
|
||||||
|
| `PELPARALDE1` | `pel_code`, `paral_code_1`, `paral_code_2` (a code range) | `st_title` |
|
||||||
|
| `PELPARALCE` | `pel_code`, `paral_code`, `paral_tk`, `tk_flag`, `pel_flag` | `st_tk` (`"1"` = bad postcode), `st_code` (`"1"` = code already exists) |
|
||||||
|
|
||||||
|
## A8. Client-side configuration files (for reference)
|
||||||
|
|
||||||
|
| File | Content |
|
||||||
|
|---|---|
|
||||||
|
| `ip.txt` | `<host:port>;<ftp host>` — web-service host (prefixed with `https://`) and update FTP host |
|
||||||
|
| `proxy.txt` | `ip;port;user;pass` |
|
||||||
|
| `printer.txt` | `print_on_create(0/1);printer name;paper size` — `1` = A4, `2` = label (A6) |
|
||||||
|
| `paral.txt`, `awb.txt` | Excel column letters for the recipient (7) and voucher (16) imports |
|
||||||
|
|
||||||
|
## A9. Excel import (voucher columns)
|
||||||
|
|
||||||
|
Recipient name, address, area, postcode, phone, mobile, pieces, weight, remarks, COD cash,
|
||||||
|
COD cheque, cheque due date, reference, surcharge 1–3 — each mapped to a column letter
|
||||||
|
(defaults `A`…`P`). Rows are validated (postcode via `PELTK1`, PostBox via `PELTKBOX`,
|
||||||
|
pieces ≤ 20, …), invalid ones shown red and skipped; valid ones go through `PELVGINNEW`
|
||||||
|
as pending vouchers, issued later from batch processing.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Part B — Printing
|
||||||
|
|
||||||
|
## B1. When the client prints
|
||||||
|
|
||||||
|
- **On creation**, if "Εκτύπωση ΣΥ.ΔΕ.ΤΑ." is ticked (default from `printer.txt`): it sends
|
||||||
|
`pel_insert_flag = "1"` and prints straight away.
|
||||||
|
- **From batch processing** ("Εκτύπωση Επιλεγμένων" / "Εκτύπωση Όλων"): issues each voucher
|
||||||
|
with `PELVG01NEW1` and prints it.
|
||||||
|
|
||||||
|
Each print job prints, in order (`Sydeta.cs:1646`, `epexergasia.cs`):
|
||||||
|
|
||||||
|
1. the **main voucher** (`print_vg`);
|
||||||
|
2. one label per **extra parcel**, `002/00n`, `003/00n`, … (`print_child`) — printing the
|
||||||
|
main voucher always prints every parcel; there is no way to print one extra parcel alone;
|
||||||
|
3. the **return voucher**, if ELTA returned `return_vg` (B6);
|
||||||
|
4. the **cheque-return voucher**, if ELTA returned `epitagh_vg` (B7).
|
||||||
|
|
||||||
|
## B2. Paper and report selection
|
||||||
|
|
||||||
|
| Paper (`printer.txt`) | Page (render DeviceInfo) | Main voucher | Extra parcel |
|
||||||
|
|---|---|---|---|
|
||||||
|
| `1` A4 | 21 × 29.7 cm, no margins | `sydetaE.rdlc` | `sydetaE1.rdlc` (separate, smaller report) |
|
||||||
|
| `2` label | **10.4 × 14.8 cm** (not ISO A6's 10.5), no margins | `SydetaLabelE.rdlc` | `SydetaLabelE.rdlc` (same report) |
|
||||||
|
|
||||||
|
Vouchers issued before October 2024 (`date_time` < `202410`) use the older reports
|
||||||
|
(`sydeta`, `sydeta1`, `SydetaLabel1`). `sydeta_R`, `sydeta1_R`, `SydetaLabel2` are only
|
||||||
|
on-screen previews. Rendering is EMF at the page size, drawn to the whole page, sent to the
|
||||||
|
configured printer without a dialog (a print dialog only if no printer is configured).
|
||||||
|
|
||||||
|
## B3. The print data — every field
|
||||||
|
|
||||||
|
The reports read one dataset row (`DataSet1.print_fields`). How the client fills it for a
|
||||||
|
**main voucher** (`Sydeta.cs::print_vg`, `epexergasia.cs::print_vg`):
|
||||||
|
|
||||||
|
**Sender (`sender_1`…`5`)**
|
||||||
|
|
||||||
|
| | |
|
||||||
|
|---|---|
|
||||||
|
| `sender_1` | `"Κωδικός:" + sender code` |
|
||||||
|
| `sender_2`, `sender_3` | Sender name, split at 40 characters (`sender_3` = the next 40, else `""`) |
|
||||||
|
| `sender_4` | Sender address (first 40 characters) |
|
||||||
|
| `sender_5` | `"TK:" + postcode + " " + area + " ΤΗΛ:" + phone`, cut at 40 |
|
||||||
|
|
||||||
|
Sender = the account (single-sender) or the chosen sub-sender.
|
||||||
|
|
||||||
|
**Recipient (`rec_1`…`5`)**
|
||||||
|
|
||||||
|
| | |
|
||||||
|
|---|---|
|
||||||
|
| `rec_1`, `rec_2` | Recipient name, split at 40 (`rec_2` = the rest, else `""`) |
|
||||||
|
| `rec_3` | Address (first 40) |
|
||||||
|
| `rec_4` | `"TK:" + postcode + " " + area` |
|
||||||
|
| `rec_5` | `"ΤΗΛ: " + phone + " " + mobile` |
|
||||||
|
|
||||||
|
**Voucher and routing**
|
||||||
|
|
||||||
|
| Field | Value |
|
||||||
|
|---|---|
|
||||||
|
| `sydeta` | Voucher number, e.g. `NZ000987368GR` |
|
||||||
|
| `barcode` | `"*" + voucher + "*"` — printed in a **Code 39 barcode font** (the asterisks are Code 39 start/stop) |
|
||||||
|
| `barcode_2` | `ocr_line` characters 2–14 (13 digits), e.g. `1426000987368` |
|
||||||
|
| `date` | A4: `dd/MM/yyyy HH:mm`; label: `dd/MM/yyyy` |
|
||||||
|
| `time` | Label only: `HH:mm` |
|
||||||
|
| `service`, `service_title` | Service code and title, e.g. `201` / `ΠΟΛΗ ΠΟΛΗ - ΠΠ` |
|
||||||
|
| `station_apo` | Deposit station = the user's station (`Γρ.Κατάθεσης`) |
|
||||||
|
| `station_pros`, `station_pros_title` | Destination station (`Γρ. Επίδοσης`), e.g. `94580` / `ΙΩΑΝΝΙΝΑ - ΠΡΑΚΤΟΡΕΙΟ` |
|
||||||
|
| `xreosi` | `ΧΡΕΩΣΗ ΑΠΟΣΤΟΛΕΑ ΠΙΣΤΩΣΗ` (charged to sender, on credit) |
|
||||||
|
| `siimvasi` | `131775-9` (fixed; the ELTA "Ταχυπληρωμή" account number) |
|
||||||
|
| `copy` | Empty on a main voucher (see extra parcels / return voucher) |
|
||||||
|
|
||||||
|
**Parcel**
|
||||||
|
|
||||||
|
| Field | Value |
|
||||||
|
|---|---|
|
||||||
|
| `baros` | Weight as entered |
|
||||||
|
| `ogos_baros` | Volumetric weight (A4) |
|
||||||
|
| `ogos_1` | `"XxYxZ"` (A4) |
|
||||||
|
| `ogos_2` | `"XxYxZ = <volumetric>"` (label) |
|
||||||
|
| `ogos_3` | `* ΠΡΟΣΟΧΗ PostBox *` for PostBox, else empty |
|
||||||
|
| `temaxia` | 1 piece: the count as entered (`1`); several: `"001/" + count` (e.g. `001/003`) |
|
||||||
|
| `polaplo` | `* ΠΟΛΛΑΠΛΗ ΑΠΟΣΤΟΛΗ *` when more than one piece |
|
||||||
|
| `periexomeno` | The Reference No (`pel_ref_no`) — printed in the REFERENCE box |
|
||||||
|
| `sxolia_1`…`3` | Remarks in **27-character** lines (1st 27, next 27, the rest) — the plain remarks, not the padded/flagged value |
|
||||||
|
|
||||||
|
**Cash on delivery** (`num6` = cash + all cheques)
|
||||||
|
|
||||||
|
| Field | When | Value |
|
||||||
|
|---|---|---|
|
||||||
|
| `antik_minima` | COD | `* ΠΡΟΣΟΧΗ ΑΝΤΙΚΑΤΑΒΟΛΗ *` |
|
||||||
|
| `apodiksi` | COD | `* Απόδειξη Είσπραξης *` (the entry screen misspells it `Είσπαξης`; batch printing spells it right) |
|
||||||
|
| `antik_1` | COD | `ΑΝΤΙΚΑΤΑΒΟΛΗ <total, 2 decimals>`; PostBox: `* ΠΡΟΣΟΧΗ PostBox *` |
|
||||||
|
| `antik_2` | COD | `* ΑΝΑΛΥΣΗ *` |
|
||||||
|
| `antik_3` | cash | `<cash> MΕΤΡΗΤΑ` (the "M" is a Latin M) |
|
||||||
|
| `antik_3`…`6` | cheques, A4 | `<amount> € ΕΠΙΤΑΓΗ <due date>` per cheque |
|
||||||
|
| `antik_3`…`6` | cheques, label | `<amount> ΕΠ/ΓΗ <due date>` per cheque |
|
||||||
|
| `antik_poso` | always | the total if paid in cash, else `0.00` (cheques and no COD) |
|
||||||
|
| `antik_ocr` | always | `ocr_line` — printed at the foot of the A4 payment stub |
|
||||||
|
|
||||||
|
**Surcharges (`sur_1`…`3`)** — from the codes, in this layout:
|
||||||
|
|
||||||
|
| Codes | `sur_1` | `sur_2` | `sur_3` |
|
||||||
|
|---|---|---|---|
|
||||||
|
| 002 | 002 ΕΙΔΙΚΗ ΔΙΑΧΕΙΡΗΣΗ | | |
|
||||||
|
| 002 + 003 | 002 … | 003 ΠΡΟΚΑΘΟΡΙΣΜΕΝΗ ΩΡΑ | |
|
||||||
|
| 002 + 003 + 004 | 002 … | 003 … | 004 ΕΠΙΔΟΣΗ ΣΑΒΒΑΤΟΥ |
|
||||||
|
| 002 + 004 | 002 … | 004 ΕΠΙΔΟΣΗ ΣΑΒΒΑΤΟΥ | |
|
||||||
|
| 003 | | 003 … | |
|
||||||
|
| 003 + 004 | | 003 … | 004 … (entry screen) / `sur_1` = 004 (batch) |
|
||||||
|
| 004 | | 004 … (entry screen) / `sur_1` = 004 (batch) | |
|
||||||
|
| 917 (PostBox) | `* ΠΡΟΣΟΧΗ PostBox *` | (003/004 as above) | |
|
||||||
|
|
||||||
|
(The entry screen and batch printing place 004 differently when 002 is absent — a client
|
||||||
|
inconsistency; `sur_4` exists in the A4 report but is never filled.)
|
||||||
|
|
||||||
|
Fields in the dataset that no code fills: `service_thirida`, `axia`, `sur_4`, `antik_7`.
|
||||||
|
|
||||||
|
## B4. Extra parcel labels (`print_child`)
|
||||||
|
|
||||||
|
For each `vg_child_no` (k = 2, 3, …; n = pieces):
|
||||||
|
|
||||||
|
| Field | Value |
|
||||||
|
|---|---|
|
||||||
|
| `sydeta`, `barcode` | The **parcel's own** number / `*number*` |
|
||||||
|
| `temaxia` | Label: `"00k/00n"` (e.g. `002/003`); A4: `n` |
|
||||||
|
| `periexomeno` | A4 only: `"00k/00n"` — printed large in the child report |
|
||||||
|
| `polaplo` | Label: `ΠΟΛΛΑΠΛΗ ΑΠΟΣΤΟΛΗ - MASTER : <main voucher>` |
|
||||||
|
| `copy` | Label: `ΠΟΛΛΑΠΛH`; A4: `"*" + main voucher + "*"` (under `ΜASTER ΣΥΔΕΤΑ`) |
|
||||||
|
| `antik_minima`, `antik_1` | COD: `* ΠΡΟΣΟΧΗ ΑΝΤΙΚΑΤΑΒΟΛΗ *` — **no amount** (collected on the main voucher) |
|
||||||
|
| sender, recipient, `date`, `time`, `service`, `service_title`, `baros`, stations, `sxolia_1`…`3` | As on the main voucher |
|
||||||
|
| Not set | `barcode_2`, `xreosi`, `siimvasi`, `sur_*`, `ogos_*`, other `antik_*`, reference (label) |
|
||||||
|
|
||||||
|
## B5. What each report prints
|
||||||
|
|
||||||
|
### A4 main voucher — `sydetaE.rdlc`
|
||||||
|
|
||||||
|
One A4 page, three bands separated by cut lines, each with a side strip naming the copy:
|
||||||
|
|
||||||
|
| Band | Copies (side strips) | Contents |
|
||||||
|
|---|---|---|
|
||||||
|
| 1 (top) | `1. ΑΠΟΣΤΟΛΕΑΣ / SHIPPER`, `3. ΑΡΧΕΙΟ / ΓΡΑΦΕΙΟ ΚΑΤΑΘΕΣΗΣ` | Full voucher: logo, ELTA details, title, barcode, voucher, deposit/destination stations, weight, volumetric, pieces, service, sender, recipient, charge line, surcharges, reference, remarks, COD block, signature boxes, terms |
|
||||||
|
| 2 | `6. ΠΑΡΑΛΗΠΤΗΣ / CONSIGNEE`, `5. ΑΡΧΕΙΟ / ΓΡΑΦΕΙΟ ΕΠΙΔΟΣΗΣ` | Same voucher again, with the sender's signature box, print time, `copy`, `antik_minima`, `apodiksi` |
|
||||||
|
| 3 (payment stub) | `2. - 4. ΛΟΓΙΣΤΗΡΙΟ` | "ΤΑΧΥΠΛΗΡΩΜΗ ΕΙΣΠΡΑΞΗ / ΜΕΤΑΒΙΒΑΣΗ": voucher + barcode, stations, weight, pieces, service, charge, sender (code + name), recipient (name, address, postcode), surcharges, remarks, signature boxes, COD breakdown, **ΠΟΣΟ** (`antik_poso`), date stamp, fees, "Η-αριθμός", "Αρ. Λογ/κής Απόδοσης", and the OCR line below "ΜΗ ΣΗΜΕΙΩΝΕΤΕ ΚΑΤΩ ΑΠΟ ΑΥΤΗ ΤΗ ΓΡΑΜΜΗ" |
|
||||||
|
|
||||||
|
Fields used: `antik_1`–`7`, `antik_minima`, `antik_ocr`, `antik_poso`, `apodiksi`, `barcode`,
|
||||||
|
`baros`, `copy`, `date`, `ogos_1`, `ogos_3`, `ogos_baros`, `periexomeno`, `rec_1`–`5`,
|
||||||
|
`sender_1`–`5`, `service`, `service_title`, `station_apo`, `station_pros`,
|
||||||
|
`station_pros_title`, `sur_1`–`4`, `sxolia_1`–`3`, `sydeta`, `temaxia`.
|
||||||
|
|
||||||
|
Fixed texts (verbatim, typos included):
|
||||||
|
|
||||||
|
- `ΣΥΝΟΔΕΥΤΙΚΟ ΔΕΛΤΙΟ ΤΑΧΥΜΕΤΑΦΟΡΑΣ`
|
||||||
|
- `ΥΠΗΡΕΣΙΑ :`, `Ογκ/κο Βάρος`
|
||||||
|
- `ΧΡΕΩΣΗ ΑΠΟΣΤΟΛΕΑ ΤΡ.ΠΛΗΡ: ΠΙΣΤΩΣΗ` (copies), `ΧΡ. ΑΠΟΣΤ: ΠΙΣΤΩΣΗ` (stub)
|
||||||
|
- `Συν.Χρέωσης (€):` / `Συν.Χρέωσης. (€):` / `Συν.Χρ. (€):`
|
||||||
|
- `Πρόσθετες Υπηρεσίες`, `* ΕΠΙΒΑΡΥΝΣΕΙΣ *`
|
||||||
|
- `* REFERENCE No *` / `* REFERENCE No*`
|
||||||
|
- `* ΠΑΡΑΤΗΡΗΣΕΙΣ *`
|
||||||
|
- `ΓΙΑ ΤΗΝ ΠΑΡΑΛΑΒΗ`, `ΟΝΟΜΑ/ΥΠΟΓΡΑΦΗ`
|
||||||
|
- `ΥΠΟΓΡΑΦΗ ΑΠΟΣΤΟΛΕΑ`, `ΟΝΟΜΑ/ΥΠΟΓΡΑΦΗ ΠΑΡΑΛΗΠΤΗ`
|
||||||
|
- `Ημερομηνία - Ωρα Εκτύπωσης :`, `Ημ/νία:`, `Ώρα:`
|
||||||
|
- `Π Ο Σ Ο`
|
||||||
|
- `Έλαβα γνώση των όρων που αναγράφονται στο αντίγραφο 1 και 6 και τους αποδέχομαι
|
||||||
|
ανεπιφύλακτα` (and a variant ending `...αντίγραφο 1 και τους αποδέχομαι ανεπιφύλακτα`)
|
||||||
|
- `ΕΕΤΤ ΑΜ 99-150 Γενική Αδεια Ταχ/κων Υπηρεσιών`
|
||||||
|
|
||||||
|
Images used, with what they contain:
|
||||||
|
|
||||||
|
| Image | Where | Content |
|
||||||
|
|---|---|---|
|
||||||
|
| `elta`, `elta1` | Band 1/2 top-left | ELTA Courier logo |
|
||||||
|
| `Πλήρηστοιχεία_red1`, `_red2`, `_black` | Next to the logo; stub | **ELTA company details** (see B8) |
|
||||||
|
| `Point2_EETTAM_August2024` | Band 1 | `ΕΕΤΤ ΑΜ: 99-150 Γενική Άδεια Ταχ/κων Υπηρεσιών` |
|
||||||
|
| `Point4_CompanynameEETTAM_August2024` | Band 2 | `ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ Α.Ε. ΕΕΤΤ ΑΜ: 99-150 Γενική Άδεια Ταχ/κων Υπηρεσιών` |
|
||||||
|
| `oroi` | Band 1, vertical | `Ισχύουν οι Γενικοί Οροι Παραχής Υπηρεσιών οι οποίοι βρίσκονται αναρτημένοι στο www.elta-courier.gr και είναι διαθέσιμοι σε ολα τα καταστήματα της εταιρίας.` ("Παραχής", "ολα": ELTA's own spelling, same as the label) |
|
||||||
|
| `ID1__shipper_ec` | Band 1 side | `1.ΑΠΟΣΤΟΛΕΑΣ / SHIPPER` |
|
||||||
|
| `ID3__file_ec` | Band 1 side | `3. ΑΡΧΕΙΟ / ΓΡΑΦΕΙΟ ΚΑΤΑΘΕΣΗΣ` |
|
||||||
|
| `ID6__consignee_ec` | Band 2 side | `6. ΠΑΡΑΛΗΠΤΗΣ / CONSIGNEE` + `ΕΕΤΤ ΑΜ:01-200 Γενική Άδεια Ταχ/κών Υπηρεσιών` |
|
||||||
|
| `ID5__file_store_elta_courier` | Band 2 side | `5. ΑΡΧΕΙΟ / ΓΡΑΦΕΙΟ ΕΠΙΔΟΣΗΣ` |
|
||||||
|
| `ID2_4_logistirio` | Stub side | `2. - 4. ΛΟΓΙΣΤΗΡΙΟ` |
|
||||||
|
| `elta_taxyplirwmi_eispraksi` | Stub header | `ΤΑΧΥΠΛΗΡΩΜΗ ΕΙΣΠΡΑΞΗ / ΜΕΤΑΒΙΒΑΣΗ Ο. Αριθμός Λογ/μού Ταχυπληρωμής 131775-9` |
|
||||||
|
| `elta_chromologiko_simantro` | Stub | ELTA Ταχυπληρωμή logo + `Χρονολογικό Σήμαντρο` (date-stamp box) |
|
||||||
|
| `elta_teli` | Stub | `Τέλη` (fees) |
|
||||||
|
| `elta_h_arithmos` | Stub | `Η - αριθμός` |
|
||||||
|
| `elta_ar__logiostikis_apodosis` | Stub | `Αρ. Λογ/κής Απόδοσης` |
|
||||||
|
| `Point5_ELTACourier_ΑποστολήμαςΕσείς_September2024` | Stub, vertical | ELTA "Hellenic Post" logo + `Αποστολή μας εσείς!` |
|
||||||
|
| `mhn_shmeivnete` | Foot | `ΜΗ ΣΗΜΕΙΩΝΕΤΕ ΚΑΤΩ ΑΠΟ ΑΥΤΗ ΤΗ ΓΡΑΜΜΗ` |
|
||||||
|
|
||||||
|
### A4 extra parcel — `sydetaE1.rdlc`
|
||||||
|
|
||||||
|
A single block: logo (`eltared`) + company details (`Πλήρηστοιχεία_red1`), `ΕΕΤΤ ΑΜ 99-150
|
||||||
|
Γενική Αδεια Ταχ/κων Υπηρεσιών`, `ΣΥΝΟΔΕΥΤΙΚΟ ΔΕΛΤΙΟ ΤΑΧΥΜΕΤΑΦΟΡΑΣ`, barcode + parcel number,
|
||||||
|
`Ημερομηνία - Ωρα Εκτύπωσης :` + date, deposit station / weight / `Ογκ/κο Βάρος` / pieces,
|
||||||
|
`ΥΠΗΡΕΣΙΑ :` + service, destination station, sender (5 lines), recipient (5 lines), and a
|
||||||
|
panel with `** ΠΟΛΛΑΠΛΗ ΑΠΟΣΤΟΛΗ **`, the piece (`002/003`, large), the COD warning,
|
||||||
|
`ΜASTER ΣΥΔΕΤΑ` and the master voucher. No surcharges, reference, remarks, charge line,
|
||||||
|
COD amounts or stub.
|
||||||
|
|
||||||
|
### Label (10.4 × 14.8 cm) — `SydetaLabelE.rdlc`
|
||||||
|
|
||||||
|
Top: logo (`elta_logoblack`), company details (`Πλήρηστοιχεία_black1`), a `ΥΠΗΡΕΣΙΑ:` box
|
||||||
|
(service + title), the EETT box (`Point2_EETTAM_August2024`), date and time,
|
||||||
|
`ΣΥΝΟΔΕΥΤΙΚΟ ΔΕΛΤΙΟ ΤΑΧΥΜΕΤΑΦΟΡΑΣ`, `copy`. Then `Γρ. Επίδοσης :` + destination station;
|
||||||
|
a row of charge (`xreosi`) / OCR reference (`barcode_2`) / `siimvasi`; `Γρ.Κατάθεσης:`,
|
||||||
|
`ΒΑΡΟΣ(Kgr)`, `ΟΓΚΟΜΕΤΡΙΚΟ ΒΑΡΟΣ(Kgr)` (`ogos_2`), `Τεμάχια`; the sender (`ΑΠΟΣΤΟΛΕΑΣ`,
|
||||||
|
5 lines) next to **`ΑΙΤΙΑ ΕΠΙΣΤΡΟΦΗΣ`** (return reasons with tick boxes: `Άγνωστος`,
|
||||||
|
`Ελλειπή Δ/νση`, `Απαράδεκτο`, `Άλλαξε Δ/νση`, `Αζήτητο`); the recipient (`Π Α Ρ Α Λ Η Π Τ Η Σ`,
|
||||||
|
5 lines) next to the COD column (`antik_1`…`7`); `REFERENCE` (`periexomeno`) and
|
||||||
|
`* ΠΑΡΑΤΗΡΗΣΕΙΣ *` (`sxolia_1`, `sxolia_2` — only two lines on the label) next to
|
||||||
|
`* ΕΠΙΒΑΡΥΝΣΕΙΣ *` (`sur_1`…`3`); the `polaplo` line; the terms (`Ισχύουν οι Γενικοί Οροι
|
||||||
|
Παραχής Υπηρεσιών οι οποίοι βρίσκονται αναρτημένοι στο www.elta-courier.gr` / `και είναι
|
||||||
|
διαθέσιμοι σε ολα τα καταστήματα της εταιρίας.` — "Παραχής" is ELTA's typo); the
|
||||||
|
`antik_1` banner; the barcode; the voucher number (`sydeta`).
|
||||||
|
|
||||||
|
## B6. Return voucher ("RETOUR")
|
||||||
|
|
||||||
|
Printed when `return_vg` is not empty (special handling with a return-to party):
|
||||||
|
|
||||||
|
| Field | Value |
|
||||||
|
|---|---|
|
||||||
|
| `copy` | `RETOUR` |
|
||||||
|
| `rec_1`…`5` (**recipient = return-to party**) | `"Κωδικός:" + code`, name (split at 40), address, `"TK:… … ΤΗΛ:…"` |
|
||||||
|
| `sender_1`…`5` (**sender = our recipient**) | name (split at 40), address, `"TK:" + postcode + " " + area`, `"ΤΗΛ: " + phones` |
|
||||||
|
| `sydeta`, `barcode` | `return_vg` |
|
||||||
|
| `barcode_2` | `r_ocr_line` characters 2–14 |
|
||||||
|
| `service`, `service_title` | `461` `RETOUR ΕΝΤΟΣ ΠΟΛΗΣ` if the original service starts with `1`, else `462` `RETOUR ΠΟΛΗ ΠΟΛΗ` |
|
||||||
|
| `xreosi` | `ΧΡΕΩΣΗ ΠΑΡΑΛΗΠΤΗ ΠΙΣΤΩΣΗ` (charged to the recipient) |
|
||||||
|
| `siimvasi` | `131775-9` |
|
||||||
|
| `baros`, `temaxia` | `0.100`, `1` |
|
||||||
|
| `station_apo` / `station_pros` | the original destination station / the return-to party's station |
|
||||||
|
| `sxolia_1`…`3` | `"ΣΥΔΕΤΑ <main voucher> Χρέωση Πελάτη <sender code>"` in 27-char lines |
|
||||||
|
| `antik_poso` / `antik_ocr` | `0.00` / `r_ocr_line` |
|
||||||
|
|
||||||
|
## B7. Cheque-return voucher
|
||||||
|
|
||||||
|
Printed when `epitagh_vg` is not empty (COD by cheque) — carries the cheques back:
|
||||||
|
|
||||||
|
| Field | Value |
|
||||||
|
|---|---|
|
||||||
|
| `copy` | empty |
|
||||||
|
| `rec_*` (**recipient = our sender**) | `"Κωδικός:" + sender code`, sender name, address, TK/area/phone line |
|
||||||
|
| `sender_*` (**sender = our recipient**) | as in B6 |
|
||||||
|
| `sydeta`, `barcode`, `barcode_2` | `epitagh_vg`, `*epitagh_vg*`, `e_ocr_line` characters 2–14 |
|
||||||
|
| `service`, `service_title` | `350` `ΕΠΙΣΤΡΟΦΗ ΑΞΙΟΓΡΑΦΩΝ` |
|
||||||
|
| `xreosi` | `ΧΡΕΩΣΗ ΠΑΡΑΛΗΠΤΗ ΠΙΣΤΩΣΗ` |
|
||||||
|
| `siimvasi`, `baros`, `temaxia` | `131775-9`, `0.100`, `1` |
|
||||||
|
| `station_apo` / `station_pros` | the original destination station / the user's station |
|
||||||
|
| `sxolia_*` | `"ΣΥΔΕΤΑ <main voucher> Χρέωση Πελάτη <sender code>"` |
|
||||||
|
| `antik_poso` / `antik_ocr` | `0.00` / `e_ocr_line` |
|
||||||
|
|
||||||
|
## B8. ELTA company details (as printed, from ELTA's current images)
|
||||||
|
|
||||||
|
```
|
||||||
|
ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ Α.Ε.
|
||||||
|
Έδρα: Λεωφ. Ιωνίας 200 & Ιακωβάτων 61,
|
||||||
|
111 44 Αθήνα
|
||||||
|
Α.Φ.Μ.: 094026421 | Δ.Ο.Υ.: ΚΕ.ΦΟ.Δ.Ε. ΑΤΤΙΚΗΣ
|
||||||
|
Τ. 210-6073000 | Ε. info@elta-courier.gr
|
||||||
|
www.elta-courier.gr
|
||||||
|
Γ.Ε.ΜΗ: 001092101000
|
||||||
|
```
|
||||||
|
|
||||||
|
EETT licence: `ΕΕΤΤ ΑΜ: 99-150 Γενική Άδεια Ταχ/κων Υπηρεσιών` (the older `01-200` still
|
||||||
|
appears on the consignee copy strip and the legacy reports, whose company block reads
|
||||||
|
`ΤΑΧΥΜΕΤΑΦΟΡΕΣ ΕΛΤΑ Α.Ε., Λ.Μεσογείων 395, Αγία Παρασκευή, 153 43, ΤΗΛ:210 6073000
|
||||||
|
FAX:2106073100, ΑΦΜ: 099759170 ΔΟΥ ΦΑΕ ΑΘΗΝΩΝ, Ε.Ε.Τ.Τ. ΑΜ 01-200` — not current).
|
||||||
|
|
||||||
|
## B9. Other printouts (reports lists)
|
||||||
|
|
||||||
|
| Report | Screen | Columns |
|
||||||
|
|---|---|---|
|
||||||
|
| `Report1` (landscape) | Index, simple | ΣΥ.ΔΕ.ΤΑ., ΒΑΡΟΣ, ΤΕΜΑΧΙΑ, ΠΑΡΑΛΗΠΤΗΣ, ΔΙΕΥΘΥΝΣΗ, Τ.Κ., ΣΤΑΘΜΟΣ, ΑΠΟΣΤΟΛΕΑΣ, REFERENCE No; title `ΚΑΤΑΣΤΑΣΗ ΣΥ.ΔΕ.ΤΑ.` + date range; totals row `ΣΥΝΟΛΑ` (weight, pieces) |
|
||||||
|
| `Report3` (landscape) | Index, extended | the above + ΤΗΛΕΦΩΝΑ, ΑΝΤ/ΛΗ, ΣΥΔΕΤΑ ΕΠΙΤΑΓΗΣ, ΣΥΔΕΤΑ ΕΠΙΣΤΡΟΦΙΚΟΥ |
|
||||||
|
| `Report2` (landscape) | Multiple search | ΣΥ.ΔΕ.ΤΑ., REFERENCE, ΠΑΡΑΛΗΠΤΗΣ, Τ.Κ., ΣΤΑΘΜΟΣ, ΑΝΤ/ΒΟΛΗ, ΤΕΛΕΥΤΑΙΟ STATUS, ΣΧΟΛΙΑ |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Part C — Where our integration differs (as of 0.29.3)
|
||||||
|
|
||||||
|
Rows marked **Fixed** are handled since 0.31.0 (see CHANGELOG); the "Ours" column describes the fixed behaviour.
|
||||||
|
|
||||||
|
## Verified against ELTA's test account (2026-09-30)
|
||||||
|
|
||||||
|
All with generic test data (`TEST RECIPIENT`, `TEST ADDRESS 1`, `10431`, `2100000000`,
|
||||||
|
references `TEST-…`); pending vouchers were deleted afterwards. One issued voucher remains
|
||||||
|
on the shared account: `NZ000987460GR` (+ return voucher `NZ000987473GR`).
|
||||||
|
|
||||||
|
| Check | Result |
|
||||||
|
|---|---|
|
||||||
|
| HTTPS | Works on `https://clients.elta-courier.gr` (443); fails on the old IP and on port 9003 (see A1) |
|
||||||
|
| Envelope/parcel flag | Accepted. ELTA trims the padding and **keeps the flag as the last character of the remarks** (`TEST REMARK2`, also in tracking `a_sxolia`). Whether ELTA also reads it as the parcel type isn't visible through the API |
|
||||||
|
| Surcharge slots | Stored exactly in the slot sent (`004` in slot 1 stays `004\|000\|000`); ELTA does not normalize. Tracking (`a_services`) shows only the service, never surcharges, so their effect can't be read back. ELTA's own client only reads Saturday from slot 3 (B3), so `004` in slot 1 would not print as Saturday there |
|
||||||
|
| Blank service | Accepted, but ELTA stores **`201` ΠΟΛΗ ΠΟΛΗ** for 10431, where its own lookup (`PELTKNEW`) gives **`101` ΕΝΤΟΣ ΠΟΛΗΣ** for the test station — a blank service can land on a different service than the client would send. Explicit `101`/`201` are honoured |
|
||||||
|
| Localities | Common: 45500 Ιωάννινα has 190 localities (170 hard-to-reach → `231`), 20100 Κόρινθος 41 (16), 72200 Χίος 56 (31); islands get `211` ΠΟΛΗ ΠΟΛΗ -ΠΠ- ΝΗΣΙ |
|
||||||
|
| Insurance | `pel_asf_poso = 50.00` is stored; effect not visible |
|
||||||
|
| No phones / 21 pieces | Both accepted at creation (the limits are the client's); not tested at issue |
|
||||||
|
| Remarks > 90 | 95 characters accepted and stored in full (90 is the client's limit) |
|
||||||
|
| Special handling + return-to | Issuing returned a **return voucher** (`return_vg` + `r_ocr_line`); tracking lists it in `a_vg_2` |
|
||||||
|
| Tracking by reference | `PELTTNEW01` with our reference (`00000007`) returns the voucher |
|
||||||
|
| Delivery / remittance fields | Present in `pel_rec` (`a_rec_name`, `a_rec_date_time`, `a_antik1`, `a_antik_text1`); empty until delivery |
|
||||||
|
| PostBox lookup (`PELTKBOX`) | `10431` → station `10200` ΑΙΟΛΟΥ 100 (Κ.Κ.), service `101`; `45500`, `84100`, `00000` → `st_flag 1` "Το Τ.Κ. Δεν Εχει PostBox" |
|
||||||
|
|
||||||
|
## The differences
|
||||||
|
|
||||||
|
| # | Topic | ELTA client | Ours | Impact |
|
||||||
|
|---|---|---|---|---|
|
||||||
|
| 1 | Envelope/parcel | Mandatory; remarks right-aligned in 99 chars + `1`/`2` in `pel_paral_sxolia` | Remarks right-aligned in 99 characters (padded by characters) + `2` | **Fixed** |
|
||||||
|
| 2 | Surcharge slots | Fixed: `002`→1, `003`→2, `004`→3, `917`→1 | Fixed slots, as the client | **Fixed** |
|
||||||
|
| 3 | Service | Always resolved first (`PELTKNEW`) and sent | Resolved with `PELTKNEW` (sender station) and sent | **Fixed** (was blank; ELTA then gave `201` where its lookup gives `101`) |
|
||||||
|
| 4 | Localities | Area = `code/title` of the picked locality; hard-to-reach → service `231` | Locality matched by the address's city (accents/case ignored) → `code/title` + its service; no match → blank service, noted on the shipment | **Fixed** |
|
||||||
|
| 5 | Phones | At least one required; PostBox needs `69…` mobile | At least one required; digits only, `30`/`0030` dropped, `69…` → mobile field | **Fixed** (PostBox not offered) |
|
||||||
|
| 6 | Pieces | 1–20 | Refused above 20 | **Fixed** |
|
||||||
|
| 7 | Insurance | Never sent (`" "`) | We send `pel_asf_poso` | Unverified whether ELTA honours it |
|
||||||
|
| 8 | PostBox (`917`) | Supported, with rules (no COD, no special handling, mobile) | "PostBox delivery" extra service: `PELTKBOX` routing, `917` in `pel_sur_1`, the client's rules checked, PostBox texts on the label | **Fixed** |
|
||||||
|
| 9 | Cheque COD | Up to 4 cheques + dates; cheque-return voucher printed | Cash only | Fine for a shop; noted for completeness |
|
||||||
|
| 10 | Special handling + return | Return-to party (`pel_retur_code`); RETOUR voucher printed | Return-to = our sender code; `return_vg` + `r_ocr_line` stored; RETOUR page printed after the parcels (B6) | **Fixed** |
|
||||||
|
| 11 | Remarks length | 90 chars | 90 | — |
|
||||||
|
| 12 | Company details on labels | B8 (Ιωνίας 200, Γ.Ε.ΜΗ) | B8 details on the A4 copies, stub, A4 child and A6 | **Fixed** |
|
||||||
|
| 13 | `Απόδειξη Είσπραξης` | Correct in batch printing | Correct | **Fixed** |
|
||||||
|
| 14 | Side copy strips, stub strips, "Αποστολή μας εσείς" | Images (B5) | Approximated / missing | Cosmetic |
|
||||||
|
| 15 | Tracking by reference | `PELTTNEW01` accepts our reference | We track by voucher only | **Verified** working — could track a voucher whose number we don't have |
|
||||||
|
| 16 | Delivery details | `a_rec_name`, `a_rec_date_time` | Stored from each tracking poll (`meta.delivered_to` / `delivered_at`); shown on the order page and Carrier Vouchers view | **Fixed** |
|
||||||
|
| 17 | COD remittance | `a_antik1`, `a_antik_text1` | Stored (`meta.cod_remitted` / `cod_remittance`); shown as "COD paid back" | **Fixed** |
|
||||||
|
| 18 | Scheme | `https://clients.elta-courier.gr` | `https://clients.elta-courier.gr`, 2 retries on connection errors / 5xx | **Fixed** |
|
||||||
+1
-1
@@ -393,7 +393,7 @@ Because Filament instantiates `Lunar\Admin\Models\Staff` directly (not a subclas
|
|||||||
```php
|
```php
|
||||||
use Lunar\Admin\Models\Staff as LunarStaff;
|
use Lunar\Admin\Models\Staff as LunarStaff;
|
||||||
|
|
||||||
LunarStaff::addActivitylogExcept(['otp_code', 'otp_expires_at', 'password']);
|
LunarStaff::addActivitylogExcept(['otp_code_hash', 'otp_expires_at', 'password']);
|
||||||
```
|
```
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
+67
-2
@@ -49,7 +49,8 @@ boboko-test/
|
|||||||
app/
|
app/
|
||||||
Models/
|
Models/
|
||||||
Customer.php ← app-level model, extends Modules\Core\Customer\Models\Customer
|
Customer.php ← app-level model, extends Modules\Core\Customer\Models\Customer
|
||||||
User.php ← app-level model, dispatches Modules\Core\Auth\Events\UserCreated
|
User.php ← app-level model, no $dispatchesEvents needed — core dispatches
|
||||||
|
UserCreated itself (Modules\Core\Auth\Services\UserOtpService)
|
||||||
Staff.php ← app-level model, extends Modules\Core\Auth\Models\Staff
|
Staff.php ← app-level model, extends Modules\Core\Auth\Models\Staff
|
||||||
Lunar/
|
Lunar/
|
||||||
Extensions/ ← app's own Filament resource extensions (source of truth, wired in PanelServiceProvider)
|
Extensions/ ← app's own Filament resource extensions (source of truth, wired in PanelServiceProvider)
|
||||||
@@ -121,6 +122,63 @@ Docker Compose merges `volumes:` lists additively across `-f` files, so the over
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## Frontend Assets (JS/CSS)
|
||||||
|
|
||||||
|
A module's JS (Stimulus controllers) and CSS ship as plain source files under `resources/js/` and `resources/css/` — **there is no separate npm package per module.** A module is never `npm install`ed; its frontend assets are read directly by the consuming app's own Vite build, straight out of `vendor/boboko/<module>`.
|
||||||
|
|
||||||
|
This mirrors the PHP story above exactly: Composer already gives every environment one single, unconditional path — `vendor/boboko/<module>` — whether that resolves to a symlink into a sibling checkout (local path repo) or a real installed copy (tagged VCS release). A consumer's `vite.config.js` and JS entry point read from that same path, so there is nothing to toggle on the JS side — whatever Composer resolved is exactly what Vite sees, in both dev and prod, automatically.
|
||||||
|
|
||||||
|
**Each module exposes one stable JS entry point** — `resources/js/index.js` — that re-exports whatever a consumer needs, e.g. `boboko-core`'s:
|
||||||
|
|
||||||
|
```js
|
||||||
|
// boboko-core/resources/js/index.js
|
||||||
|
export { registerCheckout } from './checkout/index.js'
|
||||||
|
```
|
||||||
|
|
||||||
|
A consuming app imports from that one file only, never from a path reaching into a module's internal folder structure directly:
|
||||||
|
|
||||||
|
```js
|
||||||
|
// consumer app's resources/js/app.js
|
||||||
|
import { registerCheckout } from "../../vendor/boboko/core/resources/js/index.js";
|
||||||
|
registerCheckout(application);
|
||||||
|
```
|
||||||
|
|
||||||
|
```php
|
||||||
|
{{-- consumer app's layout --}}
|
||||||
|
@vite(['vendor/boboko/core/resources/css/checkout.css', 'resources/css/app.css', 'resources/js/app.js'])
|
||||||
|
```
|
||||||
|
|
||||||
|
This keeps a module's internal file layout free to change without breaking every consumer's entry point — the same reasoning as PSR-4 namespaces for PHP, just for JS imports.
|
||||||
|
|
||||||
|
**A consuming app's `vite.config.js` needs one addition**, because `vendor/boboko/<module>` is a symlink in local path-repo dev (not a real directory Vite would otherwise watch through):
|
||||||
|
|
||||||
|
```js
|
||||||
|
export default defineConfig({
|
||||||
|
server: {
|
||||||
|
watch: {
|
||||||
|
// vendor/boboko/<module> is a symlink into ../boboko-<module> in
|
||||||
|
// local path-repo dev. Vite/chokidar don't follow symlinks for
|
||||||
|
// watched files by default, so edits to a module's source
|
||||||
|
// wouldn't otherwise trigger HMR. No-op against a real installed
|
||||||
|
// copy (tagged VCS release) in production.
|
||||||
|
followSymlinks: true,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
});
|
||||||
|
```
|
||||||
|
|
||||||
|
Bare imports inside a module's own JS (e.g. `leaflet`, `@hotwired/stimulus`) resolve against the **consumer's** `node_modules` via Node's normal upward resolution walk from `vendor/boboko/<module>/resources/js/...` — no extra config needed, as long as `vendor/boboko/<module>` sits inside the consumer's own directory tree (true for both the symlink and real-copy case). The consumer's Vite Docker service (if any) needs the same bind mount the PHP containers already get, landing at the equivalent path relative to its own working directory:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
# consumer app's docker-compose.core-dev.yml
|
||||||
|
services:
|
||||||
|
vite:
|
||||||
|
volumes:
|
||||||
|
- ../boboko-core:/app/vendor/boboko/core # match /app to the vite service's actual workdir
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
## Creating a New Module
|
## Creating a New Module
|
||||||
|
|
||||||
**1. Create the repository and `composer.json`:**
|
**1. Create the repository and `composer.json`:**
|
||||||
@@ -264,7 +322,14 @@ php artisan vendor:publish --tag=core-config
|
|||||||
'auto_create_customer_for_user' => false,
|
'auto_create_customer_for_user' => false,
|
||||||
```
|
```
|
||||||
|
|
||||||
Both listeners guard against the other direction re-triggering: they call `User::withoutEvents(...)` around `firstOrCreate`/save, so pairing a `Customer` never spuriously fires `UserCreated` (and vice versa) even if both directions are somehow active at once.
|
A guard against the other direction re-triggering is only needed where a real risk exists:
|
||||||
|
`App\Listeners\CreateUserForCustomerListener` (`boboko-test`, app-level) wraps its
|
||||||
|
`firstOrCreate` in `User::withoutEvents(...)`, since finding-or-creating a `User` there could
|
||||||
|
itself fire `UserCreated` and loop back into `CreateCustomerForUser`. `Modules\Core\Customer\
|
||||||
|
Listeners\CreateCustomerForUser` (core) needs no such guard — it calls a plain
|
||||||
|
`$model::create([])` on `Customer`, which has no `$dispatchesEvents`/model hooks of its own in
|
||||||
|
core that could re-trigger anything; the guard belongs only on the side that actually creates a
|
||||||
|
`User`.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
+3
-2
@@ -30,11 +30,12 @@ Codes expire after **10 minutes**. After a successful validation the code is cle
|
|||||||
|
|
||||||
### Database
|
### Database
|
||||||
|
|
||||||
Two columns on the `lunar_staff` table (added by `2026_05_06_000001_add_otp_to_lunar_staff_table`):
|
Two columns on the `lunar_staff` table (added by `2026_05_06_000001_add_otp_to_lunar_staff_table`,
|
||||||
|
`otp_code` replaced with a hashed column by `2026_09_30_000002_hash_otp_code_on_lunar_staff_table`):
|
||||||
|
|
||||||
| Column | Type | Purpose |
|
| Column | Type | Purpose |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
| `otp_code` | string, nullable | The generated code |
|
| `otp_code_hash` | string, nullable | Bcrypt hash of the generated code (`'hashed'` cast on `Staff`) |
|
||||||
| `otp_expires_at` | timestamp, nullable | Expiry time |
|
| `otp_expires_at` | timestamp, nullable | Expiry time |
|
||||||
|
|
||||||
### Login Page
|
### Login Page
|
||||||
|
|||||||
+55
-16
@@ -145,23 +145,20 @@ produced had it resolved synchronously.
|
|||||||
with no memory of the request that started the payment. Something has to persist enough to
|
with no memory of the request that started the payment. Something has to persist enough to
|
||||||
answer "which order/cart does gateway reference X belong to?" between the two calls.
|
answer "which order/cart does gateway reference X belong to?" between the two calls.
|
||||||
|
|
||||||
**Read directly from `lunarphp/stripe`'s own source** (`StripePaymentType::authorize()`,
|
The precedent for this originally came from reading `lunarphp/stripe`'s own source
|
||||||
`ProcessStripeWebhook`, `WebhookController`) to see how Lunar itself solves this — confirmed
|
(`StripePaymentType::authorize()`, `ProcessStripeWebhook`, `WebhookController`) — that package
|
||||||
it does **not** stash a generic opaque blob. It writes the correlating ids as real, typed
|
solved this the same way, writing the correlating ids as real, typed columns on its own
|
||||||
columns on `Lunar\Stripe\Models\StripePaymentIntent` (`cart_id`, `order_id`) at the moment the
|
`StripePaymentIntent` model rather than a generic opaque blob. **`lunarphp/stripe` has since
|
||||||
intent is created/first seen, then reads them back the same way when the webhook arrives:
|
been removed from this project** in favour of depending on `stripe/stripe-php` directly (see
|
||||||
|
CHANGELOG.md) — `Modules\Core\Payment\Models\StripePaymentIntent` is now a first-party model
|
||||||
|
over the same table shape, kept for exactly the same reason.
|
||||||
|
|
||||||
```php
|
**`StripePaymentDriver` follows this pattern**: it reads `cart_id`/`order_id` out of `$context`
|
||||||
// ProcessStripeWebhook::handle() — falls back through two real lookups,
|
at `pay()`/`authorize()` time and writes them onto its own `StripePaymentIntent` row (`src/
|
||||||
// neither of them a generic context blob:
|
Payment/Models/StripePaymentIntent.php`, table `stripe_payment_intents`), then reads them back
|
||||||
$cart = StripePaymentIntent::where('intent_id', $this->paymentIntentId)->first()?->cart
|
the same way in `handleCallback()`. No generic `context` json column beyond what that table
|
||||||
?: Cart::where('meta->payment_intent', '=', $this->paymentIntentId)->first();
|
already carries (`context`, added for a different purpose — see that migration's own
|
||||||
```
|
docblock), no new table.
|
||||||
|
|
||||||
**`StripePaymentDriver` follows this exact precedent**: it reads `cart_id`/`order_id` out of
|
|
||||||
`$context` at `pay()`/`authorize()` time and writes them onto its own `StripePaymentIntent`
|
|
||||||
row (a table already owned by `lunarphp/stripe`, already shaped for exactly this), then reads
|
|
||||||
them back the same way in `handleCallback()`. No generic `context` json column, no new table.
|
|
||||||
|
|
||||||
### This pattern is per-driver, not a shared table
|
### This pattern is per-driver, not a shared table
|
||||||
|
|
||||||
@@ -176,6 +173,48 @@ a shared generic one.
