Compare commits
44
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
409e8204f6 | ||
|
|
8472649905 | ||
|
|
57fc28ca06 | ||
|
|
9d3e54e5df | ||
|
|
44c6b7defd | ||
|
|
78bbd8390a | ||
|
|
99e55902ac | ||
|
|
864c8b19aa | ||
|
|
8f4c1a22ea | ||
|
|
13d5833d18 | ||
|
|
3e45b84636 | ||
|
|
437cbf2460 | ||
|
|
5425a0396f | ||
|
|
4d0e326cb9 | ||
|
|
d4f9766940 | ||
|
|
359e1e262e | ||
|
|
fb684dc97b | ||
|
|
9c95c0bccb | ||
|
|
73bfc748b4 | ||
|
|
4ff9bdacc3 | ||
|
|
55832d9549 | ||
|
|
7b46a83e5e | ||
|
|
e9aa08a338 | ||
|
|
0676a1f5c7 | ||
|
|
8e8ec17d09 | ||
|
|
e6f1ca179a | ||
|
|
79e525d53f | ||
|
|
456943dc74 | ||
|
|
35c3334690 | ||
|
|
a987a2d57c | ||
|
|
0fa2188146 | ||
|
|
a1301d4b46 | ||
|
|
215f43f3ef | ||
|
|
c439299144 | ||
|
|
6963515971 | ||
|
|
f43f72f633 | ||
|
|
448da869a9 | ||
|
|
1287b513cd | ||
|
|
b2919f1f4b | ||
|
|
8cb54e065e | ||
|
|
3497553b41 | ||
|
|
29e77a973b | ||
|
|
026ab5bc2d | ||
|
|
483c0ce00f |
+573
@@ -4,6 +4,579 @@ All notable changes to this project will be documented in this file.
|
|||||||
|
|
||||||
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
||||||
|
|
||||||
|
## [Unreleased]
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- Customer-portal backend groundwork — no routes/controllers/views yet (a storefront-facing UI is
|
||||||
|
3dealer's job once a frontend designer picks it up), but the boboko-owned services it needs to
|
||||||
|
call now exist:
|
||||||
|
- `Modules\Core\Auth\Services\UserOtpService::validate()` now actually logs the shopper in
|
||||||
|
(`Auth::login()`, `web` guard) — previously it only returned the `User` model with no session
|
||||||
|
established and no route/controller anywhere ever called it (the checkout page's "Login" tab
|
||||||
|
was a disabled placeholder). `Auth::login()` alone is enough to merge/associate any active
|
||||||
|
guest cart too — it fires `Illuminate\Auth\Events\Login`, which Lunar's own
|
||||||
|
`Lunar\Listeners\CartSessionAuthListener` (registered unconditionally in core, no opt-in
|
||||||
|
needed) already reacts to, honoring `config('lunar.cart.auth_policy')` (`'merge'` by default).
|
||||||
|
An earlier draft of this also called `Cart::associate()` directly from this service — removed
|
||||||
|
as redundant and actually wrong: it ran a second, separate association with a hardcoded
|
||||||
|
`'merge'` policy that ignored whatever a consumer had actually set `auth_policy` to. Also fixed
|
||||||
|
an unbounded brute-force window: a 6-digit code (1M combinations, was guessable for its full
|
||||||
|
10-minute expiry with no attempt cap) now invalidates itself after 5 wrong guesses
|
||||||
|
(`users.otp_attempts`, new column), forcing a fresh code request rather than leaving a live one
|
||||||
|
guessable indefinitely.
|
||||||
|
- `Modules\Core\Auth\Events\CustomerLoggedIn` — dispatched on every successful OTP login (new
|
||||||
|
user or returning), for a storefront to hook into (e.g. post-login redirect, analytics).
|
||||||
|
- `Modules\Core\Customer\Services\CustomerAccountService` — the storefront-facing "My Account"
|
||||||
|
API (mirrors `CartService`/`CheckoutService`'s shape): `orders()` (paginated, placed orders
|
||||||
|
only), `order()`, `addresses()`, `createAddress()`/`updateAddress()`/`deleteAddress()`,
|
||||||
|
`updateProfile()`. Every method is scoped to the given user's own
|
||||||
|
`latestCustomer()` — there is no method that accepts a bare order/address id without also
|
||||||
|
requiring the owning user, so a controller built on top of this can't leak one customer's data
|
||||||
|
to another by trusting a client-supplied id alone (verified live: a second customer attempting
|
||||||
|
to read/edit the first's address or order gets `AddressNotFoundException`/
|
||||||
|
`OrderNotFoundException`, not the record).
|
||||||
|
|
||||||
|
## [0.17.0] - 2026-09-14
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `Modules\Core\Order\Notifications\OrderPlacedNotification` — an order confirmation email,
|
||||||
|
registered against `Modules\Core\Checkout\Events\OrderPlaced` (fires exactly once per order,
|
||||||
|
regardless of `capture_mode`/driver). Previously only a Stripe (auto-captured) order triggered
|
||||||
|
any placement email at all, via `OrderCapturedNotification` — a different concern (payment
|
||||||
|
confirmation) that happened to fire at the same moment for that one driver; an offline or
|
||||||
|
bank-transfer order got no confirmation whatsoever. Verified live via Mailpit.
|
||||||
|
- `Modules\Core\Order\Listeners\DecrementStockOnOrderPlaced` — also wired to `OrderPlaced`, the
|
||||||
|
first stock decrement anywhere in this codebase (previously nothing wrote to
|
||||||
|
`ProductVariant::stock` as a result of an order at all — overselling was possible). A single
|
||||||
|
atomic `UPDATE ... SET stock = GREATEST(stock - qty, 0)` per variant, not a read-then-write on
|
||||||
|
the Eloquent model, to avoid a lost-update race between two orders decrementing the same variant
|
||||||
|
concurrently. Only touches `purchasable === 'in_stock'` variants on `physical` order lines —
|
||||||
|
`always`/`backorder` variants are deliberately left alone (their stock has no purchasing
|
||||||
|
consequence, decrementing it would just make the column an inaccurate negative number). Also
|
||||||
|
re-triggers Scout reindexing for every affected product, closing the gap `Modules\Core\Catalog\
|
||||||
|
Services\ProductIndexer`'s own docblock flagged ("nothing currently reindexes a product when an
|
||||||
|
order decrements its stock") — the search index's `in_stock` filter now reflects the change
|
||||||
|
immediately rather than only on the next scheduled reindex.
|
||||||
|
- `Modules\Core\Cart\Services\CartLifecycleService` — the single source of truth for the four
|
||||||
|
cart lifecycle states (Ongoing, Abandoned Cart, Abandoned Checkout, Completed) documented in
|
||||||
|
`docs/cart.md`. Previously `Modules\Core\Cart\Filament\Resources\CartResource\Pages\ListCarts`
|
||||||
|
and `Modules\Core\Cart\Commands\DetectAbandonedCarts` each reimplemented the same query split
|
||||||
|
independently, which is exactly the kind of drift that lets the admin panel and the
|
||||||
|
recovery-email pipeline quietly disagree about what "abandoned" means. Both now build on the
|
||||||
|
same `ongoing()`/`abandonedCarts()`/`abandonedCheckouts()`/`completed()` methods, each taking a
|
||||||
|
`Builder` so callers compose the scope onto whatever base query they already have — Filament's
|
||||||
|
own tab query (search/sort/pagination intact) for `ListCarts`, a bare `Cart::query()` for the
|
||||||
|
command.
|
||||||
|
- `core.cart.unrecoverable_after` config (default `90 days`) — beyond this age, a stale cart
|
||||||
|
stops being treated as an active "Abandoned Cart"/"Abandoned Checkout" at all (excluded from
|
||||||
|
both `CartLifecycleService` methods), rather than staying flagged as an actionable abandonment
|
||||||
|
forever. A 90-day-old (or older) cart's pricing/stock/tax have very likely moved on, so it's not
|
||||||
|
a realistic recovery target — this is about the abandoned-cart pipeline only, not data
|
||||||
|
retention; no rows are deleted or pruned.
|
||||||
|
- `Modules\Core\Cart\Filament\Resources\CartResource\Pages\ViewCart`'s Lines section now shows
|
||||||
|
each line's product thumbnail, name (linking to the product's edit page), and variant options —
|
||||||
|
not just SKU/quantity/price — mirroring Lunar's own order line item display
|
||||||
|
(`OrderItemsTable`). Also added a new Shipping section: the resolved shipping method name (not
|
||||||
|
the bare `acs`-style identifier), destination country, shipping total, and each
|
||||||
|
`shippingBreakdown` line item individually (carrier rate, plus any payment-method fee — see
|
||||||
|
0.16.3's `ApplyPaymentMethodFee`) so staff can see what makes up the total, not just the sum.
|
||||||
|
Guards around `Lunar\Models\ProductVariant::getDescription()`/`getOption()`: both are typed to
|
||||||
|
return `string` but internally read `translateAttribute()`/`translate()`, which return `null`
|
||||||
|
for a product/option with no attribute data set for the active locale — a real `TypeError` hit
|
||||||
|
live against an existing test-fixture product. Reads the underlying relations directly instead
|
||||||
|
of calling through those methods, falling back to "—" rather than crashing the page.
|
||||||
|
|
||||||
|
- `Modules\Core\Payment\Drivers\CashOnDeliveryPaymentDriver` — cash-on-delivery/cash-on-pickup was
|
||||||
|
previously wired to `OfflinePaymentDriver`, the same immediate-capture driver as cash-in-hand,
|
||||||
|
which meant a COD order was marked paid the instant it was placed even though no money had
|
||||||
|
actually changed hands. The new driver's `pay()` returns `PaymentResultStatus::Pending` and
|
||||||
|
dispatches nothing, so payment stays unresolved until staff explicitly confirm cash was received
|
||||||
|
(see `Order::paid`/`paid_at` below). A data migration repoints the already-seeded
|
||||||
|
`cash-on-delivery` `PaymentMethod` row to the new driver key.
|
||||||
|
- `Order::paid`/`paid_at` — an entirely independent boolean/timestamp pair tracking payment,
|
||||||
|
settable at any point in an order's lifecycle regardless of fulfillment progress. Exists because
|
||||||
|
cash-on-delivery payment timing has no relationship to the fulfillment sequence at all — a
|
||||||
|
courier might not reconcile cash for weeks after an order is already marked completed.
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- **Order status model, redesigned from scratch.** `Order.status` is a single column again
|
||||||
|
(a same-session 3-axis `payment_status`/`fulfillment_status`/`return_status` design was built,
|
||||||
|
then abandoned before shipping — three independent selects let staff set any combination with no
|
||||||
|
cross-field validation, and didn't map onto how staff actually think about an order: one linear
|
||||||
|
journey, not three simultaneous dials). Now driven by `Modules\Core\Order\Services\
|
||||||
|
OrderStatusFlow`, a pure transition-table service offering exactly two sequences — carrier and
|
||||||
|
store-pickup (`Order::isStorePickupOrder()`) — never four; payment method (prepaid vs. COD)
|
||||||
|
affects `Order::paid` only, not which sequence an order follows or where it sits in it. The
|
||||||
|
Filament order page's several guided buttons are replaced by three header actions: "Update
|
||||||
|
Status" offers every status in the order's own branch (`OrderStatusFlow::allOptions()`) — not
|
||||||
|
just the guided next step — so staff can also revert to an earlier status (e.g. undoing a
|
||||||
|
mistaken click); it also replaces vendor `ManageOrder`'s own built-in "Update Status" (same
|
||||||
|
action name, previously left in place unintentionally, producing two duplicate buttons), since
|
||||||
|
vendor's writes `status` directly with no audit trail or branch validation. It is a PLAIN status
|
||||||
|
write with no side effects — picking 'dispatched' there does not create a real shipment. "Create
|
||||||
|
Shipment" is its own separate action, visible only for a carrier order at 'ready_for_dispatch'
|
||||||
|
(`OrderFulfillmentService::canCreateShipment()`) — the one action that talks to a real carrier
|
||||||
|
API, so its weight/locker inputs only ever appear for that specific real-world action rather than
|
||||||
|
inside the general-purpose status select for every manual override of 'dispatched'. "Mark Paid"
|
||||||
|
is a third, separate header action — `Order::paid` is independent of `status`, so it doesn't
|
||||||
|
belong bundled into the status select either — visible only when the order's payment method
|
||||||
|
doesn't auto-capture at checkout (currently only cash-on-delivery). New status vocabulary
|
||||||
|
(`awaiting_payment`, `processing`, `ready_for_dispatch`/`ready_for_pickup`, `dispatched`,
|
||||||
|
`delivery_failed`, `picked_up`, `delivered`, `completed`, `return_requested`, `returned`,
|
||||||
|
`partially_refunded`, `refunded`) replaces the old hyphenated 7-value list in
|
||||||
|
`config/lunar/orders.php` — a breaking rename backed by a one-time data migration that maps every
|
||||||
|
existing order onto the new vocabulary (preferring axis-system data where an order was actually
|
||||||
|
moved through it during this session's testing, falling back to the legacy flat status otherwise)
|
||||||
|
and derives `paid` from historical transaction data. (The carrier branch's post-delivery status
|
||||||
|
was initially named `return_window_open`; renamed to `delivered` — same one combined moment,
|
||||||
|
parcel arrived and return window open — via a follow-up migration once the internal name turned
|
||||||
|
out to be a confusing thing for staff to see on an order.) A new "Payment Method" entry on the
|
||||||
|
order summary sidebar (`Order.meta['payment_method']`, falling back to the latest transaction's
|
||||||
|
driver) surfaces which method a shopper actually used, previously shown nowhere on the order
|
||||||
|
page. The order list topbar's tabs (Lunar's own `favourite` config flag) are trimmed to the
|
||||||
|
main-journey statuses only, rather than all twelve — the exception/branch statuses stay reachable
|
||||||
|
via the table's own filter.
|
||||||
|
- "Create Shipment"'s form now branches by carrier (`OrderFulfillmentService::carrierFor()`):
|
||||||
|
- A weight-billed carrier (ACS) gets its weight field pre-filled from the order's own line
|
||||||
|
weights via the new `Modules\Core\Shipping\Support\WeightCalculator` (the same unit-conversion
|
||||||
|
table `AcsRateDriver::totalWeightInKg()` already used for live rate quoting, now shared rather
|
||||||
|
than duplicated) — still staff-editable, not forced.
|
||||||
|
- Box Now ships by compartment size, not weight, so it gets a repeatable list of boxes (one row
|
||||||
|
per physical parcel, each with its own S/M/L size — `ShipmentRequest::$boxes`) instead of the
|
||||||
|
weight field. `BoxNowFulfillmentService::createShipment()` sends one `items` entry per box in a
|
||||||
|
single delivery request and now creates one `Shipment` row per parcel returned (was hardcoded to
|
||||||
|
exactly one box/compartmentSize=1, silently ignoring anything beyond the first parcel) — each row
|
||||||
|
independently trackable/printable/cancellable, linked to its siblings via a shared
|
||||||
|
`meta['delivery_request_id']`.
|
||||||
|
- Box Now's locker field is locked read-only once the shopper's own checkout selection
|
||||||
|
(`$order->shippingAddress->meta['box_now_locker']`) is present — staff can no longer silently
|
||||||
|
redirect a parcel to a different locker than the one the customer picked at checkout; it's only
|
||||||
|
editable for the (current, checkout-UI-less) case where nothing set it yet.
|
||||||
|
- New "Shipments" section on the order page (`Modules\Core\Shipping\Extensions\
|
||||||
|
OrderShipmentsExtension`, between Transactions and Timeline) — "Create Shipment" previously had no
|
||||||
|
counterpart anywhere to actually see what it created. One entry per `Shipment` record (a multi-box
|
||||||
|
Box Now order shows one entry per parcel), rendered as two inline-labelled lines — carrier +
|
||||||
|
tracking reference, then status + a "Created … · Locker …" helper line — rather than a grid of
|
||||||
|
individually stacked label/value blocks, which reads as a wall of repeated labels once the admin's
|
||||||
|
main content area narrows below Filament's own grid breakpoint (1024px, common with the sidebar
|
||||||
|
open). Two actions per shipment: "Print Label" and "Cancel". Also added `Modules\Core\Shipping\
|
||||||
|
Http\Controllers\DownloadShipmentLabelController` (short-lived signed URL, same auth model as
|
||||||
|
Lunar's own vendor order-PDF download) — the only other place that called
|
||||||
|
`CarrierFulfillmentInterface::printLabel()` (`ManagePickupManifests`' bulk "Print" action)
|
||||||
|
discarded the returned bytes entirely; this is the first place in the codebase that actually
|
||||||
|
delivers a label to staff. Hit and fixed two bugs while wiring this up: a `TextEntry` with a blank
|
||||||
|
`state('')` skips rendering its `suffixActions()` entirely (Filament's own empty-state branch
|
||||||
|
returns before reaching the actions markup), so the label-download entry needed a real,
|
||||||
|
non-blank value; and the label-download route, registered via `loadRoutesFrom()` with no
|
||||||
|
middleware group, had `SubstituteBindings` never run, so a type-hinted `Shipment $shipment`
|
||||||
|
parameter silently resolved to an empty, non-existent model instead of 404ing — fixed by taking a
|
||||||
|
plain `int $shipment` and looking the record up directly in the controller.
|
||||||
|
- `Modules\Core\Shipping\Enums\TrackingStatus::Failed` — previously unused — is now wired to the
|
||||||
|
new `delivery_failed` status via `Modules\Core\Order\Listeners\
|
||||||
|
MarkDeliveryFailedOnCarrierCheckpoint`, from which staff can retry dispatch or convert to a
|
||||||
|
return.
|
||||||
|
- Fixed a separate, unrelated bug hit while testing the above: `Lunar\Shipping\Models\
|
||||||
|
ShippingMethod::macro('isStorePickup', ...)` silently never registered — `Lunar\Base\Traits\
|
||||||
|
HasModelExtending::__callStatic()` (used by every `Lunar\Base\BaseModel` subclass that doesn't
|
||||||
|
declare its own `macro()`, `ShippingMethod` included) intercepts *every* unmatched static call
|
||||||
|
and dispatches it as an instance call instead of forwarding to `Macroable`, so `hasMacro()` always
|
||||||
|
returned `false` and every order was silently treated as carrier-fulfilled — including store-pickup
|
||||||
|
ones. `Order::isStorePickupOrder()` (the only caller) now reads `ShippingMethod.data
|
||||||
|
['fulfillment_type']` directly instead of going through the broken macro.
|
||||||
|
- `CartResource::getEloquentQuery()` no longer filters to carts with a known `user_id`/
|
||||||
|
`customer_id` — every cart is now listed, guest carts included. Reverses an earlier deliberate
|
||||||
|
exclusion (an anonymous cart has nothing a staff member could click into — no name, no email),
|
||||||
|
which held for that specific concern but not for the resource's other real use: seeing how many
|
||||||
|
carts are ongoing/abandoned right now. Most real storefront traffic never reaches an identified
|
||||||
|
user/customer, so excluding it silently undercounted exactly what `CartLifecycleService` exists
|
||||||
|
to report on. A guest row's Customer/User columns just render "—" (no link) rather than the row
|
||||||
|
being hidden.
|
||||||
|
- `CartLifecycleService::abandonedCarts()` now requires `whereHas('lines')` — an empty cart
|
||||||
|
(created but nothing ever added, e.g. a bot, or a session that never shopped) is no longer
|
||||||
|
counted as "abandoned." There's nothing to recover, so it was a false positive: 9 of 16 carts in
|
||||||
|
the "Abandoned Cart" tab during testing were empty. Removed the now-redundant post-hoc
|
||||||
|
`lines->isEmpty()` skip (and its `with('lines')` eager load) from `DetectAbandonedCarts`, since
|
||||||
|
the query itself excludes them now.
|
||||||
|
- `Modules\Core\Shipping\Models\Manifest` — a real record of "a manifest was issued", replacing the
|
||||||
|
loose `shipments.manifest_reference` string. ACS's own `ACS_Issue_Pickup_List` call returns
|
||||||
|
nothing beyond a `PickupList_No`, so there was previously no way to see which shipments were on a
|
||||||
|
given manifest, or when it was issued, once the moment passed — only per-shipment breadcrumbs.
|
||||||
|
`shipments.manifest_id` (FK, replacing `manifest_reference`) now links each shipment to the
|
||||||
|
`Manifest` row `AcsFulfillmentService::issueManifest()` creates; `ManifestResult::success()`
|
||||||
|
carries the created `Manifest` instead of a bare reference string. A one-time data migration
|
||||||
|
backfills a `Manifest` row per distinct existing `(carrier, manifest_reference)` pair, using the
|
||||||
|
earliest `label_printed_at` (or `updated_at`) among that group as a best-effort `issued_at`, since
|
||||||
|
the real issue time was never recorded anywhere.
|
||||||
|
- Split the standalone `Modules\Core\Shipping\Filament\Pages\ManagePickupManifests` page into two
|
||||||
|
real Filament resources — a bare `Page` has no access to Filament's resource-level pill-tab UI
|
||||||
|
(`HasTabs` is scoped to `ListRecords`), which carrier-by-carrier separation needed:
|
||||||
|
- `Modules\Core\Shipping\Filament\Resources\ShipmentResource` ("Pending Vouchers") — shipments not
|
||||||
|
yet on an issued manifest, one tab per carrier that implements `SupportsManifestBatching` (ACS
|
||||||
|
today; Box Now has no manifest concept at all — courier pickup is booked at shipment-creation
|
||||||
|
time — so it gets no tab). Adding a future carrier with its own manifest endpoints (e.g.
|
||||||
|
Speedex) needs zero UI changes here — tabs are derived from `Shipping::getSupportedDrivers()`,
|
||||||
|
not hardcoded.
|
||||||
|
- `Modules\Core\Shipping\Filament\Resources\ManifestResource` ("Issued Manifests") — lists issued
|
||||||
|
`Manifest` rows (also tabbed by carrier), with a view page and a `ShipmentsRelationManager`
|
||||||
|
showing which shipments a manifest included, each individually reprintable.
|
||||||
|
- Both bulk actions ("Print selected", "Issue Manifest") now catch `Throwable` around the actual
|
||||||
|
carrier API call and surface a Filament notification instead of an unhandled 500 — previously
|
||||||
|
neither had any error handling at all, so an `AcsApiException` (routine against a voucher/pickup
|
||||||
|
date the carrier no longer recognizes) crashed the whole page.
|
||||||
|
- Fixed a bug introduced while building this: `ViewManifest` initially overrode
|
||||||
|
`getRelationManagers()` directly instead of registering `ShipmentsRelationManager` via
|
||||||
|
`ManifestResource::getRelations()` (the actual wiring point —
|
||||||
|
`HasRelationManagers::getAllRelationManagers()` reads from `Resource::getRelations()`, not a
|
||||||
|
page-level override). The override bypassed the trait's own record-check/caching logic and
|
||||||
|
broke the relation manager's Livewire component mount, surfacing as a CSRF-token 419 redirect
|
||||||
|
loop specifically on `/boboko/manifests/{id}`.
|
||||||
|
- "Create Shipment"'s ACS branch gained a "Number of packages" field (`ShipmentRequest::
|
||||||
|
$packageCount`, already plumbed through to ACS's `Item_Quantity`/`persistMultipartVouchers()` but
|
||||||
|
never exposed in the form) — more than 1 issues a main voucher plus a multi-part sub-voucher per
|
||||||
|
extra package, each its own `Shipment` row sharing the same total weight. The existing weight
|
||||||
|
field was relabeled "Total weight (kg)" to make explicit that ACS bills by one total shipment
|
||||||
|
weight, not per package.
|
||||||
|
|
||||||
|
## [0.16.3] - 2026-09-10
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- Stripe `createAndConfirm()` built its `PaymentIntent` params with
|
||||||
|
`'automatic_payment_methods' => isset($data['payment_method']) ? null : ['enabled' => true]`. The
|
||||||
|
Stripe PHP SDK does not omit `null`-valued params from `create()` — it serializes them to an empty
|
||||||
|
string (`ApiRequestor::_encodeObjects()` → `Util::utf8(null)`), and Stripe's API rejects an empty
|
||||||
|
`automatic_payment_methods`. Every Stripe charge failed before it started whenever a
|
||||||
|
`payment_method` was supplied (i.e. every real charge in this flow). Fixed by building `$params`
|
||||||
|
conditionally so the key is either omitted entirely or set to `['enabled' => true]`, never `null`.
|
||||||
|
- `Modules\Core\Payment\Filament\Resources\PaymentMethodResource`'s "Driver status" column only
|
||||||
|
flagged a payment method whose driver *class* no longer resolves (`driver_missing_at`) — it gave
|
||||||
|
no indication when a driver resolves fine but fails `Configurable::isConfigured()` (e.g. Stripe
|
||||||
|
enabled in the DB with no `services.stripe.key` set), which `CheckoutService::getPaymentMethods()`
|
||||||
|
filters out identically. An admin had no way to tell "this method is silently absent at checkout
|
||||||
|
because of missing config" from "everything's fine" at a glance. The same icon column now also
|
||||||
|
reflects `isConfigured()`, with a tooltip distinguishing "driver not found" from "missing required
|
||||||
|
configuration" from "fully configured."
|
||||||
|
- `Modules\Core\Payment\Pipelines\Cart\ApplyCashOnDeliveryFee` (now `ApplyPaymentMethodFee`) had two
|
||||||
|
stacked bugs that together meant a configured payment-method fee (e.g. €5 on Cash on Delivery)
|
||||||
|
never actually reached the cart total:
|
||||||
|
- `PaymentMethod::where(...)->value('data->fee')` silently returned `null` on Postgres — Laravel's
|
||||||
|
query builder does not translate the `->` JSON-path column-selector syntax in `value()`/`pluck()`
|
||||||
|
the way it does inside `where()` clauses, so this resolved to a discarded
|
||||||
|
`stdClass::$data->fee` property access instead of the actual fee. Fixed by loading the model and
|
||||||
|
reading the cast `->data['fee']` attribute instead.
|
||||||
|
- Even with the fee correctly read, adding it directly to `$cart->shippingTotal` didn't survive:
|
||||||
|
`Lunar\Pipelines\Cart\CalculateTax`, which runs later in the same cart-calculation pipeline,
|
||||||
|
unconditionally recomputes `shippingTotal` (and shipping tax) from `$cart->shippingBreakdown`'s
|
||||||
|
item sum — silently discarding anything set only on the plain property. Fixed by adding the fee
|
||||||
|
as its own `Lunar\Base\ValueObjects\Cart\ShippingBreakdownItem` on `shippingBreakdown` instead,
|
||||||
|
so it survives `CalculateTax`'s recompute and is correctly included in shipping tax too.
|
||||||
|
- Also generalized while fixing: the pipeline was hardcoded to the literal type string
|
||||||
|
`cash-on-delivery`. Renamed to `ApplyPaymentMethodFee` and changed it to look up whichever
|
||||||
|
`PaymentMethod` row matches `Cart::meta['payment_method']` and apply its own `data.fee` if
|
||||||
|
present — works for any payment method configured with a fee, not just one specific slug.
|
||||||
|
- `Modules\Core\Checkout\Services\CheckoutService::selectPaymentMethod()` called `$cart->calculate()`
|
||||||
|
after saving the new payment method, but `Lunar\Models\Cart::calculate()` no-ops if the cart
|
||||||
|
instance was already calculated earlier in the same request (`Cart::isCalculated()`) —
|
||||||
|
`Lunar\Managers\CartSessionManager` memoizes one `Cart` instance per request, so this was true on
|
||||||
|
every request where the checkout page's initial render had already calculated the cart. The
|
||||||
|
result: after switching payment methods, the just-saved `meta['payment_method']` change was
|
||||||
|
persisted, but the cart's totals silently kept reflecting whichever method was calculated *first*
|
||||||
|
in the request — a shopper switching from Cash in Hand to Cash on Delivery would keep seeing Cash
|
||||||
|
in Hand's total, with no COD fee applied, until something else forced a fresh calculation. Fixed
|
||||||
|
by calling `$cart->recalculate()` instead, which forces the pipeline to re-run.
|
||||||
|
|
||||||
|
## [0.16.2] - 2026-09-09
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- `Lunar\Base\ShippingManifest` is a request-lifetime singleton whose `getOptions()` re-runs the
|
||||||
|
shipping modifier pipeline without ever clearing its `$options` collection first, and whose
|
||||||
|
`addOption()` keeps the first entry per `getIdentifier()` and silently drops any later one. In
|
||||||
|
practice, an option resolved for an earlier shipping address (or cart state) shadowed the
|
||||||
|
correct one after the address/region changed within the same request — e.g. a carrier priced
|
||||||
|
differently across two zones that both match an address would keep quoting the stale zone's
|
||||||
|
price, and `ApplyShipping` would price the cart total off that same stale option. Renamed
|
||||||
|
`Modules\Core\Shipping\Listeners\FlushLivePricingCache` to
|
||||||
|
`Modules\Core\Shipping\Listeners\InvalidateShippingOptions` and had it additionally call
|
||||||
|
`ShippingManifest::clearOptions()`, merged in because both invalidations fire on the exact same
|
||||||
|
event set (`CartLineAdded`, `CartLineUpdated`, `CartLineRemoved`, `CartCleared`,
|
||||||
|
`ShippingAddressSet`) — the only inputs the shipping modifier pipeline depends on.
|
||||||
|
|
||||||
|
## [0.16.1] - 2026-09-09
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- OTP login page (`resources/views/auth/filament/pages/login.blade.php`) had no visible spacing
|
||||||
|
between the email/OTP input, error text, and buttons following the Filament v3 → v4 upgrade.
|
||||||
|
The view relied on a bare `grid gap-y-4` Tailwind utility class, but since this view ships from
|
||||||
|
the `boboko-core` package rather than a consuming app, that class was never present in any
|
||||||
|
host app's compiled Tailwind output. Replaced with an inline `style` (flex column, `row-gap:
|
||||||
|
1rem`) so the layout no longer depends on the consuming app's Tailwind content scanning.
|
||||||
|
|
||||||
|
## [0.16.0] - 2026-09-08
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `Modules\Core\Checkout\Services\CheckoutService::setRecoveryConsent(bool $consent): Cart` — the
|
||||||
|
shopper's promotional/abandoned-cart-recovery opt-in, given once during guest checkout and
|
||||||
|
deliberately independent of `setShippingAddress()`/`setBillingAddress()`: consent is a
|
||||||
|
cart-level decision, not tied to any one `CartAddress` — changing which address is on the cart
|
||||||
|
later never resets or re-asks for it. Only an explicit call to this method (the checkbox itself
|
||||||
|
being submitted) ever changes it; calling it again with `false` is how a later opt-out is
|
||||||
|
recorded, per the legal requirement that consent be provable and withdrawable. Stored on
|
||||||
|
`Cart::meta` (interim, per the design this implements — a real column/consent record is the
|
||||||
|
eventual target, tracked as follow-up) as `recovery_consent` (bool), `recovery_consent_at`
|
||||||
|
(ISO 8601, `null` when `false`), and `recovery_consent_policy_version`
|
||||||
|
(`config('legal.privacy_policy_version')` at the moment of consent, so a later dispute is
|
||||||
|
answered from what was actually agreed to). Dispatches new
|
||||||
|
`Modules\Core\Checkout\Events\RecoveryConsentSet`. Newsletter opt-in is explicitly a separate
|
||||||
|
scope — never merged into this flag.
|
||||||
|
- `Modules\Core\Checkout\Services\CheckoutService::initiatePayment()` now requires `bool
|
||||||
|
$termsAccepted` and `string $policyVersion` as mandatory parameters (not optional data a caller
|
||||||
|
might omit) — throws the new `Modules\Core\Checkout\Exceptions\TermsNotAcceptedException`
|
||||||
|
*before* `Cart::createOrder()` is ever called if `$termsAccepted` is `false`, so an order can
|
||||||
|
never exist without a recorded acceptance (refused, not created-then-flagged). On success,
|
||||||
|
writes `terms_accepted` (`true`), `terms_accepted_at` (ISO 8601), and
|
||||||
|
`terms_accepted_policy_version` onto the created `Order`'s own `meta` — the durable,
|
||||||
|
order-level audit trail for a consumer-contract acceptance dispute, written directly (not via
|
||||||
|
an event/listener) since the `Order` row doesn't exist until `createOrder()` returns.
|
||||||
|
- `Modules\Core\Cart\Commands\DetectAbandonedCarts` — both its `CartAbandoned` and
|
||||||
|
`CheckoutAbandoned` detection queries now require `meta->recovery_consent = true`. A
|
||||||
|
non-consenting cart's abandonment is never dispatched at all (not merely filtered later at
|
||||||
|
whatever future recovery-email send step reads it) — the correct enforcement point per the
|
||||||
|
legal requirement that recovery/marketing sends only ever reach carts that opted in.
|
||||||
|
- `config/legal.php` (merged by a new `Modules\Core\Providers\CheckoutServiceProvider`) —
|
||||||
|
`privacy_policy_version`/`terms_version`, plain `env()`-backed strings bumped by whoever edits
|
||||||
|
the corresponding legal page. Recorded alongside every consent/acceptance rather than read live
|
||||||
|
at dispute time, so what a shopper actually agreed to is answered from the cart/order itself.
|
||||||
|
`CheckoutServiceProvider` itself is new — `Checkout` previously had no dedicated service
|
||||||
|
provider at all (its service/events were resolved/dispatched without one).
|
||||||
|
|
||||||
|
## [0.15.0] - 2026-09-07
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- **Breaking:** `Modules\Core\Payment\Models\PaymentMethod` is now the full DB-instance layer for
|
||||||
|
Payment, same three-layer split (registry / DB instance / cross-cutting config) `Shipping`
|
||||||
|
already has via `ShippingMethod` — see `docs/payments.md`. Every value that used to live in
|
||||||
|
`config('lunar.payments.types.{type}.*')` (`payment_driver`, `capture_mode`, `captured_status`)
|
||||||
|
moves onto the `PaymentMethod` row itself as real columns: `driver` (the new
|
||||||
|
`PaymentDriverRegistry` key — NOT the same as `type`; two rows can share one driver), `name`
|
||||||
|
(admin-facing label, nothing played this role before), `capture_mode`, `captured_status`,
|
||||||
|
`authorized_status`, `position` (admin-controlled ordering, new — reorderable in the Filament
|
||||||
|
table), `driver_missing_at`. `config('lunar.payments.types')` is gone entirely; `config/
|
||||||
|
payment.php` now holds only `cart_pipeline` (genuinely cross-cutting — every store gets the
|
||||||
|
same pipeline wiring regardless of how many payment methods it configures).
|
||||||
|
- **Breaking:** `Modules\Core\Payment\Services\PaymentDriverResolver` is deleted, replaced by
|
||||||
|
`Modules\Core\Payment\Services\PaymentDriverRegistry` — `register(string $key, string
|
||||||
|
$driverClass)`/`resolve(string $key): ?object`/`all(): array<string, string>`. Deliberately
|
||||||
|
knows nothing about `PaymentMethod` or the database (mirrors `Lunar\Shipping\Managers\
|
||||||
|
ShippingManager`'s built-in-methods + `Manager::extend()` split, purpose-built rather than
|
||||||
|
extending `Illuminate\Support\Manager` — Payment's drivers implement several independent
|
||||||
|
capability interfaces at once, not one uniform contract). Built-ins (`OfflinePaymentDriver`
|
||||||
|
as `'offline'`, `StripePaymentDriver` as `'stripe'`) registered in
|
||||||
|
`PaymentServiceProvider::boot()`, exactly how `Shipping::extend('acs', ...)` already works.
|
||||||
|
- **Breaking:** `Modules\Core\Checkout\Services\CheckoutService::getPaymentMethods()` now returns
|
||||||
|
`Illuminate\Support\Collection<int, PaymentMethod>` (ordered by `position`), not
|
||||||
|
`array<string>`. A method is offered only once three independent checks all pass — `enabled`
|
||||||
|
(admin turned it on), `driver_missing_at` is null (the driver class still exists), and the
|
||||||
|
resolved driver's own `Configurable::isConfigured()` (its runtime requirements are met) — each
|
||||||
|
failure meaning something different to an admin diagnosing why a method isn't showing up.
|
||||||
|
`initiatePayment()` resolves the driver via the selected row's own `driver` column, not `type`.
|
||||||
|
- `Modules\Core\Payment\Filament\Resources\PaymentMethodResource` — `canCreate()`/`canDelete()`
|
||||||
|
now both `true` (previously hardcoded `false`, since a row could only ever be a config-defined
|
||||||
|
type before this release). New create/edit form (`name`, `type`, `driver` — a `Select`
|
||||||
|
populated live from `PaymentDriverRegistry::all()`, `capture_mode`, `captured_status`,
|
||||||
|
`authorized_status`); reorderable table (`->reorderable('position')`); a distinct "Driver
|
||||||
|
status" icon column (separate from the `enabled` toggle) showing whether `driver_missing_at`
|
||||||
|
is set.
|
||||||
|
- `Modules\Core\Order\Listeners\ApplyResolvedPaymentStatus` reads `captured_status`/
|
||||||
|
`authorized_status` off the `PaymentMethod` row (`where('type', $event->type)`) instead of
|
||||||
|
`config(...)`.
|
||||||
|
- `Modules\Core\Command\InstallLunarCommand::seedPaymentMethods()` no longer iterates
|
||||||
|
`config('lunar.payments.types')` — it seeds exactly one opinionated `cash-on-delivery` starter
|
||||||
|
row, every value a plain literal in the command itself (not sourced from config or the
|
||||||
|
registry — a driver has no business carrying opinions about what its captured order status
|
||||||
|
should be called; that's a merchant decision). Skip-if-exists, same as before.
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `php artisan boboko:payment:sync-drivers` — reconciles every `PaymentMethod` row's `driver`
|
||||||
|
against `PaymentDriverRegistry`, setting `driver_missing_at` when a driver no longer resolves
|
||||||
|
(a package removed, a custom `register()` call deleted) and clearing it automatically if that
|
||||||
|
driver is registered again in a later deploy. Deliberately its own standalone command, meant to
|
||||||
|
run unconditionally on every container start/deploy (Dockerfile entrypoint, alongside
|
||||||
|
`migrate`) — "did the set of registered drivers change" is a deploy-time event, cheap enough to
|
||||||
|
check every time regardless of whether anything actually changed. Verified live: flags a row
|
||||||
|
whose `driver` was manually corrupted, and auto-clears the flag once the driver resolves again.
|
||||||
|
- `docs/payments.md` — new "Registry, DB instance, and cross-cutting config" section: the
|
||||||
|
three-layer split researched against `Shipping`'s own already-existing pattern and three real
|
||||||
|
e-commerce platforms (Shopify, WooCommerce, Medusa.js), the "would a store ever plausibly want
|
||||||
|
two different answers to this" test for deciding config vs. DB-column placement, and the
|
||||||
|
three-check availability chain.
|
||||||
|
|
||||||
|
- `Modules\Core\Payment\Services\PaymentMethodCache` (`Cache::rememberForever`, same pattern as
|
||||||
|
`Localization\Services\LanguageCache`) + `Modules\Core\Payment\Services\PaymentMethodService`
|
||||||
|
(`create`/`update`/`delete`/`list`) — the single read/write gateway for `PaymentMethod` now used
|
||||||
|
by every Filament resource action (create, edit, edit-fee, delete, the inline `enabled` toggle)
|
||||||
|
instead of the Eloquent model directly, so the cache is invalidated and
|
||||||
|
`PaymentMethodCreated`/`PaymentMethodUpdated`/`PaymentMethodDeleted`/`PaymentMethodsReordered`
|
||||||
|
dispatch on every write, with no exceptions other than Filament's own drag-to-reorder (which
|
||||||
|
does a raw bulk SQL `UPDATE` on the position column directly via
|
||||||
|
`CanReorderRecords`/`reorderTable()`, before `afterReordering()` fires — a confirmed, unavoidable
|
||||||
|
Filament limitation; the reorder hook only clears the cache and dispatches
|
||||||
|
`PaymentMethodsReordered` afterward). `CheckoutService::getPaymentMethods()` and
|
||||||
|
`ApplyResolvedPaymentStatus` both now read through the cache instead of querying `PaymentMethod`
|
||||||
|
directly.
|
||||||
|
- `Modules\Core\Payment\Models\CoreTransaction` (a `Lunar\Models\Transaction` subclass) +
|
||||||
|
`Modules\Core\Payment\Support\TransactionDriverAdapter`, registered via
|
||||||
|
`Lunar\Facades\ModelManifest::replace(Lunar\Models\Contracts\Transaction::class,
|
||||||
|
CoreTransaction::class)` — the same contract-swap mechanism already used elsewhere for
|
||||||
|
`Customer`/`Staff`. Fixes a real crash (`InvalidArgumentException: Driver [cash-on-delivery] not
|
||||||
|
supported`) the first time anything called `$transaction->refund()`/`->capture()`:
|
||||||
|
`Lunar\Models\Transaction::driver()` calls Lunar's own, entirely separate
|
||||||
|
`Lunar\Facades\Payments::driver()` manager, which had never heard of any of this codebase's
|
||||||
|
driver keys. `CoreTransaction::driver()` returns `TransactionDriverAdapter` instead, which
|
||||||
|
resolves the transaction's real `PaymentMethod`/`PaymentDriverRegistry` driver and calls it —
|
||||||
|
Lunar's own admin panel "Refund"/"Capture" buttons now transparently reach the real payment
|
||||||
|
system underneath, including correctly reporting failure (not a silently-faked success) when
|
||||||
|
the resolved driver doesn't implement `SupportsRefunds`/`SupportsCaptures`.
|
||||||
|
- `TransactionDriverAdapter::refundVia(Transaction $transaction, ?string $driverKey, int $amount,
|
||||||
|
?string $notes = null)` — refund through an explicitly chosen driver, independent of the one
|
||||||
|
the original payment went through (e.g. a cash-on-delivery order refunded via Bank Transfer,
|
||||||
|
which has no notion of the original offline payment at all). The order page's refund action
|
||||||
|
gained a "Refund via" `Select` (every `PaymentDriverRegistry` driver implementing
|
||||||
|
`SupportsRefunds`, defaulting to the transaction's own driver) that routes through this method
|
||||||
|
instead of `Lunar\Models\Transaction::refund()`, whose fixed signature has no room for a driver
|
||||||
|
override.
|
||||||
|
- `Modules\Core\Payment\Drivers\BankTransferPaymentDriver` (registered as `'bank-transfer'`) —
|
||||||
|
manual/attested, same trust model as `OfflinePaymentDriver`: no gateway call, `pay()`/`refund()`
|
||||||
|
decide success immediately on a staff member's say-so. Implements both `SupportsPay` and
|
||||||
|
`SupportsRefunds`; exists specifically so a payment taken through a different method can still
|
||||||
|
be refunded via bank transfer. The admin UI for receiving a payment this way (bank reference,
|
||||||
|
notes, proof-of-transfer upload) is a follow-up — the driver itself is complete and usable via
|
||||||
|
the registry today.
|
||||||
|
- `Modules\Core\Order\Filament\Infolists\TransactionEntry` (swapped in for Lunar's own
|
||||||
|
`Lunar\Admin\Support\Infolists\Components\Transaction` via a new
|
||||||
|
`OrderTransactionsExtension::extendTransactionsRepeatableEntry()` hook) — the order page's
|
||||||
|
transaction cards now also show a note recorded in `Transaction.meta['notes']` when the `notes`
|
||||||
|
column itself is empty. `Order\Services\TransactionRecorder` only ever wrote `notes` from
|
||||||
|
`PaymentResult::$failureReason`, which is never set on a successful result — a manual driver's
|
||||||
|
staff-entered note (e.g. `BankTransferPaymentDriver`'s) was being recorded but had nowhere to
|
||||||
|
render.
|
||||||
|
- `Modules\Core\Payment\Listeners\LogPaymentMethodActivity` — `PaymentMethod` now has an admin
|
||||||
|
activity trail, unlike `Order`/`Transaction`/`Staff` it previously had none. Routes
|
||||||
|
`PaymentMethodCreated`/`Updated`/`Deleted` through the existing `Logging\ActivityLogService`
|
||||||
|
(the same one `Localization\Listeners\LogTranslationActivity` already uses) rather than adding
|
||||||
|
`PaymentMethod` to `Lunar\Base\Traits\LogsActivity`'s generic model-observer logging —
|
||||||
|
`PaymentMethodUpdated::$old`/`PaymentMethodDeleted::$method`'s snapshot already carry more
|
||||||
|
deliberate before/after context than Eloquent's own dirty-attribute diffing would reconstruct.
|
||||||
|
`PaymentMethodsReordered` is deliberately NOT logged — a multi-row position change doesn't fit
|
||||||
|
`ActivityLogService`'s one-`Model`-subject shape, and isn't worth a new method for a low-stakes,
|
||||||
|
purely-cosmetic setting.
|
||||||
|
- New `payment_methods.refunded_status` column + form field (same `Select` pattern as
|
||||||
|
`captured_status`/`authorized_status`) — `ApplyResolvedPaymentStatus` now also reacts to
|
||||||
|
`PaymentRefunded`, so `Order.status` actually changes on a refund; before this, only the
|
||||||
|
*derived* `Order::paymentStatus()` reflected a refund (reading `transactions` live), while the
|
||||||
|
stored `status` column — what admin filtering, customer emails, etc. actually key off — never
|
||||||
|
moved. Resolves the ORIGINAL payment method for this lookup, not the refund event's own
|
||||||
|
`$type`: a refund routed through a different driver via `refundVia()` (e.g. cash-on-delivery
|
||||||
|
refunded through Bank Transfer) carries the REFUND driver's registry key as `$event->type`,
|
||||||
|
which usually isn't even a real `PaymentMethod.type` — the listener now finds the order's
|
||||||
|
earliest successful `capture`/`intent` transaction instead and reads `refunded_status` off
|
||||||
|
*that* transaction's own `PaymentMethod` row, since that's the payment the refund is actually
|
||||||
|
reversing. Deliberately no `void_status` yet — a void never moved money, so it doesn't carry
|
||||||
|
the same "the customer needs to see this changed" weight a refund does.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- Existing `PaymentMethod` rows seeded before this release (`cash-on-delivery`, `cash-in-hand`)
|
||||||
|
had `driver`/`capture_mode`/`captured_status` all `NULL` after the migration ran — a data
|
||||||
|
backfill was required (not automated by the migration itself) to restore them to a resolvable
|
||||||
|
state; flagged here since a consuming app upgrading past this release needs the same backfill
|
||||||
|
for its own pre-existing rows before `getPaymentMethods()` will offer them again.
|
||||||
|
- `Lunar\Admin\Filament\Resources\OrderResource\Pages\ManageOrder::getRefundAction()`/
|
||||||
|
`getCaptureAction()` and `OrderItemsTable::getBulkRefundAction()` report a failed refund/capture
|
||||||
|
by calling `$action->failureNotification(...)`, `$action->failure()`, then `$action->halt()` —
|
||||||
|
but `Filament\Actions\Concerns\InteractsWithActions::callMountedAction()` only ever sends that
|
||||||
|
notification from a code path that runs after the action's closure returns normally; `halt()`
|
||||||
|
throws `Filament\Support\Exceptions\Halt`, caught by an earlier `catch` block that rolls back and
|
||||||
|
returns, so the notification was built but never sent — clicking "Refund" on a payment method
|
||||||
|
that genuinely can't be refunded looked like nothing happened at all, no error, no toast. Real,
|
||||||
|
pre-existing Filament/Lunar bug, invisible until this release's `TransactionDriverAdapter` made
|
||||||
|
an honest failure (rather than a hard crash or a silently-faked success) actually reachable.
|
||||||
|
Fixed via new `Modules\Core\Order\Filament\Extensions\OrderRefundActionsExtension`/
|
||||||
|
`OrderItemsTableExtension`, which wrap the affected actions' closures to send the queued failure
|
||||||
|
notification themselves before re-throwing `Halt`.
|
||||||
|
- `TransactionDriverAdapter::refund()`/`capture()` never included `order_id` in the `$context`
|
||||||
|
passed to the driver, so `Order\Listeners\RecordPaymentTransaction`/`ApplyResolvedPaymentStatus`
|
||||||
|
(both requiring `$context['order_id']`) silently no-op'd for every admin-initiated refund/capture
|
||||||
|
through any driver — no audit `Transaction` row was ever created, regardless of whether the
|
||||||
|
refund/capture itself succeeded. Fixed by passing `$transaction->order_id` through.
|
||||||
|
|
||||||
|
## [0.14.0] - 2026-09-03
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- **Breaking:** `Modules\Core\Catalog\Services\ProductSearchService::search()` now returns `Modules\Core\Catalog\DTOs\ProductListingResult` — the exact same shape `ProductService::list()` already returns — instead of a bare `Illuminate\Database\Eloquent\Collection<Product>` of hydrated models with no pagination at all. New signature: `search(string $query, ?ProductFilters $filters = null, ?ProductSort $sort = null, int $perPage = 24, int $page = 1): ProductListingResult`. `->products` is a real `LengthAwarePaginator` of plain, localized indexed-document arrays (not Eloquent models, not Scout's raw response) — a search results page and a category listing page are now interchangeable from a controller's perspective: same DTO, same `ProductCard::fromIndexed()` mapping, same pagination/sort/tag/price-slider handling. `->priceBounds`/`->availableTags` are scoped to the search query itself (delegated to `ProductService::priceSliderBounds()`/`availableTags()`, both of which already accepted a `$query` param for this).
|
||||||
|
- `Modules\Core\Catalog\Services\ProductService::availableTags()` is now `public` (was `private`) and takes an optional `$query` parameter, so `ProductSearchService::search()` can reuse it directly instead of reimplementing the same facet call.
