Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a411e6bbc1 | ||
|
|
910fa94395 | ||
|
|
fdd1899c34 | ||
|
|
3ad3a1b4d6 | ||
|
|
68233f43ef | ||
|
|
027f7e8982 | ||
|
|
c084eb47cb | ||
|
|
58d165acc3 | ||
|
|
44ad943eec | ||
|
|
2cc6f5e5f0 | ||
|
|
0babc6a96d | ||
|
|
89a3d4bbad | ||
|
|
ccb2666495 | ||
|
|
97004234f0 | ||
|
|
ea73cc3562 | ||
|
|
02816fb9e7 | ||
|
|
910ce0205d | ||
|
|
e532c32cab | ||
|
|
6a51b672c8 | ||
|
|
956e9e88a6 | ||
|
|
4489475840 | ||
|
|
e4e008167a | ||
|
|
a5f3008ce2 | ||
|
|
d9fb3bbde6 | ||
|
|
26b4c5bfd7 | ||
|
|
409e8204f6 | ||
|
|
8472649905 | ||
|
|
57fc28ca06 | ||
|
|
9d3e54e5df | ||
|
|
44c6b7defd | ||
|
|
78bbd8390a | ||
|
|
99e55902ac | ||
|
|
864c8b19aa | ||
|
|
8f4c1a22ea | ||
|
|
13d5833d18 | ||
|
|
3e45b84636 | ||
|
|
437cbf2460 | ||
|
|
5425a0396f | ||
|
|
4d0e326cb9 | ||
|
|
d4f9766940 | ||
|
|
359e1e262e | ||
|
|
fb684dc97b | ||
|
|
9c95c0bccb | ||
|
|
73bfc748b4 | ||
|
|
4ff9bdacc3 | ||
|
|
55832d9549 | ||
|
|
7b46a83e5e | ||
|
|
e7784364fd | ||
|
|
59303cf25f | ||
|
|
af380a7fa0 | ||
|
|
9f540cbaa4 |
+786
-4
File diff suppressed because it is too large
Load Diff
@@ -1,6 +1,9 @@
|
|||||||
# Core Module
|
# Core Module
|
||||||
|
|
||||||
A Laravel module providing authentication, notifications, activity logging, CLI tooling, and functional types on top of the [Lunar](https://lunarphp.io) admin panel. Designed to be consumed as a standalone Composer package.
|
A Laravel module providing authentication, localization, product search/catalog, privacy/GDPR
|
||||||
|
tooling, notifications, activity logging, CLI tooling, and functional types on top of the
|
||||||
|
[Lunar](https://lunarphp.io) e-commerce package. Designed to be consumed as a standalone Composer
|
||||||
|
package by any Lunar-based e-shop.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -8,13 +11,83 @@ A Laravel module providing authentication, notifications, activity logging, CLI
|
|||||||
|
|
||||||
### OTP Authentication
|
### OTP Authentication
|
||||||
|
|
||||||
Passwordless login for both staff (Lunar panel) and customers via 6-digit codes delivered by email. Codes expire after 10 minutes. The Lunar panel login page is a two-step flow: email → OTP. Rate-limited to 5 attempts.
|
Passwordless login for both staff (Lunar panel) and customers via 6-digit codes delivered by
|
||||||
|
email. Codes expire after 10 minutes, rate-limited to 5 attempts. The Lunar panel login page is a
|
||||||
|
two-step flow (email → OTP) with a back button to return from the code step to the email step.
|
||||||
|
|
||||||
See [`docs/otp-auth.md`](docs/otp-auth.md).
|
See [`docs/otp-auth.md`](docs/otp-auth.md).
|
||||||
|
|
||||||
|
### Localization
|
||||||
|
|
||||||
|
Locale-prefixed routing (`Modules\Core\Localization\LocaleMiddleware`) — a `locale` route
|
||||||
|
middleware, opt-in per shop, that resolves and redirects to the correct language segment
|
||||||
|
(`/el/...`, `/en/...`) based on Lunar's own language list, with caching and rename-safe
|
||||||
|
translation migration. Also brings in storefront UI label translations
|
||||||
|
(`spatie/laravel-translation-loader`) with an admin-editable `LanguageLine` resource.
|
||||||
|
|
||||||
|
See [`docs/localization.md`](docs/localization.md).
|
||||||
|
|
||||||
|
### Product Search & Catalog
|
||||||
|
|
||||||
|
Two complementary services on top of Meilisearch:
|
||||||
|
|
||||||
|
- **`Modules\Core\Search\ProductSearchService`** — locale-aware full-text product search.
|
||||||
|
- **`Modules\Core\Catalog\ProductService`** — listing/filtering (by collection, brand, price
|
||||||
|
range) and single-product lookup by id or slug, reading directly from the Meilisearch index
|
||||||
|
rather than the database.
|
||||||
|
|
||||||
|
Both are backed by `Modules\Core\Search\ProductIndexer`, which extends Lunar's own indexer with
|
||||||
|
collections, price, variants, media, tags, and reviews — everything needed for both a listing
|
||||||
|
page and a full product detail page from one index.
|
||||||
|
|
||||||
|
See [`docs/product-search.md`](docs/product-search.md) and
|
||||||
|
[`docs/product-listing.md`](docs/product-listing.md).
|
||||||
|
|
||||||
|
### Product Reviews
|
||||||
|
|
||||||
|
`Modules\Core\Review\ProductReview` — ratings/reviews with staff replies, a Filament sub-navigation
|
||||||
|
page on the product edit screen, and automatic re-indexing (via `ReviewServiceProvider`) whenever
|
||||||
|
a review is created, updated, or deleted, so a product's Meilisearch document never goes stale.
|
||||||
|
|
||||||
|
### Privacy / GDPR Data-Subject Requests
|
||||||
|
|
||||||
|
Right of access (export) and right of erasure, built as an extensible contract
|
||||||
|
(`Modules\Core\Privacy\Contracts\PersonalDataProvider`) rather than a fixed table list — any
|
||||||
|
module can register its own data without core knowing it exists.
|
||||||
|
|
||||||
|
- **Two independent scopes**: erasing/exporting a Lunar `Customer` (business account) is never
|
||||||
|
the same operation as erasing/exporting a `User` (individual login) — a `Customer` erasure
|
||||||
|
never touches any linked `User`'s login, and a `User` erasure never touches a `Customer`
|
||||||
|
account's own data. See `docs/privacy.md` "User-scope vs Customer-scope".
|
||||||
|
- **Cancellable grace period** (default 30 days, configurable) before anything is actually
|
||||||
|
erased — logging back in during the window automatically reverts the request, mirroring
|
||||||
|
Shopify's own account-deletion flow. Immediate erasure exists but is staff-only by type, never
|
||||||
|
reachable from a self-service flow.
|
||||||
|
- **Sole-owner cascade**: erasing the last remaining `User` on a `Customer` also opens a (grace
|
||||||
|
period) erasure request for that now-orphaned `Customer`, so its PII doesn't sit unreachable
|
||||||
|
forever — traced back to the triggering request so login-reactivation can revert exactly that
|
||||||
|
cascade.
|
||||||
|
- **Queued export**: gathering data and writing a CSV-per-provider zip (via the generic,
|
||||||
|
reusable `Modules\Core\Export\CsvWriter`) runs as a background job; a consuming app hooks its
|
||||||
|
own notification onto the completion event via the Notification Registry (below).
|
||||||
|
|
||||||
|
See [`docs/privacy.md`](docs/privacy.md).
|
||||||
|
|
||||||
|
### Shopify Migration
|
||||||
|
|
||||||
|
`Modules\Core\MigrateImport\Shopify\ShopifyExportImporter` — imports a Shopify CSV product export
|
||||||
|
(products, variants, images, collections, tags, prices) into Lunar, idempotently re-runnable via
|
||||||
|
an `import_mappings` table. Part of a source-agnostic import framework
|
||||||
|
(`boboko:migrate:import`) designed to support additional sources later.
|
||||||
|
|
||||||
|
See [`docs/shopify-import.md`](docs/shopify-import.md).
|
||||||
|
|
||||||
### Notification Registry
|
### Notification Registry
|
||||||
|
|
||||||
An event-driven notification system. Each notification class declares which event it listens to and who to notify — the registry wires up the listener automatically. All notifications extend `BaseNotification` which implements `ShouldQueue`, so delivery is async. Supports optional delays.
|
An event-driven notification system. Each notification class declares which event it listens to
|
||||||
|
and who to notify — the registry wires up the listener automatically. All notifications extend
|
||||||
|
`BaseNotification`, which implements `ShouldQueue`, so delivery is async. Supports optional
|
||||||
|
delays.
|
||||||
|
|
||||||
**Creating a notification:**
|
**Creating a notification:**
|
||||||
|
|
||||||
@@ -33,9 +106,13 @@ class MyNotification extends BaseNotification
|
|||||||
NotificationRegistry::get()->register([MyNotification::class]);
|
NotificationRegistry::get()->register([MyNotification::class]);
|
||||||
```
|
```
|
||||||
|
|
||||||
|
See [`docs/notifications.md`](docs/notifications.md).
|
||||||
|
|
||||||
### Activity Logging
|
### Activity Logging
|
||||||
|
|
||||||
Thin wrapper around [Spatie Laravel Activity Log](https://github.com/spatie/laravel-activitylog). Four standardized methods: `created()`, `updated()`, `failed()`, `deleted()`. Logs to the `lunar` channel and auto-resolves the actor from the staff session.
|
Thin wrapper around [Spatie Laravel Activity Log](https://github.com/spatie/laravel-activitylog).
|
||||||
|
Four standardized methods: `created()`, `updated()`, `failed()`, `deleted()`. Logs to the `lunar`
|
||||||
|
channel and auto-resolves the actor from the staff session.
|
||||||
|
|
||||||
See [`docs/activity-log.md`](docs/activity-log.md).
|
See [`docs/activity-log.md`](docs/activity-log.md).
|
||||||
|
|
||||||
@@ -43,8 +120,11 @@ See [`docs/activity-log.md`](docs/activity-log.md).
|
|||||||
|
|
||||||
- Custom OTP login page replacing the default Lunar panel login
|
- Custom OTP login page replacing the default Lunar panel login
|
||||||
- `StaffResourceExtension` — removes password field from Lunar's staff resource
|
- `StaffResourceExtension` — removes password field from Lunar's staff resource
|
||||||
- `CustomerResourceExtension` — replaces default address relation manager with a custom implementation
|
- `CustomerResourceExtension` — replaces default address relation manager with a custom
|
||||||
- `CorePlugin` — configures panel path, branding, logos, navigation items, and activity log field exclusions for staff
|
implementation
|
||||||
|
- Table-rate shipping (`ShippingPlugin`) registered by default
|
||||||
|
- `CorePlugin` — configures panel path, branding, logos, navigation items, and activity log
|
||||||
|
field exclusions for staff
|
||||||
|
|
||||||
Register the plugin in your Lunar panel provider:
|
Register the plugin in your Lunar panel provider:
|
||||||
|
|
||||||
@@ -52,30 +132,36 @@ Register the plugin in your Lunar panel provider:
|
|||||||
->plugin(\Modules\Core\CorePlugin::make())
|
->plugin(\Modules\Core\CorePlugin::make())
|
||||||
```
|
```
|
||||||
|
|
||||||
|
See [`docs/lunar.md`](docs/lunar.md) for the full Lunar reference and non-obvious gotchas hit
|
||||||
|
while building against it.
|
||||||
|
|
||||||
### CLI Commands
|
### CLI Commands
|
||||||
|
|
||||||
| Command | Description |
|
| Command | Description |
|
||||||
|---|---|
|
|---|---|
|
||||||
| `core:create-admin` | Create a Lunar admin user |
|
| `boboko:anonymize` | Dummy-scrub personal data in `users`/`lunar_customers` for local dev safety (local environment only — **not** the GDPR erasure tool; see Privacy above for that) |
|
||||||
| `core:anonymize` | GDPR anonymization of users and customers (local only) |
|
| `boboko:export` | Dump database + storage files to a timestamped zip |
|
||||||
| `core:export` | Dump database + storage files to a timestamped zip |
|
| `boboko:import` | Restore from a `boboko:export` zip archive |
|
||||||
| `core:import` | Restore from a zip export (runs anonymize automatically, local only) |
|
| `boboko:export:cleanup` | Delete old export zips, keep N most recent |
|
||||||
| `core:export-cleanup` | Delete old export zips, keep N most recent |
|
| `boboko:migrate:import` | Import a vendor product catalog (Shopify, etc.) into Lunar |
|
||||||
|
| `boboko:privacy:process-erasure-requests` | Dispatch an erasure job for every due GDPR erasure request (wire into your own scheduler) |
|
||||||
|
| `lunar:create-admin` | Create a Lunar admin user (overrides Lunar's own command) |
|
||||||
|
| `lunar:install` | Seed default Lunar store data — countries, channel, currency, tax zone, attributes, product type (overrides Lunar's own command) |
|
||||||
|
|
||||||
### Functional Types
|
### Functional Types
|
||||||
|
|
||||||
Result and Option monads for explicit error handling without exceptions.
|
Result and Option types for explicit error handling without exceptions.
|
||||||
|
|
||||||
```php
|
```php
|
||||||
// Result<T, E>
|
// Result<T, E>
|
||||||
$result = Success::of($value);
|
$result = Success::create($value);
|
||||||
$result = Error::of('something went wrong');
|
$result = Error::create('something went wrong');
|
||||||
$result->map(fn($v) => ...)->flatMap(fn($v) => ...);
|
$result->map(fn($v) => ...)->flatMap(fn($v) => ...);
|
||||||
|
|
||||||
// Option<T>
|
// Option<T>
|
||||||
$option = Option::fromValue($nullableValue);
|
$option = Some::create($value);
|
||||||
$option->getOrElse('default');
|
$option = None::create();
|
||||||
$option->map(fn($v) => ...)->filter(fn($v) => $v > 0);
|
$option->map(fn($v) => ...);
|
||||||
```
|
```
|
||||||
|
|
||||||
---
|
---
|
||||||
@@ -102,17 +188,22 @@ Then run:
|
|||||||
|
|
||||||
```bash
|
```bash
|
||||||
composer require boboko/core
|
composer require boboko/core
|
||||||
|
php artisan vendor:publish --tag=core-config
|
||||||
php artisan vendor:publish --tag=core-assets
|
php artisan vendor:publish --tag=core-assets
|
||||||
php artisan migrate
|
php artisan migrate
|
||||||
```
|
```
|
||||||
|
|
||||||
|
For local core development alongside a consuming app (path-repo symlink + Docker mount), see
|
||||||
|
[`docs/modules.md`](docs/modules.md) "Docker Compose: the local-core mount".
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Requirements
|
## Requirements
|
||||||
|
|
||||||
- PHP 8.2+
|
- PHP 8.5+
|
||||||
- Laravel 11+
|
- Laravel 12+
|
||||||
- Lunar (lunarphp/lunar + lunarphp/admin)
|
- Lunar 1.3 (`lunarphp/lunar`)
|
||||||
|
- Meilisearch (for product search/listing/catalog)
|
||||||
- Spatie Laravel Activity Log
|
- Spatie Laravel Activity Log
|
||||||
|
|
||||||
---
|
---
|
||||||
@@ -120,7 +211,12 @@ php artisan migrate
|
|||||||
## Documentation
|
## Documentation
|
||||||
|
|
||||||
- [`docs/otp-auth.md`](docs/otp-auth.md) — OTP authentication flow
|
- [`docs/otp-auth.md`](docs/otp-auth.md) — OTP authentication flow
|
||||||
|
- [`docs/localization.md`](docs/localization.md) — Locale-prefixed routing and storefront translations
|
||||||
|
- [`docs/product-search.md`](docs/product-search.md) — Full-text product search
|
||||||
|
- [`docs/product-listing.md`](docs/product-listing.md) — Product listing/filtering/detail catalog service
|
||||||
|
- [`docs/privacy.md`](docs/privacy.md) — GDPR right of access/erasure, User-scope vs Customer-scope
|
||||||
|
- [`docs/shopify-import.md`](docs/shopify-import.md) — Shopify CSV → Lunar field mapping and import design
|
||||||
- [`docs/activity-log.md`](docs/activity-log.md) — Activity logging
|
- [`docs/activity-log.md`](docs/activity-log.md) — Activity logging
|
||||||
- [`docs/lunar.md`](docs/lunar.md) — Lunar framework reference
|
|
||||||
- [`docs/notifications.md`](docs/notifications.md) — Notification registry
|
- [`docs/notifications.md`](docs/notifications.md) — Notification registry
|
||||||
|
- [`docs/lunar.md`](docs/lunar.md) — Lunar framework reference and gotchas
|
||||||
- [`docs/modules.md`](docs/modules.md) — Module architecture, Customer/User pairing, provider registration pitfalls
|
- [`docs/modules.md`](docs/modules.md) — Module architecture, Customer/User pairing, provider registration pitfalls
|
||||||
|
|||||||
+5
-3
@@ -2,7 +2,7 @@
|
|||||||
"name": "boboko/core",
|
"name": "boboko/core",
|
||||||
"description": "Core module — authentication and shared panel behaviour",
|
"description": "Core module — authentication and shared panel behaviour",
|
||||||
"type": "library",
|
"type": "library",
|
||||||
"version": "0.13.1",
|
"version": "0.18.1",
|
||||||
"autoload": {
|
"autoload": {
|
||||||
"psr-4": {
|
"psr-4": {
|
||||||
"Modules\\Core\\": "src/"
|
"Modules\\Core\\": "src/"
|
||||||
@@ -18,7 +18,7 @@
|
|||||||
"lunarphp/search": "*",
|
"lunarphp/search": "*",
|
||||||
"lunarphp/meilisearch": "*",
|
"lunarphp/meilisearch": "*",
|
||||||
"spatie/laravel-translation-loader": "^2.8",
|
"spatie/laravel-translation-loader": "^2.8",
|
||||||
"lunarphp/stripe": "^1.5"
|
"stripe/stripe-php": "^16.6"
|
||||||
},
|
},
|
||||||
"require-dev": {
|
"require-dev": {
|
||||||
"fakerphp/faker": "^1.23",
|
"fakerphp/faker": "^1.23",
|
||||||
@@ -37,13 +37,15 @@
|
|||||||
"Modules\\Core\\Providers\\CoreServiceProvider",
|
"Modules\\Core\\Providers\\CoreServiceProvider",
|
||||||
"Modules\\Core\\Providers\\AuthServiceProvider",
|
"Modules\\Core\\Providers\\AuthServiceProvider",
|
||||||
"Modules\\Core\\Providers\\CustomerServiceProvider",
|
"Modules\\Core\\Providers\\CustomerServiceProvider",
|
||||||
|
"Modules\\Core\\Providers\\CheckoutServiceProvider",
|
||||||
"Modules\\Core\\Providers\\PaymentServiceProvider",
|
"Modules\\Core\\Providers\\PaymentServiceProvider",
|
||||||
"Modules\\Core\\Providers\\LocalizationServiceProvider",
|
"Modules\\Core\\Providers\\LocalizationServiceProvider",
|
||||||
"Modules\\Core\\Providers\\CatalogServiceProvider",
|
"Modules\\Core\\Providers\\CatalogServiceProvider",
|
||||||
"Modules\\Core\\Providers\\CartServiceProvider",
|
"Modules\\Core\\Providers\\CartServiceProvider",
|
||||||
"Modules\\Core\\Providers\\ReviewServiceProvider",
|
"Modules\\Core\\Providers\\ReviewServiceProvider",
|
||||||
"Modules\\Core\\Providers\\ShippingServiceProvider",
|
"Modules\\Core\\Providers\\ShippingServiceProvider",
|
||||||
"Modules\\Core\\Providers\\OrderServiceProvider"
|
"Modules\\Core\\Providers\\OrderServiceProvider",
|
||||||
|
"Modules\\Core\\Providers\\PrivacyServiceProvider"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -16,6 +16,43 @@ return [
|
|||||||
|
|
||||||
'auto_create_customer_for_user' => true,
|
'auto_create_customer_for_user' => true,
|
||||||
|
|
||||||
|
/*
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
| Privacy / GDPR data-subject requests
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| 'providers' lists every Modules\Core\Privacy\Contracts\PersonalDataProvider
|
||||||
|
| that should be consulted for right-of-access/right-of-erasure requests. A
|
||||||
|
| module never needs to be known to core in advance — it just adds its own
|
||||||
|
| provider class here, the same way config('lunar.search.indexers') maps a
|
||||||
|
| model to its indexer. See docs/privacy.md.
|
||||||
|
|
|
||||||
|
| 'grace_period_days' is how long an erasure request stays cancellable
|
||||||
|
| (account deactivated, not yet erased) before it's actually processed by
|
||||||
|
| the privacy:process-erasure-requests scheduled command.
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
|
||||||
|
'privacy' => [
|
||||||
|
'providers' => [
|
||||||
|
// ActivityLogDataProvider MUST run before AddressDataProvider —
|
||||||
|
// it resolves which activity_log rows belong to this customer
|
||||||
|
// (including ones keyed by an Address id) before
|
||||||
|
// AddressDataProvider hard-deletes those Address rows. See that
|
||||||
|
// provider's own class docblock.
|
||||||
|
\Modules\Core\Logging\Privacy\ActivityLogDataProvider::class,
|
||||||
|
\Modules\Core\Customer\Privacy\CustomerDataProvider::class,
|
||||||
|
\Modules\Core\Customer\Privacy\AddressDataProvider::class,
|
||||||
|
\Modules\Core\Order\Privacy\OrderDataProvider::class,
|
||||||
|
\Modules\Core\Cart\Privacy\CartDataProvider::class,
|
||||||
|
\Modules\Core\Review\Privacy\ReviewDataProvider::class,
|
||||||
|
\Modules\Core\Payment\Privacy\PaymentDataProvider::class,
|
||||||
|
\Modules\Core\Auth\Privacy\UserSessionDataProvider::class,
|
||||||
|
],
|
||||||
|
|
||||||
|
'grace_period_days' => 30,
|
||||||
|
],
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|--------------------------------------------------------------------------
|
|--------------------------------------------------------------------------
|
||||||
| Cart Abandonment Threshold
|
| Cart Abandonment Threshold
|
||||||
@@ -30,6 +67,64 @@ return [
|
|||||||
|
|
||||||
'cart' => [
|
'cart' => [
|
||||||
'abandoned_after' => '1 hour',
|
'abandoned_after' => '1 hour',
|
||||||
|
|
||||||
|
/*
|
||||||
|
|----------------------------------------------------------------------
|
||||||
|
| Unrecoverable Cap
|
||||||
|
|----------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| Beyond this age, a stale cart stops being treated as an active
|
||||||
|
| "Abandoned Cart"/"Abandoned Checkout" (Modules\Core\Cart\Services\
|
||||||
|
| CartLifecycleService) — too old to be a realistic recovery target
|
||||||
|
| (pricing/stock/tax likely stale by then). This is about the
|
||||||
|
| abandoned-cart pipeline only, not data retention — no rows are
|
||||||
|
| deleted or pruned based on this value.
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
|
||||||
|
'unrecoverable_after' => '90 days',
|
||||||
|
],
|
||||||
|
|
||||||
|
/*
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
| Order Return Window
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| How many days after a carrier order is delivered (Order::fulfillment_status
|
||||||
|
| becomes 'return_window_open') before Modules\Core\Order\Commands\
|
||||||
|
| CloseExpiredReturnWindows auto-completes it, if no return was requested.
|
||||||
|
| Store-pickup orders have no return-window step and are unaffected by
|
||||||
|
| this value (see Modules\Core\Order\Listeners\CompleteOrderOnPickedUp).
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
|
||||||
|
'order' => [
|
||||||
|
'return_window_days' => 14,
|
||||||
|
],
|
||||||
|
|
||||||
|
/*
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
| Storefront OTP Login
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| Modules\Core\Auth\Services\UserOtpService's passwordless login.
|
||||||
|
| max_attempts caps how many wrong codes a shopper can guess against ONE
|
||||||
|
| generated code before it's invalidated outright. generation_limit/
|
||||||
|
| generation_decay_minutes cap how often a NEW code can be requested for
|
||||||
|
| the same email — independent of max_attempts, since generating a fresh
|
||||||
|
| code also resets the guess count, so an attempt cap alone doesn't stop
|
||||||
|
| an attacker from just requesting a new code every few tries. This same
|
||||||
|
| limit is also what stands between a malicious/careless caller and
|
||||||
|
| mail-bombing one inbox.
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
|
||||||
|
'auth' => [
|
||||||
|
'otp' => [
|
||||||
|
'max_attempts' => 5,
|
||||||
|
'generation_limit' => 3,
|
||||||
|
'generation_decay_minutes' => 10,
|
||||||
|
],
|
||||||
],
|
],
|
||||||
|
|
||||||
];
|
];
|
||||||
|
|||||||
@@ -0,0 +1,21 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
return [
|
||||||
|
/*
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
| Policy versions
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| Plain version strings, bumped by whoever edits the corresponding legal
|
||||||
|
| page — recorded alongside every consent/acceptance so a later dispute
|
||||||
|
| ("what did the shopper actually agree to?") can be answered from the
|
||||||
|
| order/cart itself rather than a live lookup against whatever the pages
|
||||||
|
| say TODAY. Not tied to any CMS/database row on purpose — this stays a
|
||||||
|
| plain config value the same way payment.php's cart_pipeline is a plain
|
||||||
|
| cross-cutting setting, not a per-instance one.
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
'privacy_policy_version' => env('LEGAL_PRIVACY_POLICY_VERSION', '2026-01-01'),
|
||||||
|
|
||||||
|
'terms_version' => env('LEGAL_TERMS_VERSION', '2026-01-01'),
|
||||||
|
];
|
||||||
+13
-33
@@ -1,48 +1,28 @@
|
|||||||
<?php
|
<?php
|
||||||
|
|
||||||
use Modules\Core\Payment\Drivers\OfflinePaymentDriver;
|
use Modules\Core\Payment\Pipelines\Cart\ApplyPaymentMethodFee;
|
||||||
use Modules\Core\Payment\Pipelines\Cart\ApplyCashOnDeliveryFee;
|
|
||||||
|
|
||||||
return [
|
return [
|
||||||
/*
|
|
||||||
|--------------------------------------------------------------------------
|
|
||||||
| Lunar payment types merged in by Boboko Core
|
|
||||||
|--------------------------------------------------------------------------
|
|
||||||
|
|
|
||||||
| These are merged into config('lunar.payments.types') so every app using
|
|
||||||
| boboko-core gets cash-on-delivery out of the box, without publishing
|
|
||||||
| Lunar's own config.
|
|
||||||
|
|
|
||||||
| 'payment_driver' is boboko-owned, alongside Lunar's own 'driver' key —
|
|
||||||
| the driver instance Modules\Core\Payment\Services\PaymentDriverResolver
|
|
||||||
| resolves via the container. 'capture_mode' ('pay' or 'authorize') is
|
|
||||||
| also boboko-owned — which contract method
|
|
||||||
| CheckoutService::initiatePayment() calls for this type. Kept on the
|
|
||||||
| same row as 'driver' rather than a second, separately-keyed map, so a
|
|
||||||
| type's full definition lives in one place.
|
|
||||||
|
|
|
||||||
*/
|
|
||||||
'types' => [
|
|
||||||
'cash-on-delivery' => [
|
|
||||||
'driver' => 'offline',
|
|
||||||
'payment_driver' => OfflinePaymentDriver::class,
|
|
||||||
'capture_mode' => 'pay',
|
|
||||||
'captured_status' => 'payment-offline',
|
|
||||||
'fee' => 0,
|
|
||||||
],
|
|
||||||
],
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|--------------------------------------------------------------------------
|
|--------------------------------------------------------------------------
|
||||||
| Lunar cart pipeline additions
|
| Lunar cart pipeline additions
|
||||||
|--------------------------------------------------------------------------
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
|
||||||
| Appended to config('lunar.cart.pipelines.cart') after ApplyShipping so
|
| Appended to config('lunar.cart.pipelines.cart') after ApplyShipping so
|
||||||
| the cash-on-delivery fee is added to the shipping total before the
|
| the selected payment method's own fee (if any) is added to the
|
||||||
| final Calculate step sums everything up.
|
| shipping total before the final Calculate step sums everything up.
|
||||||
|
|
|
||||||
|
| This is the one thing left in this file — everything about WHICH
|
||||||
|
| payment methods exist (driver mapping, capture_mode, statuses) moved
|
||||||
|
| onto Modules\Core\Payment\Models\PaymentMethod's own row (see
|
||||||
|
| docs/payments.md): that's a per-instance, merchant decision, not a
|
||||||
|
| store-wide-singular setting, so it never belonged in config at all.
|
||||||
|
| This pipeline registration IS genuinely cross-cutting — every store
|
||||||
|
| using this driver gets the same cart-pipeline wiring, regardless of
|
||||||
|
| how many payment methods it configures.
|
||||||
|
|
|
|
||||||
*/
|
*/
|
||||||
'cart_pipeline' => [
|
'cart_pipeline' => [
|
||||||
ApplyCashOnDeliveryFee::class,
|
ApplyPaymentMethodFee::class,
|
||||||
],
|
],
|
||||||
];
|
];
|
||||||
|
|||||||
@@ -0,0 +1,22 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->timestamp('deactivated_at')->nullable()->after('otp_expires_at');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('deactivated_at');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,56 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('data_erasure_requests', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
// Polymorphic, not a fixed customer_id — a request targets either a
|
||||||
|
// Lunar Customer (business account) or a User (individual), never
|
||||||
|
// both at once. See docs/privacy.md "User-scope vs Customer-scope".
|
||||||
|
$table->string('subject_type');
|
||||||
|
$table->unsignedBigInteger('subject_id');
|
||||||
|
// Snapshot, not a live-looked-up value — the subject's email may
|
||||||
|
// change or the record may be gone by the time this is read.
|
||||||
|
$table->string('email')->nullable();
|
||||||
|
// Who asked for this: the subject themselves (self-service deletion)
|
||||||
|
// or a staff member acting on their behalf. Plain nullable type+id
|
||||||
|
// columns rather than morphs() — only ever one of two concrete actor
|
||||||
|
// types, not an open-ended polymorphic set.
|
||||||
|
$table->string('requested_by_type');
|
||||||
|
$table->unsignedBigInteger('requested_by_id');
|
||||||
|
$table->string('status')->default('pending');
|
||||||
|
// Set only on a Customer-scoped request that was auto-created because
|
||||||
|
// erasing a User left them as the sole remaining user on that Customer
|
||||||
|
// (see Modules\Core\Privacy\Listeners\CascadeCustomerErasureListener).
|
||||||
|
// Null for every normal, directly-requested erasure. Lets login-
|
||||||
|
// reactivation find and revert exactly the Customer request THIS
|
||||||
|
// User's cancellation caused, without touching an unrelated,
|
||||||
|
// independently-requested Customer erasure the User happens to be
|
||||||
|
// linked to.
|
||||||
|
$table->foreignId('caused_by_request_id')->nullable()->constrained('data_erasure_requests')->nullOnDelete();
|
||||||
|
// now() + config('core.privacy.grace_period_days') at creation time —
|
||||||
|
// when privacy:process-erasure-requests will actually run this.
|
||||||
|
$table->timestamp('scheduled_for');
|
||||||
|
$table->timestamp('cancelled_at')->nullable();
|
||||||
|
$table->timestamp('completed_at')->nullable();
|
||||||
|
// Every provider's outcome, written once the request completes —
|
||||||
|
// see Modules\Core\Privacy\ErasureReport. Null until then.
|
||||||
|
$table->json('report')->nullable();
|
||||||
|
$table->timestamps();
|
||||||
|
|
||||||
|
$table->index(['status', 'scheduled_for']);
|
||||||
|
$table->index(['subject_type', 'subject_id']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('data_erasure_requests');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('data_export_requests', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
// Polymorphic, not a fixed customer_id — see data_erasure_requests
|
||||||
|
// for the same shape and reasoning.
|
||||||
|
$table->string('subject_type');
|
||||||
|
$table->unsignedBigInteger('subject_id');
|
||||||
|
// Snapshot, not a live lookup — same reasoning as
|
||||||
|
// data_erasure_requests.email (see that migration).
|
||||||
|
$table->string('email')->nullable();
|
||||||
|
$table->string('status')->default('pending');
|
||||||
|
// Storage path of the assembled export .zip, set once the queued job
|
||||||
|
// finishes. Null while pending.
|
||||||
|
$table->string('file_path')->nullable();
|
||||||
|
$table->timestamp('completed_at')->nullable();
|
||||||
|
$table->timestamps();
|
||||||
|
|
||||||
|
$table->index('status');
|
||||||
|
$table->index(['subject_type', 'subject_id']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('data_export_requests');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,46 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
use Lunar\Base\Migration;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* First-party copy of lunarphp/stripe's own create_stripe_payment_intents_table
|
||||||
|
* migration (package removed in favour of depending on stripe/stripe-php
|
||||||
|
* directly — see Modules\Core\Payment\Support\StripeManager and
|
||||||
|
* Modules\Core\Payment\Models\StripePaymentIntent, which replace the
|
||||||
|
* package's own classes over this same table). Timestamped to run just
|
||||||
|
* before this app's own add_context_to_stripe_payment_intents migration,
|
||||||
|
* which already alters this table.