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## Reconciliation — a charge that succeeds on Stripe but is never written locally
|
||||||
|
|
||||||
|
This app never creates or reuses a Stripe **Customer** object — every PaymentIntent is a
|
||||||
|
one-off (`StripePaymentDriver::createAndConfirm()`'s own `$params` never includes a `customer`
|
||||||
|
key), and nothing calls Stripe's Customer API anywhere in this codebase. That's a deliberate
|
||||||
|
choice, not an oversight: a Customer object only earns its keep if something actually needs it
|
||||||
|
(saved/reusable payment methods, subscriptions, Stripe-side lifetime-value grouping across
|
||||||
|
orders) — none of which exist in this checkout flow today. Creating one anyway would just be
|
||||||
|
more PII sitting on a third party's servers for no functional benefit, and it would become
|
||||||
|
another cross-reference a future Payment privacy provider has to account for (detaching/
|
||||||
|
deleting the Customer on erasure, not just the local PaymentIntent row). If a real feature
|
||||||
|
needs it later (e.g. "save my card"), add it then, scoped to that feature.
|
||||||
|
|
||||||
|
The gap this creates: with no Customer object and no other identifying field previously sent
|
||||||
|
to Stripe, a PaymentIntent that succeeds on Stripe's side but is never written to our own DB
|
||||||
|
(e.g. a database outage at exactly the wrong moment, between Stripe confirming the charge and
|
||||||
|
`rememberIntent()`'s insert) would be **untraceable** back to a cart or order — nothing to
|
||||||
|
search Stripe's dashboard by except amount, timestamp, and card last-4.
|
||||||
|
|
||||||
|
**Fix**: `createAndConfirm()` now sets `metadata: ['cart_id' => ..., 'order_id' => ...]`
|
||||||
|
(`array_filter()`-ed, since `order_id` isn't known yet at initial `pay()`/`authorize()` time —
|
||||||
|
same null-coalesce `rememberIntent()` already does) on every PaymentIntent. This is metadata
|
||||||
|
only, visible on Stripe's own dashboard/API for manual reconciliation — it does not create a
|
||||||
|
Customer object and does not change anything about how `handleCallback()`/webhook correlation
|
||||||
|
works (that still goes through `stripe_payment_intents`, per "Async resolution" above). It's
|
||||||
|
purely a recovery aid for the case where our own write never happened at all.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## GDPR erasure/export
|
||||||
|
|
||||||
|
`Modules\Core\Payment\Privacy\PaymentDataProvider` covers `lunar_transactions`
|
||||||
|
(`card_type`/`last_four`) and `stripe_payment_intents` — see `docs/privacy.md` for the full
|
||||||
|
right-of-erasure/right-of-access design. Pseudonymizes card metadata on erasure (same
|
||||||
|
tax/accounting retention reasoning `Order`'s own provider uses) and deletes the Stripe
|
||||||
|
correlation rows outright, since their only purpose — resolving an async webhook callback, see
|
||||||
|
"Async resolution" above — has already been served by the time an erasure request runs. No
|
||||||
|
Stripe Customer object exists anywhere in this app (see "Reconciliation" above) for this
|
||||||
|
provider to also request deletion of.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
## Explicitly out of scope for this pass
|
## Explicitly out of scope for this pass
|
||||||
|
|
||||||
- **`Checkout`/`Order` wiring** — how `Checkout` calls into `Payment`, how `Order`/`Checkout`
|
- **`Checkout`/`Order` wiring** — how `Checkout` calls into `Payment`, how `Order`/`Checkout`
|
||||||
|
|||||||
+417
@@ -0,0 +1,417 @@
|
|||||||
|
# Privacy / GDPR Data-Subject Requests
|
||||||
|
|
||||||
|
`Modules\Core\Privacy` implements the right of access (export) and right of erasure for
|
||||||
|
customers, as an extensible contract rather than a fixed list of tables — any module (core,
|
||||||
|
or a future ERP/banking/etc. module) can register its own data without core knowing it exists.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## User-scope vs Customer-scope — two genuinely different operations
|
||||||
|
|
||||||
|
A Lunar `Customer` (business account: orders, addresses, buyer record) and a `User` (individual
|
||||||
|
login identity) are linked many-to-many via the `customer_user` pivot (see `docs/modules.md`
|
||||||
|
"Customer/User Pairing") — **one User can belong to many Customer accounts, and one Customer
|
||||||
|
account can have many linked Users.** This is the real shape of B2B multi-seat access: a person
|
||||||
|
can have login access to several separate business accounts, and a business account can have
|
||||||
|
several employees each with their own login.
|
||||||
|
|
||||||
|
That means "delete my personal data" and "delete this business account" are not the same request,
|
||||||
|
and conflating them is actively wrong:
|
||||||
|
|
||||||
|
- **Erasing a Customer must never touch any linked User's login or identity.** Erasing "Acme
|
||||||
|
Corp" must not deactivate or destroy access for the employees who work there — and must not
|
||||||
|
touch any *other* Customer account, even one sharing some of the same Users.
|
||||||
|
- **Erasing a User must never touch any Customer account's own data.** John asking to delete
|
||||||
|
*his* account must clear his name/email/login wherever it appears — and correctly end his
|
||||||
|
membership on every Customer he's linked to (detach the pivot) — but must not erase Acme Corp's
|
||||||
|
orders or addresses, and must not affect any other employee still linked to Acme Corp.
|
||||||
|
|
||||||
|
Every part of this module is split along that line — a `PersonalDataProvider`, a `PrivacyService`
|
||||||
|
method, a request record — is always explicitly **for a Customer** or **for a User**, never both
|
||||||
|
at once, and never one with an implicit cascade into the other.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Why an extensible contract, not a hardcoded script
|
||||||
|
|
||||||
|
A GDPR erasure/export request has to touch every module that holds personal data, but core can't
|
||||||
|
know in advance what future modules will exist or what data they'll hold — and different data
|
||||||
|
needs fundamentally different handling (freely erasable PII vs. financial records that must be
|
||||||
|
pseudonymized-not-deleted for legal retention vs. data that must be retained outright). There's
|
||||||
|
deliberately no central taxonomy for this in the contract — each module owns its own retention
|
||||||
|
judgment, since only the module that owns a table actually knows its legal requirements.
|
||||||
|
|
||||||
|
`Modules\Core\Privacy\Contracts\PersonalDataProvider` is the whole contract:
|
||||||
|
|
||||||
|
```php
|
||||||
|
interface PersonalDataProvider
|
||||||
|
{
|
||||||
|
public function name(): string;
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult;
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult;
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult;
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
Every provider implements all four methods. A provider with nothing relevant to one scope
|
||||||
|
implements that method as a no-op — `ErasureOutcome::Skipped` with a reason for erase, an empty
|
||||||
|
payload for export (e.g. `AddressDataProvider::eraseForUser()`, since addresses belong to a
|
||||||
|
Customer, not an individual).
|
||||||
|
|
||||||
|
A provider implementation lives inside the module that owns the data it erases/exports, under
|
||||||
|
that module's own `Privacy/` subdirectory (e.g. `Modules\Core\Order\Privacy\OrderDataProvider`,
|
||||||
|
`Modules\Core\Customer\Privacy\CustomerDataProvider`) — never inside `Modules\Core\Privacy`
|
||||||
|
itself, which only owns the shared contract (`Contracts\PersonalDataProvider`), the request
|
||||||
|
lifecycle (`Services\PrivacyManager`/`PrivacyService`), and the DTOs/enums every provider
|
||||||
|
returns. This mirrors how this codebase already handles other cross-cutting-but-domain-specific
|
||||||
|
code (e.g. a resource's own `Filament/Extensions/` subdirectory) — and matters concretely if a
|
||||||
|
module is ever extracted into its own composer package (see `docs/modules.md`): the provider
|
||||||
|
that knows how to erase that module's data must travel with it, not get stranded in `Privacy`
|
||||||
|
depending on a package that no longer ships in this repo.
|
||||||
|
|
||||||
|
A module registers by adding its provider class to `config('core.privacy.providers')` — the
|
||||||
|
same shape as Lunar's own `config('lunar.search.indexers')` model→indexer map:
|
||||||
|
|
||||||
|
```php
|
||||||
|
// config/core.php
|
||||||
|
'privacy' => [
|
||||||
|
'providers' => [
|
||||||
|
\Modules\Core\Customer\Privacy\CustomerDataProvider::class,
|
||||||
|
\Modules\Core\Customer\Privacy\AddressDataProvider::class,
|
||||||
|
\Modules\Core\Order\Privacy\OrderDataProvider::class,
|
||||||
|
\Modules\Core\Cart\Privacy\CartDataProvider::class,
|
||||||
|
\Modules\Core\Review\Privacy\ReviewDataProvider::class,
|
||||||
|
// A future module just adds its own provider here.
|
||||||
|
],
|
||||||
|
],
|
||||||
|
```
|
||||||
|
|
||||||
|
`PrivacyManager` resolves each class via the container and asserts every `name()` is unique —
|
||||||
|
two providers registering the same name throws, so a naming collision fails loudly at
|
||||||
|
resolution time rather than silently overwriting one provider's data in an export/report.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## `UserSubject` and `CustomerSubject` — identifying "the person" vs "the account"
|
||||||
|
|
||||||
|
Two separate value objects, not one — each deliberately carries only what its own scope needs, so
|
||||||
|
a provider can't accidentally reach across the boundary:
|
||||||
|
|
||||||
|
```php
|
||||||
|
class CustomerSubject
|
||||||
|
{
|
||||||
|
public readonly int $customerId;
|
||||||
|
// No userIds, no email — Customer-scope has no business knowing about logins.
|
||||||
|
}
|
||||||
|
|
||||||
|
class UserSubject
|
||||||
|
{
|
||||||
|
public readonly int $userId;
|
||||||
|
public readonly ?string $email;
|
||||||
|
// No customerId — one User can be linked to many Customers; a provider that
|
||||||
|
// needs to know which ones looks that up itself (e.g. to detach the pivot),
|
||||||
|
// rather than this value object assuming or privileging any single one.
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
`CustomerSubject::forCustomer(Customer $customer)` and `UserSubject::forUser($user)` build one
|
||||||
|
from the record staff (or the person themselves) look up.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Providers shipped in core
|
||||||
|
|
||||||
|
| Provider | `name()` | Lives in | Covers | Customer-scope | User-scope |
|
||||||
|
|---|---|---|---|---|---|
|
||||||
|
| `ActivityLogDataProvider` | `activity_log` | `Modules\Core\Logging\Privacy` | `activity_log` (Spatie) for subject types `Customer`/`Address`/`CartAddress`/`OrderAddress`/`Transaction` | **Pseudonymized** — `properties` redacted, who/what/when metadata kept | Skipped — `causer_id` is an actor reference, not PII content; see below |
|
||||||
|
| `CustomerDataProvider` | `customer` | `Modules\Core\Customer\Privacy` | `lunar_customers`, and separately the `User`'s own name/email/OTP fields | Erases the account's own fields only | Erases that User's name/email/OTP fields only, and detaches them from every linked Customer |
|
||||||
|
| `AddressDataProvider` | `addresses` | `Modules\Core\Customer\Privacy` | `lunar_addresses` | Erased (deleted outright) | Skipped — belongs to a Customer, not an individual |
|
||||||
|
| `OrderDataProvider` | `orders` | `Modules\Core\Order\Privacy` | `lunar_orders`, `lunar_order_addresses`, and their `meta` (`terms_accepted*`, `payment_method`, `box_now_locker`) | **Pseudonymized, not erased** — see below | Skipped — belongs to a Customer, not an individual |
|
||||||
|
| `CartDataProvider` | `carts` | `Modules\Core\Cart\Privacy` | `lunar_cart_addresses`, and `lunar_carts.meta` (`recovery_consent*`, `payment_method`, `checkout_fingerprint`) | Erased | Skipped — belongs to a Customer, not an individual |
|
||||||
|
| `ReviewDataProvider` | `reviews` | `Modules\Core\Review\Privacy` | `product_reviews` | Skipped — authored by an individual, not a business account | Pseudonymized by matching `reviewer_email`; rating/title/body text kept |
|
||||||
|
| `PaymentDataProvider` | `payments` | `Modules\Core\Payment\Privacy` | `lunar_transactions` (`card_type`/`last_four`), `stripe_payment_intents` | **Pseudonymized** — card metadata cleared, correlation rows deleted, amounts/statuses kept | Skipped — belongs to Customer-owned orders, not individual users |
|
||||||
|
| `UserSessionDataProvider` | `sessions` | `Modules\Core\Auth\Privacy` | `user_sessions` (`ip_address`, `user_agent`) | Skipped — belongs to an individual User, not a business account | Erased (deleted outright) |
|
||||||
|
|
||||||
|
`CustomerDataProvider` is the one provider that implements both scopes meaningfully, and keeps
|
||||||
|
them from touching each other — see the class docblock for the full reasoning.
|
||||||
|
|
||||||
|
### `activity_log` is redacted by subject, never by causer
|
||||||
|
|
||||||
|
`Modules\Core\Logging\ActivityLogService` (plus several Lunar models' own native `use
|
||||||
|
LogsActivity` — `Customer`, `CartAddress`, `OrderAddress`, `Transaction`) durably retains a full
|
||||||
|
snapshot of whatever it logged in `properties`, completely independent of the real row it
|
||||||
|
describes — erasing/pseudonymizing a `Customer`/`Address`/`Order`/etc. elsewhere does nothing to
|
||||||
|
this table on its own. `ActivityLogDataProvider::eraseForCustomer()` redacts `properties` on
|
||||||
|
every row whose **subject** (not causer) resolves back to that customer, across all five
|
||||||
|
PII-bearing subject types.
|
||||||
|
|
||||||
|
It deliberately never touches `causer_id` — the causer is "who performed this action," not PII
|
||||||
|
content, and erasing it would defeat the audit trail's own purpose. `eraseForUser()` is
|
||||||
|
therefore a no-op: a `User` appears in this table only as a causer, never as subject content, so
|
||||||
|
there's nothing to redact from the User side alone.
|
||||||
|
|
||||||
|
**Ordering dependency**: `ActivityLogDataProvider` must run *before* `AddressDataProvider` in
|
||||||
|
`config('core.privacy.providers')` — it resolves which `activity_log` rows are keyed by an
|
||||||
|
`Address` id while those Address rows still exist; `AddressDataProvider` then hard-deletes them.
|
||||||
|
Reversing the order would make matching those rows impossible once the addresses are gone.
|
||||||
|
|
||||||
|
**`ReviewDataProvider` needs review.** It moved from Customer-scope to User-scope on the
|
||||||
|
reasoning that authorship is a personal attribute, not a business-account attribute — but this
|
||||||
|
hasn't been fully validated against how reviews are actually attributed in this codebase. The
|
||||||
|
class carries a `NEEDS REVIEW` note; revisit before relying on it for a real request.
|
||||||
|
|
||||||
|
### Orders are pseudonymized, not deleted
|
||||||
|
|
||||||
|
GDPR Art. 17(3)(b) explicitly allows retaining data an erasure request would otherwise cover,
|
||||||
|
when a legal obligation requires it — tax/accounting law generally requires invoices be kept for
|
||||||
|
several years. `OrderDataProvider::eraseForCustomer()` clears the free-text PII fields on `Order`/
|
||||||
|
`OrderAddress` (`customer_reference`, `notes`, name/address/contact fields) but leaves the order
|
||||||
|
row, totals, line items, and tax data fully intact. Its `ProviderErasureResult` reports
|
||||||
|
`ErasureOutcome::Pseudonymized`, not `Erased` — a compliance report or admin UI can see exactly
|
||||||
|
why an order wasn't deleted without reading `OrderDataProvider`'s source.
|
||||||
|
|
||||||
|
### Reviews are matched by email — a real, documented limitation
|
||||||
|
|
||||||
|
`ProductReview` has no FK to Customer/User at all (see `docs/product-listing.md` "Reviews") —
|
||||||
|
it's deliberately anonymous, just free-text `reviewer_name`/`reviewer_email`. `ReviewDataProvider`
|
||||||
|
matches by `reviewer_email` against `UserSubject::$email`; a review submitted under a different
|
||||||
|
email than the one on file simply won't be found. There's no stronger signal available without
|
||||||
|
changing `ProductReview`'s schema.
|
||||||
|
|
||||||
|
### Staff/employee data is out of scope
|
||||||
|
|
||||||
|
`Staff` (admin/panel employees) is never a `UserSubject`/`CustomerSubject` at all — this feature
|
||||||
|
is scoped to customer-initiated and staff-initiated-on-a-customer's-behalf requests. An employee's
|
||||||
|
own data (a different HR/access-management concern) isn't reachable through this flow.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Erasure isn't immediate — a cancellable grace period
|
||||||
|
|
||||||
|
`PrivacyService` has parallel methods for each scope: `requestErasureForCustomer()` /
|
||||||
|
`requestErasureForUser()`. Neither erases anything immediately. Each opens a `DataErasureRequest`
|
||||||
|
(`pending`, `scheduled_for` = now + `config('core.privacy.grace_period_days')`, default 30). This
|
||||||
|
mirrors Shopify's own account-deletion flow: a window where the subject can change their mind
|
||||||
|
before anything is actually erased.
|
||||||
|
|
||||||
|
**Only the User-scoped request deactivates a login.** `requestErasureForCustomer()` deactivates
|
||||||
|
no one — a business-account erasure must never block anyone's access.
|
||||||
|
`requestErasureForUser()` deactivates that one User's login (blocks it — see
|
||||||
|
`Modules\Core\Auth\Services\UserOtpService` — nothing else changes).
|
||||||
|
|
||||||
|
```php
|
||||||
|
use Modules\Core\Privacy\Services\PrivacyService;
|
||||||
|
|
||||||
|
$service = app(PrivacyService::class);
|
||||||
|
|
||||||
|
// Customer-scoped: either the Customer itself (self-service) or a Staff member.
|
||||||
|
$request = $service->requestErasureForCustomer($customer, $requestedBy);
|
||||||
|
|
||||||
|
// User-scoped: either the User itself (self-service) or a Staff member.
|
||||||
|
$request = $service->requestErasureForUser($user, $requestedBy);
|
||||||
|
|
||||||
|
// Cancel before scheduled_for — for a User-scoped request, reactivates the
|
||||||
|
// account. A Customer-scoped request never deactivated anything, so there's
|
||||||
|
// nothing to reactivate for it.
|
||||||
|
$service->cancelErasure($request);
|
||||||
|
```
|
||||||
|
|
||||||
|
### Logging back in during the grace period cancels the request automatically
|
||||||
|
|
||||||
|
Authentication is never blocked by deactivation — `UserOtpService::validate()` still requires
|
||||||
|
the correct OTP code. Once validated, it dispatches `Modules\Core\Auth\Events\UserAuthenticated`;
|
||||||
|
`Modules\Core\Privacy\Listeners\CancelErasureOnLoginListener` (registered in
|
||||||
|
`PrivacyServiceProvider`, **queued** — see below) looks for a pending request keyed on *that
|
||||||
|
User's own id* — never a Customer-scoped one, since Customer-scope never deactivates a login in
|
||||||
|
the first place — and calls `cancelErasure()` on it, then reverts every Customer erasure request
|
||||||
|
it caused (see "The sole-owner cascade" below). Logging back in **is** the "I changed my mind"
|
||||||
|
action — no separate UI/flow needed for reactivation.
|
||||||
|
|
||||||
|
This listener is queued rather than synchronous, so login returns to the browser without waiting
|
||||||
|
on the bookkeeping. Nothing else in this codebase currently reads `deactivated_at` besides this
|
||||||
|
listener and `PrivacyService` itself — `UserOtpService::validate()` never gates the login on it —
|
||||||
|
so the brief window between the login response and the job actually running has no other consumer
|
||||||
|
to observe it as stale.
|
||||||
|
|
||||||
|
### The sole-owner cascade — erasing the last User on a Customer also erases the Customer
|
||||||
|
|
||||||
|
If a User is erased and they were the **only** User linked to a given Customer, that Customer's
|
||||||
|
data (orders, addresses, buyer record) becomes permanently unreachable through any login the
|
||||||
|
moment the User's identity is gone — nobody could ever again log in to exercise a data-subject
|
||||||
|
right over it. GDPR's data minimization principle (Art. 5(1)(c)) means it shouldn't just sit
|
||||||
|
there indefinitely with no legitimate purpose.
|
||||||
|
|
||||||
|
`requestErasureForUser()` and `requestImmediateErasureForUser()` both fire
|
||||||
|
`Modules\Core\Privacy\Events\UserErasureRequested` right after the request is created (and, for
|
||||||
|
the immediate path, before `completeErasure()` runs — see below).
|
||||||
|
`Modules\Core\Privacy\Listeners\CascadeCustomerErasureListener` (**queued**, registered in
|
||||||
|
`PrivacyServiceProvider`) handles it: for every Customer the User is linked to, if that User is
|
||||||
|
currently the *sole* linked User (count is 1, and that one User is this one — not just count ===
|
||||||
|
1, to be explicit rather than relying on an assumption), it opens a second, independent
|
||||||
|
grace-period request via `requestErasureForCustomer($customer, $user, causedByRequestId: ...)`.
|
||||||
|
Both requests then run through their own separate 30-day windows.
|
||||||
|
|
||||||
|
```
|
||||||
|
User erasure requested
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
UserErasureRequested event ──▶ CascadeCustomerErasureListener (queued)
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
for each linked Customer: sole owner?
|
||||||
|
│ yes
|
||||||
|
▼
|
||||||
|
requestErasureForCustomer(..., causedByRequestId: <user request id>)
|
||||||
|
```
|
||||||
|
|
||||||
|
**Tracing the cascade — `caused_by_request_id`.** A cascade-created Customer request's
|
||||||
|
`caused_by_request_id` points back at the User request that triggered it. This is what lets
|
||||||
|
`CancelErasureOnLoginListener` revert *exactly* the cascade a User's own cancellation should
|
||||||
|
undo (via `DataErasureRequest::caused()`) without ever touching an unrelated, independently
|
||||||
|
staff-requested Customer erasure the User happens to still be linked to.
|
||||||
|
|
||||||
|
**Why this is queued, not synchronous.** `CascadeCustomerErasureListener` runs as an independent,
|
||||||
|
separately-retryable job rather than inline inside `requestErasureForUser()` — a failure in the
|
||||||
|
cascade check never rolls back or blocks the User's own request, and there's no
|
||||||
|
`DB::transaction()` wrapping needed, since the two writes (the User's request, and any cascaded
|
||||||
|
Customer request) aren't required to be atomic with each other.
|
||||||
|
|
||||||
|
**A known, accepted race on the immediate-erasure path only.** Because the listener is queued,
|
||||||
|
Eloquent re-fetches its models fresh when the job actually runs (see
|
||||||
|
`Illuminate\Queue\SerializesModels`) — so `$event->request->subject->customers` reflects the
|
||||||
|
*real* state at execution time, not a stale snapshot from dispatch time. For
|
||||||
|
`requestImmediateErasureForUser()`, that job may run before or after `completeErasure()` detaches
|
||||||
|
the User's memberships in the same call. If the detach happens first, the User is simply no
|
||||||
|
longer linked to anything by the time the cascade job runs, and nothing cascades — an accepted
|
||||||
|
race for that rare, staff-only path (see "Immediate erasure" below), not a concern for the
|
||||||
|
everyday `requestErasureForUser()` grace-period path, where nothing detaches until its own later,
|
||||||
|
separate `completeErasure()` run — well after the cascade job has had time to fire.
|
||||||
|
|
||||||
|
### Processing due requests — one job per request
|
||||||
|
|
||||||
|
`php artisan boboko:privacy:process-erasure-requests` finds every `pending` request whose
|
||||||
|
`scheduled_for` has passed and dispatches one `Modules\Core\Privacy\Jobs\EraseDataSubjectJob` per
|
||||||
|
request — it does not run `completeErasure()` inline itself. Each job independently calls
|
||||||
|
`PrivacyService::completeErasure()`, which checks the request's polymorphic `subject` and calls
|
||||||
|
either every registered provider's `eraseForCustomer()` or `eraseForUser()`, writing the full
|
||||||
|
per-provider outcome onto the request's `report` column and marking it `completed`. One job per
|
||||||
|
request means one request's failure (a provider throwing, a DB error) doesn't block or crash
|
||||||
|
processing of the others, and Laravel's normal per-job retry/failure handling applies to each
|
||||||
|
request independently. This package doesn't register a schedule itself; each consuming app wires
|
||||||
|
the command into its own scheduler (daily is reasonable), the same way it owns any other
|
||||||
|
scheduled task.
|
||||||
|
|
||||||
|
### Immediate erasure — staff-only, not self-service
|
||||||
|
|
||||||
|
`requestImmediateErasureForCustomer(Customer $customer, Staff $requestedBy): ErasureReport` and
|
||||||
|
`requestImmediateErasureForUser($user, Staff $requestedBy): ErasureReport` bypass the grace
|
||||||
|
period entirely and erase right away. Both are `Staff`-only **by type**, not just by convention —
|
||||||
|
their signatures take `Staff $requestedBy` specifically (not the union type the grace-period
|
||||||
|
methods accept), so a self-service/customer-facing code path can't reach either one even by
|
||||||
|
accident; calling with a `Customer`/`User` actor is a compile-time type error, not a runtime
|
||||||
|
check to remember.
|
||||||
|
|
||||||
|
This exists for a formal legal request or regulator inquiry that genuinely requires immediate
|
||||||
|
action, not as a convenience for an impatient customer. GDPR Art. 17 requires erasure "without
|
||||||
|
undue delay," but doesn't set a maximum number of days for a grace period, and a short, disclosed,
|
||||||
|
cancellable hold before executing a self-service request is a widely-used, generally accepted
|
||||||
|
pattern (the same one Shopify and most major platforms use) — it is **not** offered as a
|
||||||
|
same-click alternative on the self-service deletion flow, since doing so would mostly defeat the
|
||||||
|
grace period's purpose (protecting an impulsive requester from themselves). If a subject
|
||||||
|
explicitly insists on immediate deletion, that's a staff/support decision to make on the record
|
||||||
|
via one of these methods, not a checkbox exposed to every customer.
|
||||||
|
|
||||||
|
```php
|
||||||
|
$report = $service->requestImmediateErasureForCustomer($customer, $staffMember);
|
||||||
|
$report = $service->requestImmediateErasureForUser($user, $staffMember);
|
||||||
|
// Both run synchronously — no queueing, no grace period. $report is the same
|
||||||
|
// ErasureReport completeErasure() would produce.
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Export — queued, not synchronous
|
||||||
|
|
||||||
|
Export gathers real data across every registered provider — potentially slow, and there's no
|
||||||
|
reason to block whatever request triggered it (a customer clicking "export my data," an API
|
||||||
|
call). `requestExportForCustomer()`/`requestExportForUser()` are fast synchronous calls that only
|
||||||
|
create a `DataExportRequest` row and dispatch the actual work:
|
||||||
|
|
||||||
|
```php
|
||||||
|
$request = $service->requestExportForCustomer($customer);
|
||||||
|
$request = $service->requestExportForUser($user);
|
||||||
|
// $request->status is 'pending'; nothing has been gathered yet.
|
||||||
|
```
|
||||||
|
|
||||||
|
### The event chain
|
||||||
|
|
||||||
|
1. **`ExportDataSubjectJob`** (queued) checks the request's polymorphic `subject` and calls every
|
||||||
|
registered provider's `exportForCustomer()` or `exportForUser()` — all sequentially, in this
|
||||||
|
one job, not fanned out into one job per provider. Per-subject export work is small (a handful
|
||||||
|
of indexed queries per provider), so there's no real parallelism win, and one job means
|
||||||
|
"finished" is just "`handle()` returned," with no `Bus::batch()`/completion-counting needed. If
|
||||||
|
a future provider ever does something genuinely slow (an external API call, a generated PDF),
|
||||||
|
that's the point to reconsider a per-provider batch — not before.
|
||||||
|
2. Once every provider's data is gathered, the job fires **`PersonalDataGathered`**
|
||||||
|
(carries the request and the assembled `ExportReport`) — no file exists yet.
|
||||||
|
3. **`Modules\Core\Privacy\Listeners\WriteExportToCsvListener`** (registered in
|
||||||
|
`PrivacyServiceProvider`) handles that event: turns each provider's data into its own CSV (via
|
||||||
|
the generic `Modules\Core\Export\CsvWriter` — see below), zips them together, writes the zip to
|
||||||
|
`storage/app/exports/privacy/`, and updates the request (`status: completed`, `file_path`).
|
||||||
|
This is its own listener — not inline in the job — so the export *format* is swappable (an app
|
||||||
|
could unregister this and register a JSON-only listener instead) without touching how data is
|
||||||
|
gathered.
|
||||||
|
4. Once the file exists, that listener fires **`PersonalDataExportFileWritten`**.
|
||||||
|
5. Core has no opinion on how the subject is told. A consuming app registers its own notification
|
||||||
|
against `PersonalDataExportFileWritten` via `Modules\Core\Notification\NotificationRegistry` —
|
||||||
|
the same pattern as `App\Notifications\QuestionnaireResultsSentNotification` listening on
|
||||||
|
`App\Events\QuestionnaireResultsSent` (see `boboko-test` for a working example). Core
|
||||||
|
deliberately does not send an email itself.
|
||||||
|
|
||||||
|
### CSV shape
|
||||||
|
|
||||||
|
Every provider's `data` is either a list of associative arrays (addresses, orders, reviews — each
|
||||||
|
item becomes a row) or a single associative array (customer — becomes one row). Any nested array
|
||||||
|
value within a row (e.g. an order's `addresses` sub-array) is JSON-encoded into that one cell
|
||||||
|
rather than exploded into further columns — a generic, provider-agnostic rule in
|
||||||
|
`WriteExportToCsvListener`, not something each provider has to think about.
|
||||||
|
|
||||||
|
### `Modules\Core\Export\CsvWriter` — a generic, reusable piece
|
||||||
|
|
||||||
|
`CsvWriter::write(array $columns, iterable $rows, string $path)` has no knowledge of GDPR,
|
||||||
|
customers, or Lunar at all — a caller supplies a schema (`CsvColumn[]`, each just a header plus a
|
||||||
|
closure that pulls that column's value out of one record) and any iterable data source. It's used
|
||||||
|
here by `WriteExportToCsvListener`, but is equally usable for an unrelated future need — an admin
|
||||||
|
bulk catalog export, an accounting handoff — by supplying a different schema and row source;
|
||||||
|
nothing about it is GDPR-specific.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Audit trail
|
||||||
|
|
||||||
|
`DataErasureRequest` (`data_erasure_requests`) and `DataExportRequest` (`data_export_requests`)
|
||||||
|
are the audit records for erasure and export respectively. Both have a polymorphic `subject`
|
||||||
|
(`subject_type`/`subject_id`, pointing at either a Lunar `Customer` or a `User` — never both) —
|
||||||
|
`subject_type`/`subject_id`/`email` are stored as a **snapshot**, not looked up live, since the
|
||||||
|
whole point is for these tables to remain readable after the record they're about has been
|
||||||
|
erased. `DataErasureRequest::isForCustomer()` tells you which scope a given request is.
|
||||||
|
|
||||||
|
`DataErasureRequest.requested_by_type`/`requested_by_id` capture who asked for it (the subject
|
||||||
|
themselves, self-service; `Staff` acting on their behalf; or, for a cascade-created Customer
|
||||||
|
request, the User whose erasure caused it — see "The sole-owner cascade") at request time.
|
||||||
|
`DataErasureRequest.caused_by_request_id` is set only on a cascade-created Customer request,
|
||||||
|
pointing back at the User request that triggered it; null on every normal, directly-requested
|
||||||
|
erasure — see `DataErasureRequest::causedBy()`/`::caused()`.
|
||||||
|
`DataErasureRequest.report` holds the full per-provider outcome once `completeErasure()` runs;
|
||||||
|
`DataExportRequest.file_path` points at the generated zip once `WriteExportToCsvListener`
|
||||||
|
finishes.
|
||||||
|
|
||||||
|
**Not yet built**: a standalone "leave/remove from a Customer account" action — unlinking a User
|
||||||
|
from a Customer without any erasure involved (e.g. a teammate leaving a project, or an account
|
||||||
|
admin removing someone) — is a related but separate, smaller feature, deliberately out of scope
|
||||||
|
for this module so far. It shares the same pivot-detach primitive `CustomerDataProvider::
|
||||||
|
eraseForUser()` already uses as part of a full erasure, but as a standalone action it doesn't
|
||||||
|
exist yet.
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Greek translations for Lunar\Models\Country::name, keyed by the exact
|
||||||
|
* English spelling Lunar's own installer seeds (`lunar:import:address-data`
|
||||||
|
* fetches http://data.lunarphp.io/countries+states.json — see
|
||||||
|
* vendor/lunarphp/core/src/Console/Commands/Import/AddressData.php).
|
||||||
|
* `Country`/`State` have no i18n support of their own (plain string
|
||||||
|
* columns, no translatable trait) — this is a plain Laravel lang file, not
|
||||||
|
* Modules\Core\Localization's DB-backed TranslationService, since these
|
||||||
|
* names are fixed reference data seeded once, not editable UI copy (see
|
||||||
|
* docs/localization.md). A consuming app's storefront looks this up
|
||||||
|
* itself, e.g. __('core::countries.'.$country->name) — core has no
|
||||||
|
* storefront UI of its own to wire this into (see docs/lunar.md).
|
||||||
|
*
|
||||||
|
* Only Greece is covered — this store operates within Greece; add further
|
||||||
|
* countries here as needed.
|
||||||
|
*/
|
||||||
|
return [
|
||||||
|
'Greece' => 'Ελλάδα',
|
||||||
|
];
|
||||||
@@ -0,0 +1,52 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Greek translations for Lunar\Models\State::name, keyed by the exact
|
||||||
|
* English spelling Lunar's own installer seeds for Greece
|
||||||
|
* (`lunar:import:address-data` — see lang/el/countries.php's own docblock
|
||||||
|
* for the full explanation of why this is a plain lang file, not
|
||||||
|
* Modules\Core\Localization's TranslationService).
|
||||||
|
*
|
||||||
|
* Covers every Greek state/regional-unit row in Lunar's seed dataset —
|
||||||
|
* scoped to Greece only, matching this store's operating country.
|
||||||
|
*/
|
||||||
|
return [
|
||||||
|
'Achaea Regional Unit' => 'Περιφερειακή Ενότητα Αχαΐας',
|
||||||
|
'Aetolia-Acarnania Regional Unit' => 'Περιφερειακή Ενότητα Αιτωλοακαρνανίας',
|
||||||
|
'Arcadia Prefecture' => 'Νομός Αρκαδίας',
|
||||||
|
'Argolis Regional Unit' => 'Περιφερειακή Ενότητα Αργολίδας',
|
||||||
|
'Attica Region' => 'Περιφέρεια Αττικής',
|
||||||
|
'Boeotia Regional Unit' => 'Περιφερειακή Ενότητα Βοιωτίας',
|
||||||
|
'Central Greece Region' => 'Περιφέρεια Στερεάς Ελλάδας',
|
||||||
|
'Central Macedonia' => 'Κεντρική Μακεδονία',
|
||||||
|
'Chania Regional Unit' => 'Περιφερειακή Ενότητα Χανίων',
|
||||||
|
'Corfu Prefecture' => 'Νομός Κέρκυρας',
|
||||||
|
'Corinthia Regional Unit' => 'Περιφερειακή Ενότητα Κορινθίας',
|
||||||
|
'Crete Region' => 'Περιφέρεια Κρήτης',
|
||||||
|
'Drama Regional Unit' => 'Περιφερειακή Ενότητα Δράμας',
|
||||||
|
'East Attica Regional Unit' => 'Περιφερειακή Ενότητα Ανατολικής Αττικής',
|
||||||
|
'East Macedonia and Thrace' => 'Ανατολική Μακεδονία και Θράκη',
|
||||||
|
'Epirus Region' => 'Περιφέρεια Ηπείρου',
|
||||||
|
'Euboea' => 'Εύβοια',
|
||||||
|
'Grevena Prefecture' => 'Νομός Γρεβενών',
|
||||||
|
'Imathia Regional Unit' => 'Περιφερειακή Ενότητα Ημαθίας',
|
||||||
|
'Ioannina Regional Unit' => 'Περιφερειακή Ενότητα Ιωαννίνων',
|
||||||
|
'Ionian Islands Region' => 'Περιφέρεια Ιονίων Νήσων',
|
||||||
|
'Karditsa Regional Unit' => 'Περιφερειακή Ενότητα Καρδίτσας',
|
||||||
|
'Kastoria Regional Unit' => 'Περιφερειακή Ενότητα Καστοριάς',
|
||||||
|
'Kefalonia Prefecture' => 'Νομός Κεφαλληνίας',
|
||||||
|
'Kilkis Regional Unit' => 'Περιφερειακή Ενότητα Κιλκίς',
|
||||||
|
'Kozani Prefecture' => 'Νομός Κοζάνης',
|
||||||
|
'Laconia' => 'Λακωνία',
|
||||||
|
'Larissa Prefecture' => 'Νομός Λάρισας',
|
||||||
|
'Lefkada Regional Unit' => 'Περιφερειακή Ενότητα Λευκάδας',
|
||||||
|
'Pella Regional Unit' => 'Περιφερειακή Ενότητα Πέλλας',
|
||||||
|
'Peloponnese Region' => 'Περιφέρεια Πελοποννήσου',
|
||||||
|
'Phthiotis Prefecture' => 'Νομός Φθιώτιδας',
|
||||||
|
'Preveza Prefecture' => 'Νομός Πρέβεζας',
|
||||||
|
'Serres Prefecture' => 'Νομός Σερρών',
|
||||||
|
'South Aegean' => 'Νότιο Αιγαίο',
|
||||||
|
'Thessaloniki Regional Unit' => 'Περιφερειακή Ενότητα Θεσσαλονίκης',
|
||||||
|
'West Greece Region' => 'Περιφέρεια Δυτικής Ελλάδας',
|
||||||
|
'West Macedonia Region' => 'Περιφέρεια Δυτικής Μακεδονίας',
|
||||||
|
];
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
{
|
||||||
|
"name": "@boboko/core",
|
||||||
|
"version": "0.31.0",
|
||||||
|
"private": true,
|
||||||
|
"type": "module",
|
||||||
|
"description": "Portable Stimulus controllers and styles for boboko-core's cart + checkout module. Installed as a real npm dependency (file:../boboko-core in dev, a tagged git install in prod) so a consuming app's `npm install` resolves this package's own dependencies (leaflet, @hotwired/stimulus) transitively, the same way `composer update boboko/*` does for PHP. See CONTRIBUTE.md's \"JS/CSS: a real npm package\" section.",
|
||||||
|
"exports": {
|
||||||
|
".": "./resources/js/index.js",
|
||||||
|
"./checkout": "./resources/js/checkout/index.js",
|
||||||
|
"./checkout/*": "./resources/js/checkout/*",
|
||||||
|
"./css/*": "./resources/css/*",
|
||||||
|
"./vite-plugin": "./vite-plugin.js"
|
||||||
|
},
|
||||||
|
"dependencies": {
|
||||||
|
"@hotwired/stimulus": "^3.2.2",
|
||||||
|
"leaflet": "^1.9.4"
|
||||||
|
},
|
||||||
|
"peerDependencies": {
|
||||||
|
"vite": "^8.0.0"
|
||||||
|
}
|
||||||
|
}
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,57 @@
|
|||||||
|
import { Controller } from '@hotwired/stimulus'
|
||||||
|
import { csrfToken } from './csrf'
|
||||||
|
|
||||||
|
// Sits on an <x-checkout::add-to-cart> <form>. Submits the line to the cart
|
||||||
|
// via fetch and hands the server-rendered cart body to the drawer through the
|
||||||
|
// `bbk-cart:changed` window event. No DOM building here — the drawer
|
||||||
|
// (bbk-cart-controller) owns rendering.