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `Modules\Core\Catalog\Support\ProductDocumentLocalizer` — the per-locale field resolution and raw-Meilisearch-response unwrapping (`withLocalizedFields()`, `hitsFrom()`) extracted out of `ProductService` into its own class, since `ProductSearchService` needed the exact same logic against the exact same kind of document. Both services now depend on this one class instead of `ProductService` owning logic a second service also needed.
|
||||||
|
|
||||||
|
## [0.13.0] - 2026-09-03
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- **Breaking:** `Payment` is now a genuinely standalone module — no direct calls into `Checkout`/`Order`, no reaching into their Eloquent models, communication only via events. The entire old `confirm()`-based flow is gone: `Modules\Core\Payment\Contracts\PaymentDriver` (and the already-stale `Modules\Core\Checkout\Contracts\PaymentDriver` duplicate), `Checkout\Events\PaymentConfirmed`, `Payment\Contracts\InitiatesPayment`, `Payment\DataTransferObjects\PaymentInitiation`, `Payment\Enums\PaymentInitiationMode`, `Payment\Events\PaymentSucceeded`/`PaymentFailed`, `Payment\Events\OrderPaymentStatusResolved`, and `Payment\Exceptions\PaymentNotConfirmedException` are all deleted. This flow was non-functional on `master` before this release — `CheckoutService::confirmPayment()` dispatched an event nothing listened for, so no order was ever placed after payment.
|
||||||
|
- **Breaking:** Every payment operation is now its own explicit, opt-in contract, modeled on how real gateways (Stripe, Mastercard's own gateway, Nexi) actually split these operations — see `docs/payments.md`: `Modules\Core\Payment\Contracts\SupportsPay` (atomic authorize+capture), `SupportsAuthorization` (hold only), `SupportsCaptures` (settle a prior hold), `SupportsVoids` (release a prior hold without settling), `SupportsRefunds` (reverse settled funds), `HandlesPaymentCallback` (resolve an async pay()/authorize() later, from a webhook), and `Configurable` (`isConfigured()`, split out of the old single `PaymentDriver` interface). A driver implements only the operations its gateway actually supports.
|
||||||
|
- **Breaking:** Every amount flowing through these contracts is `Lunar\DataTypes\Price` (Lunar's own bundled minor-unit-value + `Currency` type) — never a bare `int` paired separately with a `Currency`. Each driver converts at its own boundary (e.g. `StripeManager::toStripeAmount()`/`fromStripeAmount()`); `Payment` itself only ever speaks Lunar's `Price`.
|
||||||
|
- **Breaking:** `Modules\Core\Checkout\Services\CheckoutService::placeOrder()` and `confirmPayment()` are both replaced by a single `initiatePayment(string $fingerprint, array $data = []): Modules\Core\Payment\DTOs\PaymentResult`. It creates the draft `Order` (`Cart::createOrder()`, idempotent against an existing draft) and hands off directly to the resolved driver's `pay()`/`authorize()`, per that type's new `config('lunar.payments.types.{type}.capture_mode')` key. `Checkout\Events\OrderPlaced` no longer dispatches from `CheckoutService` — it now fires from `Modules\Core\Order\Listeners\ApplyResolvedPaymentStatus` once a `PaymentCaptured`/`PaymentAuthorized` event actually transitions the order's `placed_at`, since a draft order can now exist well before payment resolves (an async gateway).
|
||||||
|
- `Modules\Core\Payment\Services\PaymentDriverResolver::resolve()` now returns `?object` instead of the deleted `PaymentDriver` interface — a driver implements several independent capability interfaces at once, so a caller does its own `instanceof SupportsPay`/`instanceof SupportsAuthorization` check, the same pattern the capability interfaces themselves are designed around.
|
||||||
|
- `config/payment.php`'s `cash-on-delivery` entry gains `capture_mode` (`'pay'`, since `OfflinePaymentDriver` only implements `SupportsPay`) and `captured_status` (`'payment-offline'`, replacing the previously dead `'authorized' => 'awaiting-payment'` key, which nothing ever read).
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `Modules\Core\Payment\DTOs\PaymentResult` — the one return shape every operation (`pay`, `authorize`, `capture`, `void`, `refund`, `handleCallback`) produces, regardless of gateway: `status` (`Modules\Core\Payment\Enums\PaymentResultStatus`: `Succeeded`/`Failed`/`Pending`), `reference`, `amount` (a `Price`), `failureReason`, `retriable` (real on Stripe/Mastercard's own soft-decline classification, always `false` on Nexi — it has no such signal), `raw` (the untouched gateway response, for audit), `meta`, and `continuation` (see below).
|
||||||
|
- `Modules\Core\Payment\DTOs\PaymentContinuation` / `Modules\Core\Payment\Enums\PaymentContinuationType` — what a caller does next with a `Pending` `PaymentResult`, gateway-agnostically (`Redirect` or `ClientSecret`), so a storefront controller never needs gateway-specific knowledge of e.g. Stripe's own `PaymentIntent` fields to drive a 3-D Secure/redirect continuation.
|
||||||
|
- Eight new events, one terminal pair per operation, replacing the old single `PaymentSucceeded`/`PaymentFailed`: `PaymentAuthorized`/`PaymentAuthorizationFailed`, `PaymentCaptured`/`PaymentCaptureFailed`, `PaymentVoided`/`PaymentVoidFailed`, `PaymentRefunded`/`PaymentRefundFailed`. `PaymentCaptured` is deliberately the same event whether money was taken via `pay()` (one gateway call) or `authorize()`→`capture()` (two calls) — "a payment has been captured" is the same business fact either way. Every event carries `{type, result: PaymentResult, context}` — `context` is an opaque bag the caller hands in and gets back untouched, so `Payment` never needs to know what a `Cart` or `Order` is.
|
||||||
|
- `Modules\Core\Order\Listeners\ApplyResolvedPaymentStatus` (rewired, not new — previously listened to the now-deleted `OrderPaymentStatusResolved`) is the only place an `Order`'s `status` column is written in reaction to a payment outcome: it listens to `PaymentCaptured`/`PaymentAuthorized` directly, reads `$event->context['order_id']`, and resolves the new status from `config('lunar.payments.types.{type}.captured_status')`/`authorized_status`.
|
||||||
|
- `Modules\Core\Payment\Drivers\StripePaymentDriver` rewritten onto the new contracts — implements all six capability interfaces plus `Configurable`. Solves `handleCallback()`'s async-correlation problem (a webhook is a separate HTTP request from the `pay()`/`authorize()` call that started it) the same way `lunarphp/stripe`'s own `StripePaymentType`/`ProcessStripeWebhook` do: real `cart_id`/`order_id` columns on `Lunar\Stripe\Models\StripePaymentIntent`, plus two new columns this driver needs (`context`, `payment_type`) added by a new migration — `database/migrations/2026_09_03_000002_add_context_to_stripe_payment_intents.php`.
|
||||||
|
- `Modules\Core\Payment\Http\Controllers\StripeWebhookController` + `src/Payment/routes/webhooks.php` (`POST /payments/stripe/webhook`, loaded by `PaymentServiceProvider`) — a boboko-owned webhook endpoint, deliberately not `lunarphp/stripe`'s own route (which dispatches into Lunar's own `Payments::driver('stripe')` flow, the flow this driver replaces). Reuses `Lunar\Stripe\Http\Middleware\StripeWebhookMiddleware` and `Stripe\Webhook::constructEvent()` directly — both are genuine Stripe SDK signature verification, safe to reuse without touching the rest of that vendor package's flow. Requires `config('services.stripe.webhooks.lunar')` set in a consuming app; no `stripe` config type entry is added to `config/payment.php` in this release — enabling Stripe for real is a follow-up.
|
||||||
|
- `docs/payments.md` — full design notes: the operation/contract table cross-referenced against Mastercard/Stripe/Nexi's real APIs, why `PaymentResult` normalizes only what every gateway can always provide, the async-correlation pattern, and what's explicitly out of scope (a `Transaction`-writing listener, the `stripe` config entry, frontend Stripe Elements integration).
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- `Modules\Core\Checkout\Services\CheckoutService::selectPaymentMethod()` crashed (`Call to a member function toArray() on null`) the first time it ran against a cart whose `meta` column was still a genuine SQL `NULL` (any freshly-created cart) — `Cart::$meta`'s `AsArrayObject` cast returns `null`, not an empty array-like object, for a `null` column. Fixed with a null-safe fallback.
|
||||||
|
- `Modules\Core\Shipping\Carriers\Acs\AcsRateDriver`/`BoxNowRateDriver` referenced `Lunar\Shipping\DTOs\ShippingOptionRequest`, a namespace that doesn't exist in the installed `lunarphp/table-rate-shipping` version (the real class is `Lunar\Shipping\DataTransferObjects\ShippingOptionRequest`) — crashed `Illuminate\Support\Manager`'s interface-compatibility check the moment anything touched `ShippingManager::getSupportedDrivers()`, including simply adding a line to a cart (via `Modules\Core\Shipping\Listeners\FlushLivePricingCache`).
|
||||||
|
|
||||||
|
## [0.13.1] - 2026-09-03
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `Modules\Core\Order\Listeners\RecordPaymentTransaction` — writes the `lunar_transactions` row for a successful `PaymentCaptured`/`PaymentAuthorized`/`PaymentVoided`/`PaymentRefunded` event, via a new `Modules\Core\Order\Services\TransactionRecorder` (moved here from `Payment\Services`, and rewritten to take a `PaymentResult` directly instead of the deleted `CaptureResult`/`RefundResult` DTOs — `Payment` never writes to `Order`'s models, `Transaction.order_id` being required is exactly why this lives in `Order`, same reasoning as `ApplyResolvedPaymentStatus`). Closes a real gap introduced in `0.13.0`: `Order::paymentStatus()` (which derives its answer entirely from `$order->transactions`) always resolved to `PaymentStatus::Offline` — its "no transactions at all" fallback — regardless of what actually happened, since nothing had ever written a row. Verified live: a captured offline payment now produces a `type: capture` transaction and `Order::paymentStatus()` correctly resolves to `captured`.
|
||||||
|
|
||||||
|
## [0.12.1] - 2026-09-03
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- `Modules\Core\MigrateImport\Shopify\ShopifyExportImporter` now attaches a variant's `Variant Image` CSV column to that `ProductVariant`'s own `images()` media pivot (`media_product_variant`, `primary`/`position`). Previously the variant image was never read at all — every image from the CSV, including ones the export clearly scopes to one specific variant, went only into the product's own top-level gallery, so a variant swatch/option change had no way to show its own photo.
|
||||||
|
- `Modules\Core\MigrateImport\Shopify\Resolvers\ProductOptionResolver::resolveOption()` now sets `label` (same value as `name`) when creating a `Lunar\Models\ProductOption`, not just `name`. A `ProductOption` with a null `label` crashes Lunar's own `ProductOptionIndexer::toSearchableArray()` (`foreach()` on `null`) the moment that option gets reindexed — every option created by the importer before this fix has a null `label` and needs a wipe-and-reimport (see `docs/shopify-reimport.md`, new in this release) to pick up the fix, since `firstOrCreate()` never revisits an already-existing row.
|
||||||
|
- `product_reviews.product_id`'s foreign key had no `ON DELETE` clause, so deleting a reviewed `Product` threw a constraint violation instead of the review going with it, unlike every other product-dependent table. New migration adds `cascadeOnDelete()`.
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `Modules\Core\Catalog\Services\ProductIndexer::mapVariant()` now embeds `gtin`, `mpn`, `ean`, `backorder`, `unit_quantity`, `shippable`, `tax_ref`, and `dimensions` (length/width/height/weight/volume, each with `value`+`unit`) on every indexed variant — previously only `id`/`sku`/`stock`/`purchasable`/`options`/`prices`/`media` were embedded, so a search result or filter needing any of these had no way to get at them without a separate Postgres query per variant.
|
||||||
|
- `ProductIndexer::toSearchableArray()` adds a top-level, filterable `skus` field (every variant's SKU, deduplicated) — filtering/matching by SKU no longer requires reaching into the nested `variants` array.
|
||||||
|
- `docs/shopify-reimport.md` — runbook for wiping every imported product (cascading through Lunar so Meilisearch documents go too) and re-running the importer from scratch, needed whenever a fix like the two above only takes effect on newly-created rows.
|
||||||
|
|
||||||
|
## [0.12.0] - 2026-09-03
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- **Breaking:** `Modules\Core\Catalog\Services\ProductService::list()` now returns `Modules\Core\Catalog\DTOs\ProductListingResult` (`->products`: the same `Illuminate\Pagination\LengthAwarePaginator` as before, `->priceBounds`: a new `Modules\Core\Catalog\DTOs\PriceSliderBounds`) instead of returning the paginator directly. A caller doing `$service->list(...)->items()`/`->through(...)` must update to `$service->list(...)->products->items()`/`->through(...)`. This collapses what used to be two separate calls a controller had to orchestrate itself (`list()` for products, `priceRange()` + manual floor/ceil/"is this actually filtered" math for the slider) into one.
|
||||||
|
- **Breaking:** `Modules\Core\Catalog\Services\ProductSearchService::search()`'s signature changed from `search(string $query, ?string $locale = null)` to `search(string $query, ?ProductFilters $filters = null, ?ProductSort $sort = null)` — the `$locale` parameter is gone (see "every configured language, always" below); `$filters`/`$sort` apply the same `Modules\Core\Catalog\Support\ProductFilterBuilder`/`ProductSort::toMeilisearchSort()` semantics `ProductService::list()` already used, so a text search can now be narrowed by price/brand/stock and sorted the same way a category listing can.
|
||||||
|
- `ProductSearchService` now targets every configured store language's fields on every search (`Lunar\Models\Language::all()`), not just the current request locale plus the store's default language. The old `{current, default}` pairing silently stopped catching anything outside those two locales whenever they were equal (a single-language store, or a shopper browsing in the default language) — always searching every configured language closes that gap in both directions. See `docs/product-search.md`.
|
||||||
|
- Extracted `Modules\Core\Catalog\Services\ProductService`'s private `buildFilter()` into a new standalone `Modules\Core\Catalog\Support\ProductFilterBuilder`, so `ProductSearchService` can apply the exact same Meilisearch filter-clause semantics to a text query, instead of reimplementing filter-building a second time.
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `Modules\Core\Catalog\Services\ProductService::priceSliderBounds()` — `priceRange()` rounded to whole currency units (floor/ceil) plus whether the given selected min/max actually narrows it, returned as a `PriceSliderBounds` DTO. Used internally by `list()` now; also callable directly for a caller (e.g. a text-search results page) that needs slider bounds without a full `list()` call.
|
||||||
|
- `Modules\Core\Catalog\Services\ProductService::priceRange()` gained an optional `string $query = ''` parameter, so a caller can scope the price range to a text search's own matches (pass the shopper's search text) instead of always spanning the whole catalog.
|
||||||
|
- `Modules\Core\Catalog\Services\ProductService::random(int $limit)` — random products still scoped to the Meilisearch index's own channel/status visibility, unlike a raw `Product::inRandomOrder()` (which has no notion of that filtering). Meilisearch has no `ORDER BY RANDOM()` equivalent, so this fetches every matching id only (`attributesToRetrieve: ['id']`), shuffles in PHP, then fetches the full localized documents for just the ids picked, restoring the shuffled order afterward (Meilisearch's `id IN [...]` filter doesn't preserve list order on its own).
|
||||||
|
- `Modules\Core\Catalog\Services\ProductService::variantSummaries(array $product)` — the id/price/image of every variant on a product document, for a variant picker/swatch list, without a caller reaching into `$product['variants'][n]['prices'][0]`/`['media'][0]` itself.
|
||||||
|
- `Modules\Core\Catalog\Services\ProductSearchService::search()` now also targets `variants.options.value` — a variant's own option value (e.g. "Κάπτεν Γαμέρικα" on a "Name" option) is matchable by search even when that text never appears in the product's own name or description.
|
||||||
|
- `php artisan lunar:meilisearch:tune-product-search` (`Modules\Core\Command\TuneProductSearchCommand`) — tightens `minWordSizeForTypos` (1 typo only at 8+ characters, 2 typos only at 12+) and disables Meilisearch's `prefixSearch` on the product index. Meilisearch's defaults for both were loose enough to produce bad matches on short Greek words (confirmed the specific case was `prefixSearch`'s default `indexingTime` behavior on a shared word-start, not typo tolerance, via `showMatchesPosition`). Consuming apps should run this after `lunar:meilisearch:setup` whenever the product index needs (re)provisioning — **requires Meilisearch v1.12+** (`prefixSearch` didn't exist as a configurable setting before then).
|
||||||
|
|
||||||
|
## [0.11.1] - 2026-09-01
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- `Modules\Core\Catalog\Services\RecommendationService::recommend()` built its result with the base `Illuminate\Support\Collection` (`collect()`) instead of `Illuminate\Database\Eloquent\Collection`, even though every element is a `Product` model. `ProductIndexer::toSearchableArray()` calling `->load(['media', 'variants.prices'])` on that result threw `BadMethodCallException: Method Illuminate\Support\Collection::load does not exist` — silently failing every `MakeSearchable` queue job for a saved product (visible only as `FAIL` in the queue log, with the real exception in `storage/logs/laravel.log`). Fixed by having `RecommendationService` accumulate into a real `Eloquent\Collection` from the start.
|
||||||
|
|
||||||
## [0.11.0] - 2026-09-01
|
## [0.11.0] - 2026-09-01
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|||||||
+4
-2
@@ -2,7 +2,7 @@
|
|||||||
"name": "boboko/core",
|
"name": "boboko/core",
|
||||||
"description": "Core module — authentication and shared panel behaviour",
|
"description": "Core module — authentication and shared panel behaviour",
|
||||||
"type": "library",
|
"type": "library",
|
||||||
"version": "0.11.0",
|
"version": "0.17.0",
|
||||||
"autoload": {
|
"autoload": {
|
||||||
"psr-4": {
|
"psr-4": {
|
||||||
"Modules\\Core\\": "src/"
|
"Modules\\Core\\": "src/"
|
||||||
@@ -37,12 +37,14 @@
|
|||||||
"Modules\\Core\\Providers\\CoreServiceProvider",
|
"Modules\\Core\\Providers\\CoreServiceProvider",
|
||||||
"Modules\\Core\\Providers\\AuthServiceProvider",
|
"Modules\\Core\\Providers\\AuthServiceProvider",
|
||||||
"Modules\\Core\\Providers\\CustomerServiceProvider",
|
"Modules\\Core\\Providers\\CustomerServiceProvider",
|
||||||
|
"Modules\\Core\\Providers\\CheckoutServiceProvider",
|
||||||
"Modules\\Core\\Providers\\PaymentServiceProvider",
|
"Modules\\Core\\Providers\\PaymentServiceProvider",
|
||||||
"Modules\\Core\\Providers\\LocalizationServiceProvider",
|
"Modules\\Core\\Providers\\LocalizationServiceProvider",
|
||||||
"Modules\\Core\\Providers\\CatalogServiceProvider",
|
"Modules\\Core\\Providers\\CatalogServiceProvider",
|
||||||
"Modules\\Core\\Providers\\CartServiceProvider",
|
"Modules\\Core\\Providers\\CartServiceProvider",
|
||||||
"Modules\\Core\\Providers\\ReviewServiceProvider",
|
"Modules\\Core\\Providers\\ReviewServiceProvider",
|
||||||
"Modules\\Core\\Providers\\ShippingServiceProvider"
|
"Modules\\Core\\Providers\\ShippingServiceProvider",
|
||||||
|
"Modules\\Core\\Providers\\OrderServiceProvider"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -30,6 +30,64 @@ return [
|
|||||||
|
|
||||||
'cart' => [
|
'cart' => [
|
||||||
'abandoned_after' => '1 hour',
|
'abandoned_after' => '1 hour',
|
||||||
|
|
||||||
|
/*
|
||||||
|
|----------------------------------------------------------------------
|
||||||
|
| Unrecoverable Cap
|
||||||
|
|----------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| Beyond this age, a stale cart stops being treated as an active
|
||||||
|
| "Abandoned Cart"/"Abandoned Checkout" (Modules\Core\Cart\Services\
|
||||||
|
| CartLifecycleService) — too old to be a realistic recovery target
|
||||||
|
| (pricing/stock/tax likely stale by then). This is about the
|
||||||
|
| abandoned-cart pipeline only, not data retention — no rows are
|
||||||
|
| deleted or pruned based on this value.
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
|
||||||
|
'unrecoverable_after' => '90 days',
|
||||||
|
],
|
||||||
|
|
||||||
|
/*
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
| Order Return Window
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| How many days after a carrier order is delivered (Order::fulfillment_status
|
||||||
|
| becomes 'return_window_open') before Modules\Core\Order\Commands\
|
||||||
|
| CloseExpiredReturnWindows auto-completes it, if no return was requested.
|
||||||
|
| Store-pickup orders have no return-window step and are unaffected by
|
||||||
|
| this value (see Modules\Core\Order\Listeners\CompleteOrderOnPickedUp).
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
|
||||||
|
'order' => [
|
||||||
|
'return_window_days' => 14,
|
||||||
|
],
|
||||||
|
|
||||||
|
/*
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
| Storefront OTP Login
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| Modules\Core\Auth\Services\UserOtpService's passwordless login.
|
||||||
|
| max_attempts caps how many wrong codes a shopper can guess against ONE
|
||||||
|
| generated code before it's invalidated outright. generation_limit/
|
||||||
|
| generation_decay_minutes cap how often a NEW code can be requested for
|
||||||
|
| the same email — independent of max_attempts, since generating a fresh
|
||||||
|
| code also resets the guess count, so an attempt cap alone doesn't stop
|
||||||
|
| an attacker from just requesting a new code every few tries. This same
|
||||||
|
| limit is also what stands between a malicious/careless caller and
|
||||||
|
| mail-bombing one inbox.
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
|
||||||
|
'auth' => [
|
||||||
|
'otp' => [
|
||||||
|
'max_attempts' => 5,
|
||||||
|
'generation_limit' => 3,
|
||||||
|
'generation_decay_minutes' => 10,
|
||||||
|
],
|
||||||
],
|
],
|
||||||
|
|
||||||
];
|
];
|
||||||
|
|||||||
@@ -0,0 +1,21 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
return [
|
||||||
|
/*
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
| Policy versions
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| Plain version strings, bumped by whoever edits the corresponding legal
|
||||||
|
| page — recorded alongside every consent/acceptance so a later dispute
|
||||||
|
| ("what did the shopper actually agree to?") can be answered from the
|
||||||
|
| order/cart itself rather than a live lookup against whatever the pages
|
||||||
|
| say TODAY. Not tied to any CMS/database row on purpose — this stays a
|
||||||
|
| plain config value the same way payment.php's cart_pipeline is a plain
|
||||||
|
| cross-cutting setting, not a per-instance one.
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
'privacy_policy_version' => env('LEGAL_PRIVACY_POLICY_VERSION', '2026-01-01'),
|
||||||
|
|
||||||
|
'terms_version' => env('LEGAL_TERMS_VERSION', '2026-01-01'),
|
||||||
|
];
|
||||||
+13
-31
@@ -1,46 +1,28 @@
|
|||||||
<?php
|
<?php
|
||||||
|
|
||||||
use Modules\Core\Payment\Drivers\OfflinePaymentDriver;
|
use Modules\Core\Payment\Pipelines\Cart\ApplyPaymentMethodFee;
|
||||||
use Modules\Core\Payment\Pipelines\Cart\ApplyCashOnDeliveryFee;
|
|
||||||
|
|
||||||
return [
|
return [
|
||||||
/*
|
|
||||||
|--------------------------------------------------------------------------
|
|
||||||
| Lunar payment types merged in by Boboko Core
|
|
||||||
|--------------------------------------------------------------------------
|
|
||||||
|
|
|
||||||
| These are merged into config('lunar.payments.types') so every app using
|
|
||||||
| boboko-core gets cash-on-delivery out of the box, without publishing
|
|
||||||
| Lunar's own config.
|
|
||||||
|
|
|
||||||
| 'payment_driver' is boboko-owned, alongside Lunar's own 'driver' key —
|
|
||||||
| it's the Modules\Core\Checkout\Contracts\PaymentDriver class
|
|
||||||
| CheckoutService::confirmPayment() resolves via the container and calls
|
|
||||||
| confirm() on. Kept on the same row as 'driver' rather than a second,
|
|
||||||
| separately-keyed map, so a type's full definition — Lunar's driver,
|
|
||||||
| its config, and its PaymentDriver — lives in one place.
|
|
||||||
|
|
|
||||||
*/
|
|
||||||
'types' => [
|
|
||||||
'cash-on-delivery' => [
|
|
||||||
'driver' => 'offline',
|
|
||||||
'payment_driver' => OfflinePaymentDriver::class,
|
|
||||||
'authorized' => 'awaiting-payment',
|
|
||||||
'fee' => 0,
|
|
||||||
],
|
|
||||||
],
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|--------------------------------------------------------------------------
|
|--------------------------------------------------------------------------
|
||||||
| Lunar cart pipeline additions
|
| Lunar cart pipeline additions
|
||||||
|--------------------------------------------------------------------------
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
|
||||||
| Appended to config('lunar.cart.pipelines.cart') after ApplyShipping so
|
| Appended to config('lunar.cart.pipelines.cart') after ApplyShipping so
|
||||||
| the cash-on-delivery fee is added to the shipping total before the
|
| the selected payment method's own fee (if any) is added to the
|
||||||
| final Calculate step sums everything up.
|
| shipping total before the final Calculate step sums everything up.
|
||||||
|
|
|
||||||
|
| This is the one thing left in this file — everything about WHICH
|
||||||
|
| payment methods exist (driver mapping, capture_mode, statuses) moved
|
||||||
|
| onto Modules\Core\Payment\Models\PaymentMethod's own row (see
|
||||||
|
| docs/payments.md): that's a per-instance, merchant decision, not a
|
||||||
|
| store-wide-singular setting, so it never belonged in config at all.
|
||||||
|
| This pipeline registration IS genuinely cross-cutting — every store
|
||||||
|
| using this driver gets the same cart-pipeline wiring, regardless of
|
||||||
|
| how many payment methods it configures.
|
||||||
|
|
|
|
||||||
*/
|
*/
|
||||||
'cart_pipeline' => [
|
'cart_pipeline' => [
|
||||||
ApplyCashOnDeliveryFee::class,
|
ApplyPaymentMethodFee::class,
|
||||||
],
|
],
|
||||||
];
|
];
|
||||||
|
|||||||
+43
@@ -0,0 +1,43 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* product_reviews.product_id's original foreign key (2026_07_10_000001) had
|
||||||
|
* no ON DELETE clause, so deleting a Product with reviews throws a
|
||||||
|
* constraint violation instead of the review rows going with it — unlike
|
||||||
|
* every other Product-dependent table (variants, media, etc.), which does
|
||||||
|
* cascade. A review is dependent, disposable data, not something worth
|
||||||
|
* blocking a product deletion over.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('product_reviews', function (Blueprint $table) {
|
||||||
|
$table->dropForeign(['product_id']);
|
||||||
|
});
|
||||||
|
|
||||||
|
Schema::table('product_reviews', function (Blueprint $table) {
|
||||||
|
$table->foreign('product_id')
|
||||||
|
->references('id')
|
||||||
|
->on(config('lunar.database.table_prefix').'products')
|
||||||
|
->cascadeOnDelete();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('product_reviews', function (Blueprint $table) {
|
||||||
|
$table->dropForeign(['product_id']);
|
||||||
|
});
|
||||||
|
|
||||||
|
Schema::table('product_reviews', function (Blueprint $table) {
|
||||||
|
$table->foreign('product_id')
|
||||||
|
->references('id')
|
||||||
|
->on(config('lunar.database.table_prefix').'products');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,47 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
use Lunar\Base\Migration;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* lunarphp/stripe's own stripe_payment_intents table already correlates a
|
||||||
|
* Stripe intent back to a cart/order via cart_id/order_id — exactly what
|
||||||
|
* Modules\Core\Payment\Drivers\StripePaymentDriver needs to recover
|
||||||
|
* $context in handleCallback(), a separate request (a webhook) from the
|
||||||
|
* pay()/authorize() call that originated it. Two columns this driver
|
||||||
|
* needs that the vendor table doesn't have:
|
||||||
|
* - context: the full opaque $context bag pay()/authorize() received,
|
||||||
|
* stored so handleCallback() can dispatch the SAME context the
|
||||||
|
* original call would have, without Payment inventing its own
|
||||||
|
* correlation table — see docs/payments.md "Async resolution".
|
||||||
|
* - payment_type: the payment type key (e.g. 'stripe') pay()/authorize()
|
||||||
|
* were called with — needed to dispatch Payment events with the
|
||||||
|
* correct $type in handleCallback(), which otherwise has no way to
|
||||||
|
* know it (a webhook payload doesn't carry it).
|
||||||
|
*
|
||||||
|
* Extends Lunar\Base\Migration (not the plain base Migration) so $this->prefix
|
||||||
|
* resolves the SAME table-prefix config every Lunar-owned table uses
|
||||||
|
* (config('lunar.database.table_prefix')) — the vendor migration that
|
||||||
|
* creates this table (lunarphp/stripe's create_stripe_payment_intents_table)
|
||||||
|
* already does this, so a store running with a non-default prefix (this
|
||||||
|
* one runs with 'lunar_') would otherwise have this migration fail against
|
||||||
|
* a table name that doesn't exist.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table($this->prefix.'stripe_payment_intents', function (Blueprint $table) {
|
||||||
|
$table->json('context')->nullable()->after('status');
|
||||||
|
$table->string('payment_type')->nullable()->after('context');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table($this->prefix.'stripe_payment_intents', function (Blueprint $table) {
|
||||||
|
$table->dropColumn(['context', 'payment_type']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,52 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Moves the driver mapping and per-type behavior that used to live in
|
||||||
|
* config('lunar.payments.types.{type}.*') onto the PaymentMethod row
|
||||||
|
* itself — same DB-instance-vs-config split Modules\Core\Shipping's own
|
||||||
|
* shipping_methods table already has (code/driver/name/enabled columns,
|
||||||
|
* no driver mapping in any config file). See docs/payments.md.
|
||||||
|
*
|
||||||
|
* - driver: the Modules\Core\Payment\Services\PaymentDriverRegistry key
|
||||||
|
* (NOT the same as `type` — two rows can share one driver).
|
||||||
|
* - name: admin-facing label. Nothing played this role before; `type`
|
||||||
|
* was always the machine slug.
|
||||||
|
* - capture_mode / captured_status / authorized_status: per-instance
|
||||||
|
* behavior — fails the "would a store ever want two different answers
|
||||||
|
* to this" cross-cutting-config test, so these move off config.
|
||||||
|
* - position: admin-controlled display/checkout order.
|
||||||
|
* - driver_missing_at: set by the payment:sync-drivers command when
|
||||||
|
* `driver` no longer resolves via the registry — deliberately
|
||||||
|
* separate from `enabled`, so a driver vanishing (a deploy removed
|
||||||
|
* it) is never confused with an admin's own manual toggle, and a
|
||||||
|
* driver that comes back later auto-clears this with no admin action.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('payment_methods', function (Blueprint $table) {
|
||||||
|
$table->string('name')->nullable()->after('type');
|
||||||
|
$table->string('driver')->nullable()->after('name');
|
||||||
|
$table->string('capture_mode')->nullable()->after('driver');
|
||||||
|
$table->string('captured_status')->nullable()->after('capture_mode');
|
||||||
|
$table->string('authorized_status')->nullable()->after('captured_status');
|
||||||
|
$table->unsignedInteger('position')->default(0)->after('authorized_status');
|
||||||
|
$table->timestamp('driver_missing_at')->nullable()->after('position');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('payment_methods', function (Blueprint $table) {
|
||||||
|
$table->dropColumn([
|
||||||
|
'name', 'driver', 'capture_mode', 'captured_status',
|
||||||
|
'authorized_status', 'position', 'driver_missing_at',
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,38 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* captured_status/authorized_status (added in 2026_09_05_000001) cover a
|
||||||
|
* payment being taken, but nothing wrote Order.status on a REFUND —
|
||||||
|
* Order::paymentStatus() (Order\Support\OrderStatus::payment(), derived
|
||||||
|
* live from transactions) already reflects a refund correctly, but the
|
||||||
|
* stored status column — the one admin filtering, customer emails, etc.
|
||||||
|
* actually key off — never moved. Same reasoning as captured_status/
|
||||||
|
* authorized_status: a store could plausibly want a different resulting
|
||||||
|
* status per payment method (e.g. a "Refunded" vs. a "Refund Pending"
|
||||||
|
* variant), so this is a PaymentMethod column, not cross-cutting config.
|
||||||
|
*
|
||||||
|
* Deliberately no separate void_status — void never moved money (it
|
||||||
|
* releases an authorization hold before any capture), so it doesn't carry
|
||||||
|
* the same "the customer needs to see this changed" weight a refund does;
|
||||||
|
* add one later if a real need for it shows up.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('payment_methods', function (Blueprint $table) {
|
||||||
|
$table->string('refunded_status')->nullable()->after('authorized_status');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('payment_methods', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('refunded_status');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Splits Lunar's single flat `status` column into three independently
|
||||||
|
* tracked axes — payment, fulfillment, return — so a payment refund and a
|
||||||
|
* fulfillment dispatch stop racing to write the same field, and each axis
|
||||||
|
* can be filtered/queried directly instead of overloading one string for
|
||||||
|
* three unrelated concerns. See Modules\Core\Order\Enums\OrderPaymentStatus/
|
||||||
|
* OrderFulfillmentStatus/OrderReturnStatus for the value vocabularies, and
|
||||||
|
* Modules\Core\Order\Listeners\ApplyResolvedPaymentStatus and friends for
|
||||||
|
* where these columns actually get written. `status` itself is left in
|
||||||
|
* place, unchanged — Lunar core still reads/writes it in places this
|
||||||
|
* package doesn't own — but nothing in this package's business logic keys
|
||||||
|
* off it anymore after this migration's consumers land.
|
||||||
|
*
|
||||||
|
* lunar_customers already has a direct precedent for a boboko-core
|
||||||
|
* migration altering a Lunar-owned table (see
|
||||||
|
* 2026_07_02_000002_drop_otp_from_lunar_customers_table.php) — this is not
|
||||||
|
* a new pattern for this codebase, just the first time it's applied to
|
||||||
|
* lunar_orders.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('lunar_orders', function (Blueprint $table) {
|
||||||
|
$table->string('payment_status')->default('awaiting_payment')->after('status')->index();
|
||||||
|
$table->string('fulfillment_status')->default('unfulfilled')->after('payment_status')->index();
|
||||||
|
$table->string('return_status')->default('none')->after('fulfillment_status')->index();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('lunar_orders', function (Blueprint $table) {
|
||||||
|
$table->dropColumn(['payment_status', 'fulfillment_status', 'return_status']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Append-only audit trail for Order's three status axes (see
|
||||||
|
* 2026_09_11_000001_add_status_axes_to_orders_table.php) — the thing
|
||||||
|
* `Lunar\Models\Order::getDefaultLogExcept()` explicitly denies (`status`
|
||||||
|
* is excluded from Lunar's own Spatie activity log), so this is a
|
||||||
|
* from-scratch mechanism, not a gap in an existing one.
|
||||||
|
*
|
||||||
|
* No `updated_at` — a row is never edited after it's written, only ever
|
||||||
|
* inserted. `event_class` is the FQCN of whatever business event/action
|
||||||
|
* caused the write (e.g. Modules\Core\Order\Events\OrderDispatched, or a
|
||||||
|
* plain string like 'Modules\Core\Shipping\Extensions\OrderViewExtension::
|
||||||
|
* markDispatchedAction' for a manual Filament action that has no backing
|
||||||
|
* event class of its own) — see Modules\Core\Order\Services\
|
||||||
|
* OrderStatusTransitionRecorder.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('order_status_transitions', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
$table->foreignId('order_id')->constrained('lunar_orders')->cascadeOnDelete();
|
||||||
|
$table->string('axis');
|
||||||
|
$table->string('from_status')->nullable();
|
||||||
|
$table->string('to_status');
|
||||||
|
$table->string('event_class');
|
||||||
|
$table->timestamp('created_at')->useCurrent();
|
||||||
|
$table->index(['order_id', 'axis']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('order_status_transitions');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,79 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Illuminate\Support\Facades\Log;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Modules\Core\Order\Enums\PaymentStatus;
|
||||||
|
use Modules\Core\Order\Support\OrderStatus;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Maps every existing order's flat `status` (as it stood before
|
||||||
|
* 2026_09_11_000001_add_status_axes_to_orders_table.php) onto the new
|
||||||
|
* payment_status/fulfillment_status/return_status columns. A separate
|
||||||
|
* migration from the schema change so the schema migration stays simply
|
||||||
|
* reversible via down(), and this data pass can be independently re-run.
|
||||||
|
*
|
||||||
|
* The flat status never captured refunds at all (no 'refunded' value was
|
||||||
|
* ever added to config('lunar.orders.statuses')), so the table-driven
|
||||||
|
* mapping below is corrected per-order by re-deriving
|
||||||
|
* Modules\Core\Order\Support\OrderStatus::payment() — the existing,
|
||||||
|
* unchanged derived-enum logic — and overriding payment_status to
|
||||||
|
* refunded/partially_refunded wherever it disagrees with the flat-status
|
||||||
|
* mapping. This is the one place the "keep the old derived enums" design
|
||||||
|
* decision earns its keep: refund-fraction math isn't reimplemented here,
|
||||||
|
* just reused.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
private const MAP = [
|
||||||
|
'awaiting-payment' => ['payment_status' => 'awaiting_payment', 'fulfillment_status' => 'unfulfilled'],
|
||||||
|
'payment-offline' => ['payment_status' => 'awaiting_payment', 'fulfillment_status' => 'unfulfilled'],
|
||||||
|
'payment-received' => ['payment_status' => 'paid', 'fulfillment_status' => 'unfulfilled'],
|
||||||
|
'ready-for-dispatch' => ['payment_status' => 'paid', 'fulfillment_status' => 'ready'],
|
||||||
|
'ready-for-pickup' => ['payment_status' => 'paid', 'fulfillment_status' => 'ready'],
|
||||||
|
'dispatched' => ['payment_status' => 'paid', 'fulfillment_status' => 'in_transit'],
|
||||||
|
'completed' => ['payment_status' => 'paid', 'fulfillment_status' => 'completed'],
|
||||||
|
];
|
||||||
|
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Order::query()->with('transactions')->chunkById(200, function ($orders) {
|
||||||
|
foreach ($orders as $order) {
|
||||||
|
$mapped = self::MAP[$order->status] ?? null;
|
||||||
|
|
||||||
|
if ($mapped === null) {
|
||||||
|
Log::warning('Order status axis backfill: unmapped status, leaving column defaults', [
|
||||||
|
'order_id' => $order->id,
|
||||||
|
'status' => $order->status,
|
||||||
|
]);
|
||||||
|
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
$paymentStatus = $mapped['payment_status'];
|
||||||
|
|
||||||
|
$derived = OrderStatus::payment($order);
|
||||||
|
|
||||||
|
if ($derived === PaymentStatus::Refunded) {
|
||||||
|
$paymentStatus = 'refunded';
|
||||||
|
} elseif ($derived === PaymentStatus::PartialRefund) {
|
||||||
|
$paymentStatus = 'partially_refunded';
|
||||||
|
}
|
||||||
|
|
||||||
|
DB::table('lunar_orders')->where('id', $order->id)->update([
|
||||||
|
'payment_status' => $paymentStatus,
|
||||||
|
'fulfillment_status' => $mapped['fulfillment_status'],
|
||||||
|
'return_status' => 'none',
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
// Column defaults (set in the schema migration) are the correct
|
||||||
|
// "undo" — no need to reverse-map back to the flat status, since
|
||||||
|
// `status` itself was never touched by this migration.
|
||||||
|
}
|
||||||
|
};
|
||||||
+36
@@ -0,0 +1,36 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* captured_status/authorized_status/refunded_status let a merchant pick
|
||||||
|
* which per-method Order::status label a payment outcome resulted in — a
|
||||||
|
* mechanism that only made sense while Order.status was the single field
|
||||||
|
* carrying that meaning. Modules\Core\Order\Listeners\
|
||||||
|
* ApplyResolvedPaymentStatus now writes a fixed 3-value payment_status
|
||||||
|
* column instead (see 2026_09_11_000001_add_status_axes_to_orders_table.php);
|
||||||
|
* there is no longer any per-method flexibility to preserve — "paid" is
|
||||||
|
* "paid" regardless of which method captured it. Dropped rather than left
|
||||||
|
* vestigial: keeping them visible in the admin would let a merchant
|
||||||
|
* configure something that silently does nothing.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('payment_methods', function (Blueprint $table) {
|
||||||
|
$table->dropColumn(['captured_status', 'authorized_status', 'refunded_status']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('payment_methods', function (Blueprint $table) {
|
||||||
|
$table->string('captured_status')->nullable();
|
||||||
|
$table->string('authorized_status')->nullable();
|
||||||
|
$table->string('refunded_status')->nullable();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Order::paid/paid_at — entirely independent of the `status` column (see
|
||||||
|
* Modules\Core\Order\Services\OrderStatusFlow's own docblock for why
|
||||||
|
* payment timing, especially for cash-on-delivery, cannot be modeled as a
|
||||||
|
* status-sequence step). `paid` is the fast-filter boolean; `paid_at` is
|
||||||
|
* when it actually happened.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('lunar_orders', function (Blueprint $table) {
|
||||||
|
$table->boolean('paid')->default(false)->after('status')->index();
|
||||||
|
$table->timestamp('paid_at')->nullable()->after('paid');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('lunar_orders', function (Blueprint $table) {
|
||||||
|
$table->dropColumn(['paid', 'paid_at']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,116 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Illuminate\Support\Facades\Log;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Modules\Core\Order\Enums\PaymentStatus;
|
||||||
|
use Modules\Core\Order\Support\OrderStatus;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Collapses the 3-axis (payment_status/fulfillment_status/return_status)
|
||||||
|
* model this session briefly built — abandoned before shipping — back
|
||||||
|
* onto a single `status` column plus the new independent `paid`/`paid_at`
|
||||||
|
* fields. Must run after 2026_09_12_000001 (adds paid/paid_at) and before
|
||||||
|
* 2026_09_12_000003 (drops the axis columns this migration still reads).
|
||||||
|
*
|
||||||
|
* Priority rule: axis data where it's genuinely non-default (this order
|
||||||
|
* was really moved through the axis system during this session's manual
|
||||||
|
* testing); the legacy `status` column (which may still hold pre-session
|
||||||
|
* hyphenated values) as fallback everywhere else.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
private const LEGACY_MAP = [
|
||||||
|
'awaiting-payment' => 'awaiting_payment',
|
||||||
|
'payment-offline' => 'awaiting_payment',
|
||||||
|
'payment-received' => 'processing',
|
||||||
|
'ready-for-dispatch' => 'ready_for_dispatch',
|
||||||
|
'ready-for-pickup' => 'ready_for_pickup',
|
||||||
|
'dispatched' => 'dispatched',
|
||||||
|
'completed' => 'completed',
|
||||||
|
];
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Axis fulfillment_status -> new single status, given branch. Axis
|
||||||
|
* 'delivered' folds into 'return_window_open' (same combined-value
|
||||||
|
* decision the going-forward design makes). Axis payment_status is
|
||||||
|
* used only to decide whether a fully-unfulfilled order should read
|
||||||
|
* as 'awaiting_payment' or 'processing'.
|
||||||
|
*/
|
||||||
|
private function mapFromAxes(string $payment, string $fulfillment, string $return, bool $isPickup): ?string
|
||||||
|
{
|
||||||
|
if ($return === 'returned') {
|
||||||
|
return 'returned';
|
||||||
|
}
|
||||||
|
if ($return === 'requested') {
|
||||||
|
return 'return_requested';
|
||||||
|
}
|
||||||
|
|
||||||
|
return match ($fulfillment) {
|
||||||
|
'unfulfilled' => $payment === 'paid' ? 'processing' : 'awaiting_payment',
|
||||||
|
'processing' => 'processing',
|
||||||
|
'ready' => $isPickup ? 'ready_for_pickup' : 'ready_for_dispatch',
|
||||||
|
'in_transit' => 'dispatched',
|
||||||
|
'delivered', 'return_window_open' => 'return_window_open',
|
||||||
|
'picked_up' => 'picked_up',
|
||||||
|
'completed' => 'completed',
|
||||||
|
default => null,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Order::query()->with('transactions')->chunkById(200, function ($orders) {
|
||||||
|
foreach ($orders as $order) {
|
||||||
|
$isPickup = $order->isStorePickupOrder();
|
||||||
|
|
||||||
|
$axisIsDefault = $order->payment_status === 'awaiting_payment'
|
||||||
|
&& $order->fulfillment_status === 'unfulfilled'
|
||||||
|
&& $order->return_status === 'none';
|
||||||
|
|
||||||
|
$status = $axisIsDefault
|
||||||
|
? (self::LEGACY_MAP[$order->status] ?? null)
|
||||||
|
: $this->mapFromAxes($order->payment_status, $order->fulfillment_status, $order->return_status, $isPickup);
|
||||||
|
|
||||||
|
if ($status === null) {
|
||||||
|
Log::warning('Single-status backfill: unmapped order, defaulting to awaiting_payment', [
|
||||||
|
'order_id' => $order->id,
|
||||||
|
'status' => $order->status,
|
||||||
|
'payment_status' => $order->payment_status,
|
||||||
|
'fulfillment_status' => $order->fulfillment_status,
|
||||||
|
'return_status' => $order->return_status,
|
||||||
|
]);
|
||||||
|
$status = 'awaiting_payment';
|
||||||
|
}
|
||||||
|
|
||||||
|
$derived = OrderStatus::payment($order);
|
||||||
|
$paid = $order->payment_status === 'paid'
|
||||||
|
|| in_array($derived, [PaymentStatus::Captured, PaymentStatus::Refunded, PaymentStatus::PartialRefund], true);
|
||||||
|
|
||||||
|
// A refund implies the order concluded via a return —
|
||||||
|
// even one backfilled to an early status (e.g. an order
|
||||||
|
// refunded before fulfillment ever started) is corrected
|
||||||
|
// to refunded/partially_refunded here, not left stuck
|
||||||
|
// pre-fulfillment with no sign a refund ever happened.
|
||||||
|
if ($derived === PaymentStatus::Refunded) {
|
||||||
|
$status = 'refunded';
|
||||||
|
} elseif ($derived === PaymentStatus::PartialRefund) {
|
||||||
|
$status = 'partially_refunded';
|
||||||
|
}
|
||||||
|
|
||||||
|
DB::table('lunar_orders')->where('id', $order->id)->update([
|
||||||
|
'status' => $status,
|
||||||
|
'paid' => $paid,
|
||||||
|
'paid_at' => $paid ? ($order->placed_at ?? now()) : null,
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
// No reverse mapping — column defaults (post-rollback of the
|
||||||
|
// schema migrations) are the correct "undo".