|
||||||
|
*
|
||||||
|
* Guarded with hasTable(): on any environment that already ran
|
||||||
|
* lunarphp/stripe's own copy of this migration before the package was
|
||||||
|
* removed, the table already exists — this migration is only the one that
|
||||||
|
* actually creates it on a fresh install/database from now on.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
if (Schema::hasTable($this->prefix.'stripe_payment_intents')) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
Schema::create($this->prefix.'stripe_payment_intents', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
$table->foreignId('cart_id')->constrained($this->prefix.'carts');
|
||||||
|
$table->foreignId('order_id')->nullable()->constrained($this->prefix.'orders');
|
||||||
|
$table->string('intent_id')->index();
|
||||||
|
$table->string('status')->nullable();
|
||||||
|
$table->string('event_id')->index()->nullable();
|
||||||
|
$table->timestamp('processing_at')->nullable();
|
||||||
|
$table->timestamp('processed_at')->nullable();
|
||||||
|
$table->timestamps();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists($this->prefix.'stripe_payment_intents');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,52 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Moves the driver mapping and per-type behavior that used to live in
|
||||||
|
* config('lunar.payments.types.{type}.*') onto the PaymentMethod row
|
||||||
|
* itself — same DB-instance-vs-config split Modules\Core\Shipping's own
|
||||||
|
* shipping_methods table already has (code/driver/name/enabled columns,
|
||||||
|
* no driver mapping in any config file). See docs/payments.md.
|
||||||
|
*
|
||||||
|
* - driver: the Modules\Core\Payment\Services\PaymentDriverRegistry key
|
||||||
|
* (NOT the same as `type` — two rows can share one driver).
|
||||||
|
* - name: admin-facing label. Nothing played this role before; `type`
|
||||||
|
* was always the machine slug.
|
||||||
|
* - capture_mode / captured_status / authorized_status: per-instance
|
||||||
|
* behavior — fails the "would a store ever want two different answers
|
||||||
|
* to this" cross-cutting-config test, so these move off config.
|
||||||
|
* - position: admin-controlled display/checkout order.
|
||||||
|
* - driver_missing_at: set by the payment:sync-drivers command when
|
||||||
|
* `driver` no longer resolves via the registry — deliberately
|
||||||
|
* separate from `enabled`, so a driver vanishing (a deploy removed
|
||||||
|
* it) is never confused with an admin's own manual toggle, and a
|
||||||
|
* driver that comes back later auto-clears this with no admin action.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('payment_methods', function (Blueprint $table) {
|
||||||
|
$table->string('name')->nullable()->after('type');
|
||||||
|
$table->string('driver')->nullable()->after('name');
|
||||||
|
$table->string('capture_mode')->nullable()->after('driver');
|
||||||
|
$table->string('captured_status')->nullable()->after('capture_mode');
|
||||||
|
$table->string('authorized_status')->nullable()->after('captured_status');
|
||||||
|
$table->unsignedInteger('position')->default(0)->after('authorized_status');
|
||||||
|
$table->timestamp('driver_missing_at')->nullable()->after('position');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('payment_methods', function (Blueprint $table) {
|
||||||
|
$table->dropColumn([
|
||||||
|
'name', 'driver', 'capture_mode', 'captured_status',
|
||||||
|
'authorized_status', 'position', 'driver_missing_at',
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,38 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* captured_status/authorized_status (added in 2026_09_05_000001) cover a
|
||||||
|
* payment being taken, but nothing wrote Order.status on a REFUND —
|
||||||
|
* Order::paymentStatus() (Order\Support\OrderStatus::payment(), derived
|
||||||
|
* live from transactions) already reflects a refund correctly, but the
|
||||||
|
* stored status column — the one admin filtering, customer emails, etc.
|
||||||
|
* actually key off — never moved. Same reasoning as captured_status/
|
||||||
|
* authorized_status: a store could plausibly want a different resulting
|
||||||
|
* status per payment method (e.g. a "Refunded" vs. a "Refund Pending"
|
||||||
|
* variant), so this is a PaymentMethod column, not cross-cutting config.
|
||||||
|
*
|
||||||
|
* Deliberately no separate void_status — void never moved money (it
|
||||||
|
* releases an authorization hold before any capture), so it doesn't carry
|
||||||
|
* the same "the customer needs to see this changed" weight a refund does;
|
||||||
|
* add one later if a real need for it shows up.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('payment_methods', function (Blueprint $table) {
|
||||||
|
$table->string('refunded_status')->nullable()->after('authorized_status');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('payment_methods', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('refunded_status');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Splits Lunar's single flat `status` column into three independently
|
||||||
|
* tracked axes — payment, fulfillment, return — so a payment refund and a
|
||||||
|
* fulfillment dispatch stop racing to write the same field, and each axis
|
||||||
|
* can be filtered/queried directly instead of overloading one string for
|
||||||
|
* three unrelated concerns. See Modules\Core\Order\Enums\OrderPaymentStatus/
|
||||||
|
* OrderFulfillmentStatus/OrderReturnStatus for the value vocabularies, and
|
||||||
|
* Modules\Core\Order\Listeners\ApplyResolvedPaymentStatus and friends for
|
||||||
|
* where these columns actually get written. `status` itself is left in
|
||||||
|
* place, unchanged — Lunar core still reads/writes it in places this
|
||||||
|
* package doesn't own — but nothing in this package's business logic keys
|
||||||
|
* off it anymore after this migration's consumers land.
|
||||||
|
*
|
||||||
|
* lunar_customers already has a direct precedent for a boboko-core
|
||||||
|
* migration altering a Lunar-owned table (see
|
||||||
|
* 2026_07_02_000002_drop_otp_from_lunar_customers_table.php) — this is not
|
||||||
|
* a new pattern for this codebase, just the first time it's applied to
|
||||||
|
* lunar_orders.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('lunar_orders', function (Blueprint $table) {
|
||||||
|
$table->string('payment_status')->default('awaiting_payment')->after('status')->index();
|
||||||
|
$table->string('fulfillment_status')->default('unfulfilled')->after('payment_status')->index();
|
||||||
|
$table->string('return_status')->default('none')->after('fulfillment_status')->index();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('lunar_orders', function (Blueprint $table) {
|
||||||
|
$table->dropColumn(['payment_status', 'fulfillment_status', 'return_status']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Append-only audit trail for Order's three status axes (see
|
||||||
|
* 2026_09_11_000001_add_status_axes_to_orders_table.php) — the thing
|
||||||
|
* `Lunar\Models\Order::getDefaultLogExcept()` explicitly denies (`status`
|
||||||
|
* is excluded from Lunar's own Spatie activity log), so this is a
|
||||||
|
* from-scratch mechanism, not a gap in an existing one.
|
||||||
|
*
|
||||||
|
* No `updated_at` — a row is never edited after it's written, only ever
|
||||||
|
* inserted. `event_class` is the FQCN of whatever business event/action
|
||||||
|
* caused the write (e.g. Modules\Core\Order\Events\OrderDispatched, or a
|
||||||
|
* plain string like 'Modules\Core\Shipping\Extensions\OrderViewExtension::
|
||||||
|
* markDispatchedAction' for a manual Filament action that has no backing
|
||||||
|
* event class of its own) — see Modules\Core\Order\Services\
|
||||||
|
* OrderStatusTransitionRecorder.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('order_status_transitions', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
$table->foreignId('order_id')->constrained('lunar_orders')->cascadeOnDelete();
|
||||||
|
$table->string('axis');
|
||||||
|
$table->string('from_status')->nullable();
|
||||||
|
$table->string('to_status');
|
||||||
|
$table->string('event_class');
|
||||||
|
$table->timestamp('created_at')->useCurrent();
|
||||||
|
$table->index(['order_id', 'axis']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('order_status_transitions');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,79 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Illuminate\Support\Facades\Log;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Modules\Core\Order\Enums\PaymentStatus;
|
||||||
|
use Modules\Core\Order\Support\OrderStatus;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Maps every existing order's flat `status` (as it stood before
|
||||||
|
* 2026_09_11_000001_add_status_axes_to_orders_table.php) onto the new
|
||||||
|
* payment_status/fulfillment_status/return_status columns. A separate
|
||||||
|
* migration from the schema change so the schema migration stays simply
|
||||||
|
* reversible via down(), and this data pass can be independently re-run.
|
||||||
|
*
|
||||||
|
* The flat status never captured refunds at all (no 'refunded' value was
|
||||||
|
* ever added to config('lunar.orders.statuses')), so the table-driven
|
||||||
|
* mapping below is corrected per-order by re-deriving
|
||||||
|
* Modules\Core\Order\Support\OrderStatus::payment() — the existing,
|
||||||
|
* unchanged derived-enum logic — and overriding payment_status to
|
||||||
|
* refunded/partially_refunded wherever it disagrees with the flat-status
|
||||||
|
* mapping. This is the one place the "keep the old derived enums" design
|
||||||
|
* decision earns its keep: refund-fraction math isn't reimplemented here,
|
||||||
|
* just reused.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
private const MAP = [
|
||||||
|
'awaiting-payment' => ['payment_status' => 'awaiting_payment', 'fulfillment_status' => 'unfulfilled'],
|
||||||
|
'payment-offline' => ['payment_status' => 'awaiting_payment', 'fulfillment_status' => 'unfulfilled'],
|
||||||
|
'payment-received' => ['payment_status' => 'paid', 'fulfillment_status' => 'unfulfilled'],
|
||||||
|
'ready-for-dispatch' => ['payment_status' => 'paid', 'fulfillment_status' => 'ready'],
|
||||||
|
'ready-for-pickup' => ['payment_status' => 'paid', 'fulfillment_status' => 'ready'],
|
||||||
|
'dispatched' => ['payment_status' => 'paid', 'fulfillment_status' => 'in_transit'],
|
||||||
|
'completed' => ['payment_status' => 'paid', 'fulfillment_status' => 'completed'],
|
||||||
|
];
|
||||||
|
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Order::query()->with('transactions')->chunkById(200, function ($orders) {
|
||||||
|
foreach ($orders as $order) {
|
||||||
|
$mapped = self::MAP[$order->status] ?? null;
|
||||||
|
|
||||||
|
if ($mapped === null) {
|
||||||
|
Log::warning('Order status axis backfill: unmapped status, leaving column defaults', [
|
||||||
|
'order_id' => $order->id,
|
||||||
|
'status' => $order->status,
|
||||||
|
]);
|
||||||
|
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
$paymentStatus = $mapped['payment_status'];
|
||||||
|
|
||||||
|
$derived = OrderStatus::payment($order);
|
||||||
|
|
||||||
|
if ($derived === PaymentStatus::Refunded) {
|
||||||
|
$paymentStatus = 'refunded';
|
||||||
|
} elseif ($derived === PaymentStatus::PartialRefund) {
|
||||||
|
$paymentStatus = 'partially_refunded';
|
||||||
|
}
|
||||||
|
|
||||||
|
DB::table('lunar_orders')->where('id', $order->id)->update([
|
||||||
|
'payment_status' => $paymentStatus,
|
||||||
|
'fulfillment_status' => $mapped['fulfillment_status'],
|
||||||
|
'return_status' => 'none',
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
// Column defaults (set in the schema migration) are the correct
|
||||||
|
// "undo" — no need to reverse-map back to the flat status, since
|
||||||
|
// `status` itself was never touched by this migration.
|
||||||
|
}
|
||||||
|
};
|
||||||
+36
@@ -0,0 +1,36 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* captured_status/authorized_status/refunded_status let a merchant pick
|
||||||
|
* which per-method Order::status label a payment outcome resulted in — a
|
||||||
|
* mechanism that only made sense while Order.status was the single field
|
||||||
|
* carrying that meaning. Modules\Core\Order\Listeners\
|
||||||
|
* ApplyResolvedPaymentStatus now writes a fixed 3-value payment_status
|
||||||
|
* column instead (see 2026_09_11_000001_add_status_axes_to_orders_table.php);
|
||||||
|
* there is no longer any per-method flexibility to preserve — "paid" is
|
||||||
|
* "paid" regardless of which method captured it. Dropped rather than left
|
||||||
|
* vestigial: keeping them visible in the admin would let a merchant
|
||||||
|
* configure something that silently does nothing.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('payment_methods', function (Blueprint $table) {
|
||||||
|
$table->dropColumn(['captured_status', 'authorized_status', 'refunded_status']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('payment_methods', function (Blueprint $table) {
|
||||||
|
$table->string('captured_status')->nullable();
|
||||||
|
$table->string('authorized_status')->nullable();
|
||||||
|
$table->string('refunded_status')->nullable();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Order::paid/paid_at — entirely independent of the `status` column (see
|
||||||
|
* Modules\Core\Order\Services\OrderStatusFlow's own docblock for why
|
||||||
|
* payment timing, especially for cash-on-delivery, cannot be modeled as a
|
||||||
|
* status-sequence step). `paid` is the fast-filter boolean; `paid_at` is
|
||||||
|
* when it actually happened.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('lunar_orders', function (Blueprint $table) {
|
||||||
|
$table->boolean('paid')->default(false)->after('status')->index();
|
||||||
|
$table->timestamp('paid_at')->nullable()->after('paid');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('lunar_orders', function (Blueprint $table) {
|
||||||
|
$table->dropColumn(['paid', 'paid_at']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,116 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Illuminate\Support\Facades\Log;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Modules\Core\Order\Enums\PaymentStatus;
|
||||||
|
use Modules\Core\Order\Support\OrderStatus;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Collapses the 3-axis (payment_status/fulfillment_status/return_status)
|
||||||
|
* model this session briefly built — abandoned before shipping — back
|
||||||
|
* onto a single `status` column plus the new independent `paid`/`paid_at`
|
||||||
|
* fields. Must run after 2026_09_12_000001 (adds paid/paid_at) and before
|
||||||
|
* 2026_09_12_000003 (drops the axis columns this migration still reads).
|
||||||
|
*
|
||||||
|
* Priority rule: axis data where it's genuinely non-default (this order
|
||||||
|
* was really moved through the axis system during this session's manual
|
||||||
|
* testing); the legacy `status` column (which may still hold pre-session
|
||||||
|
* hyphenated values) as fallback everywhere else.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
private const LEGACY_MAP = [
|
||||||
|
'awaiting-payment' => 'awaiting_payment',
|
||||||
|
'payment-offline' => 'awaiting_payment',
|
||||||
|
'payment-received' => 'processing',
|
||||||
|
'ready-for-dispatch' => 'ready_for_dispatch',
|
||||||
|
'ready-for-pickup' => 'ready_for_pickup',
|
||||||
|
'dispatched' => 'dispatched',
|
||||||
|
'completed' => 'completed',
|
||||||
|
];
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Axis fulfillment_status -> new single status, given branch. Axis
|
||||||
|
* 'delivered' folds into 'return_window_open' (same combined-value
|
||||||
|
* decision the going-forward design makes). Axis payment_status is
|
||||||
|
* used only to decide whether a fully-unfulfilled order should read
|
||||||
|
* as 'awaiting_payment' or 'processing'.
|
||||||
|
*/
|
||||||
|
private function mapFromAxes(string $payment, string $fulfillment, string $return, bool $isPickup): ?string
|
||||||
|
{
|
||||||
|
if ($return === 'returned') {
|
||||||
|
return 'returned';
|
||||||
|
}
|
||||||
|
if ($return === 'requested') {
|
||||||
|
return 'return_requested';
|
||||||
|
}
|
||||||
|
|
||||||
|
return match ($fulfillment) {
|
||||||
|
'unfulfilled' => $payment === 'paid' ? 'processing' : 'awaiting_payment',
|
||||||
|
'processing' => 'processing',
|
||||||
|
'ready' => $isPickup ? 'ready_for_pickup' : 'ready_for_dispatch',
|
||||||
|
'in_transit' => 'dispatched',
|
||||||
|
'delivered', 'return_window_open' => 'return_window_open',
|
||||||
|
'picked_up' => 'picked_up',
|
||||||
|
'completed' => 'completed',
|
||||||
|
default => null,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Order::query()->with('transactions')->chunkById(200, function ($orders) {
|
||||||
|
foreach ($orders as $order) {
|
||||||
|
$isPickup = $order->isStorePickupOrder();
|
||||||
|
|
||||||
|
$axisIsDefault = $order->payment_status === 'awaiting_payment'
|
||||||
|
&& $order->fulfillment_status === 'unfulfilled'
|
||||||
|
&& $order->return_status === 'none';
|
||||||
|
|
||||||
|
$status = $axisIsDefault
|
||||||
|
? (self::LEGACY_MAP[$order->status] ?? null)
|
||||||
|
: $this->mapFromAxes($order->payment_status, $order->fulfillment_status, $order->return_status, $isPickup);
|
||||||
|
|
||||||
|
if ($status === null) {
|
||||||
|
Log::warning('Single-status backfill: unmapped order, defaulting to awaiting_payment', [
|
||||||
|
'order_id' => $order->id,
|
||||||
|
'status' => $order->status,
|
||||||
|
'payment_status' => $order->payment_status,
|
||||||
|
'fulfillment_status' => $order->fulfillment_status,
|
||||||
|
'return_status' => $order->return_status,
|
||||||
|
]);
|
||||||
|
$status = 'awaiting_payment';
|
||||||
|
}
|
||||||
|
|
||||||
|
$derived = OrderStatus::payment($order);
|
||||||
|
$paid = $order->payment_status === 'paid'
|
||||||
|
|| in_array($derived, [PaymentStatus::Captured, PaymentStatus::Refunded, PaymentStatus::PartialRefund], true);
|
||||||
|
|
||||||
|
// A refund implies the order concluded via a return —
|
||||||
|
// even one backfilled to an early status (e.g. an order
|
||||||
|
// refunded before fulfillment ever started) is corrected
|
||||||
|
// to refunded/partially_refunded here, not left stuck
|
||||||
|
// pre-fulfillment with no sign a refund ever happened.
|
||||||
|
if ($derived === PaymentStatus::Refunded) {
|
||||||
|
$status = 'refunded';
|
||||||
|
} elseif ($derived === PaymentStatus::PartialRefund) {
|
||||||
|
$status = 'partially_refunded';
|
||||||
|
}
|
||||||
|
|
||||||
|
DB::table('lunar_orders')->where('id', $order->id)->update([
|
||||||
|
'status' => $status,
|
||||||
|
'paid' => $paid,
|
||||||
|
'paid_at' => $paid ? ($order->placed_at ?? now()) : null,
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
// No reverse mapping — column defaults (post-rollback of the
|
||||||
|
// schema migrations) are the correct "undo".
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,34 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Reverses 2026_09_11_000001_add_status_axes_to_orders_table.php — the
|
||||||
|
* 3-axis model was abandoned before shipping in favor of a single
|
||||||
|
* `status` column plus independent `paid`/`paid_at` (see
|
||||||
|
* 2026_09_12_000001/000002). Must run after 2026_09_12_000002, which
|
||||||
|
* still reads these columns for the backfill.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('lunar_orders', function (Blueprint $table) {
|
||||||
|
$table->dropColumn(['payment_status', 'fulfillment_status', 'return_status']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
// Mirrors 2026_09_11_000001's own down() — restores columns
|
||||||
|
// empty/defaulted, does not attempt to resurrect real per-order
|
||||||
|
// values.
|
||||||
|
Schema::table('lunar_orders', function (Blueprint $table) {
|
||||||
|
$table->string('payment_status')->default('awaiting_payment')->after('paid_at')->index();
|
||||||
|
$table->string('fulfillment_status')->default('unfulfilled')->after('payment_status')->index();
|
||||||
|
$table->string('return_status')->default('none')->after('fulfillment_status')->index();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
+33
@@ -0,0 +1,33 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* There is only one status column left to audit (plus the synthetic
|
||||||
|
* 'paid' entry — see Modules\Core\Order\Listeners\RecordStatusTransition),
|
||||||
|
* so the `axis` column this table was created with
|
||||||
|
* (2026_09_11_000002_create_order_status_transitions_table.php) no longer
|
||||||
|
* means anything.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('order_status_transitions', function (Blueprint $table) {
|
||||||
|
$table->dropIndex(['order_id', 'axis']);
|
||||||
|
$table->dropColumn('axis');
|
||||||
|
$table->index('order_id');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('order_status_transitions', function (Blueprint $table) {
|
||||||
|
$table->dropIndex(['order_id']);
|
||||||
|
$table->string('axis')->default('status')->after('order_id');
|
||||||
|
$table->index(['order_id', 'axis']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
+27
@@ -0,0 +1,27 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The seeded 'cash-on-delivery' PaymentMethod row
|
||||||
|
* (Modules\Core\Command\InstallLunarCommand::seedPaymentMethods()) was
|
||||||
|
* wired to driver => 'offline' — the same immediate-capture driver as
|
||||||
|
* cash-in-hand. That's the bug that made COD "pay immediately" instead of
|
||||||
|
* waiting for staff to confirm cash was actually received. Repoints
|
||||||
|
* already-seeded environments to the new dedicated
|
||||||
|
* Modules\Core\Payment\Drivers\CashOnDeliveryPaymentDriver; the seeder
|
||||||
|
* itself is fixed separately for fresh installs.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
DB::table('payment_methods')->where('type', 'cash-on-delivery')->update(['driver' => 'cash-on-delivery']);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
DB::table('payment_methods')->where('type', 'cash-on-delivery')->update(['driver' => 'offline']);
|
||||||
|
}
|
||||||
|
};
|
||||||
+30
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* 'return_window_open' is renamed to 'delivered' — same status value,
|
||||||
|
* same meaning (the parcel arrived AND the return window is now open,
|
||||||
|
* still one combined moment — see Modules\Core\Order\Listeners\
|
||||||
|
* AdvanceFulfillmentOnDelivered), just a name a merchant expects to read
|
||||||
|
* on the order page rather than an internal mechanic. Also renames it in
|
||||||
|
* order_status_transitions' audit rows so the history stays consistent
|
||||||
|
* with `status` going forward.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
DB::table('lunar_orders')->where('status', 'return_window_open')->update(['status' => 'delivered']);
|
||||||
|
DB::table('order_status_transitions')->where('from_status', 'return_window_open')->update(['from_status' => 'delivered']);
|
||||||
|
DB::table('order_status_transitions')->where('to_status', 'return_window_open')->update(['to_status' => 'delivered']);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
DB::table('lunar_orders')->where('status', 'delivered')->update(['status' => 'return_window_open']);
|
||||||
|
DB::table('order_status_transitions')->where('from_status', 'delivered')->update(['from_status' => 'return_window_open']);
|
||||||
|
DB::table('order_status_transitions')->where('to_status', 'delivered')->update(['to_status' => 'return_window_open']);
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A real record of "a manifest was issued", not just a loose
|
||||||
|
* manifest_reference string stamped onto each Shipment row — ACS's own
|
||||||
|
* ACS_Issue_Pickup_List call returns nothing beyond a PickupList_No (see
|
||||||
|
* Modules\Core\Shipping\Carriers\Acs\AcsFulfillmentService::issueManifest()),
|
||||||
|
* so this table is entirely our own bookkeeping: when the manifest was
|
||||||
|
* issued and how many shipments it included, not something re-derivable
|
||||||
|
* from the carrier later. `shipment_count` is denormalized (also
|
||||||
|
* countable via shipments()->count()) purely so the manifests list can
|
||||||
|
* render without an extra query per row.
|
||||||
|
*
|
||||||
|
* carrier-agnostic by design — see Modules\Core\Shipping\Contracts\
|
||||||
|
* SupportsManifestBatching, the same contract any future carrier
|
||||||
|
* (Speedex, etc.) implements to get manifest batching at all; this table
|
||||||
|
* has no ACS-specific columns.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('manifests', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
$table->string('carrier');
|
||||||
|
$table->string('reference');
|
||||||
|
$table->unsignedInteger('shipment_count')->default(0);
|
||||||
|
$table->timestamp('issued_at');
|
||||||
|
$table->timestamps();
|
||||||
|
|
||||||
|
$table->unique(['carrier', 'reference']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('manifests');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,82 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Replaces the loose manifest_reference string with a real manifests
|
||||||
|
* relation — see 2026_09_13_000002_create_manifests_table.php. Backfills
|
||||||
|
* one Manifest row per distinct (carrier, manifest_reference) pair
|
||||||
|
* already present in shipments, using the earliest label_printed_at (or
|
||||||
|
* updated_at as a fallback) among that group as a best-effort issued_at,
|
||||||
|
* since the exact original issue time was never recorded anywhere.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('shipments', function (Blueprint $table) {
|
||||||
|
$table->foreignId('manifest_id')->nullable()->after('manifest_reference')->constrained()->nullOnDelete();
|
||||||
|
});
|
||||||
|
|
||||||
|
$groups = DB::table('shipments')
|
||||||
|
->select('carrier', 'manifest_reference')
|
||||||
|
->whereNotNull('manifest_reference')
|
||||||
|
->distinct()
|
||||||
|
->get();
|
||||||
|
|
||||||
|
foreach ($groups as $group) {
|
||||||
|
$shipments = DB::table('shipments')
|
||||||
|
->where('carrier', $group->carrier)
|
||||||
|
->where('manifest_reference', $group->manifest_reference)
|
||||||
|
->get();
|
||||||
|
|
||||||
|
$issuedAt = $shipments->pluck('label_printed_at')->filter()->min()
|
||||||
|
?? $shipments->pluck('updated_at')->min();
|
||||||
|
|
||||||
|
$manifestId = DB::table('manifests')->insertGetId([
|
||||||
|
'carrier' => $group->carrier,
|
||||||
|
'reference' => $group->manifest_reference,
|
||||||
|
'shipment_count' => $shipments->count(),
|
||||||
|
'issued_at' => $issuedAt,
|
||||||
|
'created_at' => $issuedAt,
|
||||||
|
'updated_at' => $issuedAt,
|
||||||
|
]);
|
||||||
|
|
||||||
|
DB::table('shipments')
|
||||||
|
->where('carrier', $group->carrier)
|
||||||
|
->where('manifest_reference', $group->manifest_reference)
|
||||||
|
->update(['manifest_id' => $manifestId]);
|
||||||
|
}
|
||||||
|
|
||||||
|
Schema::table('shipments', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('manifest_reference');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('shipments', function (Blueprint $table) {
|
||||||
|
$table->string('manifest_reference')->nullable()->after('parent_reference');
|
||||||
|
});
|
||||||
|
|
||||||
|
DB::table('shipments')
|
||||||
|
->whereNotNull('manifest_id')
|
||||||
|
->orderBy('id')
|
||||||
|
->each(function ($shipment) {
|
||||||
|
$manifest = DB::table('manifests')->find($shipment->manifest_id);
|
||||||
|
|
||||||
|
if ($manifest) {
|
||||||
|
DB::table('shipments')->where('id', $shipment->id)->update([
|
||||||
|
'manifest_reference' => $manifest->reference,
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
Schema::table('shipments', function (Blueprint $table) {
|
||||||
|
$table->dropConstrainedForeignId('manifest_id');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Caps brute-forcing a 6-digit OTP code (1M combinations, 10-minute
|
||||||
|
* window, previously uncapped) — see Modules\Core\Auth\Services\
|
||||||
|
* UserOtpService::validate(), which now invalidates the code entirely
|
||||||
|
* (forcing a fresh generateAndSend()) once otp_attempts reaches its max,
|
||||||
|
* rather than leaving a live code guessable indefinitely within its
|
||||||
|
* expiry window.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->unsignedTinyInteger('otp_attempts')->default(0)->after('otp_expires_at');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('otp_attempts');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A per-login session registry, independent of the actual session store
|
||||||
|
* driver (SESSION_DRIVER=redis in this app — no "sessions" table to
|
||||||
|
* purge by user_id the way the database driver would allow). Each
|
||||||
|
* successful OTP login (Modules\Core\Auth\Services\UserOtpService::
|
||||||
|
* validate()) records one row here and stamps the token into the
|
||||||
|
* Laravel session payload; Modules\Core\Auth\Http\Middleware\
|
||||||
|
* EnsureSessionNotRevoked checks it on every request. "Logout
|
||||||
|
* everywhere" (Modules\Core\Auth\Services\UserSessionService::
|
||||||
|
* revokeOtherSessions()) is then just marking every OTHER row
|
||||||
|
* revoked_at, no session-store-specific logic anywhere.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('user_sessions', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
$table->foreignId('user_id')->constrained()->cascadeOnDelete();
|
||||||
|
$table->string('token', 64)->unique();
|
||||||
|
$table->string('user_agent')->nullable();
|
||||||
|
$table->string('ip_address', 45)->nullable();
|
||||||
|
$table->timestamp('last_used_at');
|
||||||
|
$table->timestamp('revoked_at')->nullable();
|
||||||
|
$table->timestamps();
|
||||||
|
|
||||||
|
$table->index(['user_id', 'revoked_at']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('user_sessions');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,65 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Lunar\Models\Language;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* PaymentMethod.name becomes a locale-keyed JSON array (e.g.
|
||||||
|
* {"en": "Cash On Delivery", "el": "Αντικαταβολή"}), rendered in Filament
|
||||||
|
* via Lunar's own Lunar\Admin\Support\Forms\Components\TranslatedText —
|
||||||
|
* the same reusable component/data-shape Product/Collection names already
|
||||||
|
* use (Lunar\Base\Traits\HasTranslations), just applied directly to a
|
||||||
|
* plain column here rather than through attribute_data, since
|
||||||
|
* PaymentMethod is a merchant-configured settings row, not a translatable
|
||||||
|
* catalog attribute.
|
||||||
|
*
|
||||||
|
* Existing plain-string rows are preserved under the store's default
|
||||||
|
* Language code (falls back to 'en' if no Language row exists yet — this
|
||||||
|
* migration can run before lunar:install seeds one) rather than dropped,
|
||||||
|
* so an already-configured payment method's name isn't blanked out.
|
||||||
|
*
|
||||||
|
* Uses a raw `ALTER COLUMN ... TYPE` rather than Blueprint::change()
|
||||||
|
* (which requires doctrine/dbal — not installed in this project) —
|
||||||
|
* Postgres-specific (this project runs on `pgsql`, per its own docker
|
||||||
|
* setup), with an explicit USING clause since json isn't implicitly
|
||||||
|
* castable from varchar.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
$defaultLocale = Language::where('default', true)->value('code') ?? 'en';
|
||||||
|
|
||||||
|
$existing = DB::table('payment_methods')->pluck('name', 'id');
|
||||||
|
|
||||||
|
DB::statement('ALTER TABLE payment_methods ALTER COLUMN name DROP DEFAULT');
|
||||||
|
DB::statement("ALTER TABLE payment_methods ALTER COLUMN name TYPE json USING NULL");
|
||||||
|
|
||||||
|
foreach ($existing as $id => $name) {
|
||||||
|
if ($name === null) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
DB::table('payment_methods')
|
||||||
|
->where('id', $id)
|
||||||
|
->update(['name' => json_encode([$defaultLocale => $name])]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
$defaultLocale = Language::where('default', true)->value('code') ?? 'en';
|
||||||
|
|
||||||
|
$existing = DB::table('payment_methods')->pluck('name', 'id');
|
||||||
|
|
||||||
|
DB::statement('ALTER TABLE payment_methods ALTER COLUMN name TYPE varchar(255) USING NULL');
|
||||||
|
|
||||||
|
foreach ($existing as $id => $name) {
|
||||||
|
$decoded = json_decode((string) $name, true);
|
||||||
|
$flat = is_array($decoded) ? ($decoded[$defaultLocale] ?? reset($decoded) ?: null) : $name;
|
||||||
|
|
||||||
|
DB::table('payment_methods')->where('id', $id)->update(['name' => $flat]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,74 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Lunar\Base\Migration;
|
||||||
|
use Lunar\Models\Language;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* ShippingMethod.name becomes a locale-keyed JSON array (e.g.
|
||||||
|
* {"en": "Standard Delivery", "el": "Κανονική Παράδοση"}), rendered in
|
||||||
|
* Filament via Lunar's own Lunar\Admin\Support\Forms\Components\
|
||||||
|
* TranslatedText (Modules\Core\Shipping\Extensions\
|
||||||
|
* ShippingMethodResourceExtension::replaceNameField()) — same shape/
|
||||||
|
* resolution as PaymentMethod.name (see its own migration,
|
||||||
|
* 2026_09_15_000001_make_payment_methods_name_translatable.php) and
|
||||||
|
* Product/Collection names (Lunar\Base\Traits\HasTranslations).
|
||||||
|
*
|
||||||
|
* ShippingMethod is a vendor (lunarphp/table-rate-shipping) table, but
|
||||||
|
* converting a vendor column's type via a migration is no different from
|
||||||
|
* any other schema change this project already makes against a vendor
|
||||||
|
* table (see database/migrations/2026_08_31_000001_create_payment_methods_table.php's
|
||||||
|
* sibling migrations for the same pattern against PaymentMethod) — there
|
||||||
|
* was no good reason to route this through `data.name` instead, unlike
|
||||||
|
* `data.fulfillment_type` which is a genuinely NEW field the vendor table
|
||||||
|
* never had at all.
|
||||||
|
*
|
||||||
|
* Existing plain-string rows are preserved under the store's default
|
||||||
|
* Language code (falls back to 'en' if no Language row exists yet)
|
||||||
|
* rather than dropped.