|
||||||
|
export default class extends Controller {
|
||||||
|
static targets = ['error']
|
||||||
|
|
||||||
|
async add(event) {
|
||||||
|
event.preventDefault()
|
||||||
|
|
||||||
|
const form = this.element
|
||||||
|
const submit = form.querySelector('[type="submit"]')
|
||||||
|
|
||||||
|
this.clearError()
|
||||||
|
form.setAttribute('data-bbk-add-to-cart-state', 'loading')
|
||||||
|
if (submit) submit.disabled = true
|
||||||
|
|
||||||
|
try {
|
||||||
|
const response = await fetch(form.action, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: {
|
||||||
|
'X-CSRF-TOKEN': csrfToken(),
|
||||||
|
'X-Requested-With': 'XMLHttpRequest',
|
||||||
|
Accept: 'application/json',
|
||||||
|
},
|
||||||
|
body: new FormData(form),
|
||||||
|
})
|
||||||
|
|
||||||
|
if (!response.ok) {
|
||||||
|
const data = await response.json().catch(() => null)
|
||||||
|
this.showError(data?.error)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
window.dispatchEvent(new CustomEvent('bbk-cart:changed', {
|
||||||
|
detail: { html: await response.text() },
|
||||||
|
}))
|
||||||
|
} finally {
|
||||||
|
form.removeAttribute('data-bbk-add-to-cart-state')
|
||||||
|
if (submit) submit.disabled = false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
showError(message) {
|
||||||
|
if (!this.hasErrorTarget || !message) return
|
||||||
|
this.errorTarget.textContent = message
|
||||||
|
this.errorTarget.hidden = false
|
||||||
|
}
|
||||||
|
|
||||||
|
clearError() {
|
||||||
|
if (!this.hasErrorTarget) return
|
||||||
|
this.errorTarget.hidden = true
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,220 @@
|
|||||||
|
import { Controller } from '@hotwired/stimulus'
|
||||||
|
import L from 'leaflet'
|
||||||
|
import 'leaflet/dist/leaflet.css'
|
||||||
|
import { csrfToken } from './csrf'
|
||||||
|
|
||||||
|
// Box Now's own brand green, used for the pin instead of Leaflet's default
|
||||||
|
// blue teardrop — a small SVG data URI rather than another bundled asset.
|
||||||
|
const PIN_COLOR = '#00c389'
|
||||||
|
const PIN_COLOR_SELECTED = '#0a7a52'
|
||||||
|
|
||||||
|
function pinIcon(color) {
|
||||||
|
const svg = `
|
||||||
|
<svg xmlns="http://www.w3.org/2000/svg" width="34" height="46" viewBox="0 0 34 46">
|
||||||
|
<path
|
||||||
|
d="M17 0C7.6 0 0 7.6 0 17c0 12.75 17 29 17 29s17-16.25 17-29C34 7.6 26.4 0 17 0Z"
|
||||||
|
fill="${color}"
|
||||||
|
stroke="#ffffff"
|
||||||
|
stroke-width="1.5"
|
||||||
|
/>
|
||||||
|
<circle cx="17" cy="17" r="7" fill="#ffffff" />
|
||||||
|
</svg>
|
||||||
|
`
|
||||||
|
|
||||||
|
return L.divIcon({
|
||||||
|
className: 'bbk-box-now-pin',
|
||||||
|
html: svg,
|
||||||
|
iconSize: [34, 46],
|
||||||
|
iconAnchor: [17, 46],
|
||||||
|
popupAnchor: [0, -40],
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
const ICON = pinIcon(PIN_COLOR)
|
||||||
|
const ICON_SELECTED = pinIcon(PIN_COLOR_SELECTED)
|
||||||
|
|
||||||
|
// A self-hosted Leaflet map standing in for Box Now's own Destination Map
|
||||||
|
// JS widget — that widget only talks to Box Now's Production API (see
|
||||||
|
// their Partner API manual §4.1), so it can't be used while developing
|
||||||
|
// against Stage credentials. Same underlying /destinations data, rendered
|
||||||
|
// with OpenStreetMap tiles instead of Box Now's map.
|
||||||
|
//
|
||||||
|
// Visibility is toggled by bbk-checkout-form (see its own
|
||||||
|
// toggleBoxNowLocker()) whenever the "box-now" shipping option becomes
|
||||||
|
// selected/deselected — this controller only owns loading the locker list
|
||||||
|
// once visible, rendering pins, and autosaving the chosen one.
|
||||||
|
export default class extends Controller {
|
||||||
|
static targets = ['map', 'search', 'status', 'chosen']
|
||||||
|
|
||||||
|
static values = {
|
||||||
|
lockersUrl: String,
|
||||||
|
selectUrl: String,
|
||||||
|
loading: String,
|
||||||
|
selectLabel: String,
|
||||||
|
selectedLabel: String,
|
||||||
|
noResults: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
// Athens — a reasonable default center before any locker is loaded.
|
||||||
|
static DEFAULT_CENTER = [37.9838, 23.7275]
|
||||||
|
|
||||||
|
connect() {
|
||||||
|
this.map = null
|
||||||
|
this.markers = new Map()
|
||||||
|
this.selectedId = null
|
||||||
|
this.loaded = false
|
||||||
|
|
||||||
|
if (!this.element.hidden) this.show()
|
||||||
|
}
|
||||||
|
|
||||||
|
disconnect() {
|
||||||
|
this.map?.remove()
|
||||||
|
this.map = null
|
||||||
|
}
|
||||||
|
|
||||||
|
// Called by bbk-checkout-form right after it un-hides this element.
|
||||||
|
show() {
|
||||||
|
this.element.hidden = false
|
||||||
|
|
||||||
|
// Leaflet measures its container's size on init — doing that while
|
||||||
|
// the element (or an ancestor) is still `hidden` produces a
|
||||||
|
// collapsed/blank map, so this is deferred to the same tick `hidden`
|
||||||
|
// is cleared, then Leaflet is nudged once more via invalidateSize().
|
||||||
|
requestAnimationFrame(() => {
|
||||||
|
if (!this.map) this.initMap()
|
||||||
|
this.map.invalidateSize()
|
||||||
|
|
||||||
|
if (!this.loaded) this.loadLockers()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
hide() {
|
||||||
|
this.element.hidden = true
|
||||||
|
}
|
||||||
|
|
||||||
|
initMap() {
|
||||||
|
this.map = L.map(this.mapTarget).setView(this.constructor.DEFAULT_CENTER, 10)
|
||||||
|
|
||||||
|
L.tileLayer('https://{s}.tile.openstreetmap.org/{z}/{x}/{y}.png', {
|
||||||
|
attribution: '© OpenStreetMap contributors',
|
||||||
|
maxZoom: 19,
|
||||||
|
}).addTo(this.map)
|
||||||
|
|
||||||
|
// Delegated: popup content is re-inserted by Leaflet on every open,
|
||||||
|
// so a listener bound once on the map's container beats binding (and
|
||||||
|
// losing) one on the button each time a popup renders.
|
||||||
|
this.map.getContainer().addEventListener('click', (event) => {
|
||||||
|
const button = event.target.closest('[data-locker-id]')
|
||||||
|
if (button) this.select(button.dataset.lockerId)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
async loadLockers() {
|
||||||
|
this.setStatus(this.loadingValue)
|
||||||
|
|
||||||
|
try {
|
||||||
|
const response = await fetch(this.lockersUrlValue, {
|
||||||
|
headers: { Accept: 'application/json' },
|
||||||
|
})
|
||||||
|
|
||||||
|
if (!response.ok) return
|
||||||
|
|
||||||
|
const { lockers } = await response.json()
|
||||||
|
this.loaded = true
|
||||||
|
this.lockers = new Map(lockers.map((locker) => [String(locker.id), locker]))
|
||||||
|
this.renderMarkers(lockers)
|
||||||
|
this.setStatus('')
|
||||||
|
} catch {
|
||||||
|
this.setStatus('')
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
renderMarkers(lockers) {
|
||||||
|
this.markers.forEach((marker) => marker.remove())
|
||||||
|
this.markers = new Map(lockers.map((locker) => {
|
||||||
|
const marker = L.marker([locker.lat, locker.lng], { icon: ICON })
|
||||||
|
.addTo(this.map)
|
||||||
|
.bindPopup(this.popupHtml(locker), { maxWidth: 260 })
|
||||||
|
|
||||||
|
return [String(locker.id), marker]
|
||||||
|
}))
|
||||||
|
|
||||||
|
if (this.markers.size) {
|
||||||
|
this.map.fitBounds(L.featureGroup([...this.markers.values()]).getBounds().pad(0.2))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
popupHtml(locker) {
|
||||||
|
const isSelected = String(locker.id) === this.selectedId
|
||||||
|
|
||||||
|
return `
|
||||||
|
<div class="bbk-box-now-popup">
|
||||||
|
${locker.image ? `<img class="bbk-box-now-popup-image" src="${locker.image}" alt="">` : ''}
|
||||||
|
<p class="bbk-box-now-popup-name">${locker.name}</p>
|
||||||
|
<p class="bbk-box-now-popup-address">
|
||||||
|
${[locker.addressLine1, locker.addressLine2].filter(Boolean).join(', ')}
|
||||||
|
${locker.postalCode ? ` ${locker.postalCode}` : ''}
|
||||||
|
</p>
|
||||||
|
${locker.note ? `<p class="bbk-box-now-popup-note">${locker.note}</p>` : ''}
|
||||||
|
<button
|
||||||
|
type="button"
|
||||||
|
class="bbk-box-now-popup-select${isSelected ? ' bbk-box-now-popup-select--selected' : ''}"
|
||||||
|
data-locker-id="${locker.id}"
|
||||||
|
${isSelected ? 'disabled' : ''}
|
||||||
|
>
|
||||||
|
${isSelected ? this.selectedLabelValue : this.selectLabelValue}
|
||||||
|
</button>
|
||||||
|
</div>
|
||||||
|
`
|
||||||
|
}
|
||||||
|
|
||||||
|
async select(lockerId) {
|
||||||
|
const locker = this.lockers?.get(String(lockerId))
|
||||||
|
if (!locker) return
|
||||||
|
|
||||||
|
const previousId = this.selectedId
|
||||||
|
this.selectedId = String(lockerId)
|
||||||
|
|
||||||
|
this.restyleMarker(previousId, ICON)
|
||||||
|
this.restyleMarker(this.selectedId, ICON_SELECTED)
|
||||||
|
this.markers.get(this.selectedId)?.setPopupContent(this.popupHtml(locker))
|
||||||
|
|
||||||
|
this.chosenTarget.hidden = false
|
||||||
|
this.chosenTarget.textContent = locker.addressLine1
|
||||||
|
? `${locker.name} — ${locker.addressLine1}`
|
||||||
|
: locker.name
|
||||||
|
|
||||||
|
const body = new FormData()
|
||||||
|
body.append('locker_id', locker.id)
|
||||||
|
body.append('locker_name', locker.name ?? '')
|
||||||
|
body.append('locker_address', locker.addressLine1 ?? '')
|
||||||
|
|
||||||
|
try {
|
||||||
|
await fetch(this.selectUrlValue, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: {
|
||||||
|
'X-CSRF-TOKEN': csrfToken(),
|
||||||
|
'X-Requested-With': 'XMLHttpRequest',
|
||||||
|
Accept: 'application/json',
|
||||||
|
},
|
||||||
|
body,
|
||||||
|
})
|
||||||
|
} catch {
|
||||||
|
// Best-effort autosave, same as the rest of checkout — a failed
|
||||||
|
// save here surfaces later at place-order time via the normal
|
||||||
|
// shipment-creation error path, not as an inline field error.
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
restyleMarker(lockerId, icon) {
|
||||||
|
if (!lockerId) return
|
||||||
|
this.markers.get(lockerId)?.setIcon(icon)
|
||||||
|
}
|
||||||
|
|
||||||
|
setStatus(text) {
|
||||||
|
if (!this.hasStatusTarget) return
|
||||||
|
|
||||||
|
this.statusTarget.textContent = text
|
||||||
|
this.statusTarget.hidden = !text
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,240 @@
|
|||||||
|
import { Controller } from '@hotwired/stimulus'
|
||||||
|
import { csrfToken } from './csrf'
|
||||||
|
|
||||||
|
// Drives the slide-in cart drawer. One instance, on the drawer root in
|
||||||
|
// checkout/drawer.blade.php.
|
||||||
|
//
|
||||||
|
// - listens on window for `bbk-cart:changed` (from bbk-add-to-cart and from
|
||||||
|
// this drawer's own line forms) and swaps in the server-rendered cart body
|
||||||
|
// - handles the in-drawer quantity / remove forms (fetch + method spoofing)
|
||||||
|
// - re-emits `bbk-cart:updated` {count, total} after every render so the host
|
||||||
|
// (e.g. the header bag icon) can react
|
||||||
|
// - dialog focus handling: focus moves into the panel on open, Tab is kept
|
||||||
|
// inside it, and focus returns to whatever opened it on close
|
||||||
|
//
|
||||||
|
// Appearance is entirely CSS-driven: open state is the data-bbk-cart-state
|
||||||
|
// attribute on the root, nothing here touches styles or class lists.
|
||||||
|
export default class extends Controller {
|
||||||
|
static targets = ['panel', 'body', 'error', 'heading', 'status']
|
||||||
|
|
||||||
|
connect() {
|
||||||
|
this.onChanged = this.onChanged.bind(this)
|
||||||
|
this.onKeydown = this.onKeydown.bind(this)
|
||||||
|
this.updateTimers = new Map() // line id -> pending debounce timer
|
||||||
|
|
||||||
|
window.addEventListener('bbk-cart:changed', this.onChanged)
|
||||||
|
window.addEventListener('bbk-cart:open', this.open.bind(this))
|
||||||
|
document.addEventListener('keydown', this.onKeydown)
|
||||||
|
|
||||||
|
// Prime the host with the count rendered server-side on page load.
|
||||||
|
this.emitUpdated(this.element.querySelector('[data-bbk-cart-count]'))
|
||||||
|
}
|
||||||
|
|
||||||
|
disconnect() {
|
||||||
|
window.removeEventListener('bbk-cart:changed', this.onChanged)
|
||||||
|
document.removeEventListener('keydown', this.onKeydown)
|
||||||
|
this.updateTimers.forEach((timer) => clearTimeout(timer))
|
||||||
|
}
|
||||||
|
|
||||||
|
onChanged(event) {
|
||||||
|
if (event.detail?.html) this.replaceBody(event.detail.html)
|
||||||
|
this.open()
|
||||||
|
}
|
||||||
|
|
||||||
|
onKeydown(event) {
|
||||||
|
// Only the drawer instance is a dialog — the checkout page's summary
|
||||||
|
// reuses this controller without a panel.
|
||||||
|
if (!this.hasPanelTarget || this.element.hidden) return
|
||||||
|
|
||||||
|
if (event.key === 'Escape') this.close()
|
||||||
|
if (event.key === 'Tab') this.trapFocus(event)
|
||||||
|
}
|
||||||
|
|
||||||
|
open() {
|
||||||
|
if (!this.element.hidden) return
|
||||||
|
this.returnFocusTo = document.activeElement
|
||||||
|
this.element.hidden = false
|
||||||
|
// Next frame, so the panel transitions from its off-canvas start.
|
||||||
|
requestAnimationFrame(() => {
|
||||||
|
this.element.setAttribute('data-bbk-cart-state', 'open')
|
||||||
|
if (this.hasHeadingTarget) this.headingTarget.focus({ preventScroll: true })
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
close() {
|
||||||
|
this.element.removeAttribute('data-bbk-cart-state')
|
||||||
|
|
||||||
|
if (this.returnFocusTo?.isConnected) this.returnFocusTo.focus({ preventScroll: true })
|
||||||
|
this.returnFocusTo = null
|
||||||
|
|
||||||
|
const panel = this.panelTarget
|
||||||
|
const done = () => {
|
||||||
|
this.element.hidden = true
|
||||||
|
panel.removeEventListener('transitionend', done)
|
||||||
|
}
|
||||||
|
panel.addEventListener('transitionend', done)
|
||||||
|
}
|
||||||
|
|
||||||
|
// change on a line quantity input, or submit of a line's remove form
|
||||||
|
submit(event) {
|
||||||
|
event.preventDefault()
|
||||||
|
const form = event.target.closest('form')
|
||||||
|
if (!form) return
|
||||||
|
|
||||||
|
// A remove is a deliberate, one-shot action — only the quantity form
|
||||||
|
// (typing, or the +/- stepper below) benefits from debouncing.
|
||||||
|
form.classList.contains('bbk-cart-qty') ? this.scheduleSend(form) : this.send(form)
|
||||||
|
}
|
||||||
|
|
||||||
|
// +/- stepper buttons inside a line
|
||||||
|
step(event) {
|
||||||
|
event.preventDefault()
|
||||||
|
const form = event.target.closest('form')
|
||||||
|
const input = form.querySelector('input[type="number"]')
|
||||||
|
const next = Math.max(0, parseInt(input.value || '0', 10) + Number(event.params.dir))
|
||||||
|
input.value = String(next)
|
||||||
|
this.scheduleSend(form)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Repeated clicks (or spinner nudges) update the input instantly but only
|
||||||
|
// send once they settle for 300ms — sending on every single click was
|
||||||
|
// firing overlapping requests that raced each other and made the drawer
|
||||||
|
// visibly flicker/lag under quick clicking.
|
||||||
|
scheduleSend(form) {
|
||||||
|
const lineId = form.closest('[data-bbk-line-id]')?.dataset.bbkLineId
|
||||||
|
if (!lineId) return this.send(form)
|
||||||
|
|
||||||
|
clearTimeout(this.updateTimers.get(lineId))
|
||||||
|
this.updateTimers.set(lineId, setTimeout(() => {
|
||||||
|
this.updateTimers.delete(lineId)
|
||||||
|
this.send(form)
|
||||||
|
}, 300))
|
||||||
|
}
|
||||||
|
|
||||||
|
async send(form) {
|
||||||
|
this.bodyTarget.setAttribute('aria-busy', 'true')
|
||||||
|
this.clearError()
|
||||||
|
|
||||||
|
try {
|
||||||
|
const response = await fetch(form.action, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: {
|
||||||
|
'X-CSRF-TOKEN': csrfToken(),
|
||||||
|
'X-Requested-With': 'XMLHttpRequest',
|
||||||
|
Accept: 'application/json',
|
||||||
|
},
|
||||||
|
body: new FormData(form),
|
||||||
|
})
|
||||||
|
|
||||||
|
if (response.ok) {
|
||||||
|
this.replaceBody(await response.text())
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
const data = await response.json().catch(() => null)
|
||||||
|
this.showError(data?.error)
|
||||||
|
|
||||||
|
// The rejected quantity (typed, or from a +/- click) is left
|
||||||
|
// sitting in the input with nothing to correct it — the update
|
||||||
|
// never reached the cart, so the input must be put back to what
|
||||||
|
// the cart actually still holds, not just left showing whatever
|
||||||
|
// was rejected.
|
||||||
|
const input = form.querySelector('[data-bbk-cart-confirmed-quantity]')
|
||||||
|
if (input) input.value = input.dataset.bbkCartConfirmedQuantity
|
||||||
|
} finally {
|
||||||
|
this.bodyTarget.removeAttribute('aria-busy')
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// aria-modal hides the page from screen readers but doesn't stop Tab from
|
||||||
|
// walking out of the panel into it — wrap at either end instead.
|
||||||
|
trapFocus(event) {
|
||||||
|
const focusable = [...this.panelTarget.querySelectorAll(
|
||||||
|
'a[href], button:not([disabled]), input:not([disabled]):not([type="hidden"]), select:not([disabled]), textarea:not([disabled]), [tabindex]:not([tabindex="-1"])',
|
||||||
|
)].filter((el) => !el.closest('[hidden], [aria-hidden="true"]'))
|
||||||
|
|
||||||
|
if (!focusable.length) return
|
||||||
|
|
||||||
|
const first = focusable[0]
|
||||||
|
const last = focusable[focusable.length - 1]
|
||||||
|
const active = document.activeElement
|
||||||
|
|
||||||
|
if (event.shiftKey && (active === first || !this.panelTarget.contains(active) || (this.hasHeadingTarget && active === this.headingTarget))) {
|
||||||
|
event.preventDefault()
|
||||||
|
last.focus()
|
||||||
|
} else if (!event.shiftKey && (active === last || !this.panelTarget.contains(active))) {
|
||||||
|
event.preventDefault()
|
||||||
|
first.focus()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
showError(message) {
|
||||||
|
if (!this.hasErrorTarget || !message) return
|
||||||
|
this.errorTarget.textContent = message
|
||||||
|
this.errorTarget.hidden = false
|
||||||
|
}
|
||||||
|
|
||||||
|
clearError() {
|
||||||
|
if (!this.hasErrorTarget) return
|
||||||
|
this.errorTarget.hidden = true
|
||||||
|
}
|
||||||
|
|
||||||
|
replaceBody(html) {
|
||||||
|
const restore = this.focusSnapshot()
|
||||||
|
this.bodyTarget.innerHTML = html
|
||||||
|
restore()
|
||||||
|
this.announce()
|
||||||
|
this.emitUpdated(this.bodyTarget.querySelector('[data-bbk-cart-count]'))
|
||||||
|
}
|
||||||
|
|
||||||
|
// Swapping the body destroys whatever control had focus (a qty stepper,
|
||||||
|
// a remove button, the coupon field), dropping keyboard/screen-reader
|
||||||
|
// users back at the top of the document. Returns a callback that, after
|
||||||
|
// the swap, re-focuses the equivalent control in the new markup — or the
|
||||||
|
// heading, when that control is gone (e.g. its line was just removed).
|
||||||
|
focusSnapshot() {
|
||||||
|
const active = document.activeElement
|
||||||
|
if (!active || !this.bodyTarget.contains(active)) return () => {}
|
||||||
|
|
||||||
|
let selector = null
|
||||||
|
if (active.id) {
|
||||||
|
selector = `#${CSS.escape(active.id)}`
|
||||||
|
} else {
|
||||||
|
const lineId = active.closest('[data-bbk-line-id]')?.dataset.bbkLineId
|
||||||
|
const dir = active.dataset.bbkCartDirParam
|
||||||
|
const control = ['bbk-cart-qty-input', 'bbk-cart-qty-btn', 'bbk-cart-item-remove']
|
||||||
|
.find((name) => active.classList.contains(name))
|
||||||
|
|
||||||
|
if (lineId && control) {
|
||||||
|
selector = `[data-bbk-line-id="${CSS.escape(lineId)}"] .${control}`
|
||||||
|
+ (dir ? `[data-bbk-cart-dir-param="${CSS.escape(dir)}"]` : '')
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return () => {
|
||||||
|
const target = selector && this.bodyTarget.querySelector(selector)
|
||||||
|
if (target) target.focus({ preventScroll: true })
|
||||||
|
else if (this.hasHeadingTarget) this.headingTarget.focus({ preventScroll: true })
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Polite "Cart updated" — cleared first so an identical message is
|
||||||
|
// re-announced on the next update.
|
||||||
|
announce() {
|
||||||
|
if (!this.hasStatusTarget) return
|
||||||
|
const message = this.statusTarget.dataset.bbkCartMessage || ''
|
||||||
|
this.statusTarget.textContent = ''
|
||||||
|
requestAnimationFrame(() => { this.statusTarget.textContent = message })
|
||||||
|
}
|
||||||
|
|
||||||
|
emitUpdated(node) {
|
||||||
|
if (!node) return
|
||||||
|
|
||||||
|
window.dispatchEvent(new CustomEvent('bbk-cart:updated', {
|
||||||
|
detail: {
|
||||||
|
count: parseInt(node.dataset.bbkCartCount || '0', 10),
|
||||||
|
total: parseInt(node.dataset.bbkCartTotal || '0', 10),
|
||||||
|
},
|
||||||
|
}))
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,238 @@
|
|||||||
|
import { Controller } from '@hotwired/stimulus'
|
||||||
|
import { csrfToken } from './csrf'
|
||||||
|
|
||||||
|
// Drives the checkout page's left column: contact tabs, the same-as-billing
|
||||||
|
// toggle, and — the bulk of it — autosaving the address form and the shipping
|
||||||
|
// method with no submit buttons.
|
||||||
|
//
|
||||||
|
// Flow: any `change` in the address form is debounced ~400ms, then the whole
|
||||||
|
// form is POSTed to saveUrl. The server persists leniently and returns
|
||||||
|
// { errors, shippingOptionsHtml, summaryHtml }. We swap the shipping-options
|
||||||
|
// block in place and hand the summary fragment to the drawer's bbk-cart
|
||||||
|
// controller via the `bbk-cart:changed` window event (same mechanism the drawer
|
||||||
|
// already uses). Shipping-method radios post to selectShippingUrl the same way.
|
||||||
|
export default class extends Controller {
|
||||||
|
static targets = [
|
||||||
|
'sameAsBilling', 'shippingFields',
|
||||||
|
'form', 'shippingOptions', 'status',
|
||||||
|
]
|
||||||
|
|
||||||
|
static values = {
|
||||||
|
saveUrl: String,
|
||||||
|
selectShippingUrl: String,
|
||||||
|
statusSaving: String,
|
||||||
|
statusSaved: String,
|
||||||
|
statusError: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
connect() {
|
||||||
|
this.saveTimer = null
|
||||||
|
this.saveController = null
|
||||||
|
this.statusTimer = null
|
||||||
|
this.shippingPromise = null
|
||||||
|
|
||||||
|
if (this.hasSameAsBillingTarget) this.applySameAsBilling()
|
||||||
|
}
|
||||||
|
|
||||||
|
disconnect() {
|
||||||
|
clearTimeout(this.saveTimer)
|
||||||
|
clearTimeout(this.statusTimer)
|
||||||
|
this.saveController?.abort()
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Same as billing ────────────────────────────────────────────────
|
||||||
|
|
||||||
|
toggleSameAsBilling() {
|
||||||
|
this.applySameAsBilling()
|
||||||
|
}
|
||||||
|
|
||||||
|
applySameAsBilling() {
|
||||||
|
const on = this.sameAsBillingTarget.checked
|
||||||
|
|
||||||
|
// Checked: shipping *is* billing — copy every value across, then hide +
|
||||||
|
// disable so the browser doesn't submit them; the server reuses billing.
|
||||||
|
// Unchecked: reveal them pre-filled from billing wherever still empty.
|
||||||
|
this.element.querySelectorAll('[name^="billing_"]').forEach((billingField) => {
|
||||||
|
const shippingField = this.element.querySelector(
|
||||||
|
`[name="${billingField.name.replace(/^billing_/, 'shipping_')}"]`,
|
||||||
|
)
|
||||||
|
if (shippingField && (on || !shippingField.value)) {
|
||||||
|
shippingField.value = billingField.value
|
||||||
|
}
|
||||||
|
})
|
||||||
|
|
||||||
|
this.shippingFieldsTarget.hidden = on
|
||||||
|
this.shippingFieldsTarget.querySelectorAll('input, select, textarea').forEach((field) => {
|
||||||
|
field.disabled = on
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Autosave ───────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
scheduleSave(event) {
|
||||||
|
// The shipping-method and payment radios live inside this controller's
|
||||||
|
// element too, and this action is bound on .bbk-checkout-main to also
|
||||||
|
// catch the contact email/consent that sit outside the <form>. Only
|
||||||
|
// react to fields that actually belong to the address form.
|
||||||
|
const el = event.target
|
||||||
|
const belongsToForm = el.form?.id === 'bbk-address-form'
|
||||||
|
if (!belongsToForm) return
|
||||||
|
|
||||||
|
// No status during the wait — it only shows once the request is in flight,
|
||||||
|
// so the indicator isn't flickering "saving" on every keystroke.
|
||||||
|
clearTimeout(this.saveTimer)
|
||||||
|
this.saveTimer = setTimeout(() => this.save(), 700)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Called by bbk-payment right before place-order — a debounced save (and
|
||||||
|
// the shipping-option auto-select that happens as part of it) might still
|
||||||
|
// be pending when the shopper clicks "place order"; this guarantees the
|
||||||
|
// server has processed the current form state first.
|
||||||
|
async flush() {
|
||||||
|
clearTimeout(this.saveTimer)
|
||||||
|
await this.save()
|
||||||
|
// A shipping-method radio click fires its own (undebounced) request —
|
||||||
|
// still async, still racy against an immediate "place order" click.
|
||||||
|
if (this.shippingPromise) await this.shippingPromise
|
||||||
|
}
|
||||||
|
|
||||||
|
async save() {
|
||||||
|
this.saveController?.abort()
|
||||||
|
this.saveController = new AbortController()
|
||||||
|
this.setStatus('saving')
|
||||||
|
|
||||||
|
try {
|
||||||
|
const response = await fetch(this.saveUrlValue, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: {
|
||||||
|
'X-CSRF-TOKEN': csrfToken(),
|
||||||
|
'X-Requested-With': 'XMLHttpRequest',
|
||||||
|
Accept: 'application/json',
|
||||||
|
},
|
||||||
|
body: new FormData(this.formTarget),
|
||||||
|
signal: this.saveController.signal,
|
||||||
|
})
|
||||||
|
|
||||||
|
if (!response.ok) return this.setStatus('error')
|
||||||
|
|
||||||
|
this.applyResult(await response.json())
|
||||||
|
this.setStatus('saved')
|
||||||
|
} catch (error) {
|
||||||
|
if (error.name !== 'AbortError') this.setStatus('error')
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async selectShipping(event) {
|
||||||
|
this.toggleBoxNowLocker(event.target.dataset.boxNow === 'true')
|
||||||
|
|
||||||
|
// Tracked so flush() can await it — nothing else stops "place order"
|
||||||
|
// (a separate, unrelated click) from racing ahead of this request.
|
||||||
|
this.shippingPromise = this.doSelectShipping(event.target.value)
|
||||||
|
await this.shippingPromise
|
||||||
|
}
|
||||||
|
|
||||||
|
// The dummy Box Now locker <select> (see shipping-options.blade.php)
|
||||||
|
// lives inside the #bbk-shipping-options fragment this controller
|
||||||
|
// re-renders wholesale on every shipping-option change — so its own
|
||||||
|
// Stimulus controller reconnects fresh each time and has no memory of
|
||||||
|
// which option was previously selected. This is the one place that
|
||||||
|
// knows the newly-chosen option, so it also owns showing/hiding the
|
||||||
|
// picker. Whether an option is Box Now comes from the server
|
||||||
|
// (data-box-now, by the method's driver) — the option's value is the
|
||||||
|
// merchant-typed method code, which needn't be "box-now".
|
||||||
|
toggleBoxNowLocker(isBoxNow) {
|
||||||
|
const picker = this.shippingOptionsTarget.querySelector('#bbk-box-now-locker')
|
||||||
|
if (!picker) return
|
||||||
|
|
||||||
|
const controller = this.application.getControllerForElementAndIdentifier(picker, 'bbk-box-now-locker')
|
||||||
|
|
||||||
|
if (isBoxNow) {
|
||||||
|
controller?.show()
|
||||||
|
} else {
|
||||||
|
controller?.hide()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async doSelectShipping(value) {
|
||||||
|
this.saveController?.abort()
|
||||||
|
this.setStatus('saving')
|
||||||
|
|
||||||
|
const body = new FormData()
|
||||||
|
body.append('shipping_option', value)
|
||||||
|
|
||||||
|
try {
|
||||||
|
const response = await fetch(this.selectShippingUrlValue, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: {
|
||||||
|
'X-CSRF-TOKEN': csrfToken(),
|
||||||
|
'X-Requested-With': 'XMLHttpRequest',
|
||||||
|
Accept: 'application/json',
|
||||||
|
},
|
||||||
|
body,
|
||||||
|
})
|
||||||
|
|
||||||
|
if (!response.ok) return this.setStatus('error')
|
||||||
|
|
||||||
|
this.applyResult(await response.json())
|
||||||
|
this.setStatus('saved')
|
||||||
|
} catch {
|
||||||
|
this.setStatus('error')
|
||||||
|
} finally {
|
||||||
|
this.shippingPromise = null
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
applyResult(data) {
|
||||||
|
this.applyErrors(data.errors || {})
|
||||||
|
|
||||||
|
if (data.shippingOptionsHtml != null) {
|
||||||
|
this.shippingOptionsTarget.innerHTML = data.shippingOptionsHtml
|
||||||
|
}
|
||||||
|
|
||||||
|
if (data.summaryHtml != null) {
|
||||||
|
window.dispatchEvent(new CustomEvent('bbk-cart:changed', {
|
||||||
|
detail: { html: data.summaryHtml },
|
||||||
|
}))
|
||||||
|
}
|
||||||
|
|
||||||
|
// bbk-payment is a sibling controller (both sit on
|
||||||
|
// .bbk-checkout-main), not a target of this one — dispatched as an
|
||||||
|
// event rather than reached into directly, same shape as
|
||||||
|
// bbk-cart:changed above.
|
||||||
|
if (data.paymentMethodsHtml != null) {
|
||||||
|
window.dispatchEvent(new CustomEvent('bbk-checkout:payment-methods-changed', {
|
||||||
|
detail: { html: data.paymentMethodsHtml },
|
||||||
|
}))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
applyErrors(errors) {
|
||||||
|
this.element.querySelectorAll('[data-bbk-field-error]').forEach((el) => {
|
||||||
|
const message = errors[el.dataset.bbkFieldError]
|
||||||
|
el.textContent = message || ''
|
||||||
|
el.hidden = !message
|
||||||
|
|
||||||
|
const field = this.element.querySelector(`[name="${el.dataset.bbkFieldError}"]`)
|
||||||
|
field?.classList.toggle('bbk-field-input--error', Boolean(message))
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
setStatus(state) {
|
||||||
|
if (!this.hasStatusTarget) return
|
||||||
|
|
||||||
|
const text = {
|
||||||
|
saving: this.statusSavingValue,
|
||||||
|
saved: this.statusSavedValue,
|
||||||
|
error: this.statusErrorValue,
|
||||||
|
}[state]
|
||||||
|
|
||||||
|
this.statusTarget.textContent = text
|
||||||
|
this.statusTarget.hidden = false
|
||||||
|
this.statusTarget.dataset.state = state
|
||||||
|
|
||||||
|
clearTimeout(this.statusTimer)
|
||||||
|
if (state === 'saved') {
|
||||||
|
this.statusTimer = setTimeout(() => { this.statusTarget.hidden = true }, 2000)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,304 @@
|
|||||||
|
import { Controller } from '@hotwired/stimulus'
|
||||||
|
import { csrfToken } from './csrf'
|
||||||
|
|
||||||
|
const STRIPE_JS = 'https://js.stripe.com/v3/'
|
||||||
|
const POLL_INTERVAL = 1500
|
||||||
|
const POLL_TIMEOUT = 30000
|
||||||
|
|
||||||
|
// The payment step of the checkout page. Sits alongside bbk-checkout-form on
|
||||||
|
// .bbk-checkout-main.
|
||||||
|
//
|
||||||
|
// - selectMethod: radio change -> persist via /payment-method, refresh the
|
||||||
|
// summary (COD fee), mount/unmount the Stripe Payment Element
|
||||||
|
// - placeOrder: the real submit. For Stripe, builds a PaymentMethod client-side
|
||||||
|
// and POSTs it to /place-order, then routes on the JSON result:
|
||||||
|
// { redirect } -> order placed, go to confirmation
|
||||||
|
// { status:'pending', clientSecret } -> 3-D Secure: handleNextAction, then
|
||||||
|
// poll /order-status until the webhook places it
|
||||||
|
// { status:'failed'|'invalid'|'stale', message } -> show inline, re-enable
|
||||||
|
export default class extends Controller {
|
||||||
|
static targets = ['element', 'terms', 'error', 'submit', 'processing', 'processingText', 'methods']
|
||||||
|
|
||||||
|
static values = {
|
||||||
|
selectUrl: String,
|
||||||
|
placeOrderUrl: String,
|
||||||
|
orderStatusUrl: String,
|
||||||
|
stripeKey: String,
|
||||||
|
amount: Number,
|
||||||
|
currency: String,
|
||||||
|
termsRequired: String,
|
||||||
|
chooseMethod: String,
|
||||||
|
genericError: String,
|
||||||
|
processingSlow: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
connect() {
|
||||||
|
this.stripe = null
|
||||||
|
this.elements = null
|
||||||
|
this.paymentElement = null
|
||||||
|
|
||||||
|
this.onSummaryUpdate = (event) => {
|
||||||
|
const total = event.detail?.total
|
||||||
|
if (typeof total === 'number' && this.elements) {
|
||||||
|
this.amountValue = total
|
||||||
|
this.elements.update({ amount: Math.max(total, 1) })
|
||||||
|
}
|
||||||
|
|
||||||
|
// Removing the last line while sitting on the checkout page (via
|
||||||
|
// the order summary's own remove form) must not leave "place
|
||||||
|
// order" clickable with nothing left to charge for — this fires
|
||||||
|
// from both the drawer and the checkout page's own summary
|
||||||
|
// instance, whichever the shopper actually used.
|
||||||
|
const count = event.detail?.count
|
||||||
|
if (typeof count === 'number' && this.hasSubmitTarget) {
|
||||||
|
this.submitTarget.disabled = count === 0
|
||||||
|
}
|
||||||
|
}
|
||||||
|
window.addEventListener('bbk-cart:updated', this.onSummaryUpdate)
|
||||||
|
|
||||||
|
// Fired by bbk-checkout-form after a shipping-option change —
|
||||||
|
// getPaymentMethods() filters by fulfillment type, so the offered
|
||||||
|
// methods (and which one, if any, is still validly selected) can
|
||||||
|
// change without this controller's own element ever reconnecting.
|
||||||
|
this.onPaymentMethodsChanged = (event) => {
|
||||||
|
const html = event.detail?.html
|
||||||
|
if (html == null || !this.hasMethodsTarget) return
|
||||||
|
|
||||||
|
this.methodsTarget.innerHTML = html
|
||||||
|
|
||||||
|
if (!this.selectedIsStripe()) this.unmountStripe()
|
||||||
|
}
|
||||||
|
window.addEventListener('bbk-checkout:payment-methods-changed', this.onPaymentMethodsChanged)
|
||||||
|
|
||||||
|
if (this.selectedIsStripe()) this.mountStripe()
|
||||||
|
}
|
||||||
|
|
||||||
|
disconnect() {
|
||||||
|
window.removeEventListener('bbk-cart:updated', this.onSummaryUpdate)
|
||||||
|
window.removeEventListener('bbk-checkout:payment-methods-changed', this.onPaymentMethodsChanged)
|
||||||
|
this.unmountStripe()
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Method selection ──────────────────────────────────────────────
|
||||||
|
|
||||||
|
async selectMethod(event) {
|
||||||
|
const isStripe = event.target.dataset.paymentDriver === 'stripe'
|
||||||
|
|
||||||
|
try {
|
||||||
|
const response = await fetch(this.selectUrlValue, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: {
|
||||||
|
'X-CSRF-TOKEN': csrfToken(),
|
||||||
|
'X-Requested-With': 'XMLHttpRequest',
|
||||||
|
Accept: 'application/json',
|
||||||
|
},
|
||||||
|
body: new URLSearchParams({ payment_type: event.target.value }),
|
||||||
|
})
|
||||||
|
if (response.ok) {
|
||||||
|
const data = await response.json()
|
||||||
|
if (data.summaryHtml != null) {
|
||||||
|
window.dispatchEvent(new CustomEvent('bbk-cart:changed', { detail: { html: data.summaryHtml } }))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} catch {
|
||||||
|
// summary just won't refresh — non-fatal
|
||||||
|
}
|
||||||
|
|
||||||
|
isStripe ? this.mountStripe() : this.unmountStripe()
|
||||||
|
}
|
||||||
|
|
||||||
|
selectedRadio() {
|
||||||
|
return this.element.querySelector('input[name="payment_type"]:checked')
|
||||||
|
}
|
||||||
|
|
||||||
|
selectedIsStripe() {
|
||||||
|
return this.selectedRadio()?.dataset.paymentDriver === 'stripe'
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Stripe Payment Element ────────────────────────────────────────
|
||||||
|
|
||||||
|
async loadStripe() {
|
||||||
|
if (window.Stripe) return window.Stripe
|
||||||
|
|
||||||
|
await new Promise((resolve, reject) => {
|
||||||
|
const existing = document.querySelector(`script[src="${STRIPE_JS}"]`)
|
||||||
|
if (existing) {
|
||||||
|
existing.addEventListener('load', resolve)
|
||||||
|
existing.addEventListener('error', reject)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
const script = document.createElement('script')
|
||||||
|
script.src = STRIPE_JS
|
||||||
|
script.onload = resolve
|
||||||
|
script.onerror = reject
|
||||||
|
document.head.appendChild(script)
|
||||||
|
})
|
||||||
|
|
||||||
|
return window.Stripe
|
||||||
|
}
|
||||||
|
|
||||||
|
async mountStripe() {
|
||||||
|
if (this.paymentElement || !this.stripeKeyValue) return
|
||||||
|
|
||||||
|
const Stripe = await this.loadStripe()
|
||||||
|
this.stripe = this.stripe || Stripe(this.stripeKeyValue)
|
||||||
|
|
||||||
|
this.elements = this.stripe.elements({
|
||||||
|
mode: 'payment',
|
||||||
|
amount: Math.max(this.amountValue, 1),
|
||||||
|
currency: this.currencyValue,
|
||||||
|
paymentMethodCreation: 'manual',
|
||||||
|
// Card only — matches the server confirming with
|
||||||
|
// automatic_payment_methods.allow_redirects = 'never' (no
|
||||||
|
// return_url in our flow: 3-D Secure resolves in-page via
|
||||||
|
// handleNextAction, never a full-page redirect).
|
||||||
|
paymentMethodTypes: ['card'],
|
||||||
|
})
|
||||||
|
this.paymentElement = this.elements.create('payment')
|
||||||
|
this.paymentElement.mount(this.elementTarget)
|
||||||
|
this.elementTarget.hidden = false
|
||||||
|
}
|
||||||
|
|
||||||
|
unmountStripe() {
|
||||||
|
this.paymentElement?.unmount()
|
||||||
|
this.paymentElement = null
|
||||||
|
this.elements = null
|
||||||
|
|
||||||
|
if (this.hasElementTarget) {
|
||||||
|
this.elementTarget.innerHTML = ''
|
||||||
|
this.elementTarget.hidden = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Place order ──────────────────────────────────────────────────
|
||||||
|
|
||||||
|
// Sibling controller on the same element (.bbk-checkout-main) — used to
|
||||||
|
// flush a pending debounced address autosave before placing the order.
|
||||||
|
get checkoutForm() {
|
||||||
|
return this.application.getControllerForElementAndIdentifier(this.element, 'bbk-checkout-form')
|
||||||
|
}
|
||||||
|
|
||||||
|
async placeOrder() {
|
||||||
|
this.clearError()
|
||||||
|
this.submitTarget.disabled = true
|
||||||
|
|
||||||
|
// A debounced address save (and the shipping-option auto-select that
|
||||||
|
// happens as part of it) might still be pending — make sure the
|
||||||
|
// server has the latest state before we ask it to place the order.