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,34 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Reverses 2026_09_11_000001_add_status_axes_to_orders_table.php — the
|
||||||
|
* 3-axis model was abandoned before shipping in favor of a single
|
||||||
|
* `status` column plus independent `paid`/`paid_at` (see
|
||||||
|
* 2026_09_12_000001/000002). Must run after 2026_09_12_000002, which
|
||||||
|
* still reads these columns for the backfill.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('lunar_orders', function (Blueprint $table) {
|
||||||
|
$table->dropColumn(['payment_status', 'fulfillment_status', 'return_status']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
// Mirrors 2026_09_11_000001's own down() — restores columns
|
||||||
|
// empty/defaulted, does not attempt to resurrect real per-order
|
||||||
|
// values.
|
||||||
|
Schema::table('lunar_orders', function (Blueprint $table) {
|
||||||
|
$table->string('payment_status')->default('awaiting_payment')->after('paid_at')->index();
|
||||||
|
$table->string('fulfillment_status')->default('unfulfilled')->after('payment_status')->index();
|
||||||
|
$table->string('return_status')->default('none')->after('fulfillment_status')->index();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
+33
@@ -0,0 +1,33 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* There is only one status column left to audit (plus the synthetic
|
||||||
|
* 'paid' entry — see Modules\Core\Order\Listeners\RecordStatusTransition),
|
||||||
|
* so the `axis` column this table was created with
|
||||||
|
* (2026_09_11_000002_create_order_status_transitions_table.php) no longer
|
||||||
|
* means anything.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('order_status_transitions', function (Blueprint $table) {
|
||||||
|
$table->dropIndex(['order_id', 'axis']);
|
||||||
|
$table->dropColumn('axis');
|
||||||
|
$table->index('order_id');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('order_status_transitions', function (Blueprint $table) {
|
||||||
|
$table->dropIndex(['order_id']);
|
||||||
|
$table->string('axis')->default('status')->after('order_id');
|
||||||
|
$table->index(['order_id', 'axis']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
+27
@@ -0,0 +1,27 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The seeded 'cash-on-delivery' PaymentMethod row
|
||||||
|
* (Modules\Core\Command\InstallLunarCommand::seedPaymentMethods()) was
|
||||||
|
* wired to driver => 'offline' — the same immediate-capture driver as
|
||||||
|
* cash-in-hand. That's the bug that made COD "pay immediately" instead of
|
||||||
|
* waiting for staff to confirm cash was actually received. Repoints
|
||||||
|
* already-seeded environments to the new dedicated
|
||||||
|
* Modules\Core\Payment\Drivers\CashOnDeliveryPaymentDriver; the seeder
|
||||||
|
* itself is fixed separately for fresh installs.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
DB::table('payment_methods')->where('type', 'cash-on-delivery')->update(['driver' => 'cash-on-delivery']);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
DB::table('payment_methods')->where('type', 'cash-on-delivery')->update(['driver' => 'offline']);
|
||||||
|
}
|
||||||
|
};
|
||||||
+30
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* 'return_window_open' is renamed to 'delivered' — same status value,
|
||||||
|
* same meaning (the parcel arrived AND the return window is now open,
|
||||||
|
* still one combined moment — see Modules\Core\Order\Listeners\
|
||||||
|
* AdvanceFulfillmentOnDelivered), just a name a merchant expects to read
|
||||||
|
* on the order page rather than an internal mechanic. Also renames it in
|
||||||
|
* order_status_transitions' audit rows so the history stays consistent
|
||||||
|
* with `status` going forward.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
DB::table('lunar_orders')->where('status', 'return_window_open')->update(['status' => 'delivered']);
|
||||||
|
DB::table('order_status_transitions')->where('from_status', 'return_window_open')->update(['from_status' => 'delivered']);
|
||||||
|
DB::table('order_status_transitions')->where('to_status', 'return_window_open')->update(['to_status' => 'delivered']);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
DB::table('lunar_orders')->where('status', 'delivered')->update(['status' => 'return_window_open']);
|
||||||
|
DB::table('order_status_transitions')->where('from_status', 'delivered')->update(['from_status' => 'return_window_open']);
|
||||||
|
DB::table('order_status_transitions')->where('to_status', 'delivered')->update(['to_status' => 'return_window_open']);
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A real record of "a manifest was issued", not just a loose
|
||||||
|
* manifest_reference string stamped onto each Shipment row — ACS's own
|
||||||
|
* ACS_Issue_Pickup_List call returns nothing beyond a PickupList_No (see
|
||||||
|
* Modules\Core\Shipping\Carriers\Acs\AcsFulfillmentService::issueManifest()),
|
||||||
|
* so this table is entirely our own bookkeeping: when the manifest was
|
||||||
|
* issued and how many shipments it included, not something re-derivable
|
||||||
|
* from the carrier later. `shipment_count` is denormalized (also
|
||||||
|
* countable via shipments()->count()) purely so the manifests list can
|
||||||
|
* render without an extra query per row.
|
||||||
|
*
|
||||||
|
* carrier-agnostic by design — see Modules\Core\Shipping\Contracts\
|
||||||
|
* SupportsManifestBatching, the same contract any future carrier
|
||||||
|
* (Speedex, etc.) implements to get manifest batching at all; this table
|
||||||
|
* has no ACS-specific columns.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('manifests', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
$table->string('carrier');
|
||||||
|
$table->string('reference');
|
||||||
|
$table->unsignedInteger('shipment_count')->default(0);
|
||||||
|
$table->timestamp('issued_at');
|
||||||
|
$table->timestamps();
|
||||||
|
|
||||||
|
$table->unique(['carrier', 'reference']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('manifests');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,82 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Replaces the loose manifest_reference string with a real manifests
|
||||||
|
* relation — see 2026_09_13_000002_create_manifests_table.php. Backfills
|
||||||
|
* one Manifest row per distinct (carrier, manifest_reference) pair
|
||||||
|
* already present in shipments, using the earliest label_printed_at (or
|
||||||
|
* updated_at as a fallback) among that group as a best-effort issued_at,
|
||||||
|
* since the exact original issue time was never recorded anywhere.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('shipments', function (Blueprint $table) {
|
||||||
|
$table->foreignId('manifest_id')->nullable()->after('manifest_reference')->constrained()->nullOnDelete();
|
||||||
|
});
|
||||||
|
|
||||||
|
$groups = DB::table('shipments')
|
||||||
|
->select('carrier', 'manifest_reference')
|
||||||
|
->whereNotNull('manifest_reference')
|
||||||
|
->distinct()
|
||||||
|
->get();
|
||||||
|
|
||||||
|
foreach ($groups as $group) {
|
||||||
|
$shipments = DB::table('shipments')
|
||||||
|
->where('carrier', $group->carrier)
|
||||||
|
->where('manifest_reference', $group->manifest_reference)
|
||||||
|
->get();
|
||||||
|
|
||||||
|
$issuedAt = $shipments->pluck('label_printed_at')->filter()->min()
|
||||||
|
?? $shipments->pluck('updated_at')->min();
|
||||||
|
|
||||||
|
$manifestId = DB::table('manifests')->insertGetId([
|
||||||
|
'carrier' => $group->carrier,
|
||||||
|
'reference' => $group->manifest_reference,
|
||||||
|
'shipment_count' => $shipments->count(),
|
||||||
|
'issued_at' => $issuedAt,
|
||||||
|
'created_at' => $issuedAt,
|
||||||
|
'updated_at' => $issuedAt,
|
||||||
|
]);
|
||||||
|
|
||||||
|
DB::table('shipments')
|
||||||
|
->where('carrier', $group->carrier)
|
||||||
|
->where('manifest_reference', $group->manifest_reference)
|
||||||
|
->update(['manifest_id' => $manifestId]);
|
||||||
|
}
|
||||||
|
|
||||||
|
Schema::table('shipments', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('manifest_reference');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('shipments', function (Blueprint $table) {
|
||||||
|
$table->string('manifest_reference')->nullable()->after('parent_reference');
|
||||||
|
});
|
||||||
|
|
||||||
|
DB::table('shipments')
|
||||||
|
->whereNotNull('manifest_id')
|
||||||
|
->orderBy('id')
|
||||||
|
->each(function ($shipment) {
|
||||||
|
$manifest = DB::table('manifests')->find($shipment->manifest_id);
|
||||||
|
|
||||||
|
if ($manifest) {
|
||||||
|
DB::table('shipments')->where('id', $shipment->id)->update([
|
||||||
|
'manifest_reference' => $manifest->reference,
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
Schema::table('shipments', function (Blueprint $table) {
|
||||||
|
$table->dropConstrainedForeignId('manifest_id');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Caps brute-forcing a 6-digit OTP code (1M combinations, 10-minute
|
||||||
|
* window, previously uncapped) — see Modules\Core\Auth\Services\
|
||||||
|
* UserOtpService::validate(), which now invalidates the code entirely
|
||||||
|
* (forcing a fresh generateAndSend()) once otp_attempts reaches its max,
|
||||||
|
* rather than leaving a live code guessable indefinitely within its
|
||||||
|
* expiry window.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->unsignedTinyInteger('otp_attempts')->default(0)->after('otp_expires_at');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('otp_attempts');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A per-login session registry, independent of the actual session store
|
||||||
|
* driver (SESSION_DRIVER=redis in this app — no "sessions" table to
|
||||||
|
* purge by user_id the way the database driver would allow). Each
|
||||||
|
* successful OTP login (Modules\Core\Auth\Services\UserOtpService::
|
||||||
|
* validate()) records one row here and stamps the token into the
|
||||||
|
* Laravel session payload; Modules\Core\Auth\Http\Middleware\
|
||||||
|
* EnsureSessionNotRevoked checks it on every request. "Logout
|
||||||
|
* everywhere" (Modules\Core\Auth\Services\UserSessionService::
|
||||||
|
* revokeOtherSessions()) is then just marking every OTHER row
|
||||||
|
* revoked_at, no session-store-specific logic anywhere.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('user_sessions', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
$table->foreignId('user_id')->constrained()->cascadeOnDelete();
|
||||||
|
$table->string('token', 64)->unique();
|
||||||
|
$table->string('user_agent')->nullable();
|
||||||
|
$table->string('ip_address', 45)->nullable();
|
||||||
|
$table->timestamp('last_used_at');
|
||||||
|
$table->timestamp('revoked_at')->nullable();
|
||||||
|
$table->timestamps();
|
||||||
|
|
||||||
|
$table->index(['user_id', 'revoked_at']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('user_sessions');
|
||||||
|
}
|
||||||
|
};
|
||||||
+48
-40
@@ -1,28 +1,34 @@
|
|||||||
# Cart Admin Visibility
|
# Cart Admin Visibility
|
||||||
|
|
||||||
`Modules\Core\Cart\Filament\Resources\CartResource` gives staff read-only visibility into
|
`Modules\Core\Cart\Filament\Resources\CartResource` gives staff read-only visibility into
|
||||||
customer/user carts in the Filament admin panel. Lunar itself ships no cart admin view at
|
every cart in the Filament admin panel, guest carts included. Lunar itself ships no cart
|
||||||
all — no Filament resource for `Cart`/`CartLine` exists anywhere in `lunarphp/lunar` or
|
admin view at all — no Filament resource for `Cart`/`CartLine` exists anywhere in
|
||||||
`lunarphp/core` — this is a from-scratch addition, not an extension of something Lunar
|
`lunarphp/lunar` or `lunarphp/core` — this is a from-scratch addition, not an extension of
|
||||||
half-built. See `docs/lunar.md`'s "Cart and Checkout" section for the underlying Lunar cart
|
something Lunar half-built. See `docs/lunar.md`'s "Cart and Checkout" section for the
|
||||||
mechanics this resource reads from.
|
underlying Lunar cart mechanics this resource reads from.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Scope: only carts with a known customer or user
|
## Scope: every cart, identified or not
|
||||||
|
|
||||||
`CartResource::getEloquentQuery()` filters to `Cart::whereNotNull('user_id')->orWhereNotNull('customer_id')`
|
`CartResource` lists every cart the four lifecycle states (below) cover, with no
|
||||||
— an anonymous guest's session cart is excluded entirely.
|
`user_id`/`customer_id` filter — an anonymous guest's session cart is included.
|
||||||
|
|
||||||
This was a deliberate call, not an oversight: an anonymous cart carries no identity a staff
|
This was a reversal of an earlier, deliberate call to exclude guest carts entirely (on the
|
||||||
member could act on — no name, no email, nothing to follow up with — so listing every guest
|
reasoning that an anonymous cart carries no identity a staff member could act on — no name, no
|
||||||
session cart would be noise, not a real admin capability. This does **not** mirror Shopify's
|
email, nothing to follow up with — so listing every guest session cart would be noise, not a
|
||||||
admin (Shopify has no "all carts" view at all — only "Abandoned checkouts," gated on a
|
real admin capability). That reasoning holds for "can I click through to a Customer record,"
|
||||||
shopper reaching checkout and entering contact info, a later/narrower stage than Lunar's
|
but not for the resource's other real use — seeing how many carts are ongoing/abandoned right
|
||||||
`Cart`). Lunar's own `Cart` model already gets `user_id`/`customer_id` set the moment a
|
now regardless of who's shopping. Most real storefront traffic never reaches an identified
|
||||||
shopper is authenticated (via `Lunar\Listeners\CartSessionAuthListener` on login), with no
|
user/customer, so excluding it silently undercounts exactly the thing `ListCarts`'s tabs (and
|
||||||
checkout step required — so scoping to "identifiable" here is broader than Shopify's
|
`CartLifecycleService`, which they and `DetectAbandonedCarts` both build on) exist to report
|
||||||
equivalent, not a copy of it.
|
on. The `Customer`/`User` columns on a guest row just render "—" (Filament's `placeholder()`)
|
||||||
|
instead of a link — nothing to click into, but the row and its contents are still visible via
|
||||||
|
`ViewCart`.
|
||||||
|
|
||||||
|
This does **not** mirror Shopify's admin (Shopify has no "all carts" view at all — only
|
||||||
|
"Abandoned checkouts," gated on a shopper reaching checkout and entering contact info, a
|
||||||
|
later/narrower stage than Lunar's `Cart`).
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -40,28 +46,29 @@ distinct states together: no order ever started, vs. a draft order exists
|
|||||||
different purchase-intent signals (see "Abandoned Cart vs Abandoned Checkout" below) and
|
different purchase-intent signals (see "Abandoned Cart vs Abandoned Checkout" below) and
|
||||||
different reachability (checkout usually captures an email even for a guest), so
|
different reachability (checkout usually captures an email even for a guest), so
|
||||||
`ListCarts::getTabs()` splits them into four tabs instead of `scopeActive()`'s two-state
|
`ListCarts::getTabs()` splits them into four tabs instead of `scopeActive()`'s two-state
|
||||||
split:
|
split.
|
||||||
|
|
||||||
- **Ongoing** — `scopeActive()` and recent `updated_at` (within `abandonedCutoff()`). Default
|
`Modules\Core\Cart\Services\CartLifecycleService` is the single source of truth for these four
|
||||||
active tab on page load.
|
query shapes — both `ListCarts::getTabs()` (staff browsing) and `DetectAbandonedCarts`
|
||||||
- **Abandoned Cart** — `whereDoesntHave('orders')` and stale `updated_at`.
|
(abandonment-event dispatch) build on it, rather than each reimplementing the same split
|
||||||
- **Abandoned Checkout** — has an order with `placed_at IS NULL`, and stale `updated_at`.
|
independently (which is what happened before this service existed, and is exactly the kind of
|
||||||
- **Completed** — has an order with `placed_at IS NOT NULL`.
|
drift that lets the admin panel and the recovery-email pipeline quietly disagree about what
|
||||||
|
"abandoned" means):
|
||||||
|
|
||||||
```php
|
- **Ongoing** (`ongoing()`) — `scopeActive()` and recent `updated_at` (within
|
||||||
// Ongoing
|
`abandonedCutoff()`). Default active tab on page load.
|
||||||
$query->active()->where('updated_at', '>', CartResource::abandonedCutoff());
|
- **Abandoned Cart** (`abandonedCarts()`) — `whereDoesntHave('orders')` and stale
|
||||||
|
`updated_at`.
|
||||||
|
- **Abandoned Checkout** (`abandonedCheckouts()`) — has an order with `placed_at IS NULL`,
|
||||||
|
and stale `updated_at`.
|
||||||
|
- **Completed** (`completed()`) — has an order with `placed_at IS NOT NULL`.
|
||||||
|
|
||||||
// Abandoned Cart
|
Each method takes a `Builder` and returns it further scoped, so callers compose it onto
|
||||||
$query->whereDoesntHave('orders')->where('updated_at', '<=', CartResource::abandonedCutoff());
|
whatever base query they already have (`CartResource::getEloquentQuery()` for the Filament
|
||||||
|
tabs, a bare `Cart::query()` for the command). Deliberately query-shape-only: consent
|
||||||
// Abandoned Checkout
|
(`meta->recovery_consent`) and non-empty-lines filtering stay in `DetectAbandonedCarts`, not on
|
||||||
$query->whereHas('orders', fn ($q) => $q->whereNull('placed_at'))
|
the service — those gate whether a recovery *event* should fire, not what "abandoned" means to
|
||||||
->where('updated_at', '<=', CartResource::abandonedCutoff());
|
a staff member browsing the list.
|
||||||
|
|
||||||
// Completed
|
|
||||||
$query->whereHas('orders', fn ($q) => $q->whereNotNull('placed_at'));
|
|
||||||
```
|
|
||||||
|
|
||||||
There is deliberately **no "All" tab.** Every row shown is always scoped to one of the four
|
There is deliberately **no "All" tab.** Every row shown is always scoped to one of the four
|
||||||
states above — the list never runs an unfiltered `Cart::query()->get()` over the whole
|
states above — the list never runs an unfiltered `Cart::query()->get()` over the whole
|
||||||
@@ -111,7 +118,7 @@ runs once per admin page load, not once per cart row.
|
|||||||
```php
|
```php
|
||||||
public static function getNavigationBadge(): ?string
|
public static function getNavigationBadge(): ?string
|
||||||
{
|
{
|
||||||
return (string) static::getEloquentQuery()->active()->count();
|
return (string) static::getEloquentQuery()->active()->where('updated_at', '<=', static::abandonedCutoff())->count();
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -235,9 +242,10 @@ just upper-cases the code; `Lunar\Managers\DiscountManager::validateCoupon()` (v
|
|||||||
via a normal Eloquent write, so there's no model-event hook to dispatch from directly.
|
via a normal Eloquent write, so there's no model-event hook to dispatch from directly.
|
||||||
`Modules\Core\Cart\Commands\DetectAbandonedCarts` (registered on an hourly schedule by
|
`Modules\Core\Cart\Commands\DetectAbandonedCarts` (registered on an hourly schedule by
|
||||||
`Modules\Core\Providers\CartServiceProvider`) is the only place that moment gets detected: it
|
`Modules\Core\Providers\CartServiceProvider`) is the only place that moment gets detected: it
|
||||||
queries the same two branches `ListCarts::getTabs()` uses (no order at all vs. draft order
|
builds on the same `CartLifecycleService::abandonedCarts()`/`abandonedCheckouts()` queries
|
||||||
never placed) and dispatches `Modules\Core\Recovery\Events\CartAbandoned`/`CheckoutAbandoned`
|
`ListCarts::getTabs()` uses (no order at all vs. draft order never placed) and dispatches
|
||||||
for anything currently stale.
|
`Modules\Core\Recovery\Events\CartAbandoned`/`CheckoutAbandoned` for anything currently stale
|
||||||
|
that also has `meta->recovery_consent = true`.
|
||||||
|
|
||||||
### Cart/Checkout have zero abandonment-related writes — by design
|
### Cart/Checkout have zero abandonment-related writes — by design
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,189 @@
|
|||||||
|
# Payment — Design Notes
|
||||||
|
|
||||||
|
**Status: abstraction layer built, drivers/wiring in progress.** `Payment` is designed as a
|
||||||
|
standalone module: it never calls into `Checkout` or `Order`, never touches their Eloquent
|
||||||
|
models, and communicates only via events. This document is the design spec for that
|
||||||
|
abstraction — contracts, DTOs, events — independent of how `Checkout`/`Order` end up consuming
|
||||||
|
it (that wiring is a separate, later pass).
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Operations, not gateways
|
||||||
|
|
||||||
|
The driver contracts model the actual operations a payment gateway can perform, not vendor
|
||||||
|
terminology. Every real gateway checked while designing this converges on the same small set
|
||||||
|
under different names:
|
||||||
|
|
||||||
|
| Operation | Mastercard | Stripe | Nexi |
|
||||||
|
|---|---|---|---|
|
||||||
|
| Atomic charge (authorize+capture in one call) | `Pay` | `capture_method: automatic` | `ActionType::PAY()` |
|
||||||
|
| Hold only, settle/release later | `Authorize` | `capture_method: manual` | `ActionType::PREAUTH()` |
|
||||||
|
| Settle a prior hold | `Capture` | `PaymentIntent::capture()` | `CaptureRequest`/`CaptureResponse` |
|
||||||
|
| Release a prior hold without settling | `Void`/`Cancel` | `PaymentIntent::cancel()` | `CancelRequest`/`CancelResponse` |
|
||||||
|
| Reverse settled funds | `Refund` | `Refund::create()` | (refund endpoint) |
|
||||||
|
|
||||||
|
A driver implements only the interfaces its gateway actually supports:
|
||||||
|
|
||||||
|
- An offline/cash type (`cash-on-delivery`, `cash-in-hand`) only ever settles atomically —
|
||||||
|
implements `SupportsPay` alone.
|
||||||
|
- A card gateway capable of either mode per-transaction (Stripe, most card processors)
|
||||||
|
implements `SupportsPay`, `SupportsAuthorization`, `SupportsCaptures`, `SupportsVoids`, and
|
||||||
|
`SupportsRefunds` all at once — which one gets *called* for a given attempt is the caller's
|
||||||
|
policy choice (e.g. `config('lunar.stripe.policy')`), not something baked into the driver's
|
||||||
|
shape.
|
||||||
|
- A redirect/wallet gateway with no separate hold step (Viva/Klarna in typical flows)
|
||||||
|
implements `SupportsPay` and `SupportsRefunds`, never `SupportsCaptures`/`SupportsVoids`.
|
||||||
|
|
||||||
|
### `pay()` and `authorize()` stay separate methods even when a gateway implements both as "the same call with a flag"
|
||||||
|
|
||||||
|
Stripe has no separate `authorize`/`pay` API endpoints — one `PaymentIntent`, confirmed with
|
||||||
|
either `capture_method: automatic` or `manual`. Mastercard and Nexi *do* have genuinely
|
||||||
|
separate operations. The contract abstracts over both shapes uniformly: every driver capable
|
||||||
|
of both exposes two distinct methods, `pay()` and `authorize()`. A Mastercard-style driver
|
||||||
|
calls two different endpoints under the hood; a Stripe-style driver calls the same endpoint
|
||||||
|
twice with a different flag each time. Neither difference is visible to a caller.
|
||||||
|
|
||||||
|
### `capture()`/`void()` are only ever valid against a prior `authorize()`
|
||||||
|
|
||||||
|
They are not standalone operations — `capture()` settles a specific hold identified by the
|
||||||
|
`reference` `authorize()` returned; `void()` releases that same hold instead. A driver that
|
||||||
|
never implements `SupportsAuthorization` never produces a reference either of these methods
|
||||||
|
could act on.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## `PaymentResult` — the one return shape, every operation, every driver
|
||||||
|
|
||||||
|
```php
|
||||||
|
enum PaymentResultStatus { case Succeeded; case Failed; case Pending; }
|
||||||
|
|
||||||
|
final class PaymentResult {
|
||||||
|
public function __construct(
|
||||||
|
public readonly PaymentResultStatus $status,
|
||||||
|
public readonly string $reference,
|
||||||
|
public readonly int $amount,
|
||||||
|
public readonly ?string $failureReason = null,
|
||||||
|
public readonly bool $retriable = false,
|
||||||
|
public readonly array $raw = [],
|
||||||
|
public readonly array $meta = [],
|
||||||
|
) {}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
Real gateway responses vary wildly in richness — confirmed by reading three SDKs directly:
|
||||||
|
|
||||||
|
- **Stripe's `PaymentIntent`** is rich: `status`, `amount`, `amount_capturable`,
|
||||||
|
`amount_received`, `last_payment_error`, a full `getLastResponse()`.
|
||||||
|
- **Nexi's `CaptureResponse`/`CancelResponse`** are minimal: just `operationId` +
|
||||||
|
`operationTime` — no echoed amount or status at all. Success is inferred from getting a
|
||||||
|
response rather than an SDK exception.
|
||||||
|
- **Mastercard's** gateway sits in between, with `gatewayCode`/`acquirerCode`/
|
||||||
|
`merchantAdviceCode`.
|
||||||
|
|
||||||
|
`PaymentResult` only requires what every driver can always know: `status`, `reference`,
|
||||||
|
`amount` (the amount **we** requested — not necessarily echoed back by a sparse gateway like
|
||||||
|
Nexi's capture). Everything else is best-effort: `failureReason`/`retriable` are normalized
|
||||||
|
only when the gateway has something to normalize from; `raw` is the unconditional escape
|
||||||
|
hatch — the untouched gateway response body, always populated, for genuine audit fidelity
|
||||||
|
regardless of how sparse the normalized fields ended up.
|
||||||
|
|
||||||
|
### `retriable` — real on some gateways, absent on others
|
||||||
|
|
||||||
|
Stripe classifies declines as soft (`do_not_honor`, `insufficient_funds` — worth retrying,
|
||||||
|
after a delay) vs. hard (`stolen_card`, `expired_card` — never retry the same method).
|
||||||
|
Mastercard has the equivalent via `authorizationResponse.merchantAdviceCode` and card-scheme
|
||||||
|
soft-decline codes. **Nexi has no such signal at all** — `OperationResult` is just
|
||||||
|
`DECLINED`/`DENIED_BY_RISK`/`FAILED`/etc. with no retriability classification. `retriable`
|
||||||
|
therefore defaults to `false` (assume not safely retriable) rather than guessing when a
|
||||||
|
driver's gateway has nothing to base it on.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Events — one terminal pair per operation, keyed to the business fact, not the call path
|
||||||
|
|
||||||
|
`Modules\Core\Payment\Events`:
|
||||||
|
|
||||||
|
| Event pair | Dispatched by |
|
||||||
|
|---|---|
|
||||||
|
| `PaymentAuthorized` / `PaymentAuthorizationFailed` | `SupportsAuthorization::authorize()`, or a later `HandlesPaymentCallback::handleCallback()` resolving it |
|
||||||
|
| `PaymentCaptured` / `PaymentCaptureFailed` | `SupportsPay::pay()` **or** `SupportsCaptures::capture()` |
|
||||||
|
| `PaymentVoided` / `PaymentVoidFailed` | `SupportsVoids::void()` |
|
||||||
|
| `PaymentRefunded` / `PaymentRefundFailed` | `SupportsRefunds::refund()` |
|
||||||
|
|
||||||
|
`PaymentCaptured` is deliberately the *same* event whether money was taken via `pay()` (one
|
||||||
|
gateway call) or `authorize()` → `capture()` (two calls) — "a payment has been captured" is
|
||||||
|
the same business fact either way, and a listener reacting to it never needs to know which
|
||||||
|
path produced it. There is no separate "payment succeeded" wrapper event distinct from
|
||||||
|
`PaymentCaptured`.
|
||||||
|
|
||||||
|
Every event carries `{type: string, result: PaymentResult, context: array}`. `Payment` has no
|
||||||
|
concept of a `Cart`, an `Order`, or a checkout fingerprint — `$context` is an opaque bag the
|
||||||
|
caller hands in on the way down (`pay($type, $data, $context)`) and gets back untouched on
|
||||||
|
whichever event that call (or a later `handleCallback()`) produces. Each listener interprets
|
||||||
|
`$context` on its own terms, or ignores the event if the keys it needs aren't present —
|
||||||
|
`Checkout` is only one possible consumer of these events, not the only one.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Async resolution — `HandlesPaymentCallback`
|
||||||
|
|
||||||
|
Only implemented by a driver whose `pay()`/`authorize()` can return `PaymentResultStatus::Pending`
|
||||||
|
— a redirect the shopper completes elsewhere, a webhook that arrives later. A driver whose
|
||||||
|
gateway always resolves synchronously never implements this.
|
||||||
|
|
||||||
|
```php
|
||||||
|
public function handleCallback(string $reference, array $data, array $context = []): PaymentResult;
|
||||||
|
```
|
||||||
|
|
||||||
|
Resolves into the *same* event pair the original `pay()`/`authorize()` call would have
|
||||||
|
produced had it resolved synchronously.
|
||||||
|
|
||||||
|
### The correlation problem: `handleCallback()` runs in a different request
|
||||||
|
|
||||||
|
`$context` passed into the original `pay()`/`authorize()` call does not survive to
|
||||||
|
`handleCallback()` on its own — that call is typically a separate HTTP request (a webhook)
|
||||||
|
with no memory of the request that started the payment. Something has to persist enough to
|
||||||
|
answer "which order/cart does gateway reference X belong to?" between the two calls.
|
||||||
|
|
||||||
|
**Read directly from `lunarphp/stripe`'s own source** (`StripePaymentType::authorize()`,
|
||||||
|
`ProcessStripeWebhook`, `WebhookController`) to see how Lunar itself solves this — confirmed
|
||||||
|
it does **not** stash a generic opaque blob. It writes the correlating ids as real, typed
|
||||||
|
columns on `Lunar\Stripe\Models\StripePaymentIntent` (`cart_id`, `order_id`) at the moment the
|
||||||
|
intent is created/first seen, then reads them back the same way when the webhook arrives:
|
||||||
|
|
||||||
|
```php
|
||||||
|
// ProcessStripeWebhook::handle() — falls back through two real lookups,
|
||||||
|
// neither of them a generic context blob:
|
||||||
|
$cart = StripePaymentIntent::where('intent_id', $this->paymentIntentId)->first()?->cart
|
||||||
|
?: Cart::where('meta->payment_intent', '=', $this->paymentIntentId)->first();
|
||||||
|
```
|
||||||
|
|
||||||
|
**`StripePaymentDriver` follows this exact precedent**: it reads `cart_id`/`order_id` out of
|
||||||
|
`$context` at `pay()`/`authorize()` time and writes them onto its own `StripePaymentIntent`
|
||||||
|
row (a table already owned by `lunarphp/stripe`, already shaped for exactly this), then reads
|
||||||
|
them back the same way in `handleCallback()`. No generic `context` json column, no new table.
|
||||||
|
|
||||||
|
### This pattern is per-driver, not a shared table
|
||||||
|
|
||||||
|
`stripe_payment_intents` is Stripe-specific — keyed on `intent_id`, typed around
|
||||||
|
`Stripe\PaymentIntent`'s own status values. It cannot be reused as-is for a future non-Stripe
|
||||||
|
async driver (Nexi, Viva): that driver's own gateway reference has a different shape entirely,
|
||||||
|
and shoehorning it into Stripe-named columns would make the table misleading. The **pattern**
|
||||||
|
generalizes — *any* driver needing async callback resolution owns a small table keyed by its
|
||||||
|
own gateway's reference, storing whatever correlation data that driver specifically needs —
|
||||||
|
but each driver gets its own table, matching what it actually needs to correlate, rather than
|
||||||
|
a shared generic one.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Explicitly out of scope for this pass
|
||||||
|
|
||||||
|
- **`Checkout`/`Order` wiring** — how `Checkout` calls into `Payment`, how `Order`/`Checkout`
|
||||||
|
react to `Payment`'s events, where a draft `Order` gets created relative to when `Payment` is
|
||||||
|
called. Deliberately designed and built separately, after `Payment` itself was complete —
|
||||||
|
`Payment` must stand on its own regardless of what ends up consuming it.
|
||||||
|
- **`Transaction` persistence** — Lunar's own `transactions` table (`type`: `intent`/`capture`/
|
||||||
|
`refund`, `parent_transaction_id` chaining) already models the audit trail these events
|
||||||
|
would feed, once a listener is built to write to it. `Payment` itself does not write
|
||||||
|
`Transaction` rows — see the events table above; that is a listener's job, in whichever
|
||||||
|
module ends up owning the write (likely `Order`, since `Transaction.order_id` is required).
|
||||||
+46
-16
@@ -1,8 +1,9 @@
|
|||||||
# Product Listing
|
# Product Listing
|
||||||
|
|
||||||
`Modules\Core\Catalog\Services\ProductService` provides catalog browsing/filtering AND single-product
|
`Modules\Core\Catalog\Services\ProductService` provides catalog browsing/filtering AND single-product
|
||||||
lookup for a storefront — `list()`, `getById()`, `getBySlug()` — all reading directly from the
|
lookup for a storefront — `list()`, `getById()`, `getBySlug()`, `random()`, `variantSummaries()` —
|
||||||
Meilisearch index rather than the database. One data source for everything this service does.
|
all reading directly from the Meilisearch index rather than the database. One data source for
|
||||||
|
everything this service does.
|
||||||
|
|
||||||
This is separate from `Modules\Core\Catalog\Services\ProductSearchService` (see `product-search.md`), which
|
This is separate from `Modules\Core\Catalog\Services\ProductSearchService` (see `product-search.md`), which
|
||||||
handles free-text query search. `ProductService` is for browsing/lookup without a search term.
|
handles free-text query search. `ProductService` is for browsing/lookup without a search term.
|
||||||
@@ -28,13 +29,14 @@ use Modules\Core\Catalog\Enums\ProductSort;
|
|||||||
|
|
||||||
$service = app(ProductService::class);
|
$service = app(ProductService::class);
|
||||||
|
|
||||||
// List everything, paginated — returns a real Illuminate\Pagination\LengthAwarePaginator,
|
// One call for everything a listing page needs — products AND the price slider's
|
||||||
// built from the localized Meilisearch hits (not Scout's own paginateRaw() result — see
|
// bounds together, as a Modules\Core\Catalog\DTOs\ProductListingResult. A caller
|
||||||
// "Meilisearch driver quirk" below), so it behaves like any other Laravel paginator.
|
// used to have to call list() and priceSliderBounds() (or the older priceRange())
|
||||||
$products = $service->list(perPage: 24, page: 1);
|
// separately and glue the results together itself; that's now list()'s own job.
|
||||||
|
$listing = $service->list(perPage: 24, page: 1);
|
||||||
|
|
||||||
// Filter by collection, brand, price range, and/or stock
|
// Filter by collection, brand, price range, and/or stock
|
||||||
$products = $service->list(
|
$listing = $service->list(
|
||||||
filters: new ProductFilters(collectionId: 17, minPrice: 10.0, maxPrice: 50.0, inStockOnly: true),
|
filters: new ProductFilters(collectionId: 17, minPrice: 10.0, maxPrice: 50.0, inStockOnly: true),
|
||||||
perPage: 24,
|
perPage: 24,
|
||||||
page: 1,
|
page: 1,
|
||||||
@@ -42,8 +44,13 @@ $products = $service->list(
|
|||||||
|
|
||||||
// Sort — cheapest/priciest first, or newest first. Omit for Meilisearch's default
|
// Sort — cheapest/priciest first, or newest first. Omit for Meilisearch's default
|
||||||
// relevance ordering (irrelevant here since the query is always empty).
|
// relevance ordering (irrelevant here since the query is always empty).
|
||||||
$products = $service->list(perPage: 24, page: 1, sort: ProductSort::PriceAsc);
|
$listing = $service->list(perPage: 24, page: 1, sort: ProductSort::PriceAsc);
|
||||||
|
|
||||||
|
$products = $listing->products; // a real Illuminate\Pagination\LengthAwarePaginator,
|
||||||
|
// built from the localized Meilisearch hits (not Scout's
|
||||||
|
// own paginateRaw() result — see "Meilisearch driver
|
||||||
|
// quirk" below), so it behaves like any other Laravel
|
||||||
|
// paginator.
|
||||||
$products->items(); // array of Meilisearch documents (plain arrays, not models)
|
$products->items(); // array of Meilisearch documents (plain arrays, not models)
|
||||||
$products->total();
|
$products->total();
|
||||||
$products->perPage();
|
$products->perPage();
|
||||||
@@ -51,12 +58,32 @@ $products->currentPage();
|
|||||||
$products->lastPage();
|
$products->lastPage();
|
||||||
$products->links(); // in a Blade view — renders pagination links as usual
|
$products->links(); // in a Blade view — renders pagination links as usual
|
||||||
|
|
||||||
|
$bounds = $listing->priceBounds; // Modules\Core\Catalog\DTOs\PriceSliderBounds
|
||||||
|
$bounds->floor; // ?int — floor() of the matching range's minimum, in whole currency units
|
||||||
|
$bounds->ceil; // ?int — ceil() of the matching range's maximum
|
||||||
|
$bounds->filtered; // bool — whether the applied filters' minPrice/maxPrice actually
|
||||||
|
// narrow the slider below/above these bounds (drives whether a
|
||||||
|
// "clear filter" control should show)
|
||||||
|
|
||||||
// Single product, by primary key
|
// Single product, by primary key
|
||||||
$product = $service->getById(367); // array, or null if not found
|
$product = $service->getById(367); // array, or null if not found
|
||||||
|
|
||||||
// Single product, by URL slug (any locale — slugs are indexed across all languages)
|
// Single product, by URL slug (any locale — slugs are indexed across all languages)
|
||||||
$product = $service->getBySlug('erotika-mprelok'); // array, or null if not found
|
$product = $service->getBySlug('erotika-mprelok'); // array, or null if not found
|
||||||
|
|
||||||
|
// $limit random products — still scoped to the index's own default channel/status
|
||||||
|
// visibility, unlike Eloquent's Product::inRandomOrder() (which has no notion of
|
||||||
|
// that filtering at all). Meilisearch has no ORDER BY RANDOM() equivalent, so this
|
||||||
|
// pulls every matching id only, shuffles in PHP, then fetches the full localized
|
||||||
|
// documents for just the ids picked — see random()'s own docblock.
|
||||||
|
$randomProducts = $service->random(13); // array of documents, same shape as list()'s items
|
||||||
|
|
||||||
|
// The id/price/image of every variant on a product document — the base price and
|
||||||
|
// thumbnail a variant picker/swatch list needs, without reaching into
|
||||||
|
// $product['variants'][n]['prices'][0]/['media'][0] yourself.
|
||||||
|
$variants = $service->variantSummaries($product);
|
||||||
|
// [['id' => 1204, 'price' => 19.99, 'image' => 'https://.../thumb.jpg'], ...]
|
||||||
|
|
||||||
// Facet counts for a sidebar — value => matching product count, scoped to whatever
|
// Facet counts for a sidebar — value => matching product count, scoped to whatever
|
||||||
// $filters is passed. Does NOT exclude the faceted field itself from $filters — see
|
// $filters is passed. Does NOT exclude the faceted field itself from $filters — see
|
||||||
// facets()'s docblock for why, and how to build a standard "every option's count,
|
// facets()'s docblock for why, and how to build a standard "every option's count,
|
||||||
@@ -64,11 +91,13 @@ $product = $service->getBySlug('erotika-mprelok'); // array, or null if not fo
|
|||||||
$brandCounts = $service->facets('brand', filters: new ProductFilters(collectionId: 17));
|
$brandCounts = $service->facets('brand', filters: new ProductFilters(collectionId: 17));
|
||||||
// ['3Dealer.gr - 3D printed creations' => 48, 'Kraniou Topos - 3D printed creations' => 135]
|
// ['3Dealer.gr - 3D printed creations' => 48, 'Kraniou Topos - 3D printed creations' => 135]
|
||||||
|
|
||||||
// Min/max price across matching products, for sizing a price-range slider.
|
// Min/max price across matching products — the raw, unrounded values list() itself
|
||||||
// minPrice/maxPrice are ALWAYS excluded from the filter driving this (unlike
|
// uses to build priceBounds above. minPrice/maxPrice are ALWAYS excluded from the
|
||||||
// facets(), which doesn't auto-exclude) — the slider's own bounds shouldn't shrink
|
// filter driving this (unlike facets(), which doesn't auto-exclude) — the slider's
|
||||||
// to whatever range is currently selected on it. Other filters (collectionId,
|
// own bounds shouldn't shrink to whatever range is currently selected on it. Other
|
||||||
// brand, inStockOnly) still apply normally.
|
// filters (collectionId, brand, inStockOnly) still apply normally. Pass $query too
|
||||||
|
// to scope the range to a text search's own matches (see product-search.md) rather
|
||||||
|
// than the whole catalog.
|
||||||
$range = $service->priceRange(new ProductFilters(collectionId: 17));
|
$range = $service->priceRange(new ProductFilters(collectionId: 17));
|
||||||
// ['min' => 0.0, 'max' => 120.0]
|
// ['min' => 0.0, 'max' => 120.0]
|
||||||
```
|
```
|
||||||
@@ -77,8 +106,8 @@ All `ProductFilters` fields are optional; only the ones set are added to the Mei
|
|||||||
|
|
||||||
`facets()` only makes sense on discrete-value filterable fields (`brand`, `in_stock`) — a numeric
|
`facets()` only makes sense on discrete-value filterable fields (`brand`, `in_stock`) — a numeric
|
||||||
field like `price` would return one "facet" per exact price, not a usable range bucket. Use
|
field like `price` would return one "facet" per exact price, not a usable range bucket. Use
|
||||||
`priceRange()` for `price` instead, which reads Meilisearch's `facetStats` (min/max), a different
|
`priceRange()` (or `list()`'s own `priceBounds`) for `price` instead, which reads Meilisearch's
|
||||||
feature from `facetDistribution`.
|
`facetStats` (min/max), a different feature from `facetDistribution`.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -106,11 +135,12 @@ needs, listing and detail alike:
|
|||||||
| `collections` | `$product->collections` | Array of `{id, name}` — directly assigned collections only, `name` is the translated collection name. Not filterable — see `collection_ids`. |
|
| `collections` | `$product->collections` | Array of `{id, name}` — directly assigned collections only, `name` is the translated collection name. Not filterable — see `collection_ids`. |
|
||||||
| `collection_ids` | `$product->collections` + `->ancestors` | Filterable. Flat array of every directly-assigned collection's id, unioned with all of its ancestors' ids. `ProductFilters(collectionId: ...)` filters against this field, not `collections`, since products are typically attached only to leaf collections — a plain direct-match filter would never return anything for a parent/root category page. |
|
| `collection_ids` | `$product->collections` + `->ancestors` | Filterable. Flat array of every directly-assigned collection's id, unioned with all of its ancestors' ids. `ProductFilters(collectionId: ...)` filters against this field, not `collections`, since products are typically attached only to leaf collections — a plain direct-match filter would never return anything for a parent/root category page. |
|
||||||
| `slugs` | `$product->urls->pluck('slug')` | Filterable. Every locale's `Url::slug` for the product, so `getBySlug()` resolves purely from the index — no database read. |
|
| `slugs` | `$product->urls->pluck('slug')` | Filterable. Every locale's `Url::slug` for the product, so `getBySlug()` resolves purely from the index — no database read. |
|
||||||
|
| `skus` | `$product->variants->pluck('sku')` | Filterable. Every variant's `sku`, deduplicated, empty ones dropped. Same "resolve from the index alone" reasoning as `slugs`, for a future SKU-based lookup/filter. |
|
||||||
| `price` | Cheapest variant's base price | Filterable. Float in major units (e.g. `19.99`, not `1999`). Base price only — no customer group, default currency (`Currency::getDefault()`) only. `null` if the product has no priced variant yet, so it's excluded from range filters rather than treated as free. |
|
| `price` | Cheapest variant's base price | Filterable. Float in major units (e.g. `19.99`, not `1999`). Base price only — no customer group, default currency (`Currency::getDefault()`) only. `null` if the product has no priced variant yet, so it's excluded from range filters rather than treated as free. |
|
||||||
| `brand` | Already indexed by Lunar's base indexer | Newly marked **filterable** — it existed in the document already, just wasn't usable in a `filter` clause. |
|
| `brand` | Already indexed by Lunar's base indexer | Newly marked **filterable** — it existed in the document already, just wasn't usable in a `filter` clause. |
|
||||||
| `tags` | `$product->tags->pluck('value')` | Display only. |
|
| `tags` | `$product->tags->pluck('value')` | Display only. |
|
||||||
| `media` | `$product->media` | Full gallery (id/url/thumb per image), not just the single thumbnail Lunar's base indexer sends. |
|
| `media` | `$product->media` | Full gallery (id/url/thumb per image), not just the single thumbnail Lunar's base indexer sends. |
|
||||||
| `variants` | `$product->variants` | Per variant: `id`, `sku`, `stock`, `purchasable`, `options` (option/value names, in the current locale), `prices` (per currency/customer group), `media` (variant-specific images). |
|
| `variants` | `$product->variants` | Per variant: `id`, `sku`, `gtin`, `mpn`, `ean`, `stock`, `backorder`, `unit_quantity`, `purchasable`, `shippable`, `tax_ref`, `dimensions` (`length`/`width`/`height`/`weight`/`volume`, each `{value, unit}`), `options` (option/value names, in the current locale), `prices` (per currency/customer group), `media` (the variant's own images — `ProductVariant::images()`, a separate pivot from the product's own gallery above, populated by `ShopifyExportImporter` from Shopify's `Variant Image` CSV column). |
|
||||||
| `reviews` | `Modules\Core\Review\Models\ProductReview` | `{items, count, average_rating}` — see "Reviews" below. |
|
| `reviews` | `Modules\Core\Review\Models\ProductReview` | `{items, count, average_rating}` — see "Reviews" below. |
|
||||||
| `in_stock` | `$model->variants` | Filterable boolean. `true` if ANY variant currently passes `ProductVariant::canBeFulfilledAtQuantity(1)` — Lunar's own purchasability rule (`purchasable === 'always'` ignores stock entirely; `in_stock` checks `stock` alone; anything else checks `stock + backorder`). Only as fresh as the last reindex — see "Stock goes stale" below. |
|
| `in_stock` | `$model->variants` | Filterable boolean. `true` if ANY variant currently passes `ProductVariant::canBeFulfilledAtQuantity(1)` — Lunar's own purchasability rule (`purchasable === 'always'` ignores stock entirely; `in_stock` checks `stock` alone; anything else checks `stock + backorder`). Only as fresh as the last reindex — see "Stock goes stale" below. |
|
||||||
|
|
||||||
|
|||||||
+39
-13
@@ -24,36 +24,62 @@ merges `$builder->options` directly into the search request).