|
||||||
|
*
|
||||||
|
* Uses a raw `ALTER COLUMN ... TYPE` rather than Blueprint::change()
|
||||||
|
* (requires doctrine/dbal — not installed in this project) — Postgres-
|
||||||
|
* specific (this project runs on `pgsql`), with an explicit USING clause
|
||||||
|
* since json isn't implicitly castable from varchar.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
$table = $this->prefix.'shipping_methods';
|
||||||
|
$defaultLocale = Language::where('default', true)->value('code') ?? 'en';
|
||||||
|
|
||||||
|
// The column is NOT NULL (vendor migration never marked it
|
||||||
|
// nullable) — converting via `USING NULL` first, then
|
||||||
|
// backfilling with a second UPDATE, violates that constraint
|
||||||
|
// before the backfill ever runs. json_build_object() converts
|
||||||
|
// each existing string in place, in the same statement, so the
|
||||||
|
// column is never transiently NULL. $defaultLocale is inlined
|
||||||
|
// (not bound) — parameter binding inside an ALTER TABLE ... USING
|
||||||
|
// expression isn't reliable across drivers; it's a Language::code
|
||||||
|
// value we control, not user input, so quote_literal-safe
|
||||||
|
// interpolation here is fine.
|
||||||
|
$quotedLocale = DB::getPdo()->quote($defaultLocale);
|
||||||
|
|
||||||
|
DB::statement("ALTER TABLE {$table} ALTER COLUMN name TYPE json USING json_build_object({$quotedLocale}, name)");
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
$table = $this->prefix.'shipping_methods';
|
||||||
|
$defaultLocale = Language::where('default', true)->value('code') ?? 'en';
|
||||||
|
|
||||||
|
// Same NOT NULL constraint applies going back — ->>'{locale}'
|
||||||
|
// extracts the default locale's text value directly in the
|
||||||
|
// USING clause, falling back to the first key present via
|
||||||
|
// COALESCE for any row missing that locale (e.g. one only ever
|
||||||
|
// filled in via a non-default language).
|
||||||
|
$quotedLocale = DB::getPdo()->quote($defaultLocale);
|
||||||
|
|
||||||
|
DB::statement(
|
||||||
|
"ALTER TABLE {$table} ALTER COLUMN name TYPE varchar(255) ".
|
||||||
|
"USING COALESCE(name->>{$quotedLocale}, (SELECT value FROM json_each_text(name) LIMIT 1))"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
};
|
||||||
+48
-40
@@ -1,28 +1,34 @@
|
|||||||
# Cart Admin Visibility
|
# Cart Admin Visibility
|
||||||
|
|
||||||
`Modules\Core\Cart\Filament\Resources\CartResource` gives staff read-only visibility into
|
`Modules\Core\Cart\Filament\Resources\CartResource` gives staff read-only visibility into
|
||||||
customer/user carts in the Filament admin panel. Lunar itself ships no cart admin view at
|
every cart in the Filament admin panel, guest carts included. Lunar itself ships no cart
|
||||||
all — no Filament resource for `Cart`/`CartLine` exists anywhere in `lunarphp/lunar` or
|
admin view at all — no Filament resource for `Cart`/`CartLine` exists anywhere in
|
||||||
`lunarphp/core` — this is a from-scratch addition, not an extension of something Lunar
|
`lunarphp/lunar` or `lunarphp/core` — this is a from-scratch addition, not an extension of
|
||||||
half-built. See `docs/lunar.md`'s "Cart and Checkout" section for the underlying Lunar cart
|
something Lunar half-built. See `docs/lunar.md`'s "Cart and Checkout" section for the
|
||||||
mechanics this resource reads from.
|
underlying Lunar cart mechanics this resource reads from.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Scope: only carts with a known customer or user
|
## Scope: every cart, identified or not
|
||||||
|
|
||||||
`CartResource::getEloquentQuery()` filters to `Cart::whereNotNull('user_id')->orWhereNotNull('customer_id')`
|
`CartResource` lists every cart the four lifecycle states (below) cover, with no
|
||||||
— an anonymous guest's session cart is excluded entirely.
|
`user_id`/`customer_id` filter — an anonymous guest's session cart is included.
|
||||||
|
|
||||||
This was a deliberate call, not an oversight: an anonymous cart carries no identity a staff
|
This was a reversal of an earlier, deliberate call to exclude guest carts entirely (on the
|
||||||
member could act on — no name, no email, nothing to follow up with — so listing every guest
|
reasoning that an anonymous cart carries no identity a staff member could act on — no name, no
|
||||||
session cart would be noise, not a real admin capability. This does **not** mirror Shopify's
|
email, nothing to follow up with — so listing every guest session cart would be noise, not a
|
||||||
admin (Shopify has no "all carts" view at all — only "Abandoned checkouts," gated on a
|
real admin capability). That reasoning holds for "can I click through to a Customer record,"
|
||||||
shopper reaching checkout and entering contact info, a later/narrower stage than Lunar's
|
but not for the resource's other real use — seeing how many carts are ongoing/abandoned right
|
||||||
`Cart`). Lunar's own `Cart` model already gets `user_id`/`customer_id` set the moment a
|
now regardless of who's shopping. Most real storefront traffic never reaches an identified
|
||||||
shopper is authenticated (via `Lunar\Listeners\CartSessionAuthListener` on login), with no
|
user/customer, so excluding it silently undercounts exactly the thing `ListCarts`'s tabs (and
|
||||||
checkout step required — so scoping to "identifiable" here is broader than Shopify's
|
`CartLifecycleService`, which they and `DetectAbandonedCarts` both build on) exist to report
|
||||||
equivalent, not a copy of it.
|
on. The `Customer`/`User` columns on a guest row just render "—" (Filament's `placeholder()`)
|
||||||
|
instead of a link — nothing to click into, but the row and its contents are still visible via
|
||||||
|
`ViewCart`.
|
||||||
|
|
||||||
|
This does **not** mirror Shopify's admin (Shopify has no "all carts" view at all — only
|
||||||
|
"Abandoned checkouts," gated on a shopper reaching checkout and entering contact info, a
|
||||||
|
later/narrower stage than Lunar's `Cart`).
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -40,28 +46,29 @@ distinct states together: no order ever started, vs. a draft order exists
|
|||||||
different purchase-intent signals (see "Abandoned Cart vs Abandoned Checkout" below) and
|
different purchase-intent signals (see "Abandoned Cart vs Abandoned Checkout" below) and
|
||||||
different reachability (checkout usually captures an email even for a guest), so
|
different reachability (checkout usually captures an email even for a guest), so
|
||||||
`ListCarts::getTabs()` splits them into four tabs instead of `scopeActive()`'s two-state
|
`ListCarts::getTabs()` splits them into four tabs instead of `scopeActive()`'s two-state
|
||||||
split:
|
split.
|
||||||
|
|
||||||
- **Ongoing** — `scopeActive()` and recent `updated_at` (within `abandonedCutoff()`). Default
|
`Modules\Core\Cart\Services\CartLifecycleService` is the single source of truth for these four
|
||||||
active tab on page load.
|
query shapes — both `ListCarts::getTabs()` (staff browsing) and `DetectAbandonedCarts`
|
||||||
- **Abandoned Cart** — `whereDoesntHave('orders')` and stale `updated_at`.
|
(abandonment-event dispatch) build on it, rather than each reimplementing the same split
|
||||||
- **Abandoned Checkout** — has an order with `placed_at IS NULL`, and stale `updated_at`.
|
independently (which is what happened before this service existed, and is exactly the kind of
|
||||||
- **Completed** — has an order with `placed_at IS NOT NULL`.
|
drift that lets the admin panel and the recovery-email pipeline quietly disagree about what
|
||||||
|
"abandoned" means):
|
||||||
|
|
||||||
```php
|
- **Ongoing** (`ongoing()`) — `scopeActive()` and recent `updated_at` (within
|
||||||
// Ongoing
|
`abandonedCutoff()`). Default active tab on page load.
|
||||||
$query->active()->where('updated_at', '>', CartResource::abandonedCutoff());
|
- **Abandoned Cart** (`abandonedCarts()`) — `whereDoesntHave('orders')` and stale
|
||||||
|
`updated_at`.
|
||||||
|
- **Abandoned Checkout** (`abandonedCheckouts()`) — has an order with `placed_at IS NULL`,
|
||||||
|
and stale `updated_at`.
|
||||||
|
- **Completed** (`completed()`) — has an order with `placed_at IS NOT NULL`.
|
||||||
|
|
||||||
// Abandoned Cart
|
Each method takes a `Builder` and returns it further scoped, so callers compose it onto
|
||||||
$query->whereDoesntHave('orders')->where('updated_at', '<=', CartResource::abandonedCutoff());
|
whatever base query they already have (`CartResource::getEloquentQuery()` for the Filament
|
||||||
|
tabs, a bare `Cart::query()` for the command). Deliberately query-shape-only: consent
|
||||||
// Abandoned Checkout
|
(`meta->recovery_consent`) and non-empty-lines filtering stay in `DetectAbandonedCarts`, not on
|
||||||
$query->whereHas('orders', fn ($q) => $q->whereNull('placed_at'))
|
the service — those gate whether a recovery *event* should fire, not what "abandoned" means to
|
||||||
->where('updated_at', '<=', CartResource::abandonedCutoff());
|
a staff member browsing the list.
|
||||||
|
|
||||||
// Completed
|
|
||||||
$query->whereHas('orders', fn ($q) => $q->whereNotNull('placed_at'));
|
|
||||||
```
|
|
||||||
|
|
||||||
There is deliberately **no "All" tab.** Every row shown is always scoped to one of the four
|
There is deliberately **no "All" tab.** Every row shown is always scoped to one of the four
|
||||||
states above — the list never runs an unfiltered `Cart::query()->get()` over the whole
|
states above — the list never runs an unfiltered `Cart::query()->get()` over the whole
|
||||||
@@ -111,7 +118,7 @@ runs once per admin page load, not once per cart row.
|
|||||||
```php
|
```php
|
||||||
public static function getNavigationBadge(): ?string
|
public static function getNavigationBadge(): ?string
|
||||||
{
|
{
|
||||||
return (string) static::getEloquentQuery()->active()->count();
|
return (string) static::getEloquentQuery()->active()->where('updated_at', '<=', static::abandonedCutoff())->count();
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -235,9 +242,10 @@ just upper-cases the code; `Lunar\Managers\DiscountManager::validateCoupon()` (v
|
|||||||
via a normal Eloquent write, so there's no model-event hook to dispatch from directly.
|
via a normal Eloquent write, so there's no model-event hook to dispatch from directly.
|
||||||
`Modules\Core\Cart\Commands\DetectAbandonedCarts` (registered on an hourly schedule by
|
`Modules\Core\Cart\Commands\DetectAbandonedCarts` (registered on an hourly schedule by
|
||||||
`Modules\Core\Providers\CartServiceProvider`) is the only place that moment gets detected: it
|
`Modules\Core\Providers\CartServiceProvider`) is the only place that moment gets detected: it
|
||||||
queries the same two branches `ListCarts::getTabs()` uses (no order at all vs. draft order
|
builds on the same `CartLifecycleService::abandonedCarts()`/`abandonedCheckouts()` queries
|
||||||
never placed) and dispatches `Modules\Core\Recovery\Events\CartAbandoned`/`CheckoutAbandoned`
|
`ListCarts::getTabs()` uses (no order at all vs. draft order never placed) and dispatches
|
||||||
for anything currently stale.
|
`Modules\Core\Recovery\Events\CartAbandoned`/`CheckoutAbandoned` for anything currently stale
|
||||||
|
that also has `meta->recovery_consent = true`.
|
||||||
|
|
||||||
### Cart/Checkout have zero abandonment-related writes — by design
|
### Cart/Checkout have zero abandonment-related writes — by design
|
||||||
|
|
||||||
|
|||||||
+55
-16
@@ -145,23 +145,20 @@ produced had it resolved synchronously.
|
|||||||
with no memory of the request that started the payment. Something has to persist enough to
|
with no memory of the request that started the payment. Something has to persist enough to
|
||||||
answer "which order/cart does gateway reference X belong to?" between the two calls.
|
answer "which order/cart does gateway reference X belong to?" between the two calls.
|
||||||
|
|
||||||
**Read directly from `lunarphp/stripe`'s own source** (`StripePaymentType::authorize()`,
|
The precedent for this originally came from reading `lunarphp/stripe`'s own source
|
||||||
`ProcessStripeWebhook`, `WebhookController`) to see how Lunar itself solves this — confirmed
|
(`StripePaymentType::authorize()`, `ProcessStripeWebhook`, `WebhookController`) — that package
|
||||||
it does **not** stash a generic opaque blob. It writes the correlating ids as real, typed
|
solved this the same way, writing the correlating ids as real, typed columns on its own
|
||||||
columns on `Lunar\Stripe\Models\StripePaymentIntent` (`cart_id`, `order_id`) at the moment the
|
`StripePaymentIntent` model rather than a generic opaque blob. **`lunarphp/stripe` has since
|
||||||
intent is created/first seen, then reads them back the same way when the webhook arrives:
|
been removed from this project** in favour of depending on `stripe/stripe-php` directly (see
|
||||||
|
CHANGELOG.md) — `Modules\Core\Payment\Models\StripePaymentIntent` is now a first-party model
|
||||||
|
over the same table shape, kept for exactly the same reason.
|
||||||
|
|
||||||
```php
|
**`StripePaymentDriver` follows this pattern**: it reads `cart_id`/`order_id` out of `$context`
|
||||||
// ProcessStripeWebhook::handle() — falls back through two real lookups,
|
at `pay()`/`authorize()` time and writes them onto its own `StripePaymentIntent` row (`src/
|
||||||
// neither of them a generic context blob:
|
Payment/Models/StripePaymentIntent.php`, table `stripe_payment_intents`), then reads them back
|
||||||
$cart = StripePaymentIntent::where('intent_id', $this->paymentIntentId)->first()?->cart
|
the same way in `handleCallback()`. No generic `context` json column beyond what that table
|
||||||
?: Cart::where('meta->payment_intent', '=', $this->paymentIntentId)->first();
|
already carries (`context`, added for a different purpose — see that migration's own
|
||||||
```
|
docblock), no new table.
|
||||||
|
|
||||||
**`StripePaymentDriver` follows this exact precedent**: it reads `cart_id`/`order_id` out of
|
|
||||||
`$context` at `pay()`/`authorize()` time and writes them onto its own `StripePaymentIntent`
|
|
||||||
row (a table already owned by `lunarphp/stripe`, already shaped for exactly this), then reads
|
|
||||||
them back the same way in `handleCallback()`. No generic `context` json column, no new table.
|
|
||||||
|
|
||||||
### This pattern is per-driver, not a shared table
|
### This pattern is per-driver, not a shared table
|
||||||
|
|
||||||
@@ -176,6 +173,48 @@ a shared generic one.
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## Reconciliation — a charge that succeeds on Stripe but is never written locally
|
||||||
|
|
||||||
|
This app never creates or reuses a Stripe **Customer** object — every PaymentIntent is a
|
||||||
|
one-off (`StripePaymentDriver::createAndConfirm()`'s own `$params` never includes a `customer`
|
||||||
|
key), and nothing calls Stripe's Customer API anywhere in this codebase. That's a deliberate
|
||||||
|
choice, not an oversight: a Customer object only earns its keep if something actually needs it
|
||||||
|
(saved/reusable payment methods, subscriptions, Stripe-side lifetime-value grouping across
|
||||||
|
orders) — none of which exist in this checkout flow today. Creating one anyway would just be
|
||||||
|
more PII sitting on a third party's servers for no functional benefit, and it would become
|
||||||
|
another cross-reference a future Payment privacy provider has to account for (detaching/
|
||||||
|
deleting the Customer on erasure, not just the local PaymentIntent row). If a real feature
|
||||||
|
needs it later (e.g. "save my card"), add it then, scoped to that feature.
|
||||||
|
|
||||||
|
The gap this creates: with no Customer object and no other identifying field previously sent
|
||||||
|
to Stripe, a PaymentIntent that succeeds on Stripe's side but is never written to our own DB
|
||||||
|
(e.g. a database outage at exactly the wrong moment, between Stripe confirming the charge and
|
||||||
|
`rememberIntent()`'s insert) would be **untraceable** back to a cart or order — nothing to
|
||||||
|
search Stripe's dashboard by except amount, timestamp, and card last-4.
|
||||||
|
|
||||||
|
**Fix**: `createAndConfirm()` now sets `metadata: ['cart_id' => ..., 'order_id' => ...]`
|
||||||
|
(`array_filter()`-ed, since `order_id` isn't known yet at initial `pay()`/`authorize()` time —
|
||||||
|
same null-coalesce `rememberIntent()` already does) on every PaymentIntent. This is metadata
|
||||||
|
only, visible on Stripe's own dashboard/API for manual reconciliation — it does not create a
|
||||||
|
Customer object and does not change anything about how `handleCallback()`/webhook correlation
|
||||||
|
works (that still goes through `stripe_payment_intents`, per "Async resolution" above). It's
|
||||||
|
purely a recovery aid for the case where our own write never happened at all.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## GDPR erasure/export
|
||||||
|
|
||||||
|
`Modules\Core\Payment\Privacy\PaymentDataProvider` covers `lunar_transactions`
|
||||||
|
(`card_type`/`last_four`) and `stripe_payment_intents` — see `docs/privacy.md` for the full
|
||||||
|
right-of-erasure/right-of-access design. Pseudonymizes card metadata on erasure (same
|
||||||
|
tax/accounting retention reasoning `Order`'s own provider uses) and deletes the Stripe
|
||||||
|
correlation rows outright, since their only purpose — resolving an async webhook callback, see
|
||||||
|
"Async resolution" above — has already been served by the time an erasure request runs. No
|
||||||
|
Stripe Customer object exists anywhere in this app (see "Reconciliation" above) for this
|
||||||
|
provider to also request deletion of.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
## Explicitly out of scope for this pass
|
## Explicitly out of scope for this pass
|
||||||
|
|
||||||
- **`Checkout`/`Order` wiring** — how `Checkout` calls into `Payment`, how `Order`/`Checkout`
|
- **`Checkout`/`Order` wiring** — how `Checkout` calls into `Payment`, how `Order`/`Checkout`
|
||||||
|
|||||||
+417
@@ -0,0 +1,417 @@
|
|||||||
|
# Privacy / GDPR Data-Subject Requests
|
||||||
|
|
||||||
|
`Modules\Core\Privacy` implements the right of access (export) and right of erasure for
|
||||||
|
customers, as an extensible contract rather than a fixed list of tables — any module (core,
|
||||||
|
or a future ERP/banking/etc. module) can register its own data without core knowing it exists.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## User-scope vs Customer-scope — two genuinely different operations
|
||||||
|
|
||||||
|
A Lunar `Customer` (business account: orders, addresses, buyer record) and a `User` (individual
|
||||||
|
login identity) are linked many-to-many via the `customer_user` pivot (see `docs/modules.md`
|
||||||
|
"Customer/User Pairing") — **one User can belong to many Customer accounts, and one Customer
|
||||||
|
account can have many linked Users.** This is the real shape of B2B multi-seat access: a person
|
||||||
|
can have login access to several separate business accounts, and a business account can have
|
||||||
|
several employees each with their own login.
|
||||||
|
|
||||||
|
That means "delete my personal data" and "delete this business account" are not the same request,
|
||||||
|
and conflating them is actively wrong:
|
||||||
|
|
||||||
|
- **Erasing a Customer must never touch any linked User's login or identity.** Erasing "Acme
|
||||||
|
Corp" must not deactivate or destroy access for the employees who work there — and must not
|
||||||
|
touch any *other* Customer account, even one sharing some of the same Users.
|
||||||
|
- **Erasing a User must never touch any Customer account's own data.** John asking to delete
|
||||||
|
*his* account must clear his name/email/login wherever it appears — and correctly end his
|
||||||
|
membership on every Customer he's linked to (detach the pivot) — but must not erase Acme Corp's
|
||||||
|
orders or addresses, and must not affect any other employee still linked to Acme Corp.
|
||||||
|
|
||||||
|
Every part of this module is split along that line — a `PersonalDataProvider`, a `PrivacyService`
|
||||||
|
method, a request record — is always explicitly **for a Customer** or **for a User**, never both
|
||||||
|
at once, and never one with an implicit cascade into the other.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Why an extensible contract, not a hardcoded script
|
||||||
|
|
||||||
|
A GDPR erasure/export request has to touch every module that holds personal data, but core can't
|
||||||
|
know in advance what future modules will exist or what data they'll hold — and different data
|
||||||
|
needs fundamentally different handling (freely erasable PII vs. financial records that must be
|
||||||
|
pseudonymized-not-deleted for legal retention vs. data that must be retained outright). There's
|
||||||
|
deliberately no central taxonomy for this in the contract — each module owns its own retention
|
||||||
|
judgment, since only the module that owns a table actually knows its legal requirements.
|
||||||
|
|
||||||
|
`Modules\Core\Privacy\Contracts\PersonalDataProvider` is the whole contract:
|
||||||
|
|
||||||
|
```php
|
||||||
|
interface PersonalDataProvider
|
||||||
|
{
|
||||||
|
public function name(): string;
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult;
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult;
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult;
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
Every provider implements all four methods. A provider with nothing relevant to one scope
|
||||||
|
implements that method as a no-op — `ErasureOutcome::Skipped` with a reason for erase, an empty
|
||||||
|
payload for export (e.g. `AddressDataProvider::eraseForUser()`, since addresses belong to a
|
||||||
|
Customer, not an individual).
|
||||||
|
|
||||||
|
A provider implementation lives inside the module that owns the data it erases/exports, under
|
||||||
|
that module's own `Privacy/` subdirectory (e.g. `Modules\Core\Order\Privacy\OrderDataProvider`,
|
||||||
|
`Modules\Core\Customer\Privacy\CustomerDataProvider`) — never inside `Modules\Core\Privacy`
|
||||||
|
itself, which only owns the shared contract (`Contracts\PersonalDataProvider`), the request
|
||||||
|
lifecycle (`Services\PrivacyManager`/`PrivacyService`), and the DTOs/enums every provider
|
||||||
|
returns. This mirrors how this codebase already handles other cross-cutting-but-domain-specific
|
||||||
|
code (e.g. a resource's own `Filament/Extensions/` subdirectory) — and matters concretely if a
|
||||||
|
module is ever extracted into its own composer package (see `docs/modules.md`): the provider
|
||||||
|
that knows how to erase that module's data must travel with it, not get stranded in `Privacy`
|
||||||
|
depending on a package that no longer ships in this repo.
|
||||||
|
|
||||||
|
A module registers by adding its provider class to `config('core.privacy.providers')` — the
|
||||||
|
same shape as Lunar's own `config('lunar.search.indexers')` model→indexer map:
|
||||||
|
|
||||||
|
```php
|
||||||
|
// config/core.php
|
||||||
|
'privacy' => [
|
||||||
|
'providers' => [
|
||||||
|
\Modules\Core\Customer\Privacy\CustomerDataProvider::class,
|
||||||
|
\Modules\Core\Customer\Privacy\AddressDataProvider::class,
|
||||||
|
\Modules\Core\Order\Privacy\OrderDataProvider::class,
|
||||||
|
\Modules\Core\Cart\Privacy\CartDataProvider::class,
|
||||||
|
\Modules\Core\Review\Privacy\ReviewDataProvider::class,
|
||||||
|
// A future module just adds its own provider here.
|
||||||
|
],
|
||||||
|
],
|
||||||
|
```
|
||||||
|
|
||||||
|
`PrivacyManager` resolves each class via the container and asserts every `name()` is unique —
|
||||||
|
two providers registering the same name throws, so a naming collision fails loudly at
|
||||||
|
resolution time rather than silently overwriting one provider's data in an export/report.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## `UserSubject` and `CustomerSubject` — identifying "the person" vs "the account"
|
||||||
|
|
||||||
|
Two separate value objects, not one — each deliberately carries only what its own scope needs, so
|
||||||
|
a provider can't accidentally reach across the boundary:
|
||||||
|
|
||||||
|
```php
|
||||||
|
class CustomerSubject
|
||||||
|
{
|
||||||
|
public readonly int $customerId;
|
||||||
|
// No userIds, no email — Customer-scope has no business knowing about logins.
|
||||||
|
}
|
||||||
|
|
||||||
|
class UserSubject
|
||||||
|
{
|
||||||
|
public readonly int $userId;
|
||||||
|
public readonly ?string $email;
|
||||||
|
// No customerId — one User can be linked to many Customers; a provider that
|
||||||
|
// needs to know which ones looks that up itself (e.g. to detach the pivot),
|
||||||
|
// rather than this value object assuming or privileging any single one.
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
`CustomerSubject::forCustomer(Customer $customer)` and `UserSubject::forUser($user)` build one
|
||||||
|
from the record staff (or the person themselves) look up.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Providers shipped in core
|
||||||
|
|
||||||
|
| Provider | `name()` | Lives in | Covers | Customer-scope | User-scope |
|
||||||
|
|---|---|---|---|---|---|
|
||||||
|
| `ActivityLogDataProvider` | `activity_log` | `Modules\Core\Logging\Privacy` | `activity_log` (Spatie) for subject types `Customer`/`Address`/`CartAddress`/`OrderAddress`/`Transaction` | **Pseudonymized** — `properties` redacted, who/what/when metadata kept | Skipped — `causer_id` is an actor reference, not PII content; see below |
|
||||||
|
| `CustomerDataProvider` | `customer` | `Modules\Core\Customer\Privacy` | `lunar_customers`, and separately the `User`'s own name/email/OTP fields | Erases the account's own fields only | Erases that User's name/email/OTP fields only, and detaches them from every linked Customer |
|
||||||
|
| `AddressDataProvider` | `addresses` | `Modules\Core\Customer\Privacy` | `lunar_addresses` | Erased (deleted outright) | Skipped — belongs to a Customer, not an individual |
|
||||||
|
| `OrderDataProvider` | `orders` | `Modules\Core\Order\Privacy` | `lunar_orders`, `lunar_order_addresses`, and their `meta` (`terms_accepted*`, `payment_method`, `box_now_locker`) | **Pseudonymized, not erased** — see below | Skipped — belongs to a Customer, not an individual |
|
||||||
|
| `CartDataProvider` | `carts` | `Modules\Core\Cart\Privacy` | `lunar_cart_addresses`, and `lunar_carts.meta` (`recovery_consent*`, `payment_method`, `checkout_fingerprint`) | Erased | Skipped — belongs to a Customer, not an individual |
|
||||||
|
| `ReviewDataProvider` | `reviews` | `Modules\Core\Review\Privacy` | `product_reviews` | Skipped — authored by an individual, not a business account | Pseudonymized by matching `reviewer_email`; rating/title/body text kept |
|
||||||
|
| `PaymentDataProvider` | `payments` | `Modules\Core\Payment\Privacy` | `lunar_transactions` (`card_type`/`last_four`), `stripe_payment_intents` | **Pseudonymized** — card metadata cleared, correlation rows deleted, amounts/statuses kept | Skipped — belongs to Customer-owned orders, not individual users |
|
||||||
|
| `UserSessionDataProvider` | `sessions` | `Modules\Core\Auth\Privacy` | `user_sessions` (`ip_address`, `user_agent`) | Skipped — belongs to an individual User, not a business account | Erased (deleted outright) |
|
||||||
|
|
||||||
|
`CustomerDataProvider` is the one provider that implements both scopes meaningfully, and keeps
|
||||||
|
them from touching each other — see the class docblock for the full reasoning.
|
||||||
|
|
||||||
|
### `activity_log` is redacted by subject, never by causer
|
||||||
|
|
||||||
|
`Modules\Core\Logging\ActivityLogService` (plus several Lunar models' own native `use
|
||||||
|
LogsActivity` — `Customer`, `CartAddress`, `OrderAddress`, `Transaction`) durably retains a full
|
||||||
|
snapshot of whatever it logged in `properties`, completely independent of the real row it
|
||||||
|
describes — erasing/pseudonymizing a `Customer`/`Address`/`Order`/etc. elsewhere does nothing to
|
||||||
|
this table on its own. `ActivityLogDataProvider::eraseForCustomer()` redacts `properties` on
|
||||||
|
every row whose **subject** (not causer) resolves back to that customer, across all five
|
||||||
|
PII-bearing subject types.
|
||||||
|
|
||||||
|
It deliberately never touches `causer_id` — the causer is "who performed this action," not PII
|
||||||
|
content, and erasing it would defeat the audit trail's own purpose. `eraseForUser()` is
|
||||||
|
therefore a no-op: a `User` appears in this table only as a causer, never as subject content, so
|
||||||
|
there's nothing to redact from the User side alone.
|
||||||
|
|
||||||
|
**Ordering dependency**: `ActivityLogDataProvider` must run *before* `AddressDataProvider` in
|
||||||
|
`config('core.privacy.providers')` — it resolves which `activity_log` rows are keyed by an
|
||||||
|
`Address` id while those Address rows still exist; `AddressDataProvider` then hard-deletes them.
|
||||||
|
Reversing the order would make matching those rows impossible once the addresses are gone.
|
||||||
|
|
||||||
|
**`ReviewDataProvider` needs review.** It moved from Customer-scope to User-scope on the
|
||||||
|
reasoning that authorship is a personal attribute, not a business-account attribute — but this
|
||||||
|
hasn't been fully validated against how reviews are actually attributed in this codebase. The
|
||||||
|
class carries a `NEEDS REVIEW` note; revisit before relying on it for a real request.
|
||||||
|
|
||||||
|
### Orders are pseudonymized, not deleted
|
||||||
|
|
||||||
|
GDPR Art. 17(3)(b) explicitly allows retaining data an erasure request would otherwise cover,
|
||||||
|
when a legal obligation requires it — tax/accounting law generally requires invoices be kept for
|
||||||
|
several years. `OrderDataProvider::eraseForCustomer()` clears the free-text PII fields on `Order`/
|
||||||
|
`OrderAddress` (`customer_reference`, `notes`, name/address/contact fields) but leaves the order
|
||||||
|
row, totals, line items, and tax data fully intact. Its `ProviderErasureResult` reports
|
||||||
|
`ErasureOutcome::Pseudonymized`, not `Erased` — a compliance report or admin UI can see exactly
|
||||||
|
why an order wasn't deleted without reading `OrderDataProvider`'s source.
|
||||||
|
|
||||||
|
### Reviews are matched by email — a real, documented limitation
|
||||||
|
|
||||||
|
`ProductReview` has no FK to Customer/User at all (see `docs/product-listing.md` "Reviews") —
|
||||||
|
it's deliberately anonymous, just free-text `reviewer_name`/`reviewer_email`. `ReviewDataProvider`
|
||||||
|
matches by `reviewer_email` against `UserSubject::$email`; a review submitted under a different
|
||||||
|
email than the one on file simply won't be found. There's no stronger signal available without
|
||||||
|
changing `ProductReview`'s schema.
|
||||||
|
|
||||||
|
### Staff/employee data is out of scope
|
||||||
|
|
||||||
|
`Staff` (admin/panel employees) is never a `UserSubject`/`CustomerSubject` at all — this feature
|
||||||
|
is scoped to customer-initiated and staff-initiated-on-a-customer's-behalf requests. An employee's
|
||||||
|
own data (a different HR/access-management concern) isn't reachable through this flow.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Erasure isn't immediate — a cancellable grace period
|
||||||
|
|
||||||
|
`PrivacyService` has parallel methods for each scope: `requestErasureForCustomer()` /
|
||||||
|
`requestErasureForUser()`. Neither erases anything immediately. Each opens a `DataErasureRequest`
|
||||||
|
(`pending`, `scheduled_for` = now + `config('core.privacy.grace_period_days')`, default 30). This
|
||||||
|
mirrors Shopify's own account-deletion flow: a window where the subject can change their mind
|
||||||
|
before anything is actually erased.
|
||||||
|
|
||||||
|
**Only the User-scoped request deactivates a login.** `requestErasureForCustomer()` deactivates
|
||||||
|
no one — a business-account erasure must never block anyone's access.
|
||||||
|
`requestErasureForUser()` deactivates that one User's login (blocks it — see
|
||||||
|
`Modules\Core\Auth\Services\UserOtpService` — nothing else changes).
|
||||||
|
|
||||||
|
```php
|
||||||
|
use Modules\Core\Privacy\Services\PrivacyService;
|
||||||
|
|
||||||
|
$service = app(PrivacyService::class);
|
||||||
|
|
||||||
|
// Customer-scoped: either the Customer itself (self-service) or a Staff member.
|
||||||
|
$request = $service->requestErasureForCustomer($customer, $requestedBy);
|
||||||
|
|
||||||
|
// User-scoped: either the User itself (self-service) or a Staff member.
|
||||||
|
$request = $service->requestErasureForUser($user, $requestedBy);
|
||||||
|
|
||||||
|
// Cancel before scheduled_for — for a User-scoped request, reactivates the
|
||||||
|
// account. A Customer-scoped request never deactivated anything, so there's
|
||||||
|
// nothing to reactivate for it.