|
||||||
|
await this.checkoutForm?.flush()
|
||||||
|
|
||||||
|
if (!this.termsTarget.checked) {
|
||||||
|
this.submitTarget.disabled = false
|
||||||
|
this.showError(this.termsRequiredValue)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
const radio = this.selectedRadio()
|
||||||
|
if (!radio) {
|
||||||
|
this.submitTarget.disabled = false
|
||||||
|
this.showError(this.chooseMethodValue)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
let paymentMethodId = null
|
||||||
|
if (radio.dataset.paymentDriver === 'stripe') {
|
||||||
|
const { error: submitError } = await this.elements.submit()
|
||||||
|
if (submitError) return this.fail(submitError.message)
|
||||||
|
|
||||||
|
const { error: pmError, paymentMethod } = await this.stripe.createPaymentMethod({ elements: this.elements })
|
||||||
|
if (pmError) return this.fail(pmError.message)
|
||||||
|
paymentMethodId = paymentMethod.id
|
||||||
|
}
|
||||||
|
|
||||||
|
let data
|
||||||
|
try {
|
||||||
|
const response = await fetch(this.placeOrderUrlValue, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: {
|
||||||
|
'X-CSRF-TOKEN': csrfToken(),
|
||||||
|
'X-Requested-With': 'XMLHttpRequest',
|
||||||
|
Accept: 'application/json',
|
||||||
|
},
|
||||||
|
body: new URLSearchParams({
|
||||||
|
payment_type: radio.value,
|
||||||
|
payment_method: paymentMethodId ?? '',
|
||||||
|
terms_accepted: '1',
|
||||||
|
}),
|
||||||
|
})
|
||||||
|
data = await response.json()
|
||||||
|
} catch {
|
||||||
|
return this.fail(this.genericErrorValue)
|
||||||
|
}
|
||||||
|
|
||||||
|
if (data.redirect) {
|
||||||
|
window.location.assign(data.redirect)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
if (data.status === 'pending' && data.clientSecret) {
|
||||||
|
await this.resolvePending(data.clientSecret)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
// Points at the section that actually needs attention, rather than
|
||||||
|
// leaving a generic error and making the shopper hunt for it — e.g. a
|
||||||
|
// region with 2+ shipping methods needs an explicit pick, easy to miss.
|
||||||
|
if (data.field === 'shipping_option') {
|
||||||
|
document.getElementById('bbk-shipping-options')?.scrollIntoView({ block: 'center', behavior: 'smooth' })
|
||||||
|
this.fail(data.message || data.error || this.genericErrorValue, { scroll: false })
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
this.fail(data.message || data.error || this.genericErrorValue)
|
||||||
|
}
|
||||||
|
|
||||||
|
async resolvePending(clientSecret) {
|
||||||
|
this.processingTarget.hidden = false
|
||||||
|
|
||||||
|
const { error } = await this.stripe.handleNextAction({ clientSecret })
|
||||||
|
if (error) {
|
||||||
|
this.processingTarget.hidden = true
|
||||||
|
return this.fail(error.message)
|
||||||
|
}
|
||||||
|
|
||||||
|
// 3-D Secure cleared client-side — the webhook places the order. Poll.
|
||||||
|
const startedAt = Date.now()
|
||||||
|
const tick = async () => {
|
||||||
|
try {
|
||||||
|
const response = await fetch(this.orderStatusUrlValue, { headers: { Accept: 'application/json' } })
|
||||||
|
const data = await response.json()
|
||||||
|
if (data.placed && data.redirect) {
|
||||||
|
window.location.assign(data.redirect)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
} catch {
|
||||||
|
// keep polling
|
||||||
|
}
|
||||||
|
|
||||||
|
if (Date.now() - startedAt > POLL_TIMEOUT) {
|
||||||
|
this.processingTextTarget.textContent = this.processingSlowValue
|
||||||
|
return
|
||||||
|
}
|
||||||
|
setTimeout(tick, POLL_INTERVAL)
|
||||||
|
}
|
||||||
|
tick()
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── helpers ──────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
fail(message, { scroll = true } = {}) {
|
||||||
|
this.showError(message, { scroll })
|
||||||
|
this.submitTarget.disabled = false
|
||||||
|
}
|
||||||
|
|
||||||
|
showError(message, { scroll = true } = {}) {
|
||||||
|
this.errorTarget.textContent = message
|
||||||
|
this.errorTarget.hidden = false
|
||||||
|
if (scroll) this.errorTarget.scrollIntoView({ block: 'center', behavior: 'smooth' })
|
||||||
|
}
|
||||||
|
|
||||||
|
clearError() {
|
||||||
|
this.errorTarget.textContent = ''
|
||||||
|
this.errorTarget.hidden = true
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
// Reads the CSRF token from the standard <meta name="csrf-token"> tag every
|
||||||
|
// boboko host renders in its layout <head>. Kept as its own module so both
|
||||||
|
// checkout controllers share one source.
|
||||||
|
export function csrfToken() {
|
||||||
|
return document.querySelector('meta[name="csrf-token"]')?.getAttribute('content') || ''
|
||||||
|
}
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
import BbkAddToCartController from './bbk-add-to-cart-controller'
|
||||||
|
import BbkBoxNowLockerController from './bbk-box-now-locker-controller'
|
||||||
|
import BbkCartController from './bbk-cart-controller'
|
||||||
|
import BbkCheckoutFormController from './bbk-checkout-form-controller'
|
||||||
|
import BbkPaymentController from './bbk-payment-controller'
|
||||||
|
|
||||||
|
// Registers the checkout module's Stimulus controllers onto the host app's
|
||||||
|
// Stimulus application. Call once from the host's JS entry point:
|
||||||
|
//
|
||||||
|
// import { registerCheckout } from './checkout'
|
||||||
|
// registerCheckout(application)
|
||||||
|
//
|
||||||
|
// When this module moves to boboko-core this file ships with it unchanged;
|
||||||
|
// only that one import line in the host entry point differs per project.
|
||||||
|
export function registerCheckout(application) {
|
||||||
|
console.log('[@boboko/core] checkout module loaded from', import.meta.url, '- test 2')
|
||||||
|
application.register('bbk-add-to-cart', BbkAddToCartController)
|
||||||
|
application.register('bbk-box-now-locker', BbkBoxNowLockerController)
|
||||||
|
application.register('bbk-cart', BbkCartController)
|
||||||
|
application.register('bbk-checkout-form', BbkCheckoutFormController)
|
||||||
|
application.register('bbk-payment', BbkPaymentController)
|
||||||
|
}
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
// Single stable JS entry point for this package. A consuming app imports
|
||||||
|
// from here (`import { … } from "@boboko/core"`), never from a path
|
||||||
|
// reaching into a specific module's internals — so this file's exports can
|
||||||
|
// grow or its modules' internal layout can change without breaking every
|
||||||
|
// consumer's own entry point.
|
||||||
|
//
|
||||||
|
// stoic_embed.js is not re-exported here: per its own docblock, it's a
|
||||||
|
// standalone vendored script meant to be included directly, not imported.
|
||||||
|
export { registerCheckout } from './checkout/index.js'
|
||||||
|
export { registerWishlist } from './wishlist/index.js'
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
import WishlistController from './wishlist-controller'
|
||||||
|
|
||||||
|
// Registers the wishlist module's Stimulus controller onto the host app's
|
||||||
|
// Stimulus application. Call once from the host's JS entry point:
|
||||||
|
//
|
||||||
|
// import { registerWishlist } from '@boboko/core'
|
||||||
|
// registerWishlist(application)
|
||||||
|
export function registerWishlist(application) {
|
||||||
|
application.register('wishlist', WishlistController)
|
||||||
|
}
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
import { Controller } from '@hotwired/stimulus'
|
||||||
|
|
||||||
|
// Heart toggle. Posts the form with fetch and reflects the server's answer on
|
||||||
|
// aria-pressed, which the consuming app's own CSS uses to swap the outline
|
||||||
|
// and filled heart. If the request fails, falls back to a normal form submit.
|
||||||
|
export default class extends Controller {
|
||||||
|
static targets = ['button', 'status']
|
||||||
|
|
||||||
|
static values = {
|
||||||
|
addLabel: String,
|
||||||
|
removeLabel: String,
|
||||||
|
addedMessage: String,
|
||||||
|
removedMessage: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
async toggle(event) {
|
||||||
|
event.preventDefault()
|
||||||
|
|
||||||
|
if (this.busy) return
|
||||||
|
this.busy = true
|
||||||
|
|
||||||
|
try {
|
||||||
|
const response = await fetch(this.element.action, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: { Accept: 'application/json', 'X-Requested-With': 'XMLHttpRequest' },
|
||||||
|
body: new FormData(this.element),
|
||||||
|
})
|
||||||
|
|
||||||
|
if (!response.ok) throw new Error(`Wishlist toggle failed: ${response.status}`)
|
||||||
|
|
||||||
|
const { active } = await response.json()
|
||||||
|
|
||||||
|
this.buttonTarget.setAttribute('aria-pressed', active ? 'true' : 'false')
|
||||||
|
this.buttonTarget.setAttribute('aria-label', active ? this.removeLabelValue : this.addLabelValue)
|
||||||
|
this.statusTarget.textContent = active ? this.addedMessageValue : this.removedMessageValue
|
||||||
|
} catch {
|
||||||
|
this.element.submit()
|
||||||
|
} finally {
|
||||||
|
this.busy = false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
Binary file not shown.
|
After Width: | Height: | Size: 90 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 62 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 4.0 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 15 KiB |
@@ -0,0 +1 @@
|
|||||||
|
<svg xmlns="http://www.w3.org/2000/svg" version="1.1" xmlns:xlink="http://www.w3.org/1999/xlink" width="151" height="150" viewBox="0 0 151 150"><metadata><rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/"><rdf:Description><dc:creator>RealFaviconGenerator</dc:creator><dc:source>https://realfavicongenerator.net</dc:source></rdf:Description></rdf:RDF></metadata><image width="151" height="150" xlink:href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAJcAAACWCAYAAADTwxrcAAAACXBIWXMAAAsTAAALEwEAmpwYAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAOdEVYdFNvZnR3YXJlAEZpZ21hnrGWYwAACYRJREFUeAHtnctuG0cWhv8qJuuRgWSAWU1nMrO28gRuP4FkzANIegJZyAXIStQqQOLA8hOY2ieR/QSmnyDMOgnSuwCJAzLrmF05p6spURSvYpNddfp8gO6UxGb9fc6p21+AoiiKoiiKoiiKoiiKoiiKoiiKoiiKoiiKRAyUxVz2d+j9TvH5o3sZlKVQcY1z2d9FjhQW9+GwS99JMBLVbbLizaCHIV6jhS4JbwDlChXXZT+l93skpkPMFtKydOnvXOD/9zpQGiwuFpXDKX2Wono4onXo40WT02jzxLVZUU3iRfbo3hkaSHPE5YvyUxLWY2wfFtnDpkUxiybAhbrD9zUJi0nof/9Cz+MUDUK+uF72D6hhX8H3/OrFoU0Ce4qGIDstcqTgBg2PLr3yj6QPXcgVV7jCGtEr6zCxApOZFr/p7wcuLIbrwEsIRp64LvsJXdVzxEEquQaTlRZ5uIF7hSEU76vg02MXwpAWubirnyA2HEVaPw4nCjni8mNZdY1jrUsCf2OIQo64Yi+O+cbwk+hikCGub/uHiDEdTuJkRS8Z4jJiGiWVFL3iF5dvjARScNiHECRErgPI4kBKzzF+cQm600t2kMu4prjF5VOiuPEhWPsAAohbXPlWVpNuH5dr5KodAxF3+BR2ijnSyIm95pKXEq/ZReTELq7oG2Amefw3TrziEjjRO0GCyIk5ckkXV/Q0Y/ePUgsqLmVjqLiUjRGvuOTvXo5+V1DskUvuvj9bWDRFTeziyiAXjVw18wPk0kPkxC0uhy5k0pOwEztucVmx4noNAcQtLt9j7EIaBi8gAAkrUUXc5WNkUnZfxy8ui3NIGpIwEGNxGb+4fOF7ARlkEJTmpexblBG9nCz3Zxni4gZxeIa4ycoULwY5E9e+YTLECtdawlwG5YiLG8bgCDFiLHvVdyAMWUtufBc+tvSYAbnIQxBkGu5+12dr8BThw9H2I6nLh2QuFmQb7hjqL07jgtelyRSXr78eImSBeWGJmOaZhdxlzhwRwhTYoBRWB8KRvYZ+JLBwJoJHB0x10ACac2rZt/12rQ6ExpDA3VGTTpNt1nmLbO7hjXm3aQPAafCkKdFqnGaeFHvZPyzNbRNsjkExJcUzBw09+7rZZ1x7kbHtZYrqaLyoRugB6oz3wuLDqPZwN6ENyk4DL/0Rsf69ClRck3j3nN3ijW2MLP596zEOf9Irl9HPB8U6/gYfkq4oiqIoiqIoiqIoihIIWxnn+hVfJNO+/y98nkHZCO6XwpB4minxwHywnW14lYqrj6c7b/GWBiDtnoFLDMyuo4+Y/wR6Dsjosa+HGHb/ic+itw7aNoWQhjTD4E8U4QHgBPPdrnlGoUeDwb3CDqGFHgkuQ8VUIq7f8VVK4jigt30S01oW3vQ3MhJbtwV7dg8nGZSpFILKcUgv2B4JJMW6GJppyHFh/osOKmItcb3B14d0mVVP/I5hOiqym5Tp7piE8Bib8eLnzbkd+nixbjS7k7jKSMVLVlJsBRXZFkQ1Ce9iP1snkq0kLq6pcuSnlPoeY8uU6fLsPXzcQcMgYaUkqueo48gWTpcGR3eJYkuLi4S1S8K6XFSgbxoHc/4+Pj5BQyBhcbSq20OCo9gJRbGV9iIsJa43eMLF+vm6xXpVcBSzsA8lp8myYOdotY9QsGhTBFt6d/hCcf2BrzkNthEYkgVWCot3jW9zrf9yrCCwueL6A0+Oqc4J1tZHqsDcz/geYZ8l2TEfLjZ9mblvkVLhfsjCYrj+ozrwFdWDCYRAUespwj+k9JCe58JtelPFxY1FUeEpIoAFRiP7zyEAilin5VBD+ORok8AO5j3ETv+9/FXdvcIVSWnsLY5GmUEx3AC0ERPUi6Xnncz68S1xlQX8zF8IFY60v+HL0NPJVIoG8j3D2Nih1DHzed8QF6fDEHuGy0LFfRSpfArHqGOAtApoXpPS+dSscUNcAmqX1M93xkMZtaJO6cRpOT11gytx8Xwh4nDjmwuNrdRnNnIX8sie73R2pt0gV+IqJ6Kjh+vFWKJXWQwfQgbHk9GrEFc5TpRCDO4AMSAjao3w68vGKMQ1RC7pIpm0TPOhk0ISpvDauML67wm7SE+KgHE/Fs8vgSS45ziWGi0vpYlxXGsRFmYPIWMDWu1QJWOp0VJKjHLgcRE0L7rLixsRLg8gEYv715/CiRQX43ciBYvM1z2/Lke45roPuQTZgFSXiL2hMVZHWhrfSiCUYK/tLUJO12szmsy2Eov5Mf6BEDHCeom3KW4e2YccKHWh4lI2i4pL2RgqLmVjcG8xg1z+RJhsxcKoRjJ+x4OoYi+UesIZQqQV8UHvy1FoiqZ/8AOEEnBUziCXK3M5SouuB6HkyDMESPniZ5AIm8qVcEEvUlwctYJ2KWRHP4mMXZd9H592IbDAZHdChE0XErHX11UMReTAS4jDhX1NrWCORq6SjFJ+d/RFuRLVdSAITonv4ZOgG6+ou5y46NUd/6IQl7TUGEFK9Ljlva6iwN68nqsRehoTegYhsH8qIsD8j24COdGrM2lteSWud/DOuYzRetOJyq9LSvSyt6/jSlzUIAM2tEXE8M0RS9QaISR6daYZ8t6YuC6dkruIFL45onQZbCFmA+FsWtRibq2KaKHFdoQRFvemE6uNON31PNgbp8DYq36Gjfgtcfk730R1oTGmw0nMhziPMD3OPQRhpuHuGzxhP9RjBA4Ja2BhP5JgulvaKbGLc4LQMeia/+DhvIfMXCxIg5BsiXOBwBlieCLFzblIL7ZosNDLkoxP1Vj0oLkrUan+emwCntjOkR/R5HQHgohAYMXzW+a4lrni4uEJixZfaFBTKZwKJQprRFHge4FlCIvessJilj7753d81Q7BIK482OARCV/sOrQRQdVgDs8olbVXOWV2pVPL2POKGvZ5fRtpzQvqFR5xREWDcD+iTRGjrht7QAI/o8He8xV/bzVxMexCSEU0F/tb60n64/DcSegrHTZJLVFsjePw/K/fERbZXxi2qWjbmEVkWVs943nPpkWrWbifiqOHOYol2BQsqmERrbpYgzuLa8QmRKaiWkwhMn7NTYUOihWJ6vrPVQQbrQ2R7+dwaQvmwap1Gae+IdxLA/eiXF+mLEGZLvep4N67g9AGxYYKh5d8rvUqxfoyVCauSVhsbL5mYBOHPMHUf26zHMPeu3g30whVDYX315AE5510plk18QrYAfX8uuaD4IY6FEVRFEVRFEVRFEVRFEVRFEVRFEVRFEVRFKXJ/A2oC/VTZ0o/1AAAAABJRU5ErkJggg=="></image></svg>
|
||||||
|
After Width: | Height: | Size: 3.8 KiB |
@@ -0,0 +1,17 @@
|
|||||||
|
@extends('emails.layout')
|
||||||
|
|
||||||
|
@section('content')
|
||||||
|
<p style="margin: 0 0 24px 0;">Use the code below to confirm this address as your account's new email.</p>
|
||||||
|
|
||||||
|
<table role="presentation" cellpadding="0" cellspacing="0" border="0" width="100%" style="margin: 0 0 24px 0; background-color: #f7f6f5; border-radius: 8px;">
|
||||||
|
<tr>
|
||||||
|
<td style="padding: 16px 20px; text-align: center; font-size: 28px; font-weight: bold; letter-spacing: 0.25rem;">
|
||||||
|
{{ $code }}
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</table>
|
||||||
|
|
||||||
|
<p style="margin: 0 0 16px 0;">This code expires in 10 minutes.</p>
|
||||||
|
|
||||||
|
<p style="margin: 0;">If you didn't request this change, you can ignore this email — nothing will change.</p>
|
||||||
|
@endsection
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
@extends('emails.layout')
|
||||||
|
|
||||||
|
@section('content')
|
||||||
|
<p style="margin: 0 0 16px 0;">Your account's login email was changed to <strong>{{ $maskedEmail }}</strong>.</p>
|
||||||
|
|
||||||
|
<p style="margin: 0 0 24px 0;">From now on, login codes will be sent to the new address.</p>
|
||||||
|
|
||||||
|
<p style="margin: 0;">If you didn't make this change, please contact us right away.</p>
|
||||||
|
@endsection
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
<p>Hi {{ $name }},</p>
|
<p>Hi {{ $name }},</p>
|
||||||
|
|
||||||
<p>Your login code is:</p>
|
<p>{{ $intro }}</p>
|
||||||
|
|
||||||
<p style="font-size: 2rem; font-weight: bold; letter-spacing: 0.25rem;">{{ $code }}</p>
|
<p style="font-size: 2rem; font-weight: bold; letter-spacing: 0.25rem;">{{ $code }}</p>
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
{{--
|
||||||
|
<x-checkout::add-to-cart :purchasable="$variantId" />
|
||||||
|
|
||||||
|
A self-contained add-to-cart form. Posts the line via bbk-add-to-cart-controller
|
||||||
|
(fetch) and hands the rendered cart body to the drawer over the
|
||||||
|
`bbk-cart:changed` window event.
|
||||||
|
|
||||||
|
Props:
|
||||||
|
purchasable ProductVariant id. Omit to render no hidden id field — the host
|
||||||
|
must then supply [data-bbk-purchasable-input] itself (e.g. a
|
||||||
|
variant picker writing the selected id into it).
|
||||||
|
quantity Integer for the hidden quantity field, or false to omit it
|
||||||
|
(the host then puts its own name="quantity" control in the slot).
|
||||||
|
|
||||||
|
The button and any quantity control come from the slot, so the host owns all
|
||||||
|
appearance. Extra attributes (class, etc.) land on the <form>.
|
||||||
|
--}}
|
||||||
|
@props([
|
||||||
|
'purchasable' => null,
|
||||||
|
'quantity' => 1,
|
||||||
|
'action' => null,
|
||||||
|
])
|
||||||
|
|
||||||
|
<form
|
||||||
|
method="POST"
|
||||||
|
action="{{ $action ?? route('checkout.cart.add', app()->getLocale()) }}"
|
||||||
|
data-controller="bbk-add-to-cart"
|
||||||
|
data-action="bbk-add-to-cart#add"
|
||||||
|
{{ $attributes->class('bbk-add-to-cart') }}
|
||||||
|
>
|
||||||
|
@csrf
|
||||||
|
|
||||||
|
@if (! is_null($purchasable))
|
||||||
|
<input type="hidden" name="purchasable_id" value="{{ $purchasable }}" data-bbk-purchasable-input>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
@if ($quantity !== false)
|
||||||
|
<input type="hidden" name="quantity" value="{{ $quantity }}">
|
||||||
|
@endif
|
||||||
|
|
||||||
|
{{ $slot }}
|
||||||
|
|
||||||
|
<p class="bbk-add-to-cart-error" data-bbk-add-to-cart-target="error" hidden role="alert"></p>
|
||||||
|
</form>
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
{{--
|
||||||
|
Read-only formatted address. $address is any Lunar address model
|
||||||
|
(OrderAddress / CartAddress) — same column names on both.
|
||||||
|
--}}
|
||||||
|
@props(['address'])
|
||||||
|
|
||||||
|
<address class="bbk-address-lines">
|
||||||
|
<span>{{ trim(($address->first_name ?? '') . ' ' . ($address->last_name ?? '')) }}</span>
|
||||||
|
@if ($address->company_name)<span>{{ $address->company_name }}</span>@endif
|
||||||
|
<span>{{ $address->line_one }}</span>
|
||||||
|
@if ($address->line_two)<span>{{ $address->line_two }}</span>@endif
|
||||||
|
<span>{{ trim(($address->postcode ?? '') . ' ' . ($address->city ?? '')) }}</span>
|
||||||
|
@if ($address->state)<span>{{ $address->state }}</span>@endif
|
||||||
|
@if ($address->contact_phone)<span>{{ $address->contact_phone }}</span>@endif
|
||||||
|
</address>
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
{{--
|
||||||
|
<x-checkout::field name="billing_first_name" label="First name" required />
|
||||||
|
|
||||||
|
Generic labelled text input with old-input repopulation and validation
|
||||||
|
error display — the module's own equivalent of a host x-ui.field, used
|
||||||
|
instead of it per the module's independence rule. All styling is .bbk-field*
|
||||||
|
(resources/css/checkout.css); no host classes.
|
||||||
|
--}}
|
||||||
|
@props([
|
||||||
|
'name',
|
||||||
|
'label',
|
||||||
|
'type' => 'text',
|
||||||
|
'value' => null,
|
||||||
|
'required' => false,
|
||||||
|
])
|
||||||
|
|
||||||
|
<div class="bbk-field">
|
||||||
|
<label class="bbk-field-label" for="bbk-{{ $name }}">{{ $label }}</label>
|
||||||
|
<input
|
||||||
|
type="{{ $type }}"
|
||||||
|
name="{{ $name }}"
|
||||||
|
id="bbk-{{ $name }}"
|
||||||
|
value="{{ old($name, $value) }}"
|
||||||
|
@if ($required) required @endif
|
||||||
|
{{ $attributes->class(['bbk-field-input', 'bbk-field-input--error' => $errors->has($name)]) }}
|
||||||
|
>
|
||||||
|
{{-- Always present so bbk-checkout-form can fill it live on an autosave. --}}
|
||||||
|
<p class="bbk-field-error" data-bbk-field-error="{{ $name }}" @unless ($errors->has($name)) hidden @endunless>{{ $errors->first($name) }}</p>
|
||||||
|
</div>
|
||||||
@@ -0,0 +1,52 @@
|
|||||||
|
{{--
|
||||||
|
The state/region + country pair for one address (billing or shipping).
|
||||||
|
|
||||||
|
Single-country store ($storeCountry set): region is a <select> of that
|
||||||
|
country's Lunar states, submitting `->name` (table-rate-shipping resolves
|
||||||
|
zones with State::whereName()), and country is a fixed hidden field + label.
|
||||||
|
Otherwise: free-text region + full country <select>, as before.
|
||||||
|
--}}
|
||||||
|
@props([
|
||||||
|
'prefix',
|
||||||
|
'storeCountry' => null,
|
||||||
|
'regions' => [],
|
||||||
|
'countries' => [],
|
||||||
|
'address' => null,
|
||||||
|
])
|
||||||
|
|
||||||
|
<div class="bbk-field-row">
|
||||||
|
@if ($storeCountry)
|
||||||
|
<x-checkout::select
|
||||||
|
:name="$prefix . '_state'"
|
||||||
|
label="{{ __('checkout.page.state') }}"
|
||||||
|
:options="$regions"
|
||||||
|
value-field="name"
|
||||||
|
translation-group="states"
|
||||||
|
:value="$address?->state"
|
||||||
|
placeholder="{{ __('checkout.page.state_placeholder') }}"
|
||||||
|
required
|
||||||
|
/>
|
||||||
|
|
||||||
|
<div class="bbk-field">
|
||||||
|
<span class="bbk-field-label">{{ __('checkout.page.country') }}</span>
|
||||||
|
<p class="bbk-field-static">
|
||||||
|
{{ \Illuminate\Support\Facades\Lang::has("core::countries.{$storeCountry->name}")
|
||||||
|
? __("core::countries.{$storeCountry->name}")
|
||||||
|
: $storeCountry->name }}
|
||||||
|
</p>
|
||||||
|
<input type="hidden" name="{{ $prefix }}_country_id" value="{{ $storeCountry->id }}">
|
||||||
|
</div>
|
||||||
|
@else
|
||||||
|
<x-checkout::field :name="$prefix . '_state'" label="{{ __('checkout.page.state') }}" :value="$address?->state" />
|
||||||
|
|
||||||
|
<x-checkout::select
|
||||||
|
:name="$prefix . '_country_id'"
|
||||||
|
label="{{ __('checkout.page.country') }}"
|
||||||
|
:options="$countries"
|
||||||
|
translation-group="countries"
|
||||||
|
:value="$address?->country_id"
|
||||||
|
placeholder="{{ __('checkout.page.country_placeholder') }}"
|
||||||
|
required
|
||||||
|
/>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
@@ -0,0 +1,62 @@
|
|||||||
|
{{--
|
||||||
|
<x-checkout::select name="billing_country_id" label="Country" :options="$countries" required />
|
||||||
|
<x-checkout::select name="shipping_state" label="Region" :options="$regions" value-field="name" translation-group="states" required />
|
||||||
|
|
||||||
|
`options` is an iterable of models/objects; `label` is always read from
|
||||||
|
`->name`, the submitted value from `->{$valueField}` (default `id`, but e.g.
|
||||||
|
`name` for Lunar states — table-rate-shipping resolves those with
|
||||||
|
State::whereName(), so the address must carry the exact name string).
|
||||||
|
|
||||||
|
`translationGroup` (optional, e.g. "countries"/"states") looks the raw
|
||||||
|
`->name` up in boboko-core's `core::{group}.{name}` lang file (see
|
||||||
|
boboko-core's lang/el/countries.php, lang/el/states.php) for the
|
||||||
|
DISPLAYED label only — the submitted `value` is always the untranslated
|
||||||
|
`->{$valueField}`, since table-rate-shipping/Lunar's Country lookups key
|
||||||
|
off the original English name. Falls back to the raw name when no
|
||||||
|
translation exists for the current locale (e.g. English, or a country
|
||||||
|
outside the covered set).
|
||||||
|
--}}
|
||||||
|
@props([
|
||||||
|
'name',
|
||||||
|
'label',
|
||||||
|
'options' => [],
|
||||||
|
'value' => null,
|
||||||
|
'placeholder' => null,
|
||||||
|
'required' => false,
|
||||||
|
'valueField' => 'id',
|
||||||
|
'translationGroup' => null,
|
||||||
|
])
|
||||||
|
|
||||||
|
@php
|
||||||
|
$optionLabel = function ($option) use ($translationGroup) {
|
||||||
|
if (! $translationGroup) {
|
||||||
|
return $option->name;
|
||||||
|
}
|
||||||
|
|
||||||
|
$key = "core::{$translationGroup}.{$option->name}";
|
||||||
|
|
||||||
|
return \Illuminate\Support\Facades\Lang::has($key) ? __($key) : $option->name;
|
||||||
|
};
|
||||||
|
@endphp
|
||||||
|
|
||||||
|
@php($selected = old($name, $value))
|
||||||
|
|
||||||
|
<div class="bbk-field">
|
||||||
|
<label class="bbk-field-label" for="bbk-{{ $name }}">{{ $label }}</label>
|
||||||
|
<select
|
||||||
|
name="{{ $name }}"
|
||||||
|
id="bbk-{{ $name }}"
|
||||||
|
@if ($required) required @endif
|
||||||
|
{{ $attributes->class(['bbk-field-input', 'bbk-field-input--error' => $errors->has($name)]) }}
|
||||||
|
>
|
||||||
|
@if ($placeholder)
|
||||||
|
<option value="" @selected(! $selected)>{{ $placeholder }}</option>
|
||||||
|
@endif
|
||||||
|
@foreach ($options as $option)
|
||||||
|
<option value="{{ $option->{$valueField} }}" @selected((string) $selected === (string) $option->{$valueField})>
|
||||||
|
{{ $optionLabel($option) }}
|
||||||
|
</option>
|
||||||
|
@endforeach
|
||||||
|
</select>
|
||||||
|
<p class="bbk-field-error" data-bbk-field-error="{{ $name }}" @unless ($errors->has($name)) hidden @endunless>{{ $errors->first($name) }}</p>
|
||||||
|
</div>
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
@props([
|
||||||
|
'name',
|
||||||
|
'label',
|
||||||
|
'value' => null,
|
||||||
|
'required' => false,
|
||||||
|
])
|
||||||
|
|
||||||
|
<div class="bbk-field">
|
||||||
|
<label class="bbk-field-label" for="bbk-{{ $name }}">{{ $label }}</label>
|
||||||
|
<textarea
|
||||||
|
name="{{ $name }}"
|
||||||
|
id="bbk-{{ $name }}"
|
||||||
|
rows="3"
|
||||||
|
@if ($required) required @endif
|
||||||
|
{{ $attributes->class(['bbk-field-input', 'bbk-field-input--error' => $errors->has($name)]) }}
|
||||||
|
>{{ old($name, $value) }}</textarea>
|
||||||
|
<p class="bbk-field-error" data-bbk-field-error="{{ $name }}" @unless ($errors->has($name)) hidden @endunless>{{ $errors->first($name) }}</p>
|
||||||
|
</div>
|
||||||
@@ -0,0 +1,162 @@
|
|||||||
|
{{--
|
||||||
|
Order confirmation. Reached only via a session flash of the placed order id
|
||||||
|
(CheckoutController::confirmation) — not deep-linkable. $order is a
|
||||||
|
Lunar\Models\Order with lines + shipping/billing addresses eager-loaded.
|
||||||
|
$bankTransferInstructions is already-sanitized HTML from
|
||||||
|
StoreDetailsService::bankTransferInstructionsFor(), or null unless this
|
||||||
|
is a bank transfer order with instructions filled in for this locale.
|
||||||
|
--}}
|
||||||
|
@extends('layouts.app')
|
||||||
|
|
||||||
|
@section('title', __('checkout.page.confirmation_title') . ' — ' . config('app.name'))
|
||||||
|
|
||||||
|
@section('content')
|
||||||
|
<div class="bbk-confirmation">
|
||||||
|
<h1 class="bbk-confirmation-heading">{{ __('checkout.page.confirmation_heading') }}</h1>
|
||||||
|
|
||||||
|
<div class="bbk-notice bbk-notice--info">
|
||||||
|
<svg class="bbk-notice-icon" aria-hidden="true" focusable="false" viewBox="0 0 20 20" width="20" height="20">
|
||||||
|
<circle cx="10" cy="10" r="8.25" fill="none" stroke="currentColor" stroke-width="1.5"/>
|
||||||
|
<path d="M10 9v5" stroke="currentColor" stroke-width="1.5" stroke-linecap="round"/>
|
||||||
|
<circle cx="10" cy="6.25" r="1" fill="currentColor"/>
|
||||||
|
</svg>
|
||||||
|
<p class="bbk-notice-text">{{ __('checkout.page.confirmation_email_note') }}</p>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<dl class="bbk-confirmation-meta">
|
||||||
|
<div class="bbk-confirmation-meta-row">
|
||||||
|
<dt>{{ __('checkout.page.confirmation_order_number') }}</dt>
|
||||||
|
<dd>#{{ \Modules\Core\Order\Support\OrderReferenceDisplay::resolve($order) }}</dd>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if ($order->billingAddress?->contact_email)
|
||||||
|
<div class="bbk-confirmation-meta-row">
|
||||||
|
<dt>{{ __('checkout.page.email_label') }}</dt>
|
||||||
|
<dd>{{ $order->billingAddress->contact_email }}</dd>
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
@if ($paymentMethodName)
|
||||||
|
<div class="bbk-confirmation-meta-row">
|
||||||
|
<dt>{{ __('checkout.page.payment_heading') }}</dt>
|
||||||
|
<dd>{{ $paymentMethodName }}</dd>
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
@if ($shippingLine = $order->lines->firstWhere('type', 'shipping'))
|
||||||
|
<div class="bbk-confirmation-meta-row">
|
||||||
|
<dt>{{ __('checkout.page.shipping_method_heading') }}</dt>
|
||||||
|
<dd>{{ $shippingLine->description }}</dd>
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
</dl>
|
||||||
|
|
||||||
|
{{-- Guests: logging in with the order's email attaches it to an account
|
||||||
|
(boboko-core's Modules\Core\Customer\Listeners\ClaimGuestOrdersOnLogin),
|
||||||
|
so it shows in their history. --}}
|
||||||
|
@guest
|
||||||
|
@if ($loginRoute = config('checkout.login_route'))
|
||||||
|
<p class="bbk-checkout-note">
|
||||||
|
{{ __('checkout.page.confirmation_login_hint') }}
|
||||||
|
<a href="{{ route($loginRoute) }}">{{ __('checkout.page.login_link') }}</a>
|
||||||
|
</p>
|
||||||
|
@endif
|
||||||
|
@endguest
|
||||||
|
|
||||||
|
<section class="bbk-confirmation-section" aria-labelledby="bbk-confirmation-summary-heading">
|
||||||
|
<h2 class="bbk-confirmation-section-heading" id="bbk-confirmation-summary-heading">
|
||||||
|
{{ __('checkout.page.order_summary_heading') }}
|
||||||
|
</h2>
|
||||||
|
|
||||||
|
<ul class="bbk-confirmation-lines">
|
||||||
|
@foreach ($order->lines->where('type', '!=', 'shipping') as $line)
|
||||||
|
<li class="bbk-confirmation-line">
|
||||||
|
<div class="bbk-cart-item-media">
|
||||||
|
{{-- alt="" — the description is right beside it. --}}
|
||||||
|
@if ($thumb = $line->purchasable?->getThumbnailImage())
|
||||||
|
<img src="{{ $thumb }}" alt="" width="72" height="72" loading="lazy">
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="bbk-confirmation-line-detail">
|
||||||
|
<p class="bbk-confirmation-line-name">
|
||||||
|
{{ $line->description }}
|
||||||
|
<span class="bbk-confirmation-line-qty">
|
||||||
|
<span aria-hidden="true">× {{ $line->quantity }}</span>
|
||||||
|
<span class="bbk-visually-hidden">— {{ __('checkout.cart.quantity') }}: {{ $line->quantity }}</span>
|
||||||
|
</span>
|
||||||
|
</p>
|
||||||
|
|
||||||
|
@if ($line->option)
|
||||||
|
<p class="bbk-cart-item-variant">{{ $line->option }}</p>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
@include('checkout::partials.line-custom-fields', ['line' => $line])
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<p class="bbk-confirmation-line-total">
|
||||||
|
<span class="bbk-visually-hidden">{{ __('checkout.cart.total') }}:</span>
|
||||||
|
{{ $line->sub_total?->formatted() }}
|
||||||
|
</p>
|
||||||
|
</li>
|
||||||
|
@endforeach
|
||||||
|
</ul>
|
||||||
|
|
||||||
|
<div class="bbk-cart-summary">
|
||||||
|
<div class="bbk-cart-summary-row">
|
||||||
|
<span>{{ __('checkout.cart.subtotal') }}</span>
|
||||||
|
<span>{{ $order->sub_total?->formatted() }}</span>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if ($order->discount_total?->value > 0)
|
||||||
|
<div class="bbk-cart-summary-row bbk-cart-summary-row--discount">
|
||||||
|
<span>{{ __('checkout.cart.discount') }}</span>
|
||||||
|
<span>−{{ $order->discount_total->formatted() }}</span>
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
<div class="bbk-cart-summary-row">
|
||||||
|
<span>{{ __('checkout.cart.shipping') }}</span>
|
||||||
|
<span>{{ $order->shipping_total?->formatted() }}</span>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if ($order->tax_total?->value > 0)
|
||||||
|
<div class="bbk-cart-summary-row">
|
||||||
|
<span>{{ __('checkout.cart.tax') }}</span>
|
||||||
|
<span>{{ $order->tax_total->formatted() }}</span>
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
<div class="bbk-cart-summary-row bbk-cart-summary-row--total">
|
||||||
|
<span>{{ __('checkout.cart.total') }}</span>
|
||||||
|
<span>{{ $order->total?->formatted() }}</span>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
@if ($order->shippingAddress || $order->billingAddress)
|
||||||
|
<div class="bbk-confirmation-section bbk-confirmation-addresses">
|
||||||
|
@if ($order->shippingAddress)
|
||||||
|
<section class="bbk-confirmation-address" aria-labelledby="bbk-confirmation-shipping-heading">
|
||||||
|
<h2 class="bbk-confirmation-address-heading" id="bbk-confirmation-shipping-heading">{{ __('checkout.page.confirmation_shipping_to') }}</h2>
|
||||||
|
<x-checkout::address-lines :address="$order->shippingAddress" />
|
||||||
|
</section>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
@if ($order->billingAddress)
|
||||||
|
<section class="bbk-confirmation-address" aria-labelledby="bbk-confirmation-billing-heading">
|
||||||
|
<h2 class="bbk-confirmation-address-heading" id="bbk-confirmation-billing-heading">{{ __('checkout.page.confirmation_billing') }}</h2>
|
||||||
|
<x-checkout::address-lines :address="$order->billingAddress" />
|
||||||
|
</section>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
@if ($bankTransferInstructions)
|
||||||
|
<section class="bbk-confirmation-section bbk-confirmation-bank-transfer" aria-labelledby="bbk-confirmation-bank-transfer-heading">
|
||||||
|
<h2 class="bbk-confirmation-bank-transfer-heading" id="bbk-confirmation-bank-transfer-heading">{{ __('checkout.page.confirmation_bank_transfer_heading') }}</h2>
|
||||||
|
<div class="bbk-confirmation-bank-transfer-body">{!! $bankTransferInstructions !!}</div>
|
||||||
|
</section>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
@endsection
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
{{--
|
||||||
|
Slide-in cart drawer. Rendered once, globally, from the app layout
|
||||||
|
(@include('checkout::drawer')). Structure only — all styling lives in
|
||||||
|
resources/css/checkout.css under @layer bbk-checkout; the host restyles the
|
||||||
|
.bbk-* classes from its own stylesheet. No host components, no Tailwind.
|
||||||
|
--}}
|
||||||
|
<div class="bbk-cart" data-controller="bbk-cart" hidden>
|
||||||
|
<div class="bbk-cart-backdrop" data-action="click->bbk-cart#close"></div>
|
||||||
|
|
||||||
|
<aside
|
||||||
|
class="bbk-cart-panel"
|
||||||
|
role="dialog"
|
||||||
|
aria-modal="true"
|
||||||
|
aria-labelledby="bbk-cart-heading"
|
||||||
|
data-bbk-cart-target="panel"
|
||||||
|
>
|
||||||
|
<header class="bbk-cart-panel-header">
|
||||||
|
{{-- tabindex=-1: the controller moves focus here on open, and back
|
||||||
|
here when the focused line is removed from under the user. --}}
|
||||||
|
<h2 class="bbk-cart-heading" id="bbk-cart-heading" tabindex="-1" data-bbk-cart-target="heading">{{ __('checkout.cart.title') }}</h2>
|
||||||
|
<button
|
||||||
|
type="button"
|
||||||
|
class="bbk-cart-dismiss"
|
||||||
|
data-action="bbk-cart#close"
|
||||||
|
aria-label="{{ __('checkout.cart.close') }}"
|
||||||
|
>×</button>
|
||||||
|
</header>
|
||||||
|
|
||||||
|
@include('checkout::partials.cart-error')
|
||||||
|
|
||||||
|
{{-- A short announcement after each update, rather than aria-live on
|
||||||
|
the body itself, which re-read the whole cart on every change. --}}
|
||||||
|
<p
|
||||||
|
class="bbk-visually-hidden"
|
||||||
|
role="status"
|
||||||
|
data-bbk-cart-target="status"
|
||||||
|
data-bbk-cart-message="{{ __('checkout.cart.updated') }}"
|
||||||
|
></p>
|
||||||
|
|
||||||
|
<div class="bbk-cart-panel-body" data-bbk-cart-target="body">
|
||||||
|
@include('checkout::partials.cart-body')
|
||||||
|
</div>
|
||||||
|
</aside>
|
||||||
|
</div>
|
||||||
@@ -0,0 +1,285 @@
|
|||||||
|
{{--
|
||||||
|
The checkout page. Two columns: left is contact + billing + shipping +
|
||||||
|
shipping method, right is the order summary (the same cart-body partial the
|
||||||
|
drawer uses, minus its own "Checkout" CTA — see .bbk-checkout-summary in
|
||||||
|
checkout.css). Stops short of payment for this slice — see
|
||||||
|
CheckoutController's class docblock.
|
||||||
|
|
||||||
|
$cart, $lines, $billingAddress, $shippingAddress, $shippingOptions,
|
||||||
|
$countries come from CheckoutController::show().