|
|||||||
## Usage
|
## Usage
|
||||||
|
|
||||||
```php
|
```php
|
||||||
|
use Modules\Core\Catalog\DTOs\ProductFilters;
|
||||||
|
use Modules\Core\Catalog\Enums\ProductSort;
|
||||||
use Modules\Core\Catalog\Services\ProductSearchService;
|
use Modules\Core\Catalog\Services\ProductSearchService;
|
||||||
|
|
||||||
$results = app(ProductSearchService::class)->search('running shoes');
|
$results = app(ProductSearchService::class)->search('running shoes');
|
||||||
// or an explicit locale, bypassing App::getLocale():
|
|
||||||
$results = app(ProductSearchService::class)->search('running shoes', 'el');
|
// Filters/sort apply the exact same semantics ProductService::list() uses for
|
||||||
|
// collection browsing (same ProductFilterBuilder, same ProductSort) — a shopper
|
||||||
|
// narrowing a text search by price/brand/stock gets identical filter behavior
|
||||||
|
// to narrowing a category listing.
|
||||||
|
$results = app(ProductSearchService::class)->search(
|
||||||
|
'running shoes',
|
||||||
|
filters: new ProductFilters(brand: 'Acme', minPrice: 20.0, inStockOnly: true),
|
||||||
|
sort: ProductSort::PriceAsc,
|
||||||
|
);
|
||||||
```
|
```
|
||||||
|
|
||||||
Returns an `Illuminate\Database\Eloquent\Collection` of `Lunar\Models\Product` — Scout's
|
Returns an `Illuminate\Database\Eloquent\Collection` of `Lunar\Models\Product` — Scout's
|
||||||
`->get()` hydrates real models from the database after the Meilisearch query, so relations
|
`->get()` hydrates real models from the database after the Meilisearch query, so relations
|
||||||
(`variants`, `brand`, `media`, etc.) are available on the results as normal.
|
(`variants`, `brand`, `media`, etc.) are available on the results as normal.
|
||||||
|
|
||||||
`$locale` defaults to `App::getLocale()` — already set correctly on every storefront request by
|
There is no `$locale` parameter — see "Field list is dynamic, not hardcoded" below for why
|
||||||
`Modules\Core\Localization\Middleware\LocaleMiddleware` (see `localization.md`), so callers in controllers
|
every configured store language is always searched, regardless of the current request locale.
|
||||||
don't need to pass it explicitly.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Missing-translation fallback
|
## Missing-translation fallback, in both directions
|
||||||
|
|
||||||
If a product was only ever given an English name, `name_el` doesn't exist on that document at
|
If a product was only ever given an English name, `name_el` doesn't exist on that document at
|
||||||
all (Lunar's indexer only writes a `{handle}_{locale}` field for locales actually present in the
|
all (Lunar's indexer only writes a `{handle}_{locale}` field for locales actually present in the
|
||||||
attribute's stored data — see `ScoutIndexer::mapSearchableAttributes()`). Searching strictly
|
attribute's stored data — see `ScoutIndexer::mapSearchableAttributes()`). Searching strictly
|
||||||
against `name_el` would make that product invisible to Greek-locale search, even though it's a
|
against the current request's locale field would make that product invisible whenever a shopper's
|
||||||
real catalog item.
|
locale doesn't match the language it happens to be translated into.
|
||||||
|
|
||||||
To avoid silently hiding incompletely-translated products, `ProductSearchService` targets **both**
|
`ProductSearchService` avoids this by targeting **every configured store language's fields**
|
||||||
the resolved locale's fields **and** the default language's fields
|
(`Lunar\Models\Language::all()`) on every search, not just the current request locale plus the
|
||||||
(`Lunar\Models\Language::getDefault()->code`) — e.g. searching in `el` targets `name_el`,
|
store default — e.g. with `el`/`en` configured, every search targets `name_el`, `name_en`,
|
||||||
`name_en`, `description_el`, `description_en` together (assuming `en` is the default language).
|
`description_el`, `description_en` together, regardless of which locale the shopper is browsing
|
||||||
A product missing an `el` translation still matches via its `en` fields.
|
in. This is deliberately not scoped to "current locale + default locale": if the current locale
|
||||||
|
already equals the default (a single-language store, or a shopper browsing in the default
|
||||||
|
language), that pairing collapses to one locale and stops catching anything else — always
|
||||||
|
searching every configured language avoids that gap in both directions, at the cost of a larger
|
||||||
|
`attributesToSearchOn` list as the store's language count grows.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Variant option values are searched too
|
||||||
|
|
||||||
|
Alongside the locale-suffixed attribute fields, every search also targets
|
||||||
|
`variants.options.value` directly — e.g. a variant named "Κάπτεν Γαμέρικα" on a "Name" option
|
||||||
|
matches a search for that text, even though it never appears in the product's own name or
|
||||||
|
description. This isn't one of Lunar's own attributes (`AttributeManifest` has no entry for it),
|
||||||
|
so it can't be discovered the way `name`/`description` are — it's a structural field of
|
||||||
|
`Modules\Core\Catalog\Services\ProductIndexer`'s own document shape (see `ProductIndexer::mapVariant()`),
|
||||||
|
added here directly. Not locale-suffixed — each option value is stored as one already-resolved
|
||||||
|
string per variant.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,450 @@
|
|||||||
|
<title>Order Feature Survey</title>
|
||||||
|
<style>
|
||||||
|
:root {
|
||||||
|
--paper: #FAFAF7;
|
||||||
|
--ink: #1C1C1A;
|
||||||
|
--muted: #6B6B63;
|
||||||
|
--accent: #2F5D50;
|
||||||
|
--accent-soft: #E4EDE9;
|
||||||
|
--good: #3F7A5C;
|
||||||
|
--good-soft: #E6F0EA;
|
||||||
|
--warn: #B8863B;
|
||||||
|
--warn-soft: #F5ECDC;
|
||||||
|
--miss: #A14B3B;
|
||||||
|
--miss-soft: #F5E5E0;
|
||||||
|
--hairline: #E4E2DB;
|
||||||
|
--card: #FFFFFF;
|
||||||
|
}
|
||||||
|
|
||||||
|
:root:not([data-theme="light"]) {
|
||||||
|
@media (prefers-color-scheme: dark) {
|
||||||
|
--paper: #17181A;
|
||||||
|
--ink: #EDEBE4;
|
||||||
|
--muted: #9B9A90;
|
||||||
|
--accent: #7FBFA8;
|
||||||
|
--accent-soft: #1E2C27;
|
||||||
|
--good: #6FBF97;
|
||||||
|
--good-soft: #1B2A22;
|
||||||
|
--warn: #D9A85C;
|
||||||
|
--warn-soft: #2C2418;
|
||||||
|
--miss: #D97C68;
|
||||||
|
--miss-soft: #2E1E1A;
|
||||||
|
--hairline: #2C2D2E;
|
||||||
|
--card: #1E1F21;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
:root[data-theme="dark"] {
|
||||||
|
--paper: #17181A;
|
||||||
|
--ink: #EDEBE4;
|
||||||
|
--muted: #9B9A90;
|
||||||
|
--accent: #7FBFA8;
|
||||||
|
--accent-soft: #1E2C27;
|
||||||
|
--good: #6FBF97;
|
||||||
|
--good-soft: #1B2A22;
|
||||||
|
--warn: #D9A85C;
|
||||||
|
--warn-soft: #2C2418;
|
||||||
|
--miss: #D97C68;
|
||||||
|
--miss-soft: #2E1E1A;
|
||||||
|
--hairline: #2C2D2E;
|
||||||
|
--card: #1E1F21;
|
||||||
|
}
|
||||||
|
|
||||||
|
* { box-sizing: border-box; }
|
||||||
|
|
||||||
|
body {
|
||||||
|
background: var(--paper);
|
||||||
|
color: var(--ink);
|
||||||
|
font-family: "IBM Plex Sans", ui-sans-serif, system-ui, sans-serif;
|
||||||
|
font-size: 15.5px;
|
||||||
|
line-height: 1.55;
|
||||||
|
margin: 0;
|
||||||
|
padding: 4.5rem 1.5rem 6rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.wrap {
|
||||||
|
max-width: 780px;
|
||||||
|
margin: 0 auto;
|
||||||
|
}
|
||||||
|
|
||||||
|
header.page {
|
||||||
|
margin-bottom: 3.25rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.eyebrow {
|
||||||
|
font-family: "IBM Plex Mono", ui-monospace, monospace;
|
||||||
|
font-size: 0.72rem;
|
||||||
|
letter-spacing: 0.12em;
|
||||||
|
text-transform: uppercase;
|
||||||
|
color: var(--accent);
|
||||||
|
margin-bottom: 0.9rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
h1 {
|
||||||
|
font-family: "Fraunces", Georgia, serif;
|
||||||
|
font-weight: 560;
|
||||||
|
font-size: clamp(2.1rem, 4.5vw, 2.65rem);
|
||||||
|
line-height: 1.08;
|
||||||
|
letter-spacing: -0.01em;
|
||||||
|
margin: 0 0 0.9rem;
|
||||||
|
text-wrap: balance;
|
||||||
|
}
|
||||||
|
|
||||||
|
.dek {
|
||||||
|
color: var(--muted);
|
||||||
|
max-width: 60ch;
|
||||||
|
font-size: 1.02rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.dek strong {
|
||||||
|
color: var(--ink);
|
||||||
|
font-weight: 600;
|
||||||
|
}
|
||||||
|
|
||||||
|
.legend {
|
||||||
|
display: flex;
|
||||||
|
flex-wrap: wrap;
|
||||||
|
gap: 0.6rem;
|
||||||
|
margin-top: 1.6rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.chip {
|
||||||
|
display: inline-flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 0.4rem;
|
||||||
|
font-family: "IBM Plex Mono", ui-monospace, monospace;
|
||||||
|
font-size: 0.72rem;
|
||||||
|
letter-spacing: 0.04em;
|
||||||
|
padding: 0.28rem 0.6rem;
|
||||||
|
border-radius: 3px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.chip.have { background: var(--good-soft); color: var(--good); }
|
||||||
|
.chip.partial { background: var(--warn-soft); color: var(--warn); }
|
||||||
|
.chip.missing { background: var(--miss-soft); color: var(--miss); }
|
||||||
|
|
||||||
|
section.category {
|
||||||
|
margin-top: 3rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.cat-head {
|
||||||
|
display: flex;
|
||||||
|
align-items: baseline;
|
||||||
|
gap: 0.85rem;
|
||||||
|
border-bottom: 1px solid var(--hairline);
|
||||||
|
padding-bottom: 0.7rem;
|
||||||
|
margin-bottom: 1.1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.cat-num {
|
||||||
|
font-family: "Fraunces", Georgia, serif;
|
||||||
|
font-size: 1.05rem;
|
||||||
|
color: var(--accent);
|
||||||
|
font-variant-numeric: tabular-nums;
|
||||||
|
min-width: 1.6rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.cat-head h2 {
|
||||||
|
font-family: "Fraunces", Georgia, serif;
|
||||||
|
font-weight: 500;
|
||||||
|
font-size: 1.28rem;
|
||||||
|
margin: 0;
|
||||||
|
letter-spacing: -0.005em;
|
||||||
|
}
|
||||||
|
|
||||||
|
.cat-note {
|
||||||
|
color: var(--muted);
|
||||||
|
font-size: 0.86rem;
|
||||||
|
margin: 0 0 1.2rem;
|
||||||
|
max-width: 62ch;
|
||||||
|
}
|
||||||
|
|
||||||
|
.feature {
|
||||||
|
display: grid;
|
||||||
|
grid-template-columns: 1fr auto;
|
||||||
|
gap: 0.3rem 1rem;
|
||||||
|
padding: 1.05rem 0;
|
||||||
|
border-bottom: 1px solid var(--hairline);
|
||||||
|
align-items: start;
|
||||||
|
}
|
||||||
|
|
||||||
|
.feature:last-child { border-bottom: none; }
|
||||||
|
|
||||||
|
.f-name {
|
||||||
|
font-weight: 600;
|
||||||
|
font-size: 0.98rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.f-status {
|
||||||
|
font-family: "IBM Plex Mono", ui-monospace, monospace;
|
||||||
|
font-size: 0.68rem;
|
||||||
|
letter-spacing: 0.06em;
|
||||||
|
text-transform: uppercase;
|
||||||
|
padding: 0.22rem 0.55rem;
|
||||||
|
border-radius: 3px;
|
||||||
|
white-space: nowrap;
|
||||||
|
height: fit-content;
|
||||||
|
}
|
||||||
|
|
||||||
|
.f-status.have { background: var(--good-soft); color: var(--good); }
|
||||||
|
.f-status.partial { background: var(--warn-soft); color: var(--warn); }
|
||||||
|
.f-status.missing { background: var(--miss-soft); color: var(--miss); }
|
||||||
|
|
||||||
|
.f-note {
|
||||||
|
grid-column: 1 / -1;
|
||||||
|
color: var(--muted);
|
||||||
|
font-size: 0.87rem;
|
||||||
|
margin-top: 0.15rem;
|
||||||
|
max-width: 66ch;
|
||||||
|
}
|
||||||
|
|
||||||
|
.f-note code {
|
||||||
|
font-family: "IBM Plex Mono", ui-monospace, monospace;
|
||||||
|
font-size: 0.82em;
|
||||||
|
background: var(--accent-soft);
|
||||||
|
color: var(--accent);
|
||||||
|
padding: 0.08em 0.35em;
|
||||||
|
border-radius: 3px;
|
||||||
|
}
|
||||||
|
|
||||||
|
footer.page {
|
||||||
|
margin-top: 4rem;
|
||||||
|
padding-top: 1.5rem;
|
||||||
|
border-top: 1px solid var(--hairline);
|
||||||
|
color: var(--muted);
|
||||||
|
font-size: 0.82rem;
|
||||||
|
display: flex;
|
||||||
|
justify-content: space-between;
|
||||||
|
gap: 1rem;
|
||||||
|
flex-wrap: wrap;
|
||||||
|
}
|
||||||
|
|
||||||
|
footer.page a { color: var(--accent); }
|
||||||
|
|
||||||
|
@media (max-width: 560px) {
|
||||||
|
body { padding: 3rem 1.1rem 4rem; }
|
||||||
|
.feature { grid-template-columns: 1fr; }
|
||||||
|
.f-status { justify-self: start; }
|
||||||
|
}
|
||||||
|
</style>
|
||||||
|
<link rel="stylesheet" href="https://fonts.googleapis.com/css2?family=Fraunces:opsz,wght@9..144,400..600&family=IBM+Plex+Sans:wght@400;500;600&family=IBM+Plex+Mono:wght@400;500&display=swap">
|
||||||
|
|
||||||
|
<div class="wrap">
|
||||||
|
|
||||||
|
<header class="page">
|
||||||
|
<div class="eyebrow">boboko / order · competitive survey</div>
|
||||||
|
<h1>What order management elsewhere can do that boboko can't yet</h1>
|
||||||
|
<p class="dek">
|
||||||
|
Where the Checkout survey stopped — the instant <code>Order</code> exists — this
|
||||||
|
one starts. A feature-by-feature pass across Shopify, WooCommerce, PrestaShop, and
|
||||||
|
(briefly) Magento's post-placement order layer — sourced, not recalled from memory —
|
||||||
|
checked against what <strong>Lunar's <code>Order</code> model and the
|
||||||
|
already-shipped Filament <code>ManageOrder</code> page</strong> actually support
|
||||||
|
today. For deciding what the new <code>Order</code> module needs to own, not a
|
||||||
|
build order.
|
||||||
|
</p>
|
||||||
|
<div class="legend">
|
||||||
|
<span class="chip have">● have</span>
|
||||||
|
<span class="chip partial">◐ partial</span>
|
||||||
|
<span class="chip missing">○ missing</span>
|
||||||
|
</div>
|
||||||
|
</header>
|
||||||
|
|
||||||
|
<section class="category">
|
||||||
|
<div class="cat-head">
|
||||||
|
<span class="cat-num">01</span>
|
||||||
|
<h2>Status model</h2>
|
||||||
|
</div>
|
||||||
|
<p class="cat-note">One field, or several axes — and who's allowed to move it.</p>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Payment status independent of a single overall status</div>
|
||||||
|
<span class="f-status partial">partial</span>
|
||||||
|
<div class="f-note">The data exists — <code>ManageOrder::paymentStatus()</code> derives a real value from <code>transactions()</code>/<code>captureTotal()</code>/<code>refundTotal()</code>/<code>intentTotal()</code> — but it's a computed display value on the admin page, not a stored column or something the rest of the system (mailers, automations) can key off. Shopify and Magento both make payment status a first-class, independently-queryable dimension; here it's derived on the fly, once, in one Filament page.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Fulfillment status independent of overall status</div>
|
||||||
|
<span class="f-status missing">missing</span>
|
||||||
|
<div class="f-note">No equivalent of <code>paymentStatus()</code> exists for shipment/fulfillment state — <code>Order</code> has no <code>shipments()</code> relation of its own at all; it's added dynamically by <code>Modules\Core\Shipping\Providers\ShippingServiceProvider::resolveRelationUsing()</code>, outside Order's own boundary (see docs/checkout.md, "Where Order would likely absorb work"). Every platform researched (Shopify, Woo, PrestaShop, Magento) treats "has this shipped" as derivable from child records, not a manually-set field — Lunar has the child records (<code>Shipment</code>) but no derived status method reading them.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Staff-editable order status with a picker/action</div>
|
||||||
|
<span class="f-status have">have</span>
|
||||||
|
<div class="f-note"><code>ManageOrder</code> ships a working <code>UpdateStatusAction</code> out of the box, backed by <code>config('lunar.orders.statuses')</code> — a flat, merchant-configured list, each entry carrying a <code>label</code>/<code>color</code>/<code>favourite</code> flag. Closer to WooCommerce's single linear field than Shopify's multi-axis split.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Status rows carry behavior (auto-send email, generate invoice, restock)</div>
|
||||||
|
<span class="f-status partial">partial</span>
|
||||||
|
<div class="f-note">Each status entry in <code>config('lunar.orders.statuses')</code> already declares <code>mailers</code> and <code>notifications</code> arrays — the PrestaShop-style shape is there in config — but per the Checkout survey's finding, nothing in core actually reads and dispatches from those keys on a transition. The data model for "status carries behavior" exists; the behavior doesn't.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Order-status-changed event other code can react to</div>
|
||||||
|
<span class="f-status missing">missing</span>
|
||||||
|
<div class="f-note">Same gap the Checkout survey flagged for order creation: no <code>OrderStatusUpdated</code>/equivalent exists anywhere in core. <code>UpdateStatusAction</code> just writes the column. Anything wanting to react to a status change — a confirmation email, a webhook, re-deriving payment/fulfillment status — has to hook the raw Eloquent <code>Order::updated()</code> event and diff <code>status</code> itself.</div>
|
||||||
|
</div>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<section class="category">
|
||||||
|
<div class="cat-head">
|
||||||
|
<span class="cat-num">02</span>
|
||||||
|
<h2>Fulfillment & shipment tracking</h2>
|
||||||
|
</div>
|
||||||
|
<p class="cat-note">Turning a placed order into a package that moves.</p>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Shipment as its own record, separate from the order</div>
|
||||||
|
<span class="f-status have">have</span>
|
||||||
|
<div class="f-note"><code>Modules\Core\Shipping\Models\Shipment</code> (carrier, tracking reference, label-printed timestamp, manifest reference) already exists and belongs to <code>Order</code>. Built this session, ahead of most gaps in this survey — the record shape is closer to Magento's per-shipment entity than Woo's "no shipment entity at all."</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Multiple shipments per order (partial/split fulfillment)</div>
|
||||||
|
<span class="f-status partial">partial</span>
|
||||||
|
<div class="f-note"><code>Shipment</code> has no <code>quantity</code>-per-line or <code>order_line_id</code> concept — it's one shipment record per carrier voucher, with a <code>parent_reference</code> for ACS's own multipart-voucher case (one physical order split into multiple packages by the carrier), not a per-line-item fulfillment split decided by staff. Closer to "multiple packages for one shipment" than Magento's true per-line partial-shipment model.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Create-shipment action from the order admin screen</div>
|
||||||
|
<span class="f-status have">have</span>
|
||||||
|
<div class="f-note"><code>Modules\Core\Shipping\Extensions\OrderViewExtension</code> adds a working "Create Shipment" header action to <code>ManageOrder</code>, resolving a <code>CarrierFulfillmentInterface</code> by the order's chosen shipping method and calling <code>createShipment()</code> — genuinely wired, not a stub. Currently lives under <code>Shipping</code>, flagged in docs/checkout.md as conceptually an <code>Order</code> concern.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Tracking number + carrier surfaced on the order itself</div>
|
||||||
|
<span class="f-status have">have</span>
|
||||||
|
<div class="f-note"><code>Shipment.tracking_reference</code>/<code>carrier</code> exist and are populated by <code>createShipment()</code>; <code>PollShipmentTrackingJob</code> (scheduled every 30 minutes) keeps <code>ShipmentInfo</code> checkpoints current via <code>CarrierFulfillmentInterface::trackShipment()</code>. Genuinely ahead of PrestaShop's thin <code>order_carrier.tracking_number</code> field — this has a real checkpoint history, not just one string.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">"Shipped"/"delivered" status auto-derived from tracking</div>
|
||||||
|
<span class="f-status missing">missing</span>
|
||||||
|
<div class="f-note">The tracking checkpoints exist (<code>ShipmentInfo</code>, <code>TrackingStatus</code> enum including <code>Delivered</code>) but nothing writes them back onto <code>Order.status</code> — a delivered shipment doesn't move the order out of whatever status it was already in. Every platform researched treats "delivered" as a status a customer/staff can see on the order, not something buried one relation away.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Shipping/delivery notification emails (shipped, out-for-delivery, delivered)</div>
|
||||||
|
<span class="f-status missing">missing</span>
|
||||||
|
<div class="f-note">Research: Shopify fires four separate templated notifications across this window alone (shipping confirmation, out-for-delivery, delivered, plus edited-order). None of the pieces exist here — no order-status-changed event (01) to trigger from, and no mailer wired to <code>PollShipmentTrackingJob</code>'s own status updates either.</div>
|
||||||
|
</div>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<section class="category">
|
||||||
|
<div class="cat-head">
|
||||||
|
<span class="cat-num">03</span>
|
||||||
|
<h2>Payments: capture, refund, cancellation</h2>
|
||||||
|
</div>
|
||||||
|
<p class="cat-note">Money moving back out, and orders that never should have been placed.</p>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Refund action from the order screen, amount-scoped</div>
|
||||||
|
<span class="f-status have">have</span>
|
||||||
|
<div class="f-note"><code>ManageOrder</code>'s <code>refund</code> action already exists — picks a transaction, an amount (validated against <code>availableToRefund()</code>), and notes, then calls the driver's own <code>Transaction::refund()</code>. This is genuinely native, matching Woo/Magento's line-item-adjacent (if not line-item-exact) refund UX.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Capture action for auth-then-capture payment flows</div>
|
||||||
|
<span class="f-status have">have</span>
|
||||||
|
<div class="f-note"><code>ManageOrder</code>'s <code>capture</code> action + <code>requiresCapture()</code>/<code>canBeRefunded()</code> guard methods already exist, delegating to <code>Transaction::capture()</code> — this is the Stripe "authorize now, capture later" flow's admin-side half, already built ahead of most gaps here.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Refund tied to specific line items (not just a dollar amount)</div>
|
||||||
|
<span class="f-status missing">missing</span>
|
||||||
|
<div class="f-note">The refund action takes a transaction + amount, with no line-item selection or restock decision — WooCommerce and Magento both make "which items, how many, restock or not" the primary refund UI; here it's one number against one transaction, closer to a manual adjustment than a structured partial return.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Order cancellation as a distinct action (vs. just changing status)</div>
|
||||||
|
<span class="f-status missing">missing</span>
|
||||||
|
<div class="f-note">No dedicated "cancel" action exists on <code>ManageOrder</code> — a cancellation today would just be picking a "cancelled"-labeled entry from the generic status dropdown (01), with no automatic refund trigger, no stock-release logic, and no distinction from any other manual status edit.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Refund/capture reflected back into an order-level payment status</div>
|
||||||
|
<span class="f-status partial">partial</span>
|
||||||
|
<div class="f-note">Same gap as 01's payment-status finding — <code>paymentStatus()</code> recomputes correctly from transactions when the admin page loads, but a refund doesn't push the order into a <code>refunded</code>/<code>partially-refunded</code> overall status the way Shopify's <code>displayFinancialStatus</code> does automatically.</div>
|
||||||
|
</div>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<section class="category">
|
||||||
|
<div class="cat-head">
|
||||||
|
<span class="cat-num">04</span>
|
||||||
|
<h2>Returns (RMA)</h2>
|
||||||
|
</div>
|
||||||
|
<p class="cat-note">The one area every researched platform treats as optional, not core.</p>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Return-merchandise-authorization flow (customer requests, staff approves)</div>
|
||||||
|
<span class="f-status missing">missing</span>
|
||||||
|
<div class="f-note">No <code>Return</code>/RMA model, status set, or request flow exists anywhere in this codebase. Consistent with the research: Shopify is the only platform of the four with this genuinely native; PrestaShop ships it off-by-default; Magento gates it behind the paid Adobe Commerce tier; WooCommerce lacks it entirely. Safe to treat as a real gap, not an urgent one.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Return shipping label generation</div>
|
||||||
|
<span class="f-status missing">missing</span>
|
||||||
|
<div class="f-note">Depends entirely on the RMA flow above existing first — <code>CarrierFulfillmentInterface</code> already has the label-printing primitive (<code>printLabel()</code>) a return label would reuse, so the carrier-side plumbing isn't the blocker, the RMA request/approval model is.</div>
|
||||||
|
</div>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<section class="category">
|
||||||
|
<div class="cat-head">
|
||||||
|
<span class="cat-num">05</span>
|
||||||
|
<h2>Order editing</h2>
|
||||||
|
</div>
|
||||||
|
<p class="cat-note">Changing a placed order — and where every platform draws the line.</p>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Editing guardrails keyed to fulfillment state</div>
|
||||||
|
<span class="f-status missing">missing</span>
|
||||||
|
<div class="f-note">No line-item add/remove exists on a placed order at all today (unlike Shopify/Woo/PrestaShop, which all allow it up to some fulfillment-keyed cutoff, then force a return instead) — so there's no guardrail to speak of yet because there's no editing to guard. Whatever gets built here should key the cutoff to <code>Shipment</code> existing, per the pattern all four researched platforms converge on.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Editable shipping/billing address after placement</div>
|
||||||
|
<span class="f-status missing">missing</span>
|
||||||
|
<div class="f-note"><code>OrderAddress</code> rows are snapshotted at creation (see Checkout survey, 02) and nothing in <code>ManageOrder</code> exposes editing them afterward — every platform researched treats address edits as lower-risk than line-item edits and allows them more freely; this codebase currently allows neither.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Tag editing on a placed order</div>
|
||||||
|
<span class="f-status have">have</span>
|
||||||
|
<div class="f-note"><code>ManageOrder</code>'s <code>edit_tags</code> action already works — the one piece of native post-placement editing that exists today, via <code>HasTags</code> on the <code>Order</code> model.</div>
|
||||||
|
</div>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<section class="category">
|
||||||
|
<div class="cat-head">
|
||||||
|
<span class="cat-num">06</span>
|
||||||
|
<h2>Notes & audit trail</h2>
|
||||||
|
</div>
|
||||||
|
<p class="cat-note">The one thing every researched platform treats as non-negotiable.</p>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Append-only change history (who changed what, when)</div>
|
||||||
|
<span class="f-status have">have</span>
|
||||||
|
<div class="f-note"><code>Order</code> already uses Spatie's <code>LogsActivity</code> trait — every save is recorded with a diff, same underlying mechanism already relied on elsewhere in this codebase (staff activity log, translation history). Structurally equivalent to PrestaShop's <code>order_history</code> table, just via a different package.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Internal staff notes, separate from system-generated log entries</div>
|
||||||
|
<span class="f-status missing">missing</span>
|
||||||
|
<div class="f-note">The activity log above captures field changes automatically, but there's no free-text "leave a note for the next person" field — every platform researched has this as a distinct feed from the automatic history (Woo's Order Notes, Shopify's Timeline comments, Magento's Comments History), usually with a private-vs-customer-visible toggle. Nothing here yet.</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="feature">
|
||||||
|
<div class="f-name">Customer-visible note-to-customer, sent as a message</div>
|
||||||
|
<span class="f-status missing">missing</span>
|
||||||
|
<div class="f-note">Depends on both the internal-notes feature above and a working mailer (01/02) — genuinely blocked on more foundational gaps, not just unbuilt on its own.</div>
|
||||||
|
</div>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<footer class="page">
|
||||||
|
<span>Compiled 2026-09-01 — sources cited inline; <code>vendor/lunarphp/lunar</code> and this codebase's own <code>src/</code> reads are marked by file/class name, Shopify/WooCommerce/PrestaShop/Magento claims are marked "Research."</span>
|
||||||
|
<span>boboko-core / docs</span>
|
||||||
|
</footer>
|
||||||
|
|
||||||
|
</div>
|
||||||
@@ -2,6 +2,9 @@
|
|||||||
|
|
||||||
Findings from comparing a real Shopify product export CSV against Lunar's schema (`vendor/lunarphp/core`), plus the resulting implementation plan for `MigrateImport\Shopify\ShopifyExportImporter`.
|
Findings from comparing a real Shopify product export CSV against Lunar's schema (`vendor/lunarphp/core`), plus the resulting implementation plan for `MigrateImport\Shopify\ShopifyExportImporter`.
|
||||||
|
|
||||||
|
Need to discard everything and re-import from scratch (e.g. after a schema/indexer change that
|
||||||
|
only applies to newly-created rows)? See `docs/shopify-reimport.md`.
|
||||||
|
|
||||||
## Idempotency problem
|
## Idempotency problem
|
||||||
|
|
||||||
Nothing in Lunar tracks "this record came from external system X, ID Y." Re-running an import with no external-ID tracking would duplicate every product on each run.
|
Nothing in Lunar tracks "this record came from external system X, ID Y." Re-running an import with no external-ID tracking would duplicate every product on each run.
|
||||||
|
|||||||
@@ -0,0 +1,149 @@
|
|||||||
|
# Wiping products before a clean Shopify re-import
|
||||||
|
|
||||||
|
A runbook for discarding every imported product (and everything that hangs off one —
|
||||||
|
variants, prices, media, reviews, options/values, the Meilisearch documents) and re-running
|
||||||
|
`ShopifyExportImporter` from scratch. Useful after a schema/indexer change that only applies to
|
||||||
|
newly-created rows (see "Why a wipe, not an update" below), or when the export CSV itself changed
|
||||||
|
enough that stale products need to go, not just be updated in place.
|
||||||
|
|
||||||
|
Every command below is a `tinker --execute=` one-liner run inside the app container — adjust the
|
||||||
|
exec prefix (`./bin/dc-core.sh exec app ...`, `docker compose exec app ...`, etc.) for your setup.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Why a wipe, not an update
|
||||||
|
|
||||||
|
`ShopifyExportImporter`'s resolvers are mostly `firstOrCreate` — re-running the importer against
|
||||||
|
an *existing* database updates matched rows but leaves already-created ones exactly as they were.
|
||||||
|
That's the right behavior for routine re-imports (an updated price, a new variant), but it means a
|
||||||
|
change to what gets set **at creation time only** — e.g. `ProductOptionResolver` now also setting
|
||||||
|
`label`, not just `name`, on a `ProductOption` — never reaches a `ProductOption` row that already
|
||||||
|
exists. A wipe forces every row to go through creation again, picking up such fixes.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 1. Delete every product
|
||||||
|
|
||||||
|
Cascades to `ProductVariant`, prices, and Spatie media rows — verified live (see
|
||||||
|
`shopify-import.md`'s own history/commit log for context). Also removes each product's Meilisearch
|
||||||
|
document automatically, via Scout's own delete hook fired on `forceDelete()` — no separate
|
||||||
|
`scout:flush` needed.
|
||||||
|
|
||||||
|
```php
|
||||||
|
\Lunar\Models\Product::withTrashed()->get()->each->forceDelete();
|
||||||
|
```
|
||||||
|
|
||||||
|
**Let this run to completion.** Interrupting it mid-loop (e.g. Ctrl+C on the tinker session) stops
|
||||||
|
after whichever product it was on, leaving the rest undeleted — safe to just re-run the same
|
||||||
|
command again afterward, since already-deleted products are simply skipped.
|
||||||
|
|
||||||
|
Verify:
|
||||||
|
|
||||||
|
```php
|
||||||
|
\Lunar\Models\Product::withTrashed()->count(); // 0
|
||||||
|
```
|
||||||
|
|
||||||
|
### Requires: `product_reviews.product_id` cascades on delete
|
||||||
|
|
||||||
|
`product_reviews` (boboko-core's own table, not Lunar's) originally had no `ON DELETE` clause on
|
||||||
|
its `product_id` foreign key — deleting a reviewed product threw a constraint violation instead of
|
||||||
|
the review going with it. Fixed by
|
||||||
|
`database/migrations/2026_09_03_000001_add_cascade_delete_to_product_reviews_product_id.php`. Make
|
||||||
|
sure this migration has actually run (`php artisan migrate`) before step 1, or a product with
|
||||||
|
reviews will fail to delete.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 2. Delete product options and values
|
||||||
|
|
||||||
|
Not touched by step 1 (`ProductOption`/`ProductOptionValue` aren't scoped to one product — they're
|
||||||
|
shared across the catalog, per `ProductOptionResolver::resolveOption()`'s `shared: true`). Safe to
|
||||||
|
delete in full once every product (and therefore every variant referencing an option value via the
|
||||||
|
`product_option_value_product_variant` pivot) is gone — deleting values while variants still
|
||||||
|
reference them throws the same kind of FK violation step 1 guards against.
|
||||||
|
|
||||||
|
```php
|
||||||
|
\Lunar\Models\ProductOptionValue::query()->delete();
|
||||||
|
\Lunar\Models\ProductOption::query()->delete();
|
||||||
|
```
|
||||||
|
|
||||||
|
Verify:
|
||||||
|
|
||||||
|
```php
|
||||||
|
\Lunar\Models\ProductOption::count(); // 0
|
||||||
|
\Lunar\Models\ProductOptionValue::count(); // 0
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 3. Clear the import mappings
|
||||||
|
|
||||||
|
Without this, the importer's `ImportMapping::resolve(...)` calls still find the (now-deleted)
|
||||||
|
mappings' rows absent, so this step is really about not leaving stale mapping rows pointing at
|
||||||
|
nothing — `ImportMapping` rows aren't foreign-keyed to the models they map (`morphTo`, no
|
||||||
|
constraint), so leaving them wouldn't break the re-import, but a stale mapping for a product that
|
||||||
|
no longer exists is dead weight.
|
||||||
|
|
||||||
|
```php
|
||||||
|
\Modules\Core\MigrateImport\Models\ImportMapping::where('source', 'shopify')->delete();
|
||||||
|
```
|
||||||
|
|
||||||
|
Verify:
|
||||||
|
|
||||||
|
```php
|
||||||
|
\Modules\Core\MigrateImport\Models\ImportMapping::where('source', 'shopify')->count(); // 0
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 4. Re-run the importer
|
||||||
|
|
||||||
|
`boboko:migrate:import` dispatches `RunMigrateImportJob` onto the queue — **not synchronous** —
|
||||||
|
so a queue worker must actually be running (`php artisan queue:work`, or your dev queue container)
|
||||||
|
or the job just sits queued.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
php artisan boboko:migrate:import --source=shopify --type=export --file=<absolute path to the CSV>
|
||||||
|
```
|
||||||
|
|
||||||
|
The `--file` value must be an **absolute path** inside the container (e.g.
|
||||||
|
`/var/www/html/storage/app/private/imports/shopify/products_export.csv`) when running
|
||||||
|
non-interactively — a path relative to `storage/app/private/imports` only resolves correctly when
|
||||||
|
the command can fall back to its interactive prompt, which isn't available in a scripted/non-TTY
|
||||||
|
run.
|
||||||
|
|
||||||
|
Watch the queue worker's own log output for `FAIL` entries (see `docs/lunar.md` or your compose
|
||||||
|
setup for how logs are routed to `docker compose logs`) — a clean run shows every
|
||||||
|
`Laravel\Scout\Jobs\MakeSearchable` / `Spatie\MediaLibrary\Conversions\Jobs\PerformConversionsJob`
|
||||||
|
line ending `DONE`, never `FAIL`.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 5. Re-sync Meilisearch and reindex
|
||||||
|
|
||||||
|
```bash
|
||||||
|
php artisan lunar:meilisearch:setup
|
||||||
|
php artisan lunar:meilisearch:tune-product-search
|
||||||
|
php artisan lunar:search:index "Lunar\Models\Product" --refresh
|
||||||
|
```
|
||||||
|
|
||||||
|
`--refresh` re-syncs filterable/sortable index settings *and* reindexes every document — it does
|
||||||
|
not reset `typoTolerance`/`prefixSearch` (confirmed live: both survived a `--refresh` run
|
||||||
|
unchanged), so `tune-product-search` only needs re-running here for completeness/if it hadn't
|
||||||
|
already been applied, not because `--refresh` would have clobbered it.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Verifying the result
|
||||||
|
|
||||||
|
```php
|
||||||
|
// Product count should match the CSV's actual unique `Handle` count, not
|
||||||
|
// whatever the database held before the wipe — those aren't the same number
|
||||||
|
// if stale/manually-added products existed alongside the CSV-sourced ones.
|
||||||
|
\Lunar\Models\Product::count();
|
||||||
|
|
||||||
|
// Spot-check that at least one variant picked up its own image (see
|
||||||
|
// shopify-import.md's "Images" section) — 0 is only correct if the CSV
|
||||||
|
// genuinely has no `Variant Image` values populated.
|
||||||
|
\Lunar\Models\ProductVariant::has('images')->count();
|
||||||
|
```
|
||||||
@@ -2,7 +2,7 @@
|
|||||||
|
|
||||||
@if (! $otpSent)
|
@if (! $otpSent)
|
||||||
<form wire:submit="requestOtp">
|
<form wire:submit="requestOtp">
|
||||||
<div class="grid gap-y-4">
|
<div style="display: flex; flex-direction: column; row-gap: 1rem;">
|
||||||
<x-filament::input.wrapper>
|
<x-filament::input.wrapper>
|
||||||
<x-filament::input
|
<x-filament::input
|
||||||
type="email"
|
type="email"
|
||||||
@@ -24,7 +24,7 @@
|
|||||||
</form>
|
</form>
|
||||||
@else
|
@else
|
||||||
<form wire:submit="authenticate">
|
<form wire:submit="authenticate">
|
||||||
<div class="grid gap-y-4">
|
<div style="display: flex; flex-direction: column; row-gap: 1rem;">
|
||||||
<p class="text-sm text-gray-500">
|
<p class="text-sm text-gray-500">
|
||||||
A login code was sent to <strong>{{ $email }}</strong>.
|
A login code was sent to <strong>{{ $email }}</strong>.
|
||||||
</p>
|
</p>
|
||||||
|
|||||||
@@ -0,0 +1,127 @@
|
|||||||
|
@php
|
||||||
|
$transaction = $getRecord();
|
||||||
|
$notes = $transaction->notes ?: ($transaction->meta['notes'] ?? null);
|
||||||
|
@endphp
|
||||||
|
|
||||||
|
@once
|
||||||
|
@php
|
||||||
|
$renderPaymentIcons();
|
||||||
|
@endphp
|
||||||
|
@endonce
|
||||||
|
<div
|
||||||
|
@class([
|
||||||
|
'text-sm rounded-lg shadow-md border dark:bg-gray-900',
|
||||||
|
'text-gray-950 dark:text-white',
|
||||||
|
match($transaction->type){
|
||||||
|
'refund' => 'border-orange-300',
|
||||||
|
'intent' => 'border-sky-300',
|
||||||
|
'capture' => 'border-green-300',
|
||||||
|
default => 'border-gray-300',
|
||||||
|
},
|
||||||
|
'!border-red-500 bg-red-50' => !$transaction->success,
|
||||||
|
'bg-gray-50' => $transaction->success,
|
||||||
|
])
|
||||||
|
>
|
||||||
|
<div class="p-2 space-y-2">
|
||||||
|
<div class="px-4 py-2 rounded text-xs bg-white dark:bg-gray-800 shadow text-gray-600 dark:text-gray-400 ring-1 ring-gray-100 dark:ring-gray-700">
|
||||||
|
<span>{{ $transaction->driver }}</span> //
|
||||||
|
<span>{{ $transaction->reference }}</span>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="flex items-center justify-between p-4 bg-white dark:bg-gray-800 rounded shadow ring-1 ring-gray-100 dark:ring-gray-700">
|
||||||
|
<div class="flex items-center gap-6">
|
||||||
|
<div>
|
||||||
|
<strong class="text-xs">
|
||||||
|
{{ $transaction->status }}
|
||||||
|
</strong>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div>
|
||||||
|
<svg viewBox="0 0 50 50" class="w-10">
|
||||||
|
<use xlink:href="#{{ strtolower($transaction->card_type) }}"></use>
|
||||||
|
</svg>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if($transaction->last_four)
|
||||||
|
<p class="text-sm">
|
||||||
|
<span class="inline-block -translate-y-px">
|
||||||
|
∗∗∗∗ ∗∗∗∗ ∗∗∗∗
|
||||||
|
</span>
|
||||||
|
|
||||||
|
<span class="font-medium">
|
||||||
|
{{ (string) $transaction->last_four }}
|
||||||
|
</span>
|
||||||
|
</p>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<strong
|
||||||
|
@class([
|
||||||
|
"text-sm",
|
||||||
|
'text-red-500' => !$transaction->success,
|
||||||
|
match($transaction->type){
|
||||||
|
'refund' => "text-orange-500",
|
||||||
|
default => "text-gray-900 dark:text-gray-100",
|
||||||
|
},
|
||||||
|
])
|
||||||
|
>
|
||||||
|
@if($transaction->type == 'refund')-@endif{{ $transaction->amount->formatted }}
|
||||||
|
</strong>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="px-4 py-2 bg-white dark:bg-gray-800 shadow rounded flex items-center justify-between text-gray-600 dark:text-gray-400 ring-1 ring-gray-100 dark:ring-gray-700">
|
||||||
|
<div class="text-xs flex items-center gap-2">
|
||||||
|
<div>
|
||||||
|
<x-filament::icon
|
||||||
|
icon="heroicon-o-clock"
|
||||||
|
class="w-4"
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
<span>{{ $transaction->created_at->format('jS F Y h:ia') }}</span>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="flex space-x-2">
|
||||||
|
@foreach($transaction->paymentChecks() as $check)
|
||||||
|
<x-filament::badge
|
||||||
|
:icon="$check->successful ? 'heroicon-m-check' : 'heroicon-m-x-mark'"
|
||||||
|
:color="$check->successful ? \Filament\Support\Colors\Color::Sky : 'gray'"
|
||||||
|
>
|
||||||
|
{{ $check->label }}: {{ $check->message }}
|
||||||
|
</x-filament::badge>
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if($notes)
|
||||||
|
<div class="px-4 py-2 bg-white dark:bg-gray-800 shadow flex items-center rounded gap-2 ring-1 ring-gray-100 dark:ring-gray-700">
|
||||||
|
<div>
|
||||||
|
<x-filament::icon
|
||||||
|
icon="heroicon-o-chat-bubble-oval-left-ellipsis"
|
||||||
|
class="w-4"
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<p class="text-sm">{{ $notes }}</p>
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div
|
||||||
|
@class([
|
||||||
|
"bottom-0 left-0 block w-full text-center rounded-b-lg border-t text-xs py-1",
|
||||||
|
"!bg-red-50 !dark:bg-red-400/10 !border-red-300 !text-red-600 !dark:text-red-400" => !$transaction->success,
|
||||||
|
match($transaction->type){
|
||||||
|
'refund' => "bg-orange-50 dark:bg-orange-400/10 border-orange-300 text-orange-600 dark:text-orange-400",
|
||||||
|
'intent' => "bg-sky-50 dark:bg-sky-400/10 border-sky-300 text-sky-600 dark:text-sky-400",
|
||||||
|
'capture' => "bg-green-50 dark:bg-green-400/10 border-green-300 text-green-600 dark:text-green-400",
|
||||||
|
default => "bg-gray-50 dark:bg-gray-400/10 border-gray-300 text-gray-600 dark:text-gray-400",
|
||||||
|
},
|
||||||
|
])
|
||||||
|
>
|
||||||
|
@if(!$transaction->success)
|
||||||
|
{{ __('lunarpanel::order.transactions.failed') }}
|
||||||
|
@else
|
||||||
|
{{ __('lunarpanel::order.transactions.'.$transaction->type) }}
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
<p>Hi,</p>
|
||||||
|
|
||||||
|
<p>Payment of <strong>{{ $amount }}</strong> for your order <strong>{{ $reference }}</strong> has been captured.</p>
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
<p>Hi,</p>
|
||||||
|
|
||||||
|
<p>Your order <strong>{{ $reference }}</strong> is complete. Thanks for shopping with us!</p>
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
<p>Hi,</p>
|
||||||
|
|
||||||
|
<p>Good news — your order <strong>{{ $reference }}</strong> has been delivered.</p>
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
<p>Hi,</p>
|
||||||
|
|
||||||
|
<p>Your order <strong>{{ $reference }}</strong> is on its way.</p>
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
<p>Hi,</p>
|
||||||
|
|
||||||
|
<p>Your order <strong>{{ $reference }}</strong> is ready for pickup in store.</p>
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
<p>Hi,</p>
|
||||||
|
|
||||||
|
<p>Thanks for your order! Your order <strong>{{ $reference }}</strong> is confirmed.</p>
|
||||||
|
|
||||||
|
<ul>
|
||||||
|
@foreach ($lines as $line)
|
||||||
|
<li>{{ $line->quantity }} × {{ $line->description }} — {{ $line->total?->formatted }}</li>
|
||||||
|
@endforeach
|
||||||
|
</ul>
|
||||||
|
|
||||||
|
<p>Total: <strong>{{ $total }}</strong></p>
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
<p>Hi,</p>
|
||||||
|
|
||||||
|
<p>A refund of <strong>{{ $amount }}</strong> has been issued for your order <strong>{{ $reference }}</strong>.</p>
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
<p>Hi,</p>
|
||||||
|
|
||||||
|
<p>Your order <strong>{{ $reference }}</strong> is now: <strong>{{ $statusLabel }}</strong></p>
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
<x-filament-panels::page>
|
|
||||||
{{ $this->table }}
|
|
||||||
</x-filament-panels::page>
|
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Modules\Core\Auth\Services\UserOtpService::validate() on a
|
||||||
|
* successful OTP login — distinct from UserCreated (which only fires for
|
||||||
|
* a genuinely first-time email); this fires on every successful login,
|
||||||
|
* new user or returning one.
|
||||||
|
*/
|
||||||
|
class CustomerLoggedIn
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly Authenticatable $user,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Exceptions;
|
||||||
|
|
||||||
|
use RuntimeException;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Thrown by Modules\Core\Auth\Services\UserOtpService::generateAndSend()
|
||||||
|
* when an email has requested too many codes too quickly — caps both
|
||||||
|
* mail-bombing one inbox and the "just request a fresh code to reset my
|
||||||
|
* guess count" loophole a per-code attempt cap alone doesn't close.