|
||||||
|
$service->cancelErasure($request);
|
||||||
|
```
|
||||||
|
|
||||||
|
### Logging back in during the grace period cancels the request automatically
|
||||||
|
|
||||||
|
Authentication is never blocked by deactivation — `UserOtpService::validate()` still requires
|
||||||
|
the correct OTP code. Once validated, it dispatches `Modules\Core\Auth\Events\UserAuthenticated`;
|
||||||
|
`Modules\Core\Privacy\Listeners\CancelErasureOnLoginListener` (registered in
|
||||||
|
`PrivacyServiceProvider`, **queued** — see below) looks for a pending request keyed on *that
|
||||||
|
User's own id* — never a Customer-scoped one, since Customer-scope never deactivates a login in
|
||||||
|
the first place — and calls `cancelErasure()` on it, then reverts every Customer erasure request
|
||||||
|
it caused (see "The sole-owner cascade" below). Logging back in **is** the "I changed my mind"
|
||||||
|
action — no separate UI/flow needed for reactivation.
|
||||||
|
|
||||||
|
This listener is queued rather than synchronous, so login returns to the browser without waiting
|
||||||
|
on the bookkeeping. Nothing else in this codebase currently reads `deactivated_at` besides this
|
||||||
|
listener and `PrivacyService` itself — `UserOtpService::validate()` never gates the login on it —
|
||||||
|
so the brief window between the login response and the job actually running has no other consumer
|
||||||
|
to observe it as stale.
|
||||||
|
|
||||||
|
### The sole-owner cascade — erasing the last User on a Customer also erases the Customer
|
||||||
|
|
||||||
|
If a User is erased and they were the **only** User linked to a given Customer, that Customer's
|
||||||
|
data (orders, addresses, buyer record) becomes permanently unreachable through any login the
|
||||||
|
moment the User's identity is gone — nobody could ever again log in to exercise a data-subject
|
||||||
|
right over it. GDPR's data minimization principle (Art. 5(1)(c)) means it shouldn't just sit
|
||||||
|
there indefinitely with no legitimate purpose.
|
||||||
|
|
||||||
|
`requestErasureForUser()` and `requestImmediateErasureForUser()` both fire
|
||||||
|
`Modules\Core\Privacy\Events\UserErasureRequested` right after the request is created (and, for
|
||||||
|
the immediate path, before `completeErasure()` runs — see below).
|
||||||
|
`Modules\Core\Privacy\Listeners\CascadeCustomerErasureListener` (**queued**, registered in
|
||||||
|
`PrivacyServiceProvider`) handles it: for every Customer the User is linked to, if that User is
|
||||||
|
currently the *sole* linked User (count is 1, and that one User is this one — not just count ===
|
||||||
|
1, to be explicit rather than relying on an assumption), it opens a second, independent
|
||||||
|
grace-period request via `requestErasureForCustomer($customer, $user, causedByRequestId: ...)`.
|
||||||
|
Both requests then run through their own separate 30-day windows.
|
||||||
|
|
||||||
|
```
|
||||||
|
User erasure requested
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
UserErasureRequested event ──▶ CascadeCustomerErasureListener (queued)
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
for each linked Customer: sole owner?
|
||||||
|
│ yes
|
||||||
|
▼
|
||||||
|
requestErasureForCustomer(..., causedByRequestId: <user request id>)
|
||||||
|
```
|
||||||
|
|
||||||
|
**Tracing the cascade — `caused_by_request_id`.** A cascade-created Customer request's
|
||||||
|
`caused_by_request_id` points back at the User request that triggered it. This is what lets
|
||||||
|
`CancelErasureOnLoginListener` revert *exactly* the cascade a User's own cancellation should
|
||||||
|
undo (via `DataErasureRequest::caused()`) without ever touching an unrelated, independently
|
||||||
|
staff-requested Customer erasure the User happens to still be linked to.
|
||||||
|
|
||||||
|
**Why this is queued, not synchronous.** `CascadeCustomerErasureListener` runs as an independent,
|
||||||
|
separately-retryable job rather than inline inside `requestErasureForUser()` — a failure in the
|
||||||
|
cascade check never rolls back or blocks the User's own request, and there's no
|
||||||
|
`DB::transaction()` wrapping needed, since the two writes (the User's request, and any cascaded
|
||||||
|
Customer request) aren't required to be atomic with each other.
|
||||||
|
|
||||||
|
**A known, accepted race on the immediate-erasure path only.** Because the listener is queued,
|
||||||
|
Eloquent re-fetches its models fresh when the job actually runs (see
|
||||||
|
`Illuminate\Queue\SerializesModels`) — so `$event->request->subject->customers` reflects the
|
||||||
|
*real* state at execution time, not a stale snapshot from dispatch time. For
|
||||||
|
`requestImmediateErasureForUser()`, that job may run before or after `completeErasure()` detaches
|
||||||
|
the User's memberships in the same call. If the detach happens first, the User is simply no
|
||||||
|
longer linked to anything by the time the cascade job runs, and nothing cascades — an accepted
|
||||||
|
race for that rare, staff-only path (see "Immediate erasure" below), not a concern for the
|
||||||
|
everyday `requestErasureForUser()` grace-period path, where nothing detaches until its own later,
|
||||||
|
separate `completeErasure()` run — well after the cascade job has had time to fire.
|
||||||
|
|
||||||
|
### Processing due requests — one job per request
|
||||||
|
|
||||||
|
`php artisan boboko:privacy:process-erasure-requests` finds every `pending` request whose
|
||||||
|
`scheduled_for` has passed and dispatches one `Modules\Core\Privacy\Jobs\EraseDataSubjectJob` per
|
||||||
|
request — it does not run `completeErasure()` inline itself. Each job independently calls
|
||||||
|
`PrivacyService::completeErasure()`, which checks the request's polymorphic `subject` and calls
|
||||||
|
either every registered provider's `eraseForCustomer()` or `eraseForUser()`, writing the full
|
||||||
|
per-provider outcome onto the request's `report` column and marking it `completed`. One job per
|
||||||
|
request means one request's failure (a provider throwing, a DB error) doesn't block or crash
|
||||||
|
processing of the others, and Laravel's normal per-job retry/failure handling applies to each
|
||||||
|
request independently. This package doesn't register a schedule itself; each consuming app wires
|
||||||
|
the command into its own scheduler (daily is reasonable), the same way it owns any other
|
||||||
|
scheduled task.
|
||||||
|
|
||||||
|
### Immediate erasure — staff-only, not self-service
|
||||||
|
|
||||||
|
`requestImmediateErasureForCustomer(Customer $customer, Staff $requestedBy): ErasureReport` and
|
||||||
|
`requestImmediateErasureForUser($user, Staff $requestedBy): ErasureReport` bypass the grace
|
||||||
|
period entirely and erase right away. Both are `Staff`-only **by type**, not just by convention —
|
||||||
|
their signatures take `Staff $requestedBy` specifically (not the union type the grace-period
|
||||||
|
methods accept), so a self-service/customer-facing code path can't reach either one even by
|
||||||
|
accident; calling with a `Customer`/`User` actor is a compile-time type error, not a runtime
|
||||||
|
check to remember.
|
||||||
|
|
||||||
|
This exists for a formal legal request or regulator inquiry that genuinely requires immediate
|
||||||
|
action, not as a convenience for an impatient customer. GDPR Art. 17 requires erasure "without
|
||||||
|
undue delay," but doesn't set a maximum number of days for a grace period, and a short, disclosed,
|
||||||
|
cancellable hold before executing a self-service request is a widely-used, generally accepted
|
||||||
|
pattern (the same one Shopify and most major platforms use) — it is **not** offered as a
|
||||||
|
same-click alternative on the self-service deletion flow, since doing so would mostly defeat the
|
||||||
|
grace period's purpose (protecting an impulsive requester from themselves). If a subject
|
||||||
|
explicitly insists on immediate deletion, that's a staff/support decision to make on the record
|
||||||
|
via one of these methods, not a checkbox exposed to every customer.
|
||||||
|
|
||||||
|
```php
|
||||||
|
$report = $service->requestImmediateErasureForCustomer($customer, $staffMember);
|
||||||
|
$report = $service->requestImmediateErasureForUser($user, $staffMember);
|
||||||
|
// Both run synchronously — no queueing, no grace period. $report is the same
|
||||||
|
// ErasureReport completeErasure() would produce.
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Export — queued, not synchronous
|
||||||
|
|
||||||
|
Export gathers real data across every registered provider — potentially slow, and there's no
|
||||||
|
reason to block whatever request triggered it (a customer clicking "export my data," an API
|
||||||
|
call). `requestExportForCustomer()`/`requestExportForUser()` are fast synchronous calls that only
|
||||||
|
create a `DataExportRequest` row and dispatch the actual work:
|
||||||
|
|
||||||
|
```php
|
||||||
|
$request = $service->requestExportForCustomer($customer);
|
||||||
|
$request = $service->requestExportForUser($user);
|
||||||
|
// $request->status is 'pending'; nothing has been gathered yet.
|
||||||
|
```
|
||||||
|
|
||||||
|
### The event chain
|
||||||
|
|
||||||
|
1. **`ExportDataSubjectJob`** (queued) checks the request's polymorphic `subject` and calls every
|
||||||
|
registered provider's `exportForCustomer()` or `exportForUser()` — all sequentially, in this
|
||||||
|
one job, not fanned out into one job per provider. Per-subject export work is small (a handful
|
||||||
|
of indexed queries per provider), so there's no real parallelism win, and one job means
|
||||||
|
"finished" is just "`handle()` returned," with no `Bus::batch()`/completion-counting needed. If
|
||||||
|
a future provider ever does something genuinely slow (an external API call, a generated PDF),
|
||||||
|
that's the point to reconsider a per-provider batch — not before.
|
||||||
|
2. Once every provider's data is gathered, the job fires **`PersonalDataGathered`**
|
||||||
|
(carries the request and the assembled `ExportReport`) — no file exists yet.
|
||||||
|
3. **`Modules\Core\Privacy\Listeners\WriteExportToCsvListener`** (registered in
|
||||||
|
`PrivacyServiceProvider`) handles that event: turns each provider's data into its own CSV (via
|
||||||
|
the generic `Modules\Core\Export\CsvWriter` — see below), zips them together, writes the zip to
|
||||||
|
`storage/app/exports/privacy/`, and updates the request (`status: completed`, `file_path`).
|
||||||
|
This is its own listener — not inline in the job — so the export *format* is swappable (an app
|
||||||
|
could unregister this and register a JSON-only listener instead) without touching how data is
|
||||||
|
gathered.
|
||||||
|
4. Once the file exists, that listener fires **`PersonalDataExportFileWritten`**.
|
||||||
|
5. Core has no opinion on how the subject is told. A consuming app registers its own notification
|
||||||
|
against `PersonalDataExportFileWritten` via `Modules\Core\Notification\NotificationRegistry` —
|
||||||
|
the same pattern as `App\Notifications\QuestionnaireResultsSentNotification` listening on
|
||||||
|
`App\Events\QuestionnaireResultsSent` (see `boboko-test` for a working example). Core
|
||||||
|
deliberately does not send an email itself.
|
||||||
|
|
||||||
|
### CSV shape
|
||||||
|
|
||||||
|
Every provider's `data` is either a list of associative arrays (addresses, orders, reviews — each
|
||||||
|
item becomes a row) or a single associative array (customer — becomes one row). Any nested array
|
||||||
|
value within a row (e.g. an order's `addresses` sub-array) is JSON-encoded into that one cell
|
||||||
|
rather than exploded into further columns — a generic, provider-agnostic rule in
|
||||||
|
`WriteExportToCsvListener`, not something each provider has to think about.
|
||||||
|
|
||||||
|
### `Modules\Core\Export\CsvWriter` — a generic, reusable piece
|
||||||
|
|
||||||
|
`CsvWriter::write(array $columns, iterable $rows, string $path)` has no knowledge of GDPR,
|
||||||
|
customers, or Lunar at all — a caller supplies a schema (`CsvColumn[]`, each just a header plus a
|
||||||
|
closure that pulls that column's value out of one record) and any iterable data source. It's used
|
||||||
|
here by `WriteExportToCsvListener`, but is equally usable for an unrelated future need — an admin
|
||||||
|
bulk catalog export, an accounting handoff — by supplying a different schema and row source;
|
||||||
|
nothing about it is GDPR-specific.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Audit trail
|
||||||
|
|
||||||
|
`DataErasureRequest` (`data_erasure_requests`) and `DataExportRequest` (`data_export_requests`)
|
||||||
|
are the audit records for erasure and export respectively. Both have a polymorphic `subject`
|
||||||
|
(`subject_type`/`subject_id`, pointing at either a Lunar `Customer` or a `User` — never both) —
|
||||||
|
`subject_type`/`subject_id`/`email` are stored as a **snapshot**, not looked up live, since the
|
||||||
|
whole point is for these tables to remain readable after the record they're about has been
|
||||||
|
erased. `DataErasureRequest::isForCustomer()` tells you which scope a given request is.
|
||||||
|
|
||||||
|
`DataErasureRequest.requested_by_type`/`requested_by_id` capture who asked for it (the subject
|
||||||
|
themselves, self-service; `Staff` acting on their behalf; or, for a cascade-created Customer
|
||||||
|
request, the User whose erasure caused it — see "The sole-owner cascade") at request time.
|
||||||
|
`DataErasureRequest.caused_by_request_id` is set only on a cascade-created Customer request,
|
||||||
|
pointing back at the User request that triggered it; null on every normal, directly-requested
|
||||||
|
erasure — see `DataErasureRequest::causedBy()`/`::caused()`.
|
||||||
|
`DataErasureRequest.report` holds the full per-provider outcome once `completeErasure()` runs;
|
||||||
|
`DataExportRequest.file_path` points at the generated zip once `WriteExportToCsvListener`
|
||||||
|
finishes.
|
||||||
|
|
||||||
|
**Not yet built**: a standalone "leave/remove from a Customer account" action — unlinking a User
|
||||||
|
from a Customer without any erasure involved (e.g. a teammate leaving a project, or an account
|
||||||
|
admin removing someone) — is a related but separate, smaller feature, deliberately out of scope
|
||||||
|
for this module so far. It shares the same pivot-detach primitive `CustomerDataProvider::
|
||||||
|
eraseForUser()` already uses as part of a full erasure, but as a standalone action it doesn't
|
||||||
|
exist yet.
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Greek translations for Lunar\Models\Country::name, keyed by the exact
|
||||||
|
* English spelling Lunar's own installer seeds (`lunar:import:address-data`
|
||||||
|
* fetches http://data.lunarphp.io/countries+states.json — see
|
||||||
|
* vendor/lunarphp/core/src/Console/Commands/Import/AddressData.php).
|
||||||
|
* `Country`/`State` have no i18n support of their own (plain string
|
||||||
|
* columns, no translatable trait) — this is a plain Laravel lang file, not
|
||||||
|
* Modules\Core\Localization's DB-backed TranslationService, since these
|
||||||
|
* names are fixed reference data seeded once, not editable UI copy (see
|
||||||
|
* docs/localization.md). A consuming app's storefront looks this up
|
||||||
|
* itself, e.g. __('core::countries.'.$country->name) — core has no
|
||||||
|
* storefront UI of its own to wire this into (see docs/lunar.md).
|
||||||
|
*
|
||||||
|
* Only Greece is covered — this store operates within Greece; add further
|
||||||
|
* countries here as needed.
|
||||||
|
*/
|
||||||
|
return [
|
||||||
|
'Greece' => 'Ελλάδα',
|
||||||
|
];
|
||||||
@@ -0,0 +1,52 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Greek translations for Lunar\Models\State::name, keyed by the exact
|
||||||
|
* English spelling Lunar's own installer seeds for Greece
|
||||||
|
* (`lunar:import:address-data` — see lang/el/countries.php's own docblock
|
||||||
|
* for the full explanation of why this is a plain lang file, not
|
||||||
|
* Modules\Core\Localization's TranslationService).
|
||||||
|
*
|
||||||
|
* Covers every Greek state/regional-unit row in Lunar's seed dataset —
|
||||||
|
* scoped to Greece only, matching this store's operating country.
|
||||||
|
*/
|
||||||
|
return [
|
||||||
|
'Achaea Regional Unit' => 'Περιφερειακή Ενότητα Αχαΐας',
|
||||||
|
'Aetolia-Acarnania Regional Unit' => 'Περιφερειακή Ενότητα Αιτωλοακαρνανίας',
|
||||||
|
'Arcadia Prefecture' => 'Νομός Αρκαδίας',
|
||||||
|
'Argolis Regional Unit' => 'Περιφερειακή Ενότητα Αργολίδας',
|
||||||
|
'Attica Region' => 'Περιφέρεια Αττικής',
|
||||||
|
'Boeotia Regional Unit' => 'Περιφερειακή Ενότητα Βοιωτίας',
|
||||||
|
'Central Greece Region' => 'Περιφέρεια Στερεάς Ελλάδας',
|
||||||
|
'Central Macedonia' => 'Κεντρική Μακεδονία',
|
||||||
|
'Chania Regional Unit' => 'Περιφερειακή Ενότητα Χανίων',
|
||||||
|
'Corfu Prefecture' => 'Νομός Κέρκυρας',
|
||||||
|
'Corinthia Regional Unit' => 'Περιφερειακή Ενότητα Κορινθίας',
|
||||||
|
'Crete Region' => 'Περιφέρεια Κρήτης',
|
||||||
|
'Drama Regional Unit' => 'Περιφερειακή Ενότητα Δράμας',
|
||||||
|
'East Attica Regional Unit' => 'Περιφερειακή Ενότητα Ανατολικής Αττικής',
|
||||||
|
'East Macedonia and Thrace' => 'Ανατολική Μακεδονία και Θράκη',
|
||||||
|
'Epirus Region' => 'Περιφέρεια Ηπείρου',
|
||||||
|
'Euboea' => 'Εύβοια',
|
||||||
|
'Grevena Prefecture' => 'Νομός Γρεβενών',
|
||||||
|
'Imathia Regional Unit' => 'Περιφερειακή Ενότητα Ημαθίας',
|
||||||
|
'Ioannina Regional Unit' => 'Περιφερειακή Ενότητα Ιωαννίνων',
|
||||||
|
'Ionian Islands Region' => 'Περιφέρεια Ιονίων Νήσων',
|
||||||
|
'Karditsa Regional Unit' => 'Περιφερειακή Ενότητα Καρδίτσας',
|
||||||
|
'Kastoria Regional Unit' => 'Περιφερειακή Ενότητα Καστοριάς',
|
||||||
|
'Kefalonia Prefecture' => 'Νομός Κεφαλληνίας',
|
||||||
|
'Kilkis Regional Unit' => 'Περιφερειακή Ενότητα Κιλκίς',
|
||||||
|
'Kozani Prefecture' => 'Νομός Κοζάνης',
|
||||||
|
'Laconia' => 'Λακωνία',
|
||||||
|
'Larissa Prefecture' => 'Νομός Λάρισας',
|
||||||
|
'Lefkada Regional Unit' => 'Περιφερειακή Ενότητα Λευκάδας',
|
||||||
|
'Pella Regional Unit' => 'Περιφερειακή Ενότητα Πέλλας',
|
||||||
|
'Peloponnese Region' => 'Περιφέρεια Πελοποννήσου',
|
||||||
|
'Phthiotis Prefecture' => 'Νομός Φθιώτιδας',
|
||||||
|
'Preveza Prefecture' => 'Νομός Πρέβεζας',
|
||||||
|
'Serres Prefecture' => 'Νομός Σερρών',
|
||||||
|
'South Aegean' => 'Νότιο Αιγαίο',
|
||||||
|
'Thessaloniki Regional Unit' => 'Περιφερειακή Ενότητα Θεσσαλονίκης',
|
||||||
|
'West Greece Region' => 'Περιφέρεια Δυτικής Ελλάδας',
|
||||||
|
'West Macedonia Region' => 'Περιφέρεια Δυτικής Μακεδονίας',
|
||||||
|
];
|
||||||
@@ -2,7 +2,7 @@
|
|||||||
|
|
||||||
@if (! $otpSent)
|
@if (! $otpSent)
|
||||||
<form wire:submit="requestOtp">
|
<form wire:submit="requestOtp">
|
||||||
<div class="grid gap-y-4">
|
<div style="display: flex; flex-direction: column; row-gap: 1rem;">
|
||||||
<x-filament::input.wrapper>
|
<x-filament::input.wrapper>
|
||||||
<x-filament::input
|
<x-filament::input
|
||||||
type="email"
|
type="email"
|
||||||
@@ -24,7 +24,7 @@
|
|||||||
</form>
|
</form>
|
||||||
@else
|
@else
|
||||||
<form wire:submit="authenticate">
|
<form wire:submit="authenticate">
|
||||||
<div class="grid gap-y-4">
|
<div style="display: flex; flex-direction: column; row-gap: 1rem;">
|
||||||
<p class="text-sm text-gray-500">
|
<p class="text-sm text-gray-500">
|
||||||
A login code was sent to <strong>{{ $email }}</strong>.
|
A login code was sent to <strong>{{ $email }}</strong>.
|
||||||
</p>
|
</p>
|
||||||
|
|||||||
@@ -0,0 +1,127 @@
|
|||||||
|
@php
|
||||||
|
$transaction = $getRecord();
|
||||||
|
$notes = $transaction->notes ?: ($transaction->meta['notes'] ?? null);
|
||||||
|
@endphp
|
||||||
|
|
||||||
|
@once
|
||||||
|
@php
|
||||||
|
$renderPaymentIcons();
|
||||||
|
@endphp
|
||||||
|
@endonce
|
||||||
|
<div
|
||||||
|
@class([
|
||||||
|
'text-sm rounded-lg shadow-md border dark:bg-gray-900',
|
||||||
|
'text-gray-950 dark:text-white',
|
||||||
|
match($transaction->type){
|
||||||
|
'refund' => 'border-orange-300',
|
||||||
|
'intent' => 'border-sky-300',
|
||||||
|
'capture' => 'border-green-300',
|
||||||
|
default => 'border-gray-300',
|
||||||
|
},
|
||||||
|
'!border-red-500 bg-red-50' => !$transaction->success,
|
||||||
|
'bg-gray-50' => $transaction->success,
|
||||||
|
])
|
||||||
|
>
|
||||||
|
<div class="p-2 space-y-2">
|
||||||
|
<div class="px-4 py-2 rounded text-xs bg-white dark:bg-gray-800 shadow text-gray-600 dark:text-gray-400 ring-1 ring-gray-100 dark:ring-gray-700">
|
||||||
|
<span>{{ $transaction->driver }}</span> //
|
||||||
|
<span>{{ $transaction->reference }}</span>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="flex items-center justify-between p-4 bg-white dark:bg-gray-800 rounded shadow ring-1 ring-gray-100 dark:ring-gray-700">
|
||||||
|
<div class="flex items-center gap-6">
|
||||||
|
<div>
|
||||||
|
<strong class="text-xs">
|
||||||
|
{{ $transaction->status }}
|
||||||
|
</strong>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div>
|
||||||
|
<svg viewBox="0 0 50 50" class="w-10">
|
||||||
|
<use xlink:href="#{{ strtolower($transaction->card_type) }}"></use>
|
||||||
|
</svg>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if($transaction->last_four)
|
||||||
|
<p class="text-sm">
|
||||||
|
<span class="inline-block -translate-y-px">
|
||||||
|
∗∗∗∗ ∗∗∗∗ ∗∗∗∗
|
||||||
|
</span>
|
||||||
|
|
||||||
|
<span class="font-medium">
|
||||||
|
{{ (string) $transaction->last_four }}
|
||||||
|
</span>
|
||||||
|
</p>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<strong
|
||||||
|
@class([
|
||||||
|
"text-sm",
|
||||||
|
'text-red-500' => !$transaction->success,
|
||||||
|
match($transaction->type){
|
||||||
|
'refund' => "text-orange-500",
|
||||||
|
default => "text-gray-900 dark:text-gray-100",
|
||||||
|
},
|
||||||
|
])
|
||||||
|
>
|
||||||
|
@if($transaction->type == 'refund')-@endif{{ $transaction->amount->formatted }}
|
||||||
|
</strong>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="px-4 py-2 bg-white dark:bg-gray-800 shadow rounded flex items-center justify-between text-gray-600 dark:text-gray-400 ring-1 ring-gray-100 dark:ring-gray-700">
|
||||||
|
<div class="text-xs flex items-center gap-2">
|
||||||
|
<div>
|
||||||
|
<x-filament::icon
|
||||||
|
icon="heroicon-o-clock"
|
||||||
|
class="w-4"
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
<span>{{ $transaction->created_at->format('jS F Y h:ia') }}</span>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="flex space-x-2">
|
||||||
|
@foreach($transaction->paymentChecks() as $check)
|
||||||
|
<x-filament::badge
|
||||||
|
:icon="$check->successful ? 'heroicon-m-check' : 'heroicon-m-x-mark'"
|
||||||
|
:color="$check->successful ? \Filament\Support\Colors\Color::Sky : 'gray'"
|
||||||
|
>
|
||||||
|
{{ $check->label }}: {{ $check->message }}
|
||||||
|
</x-filament::badge>
|
||||||
|
@endforeach
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
@if($notes)
|
||||||
|
<div class="px-4 py-2 bg-white dark:bg-gray-800 shadow flex items-center rounded gap-2 ring-1 ring-gray-100 dark:ring-gray-700">
|
||||||
|
<div>
|
||||||
|
<x-filament::icon
|
||||||
|
icon="heroicon-o-chat-bubble-oval-left-ellipsis"
|
||||||
|
class="w-4"
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<p class="text-sm">{{ $notes }}</p>
|
||||||
|
</div>
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div
|
||||||
|
@class([
|
||||||
|
"bottom-0 left-0 block w-full text-center rounded-b-lg border-t text-xs py-1",
|
||||||
|
"!bg-red-50 !dark:bg-red-400/10 !border-red-300 !text-red-600 !dark:text-red-400" => !$transaction->success,
|
||||||
|
match($transaction->type){
|
||||||
|
'refund' => "bg-orange-50 dark:bg-orange-400/10 border-orange-300 text-orange-600 dark:text-orange-400",
|
||||||
|
'intent' => "bg-sky-50 dark:bg-sky-400/10 border-sky-300 text-sky-600 dark:text-sky-400",
|
||||||
|
'capture' => "bg-green-50 dark:bg-green-400/10 border-green-300 text-green-600 dark:text-green-400",
|
||||||
|
default => "bg-gray-50 dark:bg-gray-400/10 border-gray-300 text-gray-600 dark:text-gray-400",
|
||||||
|
},
|
||||||
|
])
|
||||||
|
>
|
||||||
|
@if(!$transaction->success)
|
||||||
|
{{ __('lunarpanel::order.transactions.failed') }}
|
||||||
|
@else
|
||||||
|
{{ __('lunarpanel::order.transactions.'.$transaction->type) }}
|
||||||
|
@endif
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
<p>Hi,</p>
|
||||||
|
|
||||||
|
<p>Your order <strong>{{ $reference }}</strong> is complete. Thanks for shopping with us!</p>
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
<p>Hi,</p>
|
||||||
|
|
||||||
|
<p>Your order <strong>{{ $reference }}</strong> is on its way.</p>
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
<p>Hi,</p>
|
||||||
|
|
||||||
|
<p>Your order <strong>{{ $reference }}</strong> is ready for pickup in store.</p>
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
<p>Hi,</p>
|
||||||
|
|
||||||
|
<p>Thanks for your order! Your order <strong>{{ $reference }}</strong> is confirmed.</p>
|
||||||
|
|
||||||
|
<ul>
|
||||||
|
@foreach ($lines as $line)
|
||||||
|
<li>{{ $line->quantity }} × {{ $line->description }} — {{ $line->total?->formatted }}</li>
|
||||||
|
@endforeach
|
||||||
|
</ul>
|
||||||
|
|
||||||
|
<p>Total: <strong>{{ $total }}</strong></p>
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
<x-filament-panels::page>
|
|
||||||
{{ $this->table }}
|
|
||||||
</x-filament-panels::page>
|
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Lunar\Base\LunarUser;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by UserOtpService::validate() on every successful OTP login, not just
|
||||||
|
* a first-time one. Modules\Core\Privacy listens on this to auto-cancel a pending
|
||||||
|
* DataErasureRequest — logging back in during the grace period is the "I changed
|
||||||
|
* my mind" action (see Modules\Core\Privacy\Listeners\CancelErasureOnLoginListener),
|
||||||
|
* which needs $user->customers to resolve any pending request. Typed as
|
||||||
|
* Authenticatable&LunarUser rather than plain Authenticatable (unlike the sibling
|
||||||
|
* UserCreated event) specifically because that listener depends on it — every real
|
||||||
|
* User in this codebase implements LunarUser (see docs/lunar.md "LunarUser trait"),
|
||||||
|
* and User is the only Authenticatable entity in this project (Customer is not —
|
||||||
|
* see docs/modules.md "Customer/User Pairing").
|
||||||
|
*/
|
||||||
|
class UserAuthenticated
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly Authenticatable&LunarUser $user,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Exceptions;
|
||||||
|
|
||||||
|
use RuntimeException;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Thrown by Modules\Core\Auth\Services\UserOtpService::generateAndSend()
|
||||||
|
* when an email has requested too many codes too quickly — caps both
|
||||||
|
* mail-bombing one inbox and the "just request a fresh code to reset my
|
||||||
|
* guess count" loophole a per-code attempt cap alone doesn't close.
|
||||||
|
*/
|
||||||
|
class OtpThrottledException extends RuntimeException
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly int $availableInSeconds,
|
||||||
|
) {
|
||||||
|
parent::__construct("Too many code requests. Try again in {$availableInSeconds} second(s).");
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,50 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Http\Middleware;
|
||||||
|
|
||||||
|
use Closure;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Facades\Auth;
|
||||||
|
use Modules\Core\Auth\Services\UserSessionService;
|
||||||
|
use Symfony\Component\HttpFoundation\Response;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The enforcement half of the session registry — see
|
||||||
|
* Modules\Core\Auth\Services\UserSessionService's own docblock. Not
|
||||||
|
* auto-registered anywhere (no routes/kernel wiring exist in this
|
||||||
|
* package — see Modules\Core\Customer\Services\CustomerAccountService's
|
||||||
|
* own docblock for why this branch stops at services); a consuming app
|
||||||
|
* adds this to its `web` middleware group (after `auth`) to actually get
|
||||||
|
* "logout everywhere" enforcement.
|
||||||
|
*
|
||||||
|
* A request with no recorded UserSession at all (see
|
||||||
|
* UserSessionService::currentSession()'s own docblock) is let through —
|
||||||
|
* only an EXPLICITLY revoked session is rejected.
|
||||||
|
*/
|
||||||
|
class EnsureSessionNotRevoked
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly UserSessionService $sessions,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public function handle(Request $request, Closure $next): Response
|
||||||
|
{
|
||||||
|
if (! Auth::check()) {
|
||||||
|
return $next($request);
|
||||||
|
}
|
||||||
|
|
||||||
|
$session = $this->sessions->currentSession();
|
||||||
|
|
||||||
|
if ($session && $session->isRevoked()) {
|
||||||
|
Auth::logout();
|
||||||
|
$request->session()->invalidate();
|
||||||
|
$request->session()->regenerateToken();
|
||||||
|
|
||||||
|
abort(401, 'Your session has been revoked. Please log in again.');
|
||||||
|
}
|
||||||
|
|
||||||
|
$session?->update(['last_used_at' => now()]);
|
||||||
|
|
||||||
|
return $next($request);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Models;
|
||||||
|
|
||||||
|
use Illuminate\Database\Eloquent\Model;
|
||||||
|
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* One row per login (see Modules\Core\Auth\Services\UserOtpService::
|
||||||
|
* validate()) — see that table's own migration docblock for why this
|
||||||
|
* exists independent of the actual session-store driver.
|
||||||
|
*/
|
||||||
|
class UserSession extends Model
|
||||||
|
{
|
||||||
|
protected $guarded = [];
|
||||||
|
|
||||||
|
protected $casts = [
|
||||||
|
'last_used_at' => 'datetime',
|
||||||
|
'revoked_at' => 'datetime',
|
||||||
|
];
|
||||||
|
|
||||||
|
public function user(): BelongsTo
|
||||||
|
{
|
||||||
|
$model = config('auth.providers.users.model');
|
||||||
|
|
||||||
|
return $this->belongsTo($model);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function isRevoked(): bool
|
||||||
|
{
|
||||||
|
return $this->revoked_at !== null;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,68 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Privacy;
|
||||||
|
|
||||||
|
use Modules\Core\Auth\Models\UserSession;
|
||||||
|
use Modules\Core\Privacy\Contracts\PersonalDataProvider;
|
||||||
|
use Modules\Core\Privacy\DTOs\CustomerSubject;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureOutcome;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderErasureResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderExportResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\UserSubject;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Login-session device/location metadata (user_sessions) — ip_address and
|
||||||
|
* user_agent are device/location fingerprinting data tied 1:1 to a User via
|
||||||
|
* user_id, never to a Customer (business account), so this is User-scope
|
||||||
|
* only. No legal retention requirement applies to session metadata the way
|
||||||
|
* it does to Order (there's no tax/accounting reason to keep old login IPs
|
||||||
|
* around), so rows are deleted outright rather than pseudonymized.