|
||||||
|
--}}
|
||||||
|
@extends('layouts.app')
|
||||||
|
|
||||||
|
@section('title', __('checkout.page.title') . ' — ' . config('app.name'))
|
||||||
|
|
||||||
|
@section('content')
|
||||||
|
<div class="bbk-checkout-page">
|
||||||
|
<h1 class="bbk-checkout-heading">{{ __('checkout.page.title') }}</h1>
|
||||||
|
|
||||||
|
<div class="bbk-checkout">
|
||||||
|
<div
|
||||||
|
class="bbk-checkout-main"
|
||||||
|
data-controller="bbk-checkout-form bbk-payment"
|
||||||
|
data-action="input->bbk-checkout-form#scheduleSave"
|
||||||
|
data-bbk-checkout-form-save-url-value="{{ route('checkout.address.save', app()->getLocale()) }}"
|
||||||
|
data-bbk-checkout-form-select-shipping-url-value="{{ route('checkout.shipping-option.select', app()->getLocale()) }}"
|
||||||
|
data-bbk-checkout-form-status-saving-value="{{ __('checkout.page.saving') }}"
|
||||||
|
data-bbk-checkout-form-status-saved-value="{{ __('checkout.page.saved') }}"
|
||||||
|
data-bbk-checkout-form-status-error-value="{{ __('checkout.page.save_error') }}"
|
||||||
|
data-bbk-payment-select-url-value="{{ route('checkout.payment-method.select', app()->getLocale()) }}"
|
||||||
|
data-bbk-payment-place-order-url-value="{{ route('checkout.place-order', app()->getLocale()) }}"
|
||||||
|
data-bbk-payment-order-status-url-value="{{ route('checkout.order-status', app()->getLocale()) }}"
|
||||||
|
data-bbk-payment-stripe-key-value="{{ config('services.stripe.public_key') }}"
|
||||||
|
data-bbk-payment-amount-value="{{ $cart?->total?->value ?? 0 }}"
|
||||||
|
data-bbk-payment-currency-value="{{ strtolower($cart?->total?->currency?->code ?? 'eur') }}"
|
||||||
|
data-bbk-payment-terms-required-value="{{ __('checkout.page.terms_required') }}"
|
||||||
|
data-bbk-payment-choose-method-value="{{ __('checkout.page.choose_payment_method') }}"
|
||||||
|
data-bbk-payment-generic-error-value="{{ __('checkout.page.payment_failed') }}"
|
||||||
|
data-bbk-payment-processing-slow-value="{{ __('checkout.page.payment_processing_slow') }}"
|
||||||
|
>
|
||||||
|
|
||||||
|
{{-- Contact. Logged in: the order email is the account's (forced
|
||||||
|
server-side in saveAddress()), so there's no field. Guests type
|
||||||
|
their email, plus a login link when config('checkout.login_route')
|
||||||
|
is set; the storefront's login page sends them back here and Lunar
|
||||||
|
merges the guest cart into the account. --}}
|
||||||
|
@php($loginRoute = config('checkout.login_route'))
|
||||||
|
<section class="bbk-checkout-section">
|
||||||
|
@auth
|
||||||
|
<p class="bbk-checkout-logged-in">
|
||||||
|
{{ __('checkout.page.logged_in_as') }} <strong>{{ auth()->user()->email }}</strong>
|
||||||
|
</p>
|
||||||
|
@else
|
||||||
|
@if ($loginRoute)
|
||||||
|
<p class="bbk-checkout-login-prompt">
|
||||||
|
{{ __('checkout.page.login_prompt') }}
|
||||||
|
<a href="{{ route($loginRoute, ['redirect' => route('checkout.show', app()->getLocale(), false)]) }}">{{ __('checkout.page.login_link') }}</a>
|
||||||
|
</p>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
<x-checkout::field
|
||||||
|
name="contact_email"
|
||||||
|
label="{{ __('checkout.page.email_label') }}"
|
||||||
|
type="email"
|
||||||
|
:value="$shippingAddress?->contact_email ?? $billingAddress?->contact_email"
|
||||||
|
required
|
||||||
|
form="bbk-address-form"
|
||||||
|
/>
|
||||||
|
@endauth
|
||||||
|
|
||||||
|
{{-- Abandoned-cart-recovery opt-in. Optional, unticked, never
|
||||||
|
required — direct marketing under ePrivacy (GR L. 3471/2006
|
||||||
|
art. 11), so it needs an explicit opt-in and checkout can't be
|
||||||
|
gated on it. Narrow scope by design (boboko-core's
|
||||||
|
setRecoveryConsent) — a general newsletter opt-in, if wanted,
|
||||||
|
is a separate checkbox. --}}
|
||||||
|
<label class="bbk-checkbox bbk-checkbox--stacked">
|
||||||
|
<input
|
||||||
|
type="checkbox"
|
||||||
|
name="recovery_consent"
|
||||||
|
value="1"
|
||||||
|
form="bbk-address-form"
|
||||||
|
{{ old('recovery_consent', data_get($cart, 'meta.recovery_consent')) ? 'checked' : '' }}
|
||||||
|
>
|
||||||
|
{{ __('checkout.page.recovery_consent') }}
|
||||||
|
</label>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
{{-- Autosaves — no submit button. Any `change` inside .bbk-checkout-main
|
||||||
|
(this form, plus the contact email/consent which sit outside it but
|
||||||
|
link via form="bbk-address-form") is debounced and POSTed as the whole
|
||||||
|
form; the shipping-method radios are excluded in scheduleSave(). --}}
|
||||||
|
<form
|
||||||
|
id="bbk-address-form"
|
||||||
|
method="POST"
|
||||||
|
action="{{ route('checkout.address.save', app()->getLocale()) }}"
|
||||||
|
data-bbk-checkout-form-target="form"
|
||||||
|
>
|
||||||
|
@csrf
|
||||||
|
|
||||||
|
{{-- Billing --}}
|
||||||
|
<section class="bbk-checkout-section">
|
||||||
|
<h2 class="bbk-checkout-section-heading">{{ __('checkout.page.billing_heading') }}</h2>
|
||||||
|
|
||||||
|
<div class="bbk-field-row">
|
||||||
|
<x-checkout::field name="billing_first_name" label="{{ __('checkout.page.first_name') }}" :value="$billingAddress?->first_name" required />
|
||||||
|
<x-checkout::field name="billing_last_name" label="{{ __('checkout.page.last_name') }}" :value="$billingAddress?->last_name" required />
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- Company/ΑΦΜ only when an invoice is wanted. Revealed by CSS
|
||||||
|
(:has on the checkbox), saved/cleared by saveAddress(), and
|
||||||
|
required at place-order. --}}
|
||||||
|
<div class="bbk-invoice">
|
||||||
|
<label class="bbk-checkbox">
|
||||||
|
<input
|
||||||
|
type="checkbox"
|
||||||
|
name="wants_invoice"
|
||||||
|
value="1"
|
||||||
|
aria-controls="bbk-invoice-fields"
|
||||||
|
@checked($wantsInvoice)
|
||||||
|
>
|
||||||
|
{{ __('checkout.page.wants_invoice') }}
|
||||||
|
</label>
|
||||||
|
|
||||||
|
<div class="bbk-field-row bbk-invoice-fields" id="bbk-invoice-fields">
|
||||||
|
<x-checkout::field name="billing_company_name" label="{{ __('checkout.page.company_name') }}" :value="$billingAddress?->company_name" />
|
||||||
|
<x-checkout::field name="billing_tax_identifier" label="{{ __('checkout.page.tax_identifier') }}" :value="$billingAddress?->tax_identifier" />
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<x-checkout::field name="billing_line_one" label="{{ __('checkout.page.address_line_one') }}" :value="$billingAddress?->line_one" required />
|
||||||
|
|
||||||
|
<div class="bbk-field-row">
|
||||||
|
<x-checkout::field name="billing_city" label="{{ __('checkout.page.city') }}" :value="$billingAddress?->city" required />
|
||||||
|
<x-checkout::field name="billing_postcode" label="{{ __('checkout.page.postcode') }}" :value="$billingAddress?->postcode" required />
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<x-checkout::region-country
|
||||||
|
prefix="billing"
|
||||||
|
:store-country="$storeCountry"
|
||||||
|
:regions="$regions"
|
||||||
|
:countries="$countries"
|
||||||
|
:address="$billingAddress"
|
||||||
|
/>
|
||||||
|
|
||||||
|
<x-checkout::field name="billing_contact_phone" label="{{ __('checkout.page.phone') }}" type="tel" :value="$billingAddress?->contact_phone" />
|
||||||
|
</section>
|
||||||
|
|
||||||
|
{{-- Shipping --}}
|
||||||
|
<section class="bbk-checkout-section">
|
||||||
|
<h2 class="bbk-checkout-section-heading">{{ __('checkout.page.shipping_heading') }}</h2>
|
||||||
|
|
||||||
|
<label class="bbk-checkbox">
|
||||||
|
<input
|
||||||
|
type="checkbox"
|
||||||
|
name="same_as_billing"
|
||||||
|
value="1"
|
||||||
|
data-bbk-checkout-form-target="sameAsBilling"
|
||||||
|
data-action="bbk-checkout-form#toggleSameAsBilling"
|
||||||
|
@checked($shipToBilling)
|
||||||
|
>
|
||||||
|
{{ __('checkout.page.same_as_billing') }}
|
||||||
|
</label>
|
||||||
|
|
||||||
|
<div class="bbk-checkout-shipping-fields" data-bbk-checkout-form-target="shippingFields">
|
||||||
|
<div class="bbk-field-row">
|
||||||
|
<x-checkout::field name="shipping_first_name" label="{{ __('checkout.page.first_name') }}" :value="$shippingAddress?->first_name" required />
|
||||||
|
<x-checkout::field name="shipping_last_name" label="{{ __('checkout.page.last_name') }}" :value="$shippingAddress?->last_name" required />
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<x-checkout::field name="shipping_line_one" label="{{ __('checkout.page.address_line_one') }}" :value="$shippingAddress?->line_one" required />
|
||||||
|
|
||||||
|
<div class="bbk-field-row">
|
||||||
|
<x-checkout::field name="shipping_city" label="{{ __('checkout.page.city') }}" :value="$shippingAddress?->city" required />
|
||||||
|
<x-checkout::field name="shipping_postcode" label="{{ __('checkout.page.postcode') }}" :value="$shippingAddress?->postcode" required />
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<x-checkout::region-country
|
||||||
|
prefix="shipping"
|
||||||
|
:store-country="$storeCountry"
|
||||||
|
:regions="$regions"
|
||||||
|
:countries="$countries"
|
||||||
|
:address="$shippingAddress"
|
||||||
|
/>
|
||||||
|
|
||||||
|
<x-checkout::field name="shipping_contact_phone" label="{{ __('checkout.page.phone') }}" type="tel" :value="$shippingAddress?->contact_phone" />
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<x-checkout::textarea
|
||||||
|
name="shipping_delivery_instructions"
|
||||||
|
label="{{ __('checkout.page.delivery_instructions') }}"
|
||||||
|
:value="$shippingAddress?->delivery_instructions"
|
||||||
|
/>
|
||||||
|
</section>
|
||||||
|
</form>
|
||||||
|
|
||||||
|
<p
|
||||||
|
class="bbk-checkout-status"
|
||||||
|
data-bbk-checkout-form-target="status"
|
||||||
|
role="status"
|
||||||
|
aria-live="polite"
|
||||||
|
hidden
|
||||||
|
></p>
|
||||||
|
|
||||||
|
{{-- Shipping method — resolves from the saved shipping address;
|
||||||
|
re-rendered as a fragment by bbk-checkout-form after each
|
||||||
|
autosave / option change. --}}
|
||||||
|
<section class="bbk-checkout-section">
|
||||||
|
<h2 class="bbk-checkout-section-heading">{{ __('checkout.page.shipping_method_heading') }}</h2>
|
||||||
|
|
||||||
|
<div id="bbk-shipping-options" data-bbk-checkout-form-target="shippingOptions">
|
||||||
|
@include('checkout::partials.shipping-options', [
|
||||||
|
'shippingAddress' => $shippingAddress,
|
||||||
|
'shippingOptions' => $shippingOptions,
|
||||||
|
])
|
||||||
|
</div>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
{{-- Payment --}}
|
||||||
|
<section class="bbk-checkout-section">
|
||||||
|
<h2 class="bbk-checkout-section-heading">{{ __('checkout.page.payment_heading') }}</h2>
|
||||||
|
|
||||||
|
<div id="bbk-payment-methods" data-bbk-payment-target="methods">
|
||||||
|
@include('checkout::partials.payment-methods', [
|
||||||
|
'paymentMethods' => $paymentMethods,
|
||||||
|
'cart' => $cart,
|
||||||
|
])
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- Stripe Payment Element mounts here when a Stripe method is picked. --}}
|
||||||
|
<div class="bbk-payment-element" data-bbk-payment-target="element" hidden></div>
|
||||||
|
|
||||||
|
<label class="bbk-checkbox bbk-checkbox--stacked">
|
||||||
|
<input type="checkbox" data-bbk-payment-target="terms">
|
||||||
|
{!! __('checkout.page.terms_accept', [
|
||||||
|
'terms' => route('legal.terms', app()->getLocale()),
|
||||||
|
'privacy' => route('legal.privacy', app()->getLocale()),
|
||||||
|
]) !!}
|
||||||
|
</label>
|
||||||
|
|
||||||
|
<p class="bbk-checkout-withdrawal">
|
||||||
|
{!! __('checkout.page.withdrawal_notice', [
|
||||||
|
'link' => route('legal.shipping-returns', app()->getLocale()),
|
||||||
|
]) !!}
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<p class="bbk-checkout-error" data-bbk-payment-target="error" role="alert" hidden></p>
|
||||||
|
|
||||||
|
<button
|
||||||
|
type="button"
|
||||||
|
class="bbk-checkout-continue"
|
||||||
|
data-bbk-payment-target="submit"
|
||||||
|
data-action="bbk-payment#placeOrder"
|
||||||
|
@disabled($lines->isEmpty())
|
||||||
|
>
|
||||||
|
{{ __('checkout.page.place_order') }}
|
||||||
|
</button>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
{{-- Fixed overlay while a payment is confirming (3-D Secure / webhook
|
||||||
|
poll). Inside .bbk-checkout-main so bbk-payment can target it. --}}
|
||||||
|
<div class="bbk-checkout-processing" data-bbk-payment-target="processing" hidden>
|
||||||
|
<span class="bbk-spinner" aria-hidden="true"></span>
|
||||||
|
<p data-bbk-payment-target="processingText">{{ __('checkout.page.payment_processing') }}</p>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<aside class="bbk-checkout-aside">
|
||||||
|
<div class="bbk-checkout-summary" data-controller="bbk-cart">
|
||||||
|
<h2 class="bbk-checkout-summary-heading" tabindex="-1" data-bbk-cart-target="heading">{{ __('checkout.page.order_summary_heading') }}</h2>
|
||||||
|
@include('checkout::partials.cart-error')
|
||||||
|
<p
|
||||||
|
class="bbk-visually-hidden"
|
||||||
|
role="status"
|
||||||
|
data-bbk-cart-target="status"
|
||||||
|
data-bbk-cart-message="{{ __('checkout.cart.updated') }}"
|
||||||
|
></p>
|
||||||
|
<div data-bbk-cart-target="body">
|
||||||
|
@include('checkout::partials.cart-body')
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</aside>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
@endsection
|
||||||
@@ -0,0 +1,121 @@
|
|||||||
|
{{--
|
||||||
|
Server-rendered cart contents. Rendered inline on first page load inside
|
||||||
|
checkout/drawer.blade.php, and re-fetched + swapped into the drawer by
|
||||||
|
bbk-cart-controller after every mutation. $cart / $lines come from the view
|
||||||
|
composer in CheckoutModuleServiceProvider.
|
||||||
|
|
||||||
|
The data-bbk-cart-* attributes on the root are the module's read API for the
|
||||||
|
host (e.g. the header bag-icon count) — bbk-cart-controller reads them after
|
||||||
|
each swap and re-emits them on the `bbk-cart:updated` window event.
|
||||||
|
--}}
|
||||||
|
@php($count = $lines->sum('quantity'))
|
||||||
|
|
||||||
|
{{-- @dump($lines) --}}
|
||||||
|
|
||||||
|
<div
|
||||||
|
class="bbk-cart-content"
|
||||||
|
data-bbk-cart-count="{{ $count }}"
|
||||||
|
data-bbk-cart-total="{{ $cart?->total?->value ?? 0 }}"
|
||||||
|
>
|
||||||
|
@if ($lines->isEmpty())
|
||||||
|
<p class="bbk-cart-empty">{{ __('checkout.cart.empty') }}</p>
|
||||||
|
@else
|
||||||
|
<ul class="bbk-cart-items">
|
||||||
|
@each('checkout::partials.cart-line', $lines, 'line')
|
||||||
|
</ul>
|
||||||
|
|
||||||
|
<div class="bbk-cart-summary">
|
||||||
|
<div class="bbk-cart-coupon">
|
||||||
|
@if ($cart?->coupon_code)
|
||||||
|
<div class="bbk-cart-coupon-applied">
|
||||||
|
<span class="bbk-cart-coupon-code">{{ $cart->coupon_code }}</span>
|
||||||
|
|
||||||
|
<form
|
||||||
|
method="POST"
|
||||||
|
action="{{ route('checkout.cart.coupon.remove', app()->getLocale()) }}"
|
||||||
|
data-action="submit->bbk-cart#submit"
|
||||||
|
>
|
||||||
|
@csrf
|
||||||
|
@method('DELETE')
|
||||||
|
<button type="submit" class="bbk-cart-coupon-remove">
|
||||||
|
{{ __('checkout.cart.coupon_remove') }}
|
||||||
|
</button>
|
||||||
|
</form>
|
||||||
|
</div>
|
||||||
|
@else
|
||||||
|
<form
|
||||||
|
class="bbk-cart-coupon-form"
|
||||||
|
method="POST"
|
||||||
|
action="{{ route('checkout.cart.coupon.apply', app()->getLocale()) }}"
|
||||||
|
data-action="submit->bbk-cart#submit"
|
||||||
|
>
|
||||||
|
@csrf
|
||||||
|
<label class="bbk-visually-hidden" for="bbk-coupon-code">
|
||||||
|
{{ __('checkout.cart.coupon_label') }}
|
||||||
|
</label>
|
||||||
|
<input
|
||||||
|
type="text"
|
||||||
|
name="code"
|
||||||
|
id="bbk-coupon-code"
|
||||||
|
class="bbk-cart-coupon-input"
|
||||||
|
placeholder="{{ __('checkout.cart.coupon_placeholder') }}"
|
||||||
|
autocomplete="off"
|
||||||
|
required
|
||||||
|
>
|
||||||
|
<button type="submit" class="bbk-cart-coupon-submit">
|
||||||
|
{{ __('checkout.cart.coupon_apply') }}
|
||||||
|
</button>
|
||||||
|
</form>
|
||||||
|
|
||||||
|
@if ($couponError ?? false)
|
||||||
|
<p class="bbk-cart-coupon-error" role="alert">{{ __('checkout.cart.coupon_invalid') }}</p>
|
||||||
|
@endif
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="bbk-cart-summary-row">
|
||||||
|
<span>{{ __('checkout.cart.subtotal') }}</span>
|
||||||
|
<span>{{ $cart?->subTotal?->formatted() }}</span>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if ($cart?->discountTotal?->value > 0)
|
||||||
|
<div class="bbk-cart-summary-row bbk-cart-summary-row--discount">
|
||||||
|
<span>{{ __('checkout.cart.discount') }}</span>
|
||||||
|
<span>−{{ $cart->discountTotal->formatted() }}</span>
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
{{-- Shipping + tax appear once the shopper has a shipping address
|
||||||
|
(i.e. they're on the checkout page). In the drawer, where no
|
||||||
|
address is set yet, only subtotal + total show. --}}
|
||||||
|
@if ($cart?->shippingAddress)
|
||||||
|
<div class="bbk-cart-summary-row">
|
||||||
|
<span>{{ __('checkout.cart.shipping') }}</span>
|
||||||
|
@if ($cart->shippingAddress->shipping_option)
|
||||||
|
<span>{{ $cart->shippingTotal?->formatted() }}</span>
|
||||||
|
@else
|
||||||
|
<span class="bbk-cart-summary-pending">{{ __('checkout.cart.shipping_pending') }}</span>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
@if ($cart?->taxTotal?->value > 0)
|
||||||
|
<div class="bbk-cart-summary-row">
|
||||||
|
<span>{{ __('checkout.cart.tax') }}</span>
|
||||||
|
<span>{{ $cart->taxTotal->formatted() }}</span>
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
{{-- Always shown — equals subtotal with nothing else applied,
|
||||||
|
diverges as discount / shipping / tax come in. --}}
|
||||||
|
<div class="bbk-cart-summary-row bbk-cart-summary-row--total">
|
||||||
|
<span>{{ __('checkout.cart.total') }}</span>
|
||||||
|
<span>{{ $cart?->total?->formatted() }}</span>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<a class="bbk-cart-checkout" href="{{ route('checkout.show', app()->getLocale()) }}">
|
||||||
|
{{ __('checkout.cart.checkout') }}
|
||||||
|
</a>
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
{{--
|
||||||
|
Shared error slot for any host wrapping cart-body in a bbk-cart controller
|
||||||
|
instance (the drawer, and the checkout page's own order summary) —
|
||||||
|
bbk-cart-controller.js#showError() writes into whichever one is present.
|
||||||
|
Without this element in a given host, a rejected quantity update (e.g.
|
||||||
|
over stock) still gets rejected server-side, but the shopper never sees
|
||||||
|
why.
|
||||||
|
--}}
|
||||||
|
<p class="bbk-cart-error" data-bbk-cart-target="error" hidden role="alert"></p>
|
||||||
@@ -0,0 +1,119 @@
|
|||||||
|
{{--
|
||||||
|
One cart line. $line is a Lunar\Models\CartLine (iteration var set by
|
||||||
|
@each in cart-body). The two forms post through bbk-cart-controller
|
||||||
|
(fetch + method spoofing) and the response re-renders cart-body.
|
||||||
|
--}}
|
||||||
|
@php
|
||||||
|
$variant = $line->purchasable;
|
||||||
|
$product = $variant?->product;
|
||||||
|
$name = $product?->translateAttribute('name') ?? $variant?->sku ?? '—';
|
||||||
|
// The variant's own image (falls back to the product's thumbnail
|
||||||
|
// internally — see ProductVariant::getThumbnail()) — the specific option
|
||||||
|
// the shopper picked, not just the product in general.
|
||||||
|
$thumb = $variant?->getThumbnailImage() ?: null;
|
||||||
|
$variantLabel = $variant?->getOption();
|
||||||
|
// Not routed through checkout::'s own locale-explicit convention — this
|
||||||
|
// is a storefront route, so it follows the storefront's own (implicit
|
||||||
|
// locale) call shape, same as App\Catalog\ProductCard. Carries the
|
||||||
|
// variant id along so the product page can restore the same option the
|
||||||
|
// shopper actually has in their cart, not just default to the first one
|
||||||
|
// (see product-form-controller.js reading ?variant= on connect()).
|
||||||
|
$productUrl = $product ? route('product.show', ['id' => $product->id, 'variant' => $variant?->id]) : null;
|
||||||
|
@endphp
|
||||||
|
|
||||||
|
<li class="bbk-cart-item" data-bbk-line-id="{{ $line->id }}">
|
||||||
|
<div class="bbk-cart-item-media">
|
||||||
|
@if ($thumb)
|
||||||
|
{{-- Decorative duplicate of the title link below — hidden from AT
|
||||||
|
and skipped by keyboard so the product isn't announced twice. --}}
|
||||||
|
@if ($productUrl)
|
||||||
|
<a href="{{ $productUrl }}" aria-hidden="true" tabindex="-1">
|
||||||
|
<img src="{{ $thumb }}" alt="" width="72" height="72" loading="lazy">
|
||||||
|
</a>
|
||||||
|
@else
|
||||||
|
<img src="{{ $thumb }}" alt="" width="72" height="72" loading="lazy">
|
||||||
|
@endif
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="bbk-cart-item-detail">
|
||||||
|
<div class="bbk-cart-item-head">
|
||||||
|
@if ($productUrl)
|
||||||
|
<a href="{{ $productUrl }}" class="bbk-cart-item-title" id="bbk-cart-item-title-{{ $line->id }}">{{ $name }}</a>
|
||||||
|
@else
|
||||||
|
<p class="bbk-cart-item-title" id="bbk-cart-item-title-{{ $line->id }}">{{ $name }}</p>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
<form
|
||||||
|
class="bbk-cart-item-remove-form"
|
||||||
|
method="POST"
|
||||||
|
action="{{ route('checkout.cart.remove', ['locale' => app()->getLocale(), 'line' => $line->id]) }}"
|
||||||
|
data-action="submit->bbk-cart#submit"
|
||||||
|
>
|
||||||
|
@csrf
|
||||||
|
@method('DELETE')
|
||||||
|
{{-- Named "Remove", described by the product title, so AT
|
||||||
|
hears which line it removes rather than a bare "Remove". --}}
|
||||||
|
<button
|
||||||
|
type="submit"
|
||||||
|
class="bbk-cart-item-remove"
|
||||||
|
aria-label="{{ __('checkout.cart.remove') }}"
|
||||||
|
aria-describedby="bbk-cart-item-title-{{ $line->id }}"
|
||||||
|
><span aria-hidden="true">×</span></button>
|
||||||
|
</form>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if ($variantLabel)
|
||||||
|
<p class="bbk-cart-item-variant">{{ $variantLabel }}</p>
|
||||||
|
@endif
|
||||||
|
@include('checkout::partials.line-custom-fields', ['line' => $line])
|
||||||
|
<p class="bbk-cart-item-unit">{{ $line->unitPrice?->formatted() }}</p>
|
||||||
|
|
||||||
|
<div class="bbk-cart-item-foot">
|
||||||
|
{{-- role=group + the title as its name: entering the stepper
|
||||||
|
announces which product's quantity is being changed. --}}
|
||||||
|
<form
|
||||||
|
class="bbk-cart-qty"
|
||||||
|
method="POST"
|
||||||
|
action="{{ route('checkout.cart.update', ['locale' => app()->getLocale(), 'line' => $line->id]) }}"
|
||||||
|
role="group"
|
||||||
|
aria-labelledby="bbk-cart-item-title-{{ $line->id }}"
|
||||||
|
>
|
||||||
|
@csrf
|
||||||
|
@method('PATCH')
|
||||||
|
<button
|
||||||
|
type="button"
|
||||||
|
class="bbk-cart-qty-btn"
|
||||||
|
data-action="bbk-cart#step"
|
||||||
|
data-bbk-cart-dir-param="-1"
|
||||||
|
aria-label="{{ __('checkout.cart.decrease') }}"
|
||||||
|
><span aria-hidden="true">−</span></button>
|
||||||
|
|
||||||
|
<input
|
||||||
|
type="number"
|
||||||
|
name="quantity"
|
||||||
|
value="{{ $line->quantity }}"
|
||||||
|
min="0"
|
||||||
|
inputmode="numeric"
|
||||||
|
class="bbk-cart-qty-input"
|
||||||
|
data-action="change->bbk-cart#submit"
|
||||||
|
data-bbk-cart-confirmed-quantity="{{ $line->quantity }}"
|
||||||
|
aria-label="{{ __('checkout.cart.quantity') }}"
|
||||||
|
>
|
||||||
|
|
||||||
|
<button
|
||||||
|
type="button"
|
||||||
|
class="bbk-cart-qty-btn"
|
||||||
|
data-action="bbk-cart#step"
|
||||||
|
data-bbk-cart-dir-param="1"
|
||||||
|
aria-label="{{ __('checkout.cart.increase') }}"
|
||||||
|
><span aria-hidden="true">+</span></button>
|
||||||
|
</form>
|
||||||
|
|
||||||
|
<p class="bbk-cart-item-total">
|
||||||
|
<span class="bbk-visually-hidden">{{ __('checkout.cart.total') }}:</span>
|
||||||
|
{{ $line->subTotal?->formatted() }}
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</li>
|
||||||
@@ -0,0 +1,51 @@
|
|||||||
|
{{--
|
||||||
|
@include('checkout::partials.line-custom-fields', ['line' => $line])
|
||||||
|
|
||||||
|
A cart or order line's custom-field answers (meta.custom_fields, written by
|
||||||
|
Cart\Http\Controllers\CartController::customFieldsMeta()). A file answer
|
||||||
|
only carries a File id (Modules\Core\File\Models\File is the source of
|
||||||
|
truth for name/mime/disk/path — never duplicated into meta), resolved
|
||||||
|
here and linked through the signed download route (files.download),
|
||||||
|
minted fresh on every render, with a thumbnail when the browser can
|
||||||
|
display the format (HEIC can't be shown outside Safari, so it gets the
|
||||||
|
name only).
|
||||||
|
--}}
|
||||||
|
@php
|
||||||
|
$fields = $line->meta['custom_fields'] ?? [];
|
||||||
|
$previewable = ['image/jpeg', 'image/png', 'image/webp', 'image/gif'];
|
||||||
|
@endphp
|
||||||
|
|
||||||
|
@if (! empty($fields))
|
||||||
|
<dl class="bbk-line-fields">
|
||||||
|
@foreach ($fields as $field)
|
||||||
|
<div class="bbk-line-field">
|
||||||
|
@if ($field['type'] === 'file')
|
||||||
|
<dt>{{ $field['label'] }}:</dt>
|
||||||
|
<dd>
|
||||||
|
@php
|
||||||
|
$file = \Modules\Core\File\Models\File::find($field['file_id'] ?? null);
|
||||||
|
@endphp
|
||||||
|
@if ($file)
|
||||||
|
@php
|
||||||
|
$fileUrl = \Illuminate\Support\Facades\URL::temporarySignedRoute(
|
||||||
|
'files.download',
|
||||||
|
now()->addHours(2),
|
||||||
|
['file' => $file->id],
|
||||||
|
);
|
||||||
|
@endphp
|
||||||
|
<a href="{{ $fileUrl }}" class="bbk-line-field-file" target="_blank" rel="noopener">
|
||||||
|
@if (in_array($file->mime, $previewable, true))
|
||||||
|
<img src="{{ $fileUrl }}" alt="" width="40" height="40" loading="lazy">
|
||||||
|
@endif
|
||||||
|
<span>{{ $file->original_name }}</span>
|
||||||
|
</a>
|
||||||
|
|
||||||
|
@endif
|
||||||
|
</dd>
|
||||||
|
@else
|
||||||
|
<span>{{ $field['label'] }}: {{ $field['value'] }}</span>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
@endforeach
|
||||||
|
</dl>
|
||||||
|
@endif
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
{{--
|
||||||
|
Payment method radios. $paymentMethods is Collection<Modules\Core\Payment\
|
||||||
|
Models\PaymentMethod> from CheckoutService::getPaymentMethods() (already
|
||||||
|
filtered to enabled + driver-resolves + isConfigured()). Selecting one
|
||||||
|
autosaves via bbk-payment#selectMethod; `data-payment-driver` tells the
|
||||||
|
controller whether to mount the Stripe Element.
|
||||||
|
|
||||||
|
$paymentMethods, $cart come from the page / controller.
|
||||||
|
--}}
|
||||||
|
@php($selected = $cart?->meta['payment_method'] ?? null)
|
||||||
|
|
||||||
|
@if ($paymentMethods->isEmpty())
|
||||||
|
<p class="bbk-checkout-note">{{ __('checkout.page.payment_method_none') }}</p>
|
||||||
|
@else
|
||||||
|
<div class="bbk-checkout-payment-options">
|
||||||
|
@foreach ($paymentMethods as $method)
|
||||||
|
<label class="bbk-checkout-payment-option">
|
||||||
|
<input
|
||||||
|
type="radio"
|
||||||
|
name="payment_type"
|
||||||
|
value="{{ $method->type }}"
|
||||||
|
data-payment-driver="{{ $method->driver }}"
|
||||||
|
@checked($selected === $method->type)
|
||||||
|
data-action="change->bbk-payment#selectMethod"
|
||||||
|
>
|
||||||
|
<span class="bbk-checkout-payment-option-name">{{ $method->translate('name') }}</span>
|
||||||
|
</label>
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
@@ -0,0 +1,109 @@
|
|||||||
|
{{--
|
||||||
|
Shipping methods for the checkout page. Rendered inline by page.blade.php on
|
||||||
|
load, and re-rendered as a fragment by CheckoutController after every
|
||||||
|
address save / option change (bbk-checkout-form swaps it in). Radios
|
||||||
|
autosave via bbk-checkout-form#selectShipping — no submit button. A single
|
||||||
|
resolved option is auto-selected server-side and shown as a fixed line.
|
||||||
|
|
||||||
|
$shippingAddress, $shippingOptions come from the controller / page scope.
|
||||||
|
--}}
|
||||||
|
@php($selected = $shippingAddress?->shipping_option)
|
||||||
|
{{-- Box Now by the method's driver, not its (merchant-typed) code --}}
|
||||||
|
@php($boxNowCodes = \Modules\Core\Shipping\Support\BoxNowShipping::codes())
|
||||||
|
|
||||||
|
{{-- Rate resolution needs country (always Greece here) + postcode; until a
|
||||||
|
postcode is saved there's nothing to quote against yet. --}}
|
||||||
|
@if (! $shippingAddress?->postcode)
|
||||||
|
<p class="bbk-checkout-note">{{ __('checkout.page.shipping_method_empty') }}</p>
|
||||||
|
@elseif ($shippingOptions->isEmpty())
|
||||||
|
<p class="bbk-checkout-note">{{ __('checkout.page.shipping_method_none') }}</p>
|
||||||
|
@elseif ($shippingOptions->count() === 1)
|
||||||
|
@php($only = $shippingOptions->first())
|
||||||
|
<div class="bbk-checkout-shipping-confirmed">
|
||||||
|
<span class="bbk-checkout-shipping-option-detail">
|
||||||
|
<span class="bbk-checkout-shipping-option-name">{{ $only->name }}</span>
|
||||||
|
@if ($only->description)
|
||||||
|
<span class="bbk-checkout-shipping-option-description">{{ strip_tags($only->description) }}</span>
|
||||||
|
@endif
|
||||||
|
</span>
|
||||||
|
<span class="bbk-checkout-shipping-option-price">{{ $only->price->formatted() }}</span>
|
||||||
|
</div>
|
||||||
|
@else
|
||||||
|
<div class="bbk-checkout-shipping-options">
|
||||||
|
@foreach ($shippingOptions as $option)
|
||||||
|
<label class="bbk-checkout-shipping-option">
|
||||||
|
<input
|
||||||
|
type="radio"
|
||||||
|
name="shipping_option"
|
||||||
|
value="{{ $option->identifier }}"
|
||||||
|
data-box-now="{{ in_array($option->identifier, $boxNowCodes, true) ? 'true' : 'false' }}"
|
||||||
|
@checked($selected === $option->identifier)
|
||||||
|
data-action="change->bbk-checkout-form#selectShipping"
|
||||||
|
>
|
||||||
|
<span class="bbk-checkout-shipping-option-detail">
|
||||||
|
<span class="bbk-checkout-shipping-option-name">{{ $option->name }}</span>
|
||||||
|
@if ($option->description)
|
||||||
|
<span class="bbk-checkout-shipping-option-description">{{ strip_tags($option->description) }}</span>
|
||||||
|
@endif
|
||||||
|
</span>
|
||||||
|
<span class="bbk-checkout-shipping-option-price">{{ $option->price->formatted() }}</span>
|
||||||
|
</label>
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
{{--
|
||||||
|
Dummy Box Now locker picker — a Leaflet map standing in for Box Now's own
|
||||||
|
Destination Map JS widget, which only talks to their Production API (not
|
||||||
|
Stage/sandbox — see their Partner API manual §4.1), making it useless
|
||||||
|
for local/staging development. Backed by the same GET /destinations data
|
||||||
|
(including lat/lng) via CheckoutController::boxNowLockers(). Only shown
|
||||||
|
once the "box-now" shipping option is selected (bbk-checkout-form
|
||||||
|
toggles [hidden] on shipping-option change; see bbk-box-now-locker
|
||||||
|
Stimulus controller). Persists the choice via a separate autosave POST
|
||||||
|
(checkout.box-now.locker.select) rather than piggybacking on the
|
||||||
|
shipping-option field, since the two are independent pieces of state
|
||||||
|
(method vs. destination) that CheckoutService models as two calls
|
||||||
|
(selectShippingOption() / selectBoxNowLocker()).
|
||||||
|
--}}
|
||||||
|
<div
|
||||||
|
id="bbk-box-now-locker"
|
||||||
|
class="bbk-checkout-box-now-locker"
|
||||||
|
data-controller="bbk-box-now-locker"
|
||||||
|
data-bbk-box-now-locker-lockers-url-value="{{ route('checkout.box-now.lockers', app()->getLocale()) }}"
|
||||||
|
data-bbk-box-now-locker-select-url-value="{{ route('checkout.box-now.locker.select', app()->getLocale()) }}"
|
||||||
|
data-bbk-box-now-locker-loading-value="{{ __('checkout.page.box_now_locker_loading') }}"
|
||||||
|
data-bbk-box-now-locker-select-label-value="{{ __('checkout.page.box_now_locker_select') }}"
|
||||||
|
data-bbk-box-now-locker-selected-label-value="{{ __('checkout.page.box_now_locker_selected') }}"
|
||||||
|
data-bbk-box-now-locker-no-results-value="{{ __('checkout.page.box_now_locker_no_results') }}"
|
||||||
|
@if (! in_array($selected, $boxNowCodes, true)) hidden @endif
|
||||||
|
>
|
||||||
|
<p class="bbk-checkout-box-now-locker-label">
|
||||||
|
{{ __('checkout.page.box_now_locker_label') }}
|
||||||
|
</p>
|
||||||
|
<input
|
||||||
|
type="search"
|
||||||
|
class="bbk-checkout-box-now-locker-search"
|
||||||
|
placeholder="{{ __('checkout.page.box_now_locker_search') }}"
|
||||||
|
data-bbk-box-now-locker-target="search"
|
||||||
|
data-action="input->bbk-box-now-locker#search"
|
||||||
|
autocomplete="off"
|
||||||
|
>
|
||||||
|
<div
|
||||||
|
id="bbk-box-now-locker-map"
|
||||||
|
class="bbk-checkout-box-now-locker-map"
|
||||||
|
data-bbk-box-now-locker-target="map"
|
||||||
|
></div>
|
||||||
|
<p
|
||||||
|
class="bbk-checkout-box-now-locker-chosen"
|
||||||
|
data-bbk-box-now-locker-target="chosen"
|
||||||
|
hidden
|
||||||
|
></p>
|
||||||
|
<p
|
||||||
|
class="bbk-checkout-status"
|
||||||
|
data-bbk-box-now-locker-target="status"
|
||||||
|
role="status"
|
||||||
|
aria-live="polite"
|
||||||
|
hidden
|
||||||
|
></p>
|
||||||
|
</div>
|
||||||
@@ -0,0 +1,113 @@
|
|||||||
|
{{--
|
||||||
|
Copy of lunarphp/lunar's resources/views/livewire/components/activity-log-feed.blade.php
|
||||||
|
(the order page's Timeline), overriding it via View::prependNamespace('lunarpanel')
|
||||||
|
in CoreServiceProvider. The only changes: the day heading and each entry's time are
|
||||||
|
shown in core.display_timezone instead of UTC (Lunar formats them by hand, so
|
||||||
|
Filament's display timezone doesn't reach them). Re-copy it if Lunar changes the
|
||||||
|
original. Lunar still groups entries by UTC day, so an entry just after local
|
||||||
|
midnight can sit under the previous day's heading.
|
||||||
|
--}}
|
||||||
|
<div class="px-2 pb-4 scroll-mt-32" id="lunar-panel-timeline">
|
||||||
|
<div class="relative flex items-end gap-4 mt-4">
|
||||||
|
<div class="shrink-0">
|
||||||
|
<div>
|
||||||
|
<img src="{{ $this->userAvatar }}"
|
||||||
|
class="inline-block w-8 h-8 rounded-full" />
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<form class="w-full"
|
||||||
|
wire:submit.prevent="addComment">
|
||||||
|
|
||||||
|
{{ $this->form }}
|
||||||
|
|
||||||
|
<div class="absolute right-0 mt-2">
|
||||||
|
{{ $this->addCommentAction }}
|
||||||
|
</div>
|
||||||
|
</form>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="relative pt-8 -ml-[5px] z-10 pointer-events-none">
|
||||||
|
<span class="absolute inset-y-0 left-5 w-[2px] bg-gray-200 dark:bg-gray-600 rounded-full"></span>
|
||||||
|
|
||||||
|
<div class="flow-root">
|
||||||
|
<ul class="-my-8 divide-y-2 divide-gray-200 dark:divide-gray-600"
|
||||||
|
role="list">
|
||||||
|
@foreach ($this->activityLog as $log)
|
||||||
|
<li class="relative py-8 ml-5">
|
||||||
|
<p class="ml-8 font-bold text-gray-950 dark:text-gray-300">
|
||||||
|
{{ $log['items']->first()['log']->created_at->inDisplayTimezone()->format('F jS, Y') }}
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<ul class="mt-4 space-y-6 pointer-events-auto">
|
||||||
|
@foreach ($log['items'] as $item)
|
||||||
|
@php
|
||||||
|
$logUserName = $item['log']->causer ? ($item['log']->causer->fullName ?: $item['log']->causer->name) : null;
|
||||||
|
@endphp
|
||||||
|
|
||||||
|
<li class="relative pl-8">
|
||||||
|
<div @class([
|
||||||
|
'absolute top-[2px]',
|
||||||
|
'-left-[calc(0.75rem_-_1px)]' => $item['log']->causer,
|
||||||
|
'-left-[calc(0.5rem_-_1px)]' => !$item['log']->causer,
|
||||||
|
])>
|
||||||
|
@if ($email = $item['log']->causer?->email)
|
||||||
|
<img
|
||||||
|
src="{{ $this->getAvatarUrl($email) }}"
|
||||||
|
class="w-6 h-6 rounded-full ring-4 ring-gray-200 dark:ring-gray-600"
|
||||||
|
alt="{{ $logUserName }}"
|
||||||
|
/>
|
||||||
|
@else
|
||||||
|
<span @class([
|
||||||
|
'absolute w-4 h-4 rounded-full ring-4',
|
||||||
|
match($item['log']->description){
|
||||||
|
'created' => 'bg-sky-500 ring-sky-100 dark:ring-sky-800',
|
||||||
|
'updated' => 'bg-teal-500 ring-teal-100 dark:ring-teal-800',
|
||||||
|
'status-update' => 'bg-purple-500 ring-purple-100 dark:ring-purple-800',
|
||||||
|
default => 'bg-gray-300 ring-gray-200 dark:ring-gray-600',
|
||||||
|
},
|
||||||
|
])>
|
||||||
|
</span>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div @class([
|
||||||
|
'flex justify-between',
|
||||||
|
'pt-[5px]' => $item['log']->causer,
|
||||||
|
'pt-[1px]' => !$item['log']->causer,
|
||||||
|
])>
|
||||||
|
<div>
|
||||||
|
<div class="text-xs font-medium text-gray-500 dark:text-gray-400">
|
||||||
|
@if (!$item['log']->causer)
|
||||||
|
{{ __('lunarpanel::components.activity-log.system') }}
|
||||||
|
@else
|
||||||
|
{{ $logUserName }}
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if (count($item['renderers']))
|
||||||
|
<div class="mt-2 text-sm font-medium text-gray-700 dark:text-gray-200">
|
||||||
|
@foreach ($item['renderers'] as $class)
|
||||||
|
{{ $class->render($item['log']) }}
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<time class="flex-shrink-0 ml-4 text-xs mt-0.5 text-gray-500 dark:text-gray-400 font-medium">
|
||||||
|
{{ $item['log']->created_at->inDisplayTimezone()->format('h:ia') }}
|
||||||
|
</time>
|
||||||
|
</div>
|
||||||
|
</li>
|
||||||
|
@endforeach
|
||||||
|
</ul>
|
||||||
|
</li>
|
||||||
|
@endforeach
|
||||||
|
</ul>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="pt-4">
|
||||||
|
{{ $this->activityLog->links('lunarpanel::components.activity-log.timeline-paginator.index', data: ['scrollTo' => '#lunar-panel-timeline']) }}
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
@@ -77,7 +77,7 @@
|
|||||||
class="w-4"
|
class="w-4"
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
<span>{{ $transaction->created_at->format('jS F Y h:ia') }}</span>
|
<span>{{ $transaction->created_at->inDisplayTimezone()->format('jS F Y h:ia') }}</span>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="flex space-x-2">
|
<div class="flex space-x-2">
|
||||||
|
|||||||
@@ -1,3 +1,12 @@
|
|||||||
<p>Hi,</p>
|
<p>Hi,</p>
|
||||||
|
|
||||||
<p>Your order <strong>{{ $reference }}</strong> is on its way.</p>
|
<p>Your order <strong>{{ $reference }}</strong> is on its way.</p>
|
||||||
|
|
||||||
|
@foreach ($shipments ?? [] as $shipment)
|
||||||
|
<p>
|
||||||
|
{{ $shipment->carrierLabel() }}: <strong>{{ $shipment->tracking_reference }}</strong>
|
||||||
|
@if ($url = $shipment->trackingUrl())
|
||||||
|
— <a href="{{ $url }}">Track your parcel</a>
|
||||||
|
@endif
|
||||||
|
</p>
|
||||||
|
@endforeach
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
<div class="flex flex-col gap-1">
|
||||||
|
<div class="flex flex-wrap items-center gap-2">
|
||||||
|
@svg('heroicon-m-truck', ['class' => 'w-4 text-gray-500'])
|
||||||
|
<span>{{ $carrier }} {{ $trackingReference }}@if ($isReturn) (return)@endif</span>
|
||||||
|
<x-filament::badge :color="$statusColor">{{ $statusLabel }}</x-filament::badge>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if ($details || $occurredAt)
|
||||||
|
<div class="text-sm text-gray-500">
|
||||||
|
{{ $details }}@if ($details && $occurredAt) · @endif{{ $occurredAt?->format('Y-m-d H:i') }}
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
@@ -0,0 +1,119 @@
|
|||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="el">
|
||||||
|
<head>
|
||||||
|
<meta charset="utf-8">
|
||||||
|
<style>
|
||||||
|
{{--
|
||||||
|
An extra parcel of a multi-parcel send on A4 — ELTA's own client
|
||||||
|
prints these with a separate, smaller report (ELTA_PEL.sydetaE1.rdlc,
|
||||||
|
via epexergasia.cs::print_child()) instead of the full 3-copy
|
||||||
|
voucher: one block with the parcel's own voucher/barcode, its
|
||||||
|
piece ("002/002"), the master voucher and, for cash on delivery,
|
||||||
|
only the warning (the amount is collected on the master). Every
|
||||||
|
position below is that report's own Top/Left in cm, on the page.