|
||||||
|
*/
|
||||||
|
class OtpThrottledException extends RuntimeException
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly int $availableInSeconds,
|
||||||
|
) {
|
||||||
|
parent::__construct("Too many code requests. Try again in {$availableInSeconds} second(s).");
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,50 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Http\Middleware;
|
||||||
|
|
||||||
|
use Closure;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Facades\Auth;
|
||||||
|
use Modules\Core\Auth\Services\UserSessionService;
|
||||||
|
use Symfony\Component\HttpFoundation\Response;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The enforcement half of the session registry — see
|
||||||
|
* Modules\Core\Auth\Services\UserSessionService's own docblock. Not
|
||||||
|
* auto-registered anywhere (no routes/kernel wiring exist in this
|
||||||
|
* package — see Modules\Core\Customer\Services\CustomerAccountService's
|
||||||
|
* own docblock for why this branch stops at services); a consuming app
|
||||||
|
* adds this to its `web` middleware group (after `auth`) to actually get
|
||||||
|
* "logout everywhere" enforcement.
|
||||||
|
*
|
||||||
|
* A request with no recorded UserSession at all (see
|
||||||
|
* UserSessionService::currentSession()'s own docblock) is let through —
|
||||||
|
* only an EXPLICITLY revoked session is rejected.
|
||||||
|
*/
|
||||||
|
class EnsureSessionNotRevoked
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly UserSessionService $sessions,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public function handle(Request $request, Closure $next): Response
|
||||||
|
{
|
||||||
|
if (! Auth::check()) {
|
||||||
|
return $next($request);
|
||||||
|
}
|
||||||
|
|
||||||
|
$session = $this->sessions->currentSession();
|
||||||
|
|
||||||
|
if ($session && $session->isRevoked()) {
|
||||||
|
Auth::logout();
|
||||||
|
$request->session()->invalidate();
|
||||||
|
$request->session()->regenerateToken();
|
||||||
|
|
||||||
|
abort(401, 'Your session has been revoked. Please log in again.');
|
||||||
|
}
|
||||||
|
|
||||||
|
$session?->update(['last_used_at' => now()]);
|
||||||
|
|
||||||
|
return $next($request);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Models;
|
||||||
|
|
||||||
|
use Illuminate\Database\Eloquent\Model;
|
||||||
|
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* One row per login (see Modules\Core\Auth\Services\UserOtpService::
|
||||||
|
* validate()) — see that table's own migration docblock for why this
|
||||||
|
* exists independent of the actual session-store driver.
|
||||||
|
*/
|
||||||
|
class UserSession extends Model
|
||||||
|
{
|
||||||
|
protected $guarded = [];
|
||||||
|
|
||||||
|
protected $casts = [
|
||||||
|
'last_used_at' => 'datetime',
|
||||||
|
'revoked_at' => 'datetime',
|
||||||
|
];
|
||||||
|
|
||||||
|
public function user(): BelongsTo
|
||||||
|
{
|
||||||
|
$model = config('auth.providers.users.model');
|
||||||
|
|
||||||
|
return $this->belongsTo($model);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function isRevoked(): bool
|
||||||
|
{
|
||||||
|
return $this->revoked_at !== null;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -2,16 +2,75 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Auth\Services;
|
namespace Modules\Core\Auth\Services;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Facades\Auth;
|
||||||
|
use Illuminate\Support\Facades\Event;
|
||||||
use Illuminate\Support\Facades\Mail;
|
use Illuminate\Support\Facades\Mail;
|
||||||
|
use Illuminate\Support\Facades\RateLimiter;
|
||||||
|
use Modules\Core\Auth\Events\CustomerLoggedIn;
|
||||||
|
use Modules\Core\Auth\Exceptions\OtpThrottledException;
|
||||||
use Modules\Core\Auth\Mail\UserOtpMail;
|
use Modules\Core\Auth\Mail\UserOtpMail;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The storefront's passwordless login — a shopper supplies only an email
|
||||||
|
* (Shopify-style), gets a 6-digit code, and validate() authenticates the
|
||||||
|
* `web` guard via Auth::login().
|
||||||
|
*
|
||||||
|
* That alone is enough to merge/associate any active guest cart into the
|
||||||
|
* now-known customer — Auth::login() fires Illuminate\Auth\Events\Login,
|
||||||
|
* which Lunar's own Lunar\Listeners\CartSessionAuthListener (registered
|
||||||
|
* unconditionally in LunarServiceProvider::boot(), no opt-in needed)
|
||||||
|
* already listens to, calling CartSession::associate() with
|
||||||
|
* config('lunar.cart.auth_policy') — 'merge' by default, 'override' if a
|
||||||
|
* consumer changes that config. Deliberately no cart-association call
|
||||||
|
* here: doing our own on top would run a SECOND merge attempt with a
|
||||||
|
* hardcoded policy that ignores whatever the consumer configured.
|
||||||
|
*
|
||||||
|
* generateAndSend()'s find-or-create already triggers the full
|
||||||
|
* Customer/User pairing cascade for a genuinely new email — see
|
||||||
|
* Modules\Core\Auth\Events\UserCreated's own docblock and
|
||||||
|
* Modules\Core\Customer\Listeners\CreateCustomerForUser.
|
||||||
|
*
|
||||||
|
* Two independent throttles, both configured under core.auth.otp — see
|
||||||
|
* config/core.php's own comment for why they're separate: max_attempts
|
||||||
|
* caps wrong guesses against ONE code; generation_limit caps how often a
|
||||||
|
* NEW code can be requested for the same email at all (closes both the
|
||||||
|
* "regenerate to reset my guess count" loophole and mail-bombing one
|
||||||
|
* inbox).
|
||||||
|
*
|
||||||
|
* validate() also records a UserSessionService entry for the new login —
|
||||||
|
* see that class's own docblock for the "logout everywhere" registry
|
||||||
|
* this feeds (Modules\Core\Auth\Http\Middleware\EnsureSessionNotRevoked
|
||||||
|
* is the enforcement half; a consuming app must add it to its own
|
||||||
|
* middleware stack). $request is optional purely so this service stays
|
||||||
|
* callable from a context with no HTTP request at all (a console
|
||||||
|
* command, a test) — user-agent/ip are simply not recorded when omitted.
|
||||||
|
*/
|
||||||
class UserOtpService
|
class UserOtpService
|
||||||
{
|
{
|
||||||
private const EXPIRY_MINUTES = 10;
|
private const EXPIRY_MINUTES = 10;
|
||||||
private const CODE_LENGTH = 6;
|
private const CODE_LENGTH = 6;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
private readonly UserSessionService $sessions,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws OtpThrottledException if this email has requested too many
|
||||||
|
* codes within core.auth.otp.generation_decay_minutes
|
||||||
|
*/
|
||||||
public function generateAndSend(string $email): bool
|
public function generateAndSend(string $email): bool
|
||||||
{
|
{
|
||||||
|
$limiterKey = $this->generationLimiterKey($email);
|
||||||
|
$maxGenerations = (int) config('core.auth.otp.generation_limit', 3);
|
||||||
|
|
||||||
|
if (RateLimiter::tooManyAttempts($limiterKey, $maxGenerations)) {
|
||||||
|
throw new OtpThrottledException(RateLimiter::availableIn($limiterKey));
|
||||||
|
}
|
||||||
|
|
||||||
|
RateLimiter::hit($limiterKey, (int) config('core.auth.otp.generation_decay_minutes', 10) * 60);
|
||||||
|
|
||||||
$model = config('auth.providers.users.model');
|
$model = config('auth.providers.users.model');
|
||||||
$user = $model::firstOrCreate(['email' => $email]);
|
$user = $model::firstOrCreate(['email' => $email]);
|
||||||
|
|
||||||
@@ -19,6 +78,7 @@ class UserOtpService
|
|||||||
|
|
||||||
$user->otp_code = $code;
|
$user->otp_code = $code;
|
||||||
$user->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES);
|
$user->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES);
|
||||||
|
$user->otp_attempts = 0;
|
||||||
$user->save();
|
$user->save();
|
||||||
|
|
||||||
Mail::to($user->email)->send(new UserOtpMail($user->name ?? $user->email, $code));
|
Mail::to($user->email)->send(new UserOtpMail($user->name ?? $user->email, $code));
|
||||||
@@ -26,23 +86,55 @@ class UserOtpService
|
|||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
public function validate(string $email, string $code)
|
/**
|
||||||
|
* A wrong code counts against core.auth.otp.max_attempts and, once
|
||||||
|
* reached, invalidates the code entirely — the shopper must request
|
||||||
|
* a fresh one via generateAndSend() (itself throttled independently
|
||||||
|
* — see this class's own docblock) rather than being able to keep
|
||||||
|
* guessing against a still-live code for the rest of its 10-minute
|
||||||
|
* expiry window.
|
||||||
|
*/
|
||||||
|
public function validate(string $email, string $code, ?Request $request = null): ?Authenticatable
|
||||||
{
|
{
|
||||||
$model = config('auth.providers.users.model');
|
$model = config('auth.providers.users.model');
|
||||||
$user = $model::where('email', $email)->first();
|
$user = $model::where('email', $email)->first();
|
||||||
|
|
||||||
if (! $user) {
|
if (! $user || ! $user->otp_expires_at || now()->isAfter($user->otp_expires_at)) {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (! $user->otp_expires_at || $user->otp_code != $code || now()->isAfter($user->otp_expires_at)) {
|
if ($user->otp_code != $code) {
|
||||||
|
$user->otp_attempts++;
|
||||||
|
|
||||||
|
if ($user->otp_attempts >= (int) config('core.auth.otp.max_attempts', 5)) {
|
||||||
|
$user->otp_code = null;
|
||||||
|
$user->otp_expires_at = null;
|
||||||
|
$user->otp_attempts = 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
$user->save();
|
||||||
|
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
$user->otp_code = null;
|
$user->otp_code = null;
|
||||||
$user->otp_expires_at = null;
|
$user->otp_expires_at = null;
|
||||||
|
$user->otp_attempts = 0;
|
||||||
$user->save();
|
$user->save();
|
||||||
|
|
||||||
|
RateLimiter::clear($this->generationLimiterKey($email));
|
||||||
|
|
||||||
|
Auth::login($user);
|
||||||
|
|
||||||
|
$this->sessions->record($user, $request);
|
||||||
|
|
||||||
|
Event::dispatch(new CustomerLoggedIn($user));
|
||||||
|
|
||||||
return $user;
|
return $user;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private function generationLimiterKey(string $email): string
|
||||||
|
{
|
||||||
|
return 'otp-generate:'.strtolower($email);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,105 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Services;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Str;
|
||||||
|
use Modules\Core\Auth\Models\UserSession;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The record/revoke half of the session registry — see
|
||||||
|
* database/migrations/2026_09_15_000001_create_user_sessions_table.php's
|
||||||
|
* own docblock for why this exists (SESSION_DRIVER=redis in this app has
|
||||||
|
* no "sessions" table to purge by user_id). The enforcement half is
|
||||||
|
* Modules\Core\Auth\Http\Middleware\EnsureSessionNotRevoked, which reads
|
||||||
|
* the token this class stamps into the session payload.
|
||||||
|
*/
|
||||||
|
class UserSessionService
|
||||||
|
{
|
||||||
|
private const SESSION_TOKEN_KEY = 'user_session_token';
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Called once, right after Auth::login() succeeds (see
|
||||||
|
* UserOtpService::validate()) — generates a fresh token, records it,
|
||||||
|
* and stamps it into the CURRENT session payload so
|
||||||
|
* EnsureSessionNotRevoked can look it up on later requests.
|
||||||
|
*/
|
||||||
|
public function record(Authenticatable $user, ?Request $request = null): UserSession
|
||||||
|
{
|
||||||
|
$token = Str::random(64);
|
||||||
|
|
||||||
|
$session = UserSession::create([
|
||||||
|
'user_id' => $user->getAuthIdentifier(),
|
||||||
|
'token' => $token,
|
||||||
|
'user_agent' => $request?->userAgent(),
|
||||||
|
'ip_address' => $request?->ip(),
|
||||||
|
'last_used_at' => now(),
|
||||||
|
]);
|
||||||
|
|
||||||
|
session([self::SESSION_TOKEN_KEY => $token]);
|
||||||
|
|
||||||
|
return $session;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Revokes every OTHER active session for $user — the current one
|
||||||
|
* (matched by the token in the CURRENT session payload) is left
|
||||||
|
* alone, matching Laravel's own logoutOtherDevices() semantics
|
||||||
|
* (there just isn't a password to re-verify against here — this is a
|
||||||
|
* passwordless account, so revocation is simply "every row that
|
||||||
|
* isn't the one making this request").
|
||||||
|
*
|
||||||
|
* Known, deliberately accepted gap: this requires only a currently
|
||||||
|
* valid session, not a freshly-completed login — so anyone holding
|
||||||
|
* an already-authenticated session (e.g. someone who sits down at an
|
||||||
|
* account left logged in on a shared/public PC) can use this to
|
||||||
|
* evict the real owner's OTHER sessions just as easily as the real
|
||||||
|
* owner could use it to evict an intruder's. A stricter version would
|
||||||
|
* require a fresh OTP re-verification (e.g. within the last few
|
||||||
|
* minutes) before allowing this call. Left as-is for now — revisit if
|
||||||
|
* this turns out to matter in practice, rather than building
|
||||||
|
* abuse-resistance against a threat model nobody's confirmed is real
|
||||||
|
* for this storefront.
|
||||||
|
*/
|
||||||
|
public function revokeOtherSessions(Authenticatable $user): int
|
||||||
|
{
|
||||||
|
$currentToken = session(self::SESSION_TOKEN_KEY);
|
||||||
|
|
||||||
|
return UserSession::query()
|
||||||
|
->where('user_id', $user->getAuthIdentifier())
|
||||||
|
->whereNull('revoked_at')
|
||||||
|
->when($currentToken, fn ($query) => $query->where('token', '!=', $currentToken))
|
||||||
|
->update(['revoked_at' => now()]);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Revokes EVERY session for $user, current one included — for a
|
||||||
|
* "this account may be compromised" response, not a routine logout.
|
||||||
|
*/
|
||||||
|
public function revokeAllSessions(Authenticatable $user): int
|
||||||
|
{
|
||||||
|
return UserSession::query()
|
||||||
|
->where('user_id', $user->getAuthIdentifier())
|
||||||
|
->whereNull('revoked_at')
|
||||||
|
->update(['revoked_at' => now()]);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return UserSession|null null if the CURRENT session has no
|
||||||
|
* recorded token at all (e.g. a session predating this feature, or
|
||||||
|
* one Auth::login() established outside UserOtpService) — treated
|
||||||
|
* as valid by EnsureSessionNotRevoked rather than rejected, since
|
||||||
|
* there's nothing to have been revoked.
|
||||||
|
*/
|
||||||
|
public function currentSession(): ?UserSession
|
||||||
|
{
|
||||||
|
$token = session(self::SESSION_TOKEN_KEY);
|
||||||
|
|
||||||
|
if (! $token) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
return UserSession::where('token', $token)->first();
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -5,7 +5,7 @@ namespace Modules\Core\Cart\Commands;
|
|||||||
use Illuminate\Console\Command;
|
use Illuminate\Console\Command;
|
||||||
use Illuminate\Support\Facades\Event;
|
use Illuminate\Support\Facades\Event;
|
||||||
use Lunar\Models\Cart;
|
use Lunar\Models\Cart;
|
||||||
use Modules\Core\Cart\Filament\Resources\CartResource;
|
use Modules\Core\Cart\Services\CartLifecycleService;
|
||||||
use Modules\Core\Recovery\Events\CartAbandoned;
|
use Modules\Core\Recovery\Events\CartAbandoned;
|
||||||
use Modules\Core\Recovery\Events\CheckoutAbandoned;
|
use Modules\Core\Recovery\Events\CheckoutAbandoned;
|
||||||
|
|
||||||
@@ -31,6 +31,20 @@ use Modules\Core\Recovery\Events\CheckoutAbandoned;
|
|||||||
* state at all; every cart still matching the query below refires its event
|
* state at all; every cart still matching the query below refires its event
|
||||||
* on every run until Recovery (not yet built — see
|
* on every run until Recovery (not yet built — see
|
||||||
* docs/recovery-strategies.md) owns its own dedup/tracking table.
|
* docs/recovery-strategies.md) owns its own dedup/tracking table.
|
||||||
|
*
|
||||||
|
* Both queries require meta->recovery_consent = true — CartAbandoned/
|
||||||
|
* CheckoutAbandoned exist specifically to drive future recovery-email
|
||||||
|
* sends (Checkout\Services\CheckoutService::setRecoveryConsent() is where
|
||||||
|
* that consent is actually recorded), and a non-consenting cart's
|
||||||
|
* abandonment must never be dispatched at all, not merely filtered later
|
||||||
|
* at send time — see docs referenced above for the legal reasoning. This
|
||||||
|
* consent filter stays here rather than on Modules\Core\Cart\Services\
|
||||||
|
* CartLifecycleService, whose two "abandoned" queries this command builds
|
||||||
|
* on — dispatch eligibility is this command's own concern, not part of
|
||||||
|
* what "abandoned" means to a staff member browsing the admin panel. (The
|
||||||
|
* non-empty-lines requirement, by contrast, IS part of what "abandoned"
|
||||||
|
* means either way, so it lives on CartLifecycleService::abandonedCarts()
|
||||||
|
* itself, not here.)
|
||||||
*/
|
*/
|
||||||
class DetectAbandonedCarts extends Command
|
class DetectAbandonedCarts extends Command
|
||||||
{
|
{
|
||||||
@@ -38,32 +52,23 @@ class DetectAbandonedCarts extends Command
|
|||||||
|
|
||||||
protected $description = 'Dispatch CartAbandoned/CheckoutAbandoned for carts that just crossed the abandonment threshold.';
|
protected $description = 'Dispatch CartAbandoned/CheckoutAbandoned for carts that just crossed the abandonment threshold.';
|
||||||
|
|
||||||
public function handle(): void
|
public function handle(CartLifecycleService $lifecycle): void
|
||||||
{
|
{
|
||||||
$cutoff = CartResource::abandonedCutoff();
|
|
||||||
|
|
||||||
$cartsAbandoned = 0;
|
$cartsAbandoned = 0;
|
||||||
$checkoutsAbandoned = 0;
|
$checkoutsAbandoned = 0;
|
||||||
|
|
||||||
Cart::query()
|
$lifecycle->abandonedCarts(Cart::query())
|
||||||
->whereDoesntHave('orders')
|
->where('meta->recovery_consent', true)
|
||||||
->where('updated_at', '<=', $cutoff)
|
|
||||||
->with('lines')
|
|
||||||
->chunkById(200, function ($carts) use (&$cartsAbandoned) {
|
->chunkById(200, function ($carts) use (&$cartsAbandoned) {
|
||||||
foreach ($carts as $cart) {
|
foreach ($carts as $cart) {
|
||||||
if ($cart->lines->isEmpty()) {
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
|
|
||||||
Event::dispatch(new CartAbandoned($cart));
|
Event::dispatch(new CartAbandoned($cart));
|
||||||
|
|
||||||
$cartsAbandoned++;
|
$cartsAbandoned++;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
Cart::query()
|
$lifecycle->abandonedCheckouts(Cart::query())
|
||||||
->whereHas('orders', fn ($query) => $query->whereNull('placed_at'))
|
->where('meta->recovery_consent', true)
|
||||||
->where('updated_at', '<=', $cutoff)
|
|
||||||
->with(['orders' => fn ($query) => $query->whereNull('placed_at')])
|
->with(['orders' => fn ($query) => $query->whereNull('placed_at')])
|
||||||
->chunkById(200, function ($carts) use (&$checkoutsAbandoned) {
|
->chunkById(200, function ($carts) use (&$checkoutsAbandoned) {
|
||||||
foreach ($carts as $cart) {
|
foreach ($carts as $cart) {
|
||||||
|
|||||||
@@ -9,20 +9,22 @@ use Modules\Core\Cart\Filament\Resources\CartResource\Pages\ViewCart;
|
|||||||
use Filament\Resources\Resource;
|
use Filament\Resources\Resource;
|
||||||
use Filament\Tables;
|
use Filament\Tables;
|
||||||
use Filament\Tables\Table;
|
use Filament\Tables\Table;
|
||||||
use Illuminate\Database\Eloquent\Builder;
|
|
||||||
use Illuminate\Support\Carbon;
|
use Illuminate\Support\Carbon;
|
||||||
use Lunar\Admin\Filament\Resources\CustomerResource;
|
use Lunar\Admin\Filament\Resources\CustomerResource;
|
||||||
use Lunar\Models\Cart;
|
use Lunar\Models\Cart;
|
||||||
use Modules\Core\Cart\Filament\Resources\CartResource\Pages;
|
use Modules\Core\Cart\Filament\Resources\CartResource\Pages;
|
||||||
|
use Modules\Core\Cart\Services\CartLifecycleService;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Read-only — a cart is managed entirely through the storefront (add/update/remove
|
* Read-only — a cart is managed entirely through the storefront (add/update/remove
|
||||||
* line, checkout), never hand-edited by staff. Scoped to carts with a known
|
* line, checkout), never hand-edited by staff. Lists every cart, guest carts
|
||||||
* `user_id`/`customer_id` only: an anonymous guest's session cart carries no
|
* included — see docs/cart.md ("Scope: every cart, identified or not"). An
|
||||||
* identity a staff member could act on (no name, no email, nothing to follow up
|
* anonymous cart's Customer/User columns just render "—" (see table() below)
|
||||||
* with), so listing every such row would be noise, not a real admin capability —
|
* rather than the row being hidden outright: most real traffic never reaches
|
||||||
* see docs/cart.md for the reasoning (Lunar itself ships no cart admin view at all
|
* an identified user/customer, and "how many carts are ongoing/abandoned
|
||||||
* to follow a precedent from).
|
* right now" is a real reporting need regardless of identity — excluding
|
||||||
|
* anonymous carts would silently undercount it. Lunar itself ships no cart
|
||||||
|
* admin view at all to follow a precedent from.
|
||||||
*/
|
*/
|
||||||
class CartResource extends Resource
|
class CartResource extends Resource
|
||||||
{
|
{
|
||||||
@@ -36,12 +38,6 @@ class CartResource extends Resource
|
|||||||
|
|
||||||
protected static ?string $pluralModelLabel = 'Carts';
|
protected static ?string $pluralModelLabel = 'Carts';
|
||||||
|
|
||||||
public static function getEloquentQuery(): Builder
|
|
||||||
{
|
|
||||||
return parent::getEloquentQuery()
|
|
||||||
->where(fn (Builder $query) => $query->whereNotNull('user_id')->orWhereNotNull('customer_id'));
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Count only, not a fetch — no rows are loaded. Combines BOTH abandoned
|
* Count only, not a fetch — no rows are loaded. Combines BOTH abandoned
|
||||||
* states (`active()` already covers "no order at all" and "draft order,
|
* states (`active()` already covers "no order at all" and "draft order,
|
||||||
@@ -56,6 +52,11 @@ class CartResource extends Resource
|
|||||||
return (string) static::getEloquentQuery()->active()->where('updated_at', '<=', static::abandonedCutoff())->count();
|
return (string) static::getEloquentQuery()->active()->where('updated_at', '<=', static::abandonedCutoff())->count();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public static function lifecycle(): CartLifecycleService
|
||||||
|
{
|
||||||
|
return app(CartLifecycleService::class);
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* `Cart::scopeActive()` (not-yet-converted-to-an-order carts) mixes two very
|
* `Cart::scopeActive()` (not-yet-converted-to-an-order carts) mixes two very
|
||||||
* different things together: a cart someone is actively shopping in right now,
|
* different things together: a cart someone is actively shopping in right now,
|
||||||
@@ -67,7 +68,7 @@ class CartResource extends Resource
|
|||||||
*/
|
*/
|
||||||
public static function abandonedCutoff(): Carbon
|
public static function abandonedCutoff(): Carbon
|
||||||
{
|
{
|
||||||
return now()->sub(config('core.cart.abandoned_after', '1 hour'));
|
return static::lifecycle()->abandonedCutoff();
|
||||||
}
|
}
|
||||||
|
|
||||||
public static function table(Table $table): Table
|
public static function table(Table $table): Table
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ use Filament\Schemas\Components\Tabs\Tab;
|
|||||||
use Filament\Resources\Pages\ListRecords;
|
use Filament\Resources\Pages\ListRecords;
|
||||||
use Illuminate\Database\Eloquent\Builder;
|
use Illuminate\Database\Eloquent\Builder;
|
||||||
use Modules\Core\Cart\Filament\Resources\CartResource;
|
use Modules\Core\Cart\Filament\Resources\CartResource;
|
||||||
|
use Modules\Core\Cart\Services\CartLifecycleService;
|
||||||
|
|
||||||
class ListCarts extends ListRecords
|
class ListCarts extends ListRecords
|
||||||
{
|
{
|
||||||
@@ -27,30 +28,24 @@ class ListCarts extends ListRecords
|
|||||||
* bucket — same distinction Modules\Core\Recovery\Events\CartAbandoned /
|
* bucket — same distinction Modules\Core\Recovery\Events\CartAbandoned /
|
||||||
* Modules\Core\Recovery\Events\CheckoutAbandoned draw.
|
* Modules\Core\Recovery\Events\CheckoutAbandoned draw.
|
||||||
*
|
*
|
||||||
* "Ongoing" vs the two abandoned tabs all split on `updated_at` against
|
* The four query shapes below live on Modules\Core\Cart\Services\
|
||||||
* `CartResource::abandonedCutoff()` — Lunar has no time-based staleness
|
* CartLifecycleService, shared with Modules\Core\Cart\Commands\
|
||||||
* signal of its own, so recent activity is the only thing distinguishing a
|
* DetectAbandonedCarts — see that service's docblock for why duplicating
|
||||||
* cart someone is shopping in right now from one genuinely left behind.
|
* them independently in both places was worth centralizing.
|
||||||
*/
|
*/
|
||||||
public function getTabs(): array
|
public function getTabs(): array
|
||||||
{
|
{
|
||||||
|
$lifecycle = app(CartLifecycleService::class);
|
||||||
|
|
||||||
return [
|
return [
|
||||||
'abandoned_cart' => Tab::make('Abandoned Cart')
|
'abandoned_cart' => Tab::make('Abandoned Cart')
|
||||||
->modifyQueryUsing(fn(Builder $query) => $query
|
->modifyQueryUsing(fn (Builder $query) => $lifecycle->abandonedCarts($query)),
|
||||||
->whereDoesntHave('orders')
|
|
||||||
->where('updated_at', '<=', CartResource::abandonedCutoff())),
|
|
||||||
'abandoned_checkout' => Tab::make('Abandoned Checkout')
|
'abandoned_checkout' => Tab::make('Abandoned Checkout')
|
||||||
->modifyQueryUsing(fn(Builder $query) => $query
|
->modifyQueryUsing(fn (Builder $query) => $lifecycle->abandonedCheckouts($query)),
|
||||||
->whereHas('orders', fn(Builder $query) => $query->whereNull('placed_at'))
|
|
||||||
->where('updated_at', '<=', CartResource::abandonedCutoff())),
|
|
||||||
|
|
||||||
'ongoing' => Tab::make('Ongoing')
|
'ongoing' => Tab::make('Ongoing')
|
||||||
->modifyQueryUsing(fn(Builder $query) => $query->active()->where('updated_at', '>', CartResource::abandonedCutoff())),
|
->modifyQueryUsing(fn (Builder $query) => $lifecycle->ongoing($query)),
|
||||||
'completed' => Tab::make('Completed')
|
'completed' => Tab::make('Completed')
|
||||||
->modifyQueryUsing(fn(Builder $query) => $query->whereHas(
|
->modifyQueryUsing(fn (Builder $query) => $lifecycle->completed($query)),
|
||||||
'orders',
|
|
||||||
fn(Builder $query) => $query->whereNotNull('placed_at'),
|
|
||||||
)),
|
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,12 +5,18 @@ namespace Modules\Core\Cart\Filament\Resources\CartResource\Pages;
|
|||||||
use Filament\Schemas\Schema;
|
use Filament\Schemas\Schema;
|
||||||
use Filament\Schemas\Components\Section;
|
use Filament\Schemas\Components\Section;
|
||||||
use Filament\Actions\Action;
|
use Filament\Actions\Action;
|
||||||
|
use Filament\Infolists\Components\ImageEntry;
|
||||||
use Filament\Infolists\Components\RepeatableEntry;
|
use Filament\Infolists\Components\RepeatableEntry;
|
||||||
use Filament\Infolists\Components\TextEntry;
|
use Filament\Infolists\Components\TextEntry;
|
||||||
use Filament\Resources\Pages\ViewRecord;
|
use Filament\Resources\Pages\ViewRecord;
|
||||||
|
use Filament\Support\Colors\Color;
|
||||||
|
use Illuminate\Database\Eloquent\Collection as EloquentCollection;
|
||||||
|
use Illuminate\Support\Facades\Blade;
|
||||||
use Lunar\Admin\Filament\Resources\CustomerResource;
|
use Lunar\Admin\Filament\Resources\CustomerResource;
|
||||||
|
use Lunar\Admin\Filament\Resources\ProductResource\Pages\EditProduct;
|
||||||
use Lunar\Models\Cart;
|
use Lunar\Models\Cart;
|
||||||
use Lunar\Models\CartLine;
|
use Lunar\Models\CartLine;
|
||||||
|
use Lunar\Models\ProductVariant;
|
||||||
use Modules\Core\Cart\Filament\Resources\CartResource;
|
use Modules\Core\Cart\Filament\Resources\CartResource;
|
||||||
|
|
||||||
class ViewCart extends ViewRecord
|
class ViewCart extends ViewRecord
|
||||||
@@ -35,12 +41,23 @@ class ViewCart extends ViewRecord
|
|||||||
* (a single view page load), not per-row in the list table, since running the
|
* (a single view page load), not per-row in the list table, since running the
|
||||||
* full pipeline for every row of a paginated table would be expensive for no
|
* full pipeline for every row of a paginated table would be expensive for no
|
||||||
* real benefit — see docs/lunar.md's Cart gotchas.
|
* real benefit — see docs/lunar.md's Cart gotchas.
|
||||||
|
*
|
||||||
|
* Eager-loads what the Lines section (below) reads off each line's
|
||||||
|
* purchasable — name, thumbnail, options — the same relations Lunar's
|
||||||
|
* own OrderItemsTable loads for an order's line items (`with(['purchasable'])`,
|
||||||
|
* see vendor/lunarphp/lunar/.../OrderItemsTable::getDefaultTable()) — so
|
||||||
|
* rendering the product grid doesn't N+1 per line.
|
||||||
*/
|
*/
|
||||||
protected function resolveRecord(int|string $key): Cart
|
protected function resolveRecord(int|string $key): Cart
|
||||||
{
|
{
|
||||||
/** @var Cart $cart */
|
/** @var Cart $cart */
|
||||||
$cart = parent::resolveRecord($key);
|
$cart = parent::resolveRecord($key);
|
||||||
|
|
||||||
|
$cart->load('lines.purchasable', 'shippingAddress.country');
|
||||||
|
|
||||||
|
EloquentCollection::make($cart->lines->pluck('purchasable')->filter(fn ($p) => $p instanceof ProductVariant))
|
||||||
|
->loadMissing(['product.thumbnail', 'images', 'values']);
|
||||||
|
|
||||||
return $cart->calculate();
|
return $cart->calculate();
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -77,6 +94,37 @@ class ViewCart extends ViewRecord
|
|||||||
RepeatableEntry::make('lines')
|
RepeatableEntry::make('lines')
|
||||||
->hiddenLabel()
|
->hiddenLabel()
|
||||||
->schema([
|
->schema([
|
||||||
|
ImageEntry::make('image')
|
||||||
|
->hiddenLabel()
|
||||||
|
->state(fn (CartLine $record) => $record->purchasable instanceof ProductVariant
|
||||||
|
? $record->purchasable->getThumbnail()?->getUrl('small')
|
||||||
|
: null)
|
||||||
|
->defaultImageUrl(fn () => 'data:image/svg+xml;base64,'.base64_encode(
|
||||||
|
Blade::render('<x-filament::icon icon="heroicon-o-photo" style="color:rgb('.Color::Gray[400].');"/>')
|
||||||
|
))
|
||||||
|
->imageSize(48),
|
||||||
|
TextEntry::make('description')
|
||||||
|
->label('Product')
|
||||||
|
// ProductVariant::getDescription()/getOption() are typed
|
||||||
|
// string but internally read translateAttribute()/
|
||||||
|
// translate(), which return null for a product/option
|
||||||
|
// with no attribute data set for the active locale —
|
||||||
|
// reading the underlying relations directly here avoids
|
||||||
|
// that TypeError rather than calling through them.
|
||||||
|
->state(fn (CartLine $record) => $record->purchasable instanceof ProductVariant
|
||||||
|
? ($record->purchasable->product?->translateAttribute('name') ?? '—')
|
||||||
|
: '—')
|
||||||
|
->url(fn (CartLine $record) => $record->purchasable instanceof ProductVariant
|
||||||
|
? EditProduct::getUrl(['record' => $record->purchasable->product_id])
|
||||||
|
: null)
|
||||||
|
->weight('bold'),
|
||||||
|
TextEntry::make('options')
|
||||||
|
->label('Options')
|
||||||
|
->state(fn (CartLine $record) => $record->purchasable instanceof ProductVariant
|
||||||
|
? ($record->purchasable->values->map(fn ($value) => $value->translate('name'))->filter()->join(', ') ?: null)
|
||||||
|
: null)
|
||||||
|
->placeholder('—')
|
||||||
|
->badge(),
|
||||||
TextEntry::make('purchasable.sku')
|
TextEntry::make('purchasable.sku')
|
||||||
->label('SKU')
|
->label('SKU')
|
||||||
->placeholder('—'),
|
->placeholder('—'),
|
||||||
@@ -90,6 +138,53 @@ class ViewCart extends ViewRecord
|
|||||||
])
|
])
|
||||||
->columns(4),
|
->columns(4),
|
||||||
]),
|
]),
|
||||||
|
Section::make('Shipping')
|
||||||
|
->columns(3)
|
||||||
|
->schema([
|
||||||
|
TextEntry::make('shippingAddress.shipping_option')
|
||||||
|
->label('Shipping method')
|
||||||
|
// The raw identifier (e.g. "acs") is all a
|
||||||
|
// CartAddress row stores — the human-readable
|
||||||
|
// name only exists on the resolved
|
||||||
|
// Lunar\DataTypes\ShippingOption, which is what
|
||||||
|
// shippingBreakdown's items are keyed/named
|
||||||
|
// from below, so fall back to that name rather
|
||||||
|
// than showing the bare identifier.
|
||||||
|
->formatStateUsing(fn (Cart $record, ?string $state) => $state
|
||||||
|
? ($record->shippingBreakdown?->items->get($state)?->name ?? $state)
|
||||||
|
: null)
|
||||||
|
->placeholder('Not selected'),
|
||||||
|
TextEntry::make('shippingAddress.country.name')
|
||||||
|
->label('Shipping to')
|
||||||
|
->placeholder('—'),
|
||||||
|
TextEntry::make('shippingTotal')
|
||||||
|
->label('Shipping total')
|
||||||
|
->formatStateUsing(fn (Cart $record) => $record->shippingTotal?->formatted() ?? '—')
|
||||||
|
->weight('bold'),
|
||||||
|
RepeatableEntry::make('shippingBreakdownItems')
|
||||||
|
->label('Breakdown')
|
||||||
|
->columnSpanFull()
|
||||||
|
// shippingBreakdown->items is a plain (non-Eloquent)
|
||||||
|
// Collection of Lunar\Base\ValueObjects\Cart\
|
||||||
|
// ShippingBreakdownItem — e.g. the carrier rate and,
|
||||||
|
// separately, Modules\Core\Payment\Pipelines\Cart\
|
||||||
|
// ApplyPaymentMethodFee's own line item when the
|
||||||
|
// selected payment method carries a fee (see
|
||||||
|
// CHANGELOG 0.16.3) — both show up here individually
|
||||||
|
// rather than only as the summed shippingTotal above.
|
||||||
|
->state(fn (Cart $record) => $record->shippingBreakdown?->items->values() ?? [])
|
||||||
|
->schema([
|
||||||
|
TextEntry::make('name')
|
||||||
|
->hiddenLabel(),
|
||||||
|
TextEntry::make('price')
|
||||||
|
->hiddenLabel()
|
||||||
|
->formatStateUsing(fn ($state) => $state?->formatted() ?? '—')
|
||||||
|
->alignEnd(),
|
||||||
|
])
|
||||||
|
->columns(2)
|
||||||
|
->visible(fn (Cart $record) => (bool) $record->shippingBreakdown?->items->isNotEmpty()),
|
||||||
|
])
|
||||||
|
->visible(fn (Cart $record) => $record->shippingAddress !== null),
|
||||||
Section::make('Totals')
|
Section::make('Totals')
|
||||||
->columns(3)
|
->columns(3)
|
||||||
->schema([
|
->schema([
|
||||||
|
|||||||
@@ -0,0 +1,99 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Cart\Services;
|
||||||
|
|
||||||
|
use Illuminate\Database\Eloquent\Builder;
|
||||||
|
use Illuminate\Support\Carbon;
|
||||||
|
use Lunar\Models\Cart;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The single source of truth for the four cart lifecycle states documented in
|
||||||
|
* docs/cart.md ("Four states, not two — and not Cart::completed_at"). Both
|
||||||
|
* Modules\Core\Cart\Filament\Resources\CartResource/ListCarts (staff-facing
|
||||||
|
* browsing/tabs) and Modules\Core\Cart\Commands\DetectAbandonedCarts
|
||||||
|
* (abandonment-event dispatch) build on these same four query shapes — before
|
||||||
|
* this existed, each reimplemented them independently, which is exactly the
|
||||||
|
* kind of drift that lets the admin panel and the recovery-email pipeline
|
||||||
|
* quietly disagree about what "abandoned" means.
|
||||||
|
*
|
||||||
|
* `Cart::completed_at` is declared/cast on the model but never actually
|
||||||
|
* written anywhere in Lunar core — not a real signal, not used here.
|
||||||
|
* `Cart::scopeActive()` (Lunar's own "not yet converted to an order" scope)
|
||||||
|
* mixes two distinct states together (no order at all vs. a draft order that
|
||||||
|
* was never placed) — see docs/cart.md for why they're kept apart as
|
||||||
|
* different purchase-intent/reachability signals rather than folded into one
|
||||||
|
* "not converted" bucket.
|
||||||
|
*
|
||||||
|
* Query shape only: consent (`meta->recovery_consent`) and non-empty-lines
|
||||||
|
* filtering stay in DetectAbandonedCarts, not here — those are specific to
|
||||||
|
* whether a recovery event should fire, not to what "abandoned" means. Staff
|
||||||
|
* browsing the admin panel should see every abandoned cart, consenting or
|
||||||
|
* not.
|
||||||
|
*
|
||||||
|
* `unrecoverableCutoff()` is a second, older threshold
|
||||||
|
* (`core.cart.unrecoverable_after`, default 90 days) applied as a lower
|
||||||
|
* bound on both abandoned*() methods below: a cart past it is too old to be
|
||||||
|
* a realistic recovery target (pricing/stock/tax have likely moved on), so
|
||||||
|
* it drops out of "Abandoned Cart"/"Abandoned Checkout" entirely rather than
|
||||||
|
* staying flagged as an actionable abandonment forever. It does not appear
|
||||||
|
* in `ongoing()`/`completed()` either — this is about the abandoned-cart
|
||||||
|
* pipeline specifically, not a retention/deletion policy (no rows are
|
||||||
|
* touched here).
|
||||||
|
*/
|
||||||
|
class CartLifecycleService
|
||||||
|
{
|
||||||
|
public function abandonedCutoff(): Carbon
|
||||||
|
{
|
||||||
|
return now()->sub(config('core.cart.abandoned_after', '1 hour'));
|
||||||
|
}
|
||||||
|
|
||||||
|
public function unrecoverableCutoff(): Carbon
|
||||||
|
{
|
||||||
|
return now()->sub(config('core.cart.unrecoverable_after', '90 days'));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Not yet converted to an order (scopeActive()), with recent activity —
|
||||||
|
* someone plausibly shopping right now, not (yet) left behind.
|
||||||
|
*/
|
||||||
|
public function ongoing(Builder $query): Builder
|
||||||
|
{
|
||||||
|
return $query->active()->where('updated_at', '>', $this->abandonedCutoff());
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* No order started at all, stale, not yet past the unrecoverable cap, and
|
||||||
|
* actually has something in it — the weaker of the two abandoned states
|
||||||
|
* (see docs/cart.md's "Abandoned Cart vs Abandoned Checkout"). An empty
|
||||||
|
* cart (created but nothing ever added — e.g. a bot, or a session that
|
||||||
|
* never shopped) was never really "abandoned"; there's nothing to
|
||||||
|
* recover, so it's excluded rather than counted as a false positive.
|
||||||
|
*/
|
||||||
|
public function abandonedCarts(Builder $query): Builder
|
||||||
|
{
|
||||||
|
return $query->whereDoesntHave('orders')
|
||||||
|
->whereHas('lines')
|
||||||
|
->where('updated_at', '<=', $this->abandonedCutoff())
|
||||||
|
->where('updated_at', '>', $this->unrecoverableCutoff());
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A draft order exists (checkout was started) but was never placed,
|
||||||
|
* stale, and not yet past the unrecoverable cap — the stronger of the
|
||||||
|
* two abandoned states.
|
||||||
|
*/
|
||||||
|
public function abandonedCheckouts(Builder $query): Builder
|
||||||
|
{
|
||||||
|
return $query->whereHas('orders', fn (Builder $query) => $query->whereNull('placed_at'))
|
||||||
|
->where('updated_at', '<=', $this->abandonedCutoff())
|
||||||
|
->where('updated_at', '>', $this->unrecoverableCutoff());
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Has an order that was actually placed, not just drafted.
|
||||||
|
*/
|
||||||
|
public function completed(Builder $query): Builder
|
||||||
|
{
|
||||||
|
return $query->whereHas('orders', fn (Builder $query) => $query->whereNotNull('placed_at'));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Catalog\DTOs;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A price range slider's bounds and whether it's currently narrowed —
|
||||||
|
* built by ProductService::priceSliderBounds(), which owns the floor/ceil
|
||||||
|
* rounding and "is this actually a meaningful filter" comparison, so a
|
||||||
|
* controller (CategoryController, SearchController, ...) doesn't have to
|
||||||
|
* reimplement that rule itself.
|
||||||
|
*/
|
||||||
|
class PriceSliderBounds
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly ?int $floor,
|
||||||
|
public readonly ?int $ceil,
|
||||||
|
public readonly bool $filtered,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -17,10 +17,12 @@ class ProductFilters
|
|||||||
* not a direct-assignment-only match) — the right semantics for "products on
|
* not a direct-assignment-only match) — the right semantics for "products on
|
||||||
* this category page", since products are typically attached only to leaf
|
* this category page", since products are typically attached only to leaf
|
||||||
* collections.
|
* collections.
|
||||||
|
* @param $tag exactly one tag — no multi-select yet.
|
||||||
*/
|
*/
|
||||||
public function __construct(
|
public function __construct(
|
||||||
public readonly ?int $collectionId = null,
|
public readonly ?int $collectionId = null,
|
||||||
public readonly ?string $brand = null,
|
public readonly ?string $brand = null,
|
||||||
|
public readonly ?string $tag = null,
|
||||||
public readonly ?float $minPrice = null,
|
public readonly ?float $minPrice = null,
|
||||||
public readonly ?float $maxPrice = null,
|
public readonly ?float $maxPrice = null,
|
||||||
public readonly bool $inStockOnly = false,
|
public readonly bool $inStockOnly = false,
|
||||||
|
|||||||
@@ -0,0 +1,33 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Catalog\DTOs;
|
||||||
|
|
||||||
|
use Illuminate\Pagination\LengthAwarePaginator;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Everything a listing page needs from one ProductService::list() call —
|
||||||
|
* the product page itself, the price slider's bounds, and the set of tags
|
||||||
|
* actually present on matching products (for a tag filter sidebar) — so a
|
||||||
|
* controller makes one service call instead of orchestrating list(),
|
||||||
|
* priceSliderBounds(), and facets('tags', ...) separately. list() still
|
||||||
|
* issues multiple Meilisearch requests internally (the product search, the
|
||||||
|
* price facet stats, the tag facet distribution — see priceSliderBounds()'s
|
||||||
|
* own docblock for why the price ones can't be merged into one without
|
||||||
|
* changing the slider's UX), but that's this DTO's job to hide, not the
|
||||||
|
* controller's to know about.
|
||||||
|
*/
|
||||||
|
class ProductListingResult
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param array<int, string> $availableTags every distinct tag value
|
||||||
|
* present on at least one product matching the listing's OTHER
|
||||||
|
* filters (collection/price/stock — never the tag filter itself, so
|
||||||
|
* selecting a tag doesn't collapse the list down to just that tag).
|
||||||
|
* Sorted alphabetically. Empty if no product in scope has any tag.
|
||||||
|
*/
|
||||||
|
public function __construct(
|
||||||
|
public readonly LengthAwarePaginator $products,
|
||||||
|
public readonly PriceSliderBounds $priceBounds,
|
||||||
|
public readonly array $availableTags = [],
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -27,8 +27,14 @@ use Spatie\MediaLibrary\MediaCollections\Models\Media;
|
|||||||
* - slugs (every locale's Url::slug for the product, filterable) — lets
|
* - slugs (every locale's Url::slug for the product, filterable) — lets
|
||||||
* ProductService::getBySlug() resolve a product from the index directly, with
|
* ProductService::getBySlug() resolve a product from the index directly, with
|
||||||
* no database read at all
|
* no database read at all
|
||||||
|
* - skus (every variant's sku, deduplicated, filterable) — same "resolve from the
|
||||||
|
* index alone" reasoning as slugs, for a future SKU-based lookup/filter
|
||||||
* - price (cheapest variant, filterable) and full per-variant pricing
|
* - price (cheapest variant, filterable) and full per-variant pricing
|
||||||
* - variants: sku, stock, purchasable, option values, prices, media
|
* - variants: sku, gtin, mpn, ean, stock, backorder, unit_quantity, purchasable,
|
||||||
|
* shippable, tax_ref, dimensions (length/width/height/weight/volume, each
|
||||||
|
* {value, unit}), option values, prices, media — the variant's own images
|
||||||
|
* (ProductVariant::images(), separate from the product's gallery below), not
|
||||||
|
* the product's own media repeated per variant
|
||||||
* - the full media gallery (not just the single thumbnail Lunar's base indexer sends)
|
* - the full media gallery (not just the single thumbnail Lunar's base indexer sends)
|
||||||
* - tags
|
* - tags
|
||||||
* - reviews: {items: [...], count, average_rating} — items are public-safe fields
|
* - reviews: {items: [...], count, average_rating} — items are public-safe fields
|
||||||
@@ -41,8 +47,12 @@ use Spatie\MediaLibrary\MediaCollections\Models\Media;
|
|||||||
* quantity 1, via ProductVariant::canBeFulfilledAtQuantity() (Lunar's own
|
* quantity 1, via ProductVariant::canBeFulfilledAtQuantity() (Lunar's own
|
||||||
* purchasability rule: `purchasable === 'always'` is always true regardless of
|
* purchasability rule: `purchasable === 'always'` is always true regardless of
|
||||||
* stock, `in_stock` checks stock alone, anything else checks stock+backorder).