|
||||||
|
*
|
||||||
|
* A hard delete here is safe regardless of whether the User row itself has
|
||||||
|
* already been erased — CustomerDataProvider::eraseForUser() nulls the
|
||||||
|
* User's own name/email but never touches user_sessions, and the table's
|
||||||
|
* own user_id FK is cascadeOnDelete() only if the User row itself were
|
||||||
|
* hard-deleted, which it never is (erasure here means "identity nulled,"
|
||||||
|
* not "row removed" — see docs/modules.md "Customer/User Pairing").
|
||||||
|
*/
|
||||||
|
class UserSessionDataProvider implements PersonalDataProvider
|
||||||
|
{
|
||||||
|
public function name(): string
|
||||||
|
{
|
||||||
|
return 'sessions';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
return new ProviderExportResult('sessions', []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$sessions = UserSession::where('user_id', $subject->userId)->get();
|
||||||
|
|
||||||
|
return new ProviderExportResult('sessions', $sessions->map(fn (UserSession $session) => [
|
||||||
|
'id' => $session->id,
|
||||||
|
'ip_address' => $session->ip_address,
|
||||||
|
'user_agent' => $session->user_agent,
|
||||||
|
'last_used_at' => $session->last_used_at?->toIso8601String(),
|
||||||
|
'revoked_at' => $session->revoked_at?->toIso8601String(),
|
||||||
|
])->all());
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
return new ProviderErasureResult('sessions', ErasureOutcome::Skipped, 'Login sessions belong to individual Users, not Customer accounts.');
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
$deleted = UserSession::where('user_id', $subject->userId)->delete();
|
||||||
|
|
||||||
|
if ($deleted === 0) {
|
||||||
|
return new ProviderErasureResult('sessions', ErasureOutcome::Skipped, 'No login sessions for this user.');
|
||||||
|
}
|
||||||
|
|
||||||
|
return new ProviderErasureResult('sessions', ErasureOutcome::Erased);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -2,16 +2,76 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Auth\Services;
|
namespace Modules\Core\Auth\Services;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Facades\Auth;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Illuminate\Support\Facades\Event;
|
||||||
use Illuminate\Support\Facades\Mail;
|
use Illuminate\Support\Facades\Mail;
|
||||||
|
use Illuminate\Support\Facades\RateLimiter;
|
||||||
|
use Modules\Core\Auth\Events\UserAuthenticated;
|
||||||
|
use Modules\Core\Auth\Exceptions\OtpThrottledException;
|
||||||
use Modules\Core\Auth\Mail\UserOtpMail;
|
use Modules\Core\Auth\Mail\UserOtpMail;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The storefront's passwordless login — a shopper supplies only an email
|
||||||
|
* (Shopify-style), gets a 6-digit code, and validate() authenticates the
|
||||||
|
* `web` guard via Auth::login().
|
||||||
|
*
|
||||||
|
* That alone is enough to merge/associate any active guest cart into the
|
||||||
|
* now-known customer — Auth::login() fires Illuminate\Auth\Events\Login,
|
||||||
|
* which Lunar's own Lunar\Listeners\CartSessionAuthListener (registered
|
||||||
|
* unconditionally in LunarServiceProvider::boot(), no opt-in needed)
|
||||||
|
* already listens to, calling CartSession::associate() with
|
||||||
|
* config('lunar.cart.auth_policy') — 'merge' by default, 'override' if a
|
||||||
|
* consumer changes that config. Deliberately no cart-association call
|
||||||
|
* here: doing our own on top would run a SECOND merge attempt with a
|
||||||
|
* hardcoded policy that ignores whatever the consumer configured.
|
||||||
|
*
|
||||||
|
* generateAndSend()'s find-or-create already triggers the full
|
||||||
|
* Customer/User pairing cascade for a genuinely new email — see
|
||||||
|
* Modules\Core\Auth\Events\UserCreated's own docblock and
|
||||||
|
* Modules\Core\Customer\Listeners\CreateCustomerForUser.
|
||||||
|
*
|
||||||
|
* Two independent throttles, both configured under core.auth.otp — see
|
||||||
|
* config/core.php's own comment for why they're separate: max_attempts
|
||||||
|
* caps wrong guesses against ONE code; generation_limit caps how often a
|
||||||
|
* NEW code can be requested for the same email at all (closes both the
|
||||||
|
* "regenerate to reset my guess count" loophole and mail-bombing one
|
||||||
|
* inbox).
|
||||||
|
*
|
||||||
|
* validate() also records a UserSessionService entry for the new login —
|
||||||
|
* see that class's own docblock for the "logout everywhere" registry
|
||||||
|
* this feeds (Modules\Core\Auth\Http\Middleware\EnsureSessionNotRevoked
|
||||||
|
* is the enforcement half; a consuming app must add it to its own
|
||||||
|
* middleware stack). $request is optional purely so this service stays
|
||||||
|
* callable from a context with no HTTP request at all (a console
|
||||||
|
* command, a test) — user-agent/ip are simply not recorded when omitted.
|
||||||
|
*/
|
||||||
class UserOtpService
|
class UserOtpService
|
||||||
{
|
{
|
||||||
private const EXPIRY_MINUTES = 10;
|
private const EXPIRY_MINUTES = 10;
|
||||||
private const CODE_LENGTH = 6;
|
private const CODE_LENGTH = 6;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
private readonly UserSessionService $sessions,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws OtpThrottledException if this email has requested too many
|
||||||
|
* codes within core.auth.otp.generation_decay_minutes
|
||||||
|
*/
|
||||||
public function generateAndSend(string $email): bool
|
public function generateAndSend(string $email): bool
|
||||||
{
|
{
|
||||||
|
$limiterKey = $this->generationLimiterKey($email);
|
||||||
|
$maxGenerations = (int) config('core.auth.otp.generation_limit', 3);
|
||||||
|
|
||||||
|
if (RateLimiter::tooManyAttempts($limiterKey, $maxGenerations)) {
|
||||||
|
throw new OtpThrottledException(RateLimiter::availableIn($limiterKey));
|
||||||
|
}
|
||||||
|
|
||||||
|
RateLimiter::hit($limiterKey, (int) config('core.auth.otp.generation_decay_minutes', 10) * 60);
|
||||||
|
|
||||||
$model = config('auth.providers.users.model');
|
$model = config('auth.providers.users.model');
|
||||||
$user = $model::firstOrCreate(['email' => $email]);
|
$user = $model::firstOrCreate(['email' => $email]);
|
||||||
|
|
||||||
@@ -19,6 +79,7 @@ class UserOtpService
|
|||||||
|
|
||||||
$user->otp_code = $code;
|
$user->otp_code = $code;
|
||||||
$user->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES);
|
$user->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES);
|
||||||
|
$user->otp_attempts = 0;
|
||||||
$user->save();
|
$user->save();
|
||||||
|
|
||||||
Mail::to($user->email)->send(new UserOtpMail($user->name ?? $user->email, $code));
|
Mail::to($user->email)->send(new UserOtpMail($user->name ?? $user->email, $code));
|
||||||
@@ -26,23 +87,70 @@ class UserOtpService
|
|||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
public function validate(string $email, string $code)
|
/**
|
||||||
|
* A wrong code counts against core.auth.otp.max_attempts and, once
|
||||||
|
* reached, invalidates the code entirely — the shopper must request
|
||||||
|
* a fresh one via generateAndSend() (itself throttled independently
|
||||||
|
* — see this class's own docblock) rather than being able to keep
|
||||||
|
* guessing against a still-live code for the rest of its 10-minute
|
||||||
|
* expiry window.
|
||||||
|
*/
|
||||||
|
public function validate(string $email, string $code, ?Request $request = null): ?Authenticatable
|
||||||
{
|
{
|
||||||
$model = config('auth.providers.users.model');
|
$model = config('auth.providers.users.model');
|
||||||
$user = $model::where('email', $email)->first();
|
|
||||||
|
|
||||||
if (! $user) {
|
// lockForUpdate() + a transaction make the read-check-increment-save
|
||||||
|
// below atomic across concurrent requests for the same user — without
|
||||||
|
// it, two guesses fired in parallel can each read the same
|
||||||
|
// pre-increment otp_attempts value and both save past
|
||||||
|
// max_attempts, letting an attacker exceed the lockout by
|
||||||
|
// parallelizing requests instead of sending them serially.
|
||||||
|
$result = DB::transaction(function () use ($model, $email, $code) {
|
||||||
|
$user = $model::where('email', $email)->lockForUpdate()->first();
|
||||||
|
|
||||||
|
if (! $user || ! $user->otp_expires_at || now()->isAfter($user->otp_expires_at)) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (! hash_equals((string) $user->otp_code, $code)) {
|
||||||
|
$user->otp_attempts++;
|
||||||
|
|
||||||
|
if ($user->otp_attempts >= (int) config('core.auth.otp.max_attempts', 5)) {
|
||||||
|
$user->otp_code = null;
|
||||||
|
$user->otp_expires_at = null;
|
||||||
|
$user->otp_attempts = 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
$user->save();
|
||||||
|
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
$user->otp_code = null;
|
||||||
|
$user->otp_expires_at = null;
|
||||||
|
$user->otp_attempts = 0;
|
||||||
|
$user->save();
|
||||||
|
|
||||||
|
return $user;
|
||||||
|
});
|
||||||
|
|
||||||
|
if (! $result) {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (! $user->otp_expires_at || $user->otp_code != $code || now()->isAfter($user->otp_expires_at)) {
|
RateLimiter::clear($this->generationLimiterKey($email));
|
||||||
return null;
|
|
||||||
}
|
|
||||||
|
|
||||||
$user->otp_code = null;
|
Auth::login($result);
|
||||||
$user->otp_expires_at = null;
|
|
||||||
$user->save();
|
|
||||||
|
|
||||||
return $user;
|
$this->sessions->record($result, $request);
|
||||||
|
|
||||||
|
Event::dispatch(new UserAuthenticated($result));
|
||||||
|
|
||||||
|
return $result;
|
||||||
|
}
|
||||||
|
|
||||||
|
private function generationLimiterKey(string $email): string
|
||||||
|
{
|
||||||
|
return 'otp-generate:'.strtolower($email);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,105 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Services;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Str;
|
||||||
|
use Modules\Core\Auth\Models\UserSession;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The record/revoke half of the session registry — see
|
||||||
|
* database/migrations/2026_09_15_000001_create_user_sessions_table.php's
|
||||||
|
* own docblock for why this exists (SESSION_DRIVER=redis in this app has
|
||||||
|
* no "sessions" table to purge by user_id). The enforcement half is
|
||||||
|
* Modules\Core\Auth\Http\Middleware\EnsureSessionNotRevoked, which reads
|
||||||
|
* the token this class stamps into the session payload.
|
||||||
|
*/
|
||||||
|
class UserSessionService
|
||||||
|
{
|
||||||
|
private const SESSION_TOKEN_KEY = 'user_session_token';
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Called once, right after Auth::login() succeeds (see
|
||||||
|
* UserOtpService::validate()) — generates a fresh token, records it,
|
||||||
|
* and stamps it into the CURRENT session payload so
|
||||||
|
* EnsureSessionNotRevoked can look it up on later requests.
|
||||||
|
*/
|
||||||
|
public function record(Authenticatable $user, ?Request $request = null): UserSession
|
||||||
|
{
|
||||||
|
$token = Str::random(64);
|
||||||
|
|
||||||
|
$session = UserSession::create([
|
||||||
|
'user_id' => $user->getAuthIdentifier(),
|
||||||
|
'token' => $token,
|
||||||
|
'user_agent' => $request?->userAgent(),
|
||||||
|
'ip_address' => $request?->ip(),
|
||||||
|
'last_used_at' => now(),
|
||||||
|
]);
|
||||||
|
|
||||||
|
session([self::SESSION_TOKEN_KEY => $token]);
|
||||||
|
|
||||||
|
return $session;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Revokes every OTHER active session for $user — the current one
|
||||||
|
* (matched by the token in the CURRENT session payload) is left
|
||||||
|
* alone, matching Laravel's own logoutOtherDevices() semantics
|
||||||
|
* (there just isn't a password to re-verify against here — this is a
|
||||||
|
* passwordless account, so revocation is simply "every row that
|
||||||
|
* isn't the one making this request").
|
||||||
|
*
|
||||||
|
* Known, deliberately accepted gap: this requires only a currently
|
||||||
|
* valid session, not a freshly-completed login — so anyone holding
|
||||||
|
* an already-authenticated session (e.g. someone who sits down at an
|
||||||
|
* account left logged in on a shared/public PC) can use this to
|
||||||
|
* evict the real owner's OTHER sessions just as easily as the real
|
||||||
|
* owner could use it to evict an intruder's. A stricter version would
|
||||||
|
* require a fresh OTP re-verification (e.g. within the last few
|
||||||
|
* minutes) before allowing this call. Left as-is for now — revisit if
|
||||||
|
* this turns out to matter in practice, rather than building
|
||||||
|
* abuse-resistance against a threat model nobody's confirmed is real
|
||||||
|
* for this storefront.
|
||||||
|
*/
|
||||||
|
public function revokeOtherSessions(Authenticatable $user): int
|
||||||
|
{
|
||||||
|
$currentToken = session(self::SESSION_TOKEN_KEY);
|
||||||
|
|
||||||
|
return UserSession::query()
|
||||||
|
->where('user_id', $user->getAuthIdentifier())
|
||||||
|
->whereNull('revoked_at')
|
||||||
|
->when($currentToken, fn ($query) => $query->where('token', '!=', $currentToken))
|
||||||
|
->update(['revoked_at' => now()]);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Revokes EVERY session for $user, current one included — for a
|
||||||
|
* "this account may be compromised" response, not a routine logout.
|
||||||
|
*/
|
||||||
|
public function revokeAllSessions(Authenticatable $user): int
|
||||||
|
{
|
||||||
|
return UserSession::query()
|
||||||
|
->where('user_id', $user->getAuthIdentifier())
|
||||||
|
->whereNull('revoked_at')
|
||||||
|
->update(['revoked_at' => now()]);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return UserSession|null null if the CURRENT session has no
|
||||||
|
* recorded token at all (e.g. a session predating this feature, or
|
||||||
|
* one Auth::login() established outside UserOtpService) — treated
|
||||||
|
* as valid by EnsureSessionNotRevoked rather than rejected, since
|
||||||
|
* there's nothing to have been revoked.
|
||||||
|
*/
|
||||||
|
public function currentSession(): ?UserSession
|
||||||
|
{
|
||||||
|
$token = session(self::SESSION_TOKEN_KEY);
|
||||||
|
|
||||||
|
if (! $token) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
return UserSession::where('token', $token)->first();
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -5,7 +5,7 @@ namespace Modules\Core\Cart\Commands;
|
|||||||
use Illuminate\Console\Command;
|
use Illuminate\Console\Command;
|
||||||
use Illuminate\Support\Facades\Event;
|
use Illuminate\Support\Facades\Event;
|
||||||
use Lunar\Models\Cart;
|
use Lunar\Models\Cart;
|
||||||
use Modules\Core\Cart\Filament\Resources\CartResource;
|
use Modules\Core\Cart\Services\CartLifecycleService;
|
||||||
use Modules\Core\Recovery\Events\CartAbandoned;
|
use Modules\Core\Recovery\Events\CartAbandoned;
|
||||||
use Modules\Core\Recovery\Events\CheckoutAbandoned;
|
use Modules\Core\Recovery\Events\CheckoutAbandoned;
|
||||||
|
|
||||||
@@ -31,6 +31,20 @@ use Modules\Core\Recovery\Events\CheckoutAbandoned;
|
|||||||
* state at all; every cart still matching the query below refires its event
|
* state at all; every cart still matching the query below refires its event
|
||||||
* on every run until Recovery (not yet built — see
|
* on every run until Recovery (not yet built — see
|
||||||
* docs/recovery-strategies.md) owns its own dedup/tracking table.
|
* docs/recovery-strategies.md) owns its own dedup/tracking table.
|
||||||
|
*
|
||||||
|
* Both queries require meta->recovery_consent = true — CartAbandoned/
|
||||||
|
* CheckoutAbandoned exist specifically to drive future recovery-email
|
||||||
|
* sends (Checkout\Services\CheckoutService::setRecoveryConsent() is where
|
||||||
|
* that consent is actually recorded), and a non-consenting cart's
|
||||||
|
* abandonment must never be dispatched at all, not merely filtered later
|
||||||
|
* at send time — see docs referenced above for the legal reasoning. This
|
||||||
|
* consent filter stays here rather than on Modules\Core\Cart\Services\
|
||||||
|
* CartLifecycleService, whose two "abandoned" queries this command builds
|
||||||
|
* on — dispatch eligibility is this command's own concern, not part of
|
||||||
|
* what "abandoned" means to a staff member browsing the admin panel. (The
|
||||||
|
* non-empty-lines requirement, by contrast, IS part of what "abandoned"
|
||||||
|
* means either way, so it lives on CartLifecycleService::abandonedCarts()
|
||||||
|
* itself, not here.)
|
||||||
*/
|
*/
|
||||||
class DetectAbandonedCarts extends Command
|
class DetectAbandonedCarts extends Command
|
||||||
{
|
{
|
||||||
@@ -38,32 +52,23 @@ class DetectAbandonedCarts extends Command
|
|||||||
|
|
||||||
protected $description = 'Dispatch CartAbandoned/CheckoutAbandoned for carts that just crossed the abandonment threshold.';
|
protected $description = 'Dispatch CartAbandoned/CheckoutAbandoned for carts that just crossed the abandonment threshold.';
|
||||||
|
|
||||||
public function handle(): void
|
public function handle(CartLifecycleService $lifecycle): void
|
||||||
{
|
{
|
||||||
$cutoff = CartResource::abandonedCutoff();
|
|
||||||
|
|
||||||
$cartsAbandoned = 0;
|
$cartsAbandoned = 0;
|
||||||
$checkoutsAbandoned = 0;
|
$checkoutsAbandoned = 0;
|
||||||
|
|
||||||
Cart::query()
|
$lifecycle->abandonedCarts(Cart::query())
|
||||||
->whereDoesntHave('orders')
|
->where('meta->recovery_consent', true)
|
||||||
->where('updated_at', '<=', $cutoff)
|
|
||||||
->with('lines')
|
|
||||||
->chunkById(200, function ($carts) use (&$cartsAbandoned) {
|
->chunkById(200, function ($carts) use (&$cartsAbandoned) {
|
||||||
foreach ($carts as $cart) {
|
foreach ($carts as $cart) {
|
||||||
if ($cart->lines->isEmpty()) {
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
|
|
||||||
Event::dispatch(new CartAbandoned($cart));
|
Event::dispatch(new CartAbandoned($cart));
|
||||||
|
|
||||||
$cartsAbandoned++;
|
$cartsAbandoned++;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
Cart::query()
|
$lifecycle->abandonedCheckouts(Cart::query())
|
||||||
->whereHas('orders', fn ($query) => $query->whereNull('placed_at'))
|
->where('meta->recovery_consent', true)
|
||||||
->where('updated_at', '<=', $cutoff)
|
|
||||||
->with(['orders' => fn ($query) => $query->whereNull('placed_at')])
|
->with(['orders' => fn ($query) => $query->whereNull('placed_at')])
|
||||||
->chunkById(200, function ($carts) use (&$checkoutsAbandoned) {
|
->chunkById(200, function ($carts) use (&$checkoutsAbandoned) {
|
||||||
foreach ($carts as $cart) {
|
foreach ($carts as $cart) {
|
||||||
|
|||||||
@@ -9,20 +9,22 @@ use Modules\Core\Cart\Filament\Resources\CartResource\Pages\ViewCart;
|
|||||||
use Filament\Resources\Resource;
|
use Filament\Resources\Resource;
|
||||||
use Filament\Tables;
|
use Filament\Tables;
|
||||||
use Filament\Tables\Table;
|
use Filament\Tables\Table;
|
||||||
use Illuminate\Database\Eloquent\Builder;
|
|
||||||
use Illuminate\Support\Carbon;
|
use Illuminate\Support\Carbon;
|
||||||
use Lunar\Admin\Filament\Resources\CustomerResource;
|
use Lunar\Admin\Filament\Resources\CustomerResource;
|
||||||
use Lunar\Models\Cart;
|
use Lunar\Models\Cart;
|
||||||
use Modules\Core\Cart\Filament\Resources\CartResource\Pages;
|
use Modules\Core\Cart\Filament\Resources\CartResource\Pages;
|
||||||
|
use Modules\Core\Cart\Services\CartLifecycleService;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Read-only — a cart is managed entirely through the storefront (add/update/remove
|
* Read-only — a cart is managed entirely through the storefront (add/update/remove
|
||||||
* line, checkout), never hand-edited by staff. Scoped to carts with a known
|
* line, checkout), never hand-edited by staff. Lists every cart, guest carts
|
||||||
* `user_id`/`customer_id` only: an anonymous guest's session cart carries no
|
* included — see docs/cart.md ("Scope: every cart, identified or not"). An
|
||||||
* identity a staff member could act on (no name, no email, nothing to follow up
|
* anonymous cart's Customer/User columns just render "—" (see table() below)
|
||||||
* with), so listing every such row would be noise, not a real admin capability —
|
* rather than the row being hidden outright: most real traffic never reaches
|
||||||
* see docs/cart.md for the reasoning (Lunar itself ships no cart admin view at all
|
* an identified user/customer, and "how many carts are ongoing/abandoned
|
||||||
* to follow a precedent from).
|
* right now" is a real reporting need regardless of identity — excluding
|
||||||
|
* anonymous carts would silently undercount it. Lunar itself ships no cart
|
||||||
|
* admin view at all to follow a precedent from.
|
||||||
*/
|
*/
|
||||||
class CartResource extends Resource
|
class CartResource extends Resource
|
||||||
{
|
{
|
||||||
@@ -36,12 +38,6 @@ class CartResource extends Resource
|
|||||||
|
|
||||||
protected static ?string $pluralModelLabel = 'Carts';
|
protected static ?string $pluralModelLabel = 'Carts';
|
||||||
|
|
||||||
public static function getEloquentQuery(): Builder
|
|
||||||
{
|
|
||||||
return parent::getEloquentQuery()
|
|
||||||
->where(fn (Builder $query) => $query->whereNotNull('user_id')->orWhereNotNull('customer_id'));
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Count only, not a fetch — no rows are loaded. Combines BOTH abandoned
|
* Count only, not a fetch — no rows are loaded. Combines BOTH abandoned
|
||||||
* states (`active()` already covers "no order at all" and "draft order,
|
* states (`active()` already covers "no order at all" and "draft order,
|
||||||
@@ -56,6 +52,11 @@ class CartResource extends Resource
|
|||||||
return (string) static::getEloquentQuery()->active()->where('updated_at', '<=', static::abandonedCutoff())->count();
|
return (string) static::getEloquentQuery()->active()->where('updated_at', '<=', static::abandonedCutoff())->count();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public static function lifecycle(): CartLifecycleService
|
||||||
|
{
|
||||||
|
return app(CartLifecycleService::class);
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* `Cart::scopeActive()` (not-yet-converted-to-an-order carts) mixes two very
|
* `Cart::scopeActive()` (not-yet-converted-to-an-order carts) mixes two very
|
||||||
* different things together: a cart someone is actively shopping in right now,
|
* different things together: a cart someone is actively shopping in right now,
|
||||||
@@ -67,7 +68,7 @@ class CartResource extends Resource
|
|||||||
*/
|
*/
|
||||||
public static function abandonedCutoff(): Carbon
|
public static function abandonedCutoff(): Carbon
|
||||||
{
|
{
|
||||||
return now()->sub(config('core.cart.abandoned_after', '1 hour'));
|
return static::lifecycle()->abandonedCutoff();
|
||||||
}
|
}
|
||||||
|
|
||||||
public static function table(Table $table): Table
|
public static function table(Table $table): Table
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ use Filament\Schemas\Components\Tabs\Tab;
|
|||||||
use Filament\Resources\Pages\ListRecords;
|
use Filament\Resources\Pages\ListRecords;
|
||||||
use Illuminate\Database\Eloquent\Builder;
|
use Illuminate\Database\Eloquent\Builder;
|
||||||
use Modules\Core\Cart\Filament\Resources\CartResource;
|
use Modules\Core\Cart\Filament\Resources\CartResource;
|
||||||
|
use Modules\Core\Cart\Services\CartLifecycleService;
|
||||||
|
|
||||||
class ListCarts extends ListRecords
|
class ListCarts extends ListRecords
|
||||||
{
|
{
|
||||||
@@ -27,30 +28,24 @@ class ListCarts extends ListRecords
|
|||||||
* bucket — same distinction Modules\Core\Recovery\Events\CartAbandoned /
|
* bucket — same distinction Modules\Core\Recovery\Events\CartAbandoned /
|
||||||
* Modules\Core\Recovery\Events\CheckoutAbandoned draw.
|
* Modules\Core\Recovery\Events\CheckoutAbandoned draw.
|
||||||
*
|
*
|
||||||
* "Ongoing" vs the two abandoned tabs all split on `updated_at` against
|
* The four query shapes below live on Modules\Core\Cart\Services\
|
||||||
* `CartResource::abandonedCutoff()` — Lunar has no time-based staleness
|
* CartLifecycleService, shared with Modules\Core\Cart\Commands\
|
||||||
* signal of its own, so recent activity is the only thing distinguishing a
|
* DetectAbandonedCarts — see that service's docblock for why duplicating
|
||||||
* cart someone is shopping in right now from one genuinely left behind.
|
* them independently in both places was worth centralizing.
|
||||||
*/
|
*/
|
||||||
public function getTabs(): array
|
public function getTabs(): array
|
||||||
{
|
{
|
||||||
|
$lifecycle = app(CartLifecycleService::class);
|
||||||
|
|
||||||
return [
|
return [
|
||||||
'abandoned_cart' => Tab::make('Abandoned Cart')
|
'abandoned_cart' => Tab::make('Abandoned Cart')
|
||||||
->modifyQueryUsing(fn(Builder $query) => $query
|
->modifyQueryUsing(fn (Builder $query) => $lifecycle->abandonedCarts($query)),
|
||||||
->whereDoesntHave('orders')
|
|
||||||
->where('updated_at', '<=', CartResource::abandonedCutoff())),
|
|
||||||
'abandoned_checkout' => Tab::make('Abandoned Checkout')
|
'abandoned_checkout' => Tab::make('Abandoned Checkout')
|
||||||
->modifyQueryUsing(fn(Builder $query) => $query
|
->modifyQueryUsing(fn (Builder $query) => $lifecycle->abandonedCheckouts($query)),
|
||||||
->whereHas('orders', fn(Builder $query) => $query->whereNull('placed_at'))
|
|
||||||
->where('updated_at', '<=', CartResource::abandonedCutoff())),
|
|
||||||
|
|
||||||
'ongoing' => Tab::make('Ongoing')
|
'ongoing' => Tab::make('Ongoing')
|
||||||
->modifyQueryUsing(fn(Builder $query) => $query->active()->where('updated_at', '>', CartResource::abandonedCutoff())),
|
->modifyQueryUsing(fn (Builder $query) => $lifecycle->ongoing($query)),
|
||||||
'completed' => Tab::make('Completed')
|
'completed' => Tab::make('Completed')
|
||||||
->modifyQueryUsing(fn(Builder $query) => $query->whereHas(
|
->modifyQueryUsing(fn (Builder $query) => $lifecycle->completed($query)),
|
||||||
'orders',
|
|
||||||
fn(Builder $query) => $query->whereNotNull('placed_at'),
|
|
||||||
)),
|
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,12 +5,18 @@ namespace Modules\Core\Cart\Filament\Resources\CartResource\Pages;
|
|||||||
use Filament\Schemas\Schema;
|
use Filament\Schemas\Schema;
|
||||||
use Filament\Schemas\Components\Section;
|
use Filament\Schemas\Components\Section;
|
||||||
use Filament\Actions\Action;
|
use Filament\Actions\Action;
|
||||||
|
use Filament\Infolists\Components\ImageEntry;
|
||||||
use Filament\Infolists\Components\RepeatableEntry;
|
use Filament\Infolists\Components\RepeatableEntry;
|
||||||
use Filament\Infolists\Components\TextEntry;
|
use Filament\Infolists\Components\TextEntry;
|
||||||
use Filament\Resources\Pages\ViewRecord;
|
use Filament\Resources\Pages\ViewRecord;
|
||||||
|
use Filament\Support\Colors\Color;
|
||||||
|
use Illuminate\Database\Eloquent\Collection as EloquentCollection;
|
||||||
|
use Illuminate\Support\Facades\Blade;
|
||||||
use Lunar\Admin\Filament\Resources\CustomerResource;
|
use Lunar\Admin\Filament\Resources\CustomerResource;
|
||||||
|
use Lunar\Admin\Filament\Resources\ProductResource\Pages\EditProduct;
|
||||||
use Lunar\Models\Cart;
|
use Lunar\Models\Cart;
|
||||||
use Lunar\Models\CartLine;
|
use Lunar\Models\CartLine;
|
||||||
|
use Lunar\Models\ProductVariant;
|
||||||
use Modules\Core\Cart\Filament\Resources\CartResource;
|
use Modules\Core\Cart\Filament\Resources\CartResource;
|
||||||
|
|
||||||
class ViewCart extends ViewRecord
|
class ViewCart extends ViewRecord
|
||||||
@@ -35,12 +41,23 @@ class ViewCart extends ViewRecord
|
|||||||
* (a single view page load), not per-row in the list table, since running the
|
* (a single view page load), not per-row in the list table, since running the
|
||||||
* full pipeline for every row of a paginated table would be expensive for no
|
* full pipeline for every row of a paginated table would be expensive for no
|
||||||
* real benefit — see docs/lunar.md's Cart gotchas.
|
* real benefit — see docs/lunar.md's Cart gotchas.
|
||||||
|
*
|
||||||
|
* Eager-loads what the Lines section (below) reads off each line's
|
||||||
|
* purchasable — name, thumbnail, options — the same relations Lunar's
|
||||||
|
* own OrderItemsTable loads for an order's line items (`with(['purchasable'])`,
|
||||||
|
* see vendor/lunarphp/lunar/.../OrderItemsTable::getDefaultTable()) — so
|
||||||
|
* rendering the product grid doesn't N+1 per line.
|
||||||
*/
|
*/
|
||||||
protected function resolveRecord(int|string $key): Cart
|
protected function resolveRecord(int|string $key): Cart
|
||||||
{
|
{
|
||||||
/** @var Cart $cart */
|
/** @var Cart $cart */
|
||||||
$cart = parent::resolveRecord($key);
|
$cart = parent::resolveRecord($key);
|
||||||
|
|
||||||
|
$cart->load('lines.purchasable', 'shippingAddress.country');
|
||||||
|
|
||||||
|
EloquentCollection::make($cart->lines->pluck('purchasable')->filter(fn ($p) => $p instanceof ProductVariant))
|
||||||
|
->loadMissing(['product.thumbnail', 'images', 'values']);
|
||||||
|
|
||||||
return $cart->calculate();
|
return $cart->calculate();
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -77,6 +94,37 @@ class ViewCart extends ViewRecord
|
|||||||
RepeatableEntry::make('lines')
|
RepeatableEntry::make('lines')
|
||||||
->hiddenLabel()
|
->hiddenLabel()
|
||||||
->schema([
|
->schema([
|
||||||
|
ImageEntry::make('image')
|
||||||
|
->hiddenLabel()
|
||||||
|
->state(fn (CartLine $record) => $record->purchasable instanceof ProductVariant
|
||||||
|
? $record->purchasable->getThumbnail()?->getUrl('small')
|
||||||
|
: null)
|
||||||
|
->defaultImageUrl(fn () => 'data:image/svg+xml;base64,'.base64_encode(
|
||||||
|
Blade::render('<x-filament::icon icon="heroicon-o-photo" style="color:rgb('.Color::Gray[400].');"/>')
|
||||||
|
))
|
||||||
|
->imageSize(48),
|
||||||
|
TextEntry::make('description')
|
||||||
|
->label('Product')
|
||||||
|
// ProductVariant::getDescription()/getOption() are typed
|
||||||
|
// string but internally read translateAttribute()/
|
||||||
|
// translate(), which return null for a product/option
|
||||||
|
// with no attribute data set for the active locale —
|
||||||
|
// reading the underlying relations directly here avoids
|
||||||
|
// that TypeError rather than calling through them.