|
||||||
|
Classes are ch-* so they don't collide with label-a4's when a
|
||||||
|
batch PDF holds both.
|
||||||
|
--}}
|
||||||
|
@page { margin: 0; size: 21cm 29.7cm; }
|
||||||
|
html, body { margin: 0; padding: 0; }
|
||||||
|
body { font-family: 'DejaVu Sans', sans-serif; font-size: 6.5pt; color: #000; }
|
||||||
|
|
||||||
|
.ch-page { position: relative; width: 21cm; height: 29.7cm; }
|
||||||
|
.ch-page > * { position: absolute; box-sizing: border-box; }
|
||||||
|
.ch-box { border: 1px solid #000; }
|
||||||
|
.ch-box > * { position: absolute; }
|
||||||
|
.ch-label { font-size: 6pt; }
|
||||||
|
.ch-val { font-size: 8pt; font-weight: bold; }
|
||||||
|
.ch-line { font-size: 9pt; white-space: nowrap; overflow: hidden; }
|
||||||
|
.ch-center { text-align: center; left: 0; width: 100%; }
|
||||||
|
.ch-logo img { width: 100%; }
|
||||||
|
.ch-company { font-size: 5pt; line-height: 1.25; white-space: nowrap; }
|
||||||
|
.ch-company-name { font-weight: bold; font-size: 5.5pt; }
|
||||||
|
.ch-barcode img { width: 100%; height: 0.62cm; }
|
||||||
|
</style>
|
||||||
|
</head>
|
||||||
|
<body>
|
||||||
|
<div class="page ch-page">
|
||||||
|
{{-- Image22 (logo) + image4 (ELTA details bitmap, reproduced as text) --}}
|
||||||
|
<div class="ch-logo" style="top:9.07cm;left:0.41cm;width:1.33cm;height:1.28cm;">
|
||||||
|
<img src="{{ $eltaLogo }}" alt="ELTA Courier">
|
||||||
|
</div>
|
||||||
|
{{-- Πλήρηστοιχεία_red1 --}}
|
||||||
|
<div class="ch-company" style="top:9.07cm;left:1.95cm;width:3.38cm;">
|
||||||
|
@include('core::shipping.carriers.elta.partials._elta-details', ['style' => 'font-size:3.5pt;line-height:1.15;'])
|
||||||
|
</div>
|
||||||
|
<div style="top:10.38cm;left:0.41cm;width:4.99cm;font-size:6pt;">ΕΕΤΤ ΑΜ 99-150 Γενική Αδεια Ταχ/κων Υπηρεσιών</div>
|
||||||
|
|
||||||
|
{{-- rectangle17: title, barcode, this parcel's voucher --}}
|
||||||
|
<div class="ch-box" style="top:9.02cm;left:5.44cm;width:8.07cm;height:1.76cm;">
|
||||||
|
<div class="ch-center" style="top:0.13cm;font-size:9pt;font-weight:bold;">ΣΥΝΟΔΕΥΤΙΚΟ ΔΕΛΤΙΟ ΤΑΧΥΜΕΤΑΦΟΡΑΣ</div>
|
||||||
|
<div class="ch-barcode" style="top:0.57cm;left:0.19cm;width:7.65cm;">
|
||||||
|
<img src="{{ $barcode_voucher }}" alt="">
|
||||||
|
</div>
|
||||||
|
<div class="ch-center" style="top:1.30cm;font-size:11pt;font-weight:bold;">{{ $voucher_no }}</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div style="top:11.02cm;left:5.10cm;width:4.55cm;font-size:8pt;">Ημερομηνία - Ωρα Εκτύπωσης :</div>
|
||||||
|
<div style="top:11.02cm;left:9.70cm;width:3.70cm;font-size:8pt;">{{ $date }} {{ $time }}</div>
|
||||||
|
|
||||||
|
{{-- rectangle18-21: deposit station, weight, volumetric, pieces --}}
|
||||||
|
<div class="ch-box" style="top:11.45cm;left:0.11cm;width:1.51cm;height:0.82cm;">
|
||||||
|
<div class="ch-label" style="top:0.11cm;left:0.05cm;">Γρ.Κατάθεσης</div>
|
||||||
|
<div style="top:0.42cm;left:0.05cm;font-size:9pt;font-weight:bold;">{{ $station_apo }}</div>
|
||||||
|
</div>
|
||||||
|
<div class="ch-box" style="top:11.45cm;left:1.81cm;width:1.35cm;height:0.82cm;">
|
||||||
|
<div class="ch-label" style="top:0.11cm;left:0.05cm;">Βάρος</div>
|
||||||
|
<div class="ch-val" style="top:0.42cm;left:0.05cm;">{{ $weight }}</div>
|
||||||
|
</div>
|
||||||
|
<div class="ch-box" style="top:11.45cm;left:3.29cm;width:2.83cm;height:0.82cm;">
|
||||||
|
<div class="ch-label" style="top:0.11cm;left:0.05cm;">Ογκ/κο Βάρος</div>
|
||||||
|
<div class="ch-val" style="top:0.42cm;left:0.05cm;">{{ $volumetric_weight }}</div>
|
||||||
|
</div>
|
||||||
|
<div class="ch-box" style="top:11.45cm;left:6.28cm;width:1.22cm;height:0.82cm;">
|
||||||
|
<div class="ch-label" style="top:0.11cm;left:0.05cm;">Τεμάχια</div>
|
||||||
|
<div class="ch-val" style="top:0.42cm;left:0.05cm;">{{ $package_label }}</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- rectangle1: service --}}
|
||||||
|
<div class="ch-box" style="top:11.48cm;left:13.49cm;width:6.20cm;height:0.86cm;">
|
||||||
|
<div style="top:0.06cm;left:0.13cm;font-size:8pt;font-weight:bold;">ΥΠΗΡΕΣΙΑ :</div>
|
||||||
|
<div style="top:0.04cm;left:3.19cm;font-size:9pt;font-weight:bold;">{{ $service_code }}</div>
|
||||||
|
<div style="top:0.43cm;left:0.06cm;width:5.82cm;font-size:8pt;font-weight:bold;">{{ $service_name }}</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- rectangle30: destination station --}}
|
||||||
|
<div class="ch-box" style="top:12.38cm;left:0.11cm;width:12.59cm;height:0.61cm;">
|
||||||
|
<div class="ch-label" style="top:0.18cm;left:0.08cm;">Γρ.Προορισμού</div>
|
||||||
|
<div class="ch-val" style="top:0.13cm;left:1.79cm;">{{ $station_pros }}</div>
|
||||||
|
<div class="ch-val" style="top:0.14cm;left:3.65cm;width:8.73cm;">{{ $station_pros_title }}</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- rectangle52: multi-parcel panel — piece, COD warning, master voucher --}}
|
||||||
|
<div class="ch-box" style="top:12.61cm;left:13.50cm;width:6.27cm;height:6.24cm;">
|
||||||
|
<div class="ch-center" style="top:0.26cm;font-size:10pt;font-weight:bold;">** ΠΟΛΛΑΠΛΗ ΑΠΟΣΤΟΛΗ **</div>
|
||||||
|
<div class="ch-center" style="top:1.89cm;font-size:20pt;font-weight:bold;">{{ $piece_label }}</div>
|
||||||
|
@if ($antik_1)
|
||||||
|
<div class="ch-center" style="top:3.66cm;font-size:10pt;font-weight:bold;">{{ $antik_1 }}</div>
|
||||||
|
@endif
|
||||||
|
<div class="ch-center" style="top:4.77cm;font-size:10pt;font-weight:bold;">ΜASTER ΣΥΔΕΤΑ</div>
|
||||||
|
<div class="ch-center" style="top:5.31cm;font-size:11pt;font-weight:bold;">{{ $copy }}</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- rectangle24: sender (sender_1..5) --}}
|
||||||
|
<div class="ch-box" style="top:13.06cm;left:0.11cm;width:12.57cm;height:2.74cm;">
|
||||||
|
<div style="top:0.08cm;left:0.05cm;font-size:9pt;font-weight:bold;">ΑΠΟΣΤΟΛΕΑΣ</div>
|
||||||
|
@foreach ($sender_lines as $i => $line)
|
||||||
|
<div class="ch-line" style="top:{{ 0.53 + $i * 0.43 }}cm;left:0.05cm;width:11.96cm;">{{ $line }}</div>
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- rectangle27: recipient (rec_1..5) --}}
|
||||||
|
<div class="ch-box" style="top:15.94cm;left:0.11cm;width:12.57cm;height:2.90cm;">
|
||||||
|
<div style="top:0.05cm;left:0.05cm;font-size:9pt;font-weight:bold;">ΠΑΡΑΛΗΠΤΗΣ</div>
|
||||||
|
@foreach ($recipient_lines as $i => $line)
|
||||||
|
<div class="ch-line" style="top:{{ 0.49 + $i * 0.44 }}cm;left:0.05cm;width:12.12cm;font-weight:bold;">{{ $line }}</div>
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
@@ -0,0 +1,124 @@
|
|||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="el">
|
||||||
|
<head>
|
||||||
|
<meta charset="utf-8">
|
||||||
|
<style>
|
||||||
|
{{--
|
||||||
|
Geometry is transcribed directly from ELTA_PEL.sydetaE.rdlc
|
||||||
|
(the "delivery copy" RDLC ELTA's own client selects for
|
||||||
|
printer_size==1, i.e. plain A4, per Sydeta.cs::print_vg()) —
|
||||||
|
every .mc-*/.ps-* absolute position below is that report's
|
||||||
|
own Top/Left in cm, walked through its Rectangle/Textbox
|
||||||
|
nesting so each value is already relative to its own
|
||||||
|
containing band. Static label text and font sizes/weights
|
||||||
|
also come from the RDLC's own Textbox/Style elements, not
|
||||||
|
guessed from the screenshot in ELTA's setup manual (that
|
||||||
|
manual image was used only as a sanity check afterwards).
|
||||||
|
--}}
|
||||||
|
@page { margin: 0; size: 21cm 29.7cm; }
|
||||||
|
html, body { margin: 0; padding: 0; }
|
||||||
|
body { font-family: 'DejaVu Sans', sans-serif; font-size: 6.5pt; color: #000; }
|
||||||
|
|
||||||
|
.page { position: relative; width: 21cm; height: 29.7cm; }
|
||||||
|
|
||||||
|
/* Each RDLC "band" (one ΣΥΝΟΔΕΥΤΙΚΟ ΔΕΛΤΙΟ copy) is its own
|
||||||
|
positioning context, so every child offset below is a direct
|
||||||
|
transcription of the RDLC's own relative-to-band Top/Left —
|
||||||
|
no manual offset arithmetic. */
|
||||||
|
.band { position: absolute; left: 0.27cm; }
|
||||||
|
.band > * { position: absolute; }
|
||||||
|
|
||||||
|
.mc-logo, .mc-company, .mc-box, .mc-cell, .mc-partybox { position: absolute; }
|
||||||
|
.mc-logo img { width: 100%; height: 100%; object-fit: contain; }
|
||||||
|
.mc-company { font-size: 4.6pt; line-height: 1.25; }
|
||||||
|
.mc-company-name { font-weight: bold; font-size: 5.2pt; }
|
||||||
|
.mc-text.mc-small { font-size: 4.6pt; }
|
||||||
|
|
||||||
|
.mc-box { border: 1px solid #000; box-sizing: border-box; }
|
||||||
|
.mc-title { position: absolute; font-weight: bold; font-size: 8pt; line-height: 1; text-align: center; white-space: nowrap; }
|
||||||
|
.mc-barcode { position: absolute; text-align: center; }
|
||||||
|
.mc-barcode img { width: 100%; height: 22px; }
|
||||||
|
.mc-voucher { position: absolute; text-align: center; font-weight: bold; font-size: 10.5pt; line-height: 1; letter-spacing: 0.5px; }
|
||||||
|
.mc-copylabel { position: absolute; text-align: center; font-weight: bold; font-size: 8pt; line-height: 1; }
|
||||||
|
|
||||||
|
.mc-cell { border: 1px solid #000; box-sizing: border-box; padding: 1px 2px; }
|
||||||
|
.mc-cell-label { font-size: 5.5pt; }
|
||||||
|
.mc-cell-val { font-weight: bold; font-size: 8pt; margin-top: 3px; }
|
||||||
|
.mc-cell-service { text-align: center; }
|
||||||
|
|
||||||
|
/* 5-cell deposit/destination/weight/pieces/volumetric row: a real
|
||||||
|
table with border-collapse so each internal shared edge is
|
||||||
|
drawn once, not twice (see _main-copy.blade.php comment). */
|
||||||
|
.mc-cell-row { position: absolute; border-collapse: collapse; table-layout: fixed; }
|
||||||
|
.mc-cell-td { border: 1px solid #000; box-sizing: border-box; padding: 1px 2px; vertical-align: top; }
|
||||||
|
|
||||||
|
.mc-partybox { border: 1px solid #000; box-sizing: border-box; }
|
||||||
|
.mc-party-title { position: absolute; font-weight: bold; font-size: 9pt; }
|
||||||
|
.mc-party-line { position: absolute; font-size: 6.3pt; white-space: nowrap; overflow: hidden; }
|
||||||
|
|
||||||
|
.mc-charge { text-align: center; font-weight: bold; font-size: 8pt; box-sizing: border-box; padding-top: 2px; }
|
||||||
|
|
||||||
|
/* Payment stub (copy 3) reuses the .mc-* classes but at smaller
|
||||||
|
scale, matching the RDLC's own narrower band. */
|
||||||
|
.ps-brandbox { border: 1.5px solid #c8102e; box-sizing: border-box; text-align: center; padding-top: 4px; }
|
||||||
|
.ps-brand-logo img { width: 60%; margin: 0 auto 8px; display: block; }
|
||||||
|
.ps-brand-tag { color: #c8102e; font-weight: bold; font-size: 9pt; }
|
||||||
|
.ps-brandbox-small { border: 1px solid #000; box-sizing: border-box; text-align: center; padding: 2px; }
|
||||||
|
.ps-brand-logo-sm img { width: 40%; margin: 2px auto; display: block; }
|
||||||
|
.ps-legal-sm { font-size: 4.6pt; line-height: 1.3; }
|
||||||
|
|
||||||
|
/* Perforated tear-off strip on the right of copy 1 only, with
|
||||||
|
the rotated "3. ΑΡΧΕΙΟ / ΓΡΑΦΕΙΟ ΚΑΤΑΘΕΣΗΣ" label — RDLC's
|
||||||
|
image10 (x=15.42cm) is the dashed perforation line itself;
|
||||||
|
reproduced here as a CSS dashed border since we can't extract
|
||||||
|
that embedded bitmap. transform:rotate() (not
|
||||||
|
writing-mode:vertical-rl, confirmed broken in dompdf) rotates
|
||||||
|
a normal-flow block. */
|
||||||
|
.stub-strip { position: absolute; top: 2.25cm; left: 16.05cm; width: 4.90cm; height: 6.16cm; border-left: 1px dashed #000; }
|
||||||
|
.stub-vtext {
|
||||||
|
position: absolute; top: 2.6cm; left: -1.3cm; width: 6cm;
|
||||||
|
text-align: center; font-size: 6pt; font-weight: bold;
|
||||||
|
white-space: nowrap; transform: rotate(-90deg);
|
||||||
|
}
|
||||||
|
|
||||||
|
.cut-line { position: absolute; left: 0; width: 20.9cm; border-top: 1px dashed #000; text-align: center; font-weight: bold; font-size: 7pt; }
|
||||||
|
.cut-line span { position: relative; top: -5px; background: #fff; padding: 0 6px; }
|
||||||
|
|
||||||
|
.footer-ocr { position: absolute; top: 27.35cm; left: 0; width: 21cm; text-align: center; font-family: monospace; font-size: 8pt; letter-spacing: 1.5px; }
|
||||||
|
</style>
|
||||||
|
</head>
|
||||||
|
<body>
|
||||||
|
<div class="page">
|
||||||
|
|
||||||
|
{{-- Copy 1: delivery copy — RDLC band top=0 --}}
|
||||||
|
<div class="band" style="top:0.05cm; width:15.75cm; height:8.7cm;">
|
||||||
|
@include('core::shipping.carriers.elta.partials._main-copy', ['copyType' => 'delivery'])
|
||||||
|
</div>
|
||||||
|
<div class="stub-strip">
|
||||||
|
<div class="stub-vtext">3. ΑΡΧΕΙΟ / ΓΡΑΦΕΙΟ ΚΑΤΑΘΕΣΗΣ</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="cut-line" style="top:9.0cm;"><span>✂ ΑΠΟΚΟΨΤΕ ΕΔΩ</span></div>
|
||||||
|
|
||||||
|
{{-- Copy 2: sender's copy — RDLC band top≈8.94cm on the full page --}}
|
||||||
|
<div class="band" style="top:9.30cm; width:15.75cm; height:9.2cm;">
|
||||||
|
@include('core::shipping.carriers.elta.partials._main-copy', ['copyType' => 'sender'])
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="cut-line" style="top:18.75cm;"><span>✂ ΑΠΟΚΟΨΤΕ ΕΔΩ</span></div>
|
||||||
|
|
||||||
|
{{-- Copy 3: ΤΑΧΥΠΛΗΡΩΜΗ ΕΙΣΠΡΑΞΗ / ΜΕΤΑΒΙΒΑΣΗ stub — RDLC band top≈19.22cm --}}
|
||||||
|
<div style="position:absolute; top:19.05cm; left:0.27cm; width:20.4cm; font-weight:bold; font-size:7pt; text-align:center;">
|
||||||
|
ΤΑΧΥΠΛΗΡΩΜΗ ΕΙΣΠΡΑΞΗ / ΜΕΤΑΒΙΒΑΣΗ Ο. Αριθμός Λογ/μού Ταχυπληρωμής {{ $siimvasi }}
|
||||||
|
</div>
|
||||||
|
<div class="band" style="top:19.45cm; width:16.75cm; height:7.4cm;">
|
||||||
|
@include('core::shipping.carriers.elta.partials._payment-stub')
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="cut-line" style="top:26.85cm;"><span>ΜΗ ΣΗΜΕΙΩΝΕΤΕ ΚΑΤΩ ΑΠΟ ΑΥΤΗ ΤΗ ΓΡΑΜΜΗ</span></div>
|
||||||
|
|
||||||
|
{{-- antik_ocr: ELTA's OCR line as issued (it already has its own > < markers) --}}
|
||||||
|
<div class="footer-ocr">{{ $ocr_line }}</div>
|
||||||
|
</div>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
@@ -0,0 +1,244 @@
|
|||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="el">
|
||||||
|
<head>
|
||||||
|
<meta charset="utf-8">
|
||||||
|
<style>
|
||||||
|
{{--
|
||||||
|
Geometry transcribed directly from ELTA_PEL.SydetaLabelE.rdlc
|
||||||
|
— the RDLC ELTA's own client selects for printer_size==2
|
||||||
|
(the A6/"thermal label" printer-setup radio button), per
|
||||||
|
Sydeta.cs::print_vg(); RDLCPrinter.cs overrides the actual
|
||||||
|
print DeviceInfo to 10.4cm x 14.8cm for this printer_size
|
||||||
|
regardless of what PageWidth/PageHeight the RDLC itself
|
||||||
|
declares (all ELTA RDLCs declare A4 internally). Every
|
||||||
|
.a6-* absolute position below is that report's own
|
||||||
|
Top/Left in cm.
|
||||||
|
--}}
|
||||||
|
@page { margin: 0; size: 10.4cm 14.8cm; }
|
||||||
|
html, body { margin: 0; padding: 0; }
|
||||||
|
body { font-family: 'DejaVu Sans', sans-serif; font-size: 6.3pt; color: #000; }
|
||||||
|
|
||||||
|
{{--
|
||||||
|
height is deliberately a hair under the true 14.8cm page —
|
||||||
|
dompdf's border-box math isn't quite exact at this scale, and
|
||||||
|
a .page box sized to exactly fill the page (even with
|
||||||
|
box-sizing:border-box) was empirically confirmed to overflow
|
||||||
|
a fraction of a point past the page canvas and silently push
|
||||||
|
a second, blank page (reproduced with an otherwise-empty
|
||||||
|
.page div: only the border's presence, not any content,
|
||||||
|
triggered it — 14.7cm was stable, 14.75cm was not).
|
||||||
|
--}}
|
||||||
|
.page { position: relative; width: 10.4cm; height: 14.65cm; border: 1.5px solid #000; box-sizing: border-box; overflow: hidden; }
|
||||||
|
.page > * { position: absolute; box-sizing: border-box; }
|
||||||
|
|
||||||
|
.a6-logo img { width: 100%; height: 100%; object-fit: contain; }
|
||||||
|
.a6-service-box { border: 1px solid #000; text-align: center; }
|
||||||
|
.a6-service-code { font-weight: bold; font-size: 7pt; }
|
||||||
|
.a6-service-name { font-weight: bold; font-size: 6pt; text-align: center; }
|
||||||
|
|
||||||
|
.a6-title { font-weight: bold; font-size: 7pt; }
|
||||||
|
.a6-datetime { font-size: 6pt; }
|
||||||
|
.a6-copy { font-weight: bold; font-size: 7pt; text-align: right; }
|
||||||
|
|
||||||
|
.a6-station-box { border: 1px solid #000; }
|
||||||
|
.a6-station-label { font-size: 6pt; font-weight: bold; }
|
||||||
|
.a6-station-val { font-weight: bold; font-size: 8pt; }
|
||||||
|
|
||||||
|
.a6-cell { border: 1px solid #000; padding: 1px 3px; }
|
||||||
|
.a6-cell-label { font-size: 6pt; }
|
||||||
|
.a6-cell-val { font-weight: bold; font-size: 8pt; }
|
||||||
|
|
||||||
|
/* ΧΡΕΩΣΗ/REFERENCE/ΣΥΜΒΑΣΗ row and the Γρ.Κατάθεσης/ΒΑΡΟΣ/
|
||||||
|
ΟΓΚΟΜΕΤΡΙΚΟ/Τεμάχια row: real tables with border-collapse so
|
||||||
|
each internal shared edge is drawn once (see label-a6.blade.php
|
||||||
|
comment above their markup). */
|
||||||
|
.a6-cell-row { position: absolute; border-collapse: collapse; border-spacing: 0; table-layout: fixed; }
|
||||||
|
.a6-cell-td { border: 1px solid #000; box-sizing: border-box; padding: 1px 3px; vertical-align: top; overflow: hidden; }
|
||||||
|
|
||||||
|
.a6-box { border: 1px solid #000; padding: 2px 3px; }
|
||||||
|
.a6-party-title { font-weight: bold; font-size: 7pt; }
|
||||||
|
.a6-party-line { font-size: 8pt; white-space: nowrap; overflow: hidden; }
|
||||||
|
|
||||||
|
.a6-return-title { font-weight: bold; font-size: 6pt; }
|
||||||
|
.a6-return-item { font-size: 6pt; }
|
||||||
|
.a6-checkbox { border: 1px solid #000; display: inline-block; width: 6px; height: 6px; margin-right: 3px; vertical-align: middle; }
|
||||||
|
|
||||||
|
.a6-small-title { font-weight: bold; font-size: 5pt; }
|
||||||
|
.a6-small-val { font-size: 6pt; }
|
||||||
|
|
||||||
|
.a6-legal { font-size: 5pt; text-align: center; line-height: 1.15; }
|
||||||
|
|
||||||
|
.a6-barcode { text-align: center; }
|
||||||
|
.a6-barcode img { height: 24px; }
|
||||||
|
.a6-voucher { text-align: center; font-weight: bold; font-size: 12pt; letter-spacing: 1px; }
|
||||||
|
</style>
|
||||||
|
</head>
|
||||||
|
<body>
|
||||||
|
<div class="page">
|
||||||
|
{{-- Header: logo (0.10,0.12,1.66x1.26) + service box (6.42,0.10,3.93x0.84) --}}
|
||||||
|
<div class="a6-logo" style="top:0.12cm;left:0.10cm;width:1.66cm;height:1.26cm;">
|
||||||
|
<img src="{{ $eltaLogo }}" alt="ELTA Courier">
|
||||||
|
</div>
|
||||||
|
{{-- Πλήρηστοιχεία_black1: ELTA's company details, next to the logo --}}
|
||||||
|
<div style="position:absolute;top:0.10cm;left:1.92cm;width:4.29cm;height:1.60cm;">
|
||||||
|
@include('core::shipping.carriers.elta.partials._elta-details', ['style' => 'font-size:4.2pt;'])
|
||||||
|
</div>
|
||||||
|
<div class="a6-service-box" style="top:0.10cm;left:6.42cm;width:3.93cm;height:0.84cm;">
|
||||||
|
<div class="a6-service-code" style="position:absolute;top:0.02cm;left:0.09cm;">ΥΠΗΡΕΣΙΑ: {{ $service_code }}</div>
|
||||||
|
<div class="a6-service-name" style="position:absolute;top:0.40cm;left:0.04cm;width:3.81cm;">{{ $service_name }}</div>
|
||||||
|
</div>
|
||||||
|
<div class="a6-licence-box" style="top:1.05cm;left:6.42cm;width:3.88cm;height:0.62cm;border:1px solid #000;text-align:center;font-size:5.3pt;font-weight:bold;line-height:1.3;padding-top:2px;">
|
||||||
|
ΕΕΤΤ ΑΜ: 99-150 Γενική Άδεια<br>Ταχ/κων Υπηρεσιών
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="a6-datetime" style="top:1.68cm;left:0.13cm;width:1.68cm;">{{ $date }}</div>
|
||||||
|
<div class="a6-title" style="top:1.79cm;left:1.93cm;width:5.89cm;">ΣΥΝΟΔΕΥΤΙΚΟ ΔΕΛΤΙΟ ΤΑΧΥΜΕΤΑΦΟΡΑΣ</div>
|
||||||
|
{{-- textbox15 (copy): "ΠΟΛΛΑΠΛH" on the extra parcels of a multi-parcel send --}}
|
||||||
|
@if ($copy)
|
||||||
|
<div class="a6-title" style="top:1.84cm;left:7.95cm;width:2.21cm;">{{ $copy }}</div>
|
||||||
|
@endif
|
||||||
|
{{-- The RDLC's own barcode textbox here uses the "Free 3 of 9
|
||||||
|
Extended" barcode font — we don't have that font, so this
|
||||||
|
would-be *{voucher}* fallback text is dropped in favor of the
|
||||||
|
real Code 128 barcode image rendered near the bottom instead. --}}
|
||||||
|
<div class="a6-datetime" style="top:2.00cm;left:0.16cm;width:1.60cm;">{{ $time }}</div>
|
||||||
|
|
||||||
|
<div class="a6-station-box" style="top:2.33cm;left:0.10cm;width:10.20cm;height:0.44cm;">
|
||||||
|
<div class="a6-station-label" style="position:absolute;top:0.05cm;left:0.10cm;">Γρ. Επίδοσης :</div>
|
||||||
|
<div class="a6-station-val" style="position:absolute;top:0.03cm;left:2.50cm;">{{ $station_pros }}</div>
|
||||||
|
<div class="a6-station-val" style="position:absolute;top:0.03cm;left:3.90cm;width:6.06cm;">{{ $station_pros_title }}</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- ΧΡΕΩΣΗ / REFERENCE / ΣΥΜΒΑΣΗ 3-cell row, and the Γρ.Κατάθεσης /
|
||||||
|
ΒΑΡΟΣ / ΟΓΚΟΜΕΤΡΙΚΟ ΒΑΡΟΣ / Τεμάχια row right below it: both are
|
||||||
|
genuinely tabular single rows of fixed-width cells, so — like
|
||||||
|
the equivalent A4 rows — they're built as real
|
||||||
|
<table border-collapse:collapse> instead of independently-
|
||||||
|
bordered absolute divs, which was drawing every shared edge
|
||||||
|
(each cell-to-cell seam, and the seam between these two rows)
|
||||||
|
twice, visibly doubling/thickening those lines versus a real
|
||||||
|
printed ELTA label. Each table is positioned at the row's own
|
||||||
|
RDLC top/left; the first table's bottom border is dropped since
|
||||||
|
the second table's top border already draws that shared line. --}}
|
||||||
|
<table class="a6-cell-row" style="top:2.82cm;left:0.10cm;width:10.16cm;">
|
||||||
|
<colgroup>
|
||||||
|
<col style="width:5.41cm;"><col style="width:2.84cm;"><col style="width:1.91cm;">
|
||||||
|
</colgroup>
|
||||||
|
<tr>
|
||||||
|
<td class="a6-cell-td" style="height:0.47cm;border-bottom:none;">
|
||||||
|
<div style="font-size:6pt;white-space:nowrap;">{{ $xreosi }}</div>
|
||||||
|
</td>
|
||||||
|
<td class="a6-cell-td" style="height:0.47cm;text-align:center;border-bottom:none;">
|
||||||
|
<div style="font-size:7pt;">{{ $ocr_reference }}</div>
|
||||||
|
</td>
|
||||||
|
<td class="a6-cell-td" style="height:0.47cm;text-align:center;border-bottom:none;">
|
||||||
|
<div style="font-size:7pt;">{{ $siimvasi }}</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</table>
|
||||||
|
<table class="a6-cell-row" style="top:3.39cm;left:0.10cm;width:9.97cm;">
|
||||||
|
<colgroup>
|
||||||
|
<col style="width:2.00cm;"><col style="width:2.00cm;"><col style="width:4.12cm;"><col style="width:1.85cm;">
|
||||||
|
</colgroup>
|
||||||
|
<tr>
|
||||||
|
<td class="a6-cell-td" style="height:0.97cm;">
|
||||||
|
<div class="a6-cell-label">Γρ.Κατάθεσης:</div>
|
||||||
|
<div class="a6-cell-val">{{ $station_apo }}</div>
|
||||||
|
</td>
|
||||||
|
<td class="a6-cell-td" style="height:0.97cm;">
|
||||||
|
<div class="a6-cell-label">ΒΑΡΟΣ(Kgr)</div>
|
||||||
|
<div class="a6-cell-val">{{ $weight }}</div>
|
||||||
|
</td>
|
||||||
|
<td class="a6-cell-td" style="height:0.97cm;">
|
||||||
|
<div class="a6-cell-label">ΟΓΚΟΜΕΤΡΙΚΟ ΒΑΡΟΣ(Kgr)</div>
|
||||||
|
<div class="a6-cell-val" style="font-size:6.5pt;white-space:nowrap;">{{ $volumetric_weight }}</div>
|
||||||
|
</td>
|
||||||
|
<td class="a6-cell-td" style="height:0.97cm;">
|
||||||
|
<div class="a6-cell-label">Τεμάχια</div>
|
||||||
|
<div class="a6-cell-val">{{ $package_label }}</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</table>
|
||||||
|
|
||||||
|
{{-- ΑΠΟΣΤΟΛΕΑΣ + ΑΙΤΙΑ ΕΠΙΣΤΡΟΦΗΣ --}}
|
||||||
|
<div class="a6-box" style="top:4.43cm;left:0.10cm;width:7.24cm;height:2.44cm;">
|
||||||
|
@include('core::shipping.carriers.elta.partials._party-box', [
|
||||||
|
'title' => 'ΑΠΟΣΤΟΛΕΑΣ',
|
||||||
|
'lines' => $sender_lines,
|
||||||
|
])
|
||||||
|
</div>
|
||||||
|
<div class="a6-box" style="top:4.43cm;left:7.55cm;width:2.80cm;height:2.44cm;">
|
||||||
|
<div class="a6-return-title">ΑΙΤΙΑ ΕΠΙΣΤΡΟΦΗΣ</div>
|
||||||
|
<div style="margin-top:4px;">
|
||||||
|
<div class="a6-return-item"><span class="a6-checkbox"></span>Άγνωστος</div>
|
||||||
|
<div class="a6-return-item" style="margin-top:4px;"><span class="a6-checkbox"></span>Ελλειπή Δ/νση</div>
|
||||||
|
<div class="a6-return-item" style="margin-top:4px;"><span class="a6-checkbox"></span>Απαράδεκτο</div>
|
||||||
|
<div class="a6-return-item" style="margin-top:4px;"><span class="a6-checkbox"></span>Άλλαξε Δ/νση</div>
|
||||||
|
<div class="a6-return-item" style="margin-top:4px;"><span class="a6-checkbox"></span>Αζήτητο</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- ΠΑΡΑΛΗΠΤΗΣ + ΑΝΤΙΚΑΤΑΒΟΛΗ column --}}
|
||||||
|
<div class="a6-box" style="top:6.97cm;left:0.10cm;width:7.26cm;height:2.78cm;">
|
||||||
|
@include('core::shipping.carriers.elta.partials._party-box', [
|
||||||
|
'title' => 'ΠΑΡΑΛΗΠΤΗΣ',
|
||||||
|
'lines' => $recipient_lines,
|
||||||
|
])
|
||||||
|
</div>
|
||||||
|
{{-- antik_1..7 (textbox51/21/22/24/56/59/61): "ΑΝΤΙΚΑΤΑΒΟΛΗ 17.00",
|
||||||
|
"* ΑΝΑΛΥΣΗ *", "17.00 MΕΤΡΗΤΑ", one line every 0.37cm. --}}
|
||||||
|
<div class="a6-box" style="top:6.97cm;left:7.48cm;width:2.85cm;height:2.79cm;">
|
||||||
|
@foreach ($antik_lines as $i => $line)
|
||||||
|
<div style="position:absolute;top:{{ 0.16 + $i * 0.37 }}cm;left:0.10cm;width:2.62cm;font-size:6pt;">{{ $line }}</div>
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- REFERENCE / ΕΠΙΒΑΡΥΝΣΕΙΣ --}}
|
||||||
|
<div class="a6-box" style="top:9.84cm;left:0.10cm;width:5.81cm;height:0.69cm;">
|
||||||
|
<div class="a6-small-title">REFERENCE</div>
|
||||||
|
<div class="a6-small-val" style="margin-top:3px; font-weight:bold;">{{ $order_reference }}</div>
|
||||||
|
</div>
|
||||||
|
<div class="a6-box" style="top:9.84cm;left:6.00cm;width:4.37cm;height:1.56cm;">
|
||||||
|
<div class="a6-small-title">* ΕΠΙΒΑΡΥΝΣΕΙΣ *</div>
|
||||||
|
@foreach ([$sur_1 ?? null, $sur_2 ?? null, $sur_3 ?? null, $sur_4 ?? null] as $sur)
|
||||||
|
@if (!empty($sur))
|
||||||
|
<div style="font-size:6pt; margin-top:2px;">{{ $sur }}</div>
|
||||||
|
@endif
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- ΠΑΡΑΤΗΡΗΣΕΙΣ --}}
|
||||||
|
<div class="a6-box" style="top:10.60cm;left:0.10cm;width:5.82cm;height:0.80cm;">
|
||||||
|
<div class="a6-small-title">* ΠΑΡΑΤΗΡΗΣΕΙΣ *</div>
|
||||||
|
{{-- sxolia_1/2 (textbox49/50) --}}
|
||||||
|
@foreach (array_slice($sxolia, 0, 2) as $i => $line)
|
||||||
|
<div style="position:absolute;top:{{ 0.24 + $i * 0.26 }}cm;left:0.10cm;width:5.62cm;font-size:6pt;line-height:1;white-space:nowrap;overflow:hidden;">{{ $line }}</div>
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if ($multiPiece)
|
||||||
|
<div class="a6-box" style="top:11.58cm;left:0.10cm;width:10.23cm;height:0.30cm;text-align:center;">
|
||||||
|
<div style="font-weight:bold; font-size:8pt; line-height:1;">{{ $polaplo }}</div>
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
<div class="a6-box" style="top:11.98cm;left:0.10cm;width:10.23cm;height:0.52cm;">
|
||||||
|
<div class="a6-legal">
|
||||||
|
Ισχύουν οι Γενικοί Οροι Παραχής Υπηρεσιών οι οποίοι βρίσκονται αναρτημένοι στο www.elta-courier.gr<br>
|
||||||
|
και είναι διαθέσιμοι σε ολα τα καταστήματα της εταιρίας.