|
* stock, `in_stock` checks stock alone, anything else checks stock+backorder).
|
||||||
* Reflects stock as of the last reindex only — nothing currently reindexes a
|
* Modules\Core\Order\Listeners\DecrementStockOnOrderPlaced reindexes a product
|
||||||
* product when an order decrements its stock (see docs/product-listing.md).
|
* the moment an order placed against it decrements its stock — see that
|
||||||
|
* class's own docblock for why only `purchasable === 'in_stock'`
|
||||||
|
* variants are ever touched. Any other stock edit (a manual admin
|
||||||
|
* change, a future inventory-sync integration) still only reflects here
|
||||||
|
* as of the next reindex (see docs/product-listing.md).
|
||||||
*
|
*
|
||||||
* - recommendations (recommendations.id filterable): [{id, name, price, image}, ...]
|
* - recommendations (recommendations.id filterable): [{id, name, price, image}, ...]
|
||||||
* up to 4 other products to show alongside this one (a "related products"
|
* up to 4 other products to show alongside this one (a "related products"
|
||||||
@@ -83,6 +93,8 @@ class ProductIndexer extends BaseProductIndexer
|
|||||||
'channel_ids',
|
'channel_ids',
|
||||||
'in_stock',
|
'in_stock',
|
||||||
'recommendations.id',
|
'recommendations.id',
|
||||||
|
'skus',
|
||||||
|
'tags',
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -126,6 +138,7 @@ class ProductIndexer extends BaseProductIndexer
|
|||||||
->values()
|
->values()
|
||||||
->all();
|
->all();
|
||||||
$data['slugs'] = $model->urls->pluck('slug')->unique()->values()->all();
|
$data['slugs'] = $model->urls->pluck('slug')->unique()->values()->all();
|
||||||
|
$data['skus'] = $model->variants->pluck('sku')->filter()->unique()->values()->all();
|
||||||
$data['tags'] = $model->tags->pluck('value')->all();
|
$data['tags'] = $model->tags->pluck('value')->all();
|
||||||
$data['media'] = $model->media->map(fn (Media $media) => $this->mapMedia($media))->all();
|
$data['media'] = $model->media->map(fn (Media $media) => $this->mapMedia($media))->all();
|
||||||
$data['variants'] = $model->variants->map(fn (ProductVariant $variant) => $this->mapVariant($variant, $currency))->all();
|
$data['variants'] = $model->variants->map(fn (ProductVariant $variant) => $this->mapVariant($variant, $currency))->all();
|
||||||
@@ -161,8 +174,22 @@ class ProductIndexer extends BaseProductIndexer
|
|||||||
return [
|
return [
|
||||||
'id' => $variant->id,
|
'id' => $variant->id,
|
||||||
'sku' => $variant->sku,
|
'sku' => $variant->sku,
|
||||||
|
'gtin' => $variant->gtin,
|
||||||
|
'mpn' => $variant->mpn,
|
||||||
|
'ean' => $variant->ean,
|
||||||
'stock' => $variant->stock,
|
'stock' => $variant->stock,
|
||||||
|
'backorder' => $variant->backorder,
|
||||||
|
'unit_quantity' => $variant->unit_quantity,
|
||||||
'purchasable' => $variant->purchasable,
|
'purchasable' => $variant->purchasable,
|
||||||
|
'shippable' => $variant->shippable,
|
||||||
|
'tax_ref' => $variant->tax_ref,
|
||||||
|
'dimensions' => [
|
||||||
|
'length' => ['value' => $variant->length_value, 'unit' => $variant->length_unit],
|
||||||
|
'width' => ['value' => $variant->width_value, 'unit' => $variant->width_unit],
|
||||||
|
'height' => ['value' => $variant->height_value, 'unit' => $variant->height_unit],
|
||||||
|
'weight' => ['value' => $variant->weight_value, 'unit' => $variant->weight_unit],
|
||||||
|
'volume' => ['value' => $variant->volume_value, 'unit' => $variant->volume_unit],
|
||||||
|
],
|
||||||
'options' => $variant->values->map(fn ($value) => [
|
'options' => $variant->values->map(fn ($value) => [
|
||||||
'option' => $this->translatedName($value->option->name),
|
'option' => $this->translatedName($value->option->name),
|
||||||
'handle' => $value->option->handle,
|
'handle' => $value->option->handle,
|
||||||
|
|||||||
@@ -2,11 +2,15 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Catalog\Services;
|
namespace Modules\Core\Catalog\Services;
|
||||||
|
|
||||||
use Illuminate\Database\Eloquent\Collection;
|
use Illuminate\Pagination\LengthAwarePaginator;
|
||||||
use Illuminate\Support\Facades\App;
|
|
||||||
use Lunar\Facades\AttributeManifest;
|
use Lunar\Facades\AttributeManifest;
|
||||||
use Lunar\Models\Language;
|
use Lunar\Models\Language;
|
||||||
use Lunar\Models\Product;
|
use Lunar\Models\Product;
|
||||||
|
use Modules\Core\Catalog\DTOs\ProductFilters;
|
||||||
|
use Modules\Core\Catalog\DTOs\ProductListingResult;
|
||||||
|
use Modules\Core\Catalog\Enums\ProductSort;
|
||||||
|
use Modules\Core\Catalog\Support\ProductDocumentLocalizer;
|
||||||
|
use Modules\Core\Catalog\Support\ProductFilterBuilder;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Lunar's Meilisearch indexer flattens translated attributes into locale-suffixed
|
* Lunar's Meilisearch indexer flattens translated attributes into locale-suffixed
|
||||||
@@ -17,39 +21,103 @@ use Lunar\Models\Product;
|
|||||||
*/
|
*/
|
||||||
class ProductSearchService
|
class ProductSearchService
|
||||||
{
|
{
|
||||||
/**
|
public function __construct(
|
||||||
* @return Collection<int, Product>
|
private readonly ProductFilterBuilder $filterBuilder,
|
||||||
*/
|
private readonly ProductDocumentLocalizer $localizer,
|
||||||
public function search(string $query, ?string $locale = null): Collection
|
private readonly ProductService $products,
|
||||||
{
|
) {}
|
||||||
$locale ??= App::getLocale();
|
|
||||||
$defaultLocale = Language::getDefault()->code;
|
|
||||||
|
|
||||||
return Product::search($query)
|
/**
|
||||||
->options([
|
* Returns the exact same Modules\Core\Catalog\DTOs\ProductListingResult
|
||||||
'attributesToSearchOn' => $this->searchableFields($locale, $defaultLocale),
|
* ProductService::list() does — a search results page and a category
|
||||||
])
|
* listing page consume identically shaped data, one call each. The
|
||||||
->get();
|
* paginator itself carries plain, localized indexed-document arrays
|
||||||
|
* (not hydrated Product models), same as list().
|
||||||
|
*
|
||||||
|
* priceBounds/availableTags are delegated to ProductService's own
|
||||||
|
* priceSliderBounds()/availableTags() rather than reimplemented here —
|
||||||
|
* both already accept a $query param for exactly this reason (a search
|
||||||
|
* page's slider/tag sidebar should reflect only the products search
|
||||||
|
* actually matched, not the whole catalog).
|
||||||
|
*
|
||||||
|
* $filters/$sort apply the exact same semantics ProductService::list()
|
||||||
|
* uses for collection browsing (same ProductFilterBuilder, same
|
||||||
|
* ProductSort::toMeilisearchSort()) — a shopper narrowing a text search
|
||||||
|
* by price/brand/stock gets identical filter behavior to narrowing a
|
||||||
|
* category listing, since both go through the same Meilisearch `filter`
|
||||||
|
* clause underneath.
|
||||||
|
*/
|
||||||
|
public function search(
|
||||||
|
string $query,
|
||||||
|
?ProductFilters $filters = null,
|
||||||
|
?ProductSort $sort = null,
|
||||||
|
int $perPage = 24,
|
||||||
|
int $page = 1,
|
||||||
|
): ProductListingResult {
|
||||||
|
$options = [
|
||||||
|
'attributesToSearchOn' => $this->searchableFields(),
|
||||||
|
'filter' => $this->filterBuilder->build($filters),
|
||||||
|
];
|
||||||
|
|
||||||
|
if ($sort !== null) {
|
||||||
|
$options['sort'] = [$sort->toMeilisearchSort()];
|
||||||
|
}
|
||||||
|
|
||||||
|
$paginator = Product::search($query)
|
||||||
|
->options($options)
|
||||||
|
->paginateRaw(perPage: $perPage, page: $page);
|
||||||
|
|
||||||
|
$data = collect($this->localizer->hitsFrom($paginator))
|
||||||
|
->map(fn (array $product) => $this->localizer->withLocalizedFields($product))
|
||||||
|
->all();
|
||||||
|
|
||||||
|
$products = new LengthAwarePaginator(
|
||||||
|
items: $data,
|
||||||
|
total: $paginator->total(),
|
||||||
|
perPage: $paginator->perPage(),
|
||||||
|
currentPage: $paginator->currentPage(),
|
||||||
|
options: ['path' => LengthAwarePaginator::resolveCurrentPath()],
|
||||||
|
);
|
||||||
|
|
||||||
|
$priceBounds = $this->products->priceSliderBounds($filters, $filters?->minPrice, $filters?->maxPrice, $query);
|
||||||
|
$availableTags = $this->products->availableTags($filters, $query);
|
||||||
|
|
||||||
|
return new ProductListingResult($products, $priceBounds, $availableTags);
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Target the resolved locale's fields plus the default locale's fields, so a
|
* Targets every configured store language's fields, not just the current
|
||||||
* product that's only ever been translated into the default language still
|
* request locale plus the store default — a shopper browsing in Greek
|
||||||
* surfaces when searched in another locale, instead of becoming invisible
|
* typing an English word (or vice versa) should still match a product
|
||||||
* until every product is fully translated.
|
* whose only translation for that text happens to be in a third
|
||||||
|
* language. There's no per-request "current locale" concept in this
|
||||||
|
* method any more: which fields exist to search on is a property of the
|
||||||
|
* store's configured languages, not of who's asking.
|
||||||
|
*
|
||||||
|
* Also targets variants.options.value directly — a variant's option
|
||||||
|
* value (e.g. "Κάπτεν Γαμέρικα" on a "Name" option) is how ProductIndexer
|
||||||
|
* already indexes it (see mapVariant()), but it isn't one of Lunar's own
|
||||||
|
* attributes, so it can't come from AttributeManifest the way name/
|
||||||
|
* description do; it's a structural field of the document, added here
|
||||||
|
* directly instead. Not locale-suffixed like the attribute-manifest
|
||||||
|
* fields — option values are stored as one already-resolved string per
|
||||||
|
* variant (see ProductIndexer::translatedName()), not per-locale.
|
||||||
*
|
*
|
||||||
* @return array<int, string>
|
* @return array<int, string>
|
||||||
*/
|
*/
|
||||||
private function searchableFields(string $locale, string $defaultLocale): array
|
private function searchableFields(): array
|
||||||
{
|
{
|
||||||
$handles = AttributeManifest::getSearchableAttributes(Product::morphName())
|
$handles = AttributeManifest::getSearchableAttributes(Product::morphName())
|
||||||
->pluck('handle');
|
->pluck('handle');
|
||||||
|
|
||||||
$locales = array_unique([$locale, $defaultLocale]);
|
$locales = Language::all()->pluck('code');
|
||||||
|
|
||||||
return $handles
|
$attributeFields = $handles
|
||||||
->crossJoin($locales)
|
->crossJoin($locales)
|
||||||
->map(fn (array $pair) => "{$pair[0]}_{$pair[1]}")
|
->map(fn (array $pair) => "{$pair[0]}_{$pair[1]}");
|
||||||
|
|
||||||
|
return $attributeFields
|
||||||
|
->push('variants.options.value')
|
||||||
->values()
|
->values()
|
||||||
->all();
|
->all();
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,16 +2,14 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Catalog\Services;
|
namespace Modules\Core\Catalog\Services;
|
||||||
|
|
||||||
use Illuminate\Contracts\Pagination\LengthAwarePaginator as LengthAwarePaginatorContract;
|
|
||||||
use Illuminate\Pagination\LengthAwarePaginator;
|
use Illuminate\Pagination\LengthAwarePaginator;
|
||||||
use Illuminate\Support\Collection;
|
|
||||||
use Illuminate\Support\Facades\App;
|
|
||||||
use Lunar\Base\AttributeManifest;
|
|
||||||
use Lunar\FieldTypes\TranslatedText;
|
|
||||||
use Lunar\Models\Product;
|
use Lunar\Models\Product;
|
||||||
use Modules\Core\Localization\Services\LanguageCache;
|
use Modules\Core\Catalog\DTOs\PriceSliderBounds;
|
||||||
use Modules\Core\Catalog\DTOs\ProductFilters;
|
use Modules\Core\Catalog\DTOs\ProductFilters;
|
||||||
|
use Modules\Core\Catalog\DTOs\ProductListingResult;
|
||||||
use Modules\Core\Catalog\Enums\ProductSort;
|
use Modules\Core\Catalog\Enums\ProductSort;
|
||||||
|
use Modules\Core\Catalog\Support\ProductDocumentLocalizer;
|
||||||
|
use Modules\Core\Catalog\Support\ProductFilterBuilder;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Storefront product listing/filtering AND single-product lookup, all reading directly
|
* Storefront product listing/filtering AND single-product lookup, all reading directly
|
||||||
@@ -25,19 +23,34 @@ use Modules\Core\Catalog\Enums\ProductSort;
|
|||||||
class ProductService
|
class ProductService
|
||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly LanguageCache $languages,
|
private readonly ProductDocumentLocalizer $localizer,
|
||||||
private readonly AttributeManifest $attributes,
|
private readonly ProductFilterBuilder $filterBuilder,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Returns a real LengthAwarePaginator (not Scout's own paginateRaw() result -
|
* One call for everything a listing page needs: the product page AND
|
||||||
* see "Meilisearch driver quirk" below) so a controller/view gets normal
|
* the price slider's bounds — a controller used to have to call this
|
||||||
* pagination behaviour ($products->links(), JSON serialization, etc.)
|
* plus priceSliderBounds() separately and glue the results together
|
||||||
* without ever touching the raw Meilisearch response directly.
|
* itself; that orchestration now happens in here instead. Still issues
|
||||||
|
* two Meilisearch requests under the hood (the product search, and a
|
||||||
|
* separate price-facet-stats query — see priceSliderBounds()'s
|
||||||
|
* docblock for why they can't be merged into one without changing the
|
||||||
|
* slider's own UX), but the caller only ever makes one call.
|
||||||
|
*
|
||||||
|
* $filters->minPrice/$filters->maxPrice double as both the applied
|
||||||
|
* product filter AND the "is the slider actually narrowed" comparison
|
||||||
|
* in priceSliderBounds() — the same values, used two ways, so nothing
|
||||||
|
* new needs to be threaded through separately.
|
||||||
|
*
|
||||||
|
* The paginator itself is a real LengthAwarePaginator (not Scout's own
|
||||||
|
* paginateRaw() result - see "Meilisearch driver quirk" below) so a
|
||||||
|
* controller/view gets normal pagination behaviour ($products->links(),
|
||||||
|
* JSON serialization, etc.) without ever touching the raw Meilisearch
|
||||||
|
* response directly.
|
||||||
*/
|
*/
|
||||||
public function list(?ProductFilters $filters = null, int $perPage = 24, int $page = 1, ?ProductSort $sort = null): LengthAwarePaginator
|
public function list(?ProductFilters $filters = null, int $perPage = 24, int $page = 1, ?ProductSort $sort = null): ProductListingResult
|
||||||
{
|
{
|
||||||
$options = ['filter' => $this->buildFilter($filters)];
|
$options = ['filter' => $this->filterBuilder->build($filters)];
|
||||||
|
|
||||||
if ($sort !== null) {
|
if ($sort !== null) {
|
||||||
$options['sort'] = [$sort->toMeilisearchSort()];
|
$options['sort'] = [$sort->toMeilisearchSort()];
|
||||||
@@ -47,17 +60,48 @@ class ProductService
|
|||||||
->options($options)
|
->options($options)
|
||||||
->paginateRaw(perPage: $perPage, page: $page);
|
->paginateRaw(perPage: $perPage, page: $page);
|
||||||
|
|
||||||
$data = collect($this->hitsFrom($paginator))
|
$data = collect($this->localizer->hitsFrom($paginator))
|
||||||
->map(fn (array $product) => $this->withLocalizedFields($product))
|
->map(fn (array $product) => $this->localizer->withLocalizedFields($product))
|
||||||
->all();
|
->all();
|
||||||
|
|
||||||
return new LengthAwarePaginator(
|
$products = new LengthAwarePaginator(
|
||||||
items: $data,
|
items: $data,
|
||||||
total: $paginator->total(),
|
total: $paginator->total(),
|
||||||
perPage: $paginator->perPage(),
|
perPage: $paginator->perPage(),
|
||||||
currentPage: $paginator->currentPage(),
|
currentPage: $paginator->currentPage(),
|
||||||
options: ['path' => LengthAwarePaginator::resolveCurrentPath()],
|
options: ['path' => LengthAwarePaginator::resolveCurrentPath()],
|
||||||
);
|
);
|
||||||
|
|
||||||
|
$priceBounds = $this->priceSliderBounds($filters, $filters?->minPrice, $filters?->maxPrice);
|
||||||
|
$availableTags = $this->availableTags($filters);
|
||||||
|
|
||||||
|
return new ProductListingResult($products, $priceBounds, $availableTags);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Every distinct `tags` value present on a product matching $filters,
|
||||||
|
* excluding $filters->tag itself — same "scoped but not self-collapsing"
|
||||||
|
* reasoning as priceRange() excluding `price` — so selecting a tag
|
||||||
|
* doesn't shrink the sidebar down to just that one tag. Sorted
|
||||||
|
* alphabetically; Meilisearch's facetDistribution has no defined order
|
||||||
|
* of its own.
|
||||||
|
*
|
||||||
|
* $query defaults to '' (every product, same as list()'s own default
|
||||||
|
* text query) — same reasoning as priceRange()'s own $query: pass the
|
||||||
|
* shopper's search text here too so a search page's own tag sidebar
|
||||||
|
* reflects only the products search actually matched. Public (not
|
||||||
|
* private, unlike the rest of this listing-only orchestration) so
|
||||||
|
* ProductSearchService::search() can reuse it directly rather than
|
||||||
|
* reimplementing the same facet call a second time.
|
||||||
|
*
|
||||||
|
* @return array<int, string>
|
||||||
|
*/
|
||||||
|
public function availableTags(?ProductFilters $filters, string $query = ''): array
|
||||||
|
{
|
||||||
|
$filter = $this->filterBuilder->build($filters, exclude: ['tag']);
|
||||||
|
$tags = $this->rawFacets('tags', $filter, $query)['facetDistribution']['tags'] ?? [];
|
||||||
|
|
||||||
|
return collect($tags)->keys()->sort()->values()->all();
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -71,15 +115,18 @@ class ProductService
|
|||||||
* apply that field's own filter separately in the UI/query layer.
|
* apply that field's own filter separately in the UI/query layer.
|
||||||
*
|
*
|
||||||
* `$field` must be one of ProductIndexer's filterable fields; only discrete-value
|
* `$field` must be one of ProductIndexer's filterable fields; only discrete-value
|
||||||
* fields make sense here (`brand`, `in_stock`) — a numeric field like `price`
|
* fields make sense here (`brand`, `tags`, `in_stock`) — a numeric field like
|
||||||
* would return one "facet" per exact price, not a usable range bucket. Use
|
* `price` would return one "facet" per exact price, not a usable range bucket.
|
||||||
* `priceRange()` for `price` instead.
|
* Use `priceRange()` for `price` instead. `facets('tags', $filters)` is how a
|
||||||
|
* category page gets "which tags actually appear on products in this category" —
|
||||||
|
* pass a $filters that omits `tag` (see `build()`'s $exclude) so the tag list
|
||||||
|
* itself doesn't collapse to whichever tag is already selected.
|
||||||
*
|
*
|
||||||
* @return array<string, int> facet value => matching product count
|
* @return array<string, int> facet value => matching product count
|
||||||
*/
|
*/
|
||||||
public function facets(string $field, ?ProductFilters $filters = null): array
|
public function facets(string $field, ?ProductFilters $filters = null): array
|
||||||
{
|
{
|
||||||
return $this->rawFacets($field, $this->buildFilter($filters))['facetDistribution'][$field] ?? [];
|
return $this->rawFacets($field, $this->filterBuilder->build($filters))['facetDistribution'][$field] ?? [];
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -90,12 +137,17 @@ class ProductService
|
|||||||
* not `facetDistribution` — the right feature for a numeric field's range,
|
* not `facetDistribution` — the right feature for a numeric field's range,
|
||||||
* where `facets('price')` would otherwise return one entry per exact price.
|
* where `facets('price')` would otherwise return one entry per exact price.
|
||||||
*
|
*
|
||||||
|
* $query defaults to '' (every product, same as list()'s own default text
|
||||||
|
* query) — pass the shopper's search text here too so a search page's own
|
||||||
|
* price slider spans only the products that search actually matched,
|
||||||
|
* rather than the whole catalog's price range.
|
||||||
|
*
|
||||||
* @return array{min: ?float, max: ?float} null/null if no product matches
|
* @return array{min: ?float, max: ?float} null/null if no product matches
|
||||||
*/
|
*/
|
||||||
public function priceRange(?ProductFilters $filters = null): array
|
public function priceRange(?ProductFilters $filters = null, string $query = ''): array
|
||||||
{
|
{
|
||||||
$filter = $this->buildFilter($filters, exclude: ['price']);
|
$filter = $this->filterBuilder->build($filters, exclude: ['price']);
|
||||||
$stats = $this->rawFacets('price', $filter)['facetStats']['price'] ?? null;
|
$stats = $this->rawFacets('price', $filter, $query)['facetStats']['price'] ?? null;
|
||||||
|
|
||||||
return [
|
return [
|
||||||
'min' => $stats['min'] ?? null,
|
'min' => $stats['min'] ?? null,
|
||||||
@@ -103,9 +155,36 @@ class ProductService
|
|||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|
||||||
private function rawFacets(string $field, ?string $filter): array
|
/**
|
||||||
|
* priceRange() rounded to whole euros (floor/ceil, so the slider's ends
|
||||||
|
* are never tighter than what's actually in range) plus whether
|
||||||
|
* $selectedMinPrice/$selectedMaxPrice actually narrow it — the same
|
||||||
|
* "floor/ceil + is this a real filter" rule CategoryController and
|
||||||
|
* SearchController each used to duplicate inline. $selectedMinPrice/
|
||||||
|
* $selectedMaxPrice are the currently-applied filter values (e.g.
|
||||||
|
* CategoryListing::$minPrice), not part of $filters itself, since
|
||||||
|
* $filters here must already exclude price the way priceRange() expects.
|
||||||
|
*/
|
||||||
|
public function priceSliderBounds(
|
||||||
|
?ProductFilters $filters,
|
||||||
|
?float $selectedMinPrice,
|
||||||
|
?float $selectedMaxPrice,
|
||||||
|
string $query = '',
|
||||||
|
): PriceSliderBounds {
|
||||||
|
$priceRange = $this->priceRange($filters, $query);
|
||||||
|
|
||||||
|
$floor = $priceRange['min'] !== null ? (int) floor($priceRange['min']) : null;
|
||||||
|
$ceil = $priceRange['max'] !== null ? (int) ceil($priceRange['max']) : null;
|
||||||
|
|
||||||
|
$filtered = ($selectedMinPrice !== null && $selectedMinPrice > ($floor ?? PHP_INT_MIN))
|
||||||
|
|| ($selectedMaxPrice !== null && $selectedMaxPrice < ($ceil ?? PHP_INT_MAX));
|
||||||
|
|
||||||
|
return new PriceSliderBounds($floor, $ceil, $filtered);
|
||||||
|
}
|
||||||
|
|
||||||
|
private function rawFacets(string $field, ?string $filter, string $query = ''): array
|
||||||
{
|
{
|
||||||
return Product::search('')
|
return Product::search($query)
|
||||||
->options([
|
->options([
|
||||||
'filter' => $filter,
|
'filter' => $filter,
|
||||||
'facets' => [$field],
|
'facets' => [$field],
|
||||||
@@ -133,99 +212,86 @@ class ProductService
|
|||||||
return $this->findOneWhere("id = \"{$id}\"");
|
return $this->findOneWhere("id = \"{$id}\"");
|
||||||
}
|
}
|
||||||
|
|
||||||
private function findOneWhere(string $filter): ?array
|
|
||||||
{
|
|
||||||
$paginator = Product::search('')
|
|
||||||
->options(['filter' => $filter])
|
|
||||||
->paginateRaw(perPage: 1, page: 1);
|
|
||||||
|
|
||||||
$product = $this->hitsFrom($paginator)[0] ?? null;
|
|
||||||
|
|
||||||
return $product !== null ? $this->withLocalizedFields($product) : null;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Resolves every translated Product attribute's current-locale value from the
|
* The id/price/image of every variant on a product document (from
|
||||||
* indexer's per-locale `{handle}_{locale}` fields (e.g. `name_el`, `name_en`,
|
* getById()/getBySlug()'s own 'variants' array) — the base price and
|
||||||
* `seo_title_el`, ...) into a plain `{handle}` key, falling back to the store's
|
* thumbnail a variant picker/swatch list needs, without a caller
|
||||||
* default language (LanguageCache::defaultLocale()) when the current locale
|
* reaching into $product['variants'][n]['prices'][0]/['media'][0]
|
||||||
* has no translation - e.g. a product with no English copy yet still shows its
|
* itself. Domain shaping (which price/image represents a variant),
|
||||||
* Greek name on /en/ rather than rendering blank.
|
* not presentation — a card's href/layout stays a storefront concern
|
||||||
|
* (e.g. App\Catalog\ProductCard in 3dealer), but "the variant's price
|
||||||
|
* is its first price row" is a rule about the data, true regardless of
|
||||||
|
* which app renders it.
|
||||||
*
|
*
|
||||||
* Which handles are translated is read from AttributeManifest - the same
|
* @param array $product A document from getById()/getBySlug().
|
||||||
* source Lunar's own ScoutIndexer reads when exploding a TranslatedText
|
* @return array<int, array{id: int, price: ?float, image: ?string}>
|
||||||
* attribute into `{handle}_{locale}` keys at index time - rather than a fixed
|
|
||||||
* list, so a store's own custom translated attributes (e.g. `seo_title`) are
|
|
||||||
* picked up automatically with no change here. The raw per-locale keys are
|
|
||||||
* then stripped, since once resolved, callers only ever need the one that
|
|
||||||
* matched the current locale.
|
|
||||||
*
|
|
||||||
* Deliberately not config('app.locale') - App::setLocale() overwrites that
|
|
||||||
* config value on every request, so by request time it's just whatever the
|
|
||||||
* current locale already is, not a stable fallback.
|
|
||||||
*/
|
*/
|
||||||
private function withLocalizedFields(array $product): array
|
public function variantSummaries(array $product): array
|
||||||
{
|
{
|
||||||
$locale = App::getLocale();
|
return collect($product['variants'] ?? [])
|
||||||
$fallbackLocale = $this->languages->defaultLocale();
|
->map(fn (array $variant) => [
|
||||||
$availableLocales = $this->languages->availableLocales();
|
'id' => $variant['id'],
|
||||||
|
'price' => $variant['prices'][0]['price'] ?? null,
|
||||||
foreach ($this->translatedAttributeHandles() as $handle) {
|
'image' => $variant['media'][0]['url'] ?? null,
|
||||||
$product[$handle] = $product[$handle.'_'.$locale] ?? $product[$handle.'_'.$fallbackLocale] ?? null;
|
])
|
||||||
|
->values()
|
||||||
foreach ($availableLocales as $availableLocale) {
|
|
||||||
unset($product[$handle.'_'.$availableLocale]);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return $product;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @return array<int, string>
|
|
||||||
*/
|
|
||||||
private function translatedAttributeHandles(): array
|
|
||||||
{
|
|
||||||
return $this->attributes->getSearchableAttributes((new Product)->getMorphClass())
|
|
||||||
->filter(fn ($attribute) => $attribute->type === TranslatedText::class)
|
|
||||||
->pluck('handle')
|
|
||||||
->all();
|
->all();
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* For the Meilisearch driver, Scout's paginateRaw() puts the whole raw response
|
* $limit random products, still scoped to the index's own default
|
||||||
* (hits, query, processingTimeMs, ...) in items(), not a plain list of hits - the
|
* visibility (channel/status), unlike Eloquent's Product::inRandomOrder()
|
||||||
* actual documents are under the 'hits' key.
|
* which has no notion of that filtering at all — a random pick can never
|
||||||
|
* surface a hidden/unpublished product this way. Meilisearch itself has
|
||||||
|
* no ORDER BY RANDOM() equivalent, so this pulls every matching id only
|
||||||
|
* (attributesToRetrieve: ['id'], the lightest possible request — no
|
||||||
|
* name/media/variants/etc. for documents that will mostly be discarded),
|
||||||
|
* shuffles in PHP, then fetches the full localized documents for just
|
||||||
|
* the $limit ids actually picked.
|
||||||
|
*
|
||||||
|
* @return array<int, array>
|
||||||
*/
|
*/
|
||||||
private function hitsFrom(LengthAwarePaginatorContract $paginator): array
|
public function random(int $limit): array
|
||||||
{
|
{
|
||||||
$rawResponse = $paginator->items();
|
$raw = Product::search('')
|
||||||
|
->options(['attributesToRetrieve' => ['id']])
|
||||||
|
->raw();
|
||||||
|
|
||||||
return collect($rawResponse['hits'] ?? [])->values()->all();
|
$ids = collect($raw['hits'] ?? [])->pluck('id')->shuffle()->take($limit)->values();
|
||||||
|
|
||||||
|
if ($ids->isEmpty()) {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
|
||||||
|
// Meilisearch's `id IN [...]` doesn't preserve the given order — it's
|
||||||
|
// an unordered set filter, not a list to iterate — so the shuffle
|
||||||
|
// above would otherwise be silently undone by whatever order the
|
||||||
|
// re-fetch comes back in. Re-sort the fetched documents back into
|
||||||
|
// $ids's already-shuffled order instead of trusting the response's.
|
||||||
|
$products = collect($this->findAllWhere('id IN ['.$ids->implode(', ').']'))
|
||||||
|
->keyBy('id');
|
||||||
|
|
||||||
|
return $ids->map(fn ($id) => $products->get($id))->filter()->values()->all();
|
||||||
|
}
|
||||||
|
|
||||||
|
private function findOneWhere(string $filter): ?array
|
||||||
|
{
|
||||||
|
$products = $this->findAllWhere($filter, limit: 1);
|
||||||
|
|
||||||
|
return $products[0] ?? null;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @param array<int, 'collectionId'|'brand'|'price'|'inStockOnly'> $exclude filter
|
* @return array<int, array>
|
||||||
* fields to leave out even if set on $filters — e.g. priceRange() excludes
|
|
||||||
* 'price' so a price slider's own bounds don't shrink to whatever range is
|
|
||||||
* already selected on it.
|
|
||||||
*/
|
*/
|
||||||
private function buildFilter(?ProductFilters $filters, array $exclude = []): ?string
|
private function findAllWhere(string $filter, int $limit = 1000): array
|
||||||
{
|
{
|
||||||
if ($filters === null) {
|
$paginator = Product::search('')
|
||||||
return null;
|
->options(['filter' => $filter])
|
||||||
}
|
->paginateRaw(perPage: $limit, page: 1);
|
||||||
|
|
||||||
$clauses = Collection::make([
|
return collect($this->localizer->hitsFrom($paginator))
|
||||||
'collectionId' => $filters->collectionId !== null ? "collection_ids = \"{$filters->collectionId}\"" : null,
|
->map(fn (array $product) => $this->localizer->withLocalizedFields($product))
|
||||||
'brand' => $filters->brand !== null ? 'brand = "'.addcslashes($filters->brand, '"\\').'"' : null,
|
->all();
|
||||||
'price' => Collection::make([
|
|
||||||
$filters->minPrice !== null ? "price >= {$filters->minPrice}" : null,
|
|
||||||
$filters->maxPrice !== null ? "price <= {$filters->maxPrice}" : null,
|
|
||||||
])->filter()->join(' AND ') ?: null,
|
|
||||||
'inStockOnly' => $filters->inStockOnly ? 'in_stock = true' : null,
|
|
||||||
])->except($exclude)->filter();
|
|
||||||
|
|
||||||
return $clauses->isEmpty() ? null : $clauses->join(' AND ');
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Catalog\Services;
|
namespace Modules\Core\Catalog\Services;
|
||||||
|
|
||||||
use Illuminate\Support\Collection;
|
use Illuminate\Database\Eloquent\Collection;
|
||||||
use Lunar\Models\Product;
|
use Lunar\Models\Product;
|
||||||
use Modules\Core\Catalog\Contracts\RecommendationRule;
|
use Modules\Core\Catalog\Contracts\RecommendationRule;
|
||||||
|
|
||||||
@@ -25,7 +25,7 @@ class RecommendationService
|
|||||||
*/
|
*/
|
||||||
public function recommend(Product $product, int $limit = 4): Collection
|
public function recommend(Product $product, int $limit = 4): Collection
|
||||||
{
|
{
|
||||||
$recommendations = collect();
|
$recommendations = new Collection();
|
||||||
|
|
||||||
foreach (config('catalog.recommendation_rules', []) as $ruleClass) {
|
foreach (config('catalog.recommendation_rules', []) as $ruleClass) {
|
||||||
if ($recommendations->count() >= $limit) {
|
if ($recommendations->count() >= $limit) {
|
||||||
|
|||||||
@@ -0,0 +1,86 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Catalog\Support;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Pagination\LengthAwarePaginator as LengthAwarePaginatorContract;
|
||||||
|
use Illuminate\Support\Facades\App;
|
||||||
|
use Lunar\Base\AttributeManifest;
|
||||||
|
use Lunar\FieldTypes\TranslatedText;
|
||||||
|
use Lunar\Models\Product;
|
||||||
|
use Modules\Core\Localization\Services\LanguageCache;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Shared between Modules\Core\Catalog\Services\ProductService and
|
||||||
|
* ProductSearchService — both read the same kind of Meilisearch document
|
||||||
|
* (Modules\Core\Catalog\Services\ProductIndexer's shape) and need the
|
||||||
|
* exact same per-locale field resolution and raw-response unwrapping.
|
||||||
|
* Extracted rather than duplicated so a future fix to the localization-
|
||||||
|
* fallback logic only needs to be made once.
|
||||||
|
*/
|
||||||
|
class ProductDocumentLocalizer
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly LanguageCache $languages,
|
||||||
|
private readonly AttributeManifest $attributes,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Resolves every translated Product attribute's current-locale value from the
|
||||||
|
* indexer's per-locale `{handle}_{locale}` fields (e.g. `name_el`, `name_en`,
|
||||||
|
* `seo_title_el`, ...) into a plain `{handle}` key, falling back to the store's
|
||||||
|
* default language (LanguageCache::defaultLocale()) when the current locale
|
||||||
|
* has no translation - e.g. a product with no English copy yet still shows its
|
||||||
|
* Greek name on /en/ rather than rendering blank.
|
||||||
|
*
|
||||||
|
* Which handles are translated is read from AttributeManifest - the same
|
||||||
|
* source Lunar's own ScoutIndexer reads when exploding a TranslatedText
|
||||||
|
* attribute into `{handle}_{locale}` keys at index time - rather than a fixed
|
||||||
|
* list, so a store's own custom translated attributes (e.g. `seo_title`) are
|
||||||
|
* picked up automatically with no change here. The raw per-locale keys are
|
||||||
|
* then stripped, since once resolved, callers only ever need the one that
|
||||||
|
* matched the current locale.
|
||||||
|
*
|
||||||
|
* Deliberately not config('app.locale') - App::setLocale() overwrites that
|
||||||
|
* config value on every request, so by request time it's just whatever the
|
||||||
|
* current locale already is, not a stable fallback.
|
||||||
|
*/
|
||||||
|
public function withLocalizedFields(array $product): array
|
||||||
|
{
|
||||||
|
$locale = App::getLocale();
|
||||||
|
$fallbackLocale = $this->languages->defaultLocale();
|
||||||
|
$availableLocales = $this->languages->availableLocales();
|
||||||
|
|
||||||
|
foreach ($this->translatedAttributeHandles() as $handle) {
|
||||||
|
$product[$handle] = $product[$handle.'_'.$locale] ?? $product[$handle.'_'.$fallbackLocale] ?? null;
|
||||||
|
|
||||||
|
foreach ($availableLocales as $availableLocale) {
|
||||||
|
unset($product[$handle.'_'.$availableLocale]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return $product;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* For the Meilisearch driver, Scout's paginateRaw() puts the whole raw response
|
||||||
|
* (hits, query, processingTimeMs, ...) in items(), not a plain list of hits - the
|
||||||
|
* actual documents are under the 'hits' key.
|
||||||
|
*/
|
||||||
|
public function hitsFrom(LengthAwarePaginatorContract $paginator): array
|
||||||
|
{
|
||||||
|
$rawResponse = $paginator->items();
|
||||||
|
|
||||||
|
return collect($rawResponse['hits'] ?? [])->values()->all();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return array<int, string>
|
||||||
|
*/
|
||||||
|
private function translatedAttributeHandles(): array
|
||||||
|
{
|
||||||
|
return $this->attributes->getSearchableAttributes((new Product)->getMorphClass())
|
||||||
|
->filter(fn ($attribute) => $attribute->type === TranslatedText::class)
|
||||||
|
->pluck('handle')
|
||||||
|
->all();
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Catalog\Support;
|
||||||
|
|
||||||
|
use Illuminate\Support\Collection;
|
||||||
|
use Modules\Core\Catalog\DTOs\ProductFilters;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Builds a Meilisearch `filter` clause from a ProductFilters DTO — extracted
|
||||||
|
* out of ProductService (where it originated, scoped to browsing/filtering
|
||||||
|
* without a search term) so ProductSearchService can apply the exact same
|
||||||
|
* filter semantics to a text query too, rather than reimplementing it.
|
||||||
|
*/
|
||||||
|
class ProductFilterBuilder
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param array<int, 'collectionId'|'brand'|'tag'|'price'|'inStockOnly'> $exclude
|
||||||
|
* filter fields to leave out even if set on $filters — e.g.
|
||||||
|
* ProductService::priceRange() excludes 'price' so a price slider's own
|
||||||
|
* bounds don't shrink to whatever range is already selected on it.
|
||||||
|
*/
|
||||||
|
public function build(?ProductFilters $filters, array $exclude = []): ?string
|
||||||
|
{
|
||||||
|
if ($filters === null) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
$clauses = Collection::make([
|
||||||
|
'collectionId' => $filters->collectionId !== null ? "collection_ids = \"{$filters->collectionId}\"" : null,
|
||||||
|
'brand' => $filters->brand !== null ? 'brand = "'.addcslashes($filters->brand, '"\\').'"' : null,
|
||||||
|
'tag' => $filters->tag !== null ? 'tags = "'.addcslashes($filters->tag, '"\\').'"' : null,
|
||||||
|
'price' => Collection::make([
|
||||||
|
$filters->minPrice !== null ? "price >= {$filters->minPrice}" : null,
|
||||||
|
$filters->maxPrice !== null ? "price <= {$filters->maxPrice}" : null,
|
||||||
|
])->filter()->join(' AND ') ?: null,
|
||||||
|
'inStockOnly' => $filters->inStockOnly ? 'in_stock = true' : null,
|
||||||
|
])->except($exclude)->filter();
|
||||||
|
|
||||||
|
return $clauses->isEmpty() ? null : $clauses->join(' AND ');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,62 +0,0 @@
|
|||||||
<?php
|
|
||||||
|
|
||||||
namespace Modules\Core\Checkout\Contracts;
|
|
||||||
|
|
||||||
use Lunar\Exceptions\FingerprintMismatchException;
|
|
||||||
use Lunar\Exceptions\Carts\CartException;
|
|
||||||
use Lunar\Models\Cart;
|
|
||||||
use Lunar\Models\Order;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* A boboko-owned payment driver — wraps a payment gateway's own confirmation
|
|
||||||
* mechanics (Stripe's synchronous authorize() call, a redirect-based
|
|
||||||
* provider's async callback/webhook, anything else) behind one uniform
|
|
||||||
* moment: "payment is confirmed, place the order."
|
|
||||||
*
|
|
||||||
* confirm() is the only thing a driver is required to do: once it has,
|
|
||||||
* by whatever mechanism is native to that gateway, independently decided
|
|
||||||
* the payment succeeded, it calls Modules\Core\Checkout\Services\
|
|
||||||
* CheckoutService::placeOrder($fingerprint) itself — no driver ever calls
|
|
||||||
* Lunar\Models\Cart::createOrder() directly. This is what lets the
|
|
||||||
* storefront checkout sequence stay uniform regardless of which provider is
|
|
||||||
* active: set addresses, select shipping, hand off to whichever driver is
|
|
||||||
* configured, and the driver decides when (or whether) the order actually
|
|
||||||
* gets created. See docs/checkout.md / docs/payments.md.
|
|
||||||
*/
|
|
||||||
interface PaymentDriver
|
|
||||||
{
|
|
||||||
/**
|
|
||||||
* Whether this driver can actually be used right now — e.g. Stripe
|
|
||||||
* checking its own API key is present, an offline-style driver always
|
|
||||||
* returning true since it has no external dependency. Independent of
|
|
||||||
* Modules\Core\Payment\Models\PaymentMethod::enabled (the admin
|
|
||||||
* on/off toggle) — CheckoutService::getPaymentMethods() combines both:
|
|
||||||
* a type is only offered to the storefront if it's administratively
|
|
||||||
* enabled AND its driver reports itself configured.
|
|
||||||
*/
|
|
||||||
public function isConfigured(): bool;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* $type is the payment type key being confirmed (e.g. 'cash-in-hand',
|
|
||||||
* 'cash-on-delivery', 'stripe') — passed through even though most
|
|
||||||
* drivers only ever serve one type, because a driver shared across
|
|
||||||
* several types (e.g. one "no real confirmation" offline driver behind
|
|
||||||
* both cash-in-hand and cash-on-delivery) needs it to look up that
|
|
||||||
* type's own config (e.g. its 'authorized' status) rather than another
|
|
||||||
* type's.
|
|
||||||
*
|
|
||||||
* $data carries whatever the gateway needs to confirm this specific
|
|
||||||
* payment (Stripe: ['payment_intent' => $id], a redirect-based
|
|
||||||
* provider: its callback payload) — passed explicitly by the caller
|
|
||||||
* (a controller, a webhook job) rather than a driver reaching into the
|
|
||||||
* global request(), so confirm() works the same whether it's called
|
|
||||||
* from a synchronous HTTP request or an async webhook/job with no
|
|
||||||
* active request at all.
|
|
||||||
*
|
|
||||||
* @param array<string, mixed> $data
|
|
||||||
*
|
|
||||||
* @throws FingerprintMismatchException
|
|
||||||
* @throws CartException
|
|
||||||
*/
|
|
||||||
public function confirm(Cart $cart, string $type, string $fingerprint, array $data): Order;
|
|
||||||
}
|
|
||||||
@@ -5,13 +5,17 @@ namespace Modules\Core\Checkout\Events;
|
|||||||
use Lunar\Models\Order;
|
use Lunar\Models\Order;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Dispatched by CheckoutService::placeOrder() the moment an Order exists —
|
* Dispatched once an Order's placed_at is set — the handoff point between
|
||||||
* the handoff point between Checkout and Order (see docs/checkout.md's
|
* Checkout/Payment and Order (see docs/checkout.md's "Three-stage
|
||||||
* "Three-stage lifecycle"). Checkout has no opinion about what happens
|
* lifecycle"). Fired by Modules\Core\Order\Listeners\
|
||||||
* after this fires; Order's own listeners (not built yet — Order is a
|
* ApplyResolvedPaymentStatus once it resolves a PaymentCaptured/
|
||||||
* named-but-unscoped concern, same status Recovery had before it existed)
|
* PaymentAuthorized event into an actual order status change, not by
|
||||||
* would be what reacts to it — e.g. a confirmation email, initializing
|
* CheckoutService directly — a draft Order can exist (via
|
||||||
* order status tracking.
|
* CheckoutService::initiatePayment()) well before this fires, if payment
|
||||||
|
* resolves asynchronously (e.g. a redirect-based gateway). Checkout has no
|
||||||
|
* opinion about what happens after this fires; Order's own listeners are
|
||||||
|
* what react to it — e.g. a confirmation email, initializing order status
|
||||||
|
* tracking.
|
||||||
*/
|
*/
|
||||||
class OrderPlaced
|
class OrderPlaced
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -0,0 +1,20 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Checkout\Events;
|
||||||
|
|
||||||
|
use Lunar\Models\Cart;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by CheckoutService::setRecoveryConsent() every time the
|
||||||
|
* shopper's promotional/abandoned-cart-recovery opt-in changes — including
|
||||||
|
* an explicit opt-OUT (a later submit with the checkbox unticked), not
|
||||||
|
* just an opt-in. $consent is the new value, already written to
|
||||||
|
* Cart::meta by the time this fires.
|
||||||
|
*/
|
||||||
|
class RecoveryConsentSet
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly Cart $cart,
|
||||||
|
public readonly bool $consent,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Checkout\Exceptions;
|
||||||
|
|
||||||
|
use RuntimeException;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Thrown by CheckoutService::initiatePayment() when $termsAccepted is
|
||||||
|
* false — an Order is a consumer contract, and its acceptance must be
|
||||||
|
* refused rather than created-then-flagged. No Lunar exception type
|
||||||
|
* covers this, same reasoning as UnknownPaymentTypeException.