|
||||||
|
->state(fn (CartLine $record) => $record->purchasable instanceof ProductVariant
|
||||||
|
? ($record->purchasable->product?->translateAttribute('name') ?? '—')
|
||||||
|
: '—')
|
||||||
|
->url(fn (CartLine $record) => $record->purchasable instanceof ProductVariant
|
||||||
|
? EditProduct::getUrl(['record' => $record->purchasable->product_id])
|
||||||
|
: null)
|
||||||
|
->weight('bold'),
|
||||||
|
TextEntry::make('options')
|
||||||
|
->label('Options')
|
||||||
|
->state(fn (CartLine $record) => $record->purchasable instanceof ProductVariant
|
||||||
|
? ($record->purchasable->values->map(fn ($value) => $value->translate('name'))->filter()->join(', ') ?: null)
|
||||||
|
: null)
|
||||||
|
->placeholder('—')
|
||||||
|
->badge(),
|
||||||
TextEntry::make('purchasable.sku')
|
TextEntry::make('purchasable.sku')
|
||||||
->label('SKU')
|
->label('SKU')
|
||||||
->placeholder('—'),
|
->placeholder('—'),
|
||||||
@@ -90,6 +138,53 @@ class ViewCart extends ViewRecord
|
|||||||
])
|
])
|
||||||
->columns(4),
|
->columns(4),
|
||||||
]),
|
]),
|
||||||
|
Section::make('Shipping')
|
||||||
|
->columns(3)
|
||||||
|
->schema([
|
||||||
|
TextEntry::make('shippingAddress.shipping_option')
|
||||||
|
->label('Shipping method')
|
||||||
|
// The raw identifier (e.g. "acs") is all a
|
||||||
|
// CartAddress row stores — the human-readable
|
||||||
|
// name only exists on the resolved
|
||||||
|
// Lunar\DataTypes\ShippingOption, which is what
|
||||||
|
// shippingBreakdown's items are keyed/named
|
||||||
|
// from below, so fall back to that name rather
|
||||||
|
// than showing the bare identifier.
|
||||||
|
->formatStateUsing(fn (Cart $record, ?string $state) => $state
|
||||||
|
? ($record->shippingBreakdown?->items->get($state)?->name ?? $state)
|
||||||
|
: null)
|
||||||
|
->placeholder('Not selected'),
|
||||||
|
TextEntry::make('shippingAddress.country.name')
|
||||||
|
->label('Shipping to')
|
||||||
|
->placeholder('—'),
|
||||||
|
TextEntry::make('shippingTotal')
|
||||||
|
->label('Shipping total')
|
||||||
|
->formatStateUsing(fn (Cart $record) => $record->shippingTotal?->formatted() ?? '—')
|
||||||
|
->weight('bold'),
|
||||||
|
RepeatableEntry::make('shippingBreakdownItems')
|
||||||
|
->label('Breakdown')
|
||||||
|
->columnSpanFull()
|
||||||
|
// shippingBreakdown->items is a plain (non-Eloquent)
|
||||||
|
// Collection of Lunar\Base\ValueObjects\Cart\
|
||||||
|
// ShippingBreakdownItem — e.g. the carrier rate and,
|
||||||
|
// separately, Modules\Core\Payment\Pipelines\Cart\
|
||||||
|
// ApplyPaymentMethodFee's own line item when the
|
||||||
|
// selected payment method carries a fee (see
|
||||||
|
// CHANGELOG 0.16.3) — both show up here individually
|
||||||
|
// rather than only as the summed shippingTotal above.
|
||||||
|
->state(fn (Cart $record) => $record->shippingBreakdown?->items->values() ?? [])
|
||||||
|
->schema([
|
||||||
|
TextEntry::make('name')
|
||||||
|
->hiddenLabel(),
|
||||||
|
TextEntry::make('price')
|
||||||
|
->hiddenLabel()
|
||||||
|
->formatStateUsing(fn ($state) => $state?->formatted() ?? '—')
|
||||||
|
->alignEnd(),
|
||||||
|
])
|
||||||
|
->columns(2)
|
||||||
|
->visible(fn (Cart $record) => (bool) $record->shippingBreakdown?->items->isNotEmpty()),
|
||||||
|
])
|
||||||
|
->visible(fn (Cart $record) => $record->shippingAddress !== null),
|
||||||
Section::make('Totals')
|
Section::make('Totals')
|
||||||
->columns(3)
|
->columns(3)
|
||||||
->schema([
|
->schema([
|
||||||
|
|||||||
@@ -0,0 +1,108 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Cart\Privacy;
|
||||||
|
|
||||||
|
use Lunar\Models\Cart;
|
||||||
|
use Lunar\Models\CartAddress;
|
||||||
|
use Modules\Core\Privacy\Contracts\PersonalDataProvider;
|
||||||
|
use Modules\Core\Privacy\DTOs\CustomerSubject;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureOutcome;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderErasureResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderExportResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\UserSubject;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Carts and cart addresses (lunar_carts, lunar_cart_addresses) belong to the
|
||||||
|
* Customer (business account) via customer_id, not to an individual User, so this
|
||||||
|
* is Customer-scope only. Unlike Order/OrderAddress, an abandoned cart has no
|
||||||
|
* legal retention requirement, so its addresses are freely deleted. The Cart row
|
||||||
|
* itself is left alone (any completed order it produced is handled separately by
|
||||||
|
* OrderDataProvider, which is what retention law actually cares about) — only its
|
||||||
|
* address PII is removed.
|
||||||
|
*
|
||||||
|
* Also covers Cart.meta's own PII-adjacent keys — Modules\Core\Checkout\Services\
|
||||||
|
* CheckoutService::setRecoveryConsent()/selectPaymentMethod() write
|
||||||
|
* recovery_consent/recovery_consent_at/recovery_consent_policy_version and
|
||||||
|
* payment_method/checkout_fingerprint directly onto this same Cart row, which the
|
||||||
|
* address-only erase above never touched. Kept Customer-scope, consistent with
|
||||||
|
* how Cart itself is already classified — see docs/privacy.md for the
|
||||||
|
* User-vs-Customer discussion this raised.
|
||||||
|
*/
|
||||||
|
class CartDataProvider implements PersonalDataProvider
|
||||||
|
{
|
||||||
|
private const META_KEYS = [
|
||||||
|
'recovery_consent',
|
||||||
|
'recovery_consent_at',
|
||||||
|
'recovery_consent_policy_version',
|
||||||
|
'payment_method',
|
||||||
|
'checkout_fingerprint',
|
||||||
|
];
|
||||||
|
|
||||||
|
public function name(): string
|
||||||
|
{
|
||||||
|
return 'carts';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$carts = Cart::where('customer_id', $subject->customerId)->get();
|
||||||
|
|
||||||
|
$addresses = CartAddress::whereIn('cart_id', $carts->pluck('id'))->get();
|
||||||
|
|
||||||
|
return new ProviderExportResult('carts', [
|
||||||
|
'addresses' => $addresses->map(fn (CartAddress $address) => [
|
||||||
|
'type' => $address->type,
|
||||||
|
'first_name' => $address->first_name,
|
||||||
|
'last_name' => $address->last_name,
|
||||||
|
'line_one' => $address->line_one,
|
||||||
|
'city' => $address->city,
|
||||||
|
'postcode' => $address->postcode,
|
||||||
|
'contact_email' => $address->contact_email,
|
||||||
|
'contact_phone' => $address->contact_phone,
|
||||||
|
])->all(),
|
||||||
|
'carts' => $carts->map(fn (Cart $cart) => [
|
||||||
|
'id' => $cart->id,
|
||||||
|
'meta' => $this->metaOnly($cart),
|
||||||
|
])->all(),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
return new ProviderExportResult('carts', []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
$carts = Cart::where('customer_id', $subject->customerId)->get();
|
||||||
|
|
||||||
|
CartAddress::whereIn('cart_id', $carts->pluck('id'))->delete();
|
||||||
|
|
||||||
|
foreach ($carts as $cart) {
|
||||||
|
$meta = (array) $cart->meta;
|
||||||
|
|
||||||
|
foreach (self::META_KEYS as $key) {
|
||||||
|
unset($meta[$key]);
|
||||||
|
}
|
||||||
|
|
||||||
|
$cart->update(['meta' => $meta]);
|
||||||
|
}
|
||||||
|
|
||||||
|
return new ProviderErasureResult('carts', ErasureOutcome::Erased);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
return new ProviderErasureResult('carts', ErasureOutcome::Skipped, 'Carts belong to Customer accounts, not individual users.');
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return array<string, mixed>
|
||||||
|
*/
|
||||||
|
private function metaOnly(Cart $cart): array
|
||||||
|
{
|
||||||
|
$meta = (array) $cart->meta;
|
||||||
|
|
||||||
|
return array_intersect_key($meta, array_flip(self::META_KEYS));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,99 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Cart\Services;
|
||||||
|
|
||||||
|
use Illuminate\Database\Eloquent\Builder;
|
||||||
|
use Illuminate\Support\Carbon;
|
||||||
|
use Lunar\Models\Cart;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The single source of truth for the four cart lifecycle states documented in
|
||||||
|
* docs/cart.md ("Four states, not two — and not Cart::completed_at"). Both
|
||||||
|
* Modules\Core\Cart\Filament\Resources\CartResource/ListCarts (staff-facing
|
||||||
|
* browsing/tabs) and Modules\Core\Cart\Commands\DetectAbandonedCarts
|
||||||
|
* (abandonment-event dispatch) build on these same four query shapes — before
|
||||||
|
* this existed, each reimplemented them independently, which is exactly the
|
||||||
|
* kind of drift that lets the admin panel and the recovery-email pipeline
|
||||||
|
* quietly disagree about what "abandoned" means.
|
||||||
|
*
|
||||||
|
* `Cart::completed_at` is declared/cast on the model but never actually
|
||||||
|
* written anywhere in Lunar core — not a real signal, not used here.
|
||||||
|
* `Cart::scopeActive()` (Lunar's own "not yet converted to an order" scope)
|
||||||
|
* mixes two distinct states together (no order at all vs. a draft order that
|
||||||
|
* was never placed) — see docs/cart.md for why they're kept apart as
|
||||||
|
* different purchase-intent/reachability signals rather than folded into one
|
||||||
|
* "not converted" bucket.
|
||||||
|
*
|
||||||
|
* Query shape only: consent (`meta->recovery_consent`) and non-empty-lines
|
||||||
|
* filtering stay in DetectAbandonedCarts, not here — those are specific to
|
||||||
|
* whether a recovery event should fire, not to what "abandoned" means. Staff
|
||||||
|
* browsing the admin panel should see every abandoned cart, consenting or
|
||||||
|
* not.
|
||||||
|
*
|
||||||
|
* `unrecoverableCutoff()` is a second, older threshold
|
||||||
|
* (`core.cart.unrecoverable_after`, default 90 days) applied as a lower
|
||||||
|
* bound on both abandoned*() methods below: a cart past it is too old to be
|
||||||
|
* a realistic recovery target (pricing/stock/tax have likely moved on), so
|
||||||
|
* it drops out of "Abandoned Cart"/"Abandoned Checkout" entirely rather than
|
||||||
|
* staying flagged as an actionable abandonment forever. It does not appear
|
||||||
|
* in `ongoing()`/`completed()` either — this is about the abandoned-cart
|
||||||
|
* pipeline specifically, not a retention/deletion policy (no rows are
|
||||||
|
* touched here).
|
||||||
|
*/
|
||||||
|
class CartLifecycleService
|
||||||
|
{
|
||||||
|
public function abandonedCutoff(): Carbon
|
||||||
|
{
|
||||||
|
return now()->sub(config('core.cart.abandoned_after', '1 hour'));
|
||||||
|
}
|
||||||
|
|
||||||
|
public function unrecoverableCutoff(): Carbon
|
||||||
|
{
|
||||||
|
return now()->sub(config('core.cart.unrecoverable_after', '90 days'));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Not yet converted to an order (scopeActive()), with recent activity —
|
||||||
|
* someone plausibly shopping right now, not (yet) left behind.
|
||||||
|
*/
|
||||||
|
public function ongoing(Builder $query): Builder
|
||||||
|
{
|
||||||
|
return $query->active()->where('updated_at', '>', $this->abandonedCutoff());
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* No order started at all, stale, not yet past the unrecoverable cap, and
|
||||||
|
* actually has something in it — the weaker of the two abandoned states
|
||||||
|
* (see docs/cart.md's "Abandoned Cart vs Abandoned Checkout"). An empty
|
||||||
|
* cart (created but nothing ever added — e.g. a bot, or a session that
|
||||||
|
* never shopped) was never really "abandoned"; there's nothing to
|
||||||
|
* recover, so it's excluded rather than counted as a false positive.
|
||||||
|
*/
|
||||||
|
public function abandonedCarts(Builder $query): Builder
|
||||||
|
{
|
||||||
|
return $query->whereDoesntHave('orders')
|
||||||
|
->whereHas('lines')
|
||||||
|
->where('updated_at', '<=', $this->abandonedCutoff())
|
||||||
|
->where('updated_at', '>', $this->unrecoverableCutoff());
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A draft order exists (checkout was started) but was never placed,
|
||||||
|
* stale, and not yet past the unrecoverable cap — the stronger of the
|
||||||
|
* two abandoned states.
|
||||||
|
*/
|
||||||
|
public function abandonedCheckouts(Builder $query): Builder
|
||||||
|
{
|
||||||
|
return $query->whereHas('orders', fn (Builder $query) => $query->whereNull('placed_at'))
|
||||||
|
->where('updated_at', '<=', $this->abandonedCutoff())
|
||||||
|
->where('updated_at', '>', $this->unrecoverableCutoff());
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Has an order that was actually placed, not just drafted.
|
||||||
|
*/
|
||||||
|
public function completed(Builder $query): Builder
|
||||||
|
{
|
||||||
|
return $query->whereHas('orders', fn (Builder $query) => $query->whereNotNull('placed_at'));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -47,8 +47,12 @@ use Spatie\MediaLibrary\MediaCollections\Models\Media;
|
|||||||
* quantity 1, via ProductVariant::canBeFulfilledAtQuantity() (Lunar's own
|
* quantity 1, via ProductVariant::canBeFulfilledAtQuantity() (Lunar's own
|
||||||
* purchasability rule: `purchasable === 'always'` is always true regardless of
|
* purchasability rule: `purchasable === 'always'` is always true regardless of
|
||||||
* stock, `in_stock` checks stock alone, anything else checks stock+backorder).
|
* stock, `in_stock` checks stock alone, anything else checks stock+backorder).
|
||||||
* Reflects stock as of the last reindex only — nothing currently reindexes a
|
* Modules\Core\Order\Listeners\DecrementStockOnOrderPlaced reindexes a product
|
||||||
* product when an order decrements its stock (see docs/product-listing.md).
|
* the moment an order placed against it decrements its stock — see that
|
||||||
|
* class's own docblock for why only `purchasable === 'in_stock'`
|
||||||
|
* variants are ever touched. Any other stock edit (a manual admin
|
||||||
|
* change, a future inventory-sync integration) still only reflects here
|
||||||
|
* as of the next reindex (see docs/product-listing.md).
|
||||||
*
|
*
|
||||||
* - recommendations (recommendations.id filterable): [{id, name, price, image}, ...]
|
* - recommendations (recommendations.id filterable): [{id, name, price, image}, ...]
|
||||||
* up to 4 other products to show alongside this one (a "related products"
|
* up to 4 other products to show alongside this one (a "related products"
|
||||||
|
|||||||
@@ -2,12 +2,14 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Catalog\Services;
|
namespace Modules\Core\Catalog\Services;
|
||||||
|
|
||||||
use Illuminate\Database\Eloquent\Collection;
|
use Illuminate\Pagination\LengthAwarePaginator;
|
||||||
use Lunar\Facades\AttributeManifest;
|
use Lunar\Facades\AttributeManifest;
|
||||||
use Lunar\Models\Language;
|
use Lunar\Models\Language;
|
||||||
use Lunar\Models\Product;
|
use Lunar\Models\Product;
|
||||||
use Modules\Core\Catalog\DTOs\ProductFilters;
|
use Modules\Core\Catalog\DTOs\ProductFilters;
|
||||||
|
use Modules\Core\Catalog\DTOs\ProductListingResult;
|
||||||
use Modules\Core\Catalog\Enums\ProductSort;
|
use Modules\Core\Catalog\Enums\ProductSort;
|
||||||
|
use Modules\Core\Catalog\Support\ProductDocumentLocalizer;
|
||||||
use Modules\Core\Catalog\Support\ProductFilterBuilder;
|
use Modules\Core\Catalog\Support\ProductFilterBuilder;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -21,20 +23,37 @@ class ProductSearchService
|
|||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly ProductFilterBuilder $filterBuilder,
|
private readonly ProductFilterBuilder $filterBuilder,
|
||||||
|
private readonly ProductDocumentLocalizer $localizer,
|
||||||
|
private readonly ProductService $products,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
* Returns the exact same Modules\Core\Catalog\DTOs\ProductListingResult
|
||||||
|
* ProductService::list() does — a search results page and a category
|
||||||
|
* listing page consume identically shaped data, one call each. The
|
||||||
|
* paginator itself carries plain, localized indexed-document arrays
|
||||||
|
* (not hydrated Product models), same as list().
|
||||||
|
*
|
||||||
|
* priceBounds/availableTags are delegated to ProductService's own
|
||||||
|
* priceSliderBounds()/availableTags() rather than reimplemented here —
|
||||||
|
* both already accept a $query param for exactly this reason (a search
|
||||||
|
* page's slider/tag sidebar should reflect only the products search
|
||||||
|
* actually matched, not the whole catalog).
|
||||||
|
*
|
||||||
* $filters/$sort apply the exact same semantics ProductService::list()
|
* $filters/$sort apply the exact same semantics ProductService::list()
|
||||||
* uses for collection browsing (same ProductFilterBuilder, same
|
* uses for collection browsing (same ProductFilterBuilder, same
|
||||||
* ProductSort::toMeilisearchSort()) — a shopper narrowing a text search
|
* ProductSort::toMeilisearchSort()) — a shopper narrowing a text search
|
||||||
* by price/brand/stock gets identical filter behavior to narrowing a
|
* by price/brand/stock gets identical filter behavior to narrowing a
|
||||||
* category listing, since both go through the same Meilisearch `filter`
|
* category listing, since both go through the same Meilisearch `filter`
|
||||||
* clause underneath.
|
* clause underneath.
|
||||||
*
|
|
||||||
* @return Collection<int, Product>
|
|
||||||
*/
|
*/
|
||||||
public function search(string $query, ?ProductFilters $filters = null, ?ProductSort $sort = null): Collection
|
public function search(
|
||||||
{
|
string $query,
|
||||||
|
?ProductFilters $filters = null,
|
||||||
|
?ProductSort $sort = null,
|
||||||
|
int $perPage = 24,
|
||||||
|
int $page = 1,
|
||||||
|
): ProductListingResult {
|
||||||
$options = [
|
$options = [
|
||||||
'attributesToSearchOn' => $this->searchableFields(),
|
'attributesToSearchOn' => $this->searchableFields(),
|
||||||
'filter' => $this->filterBuilder->build($filters),
|
'filter' => $this->filterBuilder->build($filters),
|
||||||
@@ -44,9 +63,26 @@ class ProductSearchService
|
|||||||
$options['sort'] = [$sort->toMeilisearchSort()];
|
$options['sort'] = [$sort->toMeilisearchSort()];
|
||||||
}
|
}
|
||||||
|
|
||||||
return Product::search($query)
|
$paginator = Product::search($query)
|
||||||
->options($options)
|
->options($options)
|
||||||
->get();
|
->paginateRaw(perPage: $perPage, page: $page);
|
||||||
|
|
||||||
|
$data = collect($this->localizer->hitsFrom($paginator))
|
||||||
|
->map(fn (array $product) => $this->localizer->withLocalizedFields($product))
|
||||||
|
->all();
|
||||||
|
|
||||||
|
$products = new LengthAwarePaginator(
|
||||||
|
items: $data,
|
||||||
|
total: $paginator->total(),
|
||||||
|
perPage: $paginator->perPage(),
|
||||||
|
currentPage: $paginator->currentPage(),
|
||||||
|
options: ['path' => LengthAwarePaginator::resolveCurrentPath()],
|
||||||
|
);
|
||||||
|
|
||||||
|
$priceBounds = $this->products->priceSliderBounds($filters, $filters?->minPrice, $filters?->maxPrice, $query);
|
||||||
|
$availableTags = $this->products->availableTags($filters, $query);
|
||||||
|
|
||||||
|
return new ProductListingResult($products, $priceBounds, $availableTags);
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -2,17 +2,13 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Catalog\Services;
|
namespace Modules\Core\Catalog\Services;
|
||||||
|
|
||||||
use Illuminate\Contracts\Pagination\LengthAwarePaginator as LengthAwarePaginatorContract;
|
|
||||||
use Illuminate\Pagination\LengthAwarePaginator;
|
use Illuminate\Pagination\LengthAwarePaginator;
|
||||||
use Illuminate\Support\Facades\App;
|
|
||||||
use Lunar\Base\AttributeManifest;
|
|
||||||
use Lunar\FieldTypes\TranslatedText;
|
|
||||||
use Lunar\Models\Product;
|
use Lunar\Models\Product;
|
||||||
use Modules\Core\Localization\Services\LanguageCache;
|
|
||||||
use Modules\Core\Catalog\DTOs\PriceSliderBounds;
|
use Modules\Core\Catalog\DTOs\PriceSliderBounds;
|
||||||
use Modules\Core\Catalog\DTOs\ProductFilters;
|
use Modules\Core\Catalog\DTOs\ProductFilters;
|
||||||
use Modules\Core\Catalog\DTOs\ProductListingResult;
|
use Modules\Core\Catalog\DTOs\ProductListingResult;
|
||||||
use Modules\Core\Catalog\Enums\ProductSort;
|
use Modules\Core\Catalog\Enums\ProductSort;
|
||||||
|
use Modules\Core\Catalog\Support\ProductDocumentLocalizer;
|
||||||
use Modules\Core\Catalog\Support\ProductFilterBuilder;
|
use Modules\Core\Catalog\Support\ProductFilterBuilder;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -27,8 +23,7 @@ use Modules\Core\Catalog\Support\ProductFilterBuilder;
|
|||||||
class ProductService
|
class ProductService
|
||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly LanguageCache $languages,
|
private readonly ProductDocumentLocalizer $localizer,
|
||||||
private readonly AttributeManifest $attributes,
|
|
||||||
private readonly ProductFilterBuilder $filterBuilder,
|
private readonly ProductFilterBuilder $filterBuilder,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
@@ -65,8 +60,8 @@ class ProductService
|
|||||||
->options($options)
|
->options($options)
|
||||||
->paginateRaw(perPage: $perPage, page: $page);
|
->paginateRaw(perPage: $perPage, page: $page);
|
||||||
|
|
||||||
$data = collect($this->hitsFrom($paginator))
|
$data = collect($this->localizer->hitsFrom($paginator))
|
||||||
->map(fn (array $product) => $this->withLocalizedFields($product))
|
->map(fn (array $product) => $this->localizer->withLocalizedFields($product))
|
||||||
->all();
|
->all();
|
||||||
|
|
||||||
$products = new LengthAwarePaginator(
|
$products = new LengthAwarePaginator(
|
||||||
@@ -91,12 +86,20 @@ class ProductService
|
|||||||
* alphabetically; Meilisearch's facetDistribution has no defined order
|
* alphabetically; Meilisearch's facetDistribution has no defined order
|
||||||
* of its own.
|
* of its own.
|
||||||
*
|
*
|
||||||
|
* $query defaults to '' (every product, same as list()'s own default
|
||||||
|
* text query) — same reasoning as priceRange()'s own $query: pass the
|
||||||
|
* shopper's search text here too so a search page's own tag sidebar
|
||||||
|
* reflects only the products search actually matched. Public (not
|
||||||
|
* private, unlike the rest of this listing-only orchestration) so
|
||||||
|
* ProductSearchService::search() can reuse it directly rather than
|
||||||
|
* reimplementing the same facet call a second time.
|
||||||
|
*
|
||||||
* @return array<int, string>
|
* @return array<int, string>
|
||||||
*/
|
*/
|
||||||
private function availableTags(?ProductFilters $filters): array
|
public function availableTags(?ProductFilters $filters, string $query = ''): array
|
||||||
{
|
{
|
||||||
$filter = $this->filterBuilder->build($filters, exclude: ['tag']);
|
$filter = $this->filterBuilder->build($filters, exclude: ['tag']);
|
||||||
$tags = $this->rawFacets('tags', $filter)['facetDistribution']['tags'] ?? [];
|
$tags = $this->rawFacets('tags', $filter, $query)['facetDistribution']['tags'] ?? [];
|
||||||
|
|
||||||
return collect($tags)->keys()->sort()->values()->all();
|
return collect($tags)->keys()->sort()->values()->all();
|
||||||
}
|
}
|
||||||
@@ -287,69 +290,8 @@ class ProductService
|
|||||||
->options(['filter' => $filter])
|
->options(['filter' => $filter])
|
||||||
->paginateRaw(perPage: $limit, page: 1);
|
->paginateRaw(perPage: $limit, page: 1);
|
||||||
|
|
||||||
return collect($this->hitsFrom($paginator))
|
return collect($this->localizer->hitsFrom($paginator))
|
||||||
->map(fn (array $product) => $this->withLocalizedFields($product))
|
->map(fn (array $product) => $this->localizer->withLocalizedFields($product))
|
||||||
->all();
|
->all();
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* Resolves every translated Product attribute's current-locale value from the
|
|
||||||
* indexer's per-locale `{handle}_{locale}` fields (e.g. `name_el`, `name_en`,
|
|
||||||
* `seo_title_el`, ...) into a plain `{handle}` key, falling back to the store's
|
|
||||||
* default language (LanguageCache::defaultLocale()) when the current locale
|
|
||||||
* has no translation - e.g. a product with no English copy yet still shows its
|
|
||||||
* Greek name on /en/ rather than rendering blank.
|
|
||||||
*
|
|
||||||
* Which handles are translated is read from AttributeManifest - the same
|
|
||||||
* source Lunar's own ScoutIndexer reads when exploding a TranslatedText
|
|
||||||
* attribute into `{handle}_{locale}` keys at index time - rather than a fixed
|
|
||||||
* list, so a store's own custom translated attributes (e.g. `seo_title`) are
|
|
||||||
* picked up automatically with no change here. The raw per-locale keys are
|
|
||||||
* then stripped, since once resolved, callers only ever need the one that
|
|
||||||
* matched the current locale.
|
|
||||||
*
|
|
||||||
* Deliberately not config('app.locale') - App::setLocale() overwrites that
|
|
||||||
* config value on every request, so by request time it's just whatever the
|
|
||||||
* current locale already is, not a stable fallback.
|
|
||||||
*/
|
|
||||||
private function withLocalizedFields(array $product): array
|
|
||||||
{
|
|
||||||
$locale = App::getLocale();
|
|
||||||
$fallbackLocale = $this->languages->defaultLocale();
|
|
||||||
$availableLocales = $this->languages->availableLocales();
|
|
||||||
|
|
||||||
foreach ($this->translatedAttributeHandles() as $handle) {
|
|
||||||
$product[$handle] = $product[$handle.'_'.$locale] ?? $product[$handle.'_'.$fallbackLocale] ?? null;
|
|
||||||
|
|
||||||
foreach ($availableLocales as $availableLocale) {
|
|
||||||
unset($product[$handle.'_'.$availableLocale]);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return $product;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* @return array<int, string>
|
|
||||||
*/
|
|
||||||
private function translatedAttributeHandles(): array
|
|
||||||
{
|
|
||||||
return $this->attributes->getSearchableAttributes((new Product)->getMorphClass())
|
|
||||||
->filter(fn ($attribute) => $attribute->type === TranslatedText::class)
|
|
||||||
->pluck('handle')
|
|
||||||
->all();
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* For the Meilisearch driver, Scout's paginateRaw() puts the whole raw response
|
|
||||||
* (hits, query, processingTimeMs, ...) in items(), not a plain list of hits - the
|
|
||||||
* actual documents are under the 'hits' key.
|
|
||||||
*/
|
|
||||||
private function hitsFrom(LengthAwarePaginatorContract $paginator): array
|
|
||||||
{
|
|
||||||
$rawResponse = $paginator->items();
|
|
||||||
|
|
||||||
return collect($rawResponse['hits'] ?? [])->values()->all();
|
|
||||||
}
|
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,86 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Catalog\Support;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Pagination\LengthAwarePaginator as LengthAwarePaginatorContract;
|
||||||
|
use Illuminate\Support\Facades\App;
|
||||||
|
use Lunar\Base\AttributeManifest;
|
||||||
|
use Lunar\FieldTypes\TranslatedText;
|
||||||
|
use Lunar\Models\Product;
|
||||||
|
use Modules\Core\Localization\Services\LanguageCache;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Shared between Modules\Core\Catalog\Services\ProductService and
|
||||||
|
* ProductSearchService — both read the same kind of Meilisearch document
|
||||||
|
* (Modules\Core\Catalog\Services\ProductIndexer's shape) and need the
|
||||||
|
* exact same per-locale field resolution and raw-response unwrapping.
|
||||||
|
* Extracted rather than duplicated so a future fix to the localization-
|
||||||
|
* fallback logic only needs to be made once.
|
||||||
|
*/
|
||||||
|
class ProductDocumentLocalizer
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly LanguageCache $languages,
|
||||||
|
private readonly AttributeManifest $attributes,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Resolves every translated Product attribute's current-locale value from the
|
||||||
|
* indexer's per-locale `{handle}_{locale}` fields (e.g. `name_el`, `name_en`,
|
||||||
|
* `seo_title_el`, ...) into a plain `{handle}` key, falling back to the store's
|
||||||
|
* default language (LanguageCache::defaultLocale()) when the current locale
|
||||||
|
* has no translation - e.g. a product with no English copy yet still shows its
|
||||||
|
* Greek name on /en/ rather than rendering blank.
|
||||||
|
*
|
||||||
|
* Which handles are translated is read from AttributeManifest - the same
|
||||||
|
* source Lunar's own ScoutIndexer reads when exploding a TranslatedText
|
||||||
|
* attribute into `{handle}_{locale}` keys at index time - rather than a fixed
|
||||||
|
* list, so a store's own custom translated attributes (e.g. `seo_title`) are
|
||||||
|
* picked up automatically with no change here. The raw per-locale keys are
|
||||||
|
* then stripped, since once resolved, callers only ever need the one that
|
||||||
|
* matched the current locale.
|
||||||
|
*
|
||||||
|
* Deliberately not config('app.locale') - App::setLocale() overwrites that
|
||||||
|
* config value on every request, so by request time it's just whatever the
|
||||||
|
* current locale already is, not a stable fallback.
|
||||||
|
*/
|
||||||
|
public function withLocalizedFields(array $product): array
|
||||||
|
{
|
||||||
|
$locale = App::getLocale();
|
||||||
|
$fallbackLocale = $this->languages->defaultLocale();
|
||||||
|
$availableLocales = $this->languages->availableLocales();
|
||||||
|
|
||||||
|
foreach ($this->translatedAttributeHandles() as $handle) {
|
||||||
|
$product[$handle] = $product[$handle.'_'.$locale] ?? $product[$handle.'_'.$fallbackLocale] ?? null;
|
||||||
|
|
||||||
|
foreach ($availableLocales as $availableLocale) {
|
||||||
|
unset($product[$handle.'_'.$availableLocale]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return $product;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* For the Meilisearch driver, Scout's paginateRaw() puts the whole raw response
|
||||||
|
* (hits, query, processingTimeMs, ...) in items(), not a plain list of hits - the
|
||||||
|
* actual documents are under the 'hits' key.
|
||||||
|
*/
|
||||||
|
public function hitsFrom(LengthAwarePaginatorContract $paginator): array
|
||||||
|
{
|
||||||
|
$rawResponse = $paginator->items();
|
||||||
|
|
||||||
|
return collect($rawResponse['hits'] ?? [])->values()->all();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return array<int, string>
|
||||||
|
*/
|
||||||
|
private function translatedAttributeHandles(): array
|
||||||
|
{
|
||||||
|
return $this->attributes->getSearchableAttributes((new Product)->getMorphClass())
|
||||||
|
->filter(fn ($attribute) => $attribute->type === TranslatedText::class)
|
||||||
|
->pluck('handle')
|
||||||
|
->all();
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Checkout\Events;
|
||||||
|
|
||||||
|
use Lunar\Models\Cart;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by CheckoutService::setRecoveryConsent() every time the
|
||||||
|
* shopper's promotional/abandoned-cart-recovery opt-in changes — including
|
||||||
|
* an explicit opt-OUT (a later submit with the checkbox unticked), not
|
||||||
|
* just an opt-in. $consent is the new value, already written to
|
||||||
|
* Cart::meta by the time this fires.
|
||||||
|
*/
|
||||||
|
class RecoveryConsentSet
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly Cart $cart,
|
||||||
|
public readonly bool $consent,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Checkout\Exceptions;
|
||||||
|
|
||||||
|
use RuntimeException;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Thrown by CheckoutService::initiatePayment() when $termsAccepted is
|
||||||
|
* false — an Order is a consumer contract, and its acceptance must be
|
||||||
|
* refused rather than created-then-flagged. No Lunar exception type
|
||||||
|
* covers this, same reasoning as UnknownPaymentTypeException.