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if ($antik_1 ?? null)
|
||||||
|
<div class="a6-box" style="top:12.60cm;left:0.10cm;width:10.23cm;height:0.40cm;text-align:center;">
|
||||||
|
<div style="font-weight:bold; font-size:9pt; line-height:1;">{{ $antik_1 }}</div>
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
<div class="a6-barcode" style="top:13.18cm;left:0.10cm;width:10.27cm;">
|
||||||
|
<img src="{{ $barcode_voucher }}" alt="">
|
||||||
|
</div>
|
||||||
|
<div class="a6-voucher" style="top:14.02cm;left:0.10cm;width:10.30cm;">{{ $voucher_no }}</div>
|
||||||
|
</div>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
{{--
|
||||||
|
ELTA's company details exactly as its client prints them — the
|
||||||
|
"Πλήρηστοιχεία" images in sydetaE / sydetaE1 / SydetaLabelE (see
|
||||||
|
docs/elta.md, B8), reproduced as text since the bitmaps aren't ours
|
||||||
|
to ship. The caller positions and sizes the block.
|
||||||
|
--}}
|
||||||
|
<div class="elta-details" style="line-height:1.3; white-space:nowrap; {{ $style ?? '' }}">
|
||||||
|
<div style="font-weight:bold;">ΕΛΛΗΝΙΚΑ ΤΑΧΥΔΡΟΜΕΙΑ Α.Ε.</div>
|
||||||
|
<div>Έδρα: Λεωφ. Ιωνίας 200 & Ιακωβάτων 61,</div>
|
||||||
|
<div>111 44 Αθήνα</div>
|
||||||
|
<div>Α.Φ.Μ.: 094026421 | Δ.Ο.Υ.: ΚΕ.ΦΟ.Δ.Ε. ΑΤΤΙΚΗΣ</div>
|
||||||
|
<div>Τ. 210-6073000 | Ε. info@elta-courier.gr</div>
|
||||||
|
<div>www.elta-courier.gr</div>
|
||||||
|
<div>Γ.Ε.ΜΗ: 001092101000</div>
|
||||||
|
</div>
|
||||||
@@ -0,0 +1,173 @@
|
|||||||
|
{{--
|
||||||
|
One "ΣΥΝΟΔΕΥΤΙΚΟ ΔΕΛΤΙΟ ΤΑΧΥΜΕΤΑΦΟΡΑΣ" copy (delivery or sender's),
|
||||||
|
geometry transcribed directly from ELTA_PEL.sydetaE.rdlc's delivery-
|
||||||
|
copy band (Top/Left values there are relative to that band; here
|
||||||
|
they're absolute cm offsets from THIS partial's own 0,0, since the
|
||||||
|
caller wraps it in a `position:relative` container sized 15.75cm x
|
||||||
|
8.75cm — the same width/height as the RDLC band, read off its own
|
||||||
|
rectangle8/rectangle9/rectangle11/rectangle12 extents).
|
||||||
|
|
||||||
|
Expects: $copyType ('delivery'|'sender') and all of
|
||||||
|
EltaLabelRenderer's $data.
|
||||||
|
--}}
|
||||||
|
<div class="mc-logo" style="top:0.09cm;left:0.32cm;width:2.65cm;height:1.93cm;">
|
||||||
|
<img src="{{ $eltaLogo }}" alt="ELTA Courier">
|
||||||
|
</div>
|
||||||
|
{{-- Πλήρηστοιχεία_red1 --}}
|
||||||
|
<div class="mc-company" style="top:0.12cm;left:3.15cm;width:5.19cm;">
|
||||||
|
@include('core::shipping.carriers.elta.partials._elta-details', ['style' => 'font-size:4.4pt;line-height:1.15;'])
|
||||||
|
</div>
|
||||||
|
<div class="mc-text mc-small" style="top:1.80cm;left:3.15cm;width:5.03cm;">ΕΕΤΤ ΑΜ 99-150 Γενική Αδεια Ταχ/κων Υπηρεσιών</div>
|
||||||
|
|
||||||
|
{{-- Title / barcode / voucher, centered column at x=8.52..15.58 --}}
|
||||||
|
<div class="mc-box" style="top:0.05cm;left:8.52cm;width:7.06cm;height:1.75cm;">
|
||||||
|
<div class="mc-title" style="top:0.10cm;left:0.05cm;width:6.85cm;">ΣΥΝΟΔΕΥΤΙΚΟ ΔΕΛΤΙΟ ΤΑΧΥΜΕΤΑΦΟΡΑΣ</div>
|
||||||
|
<div class="mc-barcode" style="top:0.45cm;left:0.24cm;width:6.56cm;">
|
||||||
|
<img src="{{ $barcode_voucher }}" alt="">
|
||||||
|
</div>
|
||||||
|
{{-- The RDLC's own barcode textbox uses the "Free 3 of 9 Extended"
|
||||||
|
barcode font (literal *{voucher}* text rendered as bars by that
|
||||||
|
font) — we don't have that font, so we render a real Code 128
|
||||||
|
barcode image above instead (visually equivalent, actually
|
||||||
|
scannable), making this second plain-text *{voucher}* line
|
||||||
|
redundant with it rather than a distinct field. --}}
|
||||||
|
<div class="mc-voucher" style="top:1.20cm;left:0.00cm;width:7.04cm;">{{ $voucher_no }}</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- The sender's copy carries the COD warning under the voucher
|
||||||
|
(sydetaE.rdlc textbox205: antik_minima), only for cash on delivery.
|
||||||
|
Its "Απόδειξη Είσπραξης" note (textbox211) sits at the top-left in the
|
||||||
|
RDLC, where our header block is — it goes in this copy's COD box
|
||||||
|
instead, under the breakdown. --}}
|
||||||
|
@if ($copyType === 'sender' && ($antik_minima || ($copy ?? null)))
|
||||||
|
{{-- …or the copy field (textbox "copy"): "RETOUR" on a return voucher,
|
||||||
|
which never has COD. --}}
|
||||||
|
<div style="position:absolute;top:1.84cm;left:8.52cm;width:7.06cm;text-align:center;font-size:8pt;font-weight:bold;line-height:1;">{{ $antik_minima ?: $copy }}</div>
|
||||||
|
@endif
|
||||||
|
|
||||||
|
{{-- 5-cell deposit/destination/weight/pieces/volumetric row — a genuinely
|
||||||
|
tabular single row of fixed-width cells, so it's built as a real
|
||||||
|
<table border-collapse:collapse> rather than independently-bordered
|
||||||
|
absolute divs: that was drawing every shared internal edge twice
|
||||||
|
(once per adjacent cell), producing a visibly doubled/thickened line
|
||||||
|
that real printed ELTA labels don't show. The table is positioned via
|
||||||
|
the same absolute top/left/width the RDLC geometry gives the row as a
|
||||||
|
whole; each <td> keeps its own RDLC-derived width via <col>. --}}
|
||||||
|
<table class="mc-cell-row" style="top:2.20cm;left:0.27cm;width:8.44cm;height:0.82cm;">
|
||||||
|
<colgroup>
|
||||||
|
<col style="width:1.51cm;"><col style="width:1.67cm;"><col style="width:1.35cm;"><col style="width:1.08cm;"><col style="width:2.83cm;">
|
||||||
|
</colgroup>
|
||||||
|
<tr>
|
||||||
|
<td class="mc-cell-td">
|
||||||
|
<div class="mc-cell-label">Γρ.Κατάθεσης</div>
|
||||||
|
<div class="mc-cell-val">{{ $station_apo }}</div>
|
||||||
|
</td>
|
||||||
|
<td class="mc-cell-td">
|
||||||
|
<div class="mc-cell-label">Γρ.Προορισμού</div>
|
||||||
|
<div class="mc-cell-val">{{ $station_pros }}</div>
|
||||||
|
</td>
|
||||||
|
<td class="mc-cell-td">
|
||||||
|
<div class="mc-cell-label">Βάρος</div>
|
||||||
|
<div class="mc-cell-val">{{ $weight }}</div>
|
||||||
|
</td>
|
||||||
|
<td class="mc-cell-td">
|
||||||
|
<div class="mc-cell-label">Τεμάχια</div>
|
||||||
|
<div class="mc-cell-val">{{ $package_label }}</div>
|
||||||
|
</td>
|
||||||
|
<td class="mc-cell-td">
|
||||||
|
<div class="mc-cell-label">Ογκ/κο Βάρος</div>
|
||||||
|
<div class="mc-cell-val" style="font-size:4.7pt;white-space:nowrap;">{{ str_replace(' = ', '=', (string) $volumetric_weight) }}</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</table>
|
||||||
|
<div class="mc-cell mc-cell-service" style="top:2.20cm;left:9.19cm;width:6.19cm;height:0.82cm;">
|
||||||
|
<div style="position:absolute;top:0.05cm;left:0.32cm;font-size:6.5pt;">ΥΠΗΡΕΣΙΑ :</div>
|
||||||
|
<div style="position:absolute;top:0.03cm;left:3.21cm;font-size:7.5pt;">{{ $service_code }}</div>
|
||||||
|
<div style="position:absolute;top:0.42cm;left:0.05cm;width:6.08cm;text-align:center;font-size:7.5pt;">{{ $service_name }}</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- Sender box --}}
|
||||||
|
<div class="mc-box mc-partybox" style="top:3.12cm;left:0.27cm;width:6.24cm;height:2.53cm;">
|
||||||
|
<div class="mc-party-title" style="top:0.05cm;left:0.10cm;">ΑΠΟΣΤΟΛΕΑΣ</div>
|
||||||
|
@foreach ($sender_lines as $i => $line)
|
||||||
|
@if (trim((string) $line) !== '')
|
||||||
|
<div class="mc-party-line" style="top:{{ 0.53 + $i * 0.395 }}cm;left:0.05cm;width:6.11cm;">{{ $line }}</div>
|
||||||
|
@endif
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- Recipient box --}}
|
||||||
|
<div class="mc-box mc-partybox" style="top:5.76cm;left:0.29cm;width:6.20cm;height:2.68cm;">
|
||||||
|
<div class="mc-party-title" style="top:0.05cm;left:0.05cm;">ΠΑΡΑΛΗΠΤΗΣ</div>
|
||||||
|
@foreach ($recipient_lines as $i => $line)
|
||||||
|
@if (trim((string) $line) !== '')
|
||||||
|
<div class="mc-party-line" style="top:{{ 0.54 + $i * 0.445 }}cm;left:0.05cm;width:6.11cm;">{{ $line }}</div>
|
||||||
|
@endif
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- Charge banner + right-column panel stack (ΧΡΕΩΣΗ / Συν.Χρέωσης /
|
||||||
|
REFERENCE / ΠΑΡΑΤΗΡΗΣΕΙΣ, and the Πρόσθετες Υπηρεσίες column beside
|
||||||
|
them): these panels sit only a hair apart (~0.09-0.10cm, the RDLC's
|
||||||
|
own geometry, left untouched), close enough that each pair's two
|
||||||
|
independent borders read as one thick/doubled line at print
|
||||||
|
resolution. Each panel below keeps only the border sides it "owns"
|
||||||
|
on a shared seam (border-top/border-left removed where the
|
||||||
|
neighbouring panel above/left already draws that same line), so
|
||||||
|
every seam is drawn exactly once while every panel's outward-facing
|
||||||
|
sides keep their border. --}}
|
||||||
|
<div class="mc-box mc-charge" style="top:3.09cm;left:6.60cm;width:8.78cm;height:0.48cm;">{{ str_replace(' ΠΙΣΤΩΣΗ', ' ΤΡ.ΠΛΗΡ: ΠΙΣΤΩΣΗ', $xreosi) }}</div>
|
||||||
|
|
||||||
|
<div class="mc-box" style="top:3.66cm;left:6.60cm;width:4.37cm;height:0.44cm;border-top:none;">
|
||||||
|
<div style="position:absolute;top:0.05cm;left:0.05cm;font-size:7pt;font-weight:bold;">Συν.Χρέωσης (€):</div>
|
||||||
|
</div>
|
||||||
|
<div class="mc-box" style="top:3.66cm;left:11.07cm;width:4.31cm;height:2.65cm;border-top:none;">
|
||||||
|
<div style="position:absolute;top:0.04cm;left:0.05cm;font-size:6pt;">Πρόσθετες Υπηρεσίες</div>
|
||||||
|
@foreach ([$sur_1 ?? null, $sur_2 ?? null, $sur_3 ?? null, $sur_4 ?? null] as $i => $sur)
|
||||||
|
@if (!empty($sur))
|
||||||
|
<div style="position:absolute;top:{{ 0.35 + $i * 0.365 }}cm;left:0.08cm;width:4.18cm;font-size:6pt;">{{ $sur }}</div>
|
||||||
|
@endif
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="mc-box" style="top:4.10cm;left:6.60cm;width:4.37cm;height:0.77cm;border-top:none;">
|
||||||
|
<div style="position:absolute;top:0.03cm;left:0.05cm;font-size:6pt;">* REFERENCE No*</div>
|
||||||
|
<div style="position:absolute;top:0.31cm;left:0.05cm;font-size:6.5pt;">{{ $order_reference }}</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="mc-box" style="top:4.87cm;left:6.60cm;width:4.37cm;height:1.44cm;border-top:none;">
|
||||||
|
<div style="position:absolute;top:0.03cm;left:0.08cm;font-size:6pt;">* ΠΑΡΑΤΗΡΗΣΕΙΣ *</div>
|
||||||
|
{{-- sxolia_1..3 (textbox92/95/94) --}}
|
||||||
|
@foreach ($sxolia as $i => $line)
|
||||||
|
<div style="position:absolute;top:{{ 0.30 + $i * 0.31 }}cm;left:0.10cm;width:4.18cm;font-size:7pt;line-height:1;white-space:nowrap;overflow:hidden;">{{ $line }}</div>
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- Right-hand signature / print-timestamp column, differs by copy type --}}
|
||||||
|
@if ($copyType === 'delivery')
|
||||||
|
<div class="mc-box" style="top:6.37cm;left:6.61cm;width:4.71cm;height:2.07cm;">
|
||||||
|
{{-- antik_1..6 (textbox102/108/107/106/105/104), first line bold --}}
|
||||||
|
@foreach ($antik_lines as $i => $line)
|
||||||
|
<div style="position:absolute;top:{{ 0.12 + $i * 0.31 }}cm;left:0.08cm;width:4.55cm;font-size:7pt;{{ $i === 0 ? 'font-weight:bold;' : '' }}">{{ $line }}</div>
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
<div class="mc-box" style="top:6.37cm;left:11.48cm;width:3.89cm;height:2.03cm;">
|
||||||
|
<div style="position:absolute;top:0.08cm;left:0.08cm;font-size:6pt;">ΓΙΑ ΤΗΝ ΠΑΡΑΛΑΒΗ</div>
|
||||||
|
<div style="position:absolute;top:0.38cm;left:0.08cm;font-size:6pt;">ΟΝΟΜΑ/ΥΠΟΓΡΑΦΗ</div>
|
||||||
|
<div style="position:absolute;top:1.62cm;left:0.11cm;font-size:6pt;line-height:1;">{{ $date }} {{ $time }}</div>
|
||||||
|
</div>
|
||||||
|
@else
|
||||||
|
<div class="mc-box" style="top:6.37cm;left:6.61cm;width:4.71cm;height:2.07cm;">
|
||||||
|
{{-- antik_1..6 (textbox102/108/107/106/105/104), first line bold --}}
|
||||||
|
@foreach ($antik_lines as $i => $line)
|
||||||
|
<div style="position:absolute;top:{{ 0.12 + $i * 0.31 }}cm;left:0.08cm;width:4.55cm;font-size:7pt;{{ $i === 0 ? 'font-weight:bold;' : '' }}">{{ $line }}</div>
|
||||||
|
@endforeach
|
||||||
|
@if ($apodiksi)
|
||||||
|
<div style="position:absolute;top:1.62cm;left:0.08cm;width:4.55cm;font-size:7pt;">{{ $apodiksi }}</div>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
<div class="mc-box" style="top:6.37cm;left:11.48cm;width:3.89cm;height:2.03cm;">
|
||||||
|
<div style="position:absolute;top:0.08cm;left:0.08cm;font-size:6pt;font-weight:bold;">ΥΠΟΓΡΑΦΗ ΑΠΟΣΤΟΛΕΑ</div>
|
||||||
|
<div style="position:absolute;top:1.30cm;left:0.11cm;font-size:6pt;line-height:1.2;">Ημερομηνία - Ωρα Εκτύπωσης:<br>{{ $date }} {{ $time }}</div>
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
{{--
|
||||||
|
Sender/recipient box, matching SydetaLabelE.rdlc's rectangle10/
|
||||||
|
rectangle11 (ΑΠΟΣΤΟΛΕΑΣ/ΠΑΡΑΛΗΠΤΗΣ) layout: a bold title line, then
|
||||||
|
the RDLC's sender_1..5 / rec_1..5 fields as separate plain text
|
||||||
|
lines (ELTA's own client pre-wraps the address into these fixed-
|
||||||
|
width lines server-side, so we render each line separately rather
|
||||||
|
than reflowing the address ourselves, to match the real line
|
||||||
|
breaks).
|
||||||
|
|
||||||
|
Expects: $title, $lines (array of up to 5 strings).
|
||||||
|
--}}
|
||||||
|
<div class="pb-title">{{ $title }}</div>
|
||||||
|
@foreach ($lines as $line)
|
||||||
|
@if (trim((string) $line) !== '')
|
||||||
|
<div class="pb-line">{{ $line }}</div>
|
||||||
|
@endif
|
||||||
|
@endforeach
|
||||||
@@ -0,0 +1,120 @@
|
|||||||
|
{{--
|
||||||
|
Copy 3: the ΤΑΧΥΠΛΗΡΩΜΗ ΕΙΣΠΡΑΞΗ/ΜΕΤΑΒΙΒΑΣΗ payment-receipt stub —
|
||||||
|
the fields of sydetaE.rdlc's third band. The RDLC's own coordinates
|
||||||
|
don't survive dompdf's font metrics (its boxes ended up overlapping),
|
||||||
|
so the stub is laid out on its own grid instead:
|
||||||
|
|
||||||
|
left 0.00–6.00cm stations/weight/pieces, ΑΠΟΣΤΟΛΕΑΣ, ΠΑΡΑΛΗΠΤΗΣ
|
||||||
|
middle 6.20–11.00cm service, charge, Συν.Χρέωσης/remarks, ΕΠΙΒΑΡΥΝΣΕΙΣ
|
||||||
|
right 11.30cm– ELTA's company details, ΠΟΣΟ
|
||||||
|
|
||||||
|
with the signature / COD / ΠΟΣΟ row along the bottom. The band is
|
||||||
|
7.40cm tall (the "ΜΗ ΣΗΜΕΙΩΝΕΤΕ" line follows).
|
||||||
|
|
||||||
|
Expects all of EltaLabelRenderer's $data.
|
||||||
|
--}}
|
||||||
|
|
||||||
|
{{-- Voucher number + barcode --}}
|
||||||
|
<div class="mc-copylabel" style="top:0.35cm;left:0.00cm;width:5.80cm;text-align:left;font-size:9pt;">{{ $voucher_no }}</div>
|
||||||
|
<div class="mc-box" style="top:0.00cm;left:6.20cm;width:6.70cm;height:1.25cm;">
|
||||||
|
<div class="mc-barcode" style="top:0.08cm;left:0.20cm;width:6.26cm;">
|
||||||
|
<img src="{{ $barcode_voucher }}" alt="">
|
||||||
|
</div>
|
||||||
|
<div class="mc-voucher" style="top:0.78cm;left:0.00cm;width:6.66cm;">{{ $voucher_no }}</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- Left: stations / weight / pieces (one table, so shared edges are drawn once) --}}
|
||||||
|
<table class="mc-cell-row" style="top:1.45cm;left:0.00cm;width:6.00cm;">
|
||||||
|
<colgroup>
|
||||||
|
<col style="width:1.60cm;"><col style="width:1.60cm;"><col style="width:1.40cm;"><col style="width:1.40cm;">
|
||||||
|
</colgroup>
|
||||||
|
<tr>
|
||||||
|
@foreach (['Γρ.Κατάθεσης' => $station_apo, 'Γρ.Προορισμού' => $station_pros, 'Βάρος' => $weight, 'Τεμάχια' => $package_label] as $label => $value)
|
||||||
|
<td class="mc-cell-td" style="height:0.80cm;">
|
||||||
|
<div class="mc-cell-label" style="font-size:5pt;white-space:nowrap;">{{ $label }}</div>
|
||||||
|
<div class="mc-cell-val">{{ $value }}</div>
|
||||||
|
</td>
|
||||||
|
@endforeach
|
||||||
|
</tr>
|
||||||
|
</table>
|
||||||
|
|
||||||
|
{{-- Left: ΑΠΟΣΤΟΛΕΑΣ — sender_1/sender_2 only (code + name), as the stub prints --}}
|
||||||
|
<div class="mc-box" style="top:2.40cm;left:0.00cm;width:6.00cm;height:0.95cm;">
|
||||||
|
<div class="mc-party-title" style="top:0.04cm;left:0.10cm;font-size:6.5pt;line-height:1;">ΑΠΟΣΤΟΛΕΑΣ</div>
|
||||||
|
@foreach (array_slice($sender_lines, 0, 2) as $i => $line)
|
||||||
|
@if (trim((string) $line) !== '')
|
||||||
|
<div class="mc-party-line" style="top:{{ 0.34 + $i * 0.26 }}cm;left:0.10cm;width:5.80cm;font-size:5.6pt;line-height:1;">{{ $line }}</div>
|
||||||
|
@endif
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- Left: ΠΑΡΑΛΗΠΤΗΣ — rec_1..3: name, address, postcode (no phone) --}}
|
||||||
|
<div class="mc-box" style="top:3.45cm;left:0.00cm;width:6.00cm;height:1.45cm;">
|
||||||
|
<div class="mc-party-title" style="top:0.04cm;left:0.10cm;font-size:6.5pt;line-height:1;">ΠΑΡΑΛΗΠΤΗΣ</div>
|
||||||
|
@foreach (array_slice($recipient_lines, 0, 3) as $i => $line)
|
||||||
|
@if (trim((string) $line) !== '')
|
||||||
|
<div class="mc-party-line" style="top:{{ 0.36 + $i * 0.30 }}cm;left:0.10cm;width:5.80cm;font-size:5.6pt;line-height:1;">{{ $line }}</div>
|
||||||
|
@endif
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- Middle: service, then the charge line --}}
|
||||||
|
<div class="mc-box" style="top:1.45cm;left:6.20cm;width:4.80cm;height:0.45cm;">
|
||||||
|
<div style="position:absolute;top:0.10cm;left:0.12cm;font-size:6pt;line-height:1;">{{ $service_code }}</div>
|
||||||
|
<div style="position:absolute;top:0.10cm;left:0.80cm;width:3.90cm;font-size:6pt;line-height:1;white-space:nowrap;overflow:hidden;">{{ $service_name }}</div>
|
||||||
|
</div>
|
||||||
|
<div class="mc-box" style="top:1.90cm;left:6.20cm;width:4.80cm;height:0.40cm;border-top:none;text-align:center;font-weight:bold;">
|
||||||
|
<div style="position:absolute;top:0.10cm;left:0;width:100%;font-size:5.4pt;line-height:1;white-space:nowrap;">{{ str_replace(' ΠΙΣΤΩΣΗ', ' ΤΡ.ΠΛΗΡ: ΠΙΣΤΩΣΗ', $xreosi) }}</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- Middle: Συν.Χρέωσης, Πρόσθετες Υπηρεσίες and the remarks (sxolia_1..2 on one line) --}}
|
||||||
|
<div class="mc-box" style="top:2.40cm;left:6.20cm;width:4.80cm;height:0.95cm;">
|
||||||
|
<div style="position:absolute;top:0.05cm;left:0.12cm;font-size:6pt;line-height:1;">Συν.Χρέωσης (€):</div>
|
||||||
|
<div style="position:absolute;top:0.32cm;left:0.12cm;font-size:6pt;line-height:1;">Πρόσθετες Υπηρεσίες</div>
|
||||||
|
@if (filled($sxolia))
|
||||||
|
<div style="position:absolute;top:0.62cm;left:0.12cm;width:4.56cm;font-size:4.6pt;line-height:1;white-space:nowrap;overflow:hidden;">{{ implode('', array_slice($sxolia, 0, 2)) }}</div>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- Middle: ΕΠΙΒΑΡΥΝΣΕΙΣ — sur_1..4 --}}
|
||||||
|
<div class="mc-box" style="top:3.45cm;left:6.20cm;width:4.80cm;height:1.45cm;">
|
||||||
|
<div style="position:absolute;top:0.05cm;left:0.12cm;font-size:6pt;line-height:1;">* ΕΠΙΒΑΡΥΝΣΕΙΣ *</div>
|
||||||
|
@foreach (array_values(array_filter([$sur_1, $sur_2, $sur_3, $sur_4])) as $i => $sur)
|
||||||
|
<div style="position:absolute;top:{{ 0.33 + $i * 0.26 }}cm;left:0.12cm;width:4.56cm;font-size:6pt;line-height:1;white-space:nowrap;overflow:hidden;">{{ $sur }}</div>
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- Far right: ELTA's "Hellenic Post" logo and slogan (the RDLC's
|
||||||
|
Point5_ELTACourier_ΑποστολήμαςΕσείς image, printed there on its side) --}}
|
||||||
|
<div style="position:absolute;top:1.50cm;left:16.90cm;width:3.30cm;text-align:center;">
|
||||||
|
<img src="{{ $hellenicPostLogo }}" alt="ΕΛΤΑ" style="width:3.30cm;height:2.23cm;">
|
||||||
|
<div style="margin-top:0.15cm;font-size:7pt;font-weight:bold;line-height:1;color:#006ba6;">Αποστολή μας εσείς!</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- Right: ELTA's company details (Πλήρηστοιχεία_black) --}}
|
||||||
|
<div style="position:absolute;top:1.50cm;left:11.30cm;width:5.30cm;">
|
||||||
|
@include('core::shipping.carriers.elta.partials._elta-details', ['style' => 'font-size:5.4pt;line-height:1.25;'])
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div style="position:absolute;top:5.00cm;left:0.00cm;width:11.00cm;font-size:4.6pt;line-height:1;white-space:nowrap;">
|
||||||
|
Έλαβα γνώση των όρων που αναγράφονται στο αντίγραφο 1 και 6 και τους αποδέχομαι ανεπιφύλακτα
|
||||||
|
</div>
|
||||||
|
|
||||||
|
{{-- Bottom row: signatures (left), the COD breakdown antik_1..6 (middle), ΠΟΣΟ (right) --}}
|
||||||
|
<div class="mc-box" style="top:5.30cm;left:0.00cm;width:2.90cm;height:1.65cm;">
|
||||||
|
<div style="position:absolute;top:0.08cm;left:0.08cm;font-size:6pt;font-weight:bold;line-height:1.2;">ΥΠΟΓΡΑΦΗ<br>ΑΠΟΣΤΟΛΕΑ</div>
|
||||||
|
<div style="position:absolute;top:1.30cm;left:0.08cm;font-size:6pt;line-height:1;">{{ $date }}</div>
|
||||||
|
</div>
|
||||||
|
<div class="mc-box" style="top:5.30cm;left:3.00cm;width:3.00cm;height:1.65cm;">
|
||||||
|
<div style="position:absolute;top:0.08cm;left:0.08cm;font-size:6pt;font-weight:bold;line-height:1.2;">ΟΝΟΜΑ/ΥΠΟΓΡΑΦΗ<br>ΠΑΡΑΛΗΠΤΗ</div>
|
||||||
|
<div style="position:absolute;top:1.30cm;left:0.08cm;font-size:6pt;line-height:1;">Ημ/νία: Ώρα:</div>
|
||||||
|
</div>
|
||||||
|
<div class="mc-box" style="top:5.30cm;left:6.20cm;width:4.80cm;height:1.65cm;">
|
||||||
|
@foreach ($antik_lines as $i => $line)
|
||||||
|
<div style="position:absolute;top:{{ 0.10 + $i * 0.30 }}cm;left:0.12cm;width:4.56cm;font-size:7pt;line-height:1;{{ $i === 0 ? 'font-weight:bold;' : '' }}">{{ $line }}</div>
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
<div class="mc-box" style="top:5.30cm;left:11.30cm;width:2.80cm;height:1.65cm;text-align:center;">
|
||||||
|
<div style="position:absolute;top:0.18cm;left:0;width:100%;font-size:7pt;line-height:1;">Π Ο Σ Ο</div>
|
||||||
|
<div style="position:absolute;top:0.70cm;left:0;width:100%;font-size:13pt;font-weight:bold;line-height:1;">{{ $antik_poso }}</div>
|
||||||
|
</div>
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Lunar\Base\LunarUser;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by UserOtpService::validate() on every successful OTP login, not just
|
||||||
|
* a first-time one. Modules\Core\Privacy listens on this to auto-cancel a pending
|
||||||
|
* DataErasureRequest — logging back in during the grace period is the "I changed
|
||||||
|
* my mind" action (see Modules\Core\Privacy\Listeners\CancelErasureOnLoginListener),
|
||||||
|
* which needs $user->customers to resolve any pending request. Typed as
|
||||||
|
* Authenticatable&LunarUser rather than plain Authenticatable (unlike the sibling
|
||||||
|
* UserCreated event) specifically because that listener depends on it — every real
|
||||||
|
* User in this codebase implements LunarUser (see docs/lunar.md "LunarUser trait"),
|
||||||
|
* and User is the only Authenticatable entity in this project (Customer is not —
|
||||||
|
* see docs/modules.md "Customer/User Pairing").
|
||||||
|
*/
|
||||||
|
class UserAuthenticated
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly Authenticatable&LunarUser $user,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Customer\Services\CustomerEmailChangeService::confirm()
|
||||||
|
* once a login-email change actually takes effect — $oldEmail is what the
|
||||||
|
* account's login used to be, already overwritten on $user by the time
|
||||||
|
* this fires.
|
||||||
|
*/
|
||||||
|
class UserEmailChanged
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly Authenticatable $user,
|
||||||
|
public readonly string $oldEmail,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Exceptions;
|
||||||
|
|
||||||
|
use RuntimeException;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Thrown by Modules\Core\Auth\Services\UserOtpService::generateAndSend()
|
||||||
|
* when an email has requested too many codes too quickly — caps both
|
||||||
|
* mail-bombing one inbox and the "just request a fresh code to reset my
|
||||||
|
* guess count" loophole a per-code attempt cap alone doesn't close.
|
||||||
|
*/
|
||||||
|
class OtpThrottledException extends RuntimeException
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly int $availableInSeconds,
|
||||||
|
) {
|
||||||
|
parent::__construct("Too many code requests. Try again in {$availableInSeconds} second(s).");
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,50 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Http\Middleware;
|
||||||
|
|
||||||
|
use Closure;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Facades\Auth;
|
||||||
|
use Modules\Core\Auth\Services\UserSessionService;
|
||||||
|
use Symfony\Component\HttpFoundation\Response;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The enforcement half of the session registry — see
|
||||||
|
* Modules\Core\Auth\Services\UserSessionService's own docblock. Not
|
||||||
|
* auto-registered anywhere (no routes/kernel wiring exist in this
|
||||||
|
* package — see Modules\Core\Customer\Services\CustomerAccountService's
|
||||||
|
* own docblock for why this branch stops at services); a consuming app
|
||||||
|
* adds this to its `web` middleware group (after `auth`) to actually get
|
||||||
|
* "logout everywhere" enforcement.
|
||||||
|
*
|
||||||
|
* A request with no recorded UserSession at all (see
|
||||||
|
* UserSessionService::currentSession()'s own docblock) is let through —
|
||||||
|
* only an EXPLICITLY revoked session is rejected.
|
||||||
|
*/
|
||||||
|
class EnsureSessionNotRevoked
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly UserSessionService $sessions,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public function handle(Request $request, Closure $next): Response
|
||||||
|
{
|
||||||
|
if (! Auth::check()) {
|
||||||
|
return $next($request);
|
||||||
|
}
|
||||||
|
|
||||||
|
$session = $this->sessions->currentSession();
|
||||||
|
|
||||||
|
if ($session && $session->isRevoked()) {
|
||||||
|
Auth::logout();
|
||||||
|
$request->session()->invalidate();
|
||||||
|
$request->session()->regenerateToken();
|
||||||
|
|
||||||
|
abort(401, 'Your session has been revoked. Please log in again.');
|
||||||
|
}
|
||||||
|
|
||||||
|
$session?->update(['last_used_at' => now()]);
|
||||||
|
|
||||||
|
return $next($request);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Listeners;
|
||||||
|
|
||||||
|
use Modules\Core\Auth\Events\UserCreated;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The storefront login page shows a terms/privacy notice ("By continuing,
|
||||||
|
* you accept the Terms of Use and have read the Privacy Policy") that
|
||||||
|
* requesting an OTP code implicitly accepts — recorded once, right here,
|
||||||
|
* for a genuinely new signup only (UserCreated fires exactly once per
|
||||||
|
* user, from Auth\Services\UserOtpService::generateAndSend()'s own
|
||||||
|
* wasRecentlyCreated check). An existing user's original acceptance
|
||||||
|
* (whatever version was live when THEY signed up) must never be
|
||||||
|
* overwritten by whatever config('legal.*') says today, which is exactly
|
||||||
|
* why this only ever runs from UserCreated and nowhere else.
|
||||||
|
*/
|
||||||
|
class RecordLegalAcceptanceForNewUser
|
||||||
|
{
|
||||||
|
public function handle(UserCreated $event): void
|
||||||
|
{
|
||||||
|
$event->user->forceFill([
|
||||||
|
'terms_accepted_at' => now(),
|
||||||
|
'terms_version' => config('legal.terms_version'),
|
||||||
|
'privacy_policy_version' => config('legal.privacy_policy_version'),
|
||||||
|
])->save();
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Mail;
|
||||||
|
|
||||||
|
use Illuminate\Mail\Mailable;
|
||||||
|
use Illuminate\Mail\Mailables\Content;
|
||||||
|
use Illuminate\Mail\Mailables\Envelope;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Sent to the NEW address a shopper is trying to switch their login email
|
||||||
|
* to (Customer\Services\CustomerEmailChangeService::request()) — proves
|
||||||
|
* they can actually receive mail there before the switch takes effect.
|
||||||
|
* View overridable per-app the same way UserOtpMail's is (resources/
|
||||||
|
* views/vendor/core/auth/mail/email-change-code.blade.php).
|
||||||
|
*/
|
||||||
|
class EmailChangeCodeMail extends Mailable
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly string $code,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public function envelope(): Envelope
|
||||||
|
{
|
||||||
|
return new Envelope(subject: 'Confirm your new email address');
|
||||||
|
}
|
||||||
|
|
||||||
|
public function content(): Content
|
||||||
|
{
|
||||||
|
return new Content(view: 'core::auth.mail.email-change-code');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Mail;
|
||||||
|
|
||||||
|
use Illuminate\Mail\Mailable;
|
||||||
|
use Illuminate\Mail\Mailables\Content;
|
||||||
|
use Illuminate\Mail\Mailables\Envelope;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Sent to the OLD address once a login-email change actually takes
|
||||||
|
* effect (Customer\Services\CustomerEmailChangeService::confirm()) — lets
|
||||||
|
* the previous owner notice if someone else changed it from a hijacked
|
||||||
|
* session. Shows the new address masked (first character + domain only),
|
||||||
|
* never the full new address — this notice's whole point is alerting the
|
||||||
|
* OLD owner, not handing them the new address outright. View overridable
|
||||||
|
* per-app the same way UserOtpMail's is (resources/views/vendor/core/
|
||||||
|
* auth/mail/email-changed-notice.blade.php).
|
||||||
|
*/
|
||||||
|
class EmailChangedNoticeMail extends Mailable
|
||||||
|
{
|
||||||
|
public readonly string $maskedEmail;
|
||||||
|
|
||||||
|
public function __construct(string $newEmail)
|
||||||
|
{
|
||||||
|
[$local, $domain] = explode('@', $newEmail, 2);
|
||||||
|
|
||||||
|
$this->maskedEmail = mb_substr($local, 0, 1).'•••@'.$domain;
|
||||||
|
}
|
||||||
|
|
||||||
|
public function envelope(): Envelope
|
||||||
|
{
|
||||||
|
return new Envelope(subject: 'Your account email was changed');
|
||||||
|
}
|
||||||
|
|
||||||
|
public function content(): Content
|
||||||
|
{
|
||||||
|
return new Content(view: 'core::auth.mail.email-changed-notice');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -6,20 +6,47 @@ use Illuminate\Mail\Mailable;
|
|||||||
use Illuminate\Mail\Mailables\Content;
|
use Illuminate\Mail\Mailables\Content;
|
||||||
use Illuminate\Mail\Mailables\Envelope;
|
use Illuminate\Mail\Mailables\Envelope;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The one OTP email template for every use of Auth\Services\OtpService —
|
||||||
|
* not just admin login. A code confirming a destructive Artisan command
|
||||||
|
* (e.g. Command\WipeCatalogCommand) reuses the exact same generation/
|
||||||
|
* validation mechanism as login, but "Your login code" as the subject
|
||||||
|
* would be actively misleading for that — the recipient never initiated a
|
||||||
|
* login. $purpose is a small, fixed set of known keys (see
|
||||||
|
* COPY_BY_PURPOSE), not free text — a typo'd/unknown purpose falls back
|
||||||
|
* to 'login' rather than rendering a blank subject/intro.
|
||||||
|
*/
|
||||||
class OtpMail extends Mailable
|
class OtpMail extends Mailable
|
||||||
{
|
{
|
||||||
|
private const COPY_BY_PURPOSE = [
|
||||||
|
'login' => [
|
||||||
|
'subject' => 'Your login code',
|
||||||
|
'intro' => 'Your login code is:',
|
||||||
|
],
|
||||||
|
'wipe-catalog' => [
|
||||||
|
'subject' => 'Confirm: Wipe Catalog',
|
||||||
|
'intro' => 'Someone requested to permanently delete every product in the catalog. If this was you, enter this code to confirm:',
|
||||||
|
],
|
||||||
|
];
|
||||||
|
|
||||||
public function __construct(
|
public function __construct(
|
||||||
public readonly string $name,
|
public readonly string $name,
|
||||||
public readonly string $code,
|
public readonly string $code,
|
||||||
|
public readonly string $purpose = 'login',
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
public function envelope(): Envelope
|
public function envelope(): Envelope
|
||||||
{
|
{
|
||||||
return new Envelope(subject: 'Your login code');
|
return new Envelope(subject: $this->copy()['subject']);
|
||||||
}
|
}
|
||||||
|
|
||||||
public function content(): Content
|
public function content(): Content
|
||||||
{
|
{
|
||||||
return new Content(view: 'core::auth.mail.otp');
|
return new Content(view: 'core::auth.mail.otp', with: ['intro' => $this->copy()['intro']]);
|
||||||
|
}
|
||||||
|
|
||||||
|
private function copy(): array
|
||||||
|
{
|
||||||
|
return self::COPY_BY_PURPOSE[$this->purpose] ?? self::COPY_BY_PURPOSE['login'];
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -11,7 +11,7 @@ class Staff extends ModelsStaff
|
|||||||
'last_name',
|
'last_name',
|
||||||
'admin',
|
'admin',
|
||||||
'email',
|
'email',
|
||||||
'otp_code',
|
'otp_code_hash',
|
||||||
'otp_expires_at',
|
'otp_expires_at',
|
||||||
];
|
];
|
||||||
|
|
||||||
@@ -19,6 +19,18 @@ class Staff extends ModelsStaff
|
|||||||
'admin' => 'bool',
|
'admin' => 'bool',
|
||||||
'email_verified_at' => 'datetime',
|
'email_verified_at' => 'datetime',
|
||||||
'password' => 'hashed',
|
'password' => 'hashed',
|
||||||
|
'otp_code_hash' => 'hashed',
|
||||||
'otp_expires_at' => 'datetime',
|
'otp_expires_at' => 'datetime',
|
||||||
];
|
];
|
||||||
|
|
||||||
|
// Overrides (doesn't merge with) Lunar\Admin\Models\Staff's own
|
||||||
|
// $hidden — repeats its password/remember_token here so this class
|
||||||
|
// doesn't silently drop that protection while adding otp_code_hash/
|
||||||
|
// otp_expires_at, which the base model has no reason to know about.
|
||||||
|
protected $hidden = [
|
||||||
|
'password',
|
||||||
|
'remember_token',
|
||||||
|
'otp_code_hash',
|
||||||
|
'otp_expires_at',
|
||||||
|
];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,33 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Models;
|
||||||
|
|
||||||
|
use Illuminate\Database\Eloquent\Model;
|
||||||
|
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* One row per login (see Modules\Core\Auth\Services\UserOtpService::
|
||||||
|
* validate()) — see that table's own migration docblock for why this
|
||||||
|
* exists independent of the actual session-store driver.
|
||||||
|
*/
|
||||||
|
class UserSession extends Model
|
||||||
|
{
|
||||||
|
protected $guarded = [];
|
||||||
|
|
||||||
|
protected $casts = [
|
||||||
|
'last_used_at' => 'datetime',
|
||||||
|
'revoked_at' => 'datetime',
|
||||||
|
];
|
||||||
|
|
||||||
|
public function user(): BelongsTo
|
||||||
|
{
|
||||||
|
$model = config('auth.providers.users.model');
|
||||||
|
|
||||||
|
return $this->belongsTo($model);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function isRevoked(): bool
|
||||||
|
{
|
||||||
|
return $this->revoked_at !== null;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,68 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Privacy;
|
||||||
|
|
||||||
|
use Modules\Core\Auth\Models\UserSession;
|
||||||
|
use Modules\Core\Privacy\Contracts\PersonalDataProvider;
|
||||||
|
use Modules\Core\Privacy\DTOs\CustomerSubject;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureOutcome;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderErasureResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderExportResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\UserSubject;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Login-session device/location metadata (user_sessions) — ip_address and
|
||||||
|
* user_agent are device/location fingerprinting data tied 1:1 to a User via
|
||||||
|
* user_id, never to a Customer (business account), so this is User-scope
|
||||||
|
* only. No legal retention requirement applies to session metadata the way
|
||||||
|
* it does to Order (there's no tax/accounting reason to keep old login IPs
|
||||||
|
* around), so rows are deleted outright rather than pseudonymized.
|
||||||
|
*
|
||||||
|
* A hard delete here is safe regardless of whether the User row itself has
|
||||||
|
* already been erased — CustomerDataProvider::eraseForUser() nulls the
|
||||||
|
* User's own name/email but never touches user_sessions, and the table's
|
||||||
|
* own user_id FK is cascadeOnDelete() only if the User row itself were
|
||||||
|
* hard-deleted, which it never is (erasure here means "identity nulled,"
|
||||||
|
* not "row removed" — see docs/modules.md "Customer/User Pairing").
|
||||||
|
*/
|
||||||
|
class UserSessionDataProvider implements PersonalDataProvider
|
||||||
|
{
|
||||||
|
public function name(): string
|
||||||
|
{
|
||||||
|
return 'sessions';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
return new ProviderExportResult('sessions', []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$sessions = UserSession::where('user_id', $subject->userId)->get();
|
||||||
|
|
||||||
|
return new ProviderExportResult('sessions', $sessions->map(fn (UserSession $session) => [
|
||||||
|
'id' => $session->id,
|
||||||
|
'ip_address' => $session->ip_address,
|
||||||
|
'user_agent' => $session->user_agent,
|
||||||
|
'last_used_at' => $session->last_used_at?->toIso8601String(),
|
||||||
|
'revoked_at' => $session->revoked_at?->toIso8601String(),
|
||||||
|
])->all());
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
return new ProviderErasureResult('sessions', ErasureOutcome::Skipped, 'Login sessions belong to individual Users, not Customer accounts.');
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
$deleted = UserSession::where('user_id', $subject->userId)->delete();
|
||||||
|
|
||||||
|
if ($deleted === 0) {
|
||||||
|
return new ProviderErasureResult('sessions', ErasureOutcome::Skipped, 'No login sessions for this user.');
|
||||||
|
}
|
||||||
|
|
||||||
|
return new ProviderErasureResult('sessions', ErasureOutcome::Erased);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -2,6 +2,7 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Auth\Services;
|
namespace Modules\Core\Auth\Services;
|
||||||
|
|
||||||
|
use Illuminate\Support\Facades\Hash;
|
||||||
use Illuminate\Support\Facades\Mail;
|
use Illuminate\Support\Facades\Mail;
|
||||||
use Modules\Core\Auth\Mail\OtpMail;
|
use Modules\Core\Auth\Mail\OtpMail;
|
||||||
use Modules\Core\Auth\Models\Staff;
|
use Modules\Core\Auth\Models\Staff;
|
||||||
@@ -11,7 +12,13 @@ class OtpService
|
|||||||
private const EXPIRY_MINUTES = 10;
|
private const EXPIRY_MINUTES = 10;
|
||||||
private const CODE_LENGTH = 6;
|
private const CODE_LENGTH = 6;
|
||||||
|
|
||||||
public function generateAndSend(string $email): bool
|
/**
|
||||||
|
* $purpose is forwarded as-is to OtpMail, which only recognizes a
|
||||||
|
* fixed set of keys (see its own COPY_BY_PURPOSE) — an unrecognized
|
||||||
|
* value there just falls back to 'login' rather than failing here, so
|
||||||
|
* this method has nothing of its own to validate.
|
||||||
|
*/
|
||||||
|
public function generateAndSend(string $email, string $purpose = 'login'): bool
|
||||||
{
|
{
|
||||||
$staff = Staff::where('email', $email)->first();
|
$staff = Staff::where('email', $email)->first();
|
||||||
|
|
||||||
@@ -21,11 +28,14 @@ class OtpService
|
|||||||
|
|
||||||
$code = str_pad((string) random_int(0, 999999), self::CODE_LENGTH, '0', STR_PAD_LEFT);
|
$code = str_pad((string) random_int(0, 999999), self::CODE_LENGTH, '0', STR_PAD_LEFT);
|
||||||
|
|
||||||
$staff->otp_code = $code;
|
// otp_code_hash's 'hashed' cast (see Staff's own $casts) hashes
|
||||||
|
// this automatically on assignment, same as password — never
|
||||||
|
// stored or compared in plaintext.
|
||||||
|
$staff->otp_code_hash = $code;
|
||||||
$staff->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES);
|
$staff->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES);
|
||||||
$staff->save();
|
$staff->save();
|
||||||
|
|
||||||
Mail::to($staff->email)->send(new OtpMail($staff->first_name, $code));
|
Mail::to($staff->email)->send(new OtpMail($staff->first_name, $code, $purpose));
|
||||||
|
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
@@ -38,11 +48,15 @@ class OtpService
|
|||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (! $staff->otp_expires_at || $staff->otp_code != $code || now()->isAfter($staff->otp_expires_at)) {
|
if (! $staff->otp_code_hash || ! $staff->otp_expires_at || now()->isAfter($staff->otp_expires_at)) {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
$staff->otp_code = null;
|
if (! Hash::check($code, $staff->otp_code_hash)) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
$staff->otp_code_hash = null;
|
||||||
$staff->otp_expires_at = null;
|
$staff->otp_expires_at = null;
|
||||||
$staff->save();
|
$staff->save();
|
||||||
|
|
||||||
|
|||||||
@@ -2,47 +2,249 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Auth\Services;
|
namespace Modules\Core\Auth\Services;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Facades\Auth;
|
||||||
|
use Illuminate\Support\Facades\Cache;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Illuminate\Support\Facades\Event;
|
||||||
|
use Illuminate\Support\Facades\Hash;
|
||||||
use Illuminate\Support\Facades\Mail;
|
use Illuminate\Support\Facades\Mail;
|
||||||
|
use Illuminate\Support\Facades\RateLimiter;
|
||||||
|
use Modules\Core\Auth\Events\UserAuthenticated;
|
||||||
|
use Modules\Core\Auth\Events\UserCreated;
|
||||||
|
use Modules\Core\Auth\Exceptions\OtpThrottledException;
|
||||||
use Modules\Core\Auth\Mail\UserOtpMail;
|
use Modules\Core\Auth\Mail\UserOtpMail;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The storefront's passwordless login — a shopper supplies only an email
|
||||||
|
* (Shopify-style), gets a 6-digit code, and validate() authenticates the
|
||||||
|
* `web` guard via Auth::login().
|
||||||
|
*
|
||||||
|
* That alone is enough to merge/associate any active guest cart into the
|
||||||
|
* now-known customer — Auth::login() fires Illuminate\Auth\Events\Login,
|
||||||
|
* which Lunar's own Lunar\Listeners\CartSessionAuthListener (registered
|
||||||
|
* unconditionally in LunarServiceProvider::boot(), no opt-in needed)
|
||||||
|
* already listens to, calling CartSession::associate() with
|
||||||
|
* config('lunar.cart.auth_policy') — 'merge' by default, 'override' if a
|
||||||
|
* consumer changes that config. Deliberately no cart-association call
|
||||||
|
* here: doing our own on top would run a SECOND merge attempt with a
|
||||||
|
* hardcoded policy that ignores whatever the consumer configured.
|
||||||
|
*
|
||||||
|
* generateAndSend() does NOT create a User row for an email it hasn't
|
||||||
|
* seen before — it used to (firstOrCreate() ran unconditionally), which
|
||||||
|
* meant this login FORM was effectively a registration form: anyone could
|
||||||
|
* create a real User (and, via UserCreated's own cascade, a paired
|
||||||
|
* Customer) for any email address they liked, whether or not a single
|
||||||
|
* correct code was ever entered. A genuinely new email's pending code now
|
||||||
|
* lives in the cache (see pendingKey()), keyed by email, with no DB row
|
||||||
|
* at all — firstOrCreate() and UserCreated only fire from validate(), and
|
||||||
|
* only once the code has actually been proven correct. An email that
|
||||||
|
* already has a User row is unaffected: its OTP state still lives on that
|
||||||
|
* row's own otp_code_hash/otp_expires_at/otp_attempts columns exactly as
|
||||||
|
* before, so a returning shopper's login is unchanged. otp_code_hash
|
||||||
|
* holds a bcrypt hash of the code (the 'otp_code_hash' => 'hashed' cast
|
||||||
|
* on App\Models\User hashes it automatically on assignment, same as
|
||||||
|
* password), not the code itself — compared via Hash::check().