|
||||||
|
*/
|
||||||
|
class TermsNotAcceptedException extends RuntimeException
|
||||||
|
{
|
||||||
|
public function __construct()
|
||||||
|
{
|
||||||
|
parent::__construct('The order cannot be placed until the terms have been accepted.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -10,17 +10,19 @@ use Lunar\Base\Addressable;
|
|||||||
use Lunar\DataTypes\ShippingOption;
|
use Lunar\DataTypes\ShippingOption;
|
||||||
use Lunar\Facades\ShippingManifest;
|
use Lunar\Facades\ShippingManifest;
|
||||||
use Lunar\Models\Cart;
|
use Lunar\Models\Cart;
|
||||||
use Lunar\Models\Order;
|
|
||||||
use Modules\Core\Cart\Services\CartService;
|
use Modules\Core\Cart\Services\CartService;
|
||||||
use Modules\Core\Checkout\Contracts\PaymentDriver;
|
|
||||||
use Modules\Core\Checkout\Events\BillingAddressSet;
|
use Modules\Core\Checkout\Events\BillingAddressSet;
|
||||||
use Modules\Core\Checkout\Events\OrderPlaced;
|
|
||||||
use Modules\Core\Checkout\Events\PaymentMethodSelected;
|
use Modules\Core\Checkout\Events\PaymentMethodSelected;
|
||||||
|
use Modules\Core\Checkout\Events\RecoveryConsentSet;
|
||||||
use Modules\Core\Checkout\Events\ShippingAddressSet;
|
use Modules\Core\Checkout\Events\ShippingAddressSet;
|
||||||
use Modules\Core\Checkout\Events\ShippingOptionSelected;
|
use Modules\Core\Checkout\Events\ShippingOptionSelected;
|
||||||
use Modules\Core\Checkout\Exceptions\InvalidShippingOptionException;
|
use Modules\Core\Checkout\Exceptions\InvalidShippingOptionException;
|
||||||
|
use Modules\Core\Checkout\Exceptions\TermsNotAcceptedException;
|
||||||
use Modules\Core\Checkout\Exceptions\UnknownPaymentTypeException;
|
use Modules\Core\Checkout\Exceptions\UnknownPaymentTypeException;
|
||||||
|
use Modules\Core\Payment\DTOs\PaymentResult;
|
||||||
use Modules\Core\Payment\Models\PaymentMethod;
|
use Modules\Core\Payment\Models\PaymentMethod;
|
||||||
|
use Modules\Core\Payment\Services\PaymentDriverRegistry;
|
||||||
|
use Modules\Core\Payment\Services\PaymentMethodCache;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Storefront-facing checkout operations, mirroring
|
* Storefront-facing checkout operations, mirroring
|
||||||
@@ -29,9 +31,11 @@ use Modules\Core\Payment\Models\PaymentMethod;
|
|||||||
* implementation detail. See docs/checkout.md for the full design —
|
* implementation detail. See docs/checkout.md for the full design —
|
||||||
* Checkout is the middle of a three-stage lifecycle (Cart → Checkout →
|
* Checkout is the middle of a three-stage lifecycle (Cart → Checkout →
|
||||||
* Order): it owns the placement moment itself (address, shipping selection,
|
* Order): it owns the placement moment itself (address, shipping selection,
|
||||||
* placeOrder()) and ends the instant an Order exists. What happens to that
|
* ensuring a draft Order exists) and hands off to Payment the instant that
|
||||||
* Order afterward (status transitions, fulfillment) is deliberately out of
|
* draft exists — see initiatePayment(). What happens to that Order
|
||||||
* scope here — see OrderPlaced's docblock.
|
* afterward (status transitions, fulfillment) is deliberately out of
|
||||||
|
* scope here — see docs/payments.md and Checkout\Events\OrderPlaced's
|
||||||
|
* docblock for where that now lives.
|
||||||
*
|
*
|
||||||
* Depends on CartService for cart access rather than reaching into
|
* Depends on CartService for cart access rather than reaching into
|
||||||
* Lunar\Facades\CartSession directly a second time, so Checkout stays
|
* Lunar\Facades\CartSession directly a second time, so Checkout stays
|
||||||
@@ -41,6 +45,8 @@ class CheckoutService
|
|||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly CartService $cart,
|
private readonly CartService $cart,
|
||||||
|
private readonly PaymentDriverRegistry $paymentDrivers,
|
||||||
|
private readonly PaymentMethodCache $paymentMethods,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
public function setShippingAddress(array|Addressable $address): Cart
|
public function setShippingAddress(array|Addressable $address): Cart
|
||||||
@@ -61,6 +67,49 @@ class CheckoutService
|
|||||||
return $cart;
|
return $cart;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The shopper's promotional/abandoned-cart-recovery opt-in — a
|
||||||
|
* cart-level decision, deliberately independent of setShippingAddress()/
|
||||||
|
* setBillingAddress(): consent is given once, and must NOT be reset or
|
||||||
|
* re-asked just because the shopper later changes which address is on
|
||||||
|
* the cart (a different Addressable being set is not a withdrawal of
|
||||||
|
* consent). Only an explicit call to THIS method — the checkbox itself
|
||||||
|
* being submitted, checked or unchecked — ever changes it; calling it
|
||||||
|
* again with false is exactly how a later opt-out is recorded.
|
||||||
|
*
|
||||||
|
* Stored on Cart::meta (interim, per the legal design this implements —
|
||||||
|
* a real column/consent record is the eventual target) as
|
||||||
|
* recovery_consent (bool), recovery_consent_at (ISO 8601 timestamp,
|
||||||
|
* null when $consent is false), and recovery_consent_policy_version
|
||||||
|
* (config('legal.privacy_policy_version') at the moment of consent —
|
||||||
|
* so a later dispute is answered from what was actually agreed to,
|
||||||
|
* not whatever the policy says today). Separate from any future
|
||||||
|
* newsletter opt-in — recovery consent is its own scope, never merged
|
||||||
|
* with marketing-newsletter consent.
|
||||||
|
*
|
||||||
|
* Deliberately does not merge with the meta-writing pattern
|
||||||
|
* selectPaymentMethod() uses (read-merge-save in two separate
|
||||||
|
* statements) — this writes both meta keys in one save, since there's
|
||||||
|
* no dependency between recovery_consent and anything else needing to
|
||||||
|
* be persisted first.
|
||||||
|
*/
|
||||||
|
public function setRecoveryConsent(bool $consent): Cart
|
||||||
|
{
|
||||||
|
$cart = $this->cart->currentOrCreate();
|
||||||
|
|
||||||
|
$cart->meta = [
|
||||||
|
...($cart->meta?->toArray() ?? []),
|
||||||
|
'recovery_consent' => $consent,
|
||||||
|
'recovery_consent_at' => $consent ? now()->toIso8601String() : null,
|
||||||
|
'recovery_consent_policy_version' => $consent ? config('legal.privacy_policy_version') : null,
|
||||||
|
];
|
||||||
|
$cart->save();
|
||||||
|
|
||||||
|
Event::dispatch(new RecoveryConsentSet($cart, $consent));
|
||||||
|
|
||||||
|
return $cart;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Every shipping option currently available for the cart — already
|
* Every shipping option currently available for the cart — already
|
||||||
* fully backed by the merged Shipping-Carriers work: this runs every
|
* fully backed by the merged Shipping-Carriers work: this runs every
|
||||||
@@ -98,98 +147,73 @@ class CheckoutService
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* $fingerprint is mandatory, not optional — the caller must prove the
|
* Every payment method currently offered to the storefront, ordered by
|
||||||
* cart total the shopper last saw (Cart::fingerprint()) still matches
|
* Modules\Core\Payment\Models\PaymentMethod::position — a row is
|
||||||
* before an order is placed. Cart::checkFingerprint() throws Lunar's own
|
* offered only when ALL three checks pass, each meaning something
|
||||||
* FingerprintMismatchException on a mismatch (a line's price changed,
|
* different to an admin diagnosing why a method isn't showing up (see
|
||||||
* stock adjusted the total, another tab modified the cart) rather than
|
* docs/payments.md):
|
||||||
* silently placing an order at a different total than what was shown.
|
* 1. `enabled` — an admin turned it on.
|
||||||
|
* 2. its `driver` still resolves via PaymentDriverRegistry — the
|
||||||
|
* driver class hasn't been removed (see the `payment:sync-drivers`
|
||||||
|
* command, which sets `driver_missing_at` when this fails; a row
|
||||||
|
* with that set is excluded here regardless of `enabled`, so a
|
||||||
|
* vanished driver can never silently look "available").
|
||||||
|
* 3. the resolved driver reports Configurable::isConfigured() — its
|
||||||
|
* own runtime requirements (e.g. an API key) are met.
|
||||||
*
|
*
|
||||||
* Not called directly by a storefront — see confirmPayment(), which is
|
* @return Collection<int, PaymentMethod>
|
||||||
* the only caller and supplies the fingerprint captured in
|
|
||||||
* selectPaymentMethod(), not one the storefront has to obtain itself.
|
|
||||||
*
|
|
||||||
* No exception wrapping: Lunar\Validation\Cart\ValidateCartForOrderCreation
|
|
||||||
* (run inside Cart::createOrder()) already throws
|
|
||||||
* Lunar\Exceptions\Carts\CartException with a field-keyed MessageBag
|
|
||||||
* ($exception->errors()) for address/shipping-option validation and the
|
|
||||||
* duplicate-order guard — already the right shape for a storefront to
|
|
||||||
* render as form errors directly. FingerprintMismatchException
|
|
||||||
* propagates the same way, for the same reason.
|
|
||||||
*
|
|
||||||
* @throws FingerprintMismatchException
|
|
||||||
* @throws CartException
|
|
||||||
*/
|
*/
|
||||||
public function placeOrder(string $fingerprint): Order
|
public function getPaymentMethods(): Collection
|
||||||
{
|
{
|
||||||
$cart = $this->cart->currentOrCreate();
|
return $this->paymentMethods->all()
|
||||||
$cart->checkFingerprint($fingerprint);
|
->filter(fn (PaymentMethod $method) => $method->enabled && $method->driver_missing_at === null)
|
||||||
|
->filter(fn (PaymentMethod $method) => $this->paymentDrivers->resolve($method->driver)?->isConfigured() ?? false)
|
||||||
$order = $cart->createOrder();
|
->values();
|
||||||
|
|
||||||
Event::dispatch(new OrderPlaced($order));
|
|
||||||
|
|
||||||
return $order;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Every payment type currently offered to the storefront — every key
|
|
||||||
* in config('lunar.payments.types') that is BOTH administratively
|
|
||||||
* enabled (Modules\Core\Payment\Models\PaymentMethod::enabled) AND
|
|
||||||
* whose registered PaymentDriver reports itself usable right now
|
|
||||||
* (PaymentDriver::isConfigured() — e.g. Stripe with no API key set is
|
|
||||||
* never offered, regardless of the enabled toggle). A type with no
|
|
||||||
* PaymentMethod row at all (never seeded) is treated as not offered,
|
|
||||||
* same as disabled — nothing here creates one; see
|
|
||||||
* InstallLunarCommand::seedPaymentMethods().
|
|
||||||
*
|
|
||||||
* @return array<string>
|
|
||||||
*/
|
|
||||||
public function getPaymentMethods(): array
|
|
||||||
{
|
|
||||||
return PaymentMethod::where('enabled', true)
|
|
||||||
->pluck('type')
|
|
||||||
->filter(fn (string $type) => $this->resolvePaymentDriver($type)?->isConfigured() ?? false)
|
|
||||||
->values()
|
|
||||||
->all();
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Records which payment type the shopper picked (Cart::meta
|
* Records which payment type the shopper picked (Cart::meta
|
||||||
* ['payment_method']) — read by e.g. Modules\Core\Payment\Pipelines\
|
* ['payment_method']) — read by Modules\Core\Payment\Pipelines\
|
||||||
* Cart\ApplyCashOnDeliveryFee to add that type's own cart-total
|
* Cart\ApplyPaymentMethodFee to add that method's own `data.fee` (if
|
||||||
* adjustments before recalculation.
|
* any) before recalculation.
|
||||||
*
|
*
|
||||||
* Also snapshots Cart::fingerprint() into meta, *after* saving the
|
* Also snapshots Cart::fingerprint() into meta, *after* saving the
|
||||||
* chosen type — the fingerprint has to reflect the final total
|
* chosen type — the fingerprint has to reflect the final total
|
||||||
* including any payment-type-specific adjustment (e.g. a COD
|
* including any payment-method-specific fee, which only exists once
|
||||||
* surcharge), which only exists once payment_method is set and the
|
* payment_method is set and the cart recalculates. Captured here,
|
||||||
* cart recalculates. Captured here, server-side, rather than asked of
|
* server-side, rather than asked of the storefront: this is the last
|
||||||
* the storefront: this is the last moment before confirmPayment() that
|
* moment before initiatePayment() that the shopper's reviewed total is
|
||||||
* the shopper's reviewed total is known, and confirmPayment() reads it
|
* known, and initiatePayment() reads it back internally instead of
|
||||||
* back internally instead of taking a fingerprint parameter — a
|
* taking a fingerprint parameter — a storefront should never need to
|
||||||
* storefront should never need to know Cart::fingerprint() exists.
|
* know Cart::fingerprint() exists.
|
||||||
*
|
*
|
||||||
* Does not itself call a PaymentDriver — selecting a method and
|
* Does not itself call a payment driver — selecting a method and
|
||||||
* confirming payment against it are deliberately separate steps, same
|
* initiating payment against it are deliberately separate steps, same
|
||||||
* as selecting a shipping option happens before placing the order.
|
* as selecting a shipping option happens before placing the order.
|
||||||
*
|
*
|
||||||
* @throws UnknownPaymentTypeException if $type isn't currently offered
|
* @throws UnknownPaymentTypeException if $type isn't currently offered
|
||||||
* — see getPaymentMethods() for what that means (registered,
|
* — see getPaymentMethods() for what that means
|
||||||
* administratively enabled, and its driver reports itself usable)
|
|
||||||
*/
|
*/
|
||||||
public function selectPaymentMethod(string $type): Cart
|
public function selectPaymentMethod(string $type): Cart
|
||||||
{
|
{
|
||||||
if (! in_array($type, $this->getPaymentMethods(), true)) {
|
if (! $this->getPaymentMethods()->contains('type', $type)) {
|
||||||
throw new UnknownPaymentTypeException($type);
|
throw new UnknownPaymentTypeException($type);
|
||||||
}
|
}
|
||||||
|
|
||||||
$cart = $this->cart->currentOrCreate();
|
$cart = $this->cart->currentOrCreate();
|
||||||
$cart->meta = [...$cart->meta->toArray(), 'payment_method' => $type];
|
$cart->meta = [...($cart->meta?->toArray() ?? []), 'payment_method' => $type];
|
||||||
$cart->save();
|
$cart->save();
|
||||||
|
|
||||||
$cart = $cart->calculate();
|
// Cart::calculate() no-ops if this cart instance was already
|
||||||
$cart->meta = [...$cart->meta->toArray(), 'checkout_fingerprint' => $cart->fingerprint()];
|
// calculated earlier in the request (Cart::isCalculated()) — which
|
||||||
|
// it will have been if the shopper switches payment method after
|
||||||
|
// the checkout page's first render already calculated it. Without
|
||||||
|
// recalculate() forcing a fresh run, the just-saved payment_method
|
||||||
|
// (and any fee tied to it, see ApplyPaymentMethodFee) would never
|
||||||
|
// be reflected — the summary would keep showing whichever method
|
||||||
|
// was calculated first.
|
||||||
|
$cart = $cart->recalculate();
|
||||||
|
$cart->meta = [...($cart->meta?->toArray() ?? []), 'checkout_fingerprint' => $cart->fingerprint()];
|
||||||
$cart->save();
|
$cart->save();
|
||||||
|
|
||||||
Event::dispatch(new PaymentMethodSelected($cart, $type));
|
Event::dispatch(new PaymentMethodSelected($cart, $type));
|
||||||
@@ -198,51 +222,93 @@ class CheckoutService
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Resolves $type's registered PaymentDriver and calls confirm() —
|
* The one storefront-facing "place this order and pay for it" call —
|
||||||
* the driver decides whether/when the order actually gets placed (see
|
* the point where Checkout hands off to Payment. Ensures a draft
|
||||||
* Modules\Core\Checkout\Contracts\PaymentDriver's docblock). $data
|
* Order exists (Cart::createOrder() — confirmed idempotent against a
|
||||||
* carries whatever that driver needs (Stripe's payment_intent id, a
|
* cart's own pre-existing, not-yet-placed-at draft; see
|
||||||
* future redirect-based provider's callback payload).
|
* vendor/lunarphp/core/src/Actions/Carts/CreateOrder.php), then
|
||||||
|
* resolves the payment method selected by selectPaymentMethod() and
|
||||||
|
* calls pay() or authorize() on its driver, per that method's own
|
||||||
|
* `capture_mode` column.
|
||||||
*
|
*
|
||||||
* The fingerprint passed to the driver is the one captured by
|
* Returns the driver's own PaymentResult UNCHANGED — this method does
|
||||||
* selectPaymentMethod(), not supplied by the caller — see that
|
* not wait for or resolve anything past what pay()/authorize() itself
|
||||||
* method's docblock. Throws the same FingerprintMismatchException a
|
* returns synchronously. A Pending result (an async gateway like
|
||||||
* caller-supplied one would if the cart's total has since changed;
|
* Stripe requiring 3-D Secure/a redirect) is a normal, expected
|
||||||
* missing entirely (selectPaymentMethod() was never called for this
|
* outcome, not an error — the caller (a storefront controller) is
|
||||||
* cart) is treated the same as a mismatch, not a different error.
|
* responsible for whatever the gateway needs next.
|
||||||
*
|
*
|
||||||
* @param array<string, mixed> $data
|
* The draft order's own $order->total (not the Cart's) is what gets
|
||||||
|
* passed as $amount — Order::$total is Lunar's own Price-cast
|
||||||
|
* attribute, already resolving the correct Currency via the order's
|
||||||
|
* own currency_code, and is the authoritative total once the draft
|
||||||
|
* row exists.
|
||||||
*
|
*
|
||||||
* @throws UnknownPaymentTypeException if $type isn't currently offered
|
* $context passed to the driver is {cart_id, order_id} — the exact
|
||||||
* (see getPaymentMethods()) — re-checked here, not just in
|
* keys Modules\Core\Payment\Drivers\StripePaymentDriver::
|
||||||
* selectPaymentMethod(), since a type could be disabled between
|
* rememberIntent() already reads.
|
||||||
* selection and confirmation
|
*
|
||||||
* @throws \Lunar\Exceptions\FingerprintMismatchException
|
* Same fingerprint precondition the old placeOrder() had: mandatory,
|
||||||
* @throws \Lunar\Exceptions\Carts\CartException
|
* not optional, checked before the draft is created.
|
||||||
|
*
|
||||||
|
* $termsAccepted is likewise mandatory, not optional data a caller
|
||||||
|
* might omit — an Order is a consumer contract, and its acceptance
|
||||||
|
* must be refused (TermsNotAcceptedException, before createOrder() is
|
||||||
|
* ever called — the order is never created-then-flagged) rather than
|
||||||
|
* assumed. $policyVersion is recorded alongside it on the created
|
||||||
|
* Order's own meta (terms_accepted, terms_accepted_at,
|
||||||
|
* terms_accepted_policy_version) — the order-level equivalent of
|
||||||
|
* setRecoveryConsent()'s cart-level record, and the durable audit
|
||||||
|
* trail for a later "what did the shopper actually agree to"
|
||||||
|
* dispute. Written directly here (not via a separate event/listener)
|
||||||
|
* since the Order row this attaches to doesn't exist before
|
||||||
|
* createOrder() runs, and nothing else needs to react to this
|
||||||
|
* specific write independently of the order simply existing.
|
||||||
|
*
|
||||||
|
* @param array<string, mixed> $data passed through untouched to
|
||||||
|
* the driver's pay()/authorize() — e.g. Stripe's payment_method
|
||||||
|
* token.
|
||||||
|
*
|
||||||
|
* @throws UnknownPaymentTypeException if the cart's selected
|
||||||
|
* payment_method (from selectPaymentMethod()) is no longer offered
|
||||||
|
* — re-checked here, not just at selection time, since a method
|
||||||
|
* could be disabled (or its driver removed) in between
|
||||||
|
* @throws TermsNotAcceptedException if $termsAccepted is false
|
||||||
|
* @throws FingerprintMismatchException
|
||||||
|
* @throws CartException
|
||||||
*/
|
*/
|
||||||
public function confirmPayment(string $type, array $data = []): Order
|
public function initiatePayment(string $fingerprint, bool $termsAccepted, string $policyVersion, array $data = []): PaymentResult
|
||||||
{
|
{
|
||||||
if (! in_array($type, $this->getPaymentMethods(), true)) {
|
if (! $termsAccepted) {
|
||||||
throw new UnknownPaymentTypeException($type);
|
throw new TermsNotAcceptedException;
|
||||||
}
|
}
|
||||||
|
|
||||||
$cart = $this->cart->currentOrCreate();
|
$cart = $this->cart->currentOrCreate();
|
||||||
$fingerprint = $cart->meta['checkout_fingerprint'] ?? '';
|
$cart->checkFingerprint($fingerprint);
|
||||||
|
|
||||||
return $this->resolvePaymentDriver($type)->confirm($cart, $type, $fingerprint, $data);
|
$type = $cart->meta['payment_method'] ?? null;
|
||||||
}
|
$method = $type !== null ? $this->getPaymentMethods()->firstWhere('type', $type) : null;
|
||||||
|
|
||||||
/**
|
if ($method === null) {
|
||||||
* Resolves $type's registered PaymentDriver, or null if $type has no
|
throw new UnknownPaymentTypeException((string) $type);
|
||||||
* 'payment_driver' registered in config('lunar.payments.types.<type>')
|
}
|
||||||
* at all — deliberately non-throwing so getPaymentMethods() can filter
|
|
||||||
* unresolvable types silently rather than treating "not registered"
|
|
||||||
* as an error condition when just checking availability.
|
|
||||||
*/
|
|
||||||
private function resolvePaymentDriver(string $type): ?PaymentDriver
|
|
||||||
{
|
|
||||||
$driverClass = config("lunar.payments.types.{$type}.payment_driver");
|
|
||||||
|
|
||||||
return $driverClass ? app($driverClass) : null;
|
$order = $cart->createOrder();
|
||||||
|
|
||||||
|
$order->meta = [
|
||||||
|
...($order->meta?->toArray() ?? []),
|
||||||
|
'payment_method' => $type,
|
||||||
|
'terms_accepted' => true,
|
||||||
|
'terms_accepted_at' => now()->toIso8601String(),
|
||||||
|
'terms_accepted_policy_version' => $policyVersion,
|
||||||
|
];
|
||||||
|
$order->save();
|
||||||
|
|
||||||
|
$driver = $this->paymentDrivers->resolve($method->driver);
|
||||||
|
$context = ['cart_id' => $cart->id, 'order_id' => $order->id];
|
||||||
|
|
||||||
|
return $method->capture_mode === 'authorize'
|
||||||
|
? $driver->authorize($type, $order->total, $data, $context)
|
||||||
|
: $driver->pay($type, $order->total, $data, $context);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -284,35 +284,38 @@ class InstallLunarCommand extends Command
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Per-type skip-if-exists, same idempotent convention as
|
* A single, deliberately opinionated starter row on fresh install —
|
||||||
* seedStorefrontLabels() — a type already present (including one an
|
* `PaymentMethod` is now fully admin-creatable/deletable (see
|
||||||
* admin has since edited via the Filament Payment Methods resource) is
|
* docs/payments.md), so this is no longer "seed every config-defined
|
||||||
* left untouched. Safe to re-run after a new payment type is added to
|
* type," it's "give a fresh store one reasonable payment method to
|
||||||
* config('lunar.payments.types') (e.g. installing a Stripe/Nexi
|
* start from instead of zero." Every value here is a plain literal in
|
||||||
* package), which is the whole reason this isn't a one-time-only seed.
|
* THIS command, not sourced from config or PaymentDriverRegistry — a
|
||||||
|
* driver has no business carrying opinions about what its captured
|
||||||
|
* order status should be called; that's a merchant decision.
|
||||||
*
|
*
|
||||||
* Seeded disabled — a newly-seeded row (whether from this store's
|
* Skip-if-exists on `type`, same idempotent convention as
|
||||||
* initial install, or a payment provider package installed later)
|
* seedStorefrontLabels() — an admin who has since edited or deleted
|
||||||
* shouldn't go live for shoppers before staff have actually reviewed
|
* this row (via the Filament Payment Methods resource) is left alone;
|
||||||
* it (real credentials configured, a fee set, etc.) and turned it on
|
* re-running lunar:install never recreates a deleted starter row.
|
||||||
* via the Payment Methods resource. See CheckoutService::
|
*
|
||||||
* getPaymentMethods(), which only offers a type once both 'enabled'
|
* Seeded disabled — shouldn't go live for shoppers before staff have
|
||||||
* here and its driver's own isConfigured() check pass.
|
* actually reviewed it and turned it on via the Payment Methods
|
||||||
|
* resource. See CheckoutService::getPaymentMethods().
|
||||||
*/
|
*/
|
||||||
private function seedPaymentMethods(): void
|
private function seedPaymentMethods(): void
|
||||||
{
|
{
|
||||||
$existingTypes = PaymentMethod::pluck('type');
|
if (PaymentMethod::where('type', 'cash-on-delivery')->exists()) {
|
||||||
|
return;
|
||||||
foreach (array_keys(config('lunar.payments.types', [])) as $type) {
|
|
||||||
if ($existingTypes->contains($type)) {
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
|
|
||||||
PaymentMethod::create([
|
|
||||||
'type' => $type,
|
|
||||||
'enabled' => false,
|
|
||||||
'data' => [],
|
|
||||||
]);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
PaymentMethod::create([
|
||||||
|
'type' => 'cash-on-delivery',
|
||||||
|
'name' => 'Cash on Delivery',
|
||||||
|
'driver' => 'cash-on-delivery',
|
||||||
|
'capture_mode' => 'pay',
|
||||||
|
'position' => 0,
|
||||||
|
'enabled' => false,
|
||||||
|
'data' => [],
|
||||||
|
]);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,52 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Command;
|
||||||
|
|
||||||
|
use Illuminate\Console\Command;
|
||||||
|
use Modules\Core\Payment\Models\PaymentMethod;
|
||||||
|
use Modules\Core\Payment\Services\PaymentDriverRegistry;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Reconciles every Modules\Core\Payment\Models\PaymentMethod row's `driver`
|
||||||
|
* column against PaymentDriverRegistry — the registry only knows "which
|
||||||
|
* driver classes exist THIS deploy," and only at the moment something
|
||||||
|
* calls resolve(); nothing else notices a driver disappearing (a package
|
||||||
|
* removed, a custom Registry::register() call deleted) on its own. Meant
|
||||||
|
* to run unconditionally on every container start/deploy (alongside
|
||||||
|
* `migrate`), not on a schedule — "did the set of registered drivers
|
||||||
|
* change" is a deploy-time event, cheap enough to check every single time
|
||||||
|
* regardless of whether anything actually changed. See docs/payments.md.
|
||||||
|
*
|
||||||
|
* Sets/clears `driver_missing_at` — deliberately NOT the `enabled` column,
|
||||||
|
* so an admin's own manual toggle is never confused with "the driver
|
||||||
|
* vanished," and a driver that comes back in a later deploy auto-clears
|
||||||
|
* this with no admin action needed.
|
||||||
|
*/
|
||||||
|
class SyncPaymentDriversCommand extends Command
|
||||||
|
{
|
||||||
|
protected $signature = 'boboko:payment:sync-drivers';
|
||||||
|
|
||||||
|
protected $description = 'Flag PaymentMethod rows whose driver no longer resolves via the registry, and clear the flag for ones that do again';
|
||||||
|
|
||||||
|
public function handle(PaymentDriverRegistry $registry): int
|
||||||
|
{
|
||||||
|
$missing = 0;
|
||||||
|
$restored = 0;
|
||||||
|
|
||||||
|
PaymentMethod::query()->each(function (PaymentMethod $method) use ($registry, &$missing, &$restored) {
|
||||||
|
$resolves = $method->driver !== null && $registry->resolve($method->driver) !== null;
|
||||||
|
|
||||||
|
if (! $resolves && $method->driver_missing_at === null) {
|
||||||
|
$method->update(['driver_missing_at' => now()]);
|
||||||
|
$missing++;
|
||||||
|
} elseif ($resolves && $method->driver_missing_at !== null) {
|
||||||
|
$method->update(['driver_missing_at' => null]);
|
||||||
|
$restored++;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
$this->components->info("Payment driver sync complete: {$missing} newly flagged, {$restored} restored.");
|
||||||
|
|
||||||
|
return self::SUCCESS;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,67 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Command;
|
||||||
|
|
||||||
|
use Illuminate\Console\Command;
|
||||||
|
use Laravel\Scout\EngineManager;
|
||||||
|
use Laravel\Scout\Engines\MeilisearchEngine;
|
||||||
|
use Lunar\Models\Product;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* lunarphp/meilisearch's own `lunar:meilisearch:setup` only pushes
|
||||||
|
* filterableAttributes/sortableAttributes (see MeilisearchSetup::handle())
|
||||||
|
* — it has no notion of typo tolerance or prefix search, and Meilisearch's
|
||||||
|
* defaults for both are loose enough to produce bad matches on short Greek
|
||||||
|
* words. Confirmed via showMatchesPosition that a query for "Κάπτεν" was
|
||||||
|
* matching "κανένας" purely through prefixSearch's default 'indexingTime'
|
||||||
|
* behavior (their edit distance is far past anything typo tolerance would
|
||||||
|
* bridge) — fixed by disabling prefix search below, verified afterward with
|
||||||
|
* "Super"/"Superheroes"-style prefix probes returning no results for a
|
||||||
|
* partial word. minWordSizeForTypos is tightened defensively alongside it
|
||||||
|
* so short words in general get less typo-tolerant fuzzing, even though a
|
||||||
|
* separate short-word collision case ("Κάπτεν" vs "κάποτε", high letter
|
||||||
|
* overlap despite real edit distance) persisted after both settings were
|
||||||
|
* confirmed live and wasn't fully root-caused — treated as a known,
|
||||||
|
* narrow edge case rather than a blocker. Run this after
|
||||||
|
* `lunar:meilisearch:setup`, whenever Product's index needs
|
||||||
|
* (re)provisioning.
|
||||||
|
*
|
||||||
|
* Disabling prefix search here is a deliberate tradeoff: it also turns off
|
||||||
|
* legitimate partial-word matching (typing "car" matching "cart" before
|
||||||
|
* you finish the word) — useful for a future autocomplete/search-as-you-
|
||||||
|
* type UI. If that's built later, re-enable prefixSearch deliberately then,
|
||||||
|
* informed by real UX needs, rather than leaving it on by accident today.
|
||||||
|
*/
|
||||||
|
class TuneProductSearchCommand extends Command
|
||||||
|
{
|
||||||
|
protected $signature = 'lunar:meilisearch:tune-product-search';
|
||||||
|
|
||||||
|
protected $description = 'Tighten typo-tolerance and disable prefix search on the product search index';
|
||||||
|
|
||||||
|
public function handle(EngineManager $engineManager): void
|
||||||
|
{
|
||||||
|
/** @var MeilisearchEngine $engine */
|
||||||
|
$engine = $engineManager->createMeilisearchDriver();
|
||||||
|
|
||||||
|
$index = $engine->getIndex((new Product)->searchableAs());
|
||||||
|
|
||||||
|
$this->components->info('Updating typo tolerance for product search...');
|
||||||
|
|
||||||
|
$task = $index->updateTypoTolerance([
|
||||||
|
'minWordSizeForTypos' => [
|
||||||
|
'oneTypo' => 8,
|
||||||
|
'twoTypos' => 12,
|
||||||
|
],
|
||||||
|
]);
|
||||||
|
|
||||||
|
$engine->waitForTask($task['taskUid']);
|
||||||
|
|
||||||
|
$this->components->info('Disabling prefix search for product search...');
|
||||||
|
|
||||||
|
$task = $index->updatePrefixSearch('disabled');
|
||||||
|
|
||||||
|
$engine->waitForTask($task['taskUid']);
|
||||||
|
|
||||||
|
$this->components->info('Product search index tuned.');
|
||||||
|
}
|
||||||
|
}
|
||||||
+13
-4
@@ -3,6 +3,7 @@
|
|||||||
namespace Modules\Core;
|
namespace Modules\Core;
|
||||||
|
|
||||||
use Lunar\Admin\Filament\Resources\OrderResource\Pages\ManageOrder;
|
use Lunar\Admin\Filament\Resources\OrderResource\Pages\ManageOrder;
|
||||||
|
use Lunar\Admin\Filament\Resources\OrderResource\Pages\Components\OrderItemsTable;
|
||||||
use Filament\Contracts\Plugin;
|
use Filament\Contracts\Plugin;
|
||||||
use Filament\Panel;
|
use Filament\Panel;
|
||||||
use Illuminate\Database\Eloquent\Relations\HasMany;
|
use Illuminate\Database\Eloquent\Relations\HasMany;
|
||||||
@@ -25,13 +26,19 @@ use Modules\Core\Cart\Filament\Resources\CartResource;
|
|||||||
use Modules\Core\Catalog\Filament\Extensions\ProductOptionResourceExtension;
|
use Modules\Core\Catalog\Filament\Extensions\ProductOptionResourceExtension;
|
||||||
use Modules\Core\Catalog\Filament\Extensions\ValuesRelationManagerExtension;
|
use Modules\Core\Catalog\Filament\Extensions\ValuesRelationManagerExtension;
|
||||||
use Modules\Core\Localization\Filament\Resources\LanguageLineResource;
|
use Modules\Core\Localization\Filament\Resources\LanguageLineResource;
|
||||||
|
use Modules\Core\Order\Filament\Extensions\OrderItemsTableExtension;
|
||||||
|
use Modules\Core\Order\Filament\Extensions\OrderPaymentMethodSummaryExtension;
|
||||||
|
use Modules\Core\Order\Filament\Extensions\OrderRefundActionsExtension;
|
||||||
|
use Modules\Core\Order\Filament\Extensions\OrderTransactionsExtension;
|
||||||
use Modules\Core\Payment\Filament\Resources\PaymentMethodResource;
|
use Modules\Core\Payment\Filament\Resources\PaymentMethodResource;
|
||||||
use Modules\Core\Review\Filament\Extensions\ProductResourceExtension;
|
use Modules\Core\Review\Filament\Extensions\ProductResourceExtension;
|
||||||
use Modules\Core\Review\Models\ProductReview;
|
use Modules\Core\Review\Models\ProductReview;
|
||||||
|
use Modules\Core\Shipping\Extensions\OrderShipmentsExtension;
|
||||||
use Modules\Core\Shipping\Extensions\OrderViewExtension;
|
use Modules\Core\Shipping\Extensions\OrderViewExtension;
|
||||||
use Modules\Core\Shipping\Extensions\ShippingMethodListExtension;
|
use Modules\Core\Shipping\Extensions\ShippingMethodListExtension;
|
||||||
use Modules\Core\Shipping\Extensions\ShippingMethodResourceExtension;
|
use Modules\Core\Shipping\Extensions\ShippingMethodResourceExtension;
|
||||||
use Modules\Core\Shipping\Filament\Pages\ManagePickupManifests;
|
use Modules\Core\Shipping\Filament\Resources\ManifestResource;
|
||||||
|
use Modules\Core\Shipping\Filament\Resources\ShipmentResource;
|
||||||
|
|
||||||
class CorePlugin implements Plugin
|
class CorePlugin implements Plugin
|
||||||
{
|
{
|
||||||
@@ -51,9 +58,10 @@ class CorePlugin implements Plugin
|
|||||||
LanguageLineResource::class,
|
LanguageLineResource::class,
|
||||||
CartResource::class,
|
CartResource::class,
|
||||||
PaymentMethodResource::class,
|
PaymentMethodResource::class,
|
||||||
|
ShipmentResource::class,
|
||||||
|
ManifestResource::class,
|
||||||
])
|
])
|
||||||
->plugin(ShippingPlugin::make())
|
->plugin(ShippingPlugin::make());
|
||||||
->pages([ManagePickupManifests::class]);
|
|
||||||
|
|
||||||
LunarPanel::extensions([
|
LunarPanel::extensions([
|
||||||
StaffResource::class => StaffResourceExtension::class,
|
StaffResource::class => StaffResourceExtension::class,
|
||||||
@@ -62,7 +70,8 @@ class CorePlugin implements Plugin
|
|||||||
ValuesRelationManager::class => ValuesRelationManagerExtension::class,
|
ValuesRelationManager::class => ValuesRelationManagerExtension::class,
|
||||||
ShippingMethodResource::class => ShippingMethodResourceExtension::class,
|
ShippingMethodResource::class => ShippingMethodResourceExtension::class,
|
||||||
ListShippingMethod::class => ShippingMethodListExtension::class,
|
ListShippingMethod::class => ShippingMethodListExtension::class,
|
||||||
ManageOrder::class => OrderViewExtension::class,
|
ManageOrder::class => [OrderViewExtension::class, OrderRefundActionsExtension::class, OrderTransactionsExtension::class, OrderPaymentMethodSummaryExtension::class, OrderShipmentsExtension::class],
|
||||||
|
OrderItemsTable::class => OrderItemsTableExtension::class,
|
||||||
]);
|
]);
|
||||||
|
|
||||||
Product::macro('reviews', function (): HasMany {
|
Product::macro('reviews', function (): HasMany {
|
||||||
|
|||||||
@@ -0,0 +1,22 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Modules\Core\Customer\Services\CustomerAccountService::
|
||||||
|
* createAddress(). $causer is carried explicitly (unlike e.g.
|
||||||
|
* Modules\Core\Payment\Events\PaymentMethodCreated, which is always
|
||||||
|
* staff-caused implicitly) because this write happens on the `web`
|
||||||
|
* guard, not `staff` — a listener logging this needs to know who to
|
||||||
|
* attribute it to without guessing a guard.
|
||||||
|
*/
|
||||||
|
class CustomerAddressCreated
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly Address $address,
|
||||||
|
public readonly Authenticatable $causer,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
|
||||||
|
class CustomerAddressDeleted
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $address Snapshot of the deleted
|
||||||
|
* row — already gone from the database by dispatch time.
|
||||||
|
*/
|
||||||
|
public function __construct(
|
||||||
|
public readonly array $address,
|
||||||
|
public readonly Authenticatable $causer,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
|
||||||
|
class CustomerAddressUpdated
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $old Snapshot of the changed
|
||||||
|
* attributes before the update.
|
||||||
|
*/
|
||||||
|
public function __construct(
|
||||||
|
public readonly Address $address,
|
||||||
|
public readonly array $old,
|
||||||
|
public readonly Authenticatable $causer,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Modules\Core\Customer\Models\Customer;
|
||||||
|
|
||||||
|
class CustomerProfileUpdated
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $old Snapshot of the changed
|
||||||
|
* attributes before the update.
|
||||||
|
*/
|
||||||
|
public function __construct(
|
||||||
|
public readonly Customer $customer,
|
||||||
|
public readonly array $old,
|
||||||
|
public readonly Authenticatable $causer,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Exceptions;
|
||||||
|
|
||||||
|
use RuntimeException;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Thrown by Modules\Core\Customer\Services\CustomerAccountService when an
|
||||||
|
* address id doesn't belong to the customer making the request — never
|
||||||
|
* a plain 404/ModelNotFoundException, so a storefront can't probe for
|
||||||
|
* another customer's address ids by trying sequential ones and reading
|
||||||
|
* the response shape.
|
||||||
|
*/
|
||||||
|
class AddressNotFoundException extends RuntimeException
|
||||||
|
{
|
||||||
|
public function __construct()
|
||||||
|
{
|
||||||
|
parent::__construct('Address not found.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Exceptions;
|
||||||
|
|
||||||
|
use RuntimeException;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Thrown by Modules\Core\Customer\Services\CustomerAccountService when an
|
||||||
|
* order id doesn't belong to the customer making the request (or isn't
|
||||||
|
* placed yet) — never a plain 404/ModelNotFoundException, so a
|
||||||
|
* storefront can't probe for another customer's order ids.
|
||||||
|
*/
|
||||||
|
class OrderNotFoundException extends RuntimeException
|
||||||
|
{
|
||||||
|
public function __construct()
|
||||||
|
{
|
||||||
|
parent::__construct('Order not found.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,61 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Listeners;
|
||||||
|
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressCreated;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressDeleted;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressUpdated;
|
||||||
|
use Modules\Core\Customer\Events\CustomerProfileUpdated;
|
||||||
|
use Modules\Core\Logging\ActivityLogService;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Same pattern as Payment\Listeners\LogPaymentMethodActivity — routes
|
||||||
|
* Modules\Core\Customer\Services\CustomerAccountService's own events
|
||||||
|
* through the shared Logging\ActivityLogService, giving every
|
||||||
|
* shopper-initiated address/profile change an audit trail (previously
|
||||||
|
* none existed at all for account self-service writes). $causer is
|
||||||
|
* passed through explicitly on every call, since these events are
|
||||||
|
* `web`-guard-caused, not `staff`-guard — see ActivityLogService's own
|
||||||
|
* docblock for why that parameter exists.
|
||||||
|
*/
|
||||||
|
class LogCustomerAccountActivity
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly ActivityLogService $activityLog,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public function handleAddressCreated(CustomerAddressCreated $event): void
|
||||||
|
{
|
||||||
|
$this->activityLog->created($event->address, $event->address->getAttributes(), $event->causer);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function handleAddressUpdated(CustomerAddressUpdated $event): void
|
||||||
|
{
|
||||||
|
$this->activityLog->updated(
|
||||||
|
$event->address,
|
||||||
|
$event->old,
|
||||||
|
$event->address->only(array_keys($event->old)),
|
||||||
|
$event->causer,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function handleAddressDeleted(CustomerAddressDeleted $event): void
|
||||||
|
{
|
||||||
|
$subject = (new Address)->forceFill($event->address);
|
||||||
|
$subject->exists = true;
|
||||||
|
$subject->id = $event->address['id'];
|
||||||
|
|
||||||
|
$this->activityLog->deleted($subject, $event->address, $event->causer);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function handleProfileUpdated(CustomerProfileUpdated $event): void
|
||||||
|
{
|
||||||
|
$this->activityLog->updated(
|
||||||
|
$event->customer,
|
||||||
|
$event->old,
|
||||||
|
$event->customer->only(array_keys($event->old)),
|
||||||
|
$event->causer,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,255 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Services;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Illuminate\Pagination\LengthAwarePaginator;
|
||||||
|
use Illuminate\Support\Arr;
|
||||||
|
use Illuminate\Support\Facades\Event;
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use LogicException;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressCreated;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressDeleted;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressUpdated;
|
||||||
|
use Modules\Core\Customer\Events\CustomerProfileUpdated;
|
||||||
|
use Modules\Core\Customer\Exceptions\AddressNotFoundException;
|
||||||
|
use Modules\Core\Customer\Exceptions\OrderNotFoundException;
|
||||||
|
use Modules\Core\Customer\Models\Customer;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The storefront-facing "My Account" API — mirrors Modules\Core\Cart\
|
||||||
|
* Services\CartService's shape, one boboko-owned service a storefront
|
||||||
|
* calls, so Lunar's own Customer/Order/Address models stay an
|
||||||
|
* implementation detail. Every method is scoped to the given
|
||||||
|
* Authenticatable's own Customer::latestCustomer() (see docs/modules.md
|
||||||
|
* "Customer/User Pairing") — there is no method here that accepts a bare
|
||||||
|
* order/address id without also requiring the owning user, precisely so
|
||||||
|
* a controller built on top of this can't accidentally leak one
|
||||||
|
* customer's data to another by trusting a client-supplied id alone.
|
||||||
|
*
|
||||||
|
* $user->latestCustomer() can be null for a User that has no paired
|
||||||
|
* Customer yet (shouldn't happen via the normal OTP-login cascade — see
|
||||||
|
* Modules\Core\Auth\Events\UserCreated — but is defended against anyway,
|
||||||
|
* since nothing stops a User row existing without one, e.g. seeded data)
|
||||||
|
* — every method returns an empty/null result rather than throwing in
|
||||||
|
* that case, since "no customer paired yet" isn't a not-found error, it's
|
||||||
|
* a legitimately empty account.
|
||||||
|
*
|
||||||
|
* Address/profile writes go through an explicit column allowlist
|
||||||
|
* (WRITABLE_ADDRESS_FIELDS/WRITABLE_PROFILE_FIELDS) rather than trusting
|
||||||
|
* Lunar\Models\Address/Customer's own $guarded = [] — that flag makes
|
||||||
|
* every column mass-assignable at the model layer, including
|
||||||
|
* customer_id on addresses, so a caller passing through an unfiltered
|
||||||
|
* request array (a real risk for a storefront controller built directly
|
||||||
|
* against this service) could otherwise reassign an address to a
|
||||||
|
* different customer entirely, or overwrite created_at/id. Arr::only()
|
||||||
|
* silently drops anything not on the allowlist rather than erroring —
|
||||||
|
* this is a safety boundary, not form validation (a storefront still
|
||||||
|
* validates its own request shape before calling this).
|
||||||
|
*
|
||||||
|
* Authorization here IS the ownership scoping itself, not a separate
|
||||||
|
* layer bolted on top — there is deliberately no Laravel Policy/Gate
|
||||||
|
* class for Order/Address, since a policy is meaningless without a
|
||||||
|
* controller calling authorize() against it, and this branch is scoped
|
||||||
|
* to backend services only (no routes/controllers — see the branch's own
|
||||||
|
* commit history). Every public method below takes Authenticatable $user
|
||||||
|
* as a required first argument and resolves everything else (Order,
|
||||||
|
* Address, Customer) strictly through that user's own
|
||||||
|
* latestCustomer() — there is no method that looks anything up by a bare
|
||||||
|
* id alone. A future storefront controller cannot "forget" the
|
||||||
|
* authorization check the way it could with a separate policy class,
|
||||||
|
* because the check IS how every lookup happens; skipping it isn't an
|
||||||
|
* option the method signatures allow.
|
||||||
|
*/
|
||||||
|
class CustomerAccountService
|
||||||
|
{
|
||||||
|
private const WRITABLE_ADDRESS_FIELDS = [
|
||||||
|
'title', 'first_name', 'last_name', 'company_name',
|
||||||
|
'line_one', 'line_two', 'line_three', 'city', 'state', 'postcode',
|
||||||
|
'delivery_instructions', 'contact_email', 'contact_phone',
|
||||||
|
'country_id', 'shipping_default', 'billing_default',
|
||||||
|
];
|
||||||
|
|
||||||
|
private const WRITABLE_PROFILE_FIELDS = [
|
||||||
|
'title', 'first_name', 'last_name', 'company_name', 'vat_no',
|
||||||
|
];
|
||||||
|
|
||||||
|
public function customer(Authenticatable $user): ?Customer
|
||||||
|
{
|
||||||
|
/** @var Customer|null */
|
||||||
|
return $user->latestCustomer();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Placed orders only (placed_at IS NOT NULL) — a draft/abandoned
|
||||||
|
* order with no placed_at is checkout-in-progress state, not
|
||||||
|
* something that belongs in order history.
|
||||||
|
*/
|
||||||
|
public function orders(Authenticatable $user, int $perPage = 15): LengthAwarePaginator
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
if (! $customer) {
|
||||||
|
return new LengthAwarePaginator([], 0, $perPage);
|
||||||
|
}
|
||||||
|
|
||||||
|
return $customer->orders()
|
||||||
|
->whereNotNull('placed_at')
|
||||||
|
->latest('placed_at')
|
||||||
|
->paginate($perPage);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws OrderNotFoundException if $orderId doesn't belong to this
|
||||||
|
* customer, or belongs to a draft (never placed) order
|
||||||
|
*/
|
||||||
|
public function order(Authenticatable $user, int $orderId): Order
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
$order = $customer
|
||||||
|
?->orders()
|
||||||
|
->whereNotNull('placed_at')
|
||||||
|
->with(['lines', 'shippingAddress', 'billingAddress', 'transactions', 'shipments'])
|
||||||
|
->find($orderId);
|
||||||
|
|
||||||
|
if (! $order) {
|
||||||
|
throw new OrderNotFoundException;
|
||||||
|
}
|
||||||
|
|
||||||
|
return $order;
|
||||||
|
}
|
||||||
|
|
||||||
|
public function addresses(Authenticatable $user): iterable
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
return $customer?->addresses ?? collect();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $data Any key not in
|
||||||
|
* WRITABLE_ADDRESS_FIELDS is silently dropped — see this class's
|
||||||
|
* own docblock.