|
||||||
|
*/
|
||||||
|
class TermsNotAcceptedException extends RuntimeException
|
||||||
|
{
|
||||||
|
public function __construct()
|
||||||
|
{
|
||||||
|
parent::__construct('The order cannot be placed until the terms have been accepted.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -13,13 +13,16 @@ use Lunar\Models\Cart;
|
|||||||
use Modules\Core\Cart\Services\CartService;
|
use Modules\Core\Cart\Services\CartService;
|
||||||
use Modules\Core\Checkout\Events\BillingAddressSet;
|
use Modules\Core\Checkout\Events\BillingAddressSet;
|
||||||
use Modules\Core\Checkout\Events\PaymentMethodSelected;
|
use Modules\Core\Checkout\Events\PaymentMethodSelected;
|
||||||
|
use Modules\Core\Checkout\Events\RecoveryConsentSet;
|
||||||
use Modules\Core\Checkout\Events\ShippingAddressSet;
|
use Modules\Core\Checkout\Events\ShippingAddressSet;
|
||||||
use Modules\Core\Checkout\Events\ShippingOptionSelected;
|
use Modules\Core\Checkout\Events\ShippingOptionSelected;
|
||||||
use Modules\Core\Checkout\Exceptions\InvalidShippingOptionException;
|
use Modules\Core\Checkout\Exceptions\InvalidShippingOptionException;
|
||||||
|
use Modules\Core\Checkout\Exceptions\TermsNotAcceptedException;
|
||||||
use Modules\Core\Checkout\Exceptions\UnknownPaymentTypeException;
|
use Modules\Core\Checkout\Exceptions\UnknownPaymentTypeException;
|
||||||
use Modules\Core\Payment\DTOs\PaymentResult;
|
use Modules\Core\Payment\DTOs\PaymentResult;
|
||||||
use Modules\Core\Payment\Models\PaymentMethod;
|
use Modules\Core\Payment\Models\PaymentMethod;
|
||||||
use Modules\Core\Payment\Services\PaymentDriverResolver;
|
use Modules\Core\Payment\Services\PaymentDriverRegistry;
|
||||||
|
use Modules\Core\Payment\Services\PaymentMethodCache;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Storefront-facing checkout operations, mirroring
|
* Storefront-facing checkout operations, mirroring
|
||||||
@@ -42,7 +45,8 @@ class CheckoutService
|
|||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly CartService $cart,
|
private readonly CartService $cart,
|
||||||
private readonly PaymentDriverResolver $paymentDrivers,
|
private readonly PaymentDriverRegistry $paymentDrivers,
|
||||||
|
private readonly PaymentMethodCache $paymentMethods,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
public function setShippingAddress(array|Addressable $address): Cart
|
public function setShippingAddress(array|Addressable $address): Cart
|
||||||
@@ -63,6 +67,49 @@ class CheckoutService
|
|||||||
return $cart;
|
return $cart;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The shopper's promotional/abandoned-cart-recovery opt-in — a
|
||||||
|
* cart-level decision, deliberately independent of setShippingAddress()/
|
||||||
|
* setBillingAddress(): consent is given once, and must NOT be reset or
|
||||||
|
* re-asked just because the shopper later changes which address is on
|
||||||
|
* the cart (a different Addressable being set is not a withdrawal of
|
||||||
|
* consent). Only an explicit call to THIS method — the checkbox itself
|
||||||
|
* being submitted, checked or unchecked — ever changes it; calling it
|
||||||
|
* again with false is exactly how a later opt-out is recorded.
|
||||||
|
*
|
||||||
|
* Stored on Cart::meta (interim, per the legal design this implements —
|
||||||
|
* a real column/consent record is the eventual target) as
|
||||||
|
* recovery_consent (bool), recovery_consent_at (ISO 8601 timestamp,
|
||||||
|
* null when $consent is false), and recovery_consent_policy_version
|
||||||
|
* (config('legal.privacy_policy_version') at the moment of consent —
|
||||||
|
* so a later dispute is answered from what was actually agreed to,
|
||||||
|
* not whatever the policy says today). Separate from any future
|
||||||
|
* newsletter opt-in — recovery consent is its own scope, never merged
|
||||||
|
* with marketing-newsletter consent.
|
||||||
|
*
|
||||||
|
* Deliberately does not merge with the meta-writing pattern
|
||||||
|
* selectPaymentMethod() uses (read-merge-save in two separate
|
||||||
|
* statements) — this writes both meta keys in one save, since there's
|
||||||
|
* no dependency between recovery_consent and anything else needing to
|
||||||
|
* be persisted first.
|
||||||
|
*/
|
||||||
|
public function setRecoveryConsent(bool $consent): Cart
|
||||||
|
{
|
||||||
|
$cart = $this->cart->currentOrCreate();
|
||||||
|
|
||||||
|
$cart->meta = [
|
||||||
|
...($cart->meta?->toArray() ?? []),
|
||||||
|
'recovery_consent' => $consent,
|
||||||
|
'recovery_consent_at' => $consent ? now()->toIso8601String() : null,
|
||||||
|
'recovery_consent_policy_version' => $consent ? config('legal.privacy_policy_version') : null,
|
||||||
|
];
|
||||||
|
$cart->save();
|
||||||
|
|
||||||
|
Event::dispatch(new RecoveryConsentSet($cart, $consent));
|
||||||
|
|
||||||
|
return $cart;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Every shipping option currently available for the cart — already
|
* Every shipping option currently available for the cart — already
|
||||||
* fully backed by the merged Shipping-Carriers work: this runs every
|
* fully backed by the merged Shipping-Carriers work: this runs every
|
||||||
@@ -100,54 +147,56 @@ class CheckoutService
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Every payment type currently offered to the storefront — every key
|
* Every payment method currently offered to the storefront, ordered by
|
||||||
* in config('lunar.payments.types') that is BOTH administratively
|
* Modules\Core\Payment\Models\PaymentMethod::position — a row is
|
||||||
* enabled (Modules\Core\Payment\Models\PaymentMethod::enabled) AND
|
* offered only when ALL three checks pass, each meaning something
|
||||||
* whose registered driver reports itself usable right now
|
* different to an admin diagnosing why a method isn't showing up (see
|
||||||
* (Configurable::isConfigured() — e.g. Stripe with no API key set is
|
* docs/payments.md):
|
||||||
* never offered, regardless of the enabled toggle). A type with no
|
* 1. `enabled` — an admin turned it on.
|
||||||
* PaymentMethod row at all (never seeded) is treated as not offered,
|
* 2. its `driver` still resolves via PaymentDriverRegistry — the
|
||||||
* same as disabled — nothing here creates one; see
|
* driver class hasn't been removed (see the `payment:sync-drivers`
|
||||||
* InstallLunarCommand::seedPaymentMethods().
|
* command, which sets `driver_missing_at` when this fails; a row
|
||||||
|
* with that set is excluded here regardless of `enabled`, so a
|
||||||
|
* vanished driver can never silently look "available").
|
||||||
|
* 3. the resolved driver reports Configurable::isConfigured() — its
|
||||||
|
* own runtime requirements (e.g. an API key) are met.
|
||||||
*
|
*
|
||||||
* @return array<string>
|
* @return Collection<int, PaymentMethod>
|
||||||
*/
|
*/
|
||||||
public function getPaymentMethods(): array
|
public function getPaymentMethods(): Collection
|
||||||
{
|
{
|
||||||
return PaymentMethod::where('enabled', true)
|
return $this->paymentMethods->all()
|
||||||
->pluck('type')
|
->filter(fn (PaymentMethod $method) => $method->enabled && $method->driver_missing_at === null)
|
||||||
->filter(fn (string $type) => $this->paymentDrivers->resolve($type)?->isConfigured() ?? false)
|
->filter(fn (PaymentMethod $method) => $this->paymentDrivers->resolve($method->driver)?->isConfigured() ?? false)
|
||||||
->values()
|
->values();
|
||||||
->all();
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Records which payment type the shopper picked (Cart::meta
|
* Records which payment type the shopper picked (Cart::meta
|
||||||
* ['payment_method']) — read by e.g. Modules\Core\Payment\Pipelines\
|
* ['payment_method']) — read by Modules\Core\Payment\Pipelines\
|
||||||
* Cart\ApplyCashOnDeliveryFee to add that type's own cart-total
|
* Cart\ApplyPaymentMethodFee to add that method's own `data.fee` (if
|
||||||
* adjustments before recalculation.
|
* any) before recalculation.
|
||||||
*
|
*
|
||||||
* Also snapshots Cart::fingerprint() into meta, *after* saving the
|
* Also snapshots Cart::fingerprint() into meta, *after* saving the
|
||||||
* chosen type — the fingerprint has to reflect the final total
|
* chosen type — the fingerprint has to reflect the final total
|
||||||
* including any payment-type-specific adjustment (e.g. a COD
|
* including any payment-method-specific fee, which only exists once
|
||||||
* surcharge), which only exists once payment_method is set and the
|
* payment_method is set and the cart recalculates. Captured here,
|
||||||
* cart recalculates. Captured here, server-side, rather than asked of
|
* server-side, rather than asked of the storefront: this is the last
|
||||||
* the storefront: this is the last moment before initiatePayment() that
|
* moment before initiatePayment() that the shopper's reviewed total is
|
||||||
* the shopper's reviewed total is known, and initiatePayment() reads it
|
* known, and initiatePayment() reads it back internally instead of
|
||||||
* back internally instead of taking a fingerprint parameter — a
|
* taking a fingerprint parameter — a storefront should never need to
|
||||||
* storefront should never need to know Cart::fingerprint() exists.
|
* know Cart::fingerprint() exists.
|
||||||
*
|
*
|
||||||
* Does not itself call a payment driver — selecting a method and
|
* Does not itself call a payment driver — selecting a method and
|
||||||
* initiating payment against it are deliberately separate steps, same
|
* initiating payment against it are deliberately separate steps, same
|
||||||
* as selecting a shipping option happens before placing the order.
|
* as selecting a shipping option happens before placing the order.
|
||||||
*
|
*
|
||||||
* @throws UnknownPaymentTypeException if $type isn't currently offered
|
* @throws UnknownPaymentTypeException if $type isn't currently offered
|
||||||
* — see getPaymentMethods() for what that means (registered,
|
* — see getPaymentMethods() for what that means
|
||||||
* administratively enabled, and its driver reports itself usable)
|
|
||||||
*/
|
*/
|
||||||
public function selectPaymentMethod(string $type): Cart
|
public function selectPaymentMethod(string $type): Cart
|
||||||
{
|
{
|
||||||
if (! in_array($type, $this->getPaymentMethods(), true)) {
|
if (! $this->getPaymentMethods()->contains('type', $type)) {
|
||||||
throw new UnknownPaymentTypeException($type);
|
throw new UnknownPaymentTypeException($type);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -155,7 +204,15 @@ class CheckoutService
|
|||||||
$cart->meta = [...($cart->meta?->toArray() ?? []), 'payment_method' => $type];
|
$cart->meta = [...($cart->meta?->toArray() ?? []), 'payment_method' => $type];
|
||||||
$cart->save();
|
$cart->save();
|
||||||
|
|
||||||
$cart = $cart->calculate();
|
// Cart::calculate() no-ops if this cart instance was already
|
||||||
|
// calculated earlier in the request (Cart::isCalculated()) — which
|
||||||
|
// it will have been if the shopper switches payment method after
|
||||||
|
// the checkout page's first render already calculated it. Without
|
||||||
|
// recalculate() forcing a fresh run, the just-saved payment_method
|
||||||
|
// (and any fee tied to it, see ApplyPaymentMethodFee) would never
|
||||||
|
// be reflected — the summary would keep showing whichever method
|
||||||
|
// was calculated first.
|
||||||
|
$cart = $cart->recalculate();
|
||||||
$cart->meta = [...($cart->meta?->toArray() ?? []), 'checkout_fingerprint' => $cart->fingerprint()];
|
$cart->meta = [...($cart->meta?->toArray() ?? []), 'checkout_fingerprint' => $cart->fingerprint()];
|
||||||
$cart->save();
|
$cart->save();
|
||||||
|
|
||||||
@@ -170,11 +227,9 @@ class CheckoutService
|
|||||||
* Order exists (Cart::createOrder() — confirmed idempotent against a
|
* Order exists (Cart::createOrder() — confirmed idempotent against a
|
||||||
* cart's own pre-existing, not-yet-placed-at draft; see
|
* cart's own pre-existing, not-yet-placed-at draft; see
|
||||||
* vendor/lunarphp/core/src/Actions/Carts/CreateOrder.php), then
|
* vendor/lunarphp/core/src/Actions/Carts/CreateOrder.php), then
|
||||||
* resolves the payment type selected by selectPaymentMethod() and
|
* resolves the payment method selected by selectPaymentMethod() and
|
||||||
* calls pay() or authorize() on its driver, per that type's
|
* calls pay() or authorize() on its driver, per that method's own
|
||||||
* config('lunar.payments.types.{type}.capture_mode') — boboko-core's
|
* `capture_mode` column.
|
||||||
* own types (config/payment.php) are merged into that same Lunar
|
|
||||||
* config key by PaymentServiceProvider::boot().
|
|
||||||
*
|
*
|
||||||
* Returns the driver's own PaymentResult UNCHANGED — this method does
|
* Returns the driver's own PaymentResult UNCHANGED — this method does
|
||||||
* not wait for or resolve anything past what pay()/authorize() itself
|
* not wait for or resolve anything past what pay()/authorize() itself
|
||||||
@@ -183,14 +238,6 @@ class CheckoutService
|
|||||||
* outcome, not an error — the caller (a storefront controller) is
|
* outcome, not an error — the caller (a storefront controller) is
|
||||||
* responsible for whatever the gateway needs next.
|
* responsible for whatever the gateway needs next.
|
||||||
*
|
*
|
||||||
* KNOWN GAP, explicitly out of scope for now: PaymentResult alone does
|
|
||||||
* not carry gateway-specific continuation data (e.g. Stripe's
|
|
||||||
* PaymentIntent client_secret for a Pending result needing frontend
|
|
||||||
* confirmation) — that concept existed on the deleted PaymentInitiation
|
|
||||||
* DTO and was intentionally removed from Payment's abstraction layer.
|
|
||||||
* Nothing here re-introduces it; only OfflinePaymentDriver's
|
|
||||||
* always-Immediate-Succeeded path is fully wired end-to-end today.
|
|
||||||
*
|
|
||||||
* The draft order's own $order->total (not the Cart's) is what gets
|
* The draft order's own $order->total (not the Cart's) is what gets
|
||||||
* passed as $amount — Order::$total is Lunar's own Price-cast
|
* passed as $amount — Order::$total is Lunar's own Price-cast
|
||||||
* attribute, already resolving the correct Currency via the order's
|
* attribute, already resolving the correct Currency via the order's
|
||||||
@@ -204,36 +251,63 @@ class CheckoutService
|
|||||||
* Same fingerprint precondition the old placeOrder() had: mandatory,
|
* Same fingerprint precondition the old placeOrder() had: mandatory,
|
||||||
* not optional, checked before the draft is created.
|
* not optional, checked before the draft is created.
|
||||||
*
|
*
|
||||||
|
* $termsAccepted is likewise mandatory, not optional data a caller
|
||||||
|
* might omit — an Order is a consumer contract, and its acceptance
|
||||||
|
* must be refused (TermsNotAcceptedException, before createOrder() is
|
||||||
|
* ever called — the order is never created-then-flagged) rather than
|
||||||
|
* assumed. $policyVersion is recorded alongside it on the created
|
||||||
|
* Order's own meta (terms_accepted, terms_accepted_at,
|
||||||
|
* terms_accepted_policy_version) — the order-level equivalent of
|
||||||
|
* setRecoveryConsent()'s cart-level record, and the durable audit
|
||||||
|
* trail for a later "what did the shopper actually agree to"
|
||||||
|
* dispute. Written directly here (not via a separate event/listener)
|
||||||
|
* since the Order row this attaches to doesn't exist before
|
||||||
|
* createOrder() runs, and nothing else needs to react to this
|
||||||
|
* specific write independently of the order simply existing.
|
||||||
|
*
|
||||||
* @param array<string, mixed> $data passed through untouched to
|
* @param array<string, mixed> $data passed through untouched to
|
||||||
* the driver's pay()/authorize() — e.g. Stripe's payment_method
|
* the driver's pay()/authorize() — e.g. Stripe's payment_method
|
||||||
* token.
|
* token.
|
||||||
*
|
*
|
||||||
* @throws UnknownPaymentTypeException if the cart's selected
|
* @throws UnknownPaymentTypeException if the cart's selected
|
||||||
* payment_method (from selectPaymentMethod()) is no longer offered
|
* payment_method (from selectPaymentMethod()) is no longer offered
|
||||||
* — re-checked here, not just at selection time, since a type could
|
* — re-checked here, not just at selection time, since a method
|
||||||
* be disabled in between
|
* could be disabled (or its driver removed) in between
|
||||||
|
* @throws TermsNotAcceptedException if $termsAccepted is false
|
||||||
* @throws FingerprintMismatchException
|
* @throws FingerprintMismatchException
|
||||||
* @throws CartException
|
* @throws CartException
|
||||||
*/
|
*/
|
||||||
public function initiatePayment(string $fingerprint, array $data = []): PaymentResult
|
public function initiatePayment(string $fingerprint, bool $termsAccepted, string $policyVersion, array $data = []): PaymentResult
|
||||||
{
|
{
|
||||||
|
if (! $termsAccepted) {
|
||||||
|
throw new TermsNotAcceptedException;
|
||||||
|
}
|
||||||
|
|
||||||
$cart = $this->cart->currentOrCreate();
|
$cart = $this->cart->currentOrCreate();
|
||||||
$cart->checkFingerprint($fingerprint);
|
$cart->checkFingerprint($fingerprint);
|
||||||
|
|
||||||
$type = $cart->meta['payment_method'] ?? null;
|
$type = $cart->meta['payment_method'] ?? null;
|
||||||
|
$method = $type !== null ? $this->getPaymentMethods()->firstWhere('type', $type) : null;
|
||||||
|
|
||||||
if ($type === null || ! in_array($type, $this->getPaymentMethods(), true)) {
|
if ($method === null) {
|
||||||
throw new UnknownPaymentTypeException((string) $type);
|
throw new UnknownPaymentTypeException((string) $type);
|
||||||
}
|
}
|
||||||
|
|
||||||
$order = $cart->createOrder();
|
$order = $cart->createOrder();
|
||||||
|
|
||||||
$driver = $this->paymentDrivers->resolve($type);
|
$order->meta = [
|
||||||
$captureMode = config("lunar.payments.types.{$type}.capture_mode", 'pay');
|
...($order->meta?->toArray() ?? []),
|
||||||
|
'payment_method' => $type,
|
||||||
|
'terms_accepted' => true,
|
||||||
|
'terms_accepted_at' => now()->toIso8601String(),
|
||||||
|
'terms_accepted_policy_version' => $policyVersion,
|
||||||
|
];
|
||||||
|
$order->save();
|
||||||
|
|
||||||
|
$driver = $this->paymentDrivers->resolve($method->driver);
|
||||||
$context = ['cart_id' => $cart->id, 'order_id' => $order->id];
|
$context = ['cart_id' => $cart->id, 'order_id' => $order->id];
|
||||||
|
|
||||||
return $captureMode === 'authorize'
|
return $method->capture_mode === 'authorize'
|
||||||
? $driver->authorize($type, $order->total, $data, $context)
|
? $driver->authorize($type, $order->total, $data, $context)
|
||||||
: $driver->pay($type, $order->total, $data, $context);
|
: $driver->pay($type, $order->total, $data, $context);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,60 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Command;
|
||||||
|
|
||||||
|
use Illuminate\Console\Command;
|
||||||
|
use Lunar\Models\ProductVariant;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* One-off backfill for variants the Shopify import left with a blank SKU —
|
||||||
|
* not an importer bug, the source CSV rows genuinely had no `Variant SKU`
|
||||||
|
* value (see Modules\MigrateImport\Shopify\ShopifyExportImporter) — so
|
||||||
|
* this synthesizes one instead of re-running the import. Format is
|
||||||
|
* "SKU-P{product_id}-V{variant_id}": deterministic and guaranteed unique
|
||||||
|
* without a uniqueness check, since product_id/variant_id already are.
|
||||||
|
* Only variants with a null `sku` are touched.
|
||||||
|
*/
|
||||||
|
class BackfillMissingSkusCommand extends Command
|
||||||
|
{
|
||||||
|
protected $signature = 'boboko:catalog:backfill-skus {--dry-run : List what would change without writing}';
|
||||||
|
|
||||||
|
protected $description = 'Generate a SKU for every product variant that is missing one';
|
||||||
|
|
||||||
|
public function handle(): void
|
||||||
|
{
|
||||||
|
$dryRun = (bool) $this->option('dry-run');
|
||||||
|
|
||||||
|
$query = ProductVariant::query()->whereNull('sku');
|
||||||
|
$total = $query->count();
|
||||||
|
|
||||||
|
if ($total === 0) {
|
||||||
|
$this->info('No variants are missing a SKU.');
|
||||||
|
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->info(($dryRun ? '[dry-run] ' : '') . "Backfilling SKUs for {$total} variant(s)...");
|
||||||
|
|
||||||
|
$bar = $this->output->createProgressBar($total);
|
||||||
|
$bar->start();
|
||||||
|
|
||||||
|
$query->chunkById(500, function ($variants) use ($dryRun, $bar) {
|
||||||
|
foreach ($variants as $variant) {
|
||||||
|
$sku = "SKU-P{$variant->product_id}-V{$variant->id}";
|
||||||
|
|
||||||
|
if ($dryRun) {
|
||||||
|
$this->newLine();
|
||||||
|
$this->line("Variant {$variant->id}: sku => {$sku}");
|
||||||
|
} else {
|
||||||
|
$variant->update(['sku' => $sku]);
|
||||||
|
}
|
||||||
|
|
||||||
|
$bar->advance();
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
$bar->finish();
|
||||||
|
$this->newLine();
|
||||||
|
$this->info($dryRun ? 'Dry run complete — no changes were written.' : 'Done.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -66,6 +66,16 @@ class InstallLunarCommand extends Command
|
|||||||
]);
|
]);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (! Language::where('code', 'el')->exists()) {
|
||||||
|
$this->components->info('Adding Greek language');
|
||||||
|
|
||||||
|
Language::create([
|
||||||
|
'code' => 'el',
|
||||||
|
'name' => 'Greek',
|
||||||
|
'default' => false,
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
if (! Currency::whereDefault(true)->exists()) {
|
if (! Currency::whereDefault(true)->exists()) {
|
||||||
$this->components->info('Adding a default currency (USD)');
|
$this->components->info('Adding a default currency (USD)');
|
||||||
|
|
||||||
@@ -284,35 +294,41 @@ class InstallLunarCommand extends Command
|
|||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Per-type skip-if-exists, same idempotent convention as
|
* A single, deliberately opinionated starter row on fresh install —
|
||||||
* seedStorefrontLabels() — a type already present (including one an
|
* `PaymentMethod` is now fully admin-creatable/deletable (see
|
||||||
* admin has since edited via the Filament Payment Methods resource) is
|
* docs/payments.md), so this is no longer "seed every config-defined
|
||||||
* left untouched. Safe to re-run after a new payment type is added to
|
* type," it's "give a fresh store one reasonable payment method to
|
||||||
* config('lunar.payments.types') (e.g. installing a Stripe/Nexi
|
* start from instead of zero." Every value here is a plain literal in
|
||||||
* package), which is the whole reason this isn't a one-time-only seed.
|
* THIS command, not sourced from config or PaymentDriverRegistry — a
|
||||||
|
* driver has no business carrying opinions about what its captured
|
||||||
|
* order status should be called; that's a merchant decision.
|
||||||
*
|
*
|
||||||
* Seeded disabled — a newly-seeded row (whether from this store's
|
* Skip-if-exists on `type`, same idempotent convention as
|
||||||
* initial install, or a payment provider package installed later)
|
* seedStorefrontLabels() — an admin who has since edited or deleted
|
||||||
* shouldn't go live for shoppers before staff have actually reviewed
|
* this row (via the Filament Payment Methods resource) is left alone;
|
||||||
* it (real credentials configured, a fee set, etc.) and turned it on
|
* re-running lunar:install never recreates a deleted starter row.
|
||||||
* via the Payment Methods resource. See CheckoutService::
|
*
|
||||||
* getPaymentMethods(), which only offers a type once both 'enabled'
|
* Seeded disabled — shouldn't go live for shoppers before staff have
|
||||||
* here and its driver's own isConfigured() check pass.
|
* actually reviewed it and turned it on via the Payment Methods
|
||||||
|
* resource. See CheckoutService::getPaymentMethods().
|
||||||
*/
|
*/
|
||||||
private function seedPaymentMethods(): void
|
private function seedPaymentMethods(): void
|
||||||
{
|
{
|
||||||
$existingTypes = PaymentMethod::pluck('type');
|
if (PaymentMethod::where('type', 'cash-on-delivery')->exists()) {
|
||||||
|
return;
|
||||||
foreach (array_keys(config('lunar.payments.types', [])) as $type) {
|
|
||||||
if ($existingTypes->contains($type)) {
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
|
|
||||||
PaymentMethod::create([
|
|
||||||
'type' => $type,
|
|
||||||
'enabled' => false,
|
|
||||||
'data' => [],
|
|
||||||
]);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
PaymentMethod::create([
|
||||||
|
'type' => 'cash-on-delivery',
|
||||||
|
'name' => [
|
||||||
|
'en' => 'Cash on Delivery',
|
||||||
|
'el' => 'Αντικαταβολή',
|
||||||
|
],
|
||||||
|
'driver' => 'cash-on-delivery',
|
||||||
|
'capture_mode' => 'pay',
|
||||||
|
'position' => 0,
|
||||||
|
'enabled' => false,
|
||||||
|
'data' => [],
|
||||||
|
]);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,47 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Command;
|
||||||
|
|
||||||
|
use Illuminate\Console\Command;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureRequestStatus;
|
||||||
|
use Modules\Core\Privacy\Jobs\EraseDataSubjectJob;
|
||||||
|
use Modules\Core\Privacy\Models\DataErasureRequest;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Finds every erasure request whose grace period (config('core.privacy.
|
||||||
|
* grace_period_days')) has passed and dispatches one EraseDataSubjectJob per
|
||||||
|
* request — see docs/privacy.md. This command itself just finds due requests and
|
||||||
|
* dispatches; the actual erasure work happens in the queue, one job per request,
|
||||||
|
* so one failing request doesn't block the others. Meant to run daily via the
|
||||||
|
* scheduler; each consuming app wires that in its own Console\Kernel (or
|
||||||
|
* bootstrap/app.php schedule closure on Laravel 11+), the same way it owns any
|
||||||
|
* other scheduled task — this package doesn't register schedules itself.
|
||||||
|
*/
|
||||||
|
class ProcessErasureRequestsCommand extends Command
|
||||||
|
{
|
||||||
|
protected $signature = 'boboko:privacy:process-erasure-requests';
|
||||||
|
|
||||||
|
protected $description = 'Dispatch an erasure job for every pending data-erasure request whose grace period has passed';
|
||||||
|
|
||||||
|
public function handle(): void
|
||||||
|
{
|
||||||
|
$due = DataErasureRequest::where('status', ErasureRequestStatus::Pending)
|
||||||
|
->where('scheduled_for', '<=', now())
|
||||||
|
->get();
|
||||||
|
|
||||||
|
if ($due->isEmpty()) {
|
||||||
|
$this->info('No due erasure requests.');
|
||||||
|
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach ($due as $request) {
|
||||||
|
EraseDataSubjectJob::dispatch($request);
|
||||||
|
|
||||||
|
$scope = $request->isForCustomer() ? 'customer' : 'user';
|
||||||
|
$this->info("Dispatched erasure job for {$scope} #{$request->subject_id} (request #{$request->id})");
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->info('Dispatched '.$due->count().' erasure job(s).');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,52 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Command;
|
||||||
|
|
||||||
|
use Illuminate\Console\Command;
|
||||||
|
use Modules\Core\Payment\Models\PaymentMethod;
|
||||||
|
use Modules\Core\Payment\Services\PaymentDriverRegistry;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Reconciles every Modules\Core\Payment\Models\PaymentMethod row's `driver`
|
||||||
|
* column against PaymentDriverRegistry — the registry only knows "which
|
||||||
|
* driver classes exist THIS deploy," and only at the moment something
|
||||||
|
* calls resolve(); nothing else notices a driver disappearing (a package
|
||||||
|
* removed, a custom Registry::register() call deleted) on its own. Meant
|
||||||
|
* to run unconditionally on every container start/deploy (alongside
|
||||||
|
* `migrate`), not on a schedule — "did the set of registered drivers
|
||||||
|
* change" is a deploy-time event, cheap enough to check every single time
|
||||||
|
* regardless of whether anything actually changed. See docs/payments.md.
|
||||||
|
*
|
||||||
|
* Sets/clears `driver_missing_at` — deliberately NOT the `enabled` column,
|
||||||
|
* so an admin's own manual toggle is never confused with "the driver
|
||||||
|
* vanished," and a driver that comes back in a later deploy auto-clears
|
||||||
|
* this with no admin action needed.