|
||||||
|
*
|
||||||
|
* Two independent throttles, both configured under core.auth.otp — see
|
||||||
|
* config/core.php's own comment for why they're separate: max_attempts
|
||||||
|
* caps wrong guesses against ONE code; generation_limit caps how often a
|
||||||
|
* NEW code can be requested for the same email at all (closes both the
|
||||||
|
* "regenerate to reset my guess count" loophole and mail-bombing one
|
||||||
|
* inbox). Both apply identically whether or not a User row exists yet.
|
||||||
|
*
|
||||||
|
* validate() also records a UserSessionService entry for the new login —
|
||||||
|
* see that class's own docblock for the "logout everywhere" registry
|
||||||
|
* this feeds (Modules\Core\Auth\Http\Middleware\EnsureSessionNotRevoked
|
||||||
|
* is the enforcement half; a consuming app must add it to its own
|
||||||
|
* middleware stack). $request is optional purely so this service stays
|
||||||
|
* callable from a context with no HTTP request at all (a console
|
||||||
|
* command, a test) — user-agent/ip are simply not recorded when omitted.
|
||||||
|
*/
|
||||||
class UserOtpService
|
class UserOtpService
|
||||||
{
|
{
|
||||||
private const EXPIRY_MINUTES = 10;
|
private const EXPIRY_MINUTES = 10;
|
||||||
private const CODE_LENGTH = 6;
|
private const CODE_LENGTH = 6;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
private readonly UserSessionService $sessions,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws OtpThrottledException if this email has requested too many
|
||||||
|
* codes within core.auth.otp.generation_decay_minutes
|
||||||
|
*/
|
||||||
public function generateAndSend(string $email): bool
|
public function generateAndSend(string $email): bool
|
||||||
{
|
{
|
||||||
$model = config('auth.providers.users.model');
|
$limiterKey = $this->generationLimiterKey($email);
|
||||||
$user = $model::firstOrCreate(['email' => $email]);
|
$maxGenerations = (int) config('core.auth.otp.generation_limit', 3);
|
||||||
|
|
||||||
|
if (RateLimiter::tooManyAttempts($limiterKey, $maxGenerations)) {
|
||||||
|
throw new OtpThrottledException(RateLimiter::availableIn($limiterKey));
|
||||||
|
}
|
||||||
|
|
||||||
|
RateLimiter::hit($limiterKey, (int) config('core.auth.otp.generation_decay_minutes', 10) * 60);
|
||||||
|
|
||||||
|
$model = config('auth.providers.users.model');
|
||||||
|
$user = $model::where('email', $email)->first();
|
||||||
$code = str_pad((string) random_int(0, 999999), self::CODE_LENGTH, '0', STR_PAD_LEFT);
|
$code = str_pad((string) random_int(0, 999999), self::CODE_LENGTH, '0', STR_PAD_LEFT);
|
||||||
|
|
||||||
$user->otp_code = $code;
|
if ($user) {
|
||||||
$user->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES);
|
$user->otp_code_hash = $code;
|
||||||
$user->save();
|
$user->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES);
|
||||||
|
$user->otp_attempts = 0;
|
||||||
|
$user->save();
|
||||||
|
} else {
|
||||||
|
// No row yet — deliberately not created here. See this
|
||||||
|
// class's own docblock for why: creating one on every
|
||||||
|
// generateAndSend() call let anyone mint real User/Customer
|
||||||
|
// rows for an email nobody proved they owned.
|
||||||
|
//
|
||||||
|
// Hashed even in the cache (not just on the DB-backed path)
|
||||||
|
// — a code sitting in Cache::get()-able storage is the same
|
||||||
|
// exposure as a plaintext DB column if anything can read it.
|
||||||
|
Cache::put($this->pendingKey($email), [
|
||||||
|
'code_hash' => Hash::make($code),
|
||||||
|
'expires_at' => now()->addMinutes(self::EXPIRY_MINUTES)->timestamp,
|
||||||
|
'attempts' => 0,
|
||||||
|
], now()->addMinutes(self::EXPIRY_MINUTES));
|
||||||
|
}
|
||||||
|
|
||||||
Mail::to($user->email)->send(new UserOtpMail($user->name ?? $user->email, $code));
|
Mail::to($email)->send(new UserOtpMail($user->name ?? $email, $code));
|
||||||
|
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
public function validate(string $email, string $code)
|
/**
|
||||||
|
* A wrong code counts against core.auth.otp.max_attempts and, once
|
||||||
|
* reached, invalidates the code entirely — the shopper must request
|
||||||
|
* a fresh one via generateAndSend() (itself throttled independently
|
||||||
|
* — see this class's own docblock) rather than being able to keep
|
||||||
|
* guessing against a still-live code for the rest of its 10-minute
|
||||||
|
* expiry window. Applies identically to the cache-backed (no User row
|
||||||
|
* yet) and DB-backed (existing User row) paths.
|
||||||
|
*/
|
||||||
|
public function validate(string $email, string $code, ?Request $request = null): ?Authenticatable
|
||||||
{
|
{
|
||||||
$model = config('auth.providers.users.model');
|
$model = config('auth.providers.users.model');
|
||||||
$user = $model::where('email', $email)->first();
|
$existing = $model::where('email', $email)->exists();
|
||||||
|
|
||||||
if (! $user) {
|
$result = $existing
|
||||||
|
? $this->validateExisting($model, $email, $code)
|
||||||
|
: $this->validatePending($model, $email, $code);
|
||||||
|
|
||||||
|
if (! $result) {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (! $user->otp_expires_at || $user->otp_code != $code || now()->isAfter($user->otp_expires_at)) {
|
RateLimiter::clear($this->generationLimiterKey($email));
|
||||||
return null;
|
|
||||||
}
|
|
||||||
|
|
||||||
$user->otp_code = null;
|
Auth::login($result);
|
||||||
$user->otp_expires_at = null;
|
|
||||||
$user->save();
|
|
||||||
|
|
||||||
return $user;
|
$this->sessions->record($result, $request);
|
||||||
|
|
||||||
|
Event::dispatch(new UserAuthenticated($result));
|
||||||
|
|
||||||
|
return $result;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* lockForUpdate() + a transaction make the read-check-increment-save
|
||||||
|
* atomic across concurrent requests for the same user — without it,
|
||||||
|
* two guesses fired in parallel can each read the same pre-increment
|
||||||
|
* otp_attempts value and both save past max_attempts, letting an
|
||||||
|
* attacker exceed the lockout by parallelizing requests instead of
|
||||||
|
* sending them serially.
|
||||||
|
*/
|
||||||
|
private function validateExisting(string $model, string $email, string $code): ?Authenticatable
|
||||||
|
{
|
||||||
|
return DB::transaction(function () use ($model, $email, $code) {
|
||||||
|
$user = $model::where('email', $email)->lockForUpdate()->first();
|
||||||
|
|
||||||
|
if (! $user || ! $user->otp_code_hash || ! $user->otp_expires_at || now()->isAfter($user->otp_expires_at)) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (! Hash::check($code, $user->otp_code_hash)) {
|
||||||
|
$user->otp_attempts++;
|
||||||
|
|
||||||
|
if ($user->otp_attempts >= (int) config('core.auth.otp.max_attempts', 5)) {
|
||||||
|
$user->otp_code_hash = null;
|
||||||
|
$user->otp_expires_at = null;
|
||||||
|
$user->otp_attempts = 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
$user->save();
|
||||||
|
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
$user->otp_code_hash = null;
|
||||||
|
$user->otp_expires_at = null;
|
||||||
|
$user->otp_attempts = 0;
|
||||||
|
$user->save();
|
||||||
|
|
||||||
|
return $user;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* No User row exists yet, so there's nothing to lockForUpdate() —
|
||||||
|
* Cache::lock() is the equivalent guard against two parallel guesses
|
||||||
|
* against the same pending signup both reading the same pre-increment
|
||||||
|
* attempts count. The User (and, via UserCreated, its paired Customer)
|
||||||
|
* is only ever created here, once the code has actually been proven
|
||||||
|
* correct — never from generateAndSend().
|
||||||
|
*/
|
||||||
|
private function validatePending(string $model, string $email, string $code): ?Authenticatable
|
||||||
|
{
|
||||||
|
$key = $this->pendingKey($email);
|
||||||
|
|
||||||
|
return Cache::lock("{$key}:lock", 10)->block(5, function () use ($model, $email, $code, $key) {
|
||||||
|
$pending = Cache::get($key);
|
||||||
|
|
||||||
|
if (! $pending || now()->timestamp > $pending['expires_at']) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (! Hash::check($code, $pending['code_hash'])) {
|
||||||
|
$pending['attempts']++;
|
||||||
|
|
||||||
|
if ($pending['attempts'] >= (int) config('core.auth.otp.max_attempts', 5)) {
|
||||||
|
Cache::forget($key);
|
||||||
|
} else {
|
||||||
|
Cache::put($key, $pending, now()->addMinutes(self::EXPIRY_MINUTES));
|
||||||
|
}
|
||||||
|
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
Cache::forget($key);
|
||||||
|
|
||||||
|
$user = $model::firstOrCreate(['email' => $email]);
|
||||||
|
|
||||||
|
// wasRecentlyCreated is Eloquent's own "did firstOrCreate()
|
||||||
|
// just INSERT, or did it find an existing row" flag. Always
|
||||||
|
// true here in practice (validatePending() only runs when no
|
||||||
|
// row existed moments ago), but checked anyway rather than
|
||||||
|
// assumed, in case of an extremely unlikely race with a
|
||||||
|
// signup completed through some other path in between.
|
||||||
|
if ($user->wasRecentlyCreated) {
|
||||||
|
Event::dispatch(new UserCreated($user));
|
||||||
|
}
|
||||||
|
|
||||||
|
return $user;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
private function generationLimiterKey(string $email): string
|
||||||
|
{
|
||||||
|
return 'otp-generate:'.strtolower($email);
|
||||||
|
}
|
||||||
|
|
||||||
|
private function pendingKey(string $email): string
|
||||||
|
{
|
||||||
|
return 'otp-pending:'.strtolower($email);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,105 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Services;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Str;
|
||||||
|
use Modules\Core\Auth\Models\UserSession;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The record/revoke half of the session registry — see
|
||||||
|
* database/migrations/2026_09_15_000001_create_user_sessions_table.php's
|
||||||
|
* own docblock for why this exists (SESSION_DRIVER=redis in this app has
|
||||||
|
* no "sessions" table to purge by user_id). The enforcement half is
|
||||||
|
* Modules\Core\Auth\Http\Middleware\EnsureSessionNotRevoked, which reads
|
||||||
|
* the token this class stamps into the session payload.
|
||||||
|
*/
|
||||||
|
class UserSessionService
|
||||||
|
{
|
||||||
|
private const SESSION_TOKEN_KEY = 'user_session_token';
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Called once, right after Auth::login() succeeds (see
|
||||||
|
* UserOtpService::validate()) — generates a fresh token, records it,
|
||||||
|
* and stamps it into the CURRENT session payload so
|
||||||
|
* EnsureSessionNotRevoked can look it up on later requests.
|
||||||
|
*/
|
||||||
|
public function record(Authenticatable $user, ?Request $request = null): UserSession
|
||||||
|
{
|
||||||
|
$token = Str::random(64);
|
||||||
|
|
||||||
|
$session = UserSession::create([
|
||||||
|
'user_id' => $user->getAuthIdentifier(),
|
||||||
|
'token' => $token,
|
||||||
|
'user_agent' => $request?->userAgent(),
|
||||||
|
'ip_address' => $request?->ip(),
|
||||||
|
'last_used_at' => now(),
|
||||||
|
]);
|
||||||
|
|
||||||
|
session([self::SESSION_TOKEN_KEY => $token]);
|
||||||
|
|
||||||
|
return $session;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Revokes every OTHER active session for $user — the current one
|
||||||
|
* (matched by the token in the CURRENT session payload) is left
|
||||||
|
* alone, matching Laravel's own logoutOtherDevices() semantics
|
||||||
|
* (there just isn't a password to re-verify against here — this is a
|
||||||
|
* passwordless account, so revocation is simply "every row that
|
||||||
|
* isn't the one making this request").
|
||||||
|
*
|
||||||
|
* Known, deliberately accepted gap: this requires only a currently
|
||||||
|
* valid session, not a freshly-completed login — so anyone holding
|
||||||
|
* an already-authenticated session (e.g. someone who sits down at an
|
||||||
|
* account left logged in on a shared/public PC) can use this to
|
||||||
|
* evict the real owner's OTHER sessions just as easily as the real
|
||||||
|
* owner could use it to evict an intruder's. A stricter version would
|
||||||
|
* require a fresh OTP re-verification (e.g. within the last few
|
||||||
|
* minutes) before allowing this call. Left as-is for now — revisit if
|
||||||
|
* this turns out to matter in practice, rather than building
|
||||||
|
* abuse-resistance against a threat model nobody's confirmed is real
|
||||||
|
* for this storefront.
|
||||||
|
*/
|
||||||
|
public function revokeOtherSessions(Authenticatable $user): int
|
||||||
|
{
|
||||||
|
$currentToken = session(self::SESSION_TOKEN_KEY);
|
||||||
|
|
||||||
|
return UserSession::query()
|
||||||
|
->where('user_id', $user->getAuthIdentifier())
|
||||||
|
->whereNull('revoked_at')
|
||||||
|
->when($currentToken, fn ($query) => $query->where('token', '!=', $currentToken))
|
||||||
|
->update(['revoked_at' => now()]);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Revokes EVERY session for $user, current one included — for a
|
||||||
|
* "this account may be compromised" response, not a routine logout.
|
||||||
|
*/
|
||||||
|
public function revokeAllSessions(Authenticatable $user): int
|
||||||
|
{
|
||||||
|
return UserSession::query()
|
||||||
|
->where('user_id', $user->getAuthIdentifier())
|
||||||
|
->whereNull('revoked_at')
|
||||||
|
->update(['revoked_at' => now()]);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return UserSession|null null if the CURRENT session has no
|
||||||
|
* recorded token at all (e.g. a session predating this feature, or
|
||||||
|
* one Auth::login() established outside UserOtpService) — treated
|
||||||
|
* as valid by EnsureSessionNotRevoked rather than rejected, since
|
||||||
|
* there's nothing to have been revoked.
|
||||||
|
*/
|
||||||
|
public function currentSession(): ?UserSession
|
||||||
|
{
|
||||||
|
$token = session(self::SESSION_TOKEN_KEY);
|
||||||
|
|
||||||
|
if (! $token) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
return UserSession::where('token', $token)->first();
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -14,6 +14,7 @@ use Illuminate\Database\Eloquent\Collection as EloquentCollection;
|
|||||||
use Illuminate\Support\Facades\Blade;
|
use Illuminate\Support\Facades\Blade;
|
||||||
use Lunar\Admin\Filament\Resources\CustomerResource;
|
use Lunar\Admin\Filament\Resources\CustomerResource;
|
||||||
use Lunar\Admin\Filament\Resources\ProductResource\Pages\EditProduct;
|
use Lunar\Admin\Filament\Resources\ProductResource\Pages\EditProduct;
|
||||||
|
use Lunar\Exceptions\MissingCurrencyPriceException;
|
||||||
use Lunar\Models\Cart;
|
use Lunar\Models\Cart;
|
||||||
use Lunar\Models\CartLine;
|
use Lunar\Models\CartLine;
|
||||||
use Lunar\Models\ProductVariant;
|
use Lunar\Models\ProductVariant;
|
||||||
@@ -47,6 +48,17 @@ class ViewCart extends ViewRecord
|
|||||||
* own OrderItemsTable loads for an order's line items (`with(['purchasable'])`,
|
* own OrderItemsTable loads for an order's line items (`with(['purchasable'])`,
|
||||||
* see vendor/lunarphp/lunar/.../OrderItemsTable::getDefaultTable()) — so
|
* see vendor/lunarphp/lunar/.../OrderItemsTable::getDefaultTable()) — so
|
||||||
* rendering the product grid doesn't N+1 per line.
|
* rendering the product grid doesn't N+1 per line.
|
||||||
|
*
|
||||||
|
* calculate() throws Lunar\Exceptions\MissingCurrencyPriceException
|
||||||
|
* (vendor PricingManager) the moment ANY line's purchasable has no
|
||||||
|
* price row for the cart's currency — including a line whose
|
||||||
|
* purchasable no longer exists at all (a deleted ProductVariant still
|
||||||
|
* referenced by cart_lines.purchasable_id), which 500'd this whole
|
||||||
|
* page rather than just leaving that one line unpriced. The Lines
|
||||||
|
* section below already guards every purchasable-derived field with
|
||||||
|
* `instanceof ProductVariant` and renders fine with $cart left
|
||||||
|
* uncalculated — subTotal/total/etc. simply won't be populated, which
|
||||||
|
* reads as a stale/pending state rather than a broken page.
|
||||||
*/
|
*/
|
||||||
protected function resolveRecord(int|string $key): Cart
|
protected function resolveRecord(int|string $key): Cart
|
||||||
{
|
{
|
||||||
@@ -58,7 +70,11 @@ class ViewCart extends ViewRecord
|
|||||||
EloquentCollection::make($cart->lines->pluck('purchasable')->filter(fn ($p) => $p instanceof ProductVariant))
|
EloquentCollection::make($cart->lines->pluck('purchasable')->filter(fn ($p) => $p instanceof ProductVariant))
|
||||||
->loadMissing(['product.thumbnail', 'images', 'values']);
|
->loadMissing(['product.thumbnail', 'images', 'values']);
|
||||||
|
|
||||||
return $cart->calculate();
|
try {
|
||||||
|
return $cart->calculate();
|
||||||
|
} catch (MissingCurrencyPriceException) {
|
||||||
|
return $cart;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
public function infolist(Schema $schema): Schema
|
public function infolist(Schema $schema): Schema
|
||||||
|
|||||||
@@ -0,0 +1,253 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Cart\Http\Controllers;
|
||||||
|
|
||||||
|
use Closure;
|
||||||
|
use Illuminate\Http\JsonResponse;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Routing\Controller;
|
||||||
|
use Illuminate\Support\Facades\App;
|
||||||
|
use Illuminate\Support\Facades\Validator;
|
||||||
|
use Illuminate\Validation\ValidationException;
|
||||||
|
use Illuminate\View\View;
|
||||||
|
use Lunar\Exceptions\Carts\CartException;
|
||||||
|
use Lunar\Models\CartLine;
|
||||||
|
use Lunar\Models\ProductVariant;
|
||||||
|
use Modules\Core\Cart\Exceptions\InvalidCouponException;
|
||||||
|
use Modules\Core\Cart\Services\CartService;
|
||||||
|
use Modules\Core\File\Models\File;
|
||||||
|
use Modules\Core\File\Services\FileService;
|
||||||
|
use Modules\Core\Localization\Services\LanguageCache;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Thin storefront cart endpoints for the checkout module. Every action mutates
|
||||||
|
* the session cart via CartService and returns the same server-rendered
|
||||||
|
* `cart-body` partial — the drawer's Stimulus controller swaps that fragment
|
||||||
|
* in place (no JSON, no client-side templating). $cart / $lines for the
|
||||||
|
* partial come from the view composer in Providers\CheckoutModuleServiceProvider.
|
||||||
|
*/
|
||||||
|
class CartController extends Controller
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly CartService $cart,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* CartException here is Lunar's own add_to_cart validation pipeline
|
||||||
|
* (CartLineQuantity/CartLineStock) rejecting the line — most commonly
|
||||||
|
* "not enough stock at this quantity" for a tracked (purchasable =
|
||||||
|
* in_stock) variant. Its own message is an untranslated, hardcoded
|
||||||
|
* English string not meant for storefront display, so this returns our
|
||||||
|
* own translated one instead rather than passing it through — a
|
||||||
|
* storefront.* key rather than checkout.*, since this is a catalog/stock
|
||||||
|
* concern the storefront owns, not something specific to the portable
|
||||||
|
* checkout module.
|
||||||
|
*/
|
||||||
|
public function add(string $locale, Request $request): View|JsonResponse
|
||||||
|
{
|
||||||
|
$data = $request->validate([
|
||||||
|
'purchasable_id' => ['required', 'integer'],
|
||||||
|
'quantity' => ['nullable', 'integer', 'min:1'],
|
||||||
|
'custom_fields' => ['nullable', 'array'],
|
||||||
|
]);
|
||||||
|
|
||||||
|
$variant = ProductVariant::findOrFail($data['purchasable_id']);
|
||||||
|
|
||||||
|
try {
|
||||||
|
$meta = $this->customFieldsMeta($variant, $data['custom_fields'] ?? []);
|
||||||
|
} catch (ValidationException $e) {
|
||||||
|
return response()->json(['error' => collect($e->errors())->flatten()->first()], 422);
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
$this->cart->addLine($variant, $data['quantity'] ?? 1, $meta);
|
||||||
|
} catch (CartException) {
|
||||||
|
return $this->stockError($variant);
|
||||||
|
}
|
||||||
|
|
||||||
|
return view('checkout::partials.cart-body');
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The shopper's answers to the product's custom fields (Catalog\Models\
|
||||||
|
* Product::$custom_fields — {key, type: text|textarea|file, label,
|
||||||
|
* required}), as cart line meta. Lunar copies CartLine.meta onto the
|
||||||
|
* OrderLine at order creation, so this is also what the order keeps.
|
||||||
|
*
|
||||||
|
* Only keys the product actually defines are kept, nested under
|
||||||
|
* `custom_fields` — line meta also carries behavior flags (core's
|
||||||
|
* `saved_for_later` zeroes the line's price), so shopper input must never
|
||||||
|
* be merged into it directly. Label and type are snapshotted alongside
|
||||||
|
* each value so the cart/order still reads correctly if the product's
|
||||||
|
* fields are edited later.
|
||||||
|
*
|
||||||
|
* A `file` answer is the id of a File row the host's own upload endpoint
|
||||||
|
* already created via FileService — never the file's bytes, disk, or
|
||||||
|
* path, all of which FileService alone is the source of truth for. A
|
||||||
|
* shopper can't point this at someone else's file: the id must resolve
|
||||||
|
* to a File that is BOTH unowned (isFileAnswerValid()) and tagged with
|
||||||
|
* config('checkout.custom_field_upload_purpose') — the host's own
|
||||||
|
* upload endpoint sets its File rows to this same purpose string, so
|
||||||
|
* this stays a single source of truth without this module reaching
|
||||||
|
* into a host controller class directly (an inverted dependency this
|
||||||
|
* module can't have — a host app's upload endpoint is deliberately its
|
||||||
|
* own concern, see config/checkout.php's own comment). Attaching the
|
||||||
|
* File to the real CartLine it belongs to happens afterward, in File\
|
||||||
|
* Listeners\AttachCustomFieldFileToCartLine (listening for Cart\Events\
|
||||||
|
* CartLineAdded) — not here, since this method only builds the meta
|
||||||
|
* $this->cart->addLine() is about to receive, before any CartLine
|
||||||
|
* actually exists to own anything.
|
||||||
|
*
|
||||||
|
* Two adds with identical answers merge into one line (Lunar matches
|
||||||
|
* existing lines on meta); different answers stay separate lines.
|
||||||
|
*/
|
||||||
|
private function customFieldsMeta(ProductVariant $variant, array $input): array
|
||||||
|
{
|
||||||
|
$fields = collect($variant->product?->custom_fields ?? [])
|
||||||
|
->keyBy('key')
|
||||||
|
->map(fn (array $field) => [...$field, 'label' => $this->resolveLabel($field['label'])]);
|
||||||
|
|
||||||
|
if ($fields->isEmpty()) {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
|
||||||
|
$validated = Validator::make(
|
||||||
|
$input,
|
||||||
|
$fields->map(fn (array $field) => [
|
||||||
|
($field['required'] ?? false) ? 'required' : 'nullable',
|
||||||
|
...match ($field['type']) {
|
||||||
|
'textarea' => ['string', 'max:2000'],
|
||||||
|
'file' => [function (string $attribute, mixed $value, Closure $fail) {
|
||||||
|
if (! $this->isFileAnswerValid($value)) {
|
||||||
|
$fail('validation.uploaded')->translate();
|
||||||
|
}
|
||||||
|
}],
|
||||||
|
default => ['string', 'max:255'],
|
||||||
|
},
|
||||||
|
])->all(),
|
||||||
|
[],
|
||||||
|
$fields->map(fn (array $field) => $field['label'])->all(),
|
||||||
|
)->validate();
|
||||||
|
|
||||||
|
$answers = $fields
|
||||||
|
->filter(fn (array $field) => filled($validated[$field['key']] ?? null))
|
||||||
|
->map(fn (array $field) => [
|
||||||
|
'key' => $field['key'],
|
||||||
|
'label' => $field['label'],
|
||||||
|
'type' => $field['type'],
|
||||||
|
...($field['type'] === 'file'
|
||||||
|
? ['file_id' => (int) $validated[$field['key']]]
|
||||||
|
: ['value' => $validated[$field['key']]]),
|
||||||
|
])
|
||||||
|
->values()
|
||||||
|
->all();
|
||||||
|
|
||||||
|
return $answers === [] ? [] : ['custom_fields' => $answers];
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Product::$custom_fields stores `label` as {locale: string} (see
|
||||||
|
* Catalog\Filament\Pages\ManageProductCustomFields) — this resolves it
|
||||||
|
* to the single current-locale string cart/order line meta actually
|
||||||
|
* needs, the same filled()-over-?? fallback ProductDocumentLocalizer
|
||||||
|
* uses for every other translated field (an empty string for the
|
||||||
|
* current locale still falls through to the store's default language,
|
||||||
|
* rather than showing blank). A product saved before labels became
|
||||||
|
* translatable still has a plain string here, returned as-is.
|
||||||
|
*/
|
||||||
|
private function resolveLabel(mixed $label): string
|
||||||
|
{
|
||||||
|
if (! is_array($label)) {
|
||||||
|
return (string) $label;
|
||||||
|
}
|
||||||
|
|
||||||
|
$locale = App::getLocale();
|
||||||
|
$fallbackLocale = app(LanguageCache::class)->defaultLocale();
|
||||||
|
|
||||||
|
return filled($label[$locale] ?? null)
|
||||||
|
? $label[$locale]
|
||||||
|
: ($label[$fallbackLocale] ?? '');
|
||||||
|
}
|
||||||
|
|
||||||
|
private function isFileAnswerValid(mixed $fileId): bool
|
||||||
|
{
|
||||||
|
$file = File::find($fileId);
|
||||||
|
|
||||||
|
return $file !== null
|
||||||
|
&& $file->purpose === config('checkout.custom_field_upload_purpose')
|
||||||
|
&& $file->owner_id === null
|
||||||
|
&& app(FileService::class)->exists($file);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function updateLine(string $locale, Request $request, int $line): View|JsonResponse
|
||||||
|
{
|
||||||
|
$quantity = (int) $request->validate([
|
||||||
|
'quantity' => ['required', 'integer', 'min:0'],
|
||||||
|
])['quantity'];
|
||||||
|
|
||||||
|
try {
|
||||||
|
$quantity === 0
|
||||||
|
? $this->cart->removeLine($line)
|
||||||
|
: $this->cart->updateLine($line, $quantity);
|
||||||
|
} catch (CartException) {
|
||||||
|
$variant = CartLine::find($line)?->purchasable;
|
||||||
|
|
||||||
|
return $this->stockError($variant instanceof ProductVariant ? $variant : null);
|
||||||
|
}
|
||||||
|
|
||||||
|
return view('checkout::partials.cart-body');
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* getTotalInventory() is the same number canBeFulfilledAtQuantity()
|
||||||
|
* checked against (stock, for a tracked in_stock variant) — telling the
|
||||||
|
* shopper how many are actually left beats a generic "not enough stock"
|
||||||
|
* they'd otherwise have to guess around by trial and error.
|
||||||
|
*/
|
||||||
|
private function stockError(?ProductVariant $variant): JsonResponse
|
||||||
|
{
|
||||||
|
$available = $variant?->getTotalInventory() ?? 0;
|
||||||
|
|
||||||
|
return response()->json([
|
||||||
|
'error' => trans_choice('storefront.product.add_to_cart_failed', $available, ['count' => $available]),
|
||||||
|
], 422);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function remove(string $locale, int $line): View
|
||||||
|
{
|
||||||
|
$this->cart->removeLine($line);
|
||||||
|
|
||||||
|
return view('checkout::partials.cart-body');
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A bad code is a normal, expected outcome here (typo, expired code), not
|
||||||
|
* an error state for the request — it re-renders the same cart-body
|
||||||
|
* partial with $couponError set, rather than a 4xx/redirect, so the fetch
|
||||||
|
* + swap in bbk-cart-controller stays the one code path for every cart
|
||||||
|
* mutation.
|
||||||
|
*/
|
||||||
|
public function applyCoupon(string $locale, Request $request): View
|
||||||
|
{
|
||||||
|
$code = $request->validate([
|
||||||
|
'code' => ['required', 'string'],
|
||||||
|
])['code'];
|
||||||
|
|
||||||
|
$couponError = false;
|
||||||
|
|
||||||
|
try {
|
||||||
|
$this->cart->applyCoupon($code);
|
||||||
|
} catch (InvalidCouponException) {
|
||||||
|
$couponError = true;
|
||||||
|
}
|
||||||
|
|
||||||
|
return view('checkout::partials.cart-body', ['couponError' => $couponError]);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function removeCoupon(string $locale): View
|
||||||
|
{
|
||||||
|
$this->cart->removeCoupon();
|
||||||
|
|
||||||
|
return view('checkout::partials.cart-body');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,108 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Cart\Privacy;
|
||||||
|
|
||||||
|
use Lunar\Models\Cart;
|
||||||
|
use Lunar\Models\CartAddress;
|
||||||
|
use Modules\Core\Privacy\Contracts\PersonalDataProvider;
|
||||||
|
use Modules\Core\Privacy\DTOs\CustomerSubject;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureOutcome;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderErasureResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderExportResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\UserSubject;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Carts and cart addresses (lunar_carts, lunar_cart_addresses) belong to the
|
||||||
|
* Customer (business account) via customer_id, not to an individual User, so this
|
||||||
|
* is Customer-scope only. Unlike Order/OrderAddress, an abandoned cart has no
|
||||||
|
* legal retention requirement, so its addresses are freely deleted. The Cart row
|
||||||
|
* itself is left alone (any completed order it produced is handled separately by
|
||||||
|
* OrderDataProvider, which is what retention law actually cares about) — only its
|
||||||
|
* address PII is removed.
|
||||||
|
*
|
||||||
|
* Also covers Cart.meta's own PII-adjacent keys — Modules\Core\Checkout\Services\
|
||||||
|
* CheckoutService::setRecoveryConsent()/selectPaymentMethod() write
|
||||||
|
* recovery_consent/recovery_consent_at/recovery_consent_policy_version and
|
||||||
|
* payment_method/checkout_fingerprint directly onto this same Cart row, which the
|
||||||
|
* address-only erase above never touched. Kept Customer-scope, consistent with
|
||||||
|
* how Cart itself is already classified — see docs/privacy.md for the
|
||||||
|
* User-vs-Customer discussion this raised.
|
||||||
|
*/
|
||||||
|
class CartDataProvider implements PersonalDataProvider
|
||||||
|
{
|
||||||
|
private const META_KEYS = [
|
||||||
|
'recovery_consent',
|
||||||
|
'recovery_consent_at',
|
||||||
|
'recovery_consent_policy_version',
|
||||||
|
'payment_method',
|
||||||
|
'checkout_fingerprint',
|
||||||
|
];
|
||||||
|
|
||||||
|
public function name(): string
|
||||||
|
{
|
||||||
|
return 'carts';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$carts = Cart::where('customer_id', $subject->customerId)->get();
|
||||||
|
|
||||||
|
$addresses = CartAddress::whereIn('cart_id', $carts->pluck('id'))->get();
|
||||||
|
|
||||||
|
return new ProviderExportResult('carts', [
|
||||||
|
'addresses' => $addresses->map(fn (CartAddress $address) => [
|
||||||
|
'type' => $address->type,
|
||||||
|
'first_name' => $address->first_name,
|
||||||
|
'last_name' => $address->last_name,
|
||||||
|
'line_one' => $address->line_one,
|
||||||
|
'city' => $address->city,
|
||||||
|
'postcode' => $address->postcode,
|
||||||
|
'contact_email' => $address->contact_email,
|
||||||
|
'contact_phone' => $address->contact_phone,
|
||||||
|
])->all(),
|
||||||
|
'carts' => $carts->map(fn (Cart $cart) => [
|
||||||
|
'id' => $cart->id,
|
||||||
|
'meta' => $this->metaOnly($cart),
|
||||||
|
])->all(),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
return new ProviderExportResult('carts', []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
$carts = Cart::where('customer_id', $subject->customerId)->get();
|
||||||
|
|
||||||
|
CartAddress::whereIn('cart_id', $carts->pluck('id'))->delete();
|
||||||
|
|
||||||
|
foreach ($carts as $cart) {
|
||||||
|
$meta = (array) $cart->meta;
|
||||||
|
|
||||||
|
foreach (self::META_KEYS as $key) {
|
||||||
|
unset($meta[$key]);
|
||||||
|
}
|
||||||
|
|
||||||
|
$cart->update(['meta' => $meta]);
|
||||||
|
}
|
||||||
|
|
||||||
|
return new ProviderErasureResult('carts', ErasureOutcome::Erased);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
return new ProviderErasureResult('carts', ErasureOutcome::Skipped, 'Carts belong to Customer accounts, not individual users.');
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return array<string, mixed>
|
||||||
|
*/
|
||||||
|
private function metaOnly(Cart $cart): array
|
||||||
|
{
|
||||||
|
$meta = (array) $cart->meta;
|
||||||
|
|
||||||
|
return array_intersect_key($meta, array_flip(self::META_KEYS));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -14,6 +14,7 @@ enum ProductSort: string
|
|||||||
case PriceAsc = 'price_asc';
|
case PriceAsc = 'price_asc';
|
||||||
case PriceDesc = 'price_desc';
|
case PriceDesc = 'price_desc';
|
||||||
case Newest = 'newest';
|
case Newest = 'newest';
|
||||||
|
case Popularity = 'popularity';
|
||||||
|
|
||||||
public function toMeilisearchSort(): string
|
public function toMeilisearchSort(): string
|
||||||
{
|
{
|
||||||
@@ -21,6 +22,12 @@ enum ProductSort: string
|
|||||||
self::PriceAsc => 'price:asc',
|
self::PriceAsc => 'price:asc',
|
||||||
self::PriceDesc => 'price:desc',
|
self::PriceDesc => 'price:desc',
|
||||||
self::Newest => 'created_at:desc',
|
self::Newest => 'created_at:desc',
|
||||||
|
// order_count — see Modules\Core\Catalog\Services\
|
||||||
|
// ProductIndexer::toSearchableArray()'s own docblock: the same
|
||||||
|
// trailing-year, physical-order-line-count definition Lunar's
|
||||||
|
// own admin dashboard "Popular Products" widget already uses,
|
||||||
|
// aggregated per product rather than per variant.
|
||||||
|
self::Popularity => 'order_count:desc',
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,162 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Catalog\Filament\Pages;
|
||||||
|
|
||||||
|
use Filament\Forms\Components\Repeater;
|
||||||
|
use Filament\Forms\Components\Select;
|
||||||
|
use Filament\Forms\Components\TextInput;
|
||||||
|
use Filament\Forms\Components\Toggle;
|
||||||
|
use Filament\Schemas\Components\Group;
|
||||||
|
use Filament\Schemas\Components\Section;
|
||||||
|
use Filament\Schemas\Schema;
|
||||||
|
use Illuminate\Support\Str;
|
||||||
|
use Lunar\Admin\Filament\Resources\ProductResource;
|
||||||
|
use Lunar\Admin\Support\Pages\BaseEditRecord;
|
||||||
|
use Lunar\Models\Language;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Own sub-page for Product::$custom_fields (see that column's own docblock
|
||||||
|
* on Modules\Core\Catalog\Models\Product) — used to be a collapsible
|
||||||
|
* Section inline on the main product edit form (Review\Filament\
|
||||||
|
* Extensions\ProductResourceExtension::extendForm()), moved out to match
|
||||||
|
* how Reviews already gets its own sub-page (ManageProductReviews) rather
|
||||||
|
* than crowding the main form with a second unrelated concern.
|
||||||
|
*
|
||||||
|
* Deliberately no ->statePath('') override, no custom mount()/
|
||||||
|
* handleRecordUpdate() — EditRecord::mount() already fills the form from
|
||||||
|
* $record->attributesToArray() (which includes custom_fields, a real cast
|
||||||
|
* + fillable column) onto the default 'data' statePath, and save() reads
|
||||||
|
* it straight back off via $this->form->getState(). An earlier version of
|
||||||
|
* this page used ->statePath('') to bind the repeater directly to the
|
||||||
|
* record's attributes (copying ManageProductPricing) — that repointed the
|
||||||
|
* Repeater at $this->data['custom_fields'] AS THE ROOT state path itself,
|
||||||
|
* so every "add item" click re-filled the whole form from the record's
|
||||||
|
* still-unsaved value and immediately discarded the new row before it
|
||||||
|
* ever reached the page. Reverting to the plain default form/statePath is
|
||||||
|
* both simpler and is what actually works — same as the original inline
|
||||||
|
* repeater on the main product form did before this became its own page.
|
||||||
|
*
|
||||||
|
* Registered from Review\Filament\Extensions\ProductResourceExtension, not
|
||||||
|
* here — CorePlugin only allows one extension class per Lunar resource,
|
||||||
|
* and Review's already owns ProductResource's extension slot (see that
|
||||||
|
* class's own docblock).
|
||||||
|
*
|
||||||
|
* `label`/`help_text` are each stored as {locale: string} (e.g. {en: "...",
|
||||||
|
* el: "..."}) — see translatedField()'s own docblock for why that's a
|
||||||
|
* hand-rolled TextInput per language rather than Lunar's TranslatedText
|
||||||
|
* component. A product saved before this change still has a plain string
|
||||||
|
* `label` and no `help_text` at all; itemLabel() below tolerates both
|
||||||
|
* shapes, and the storefront/cart resolve either shape the same way (see
|
||||||
|
* product-custom-fields.blade.php and CartController::
|
||||||
|
* customFieldsMeta()). `key`/`type`/`required` stay plain, single values —
|
||||||
|
* only shopper-facing copy needs a translation, not the field's own
|
||||||
|
* machine-facing configuration.
|
||||||
|
*/
|
||||||
|
class ManageProductCustomFields extends BaseEditRecord
|
||||||
|
{
|
||||||
|
protected static string $resource = ProductResource::class;
|
||||||
|
|
||||||
|
public static function getNavigationIcon(): ?string
|
||||||
|
{
|
||||||
|
return 'heroicon-o-adjustments-horizontal';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function getTitle(): string
|
||||||
|
{
|
||||||
|
return 'Custom Fields';
|
||||||
|
}
|
||||||
|
|
||||||
|
public static function getNavigationLabel(): string
|
||||||
|
{
|
||||||
|
return 'Custom Fields';
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Without this, Filament's EditRecord defaults to every relation
|
||||||
|
* manager the WHOLE ProductResource defines (see HasRelationManagers::
|
||||||
|
* getAllRelationManagers(), which reads ProductResource::getRelations()
|
||||||
|
* regardless of which sub-page is rendering) — Channels, Customer
|
||||||
|
* Groups, Media, Pricing tabs all bleeding onto this page alongside the
|
||||||
|
* repeater below. This page has no relations of its own.
|
||||||
|
*/
|
||||||
|
public function getRelationManagers(): array
|
||||||
|
{
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A plain TextInput per configured language, named "{$field}.{locale}"
|
||||||
|
* so it resolves to a normal nested array under the repeater item
|
||||||
|
* (custom_fields.{item}.label.en, .label.el, ...) — NOT Lunar's
|
||||||
|
* TranslatedText component. That component's per-locale sub-fields
|
||||||
|
* set their own statePath to just the locale code itself
|
||||||
|
* (TranslatedText::prepareTranslateLocaleComponent()), which only
|
||||||
|
* resolves correctly when TranslatedText is used as a single
|
||||||
|
* top-level named field directly on a form's root state (exactly how
|
||||||
|
* every existing usage in this codebase uses it — Lunar's own
|
||||||
|
* product name/description). Nested inside a Repeater item here, that
|
||||||
|
* same statePath resolution silently failed to nest under the item's
|
||||||
|
* own label/help_text key at all, and every typed value was lost on
|
||||||
|
* save. Hand-rolling the per-locale inputs sidesteps that assumption
|
||||||
|
* entirely.
|
||||||
|
*/
|
||||||
|
private function translatedField(string $field, string $label, string $helperText, bool $required): Group
|
||||||
|
{
|
||||||
|
$languages = Language::orderBy('default', 'desc')->get(['code', 'name', 'default']);
|
||||||
|
|
||||||
|
return Group::make(
|
||||||
|
$languages->map(fn (Language $language, int $index) => TextInput::make("{$field}.{$language->code}")
|
||||||
|
->label($index === 0 ? $label : null)
|
||||||
|
->hiddenLabel($index !== 0)
|
||||||
|
->helperText($index === 0 ? $helperText : null)
|
||||||
|
->prefix(Str::upper($language->code))
|
||||||
|
->required($required && $language->default))->values()->all(),
|
||||||
|
)
|
||||||
|
->columnSpanFull();
|
||||||
|
}
|
||||||
|
|
||||||
|
public function form(Schema $schema): Schema
|
||||||
|
{
|
||||||
|
return $schema
|
||||||
|
->components([
|
||||||
|
Section::make('Custom Fields')
|
||||||
|
->description('Extra input the shopper fills in on this product\'s page before adding it to their cart — a reference photo, personalization text, etc.')
|
||||||
|
->schema([
|
||||||
|
Repeater::make('custom_fields')
|
||||||
|
->hiddenLabel()
|
||||||
|
->schema([
|
||||||
|
$this->translatedField('label', 'Label', 'Shown to the shopper above the field. Only the current storefront locale is shown on the cart and checkout.', required: true),
|
||||||
|
$this->translatedField('help_text', 'Help text', 'Optional — shown under the label on the product page only, not on the cart or checkout.', required: false),
|
||||||
|
Select::make('type')
|
||||||
|
->label('Field type')
|
||||||
|
->options([
|
||||||
|
'text' => 'Short text',
|
||||||
|
'textarea' => 'Long text',
|
||||||
|
'file' => 'File upload',
|
||||||
|
])
|
||||||
|
->default('text')
|
||||||
|
->native(false)
|
||||||
|
->live()
|
||||||
|
->required(),
|
||||||
|
TextInput::make('key')
|
||||||
|
->label('Key')
|
||||||
|
->helperText('Machine-facing identifier — stored on the order/cart line, used to look up this answer elsewhere. Cannot be changed once orders reference it.')
|
||||||
|
->required()
|
||||||
|
->alphaDash()
|
||||||
|
->maxLength(64),
|
||||||
|
Toggle::make('required')
|
||||||
|
->label('Required')
|
||||||
|
->helperText('Shopper cannot add this product to their cart without answering.')
|
||||||
|
->default(false),
|
||||||
|
])
|
||||||
|
->columns(2)
|
||||||
|
->addActionLabel('Add a custom field')
|
||||||
|
->reorderable()
|
||||||
|
->collapsible()
|
||||||
|
->itemLabel(fn (array $state): ?string => is_array($state['label'] ?? null)
|
||||||
|
? collect($state['label'])->first(fn ($value) => filled($value))
|
||||||
|
: ($state['label'] ?? null)),
|
||||||
|
]),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
}
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user