|
||||||
|
*/
|
||||||
|
public function createAddress(Authenticatable $user, array $data): Address
|
||||||
|
{
|
||||||
|
$customer = $this->customerOrFail($user);
|
||||||
|
|
||||||
|
$address = $customer->addresses()->create(Arr::only($data, self::WRITABLE_ADDRESS_FIELDS));
|
||||||
|
|
||||||
|
$this->enforceSingleDefault($customer, $address);
|
||||||
|
$address->refresh();
|
||||||
|
|
||||||
|
Event::dispatch(new CustomerAddressCreated($address, $user));
|
||||||
|
|
||||||
|
return $address;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws AddressNotFoundException if $addressId doesn't belong to
|
||||||
|
* this customer
|
||||||
|
*/
|
||||||
|
public function updateAddress(Authenticatable $user, int $addressId, array $data): Address
|
||||||
|
{
|
||||||
|
$address = $this->ownedAddress($user, $addressId);
|
||||||
|
$old = $address->only(array_keys(Arr::only($data, self::WRITABLE_ADDRESS_FIELDS)));
|
||||||
|
|
||||||
|
$address->update(Arr::only($data, self::WRITABLE_ADDRESS_FIELDS));
|
||||||
|
|
||||||
|
$this->enforceSingleDefault($address->customer, $address);
|
||||||
|
$address->refresh();
|
||||||
|
|
||||||
|
Event::dispatch(new CustomerAddressUpdated($address, $old, $user));
|
||||||
|
|
||||||
|
return $address;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws AddressNotFoundException if $addressId doesn't belong to
|
||||||
|
* this customer
|
||||||
|
*/
|
||||||
|
public function deleteAddress(Authenticatable $user, int $addressId): void
|
||||||
|
{
|
||||||
|
$address = $this->ownedAddress($user, $addressId);
|
||||||
|
$snapshot = $address->getAttributes();
|
||||||
|
|
||||||
|
$address->delete();
|
||||||
|
|
||||||
|
Event::dispatch(new CustomerAddressDeleted($snapshot, $user));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Lunar has no built-in action enforcing "at most one shipping
|
||||||
|
* default / one billing default per customer" — a raw update() could
|
||||||
|
* otherwise leave two addresses both flagged shipping_default. Runs
|
||||||
|
* after every create/update, unconditionally (cheap — at most two
|
||||||
|
* single-row UPDATEs, only fired when the just-written address
|
||||||
|
* itself is a default), clearing the flag on every OTHER address of
|
||||||
|
* the same customer.
|
||||||
|
*/
|
||||||
|
private function enforceSingleDefault(Customer $customer, Address $address): void
|
||||||
|
{
|
||||||
|
if ($address->shipping_default) {
|
||||||
|
$customer->addresses()->where('id', '!=', $address->id)->update(['shipping_default' => false]);
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($address->billing_default) {
|
||||||
|
$customer->addresses()->where('id', '!=', $address->id)->update(['billing_default' => false]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws AddressNotFoundException if $addressId doesn't belong to
|
||||||
|
* this customer
|
||||||
|
*/
|
||||||
|
private function ownedAddress(Authenticatable $user, int $addressId): Address
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
$address = $customer?->addresses()->find($addressId);
|
||||||
|
|
||||||
|
if (! $address) {
|
||||||
|
throw new AddressNotFoundException;
|
||||||
|
}
|
||||||
|
|
||||||
|
return $address;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $data Any key not in
|
||||||
|
* WRITABLE_PROFILE_FIELDS is silently dropped — see this class's
|
||||||
|
* own docblock.
|
||||||
|
*/
|
||||||
|
public function updateProfile(Authenticatable $user, array $data): Customer
|
||||||
|
{
|
||||||
|
$customer = $this->customerOrFail($user);
|
||||||
|
$old = $customer->only(array_keys(Arr::only($data, self::WRITABLE_PROFILE_FIELDS)));
|
||||||
|
|
||||||
|
$customer->update(Arr::only($data, self::WRITABLE_PROFILE_FIELDS));
|
||||||
|
$customer->refresh();
|
||||||
|
|
||||||
|
Event::dispatch(new CustomerProfileUpdated($customer, $old, $user));
|
||||||
|
|
||||||
|
return $customer;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws LogicException if $user has no paired Customer at all —
|
||||||
|
* distinct from AddressNotFoundException/OrderNotFoundException
|
||||||
|
* (which mean "this id isn't yours"), this means the account
|
||||||
|
* itself is in an invariant-violating state the normal OTP-login
|
||||||
|
* cascade should never produce.
|
||||||
|
*/
|
||||||
|
private function customerOrFail(Authenticatable $user): Customer
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
if (! $customer) {
|
||||||
|
throw new LogicException('This user has no paired Customer record.');
|
||||||
|
}
|
||||||
|
|
||||||
|
return $customer;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -24,6 +24,7 @@ class StorefrontLabels
|
|||||||
'nav.account' => ['en' => 'Account', 'el' => 'Λογαριασμός'],
|
'nav.account' => ['en' => 'Account', 'el' => 'Λογαριασμός'],
|
||||||
'nav.back' => ['en' => 'Back', 'el' => 'Πίσω'],
|
'nav.back' => ['en' => 'Back', 'el' => 'Πίσω'],
|
||||||
'nav.contact' => ['en' => 'Contact', 'el' => 'Επικοινωνία'],
|
'nav.contact' => ['en' => 'Contact', 'el' => 'Επικοινωνία'],
|
||||||
|
'nav.close' => ['en' => 'Close', 'el' => 'Κλείσιμο'],
|
||||||
'cart.empty' => ['en' => 'Your cart is empty', 'el' => 'Το καλάθι σας είναι άδειο'],
|
'cart.empty' => ['en' => 'Your cart is empty', 'el' => 'Το καλάθι σας είναι άδειο'],
|
||||||
'cart.checkout' => ['en' => 'Checkout', 'el' => 'Ολοκλήρωση Παραγγελίας'],
|
'cart.checkout' => ['en' => 'Checkout', 'el' => 'Ολοκλήρωση Παραγγελίας'],
|
||||||
'cart.total' => ['en' => 'Total', 'el' => 'Σύνολο'],
|
'cart.total' => ['en' => 'Total', 'el' => 'Σύνολο'],
|
||||||
@@ -38,6 +39,7 @@ class StorefrontLabels
|
|||||||
'auth.login' => ['en' => 'Log In', 'el' => 'Σύνδεση'],
|
'auth.login' => ['en' => 'Log In', 'el' => 'Σύνδεση'],
|
||||||
'auth.logout' => ['en' => 'Log Out', 'el' => 'Αποσύνδεση'],
|
'auth.logout' => ['en' => 'Log Out', 'el' => 'Αποσύνδεση'],
|
||||||
'search.placeholder' => ['en' => 'Search products…', 'el' => 'Αναζήτηση προϊόντων…'],
|
'search.placeholder' => ['en' => 'Search products…', 'el' => 'Αναζήτηση προϊόντων…'],
|
||||||
|
'search.results_for' => ['en' => 'Search results for ', 'el' => 'Αποτελέσματα αναζήτησης για '],
|
||||||
'customer_reviews' => [
|
'customer_reviews' => [
|
||||||
'en' => '{0} No customer reviews|{1} :count customer review|[2,*] :count customer reviews',
|
'en' => '{0} No customer reviews|{1} :count customer review|[2,*] :count customer reviews',
|
||||||
'el' => '{0} Καμία αξιολόγηση πελάτη|{1} :count αξιολόγηση πελάτη|[2,*] :count αξιολογήσεις πελατών',
|
'el' => '{0} Καμία αξιολόγηση πελάτη|{1} :count αξιολόγηση πελάτη|[2,*] :count αξιολογήσεις πελατών',
|
||||||
@@ -66,6 +68,7 @@ class StorefrontLabels
|
|||||||
'en' => '{0} No products found|{1} Showing :first–:last of :total result|[2,*] Showing :first–:last of :total results',
|
'en' => '{0} No products found|{1} Showing :first–:last of :total result|[2,*] Showing :first–:last of :total results',
|
||||||
'el' => '{0} Δεν βρέθηκαν προϊόντα|{1} Εμφάνιση :first–:last από :total αποτέλεσμα|[2,*] Εμφάνιση :first–:last από :total αποτελέσματα',
|
'el' => '{0} Δεν βρέθηκαν προϊόντα|{1} Εμφάνιση :first–:last από :total αποτέλεσμα|[2,*] Εμφάνιση :first–:last από :total αποτελέσματα',
|
||||||
],
|
],
|
||||||
|
'shop.all_products' => ['en' => 'All Products', 'el' => 'Όλα τα Προϊόντα'],
|
||||||
'shop.sort_label' => ['en' => 'Sort products', 'el' => 'Ταξινόμηση προϊόντων'],
|
'shop.sort_label' => ['en' => 'Sort products', 'el' => 'Ταξινόμηση προϊόντων'],
|
||||||
'shop.sort_default' => ['en' => 'Default sorting', 'el' => 'Προεπιλεγμένη ταξινόμηση'],
|
'shop.sort_default' => ['en' => 'Default sorting', 'el' => 'Προεπιλεγμένη ταξινόμηση'],
|
||||||
'shop.sort_popularity' => ['en' => 'Popularity', 'el' => 'Δημοφιλή'],
|
'shop.sort_popularity' => ['en' => 'Popularity', 'el' => 'Δημοφιλή'],
|
||||||
|
|||||||
@@ -2,25 +2,31 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Logging;
|
namespace Modules\Core\Logging;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
use Illuminate\Database\Eloquent\Model;
|
use Illuminate\Database\Eloquent\Model;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Thin wrapper around Spatie Activity Log that standardises the log channel,
|
* Thin wrapper around Spatie Activity Log that standardises the log channel,
|
||||||
* actor (authenticated staff member), and property shape for all domain events.
|
* actor, and property shape for all domain events.
|
||||||
*
|
*
|
||||||
* All logs are written to the 'lunar' channel. The subject is always an
|
* All logs are written to the 'lunar' channel. The subject is always an
|
||||||
* Eloquent model, and the actor is resolved from the 'staff' guard at call time.
|
* Eloquent model. $causer defaults to the 'staff' guard's current user —
|
||||||
|
* every existing caller of this class is admin-side — but can be passed
|
||||||
|
* explicitly for a non-staff actor (e.g. a customer editing their own
|
||||||
|
* address on the `web` guard — see Modules\Core\Customer\Services\
|
||||||
|
* CustomerAccountService, which passes the acting User rather than
|
||||||
|
* relying on this default resolving to null for a web-guard session).
|
||||||
*/
|
*/
|
||||||
class ActivityLogService
|
class ActivityLogService
|
||||||
{
|
{
|
||||||
/**
|
/**
|
||||||
* Log a creation event. $attributes describes the initial state.
|
* Log a creation event. $attributes describes the initial state.
|
||||||
*/
|
*/
|
||||||
public function created(Model $subject, array $attributes): void
|
public function created(Model $subject, array $attributes, ?Authenticatable $causer = null): void
|
||||||
{
|
{
|
||||||
activity('lunar')
|
activity('lunar')
|
||||||
->performedOn($subject)
|
->performedOn($subject)
|
||||||
->causedBy(auth('staff')->user())
|
->causedBy($causer ?? auth('staff')->user())
|
||||||
->withProperties(['attributes' => $attributes])
|
->withProperties(['attributes' => $attributes])
|
||||||
->log('created');
|
->log('created');
|
||||||
}
|
}
|
||||||
@@ -28,11 +34,11 @@ class ActivityLogService
|
|||||||
/**
|
/**
|
||||||
* Log an update event. $old holds the previous values, $attributes the new ones.
|
* Log an update event. $old holds the previous values, $attributes the new ones.
|
||||||
*/
|
*/
|
||||||
public function updated(Model $subject, array $old, array $attributes): void
|
public function updated(Model $subject, array $old, array $attributes, ?Authenticatable $causer = null): void
|
||||||
{
|
{
|
||||||
activity('lunar')
|
activity('lunar')
|
||||||
->performedOn($subject)
|
->performedOn($subject)
|
||||||
->causedBy(auth('staff')->user())
|
->causedBy($causer ?? auth('staff')->user())
|
||||||
->withProperties(['old' => $old, 'attributes' => $attributes])
|
->withProperties(['old' => $old, 'attributes' => $attributes])
|
||||||
->log('updated');
|
->log('updated');
|
||||||
}
|
}
|
||||||
@@ -40,11 +46,11 @@ class ActivityLogService
|
|||||||
/**
|
/**
|
||||||
* Log a failed operation. $attributes provides context (e.g. error message, service).
|
* Log a failed operation. $attributes provides context (e.g. error message, service).
|
||||||
*/
|
*/
|
||||||
public function failed(Model $subject, array $attributes): void
|
public function failed(Model $subject, array $attributes, ?Authenticatable $causer = null): void
|
||||||
{
|
{
|
||||||
activity('lunar')
|
activity('lunar')
|
||||||
->performedOn($subject)
|
->performedOn($subject)
|
||||||
->causedBy(auth('staff')->user())
|
->causedBy($causer ?? auth('staff')->user())
|
||||||
->withProperties(['attributes' => $attributes])
|
->withProperties(['attributes' => $attributes])
|
||||||
->log('failed');
|
->log('failed');
|
||||||
}
|
}
|
||||||
@@ -52,11 +58,11 @@ class ActivityLogService
|
|||||||
/**
|
/**
|
||||||
* Log a deletion event. $attributes provides context (e.g. reason, name).
|
* Log a deletion event. $attributes provides context (e.g. reason, name).
|
||||||
*/
|
*/
|
||||||
public function deleted(Model $subject, array $attributes): void
|
public function deleted(Model $subject, array $attributes, ?Authenticatable $causer = null): void
|
||||||
{
|
{
|
||||||
activity('lunar')
|
activity('lunar')
|
||||||
->performedOn($subject)
|
->performedOn($subject)
|
||||||
->causedBy(auth('staff')->user())
|
->causedBy($causer ?? auth('staff')->user())
|
||||||
->withProperties(['attributes' => $attributes])
|
->withProperties(['attributes' => $attributes])
|
||||||
->log('deleted');
|
->log('deleted');
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -16,10 +16,16 @@ class ProductOptionResolver
|
|||||||
// the same option instead of creating a near-duplicate.
|
// the same option instead of creating a near-duplicate.
|
||||||
$handle = Str::slug($name) ?: 'option';
|
$handle = Str::slug($name) ?: 'option';
|
||||||
|
|
||||||
|
// 'label' must be set even though nothing here reads it back — a null
|
||||||
|
// label crashes Lunar's own ProductOptionIndexer::toSearchableArray()
|
||||||
|
// (foreach (null as ...)) the moment this option gets reindexed, since
|
||||||
|
// it assumes every ProductOption always has one. Same value as 'name'
|
||||||
|
// is a reasonable default; Shopify's CSV has no separate "label" concept.
|
||||||
return ProductOption::query()->firstOrCreate(
|
return ProductOption::query()->firstOrCreate(
|
||||||
['handle' => $handle],
|
['handle' => $handle],
|
||||||
[
|
[
|
||||||
'name' => [DefaultLocale::code() => $name],
|
'name' => [DefaultLocale::code() => $name],
|
||||||
|
'label' => [DefaultLocale::code() => $name],
|
||||||
'shared' => true,
|
'shared' => true,
|
||||||
],
|
],
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -25,6 +25,7 @@ use Modules\Core\MigrateImport\Shopify\Resolvers\ProductOptionResolver;
|
|||||||
use Modules\Core\MigrateImport\Shopify\Resolvers\ProductTypeResolver;
|
use Modules\Core\MigrateImport\Shopify\Resolvers\ProductTypeResolver;
|
||||||
use Modules\Core\MigrateImport\Shopify\Resolvers\TagResolver;
|
use Modules\Core\MigrateImport\Shopify\Resolvers\TagResolver;
|
||||||
use Modules\Core\MigrateImport\Shopify\Resolvers\TaxClassResolver;
|
use Modules\Core\MigrateImport\Shopify\Resolvers\TaxClassResolver;
|
||||||
|
use Spatie\MediaLibrary\MediaCollections\Models\Media;
|
||||||
|
|
||||||
class ShopifyExportImporter implements Importer
|
class ShopifyExportImporter implements Importer
|
||||||
{
|
{
|
||||||
@@ -113,7 +114,7 @@ class ShopifyExportImporter implements Importer
|
|||||||
$options = $this->attachOptions($product, $row);
|
$options = $this->attachOptions($product, $row);
|
||||||
|
|
||||||
foreach ($group->variantRows as $index => $variantRow) {
|
foreach ($group->variantRows as $index => $variantRow) {
|
||||||
$this->importVariant($product, $group->handle, $index, $variantRow, $taxClass, $currency, $options);
|
$this->importVariant($product, $group->handle, $index, $variantRow, $taxClass, $currency, $options, $imagesPath);
|
||||||
}
|
}
|
||||||
|
|
||||||
foreach ($group->imageRows as $index => $imageRow) {
|
foreach ($group->imageRows as $index => $imageRow) {
|
||||||
@@ -151,6 +152,7 @@ class ShopifyExportImporter implements Importer
|
|||||||
TaxClass $taxClass,
|
TaxClass $taxClass,
|
||||||
Currency $currency,
|
Currency $currency,
|
||||||
array $options,
|
array $options,
|
||||||
|
string $imagesPath,
|
||||||
): void {
|
): void {
|
||||||
$externalId = "{$handle}#{$index}";
|
$externalId = "{$handle}#{$index}";
|
||||||
$existing = ImportMapping::resolve(self::SOURCE, 'variant', $externalId);
|
$existing = ImportMapping::resolve(self::SOURCE, 'variant', $externalId);
|
||||||
@@ -182,6 +184,26 @@ class ShopifyExportImporter implements Importer
|
|||||||
: null;
|
: null;
|
||||||
|
|
||||||
$this->priceResolver->resolve($variant, $currency, $price, $comparePrice);
|
$this->priceResolver->resolve($variant, $currency, $price, $comparePrice);
|
||||||
|
|
||||||
|
// Shopify's own "Variant Image" column — the one image a variant picker
|
||||||
|
// actually swaps to when that variant is selected — distinct from the
|
||||||
|
// product's full gallery (imageRows below). Often the same file as one
|
||||||
|
// of the product's own image rows, sometimes not yet imported at all
|
||||||
|
// (e.g. a variant-only image never listed as its own image row) — either
|
||||||
|
// way resolveOrImportImage() handles both via the same Image Src dedup
|
||||||
|
// key, so whichever of importVariant()/importImage() runs first for a
|
||||||
|
// given src does the actual import.
|
||||||
|
$variantImageSrc = trim((string) ($row['Variant Image'] ?? ''));
|
||||||
|
|
||||||
|
if ($variantImageSrc !== '') {
|
||||||
|
$media = $this->resolveOrImportImage($product, $handle, $variantImageSrc, 1, $imagesPath);
|
||||||
|
|
||||||
|
if ($media) {
|
||||||
|
$variant->images()->syncWithoutDetaching([
|
||||||
|
$media->id => ['primary' => true, 'position' => 1],
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
private function importImage(
|
private function importImage(
|
||||||
@@ -191,29 +213,54 @@ class ShopifyExportImporter implements Importer
|
|||||||
array $row,
|
array $row,
|
||||||
string $imagesPath,
|
string $imagesPath,
|
||||||
): void {
|
): void {
|
||||||
$externalId = $row['Image Src'] ?: "{$handle}#image-{$index}";
|
|
||||||
$position = (int) ($row['Image Position'] ?? $index + 1);
|
$position = (int) ($row['Image Position'] ?? $index + 1);
|
||||||
|
|
||||||
if (ImportMapping::resolve(self::SOURCE, 'image', $externalId)) {
|
$this->resolveOrImportImage($product, $handle, $row['Image Src'], $position, $imagesPath);
|
||||||
return;
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Resolves the Media already imported for $imageSrc (recorded under
|
||||||
|
* source_type 'image', keyed by Image Src — the same URL Shopify repeats
|
||||||
|
* across a product's own image rows and any variant's "Variant Image"
|
||||||
|
* column), importing it via AssetResolver if this is the first time this
|
||||||
|
* src has been seen. Shared by importImage() (product gallery) and
|
||||||
|
* importVariant() (variant-specific image) so the same physical file is
|
||||||
|
* never uploaded to Spatie MediaLibrary twice just because Shopify's flat
|
||||||
|
* CSV format repeats the URL on multiple rows.
|
||||||
|
*/
|
||||||
|
private function resolveOrImportImage(
|
||||||
|
Product $product,
|
||||||
|
string $handle,
|
||||||
|
string $imageSrc,
|
||||||
|
int $position,
|
||||||
|
string $imagesPath,
|
||||||
|
): ?Media {
|
||||||
|
$externalId = $imageSrc ?: "{$handle}#image-{$position}";
|
||||||
|
|
||||||
|
$existing = ImportMapping::resolve(self::SOURCE, 'image', $externalId);
|
||||||
|
|
||||||
|
if ($existing instanceof Media) {
|
||||||
|
return $existing;
|
||||||
}
|
}
|
||||||
|
|
||||||
$localFile = $this->findLocalFile($imagesPath, $row['Image Src']);
|
$localFile = $this->findLocalFile($imagesPath, $imageSrc);
|
||||||
|
|
||||||
if ($localFile === null) {
|
if ($localFile === null) {
|
||||||
Log::warning('Shopify import: image file not found', [
|
Log::warning('Shopify import: image file not found', [
|
||||||
'handle' => $handle,
|
'handle' => $handle,
|
||||||
'image_src' => $row['Image Src'],
|
'image_src' => $imageSrc,
|
||||||
]);
|
]);
|
||||||
|
|
||||||
return;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
$media = $this->assetResolver->resolve($product, $localFile, $position);
|
$media = $this->assetResolver->resolve($product, $localFile, $position);
|
||||||
|
|
||||||
if ($media) {
|
if ($media) {
|
||||||
ImportMapping::record(self::SOURCE, 'image', $externalId, $product);
|
ImportMapping::record(self::SOURCE, 'image', $externalId, $media);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
return $media;
|
||||||
}
|
}
|
||||||
|
|
||||||
private function findLocalFile(string $imagesPath, string $imageSrc): ?string
|
private function findLocalFile(string $imagesPath, string $imageSrc): ?string
|
||||||
|
|||||||
@@ -0,0 +1,68 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Commands;
|
||||||
|
|
||||||
|
use Illuminate\Console\Command;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Modules\Core\Order\Events\OrderCompleted;
|
||||||
|
use Modules\Core\Order\Services\OrderStatusWriter;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Auto-completes a carrier order once its 14-day return window has
|
||||||
|
* elapsed with no return requested — the automatic counterpart to the
|
||||||
|
* staff "Update Status" action's manual completion. Store-pickup orders
|
||||||
|
* have no return-window step at all (Modules\Core\Order\Listeners\
|
||||||
|
* CompleteOrderOnPickedUp completes them immediately), so this only ever
|
||||||
|
* touches carrier orders sitting in 'delivered' (the status also carrying
|
||||||
|
* "return window is open" — see AdvanceFulfillmentOnDelivered).
|
||||||
|
*
|
||||||
|
* Registered at exactly dailyAt('00:00') in
|
||||||
|
* Modules\Core\Providers\OrderServiceProvider — a compliance requirement
|
||||||
|
* that this run at exact midnight, not Laravel's own arbitrary default
|
||||||
|
* time for a plain daily() schedule.
|
||||||
|
*
|
||||||
|
* "When did the window open" is read from order_status_transitions rather
|
||||||
|
* than Order::updated_at, which any unrelated field write would bump —
|
||||||
|
* this is the concrete reason the audit table exists beyond pure logging.
|
||||||
|
*
|
||||||
|
* Window length is config('core.order.return_window_days') — a legal/
|
||||||
|
* policy value a store may need to change without a code deploy, not a
|
||||||
|
* hardcoded constant.
|
||||||
|
*/
|
||||||
|
class CloseExpiredReturnWindows extends Command
|
||||||
|
{
|
||||||
|
protected $signature = 'boboko:order:close-expired-return-windows';
|
||||||
|
|
||||||
|
protected $description = 'Auto-complete carrier orders whose return window has elapsed with no return requested.';
|
||||||
|
|
||||||
|
public function handle(OrderStatusWriter $writer): void
|
||||||
|
{
|
||||||
|
$cutoff = now()->subDays(config('core.order.return_window_days', 14));
|
||||||
|
|
||||||
|
$orderIds = Order::query()
|
||||||
|
->where('status', 'delivered')
|
||||||
|
->whereHas('statusTransitions', function ($query) use ($cutoff) {
|
||||||
|
$query->where('to_status', 'delivered')
|
||||||
|
->where('created_at', '<=', $cutoff);
|
||||||
|
})
|
||||||
|
->pluck('id');
|
||||||
|
|
||||||
|
$completed = 0;
|
||||||
|
|
||||||
|
foreach ($orderIds as $orderId) {
|
||||||
|
$order = Order::find($orderId);
|
||||||
|
|
||||||
|
if (! $order || $order->status !== 'delivered') {
|
||||||
|
continue; // idempotent no-op — moved on since the query ran
|
||||||
|
}
|
||||||
|
|
||||||
|
$writer->write($order, 'completed', self::class);
|
||||||
|
|
||||||
|
OrderCompleted::dispatch($order);
|
||||||
|
|
||||||
|
$completed++;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->components->info("Completed {$completed} order(s) past their return window.");
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\DTOs;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* What a Modules\Core\Order\Services\OrderFulfillmentService method
|
||||||
|
* returns instead of throwing/echoing a Filament notification directly —
|
||||||
|
* keeps that service usable outside a Filament action (a future API
|
||||||
|
* endpoint, a console command, a test) without dragging
|
||||||
|
* Filament\Notifications\Notification along. Modules\Core\Shipping\
|
||||||
|
* Extensions\OrderViewExtension is the one place that translates this
|
||||||
|
* into an actual on-screen notification.
|
||||||
|
*/
|
||||||
|
final class OrderFulfillmentResult
|
||||||
|
{
|
||||||
|
private function __construct(
|
||||||
|
public readonly bool $success,
|
||||||
|
public readonly string $message,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public static function success(string $message): self
|
||||||
|
{
|
||||||
|
return new self(true, $message);
|
||||||
|
}
|
||||||
|
|
||||||
|
public static function failure(string $message): self
|
||||||
|
{
|
||||||
|
return new self(false, $message);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Enums;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Derived from Shipment/ShipmentInfo — no equivalent existed anywhere in
|
||||||
|
* Lunar or this codebase before OrderStatus::fulfillment().
|
||||||
|
*/
|
||||||
|
enum FulfillmentStatus: string
|
||||||
|
{
|
||||||
|
case Unfulfilled = 'unfulfilled';
|
||||||
|
case Shipped = 'shipped';
|
||||||
|
case PartiallyShipped = 'partially-shipped';
|
||||||
|
case Delivered = 'delivered';
|
||||||
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Enums;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Same states/logic as Lunar's own ManageOrder::paymentStatus(), which
|
||||||
|
* only exists as a Filament-page Livewire #[Computed] method — this is
|
||||||
|
* that same derivation, reusable from anywhere via Order::paymentStatus().
|
||||||
|
*/
|
||||||
|
enum PaymentStatus: string
|
||||||
|
{
|
||||||
|
case Offline = 'offline';
|
||||||
|
case Uncaptured = 'uncaptured';
|
||||||
|
case Captured = 'captured';
|
||||||
|
case PartialRefund = 'partial-refund';
|
||||||
|
case Refunded = 'refunded';
|
||||||
|
}
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Lunar\Models\Transaction;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by TransactionObserver::saved() when a Transaction's type
|
||||||
|
* changes to 'capture' (from 'intent') and succeeds. Unlike refunds,
|
||||||
|
* Lunar's Stripe driver (StoreCharges) reuses the same Transaction row
|
||||||
|
* across intent -> capture rather than creating a new one, so this can't
|
||||||
|
* key off `wasRecentlyCreated` the way OrderRefunded does.
|
||||||
|
*/
|
||||||
|
class OrderCaptured
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
public readonly Transaction $transaction,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The one terminal signal every notification/reporting concern that only
|
||||||
|
* cares about "this order is fully done" should listen to, regardless of
|
||||||
|
* which path actually got it there — dispatched by all four:
|
||||||
|
* Modules\Core\Order\Listeners\CompleteOrderOnPickedUp (store-pickup),
|
||||||
|
* Modules\Core\Order\Commands\CloseExpiredReturnWindows (carrier,
|
||||||
|
* automatic 14-day return-window expiry), or Modules\Core\Shipping\
|
||||||
|
* Extensions\OrderViewExtension's "Mark Completed" action (manual
|
||||||
|
* universal fallback, either branch).
|
||||||
|
*/
|
||||||
|
class OrderCompleted
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Modules\Core\Shipping\Models\ShipmentInfo;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Order's DeriveOrderDeliveredFromShipment listener, which
|
||||||
|
* reacts to Shipping's ShipmentStatusUpdatedByCarrier — delivery is a
|
||||||
|
* tracking checkpoint, not a manual status write, so it never goes through
|
||||||
|
* OrderStatusUpdated. Order.status itself is left untouched here; this is
|
||||||
|
* only the signal for delivery notifications and similar reactions.
|
||||||
|
*/
|
||||||
|
class OrderDelivered
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
public readonly ShipmentInfo $shipmentInfo,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Modules\Core\Shipping\Models\ShipmentInfo;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by either of the two paths that move a carrier order's
|
||||||
|
* `status` to 'dispatched' — Modules\Core\Order\Listeners\
|
||||||
|
* AdvanceFulfillmentOnCarrierCheckpoint (automatic, reacting to a real
|
||||||
|
* carrier checkpoint) or Modules\Core\Order\Services\
|
||||||
|
* OrderFulfillmentService::createShipmentAndDispatch() (staff-driven, via
|
||||||
|
* the single "Update Status" action). $shipmentInfo is nullable
|
||||||
|
* specifically because of that second path — populated with the
|
||||||
|
* triggering checkpoint when it's real, null when staff drove it
|
||||||
|
* manually. Mirrors OrderDelivered's {order, shipmentInfo} shape, just
|
||||||
|
* with the nullability this one event additionally needs.
|
||||||
|
*/
|
||||||
|
class OrderDispatched
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
public readonly ?ShipmentInfo $shipmentInfo = null,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Modules\Core\Order\Services\OrderStatusWriter::markPaid()
|
||||||
|
* whenever Order::paid flips to true — entirely independent of the
|
||||||
|
* `status` column (see OrderStatusFlow's own docblock for why payment
|
||||||
|
* timing, especially for cash-on-delivery, cannot be modeled as a step in
|
||||||
|
* that sequence). Order::status changes are instead picked up generically
|
||||||
|
* by Modules\Core\Order\Events\OrderStatusUpdated (dispatched by
|
||||||
|
* OrderObserver whenever `status` changes, regardless of writer).
|
||||||
|
*/
|
||||||
|
class OrderPaidChanged
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
public readonly string $causeClass,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Modules\Core\Order\Services\OrderFulfillmentService::
|
||||||
|
* markPickedUp(), the staff-driven "Update Status" action's handling of
|
||||||
|
* the 'picked_up' target — the customer has collected a store-pickup
|
||||||
|
* order in person. Store-pickup only; a carrier order's equivalent
|
||||||
|
* "arrived" moment is OrderDelivered. Modules\Core\Order\Listeners\
|
||||||
|
* CompleteOrderOnPickedUp reacts to this by moving `status` straight to
|
||||||
|
* 'completed' — no return-window step for store-pickup, per the business
|
||||||
|
* design.
|
||||||
|
*/
|
||||||
|
class OrderPickedUp
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Modules\Core\Shipping\Extensions\OrderViewExtension's
|
||||||
|
* "Mark Ready" action, carrier branch (Order::isStorePickupOrder() ===
|
||||||
|
* false) — staff has packed/staged the order for carrier handoff.
|
||||||
|
* Staff-internal: nothing customer-facing happens at this moment, so no
|
||||||
|
* notification listens to this event (compare OrderReadyForPickup, which
|
||||||
|
* does trigger a customer email).
|
||||||
|
*/
|
||||||
|
class OrderReadyForDispatch
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Modules\Core\Shipping\Extensions\OrderViewExtension's
|
||||||
|
* "Mark Ready" action, store-pickup branch (Order::isStorePickupOrder()
|
||||||
|
* === true) — staff has packed/staged the order for the customer to
|
||||||
|
* collect in store. Drives Modules\Core\Order\Notifications\
|
||||||
|
* OrderPickupReadyNotification ("come collect your order").
|
||||||
|
*/
|
||||||
|
class OrderReadyForPickup
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Lunar\Models\Transaction;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by TransactionObserver::saved() whenever a successful
|
||||||
|
* type=refund Transaction row is written — every payment driver (Lunar's
|
||||||
|
* own StripePaymentType::refund(), or a future boboko-owned driver for a
|
||||||
|
* provider Lunar doesn't ship) creates a new row for each refund, so
|
||||||
|
* `created` alone (filtered to type+success) is enough here, unlike
|
||||||
|
* captures which can reuse an existing row.
|
||||||
|
*/
|
||||||
|
class OrderRefunded
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
public readonly Transaction $transaction,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Modules\Core\Order\Services\OrderStatusWriter::write()
|
||||||
|
* alongside the generic Modules\Core\Order\Events\OrderStatusUpdated
|
||||||
|
* (which Modules\Core\Order\Observers\OrderObserver dispatches for ANY
|
||||||
|
* `status` write, regardless of cause, and which
|
||||||
|
* OrderStatusUpdatedNotification already listens to). This event exists
|
||||||
|
* only because the audit trail (Modules\Core\Order\Listeners\
|
||||||
|
* RecordStatusTransition) needs $causeClass, which OrderStatusUpdated
|
||||||
|
* does not carry — OrderStatusWriter is the only writer of `status` this
|
||||||
|
* package has left, so it's the only place that needs to know its own
|
||||||
|
* cause.
|
||||||
|
*/
|
||||||
|
class OrderStatusChanged
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
public readonly ?string $previousStatus,
|
||||||
|
public readonly string $newStatus,
|
||||||
|
public readonly string $causeClass,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by OrderObserver::updated() whenever an Order's status column
|
||||||
|
* changes, regardless of what wrote it — Filament's UpdateStatusAction,
|
||||||
|
* artisan tinker, a future API. Lunar's own UpdatesOrderStatus trait fires
|
||||||
|
* mailers inline, but only for that one admin action; this event is the
|
||||||
|
* general-purpose hook everything else (our own mailers, automations,
|
||||||
|
* derived payment/fulfillment status) should listen to instead.
|
||||||
|
*/
|
||||||
|
class OrderStatusUpdated
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
public readonly ?string $previousStatus,
|
||||||
|
public readonly string $newStatus,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,50 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Filament\Extensions;
|
||||||
|
|
||||||
|
use Filament\Actions\BulkAction;
|
||||||
|
use Filament\Support\Exceptions\Halt;
|
||||||
|
use Filament\Tables\Table;
|
||||||
|
use Lunar\Admin\Support\Extending\BaseExtension;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Same fix as OrderRefundActionsExtension, applied to the order lines
|
||||||
|
* table's "bulk_refund" toolbar action (Lunar\Admin\...\OrderItemsTable::
|
||||||
|
* getBulkRefundAction()) — see that class's docblock for the underlying
|
||||||
|
* Filament bug (failureNotification()+failure()+halt() never actually
|
||||||
|
* sends the notification, because halt()'s Halt exception is caught before
|
||||||
|
* Filament reaches the code that would send it).
|
||||||
|
*/
|
||||||
|
class OrderItemsTableExtension extends BaseExtension
|
||||||
|
{
|
||||||
|
public function extendTable(Table $table): Table
|
||||||
|
{
|
||||||
|
return $table->toolbarActions(
|
||||||
|
array_map(
|
||||||
|
fn ($action) => $action instanceof BulkAction && $action->getName() === 'bulk_refund'
|
||||||
|
? $this->fixFailureNotification($action)
|
||||||
|
: $action,
|
||||||
|
$table->getToolbarActions(),
|
||||||
|
),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
private function fixFailureNotification(BulkAction $action): BulkAction
|
||||||
|
{
|
||||||
|
$originalAction = $action->getActionFunction();
|
||||||
|
|
||||||
|
if ($originalAction === null) {
|
||||||
|
return $action;
|
||||||
|
}
|
||||||
|
|
||||||
|
return $action->action(function (array $arguments) use ($action, $originalAction) {
|
||||||
|
try {
|
||||||
|
return $action->evaluate($originalAction, $arguments);
|
||||||
|
} catch (Halt $exception) {
|
||||||
|
$action->sendFailureNotification();
|
||||||
|
|
||||||
|
throw $exception;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,47 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Filament\Extensions;
|
||||||
|
|
||||||
|
use Filament\Infolists\Components\TextEntry;
|
||||||
|
use Lunar\Admin\Support\Extending\ViewPageExtension;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Modules\Core\Payment\Models\PaymentMethod;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Adds a "Payment Method" entry to the order summary sidebar — previously
|
||||||
|
* nowhere on the order page told staff which payment method a shopper
|
||||||
|
* actually used. Reads Order.meta['payment_method'] (written by
|
||||||
|
* Modules\Core\Checkout\Services\CheckoutService::initiatePayment()), the
|
||||||
|
* same source Modules\Core\Order\Services\OrderStatusFlow::isCod() reads,
|
||||||
|
* so this entry and the "Mark Paid" action's visibility always agree on
|
||||||
|
* what payment method an order used. Falls back to the most recent
|
||||||
|
* Transaction.driver for an order placed before that field existed.
|
||||||
|
*
|
||||||
|
* Uses the extendOrderSummarySchema hook, same as the deleted 3-axis
|
||||||
|
* OrderStatusSummaryExtension did — see that class's git history for the
|
||||||
|
* hook's own docblock/rationale.
|
||||||
|
*/
|
||||||
|
class OrderPaymentMethodSummaryExtension extends ViewPageExtension
|
||||||
|
{
|
||||||
|
public function extendOrderSummarySchema(array $schema): array
|
||||||
|
{
|
||||||
|
$schema[] = TextEntry::make('payment_method')
|
||||||
|
->label('Payment method')
|
||||||
|
->state(fn (Order $record) => $this->resolveLabel($record))
|
||||||
|
->placeholder('—')
|
||||||
|
->alignEnd();
|
||||||
|
|
||||||
|
return $schema;
|
||||||
|
}
|
||||||
|
|
||||||
|
private function resolveLabel(Order $record): ?string
|
||||||
|
{
|
||||||
|
$type = $record->meta['payment_method'] ?? $record->transactions()->latest('id')->value('driver');
|
||||||
|
|
||||||
|
if ($type === null) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
return PaymentMethod::where('type', $type)->value('name') ?? $type;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,199 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Filament\Extensions;
|
||||||
|
|
||||||
|
use Filament\Actions\Action;
|
||||||
|
use Filament\Forms\Components\Select;
|
||||||
|
use Filament\Notifications\Notification;
|
||||||
|
use Filament\Support\Exceptions\Halt;
|
||||||
|
use Lunar\Admin\Support\Extending\ViewPageExtension;
|
||||||
|
use Lunar\Models\Transaction;
|
||||||
|
use Modules\Core\Payment\Contracts\SupportsRefunds;
|
||||||
|
use Modules\Core\Payment\Models\CoreTransaction;
|
||||||
|
use Modules\Core\Payment\Services\PaymentDriverRegistry;
|
||||||
|
use Modules\Core\Payment\Support\TransactionDriverAdapter;
|
||||||
|
use ReflectionProperty;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Fixes a real bug in Lunar's own admin panel, not anything specific to how
|
||||||
|
* boboko resolves payment drivers: ManageOrder::getRefundAction() and
|
||||||
|
* ::getCaptureAction() (vendor/lunarphp/lunar/.../ManageOrder.php) both
|
||||||
|
* report a failed refund/capture by calling, in this order:
|
||||||
|
* $action->failureNotification(...); $action->failure(); $action->halt();
|
||||||
|
* but Filament\Actions\Concerns\InteractsWithActions::callMountedAction()
|
||||||
|
* only ever calls sendFailureNotification() from a match($action->getStatus())
|
||||||
|
* block that runs AFTER the action's call() returns normally — halt() throws
|
||||||
|
* Filament\Support\Exceptions\Halt, which is caught in an earlier catch block
|
||||||
|
* that rolls back the DB transaction and returns null, never reaching that
|
||||||
|
* match block. So the notification set via failureNotification() is built
|
||||||
|
* but never sent: the admin sees the modal just close/reset with no
|
||||||
|
* indication anything happened. This was always broken in Lunar; it was
|
||||||
|
* invisible before because nothing in this codebase's Transaction::driver()
|
||||||
|
* could return a real, honest failure — see Payment\Support\
|
||||||
|
* TransactionDriverAdapter's own docblock for that history.
|
||||||
|
*
|
||||||
|
* Fix, for capture: wrap the action's own action() closure so that, on
|
||||||
|
* Halt, we call $action->sendFailureNotification() ourselves before letting
|
||||||
|
* the Halt continue propagating — everything else is untouched.
|
||||||
|
*
|
||||||
|
* Fix, for refund: same notification fix, but the action() closure is
|
||||||
|
* replaced outright (not wrapped) rather than reused, because refund also
|
||||||
|
* needs a "Refund via" driver Select added to the modal (see
|
||||||
|
* fixRefundAction()) and the actual call routed through
|
||||||
|
* Payment\Support\TransactionDriverAdapter::refundVia() instead of
|
||||||
|
* Lunar\Models\Transaction::refund() — see fixRefundAction()'s own
|
||||||
|
* docblock.
|
||||||
|
*/
|
||||||
|
class OrderRefundActionsExtension extends ViewPageExtension
|
||||||
|
{
|
||||||
|
public function headerActions(array $actions): array
|
||||||
|
{
|
||||||
|
return array_map(
|
||||||
|
fn (Action $action) => match ($action->getName()) {
|
||||||
|
'refund' => $this->fixRefundAction($action),
|
||||||
|
'capture' => $this->fixFailureNotification($action),
|
||||||
|
default => $action,
|
||||||
|
},
|
||||||
|
$actions,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Combines both refund-only changes on top of the failure-notification
|
||||||
|
* fix every action here gets: adds a "Refund via" driver Select
|
||||||
|
* (defaulting to the transaction's own driver) to the modal, and
|
||||||
|
* replaces the actual refund call with one that honours that field —
|
||||||
|
* calling Payment\Support\TransactionDriverAdapter::refundVia()
|
||||||
|
* directly (bypassing Lunar\Models\Transaction::refund(), whose fixed
|
||||||
|
* refund(int $amount, $notes = null) signature has no room for a
|
||||||
|
* driver override) whenever the admin picked a driver other than the
|
||||||
|
* transaction's own. When left at the default, behaviour is identical
|
||||||
|
* to calling $transaction->refund() — refundVia() resolves to the same
|
||||||
|
* driver either way.
|
||||||
|
*
|
||||||
|
* The Select is appended to Lunar's own schema closure (read via
|
||||||
|
* reflection — HasSchema::$schema has no public getter) rather than
|
||||||
|
* replacing it outright, so the transaction/amount/notes/confirm
|
||||||
|
* fields Lunar already built are untouched.
|
||||||
|
*/
|
||||||
|
private function fixRefundAction(Action $action): Action
|
||||||
|
{
|
||||||
|
$originalSchema = $this->readProtectedProperty($action, 'schema');
|
||||||
|
|
||||||
|
$action->schema(function (array $arguments) use ($action, $originalSchema) {
|
||||||
|
$fields = is_callable($originalSchema)
|
||||||
|
? $action->evaluate($originalSchema, $arguments)
|
||||||
|
: ($originalSchema ?? []);
|
||||||
|
|
||||||
|
return [
|
||||||
|
...$fields,
|
||||||
|
Select::make('driver')
|
||||||
|
->label('Refund via')
|
||||||
|
->options(fn () => $this->refundCapableDriverLabels())
|
||||||
|
->default(fn ($get) => $this->driverKeyForTransaction($get('transaction')))
|
||||||
|
->native(false)
|
||||||
|
->required(),
|
||||||
|
];
|
||||||
|
});
|
||||||
|
|
||||||
|
return $action->action(function (array $data, Action $action) {
|
||||||
|
$transaction = Transaction::find($data['transaction']);
|
||||||
|
|
||||||
|
if (! $transaction instanceof CoreTransaction) {
|
||||||
|
$action->failureNotification(fn () => Notification::make('refund_failure')->danger()->title('Transaction not found.'))
|
||||||
|
->sendFailureNotification();
|
||||||
|
|
||||||
|
throw new Halt;
|
||||||
|
}
|
||||||
|
|
||||||
|
$adapter = app(TransactionDriverAdapter::class);
|
||||||
|
$driverKey = $data['driver'] ?? $adapter->driverKeyFor($transaction);
|
||||||
|
|
||||||
|
$response = $adapter->refundVia($transaction, $driverKey, (int) bcmul((string) $data['amount'], (string) $transaction->order->currency->factor), $data['notes'] ?? null);
|
||||||
|
|
||||||
|
if (! $response->success) {
|
||||||
|
$action->failureNotification(
|
||||||
|
fn () => Notification::make('refund_failure')->color('danger')->title($response->message)
|
||||||
|
)->sendFailureNotification();
|
||||||
|
|
||||||
|
throw new Halt;
|
||||||
|
}
|
||||||
|
|
||||||
|
$action->success();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return array<string, string>
|
||||||
|
*/
|
||||||
|
private function refundCapableDriverLabels(): array
|
||||||
|
{
|
||||||
|
$registry = app(PaymentDriverRegistry::class);
|
||||||
|
|
||||||
|
$labels = [];
|
||||||
|
|
||||||
|
foreach ($registry->all() as $key => $driverClass) {
|
||||||
|
if (app($driverClass) instanceof SupportsRefunds) {
|
||||||
|
$labels[$key] = $registry->label($key) ?? $key;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return $labels;
|
||||||
|
}
|
||||||
|
|
||||||
|
private function driverKeyForTransaction(mixed $transactionId): ?string
|
||||||
|
{
|
||||||
|
if (blank($transactionId)) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
$transaction = Transaction::find($transactionId);
|
||||||
|
|
||||||
|
if (! $transaction instanceof CoreTransaction) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
return app(TransactionDriverAdapter::class)->driverKeyFor($transaction);
|
||||||
|
}
|
||||||
|
|
||||||
|
private function readProtectedProperty(object $object, string $property): mixed
|
||||||
|
{
|
||||||
|
$reflected = new ReflectionProperty($object, $property);
|
||||||
|
$reflected->setAccessible(true);
|
||||||
|
|
||||||
|
return $reflected->getValue($object);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Wraps the action's own configured action() closure so that, if it
|
||||||
|
* halts (Lunar's closures throw via $action->halt() to signal failure —
|
||||||
|
* see this class's own docblock for why that alone never sends the
|
||||||
|
* notification queued via failureNotification()), we send that
|
||||||
|
* notification ourselves before letting the Halt continue propagating
|
||||||
|
* (still needed — it's what stops callMountedAction() from treating
|
||||||
|
* this as a success and closing the modal/committing the DB transaction).
|
||||||
|
*
|
||||||
|
* $this->evaluate() (not a plain call) matches exactly how Action::call()
|
||||||
|
* itself invokes the closure — Lunar's closures type-hint $data/$record/
|
||||||
|
* $action and rely on Filament's own container-style parameter
|
||||||
|
* resolution, not positional arguments.
|
||||||
|
*/
|
||||||
|
private function fixFailureNotification(Action $action): Action
|
||||||
|
{
|
||||||
|
$originalAction = $action->getActionFunction();
|
||||||
|
|
||||||
|
if ($originalAction === null) {
|
||||||
|
return $action;
|
||||||
|
}
|
||||||
|
|
||||||
|
return $action->action(function (array $arguments) use ($action, $originalAction) {
|
||||||
|
try {
|
||||||
|
return $action->evaluate($originalAction, $arguments);
|
||||||
|
} catch (Halt $exception) {
|
||||||
|
$action->sendFailureNotification();
|
||||||
|
|
||||||
|
throw $exception;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user