|
||||||
|
*/
|
||||||
|
class SyncPaymentDriversCommand extends Command
|
||||||
|
{
|
||||||
|
protected $signature = 'boboko:payment:sync-drivers';
|
||||||
|
|
||||||
|
protected $description = 'Flag PaymentMethod rows whose driver no longer resolves via the registry, and clear the flag for ones that do again';
|
||||||
|
|
||||||
|
public function handle(PaymentDriverRegistry $registry): int
|
||||||
|
{
|
||||||
|
$missing = 0;
|
||||||
|
$restored = 0;
|
||||||
|
|
||||||
|
PaymentMethod::query()->each(function (PaymentMethod $method) use ($registry, &$missing, &$restored) {
|
||||||
|
$resolves = $method->driver !== null && $registry->resolve($method->driver) !== null;
|
||||||
|
|
||||||
|
if (! $resolves && $method->driver_missing_at === null) {
|
||||||
|
$method->update(['driver_missing_at' => now()]);
|
||||||
|
$missing++;
|
||||||
|
} elseif ($resolves && $method->driver_missing_at !== null) {
|
||||||
|
$method->update(['driver_missing_at' => null]);
|
||||||
|
$restored++;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
$this->components->info("Payment driver sync complete: {$missing} newly flagged, {$restored} restored.");
|
||||||
|
|
||||||
|
return self::SUCCESS;
|
||||||
|
}
|
||||||
|
}
|
||||||
+82
-7
@@ -3,10 +3,15 @@
|
|||||||
namespace Modules\Core;
|
namespace Modules\Core;
|
||||||
|
|
||||||
use Lunar\Admin\Filament\Resources\OrderResource\Pages\ManageOrder;
|
use Lunar\Admin\Filament\Resources\OrderResource\Pages\ManageOrder;
|
||||||
|
use Lunar\Admin\Filament\Resources\OrderResource\Pages\Components\OrderItemsTable;
|
||||||
use Filament\Contracts\Plugin;
|
use Filament\Contracts\Plugin;
|
||||||
use Filament\Panel;
|
use Filament\Panel;
|
||||||
use Illuminate\Database\Eloquent\Relations\HasMany;
|
use Illuminate\Database\Eloquent\Relations\HasMany;
|
||||||
|
use Illuminate\Database\Eloquent\Relations\MorphMany;
|
||||||
use Illuminate\Support\Facades\Mail;
|
use Illuminate\Support\Facades\Mail;
|
||||||
|
use Lunar\Admin\Filament\Resources\CustomerResource;
|
||||||
|
use Lunar\Admin\Filament\Resources\CustomerResource\Pages\EditCustomer;
|
||||||
|
use Lunar\Admin\Filament\Resources\CustomerResource\Pages\ViewCustomer;
|
||||||
use Lunar\Admin\Filament\Resources\ProductOptionResource;
|
use Lunar\Admin\Filament\Resources\ProductOptionResource;
|
||||||
use Lunar\Admin\Filament\Resources\ProductOptionResource\RelationManagers\ValuesRelationManager;
|
use Lunar\Admin\Filament\Resources\ProductOptionResource\RelationManagers\ValuesRelationManager;
|
||||||
use Lunar\Admin\Filament\Resources\OrderResource;
|
use Lunar\Admin\Filament\Resources\OrderResource;
|
||||||
@@ -14,6 +19,7 @@ use Lunar\Admin\Filament\Resources\ProductResource;
|
|||||||
use Lunar\Admin\Filament\Resources\StaffResource;
|
use Lunar\Admin\Filament\Resources\StaffResource;
|
||||||
use Lunar\Admin\Models\Staff as LunarStaff;
|
use Lunar\Admin\Models\Staff as LunarStaff;
|
||||||
use Lunar\Admin\Support\Facades\LunarPanel;
|
use Lunar\Admin\Support\Facades\LunarPanel;
|
||||||
|
use Lunar\Models\Customer;
|
||||||
use Lunar\Models\Product;
|
use Lunar\Models\Product;
|
||||||
use Lunar\Shipping\Filament\Resources\ShippingMethodResource;
|
use Lunar\Shipping\Filament\Resources\ShippingMethodResource;
|
||||||
use Lunar\Shipping\Filament\Resources\ShippingMethodResource\Pages\ListShippingMethod;
|
use Lunar\Shipping\Filament\Resources\ShippingMethodResource\Pages\ListShippingMethod;
|
||||||
@@ -25,13 +31,25 @@ use Modules\Core\Cart\Filament\Resources\CartResource;
|
|||||||
use Modules\Core\Catalog\Filament\Extensions\ProductOptionResourceExtension;
|
use Modules\Core\Catalog\Filament\Extensions\ProductOptionResourceExtension;
|
||||||
use Modules\Core\Catalog\Filament\Extensions\ValuesRelationManagerExtension;
|
use Modules\Core\Catalog\Filament\Extensions\ValuesRelationManagerExtension;
|
||||||
use Modules\Core\Localization\Filament\Resources\LanguageLineResource;
|
use Modules\Core\Localization\Filament\Resources\LanguageLineResource;
|
||||||
|
use Modules\Core\Order\Filament\Extensions\OrderItemsTableExtension;
|
||||||
|
use Modules\Core\Order\Filament\Extensions\OrderPaymentMethodSummaryExtension;
|
||||||
|
use Modules\Core\Order\Filament\Extensions\OrderActionsExtension;
|
||||||
|
use Modules\Core\Order\Filament\Extensions\OrderTransactionsExtension;
|
||||||
use Modules\Core\Payment\Filament\Resources\PaymentMethodResource;
|
use Modules\Core\Payment\Filament\Resources\PaymentMethodResource;
|
||||||
|
use Modules\Core\Privacy\Filament\Extensions\CustomerErasureActionsExtension;
|
||||||
|
use Modules\Core\Privacy\Filament\Extensions\CustomerErasureRelationsExtension;
|
||||||
|
use Modules\Core\Privacy\Filament\Resources\DataErasureRequestResource;
|
||||||
|
use Modules\Core\Privacy\Filament\Resources\DataExportRequestResource;
|
||||||
|
use Modules\Core\Privacy\Models\DataErasureRequest;
|
||||||
|
use Modules\Core\Privacy\Models\DataExportRequest;
|
||||||
use Modules\Core\Review\Filament\Extensions\ProductResourceExtension;
|
use Modules\Core\Review\Filament\Extensions\ProductResourceExtension;
|
||||||
use Modules\Core\Review\Models\ProductReview;
|
use Modules\Core\Review\Models\ProductReview;
|
||||||
|
use Modules\Core\Shipping\Extensions\OrderShipmentsExtension;
|
||||||
use Modules\Core\Shipping\Extensions\OrderViewExtension;
|
use Modules\Core\Shipping\Extensions\OrderViewExtension;
|
||||||
use Modules\Core\Shipping\Extensions\ShippingMethodListExtension;
|
use Modules\Core\Shipping\Extensions\ShippingMethodListExtension;
|
||||||
use Modules\Core\Shipping\Extensions\ShippingMethodResourceExtension;
|
use Modules\Core\Shipping\Extensions\ShippingMethodResourceExtension;
|
||||||
use Modules\Core\Shipping\Filament\Pages\ManagePickupManifests;
|
use Modules\Core\Shipping\Filament\Resources\ManifestResource;
|
||||||
|
use Modules\Core\Shipping\Filament\Resources\ShipmentResource;
|
||||||
|
|
||||||
class CorePlugin implements Plugin
|
class CorePlugin implements Plugin
|
||||||
{
|
{
|
||||||
@@ -49,11 +67,14 @@ class CorePlugin implements Plugin
|
|||||||
->login(Login::class)
|
->login(Login::class)
|
||||||
->resources([
|
->resources([
|
||||||
LanguageLineResource::class,
|
LanguageLineResource::class,
|
||||||
|
DataErasureRequestResource::class,
|
||||||
|
DataExportRequestResource::class,
|
||||||
CartResource::class,
|
CartResource::class,
|
||||||
PaymentMethodResource::class,
|
PaymentMethodResource::class,
|
||||||
|
ShipmentResource::class,
|
||||||
|
ManifestResource::class,
|
||||||
])
|
])
|
||||||
->plugin(ShippingPlugin::make())
|
->plugin(ShippingPlugin::make());
|
||||||
->pages([ManagePickupManifests::class]);
|
|
||||||
|
|
||||||
LunarPanel::extensions([
|
LunarPanel::extensions([
|
||||||
StaffResource::class => StaffResourceExtension::class,
|
StaffResource::class => StaffResourceExtension::class,
|
||||||
@@ -62,12 +83,66 @@ class CorePlugin implements Plugin
|
|||||||
ValuesRelationManager::class => ValuesRelationManagerExtension::class,
|
ValuesRelationManager::class => ValuesRelationManagerExtension::class,
|
||||||
ShippingMethodResource::class => ShippingMethodResourceExtension::class,
|
ShippingMethodResource::class => ShippingMethodResourceExtension::class,
|
||||||
ListShippingMethod::class => ShippingMethodListExtension::class,
|
ListShippingMethod::class => ShippingMethodListExtension::class,
|
||||||
ManageOrder::class => OrderViewExtension::class,
|
ManageOrder::class => [OrderViewExtension::class, OrderActionsExtension::class, OrderTransactionsExtension::class, OrderPaymentMethodSummaryExtension::class, OrderShipmentsExtension::class],
|
||||||
|
OrderItemsTable::class => OrderItemsTableExtension::class,
|
||||||
|
// headerActions() is resolved per PAGE class, not per resource class —
|
||||||
|
// unlike extendForm()/extendTable(), which really are resource-keyed
|
||||||
|
// (called statically from the Resource class itself). Registering this
|
||||||
|
// under CustomerResource::class would silently never fire; it has to be
|
||||||
|
// keyed by each concrete page it should appear on. Layered with
|
||||||
|
// whatever extension the consuming app registers for the same page —
|
||||||
|
// LunarPanel::extensions() merges per key, and this one only touches
|
||||||
|
// headerActions(), so it never conflicts with an app's own extension
|
||||||
|
// (see docs/modules.md "Layering Module and App Configuration").
|
||||||
|
EditCustomer::class => CustomerErasureActionsExtension::class,
|
||||||
|
ViewCustomer::class => CustomerErasureActionsExtension::class,
|
||||||
|
// getRelations(), unlike headerActions(), genuinely is resolved
|
||||||
|
// statically from the Resource class itself — CustomerResource::class
|
||||||
|
// is the correct key here.
|
||||||
|
CustomerResource::class => CustomerErasureRelationsExtension::class,
|
||||||
]);
|
]);
|
||||||
|
|
||||||
Product::macro('reviews', function (): HasMany {
|
// resolveRelationUsing(), not macro() — Illuminate\Database\Eloquent\
|
||||||
/** @var Product $this */
|
// Model does not use the Macroable trait in this Laravel version, so
|
||||||
return $this->hasMany(ProductReview::class);
|
// Product::macro(...)/Customer::macro(...)/$userModel::macro(...)
|
||||||
|
// silently fall through to Model::__callStatic(), which instantiates
|
||||||
|
// the model and tries to call the method as a real one, hitting
|
||||||
|
// newQuery()->getConnection() — this crashes every console command
|
||||||
|
// and every request, since CorePlugin::register() runs during
|
||||||
|
// provider registration, before the DB connection is configured
|
||||||
|
// ("Call to a member function connection() on null"). This bit us
|
||||||
|
// once already; resolveRelationUsing() is Eloquent's real, intended,
|
||||||
|
// connection-free extension point for exactly this (Order::
|
||||||
|
// resolveRelationUsing('shipments', ...) in ShippingServiceProvider
|
||||||
|
// already uses it correctly).
|
||||||
|
Product::resolveRelationUsing('reviews', function (Product $product): HasMany {
|
||||||
|
return $product->hasMany(ProductReview::class);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Customer::erasureRequests()/exportRequests() and the User-model
|
||||||
|
// equivalents below let a relation manager scope
|
||||||
|
// DataErasureRequest/DataExportRequest to one specific subject — both
|
||||||
|
// tables use a plain subject_type/subject_id pair rather than Laravel's
|
||||||
|
// usual morphs() convention, since one column pair identifies either a
|
||||||
|
// Customer or a User (see docs/privacy.md "User-scope vs Customer-scope"),
|
||||||
|
// so this is a MorphMany built by hand rather than a bare Eloquent
|
||||||
|
// convention lookup.
|
||||||
|
Customer::resolveRelationUsing('erasureRequests', function (Customer $customer): MorphMany {
|
||||||
|
return $customer->morphMany(DataErasureRequest::class, 'subject', 'subject_type', 'subject_id');
|
||||||
|
});
|
||||||
|
|
||||||
|
Customer::resolveRelationUsing('exportRequests', function (Customer $customer): MorphMany {
|
||||||
|
return $customer->morphMany(DataExportRequest::class, 'subject', 'subject_type', 'subject_id');
|
||||||
|
});
|
||||||
|
|
||||||
|
$userModel = config('auth.providers.users.model');
|
||||||
|
|
||||||
|
$userModel::resolveRelationUsing('erasureRequests', function ($user): MorphMany {
|
||||||
|
return $user->morphMany(DataErasureRequest::class, 'subject', 'subject_type', 'subject_id');
|
||||||
|
});
|
||||||
|
|
||||||
|
$userModel::resolveRelationUsing('exportRequests', function ($user): MorphMany {
|
||||||
|
return $user->morphMany(DataExportRequest::class, 'subject', 'subject_type', 'subject_id');
|
||||||
});
|
});
|
||||||
|
|
||||||
LunarStaff::addActivitylogExcept([
|
LunarStaff::addActivitylogExcept([
|
||||||
|
|||||||
@@ -0,0 +1,22 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Modules\Core\Customer\Services\CustomerAccountService::
|
||||||
|
* createAddress(). $causer is carried explicitly (unlike e.g.
|
||||||
|
* Modules\Core\Payment\Events\PaymentMethodCreated, which is always
|
||||||
|
* staff-caused implicitly) because this write happens on the `web`
|
||||||
|
* guard, not `staff` — a listener logging this needs to know who to
|
||||||
|
* attribute it to without guessing a guard.
|
||||||
|
*/
|
||||||
|
class CustomerAddressCreated
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly Address $address,
|
||||||
|
public readonly Authenticatable $causer,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
|
||||||
|
class CustomerAddressDeleted
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $address Snapshot of the deleted
|
||||||
|
* row — already gone from the database by dispatch time.
|
||||||
|
*/
|
||||||
|
public function __construct(
|
||||||
|
public readonly array $address,
|
||||||
|
public readonly Authenticatable $causer,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
|
||||||
|
class CustomerAddressUpdated
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $old Snapshot of the changed
|
||||||
|
* attributes before the update.
|
||||||
|
*/
|
||||||
|
public function __construct(
|
||||||
|
public readonly Address $address,
|
||||||
|
public readonly array $old,
|
||||||
|
public readonly Authenticatable $causer,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Modules\Core\Customer\Models\Customer;
|
||||||
|
|
||||||
|
class CustomerProfileUpdated
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $old Snapshot of the changed
|
||||||
|
* attributes before the update.
|
||||||
|
*/
|
||||||
|
public function __construct(
|
||||||
|
public readonly Customer $customer,
|
||||||
|
public readonly array $old,
|
||||||
|
public readonly Authenticatable $causer,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Exceptions;
|
||||||
|
|
||||||
|
use RuntimeException;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Thrown by Modules\Core\Customer\Services\CustomerAccountService when an
|
||||||
|
* address id doesn't belong to the customer making the request — never
|
||||||
|
* a plain 404/ModelNotFoundException, so a storefront can't probe for
|
||||||
|
* another customer's address ids by trying sequential ones and reading
|
||||||
|
* the response shape.
|
||||||
|
*/
|
||||||
|
class AddressNotFoundException extends RuntimeException
|
||||||
|
{
|
||||||
|
public function __construct()
|
||||||
|
{
|
||||||
|
parent::__construct('Address not found.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Exceptions;
|
||||||
|
|
||||||
|
use RuntimeException;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Thrown by Modules\Core\Customer\Services\CustomerAccountService when an
|
||||||
|
* order id doesn't belong to the customer making the request (or isn't
|
||||||
|
* placed yet) — never a plain 404/ModelNotFoundException, so a
|
||||||
|
* storefront can't probe for another customer's order ids.
|
||||||
|
*/
|
||||||
|
class OrderNotFoundException extends RuntimeException
|
||||||
|
{
|
||||||
|
public function __construct()
|
||||||
|
{
|
||||||
|
parent::__construct('Order not found.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,61 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Listeners;
|
||||||
|
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressCreated;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressDeleted;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressUpdated;
|
||||||
|
use Modules\Core\Customer\Events\CustomerProfileUpdated;
|
||||||
|
use Modules\Core\Logging\ActivityLogService;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Same pattern as Payment\Listeners\LogPaymentMethodActivity — routes
|
||||||
|
* Modules\Core\Customer\Services\CustomerAccountService's own events
|
||||||
|
* through the shared Logging\ActivityLogService, giving every
|
||||||
|
* shopper-initiated address/profile change an audit trail (previously
|
||||||
|
* none existed at all for account self-service writes). $causer is
|
||||||
|
* passed through explicitly on every call, since these events are
|
||||||
|
* `web`-guard-caused, not `staff`-guard — see ActivityLogService's own
|
||||||
|
* docblock for why that parameter exists.
|
||||||
|
*/
|
||||||
|
class LogCustomerAccountActivity
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly ActivityLogService $activityLog,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public function handleAddressCreated(CustomerAddressCreated $event): void
|
||||||
|
{
|
||||||
|
$this->activityLog->created($event->address, $event->address->getAttributes(), $event->causer);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function handleAddressUpdated(CustomerAddressUpdated $event): void
|
||||||
|
{
|
||||||
|
$this->activityLog->updated(
|
||||||
|
$event->address,
|
||||||
|
$event->old,
|
||||||
|
$event->address->only(array_keys($event->old)),
|
||||||
|
$event->causer,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function handleAddressDeleted(CustomerAddressDeleted $event): void
|
||||||
|
{
|
||||||
|
$subject = (new Address)->forceFill($event->address);
|
||||||
|
$subject->exists = true;
|
||||||
|
$subject->id = $event->address['id'];
|
||||||
|
|
||||||
|
$this->activityLog->deleted($subject, $event->address, $event->causer);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function handleProfileUpdated(CustomerProfileUpdated $event): void
|
||||||
|
{
|
||||||
|
$this->activityLog->updated(
|
||||||
|
$event->customer,
|
||||||
|
$event->old,
|
||||||
|
$event->customer->only(array_keys($event->old)),
|
||||||
|
$event->causer,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,63 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Privacy;
|
||||||
|
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
use Modules\Core\Privacy\Contracts\PersonalDataProvider;
|
||||||
|
use Modules\Core\Privacy\DTOs\CustomerSubject;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureOutcome;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderErasureResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderExportResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\UserSubject;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A customer's saved addresses (lunar_addresses) — belong to the Customer
|
||||||
|
* (business account) via customer_id, not to an individual User, so this is
|
||||||
|
* Customer-scope only. No legal retention requirement of their own (unlike
|
||||||
|
* OrderAddress, handled by OrderDataProvider), so they're freely deleted outright
|
||||||
|
* rather than pseudonymized in place.
|
||||||
|
*/
|
||||||
|
class AddressDataProvider implements PersonalDataProvider
|
||||||
|
{
|
||||||
|
public function name(): string
|
||||||
|
{
|
||||||
|
return 'addresses';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$addresses = Address::where('customer_id', $subject->customerId)->get();
|
||||||
|
|
||||||
|
return new ProviderExportResult('addresses', $addresses->map(fn (Address $address) => [
|
||||||
|
'id' => $address->id,
|
||||||
|
'first_name' => $address->first_name,
|
||||||
|
'last_name' => $address->last_name,
|
||||||
|
'company_name' => $address->company_name,
|
||||||
|
'line_one' => $address->line_one,
|
||||||
|
'line_two' => $address->line_two,
|
||||||
|
'line_three' => $address->line_three,
|
||||||
|
'city' => $address->city,
|
||||||
|
'state' => $address->state,
|
||||||
|
'postcode' => $address->postcode,
|
||||||
|
'contact_email' => $address->contact_email,
|
||||||
|
'contact_phone' => $address->contact_phone,
|
||||||
|
])->all());
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
return new ProviderExportResult('addresses', []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
Address::where('customer_id', $subject->customerId)->delete();
|
||||||
|
|
||||||
|
return new ProviderErasureResult('addresses', ErasureOutcome::Erased);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
return new ProviderErasureResult('addresses', ErasureOutcome::Skipped, 'Addresses belong to Customer accounts, not individual users.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,122 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Privacy;
|
||||||
|
|
||||||
|
use Lunar\Models\Customer;
|
||||||
|
use Modules\Core\Privacy\Contracts\PersonalDataProvider;
|
||||||
|
use Modules\Core\Privacy\DTOs\CustomerSubject;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureOutcome;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderErasureResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderExportResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\UserSubject;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The Customer record itself (lunar_customers) and, on the User side, the User's
|
||||||
|
* own name/email. This is the one provider that implements both scopes
|
||||||
|
* meaningfully, and they are deliberately kept from touching each other's data:
|
||||||
|
*
|
||||||
|
* - eraseForCustomer() clears the account's own fields (name, company, tax id)
|
||||||
|
* only — it never touches any linked User's login or identity, even though
|
||||||
|
* $customer->users exists. Erasing a business account must not destroy the
|
||||||
|
* login access of every person who works there.
|
||||||
|
* - eraseForUser() clears that one person's name/email only — it never touches
|
||||||
|
* the Customer record's own fields, and it also detaches the User from every
|
||||||
|
* Customer they're linked to (the customer_user pivot — see docs/modules.md
|
||||||
|
* "Customer/User Pairing"), since erasing a person's identity should end
|
||||||
|
* their membership everywhere, without erasing the business accounts
|
||||||
|
* themselves or any other User still linked to them.
|
||||||
|
*
|
||||||
|
* No legal retention requirement applies to this table on its own, so both
|
||||||
|
* directions are freely erased — Order/OrderAddress, which DO have a retention
|
||||||
|
* requirement, are handled separately by OrderDataProvider.
|
||||||
|
*/
|
||||||
|
class CustomerDataProvider implements PersonalDataProvider
|
||||||
|
{
|
||||||
|
public function name(): string
|
||||||
|
{
|
||||||
|
return 'customer';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$customer = Customer::find($subject->customerId);
|
||||||
|
|
||||||
|
return new ProviderExportResult('customer', $customer ? [
|
||||||
|
'id' => $customer->id,
|
||||||
|
'title' => $customer->title,
|
||||||
|
'first_name' => $customer->first_name,
|
||||||
|
'last_name' => $customer->last_name,
|
||||||
|
'company_name' => $customer->company_name,
|
||||||
|
'tax_identifier' => $customer->tax_identifier,
|
||||||
|
'meta' => $customer->meta,
|
||||||
|
'users' => $customer->users->map(fn ($user) => [
|
||||||
|
'id' => $user->id,
|
||||||
|
'name' => $user->name,
|
||||||
|
'email' => $user->email,
|
||||||
|
])->all(),
|
||||||
|
] : []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$model = config('auth.providers.users.model');
|
||||||
|
$user = $model::find($subject->userId);
|
||||||
|
|
||||||
|
return new ProviderExportResult('customer', $user ? [
|
||||||
|
'id' => $user->id,
|
||||||
|
'name' => $user->name,
|
||||||
|
'email' => $user->email,
|
||||||
|
'customers' => $user->customers->map(fn (Customer $customer) => [
|
||||||
|
'id' => $customer->id,
|
||||||
|
'company_name' => $customer->company_name,
|
||||||
|
])->all(),
|
||||||
|
] : []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
$customer = Customer::find($subject->customerId);
|
||||||
|
|
||||||
|
if (! $customer) {
|
||||||
|
return new ProviderErasureResult('customer', ErasureOutcome::Skipped, 'Customer record not found.');
|
||||||
|
}
|
||||||
|
|
||||||
|
$customer->update([
|
||||||
|
'title' => null,
|
||||||
|
'first_name' => 'Erased',
|
||||||
|
'last_name' => "Customer #{$customer->id}",
|
||||||
|
'company_name' => null,
|
||||||
|
'tax_identifier' => null,
|
||||||
|
'account_ref' => null,
|
||||||
|
'meta' => null,
|
||||||
|
]);
|
||||||
|
|
||||||
|
return new ProviderErasureResult('customer', ErasureOutcome::Erased);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
$model = config('auth.providers.users.model');
|
||||||
|
$user = $model::find($subject->userId);
|
||||||
|
|
||||||
|
if (! $user) {
|
||||||
|
return new ProviderErasureResult('customer', ErasureOutcome::Skipped, 'User record not found.');
|
||||||
|
}
|
||||||
|
|
||||||
|
$user->customers()->detach();
|
||||||
|
|
||||||
|
$user->update([
|
||||||
|
'name' => null,
|
||||||
|
'email' => "erased-user-{$user->id}@example.invalid",
|
||||||
|
// A live OTP code left on an otherwise-erased row is a residual
|
||||||
|
// secret tied to an identity that no longer exists here — clear
|
||||||
|
// it alongside name/email rather than leaving it to expire on
|
||||||
|
// its own 10-minute window.
|
||||||
|
'otp_code' => null,
|
||||||
|
'otp_expires_at' => null,
|
||||||
|
'otp_attempts' => 0,
|
||||||
|
]);
|
||||||
|
|
||||||
|
return new ProviderErasureResult('customer', ErasureOutcome::Erased);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,255 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Services;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Illuminate\Pagination\LengthAwarePaginator;
|
||||||
|
use Illuminate\Support\Arr;
|
||||||
|
use Illuminate\Support\Facades\Event;
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use LogicException;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressCreated;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressDeleted;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressUpdated;
|
||||||
|
use Modules\Core\Customer\Events\CustomerProfileUpdated;
|
||||||
|
use Modules\Core\Customer\Exceptions\AddressNotFoundException;
|
||||||
|
use Modules\Core\Customer\Exceptions\OrderNotFoundException;
|
||||||
|
use Modules\Core\Customer\Models\Customer;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The storefront-facing "My Account" API — mirrors Modules\Core\Cart\
|
||||||
|
* Services\CartService's shape, one boboko-owned service a storefront
|
||||||
|
* calls, so Lunar's own Customer/Order/Address models stay an
|
||||||
|
* implementation detail. Every method is scoped to the given
|
||||||
|
* Authenticatable's own Customer::latestCustomer() (see docs/modules.md
|
||||||
|
* "Customer/User Pairing") — there is no method here that accepts a bare
|
||||||
|
* order/address id without also requiring the owning user, precisely so
|
||||||
|
* a controller built on top of this can't accidentally leak one
|
||||||
|
* customer's data to another by trusting a client-supplied id alone.
|
||||||
|
*
|
||||||
|
* $user->latestCustomer() can be null for a User that has no paired
|
||||||
|
* Customer yet (shouldn't happen via the normal OTP-login cascade — see
|
||||||
|
* Modules\Core\Auth\Events\UserCreated — but is defended against anyway,
|
||||||
|
* since nothing stops a User row existing without one, e.g. seeded data)
|
||||||
|
* — every method returns an empty/null result rather than throwing in
|
||||||
|
* that case, since "no customer paired yet" isn't a not-found error, it's
|
||||||
|
* a legitimately empty account.
|
||||||
|
*
|
||||||
|
* Address/profile writes go through an explicit column allowlist
|
||||||
|
* (WRITABLE_ADDRESS_FIELDS/WRITABLE_PROFILE_FIELDS) rather than trusting
|
||||||
|
* Lunar\Models\Address/Customer's own $guarded = [] — that flag makes
|
||||||
|
* every column mass-assignable at the model layer, including
|
||||||
|
* customer_id on addresses, so a caller passing through an unfiltered
|
||||||
|
* request array (a real risk for a storefront controller built directly
|
||||||
|
* against this service) could otherwise reassign an address to a
|
||||||
|
* different customer entirely, or overwrite created_at/id. Arr::only()
|
||||||
|
* silently drops anything not on the allowlist rather than erroring —
|
||||||
|
* this is a safety boundary, not form validation (a storefront still
|
||||||
|
* validates its own request shape before calling this).
|
||||||
|
*
|
||||||
|
* Authorization here IS the ownership scoping itself, not a separate
|
||||||
|
* layer bolted on top — there is deliberately no Laravel Policy/Gate
|
||||||
|
* class for Order/Address, since a policy is meaningless without a
|
||||||
|
* controller calling authorize() against it, and this branch is scoped
|
||||||
|
* to backend services only (no routes/controllers — see the branch's own
|
||||||
|
* commit history). Every public method below takes Authenticatable $user
|
||||||
|
* as a required first argument and resolves everything else (Order,
|
||||||
|
* Address, Customer) strictly through that user's own
|
||||||
|
* latestCustomer() — there is no method that looks anything up by a bare
|
||||||
|
* id alone. A future storefront controller cannot "forget" the
|
||||||
|
* authorization check the way it could with a separate policy class,
|
||||||
|
* because the check IS how every lookup happens; skipping it isn't an
|
||||||
|
* option the method signatures allow.
|
||||||
|
*/
|
||||||
|
class CustomerAccountService
|
||||||
|
{
|
||||||
|
private const WRITABLE_ADDRESS_FIELDS = [
|
||||||
|
'title', 'first_name', 'last_name', 'company_name',
|
||||||
|
'line_one', 'line_two', 'line_three', 'city', 'state', 'postcode',
|
||||||
|
'delivery_instructions', 'contact_email', 'contact_phone',
|
||||||
|
'country_id', 'shipping_default', 'billing_default',
|
||||||
|
];
|
||||||
|
|
||||||
|
private const WRITABLE_PROFILE_FIELDS = [
|
||||||
|
'title', 'first_name', 'last_name', 'company_name', 'vat_no',
|
||||||
|
];
|
||||||
|
|
||||||
|
public function customer(Authenticatable $user): ?Customer
|
||||||
|
{
|
||||||
|
/** @var Customer|null */
|
||||||
|
return $user->latestCustomer();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Placed orders only (placed_at IS NOT NULL) — a draft/abandoned
|
||||||
|
* order with no placed_at is checkout-in-progress state, not
|
||||||
|
* something that belongs in order history.
|
||||||
|
*/
|
||||||
|
public function orders(Authenticatable $user, int $perPage = 15): LengthAwarePaginator
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
if (! $customer) {
|
||||||
|
return new LengthAwarePaginator([], 0, $perPage);
|
||||||
|
}
|
||||||
|
|
||||||
|
return $customer->orders()
|
||||||
|
->whereNotNull('placed_at')
|
||||||
|
->latest('placed_at')
|
||||||
|
->paginate($perPage);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws OrderNotFoundException if $orderId doesn't belong to this
|
||||||
|
* customer, or belongs to a draft (never placed) order
|
||||||
|
*/
|
||||||
|
public function order(Authenticatable $user, int $orderId): Order
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
$order = $customer
|
||||||
|
?->orders()
|
||||||
|
->whereNotNull('placed_at')
|
||||||
|
->with(['lines', 'shippingAddress', 'billingAddress', 'transactions', 'shipments'])
|
||||||
|
->find($orderId);
|
||||||
|
|
||||||
|
if (! $order) {
|
||||||
|
throw new OrderNotFoundException;
|
||||||
|
}
|
||||||
|
|
||||||
|
return $order;
|
||||||
|
}
|
||||||
|
|
||||||
|
public function addresses(Authenticatable $user): iterable
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
return $customer?->addresses ?? collect();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $data Any key not in
|
||||||
|
* WRITABLE_ADDRESS_FIELDS is silently dropped — see this class's
|
||||||
|
* own docblock.
|
||||||
|
*/
|
||||||
|
public function createAddress(Authenticatable $user, array $data): Address
|
||||||
|
{
|
||||||
|
$customer = $this->customerOrFail($user);
|
||||||
|
|
||||||
|
$address = $customer->addresses()->create(Arr::only($data, self::WRITABLE_ADDRESS_FIELDS));
|
||||||
|
|
||||||
|
$this->enforceSingleDefault($customer, $address);
|
||||||
|
$address->refresh();
|
||||||
|
|
||||||
|
Event::dispatch(new CustomerAddressCreated($address, $user));
|
||||||
|
|
||||||
|
return $address;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws AddressNotFoundException if $addressId doesn't belong to
|
||||||
|
* this customer
|
||||||
|
*/
|
||||||
|
public function updateAddress(Authenticatable $user, int $addressId, array $data): Address
|
||||||
|
{
|
||||||
|
$address = $this->ownedAddress($user, $addressId);
|
||||||
|
$old = $address->only(array_keys(Arr::only($data, self::WRITABLE_ADDRESS_FIELDS)));
|
||||||
|
|
||||||
|
$address->update(Arr::only($data, self::WRITABLE_ADDRESS_FIELDS));
|
||||||
|
|
||||||
|
$this->enforceSingleDefault($address->customer, $address);
|
||||||
|
$address->refresh();
|
||||||
|
|
||||||
|
Event::dispatch(new CustomerAddressUpdated($address, $old, $user));
|
||||||
|
|
||||||
|
return $address;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws AddressNotFoundException if $addressId doesn't belong to
|
||||||
|
* this customer
|
||||||
|
*/
|
||||||
|
public function deleteAddress(Authenticatable $user, int $addressId): void
|
||||||
|
{
|
||||||
|
$address = $this->ownedAddress($user, $addressId);
|
||||||
|
$snapshot = $address->getAttributes();
|
||||||
|
|
||||||
|
$address->delete();
|
||||||
|
|
||||||
|
Event::dispatch(new CustomerAddressDeleted($snapshot, $user));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Lunar has no built-in action enforcing "at most one shipping
|
||||||
|
* default / one billing default per customer" — a raw update() could
|
||||||
|
* otherwise leave two addresses both flagged shipping_default. Runs
|
||||||
|
* after every create/update, unconditionally (cheap — at most two
|
||||||
|
* single-row UPDATEs, only fired when the just-written address
|
||||||
|
* itself is a default), clearing the flag on every OTHER address of
|
||||||
|
* the same customer.
|
||||||
|
*/
|
||||||
|
private function enforceSingleDefault(Customer $customer, Address $address): void
|
||||||
|
{
|
||||||
|
if ($address->shipping_default) {
|
||||||
|
$customer->addresses()->where('id', '!=', $address->id)->update(['shipping_default' => false]);
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($address->billing_default) {
|
||||||
|
$customer->addresses()->where('id', '!=', $address->id)->update(['billing_default' => false]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws AddressNotFoundException if $addressId doesn't belong to
|
||||||
|
* this customer
|
||||||
|
*/
|
||||||
|
private function ownedAddress(Authenticatable $user, int $addressId): Address
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
$address = $customer?->addresses()->find($addressId);
|
||||||
|
|
||||||
|
if (! $address) {
|
||||||
|
throw new AddressNotFoundException;
|
||||||
|
}
|
||||||
|
|
||||||
|
return $address;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $data Any key not in
|
||||||
|
* WRITABLE_PROFILE_FIELDS is silently dropped — see this class's
|
||||||
|
* own docblock.
|
||||||
|
*/
|
||||||
|
public function updateProfile(Authenticatable $user, array $data): Customer
|
||||||
|
{
|
||||||
|
$customer = $this->customerOrFail($user);
|
||||||
|
$old = $customer->only(array_keys(Arr::only($data, self::WRITABLE_PROFILE_FIELDS)));
|
||||||
|
|
||||||
|
$customer->update(Arr::only($data, self::WRITABLE_PROFILE_FIELDS));
|
||||||
|
$customer->refresh();
|
||||||
|
|
||||||
|
Event::dispatch(new CustomerProfileUpdated($customer, $old, $user));
|
||||||
|
|
||||||
|
return $customer;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws LogicException if $user has no paired Customer at all —
|
||||||
|
* distinct from AddressNotFoundException/OrderNotFoundException
|
||||||
|
* (which mean "this id isn't yours"), this means the account
|
||||||
|
* itself is in an invariant-violating state the normal OTP-login
|
||||||
|
* cascade should never produce.
|
||||||
|
*/
|
||||||
|
private function customerOrFail(Authenticatable $user): Customer
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
if (! $customer) {
|
||||||
|
throw new LogicException('This user has no paired Customer record.');
|
||||||
|
}
|
||||||
|
|
||||||
|
return $customer;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Export;
|
||||||
|
|
||||||
|
use Closure;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* One column in a CsvWriter schema: a header label plus a closure that pulls this
|
||||||
|
* column's value out of one record. The closure doesn't care what shape a record
|
||||||
|
* is — an array, an Eloquent model, a DTO — so the same CsvWriter serves any
|
||||||
|
* domain (GDPR export, an admin catalog export, an accounting export) by simply
|
||||||
|
* being handed a different column schema and a different row source.
|
||||||
|
*/
|
||||||
|
final class CsvColumn
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param Closure(mixed):((string|int|float|null)) $value
|
||||||
|
*/
|
||||||
|
public function __construct(
|
||||||
|
public readonly string $header,
|
||||||
|
public readonly Closure $value,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,45 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Export;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A generic columns + rows -> CSV file writer. No knowledge of any domain (GDPR,
|
||||||
|
* catalog, accounting, ...) — a caller supplies the schema (CsvColumn[]) and the
|
||||||
|
* data source (any iterable of records), and this writes one CSV. Reusable for
|
||||||
|
* any future bulk-export need without modification.
|
||||||
|
*/
|
||||||
|
class CsvWriter
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param array<int, CsvColumn> $columns
|
||||||
|
* @param iterable<mixed> $rows
|
||||||
|
*/
|
||||||
|
public function write(array $columns, iterable $rows, string $path): void
|
||||||
|
{
|
||||||
|
$handle = fopen($path, 'w');
|
||||||
|
|
||||||
|
fputcsv($handle, array_map(fn (CsvColumn $column) => $column->header, $columns));
|
||||||
|
|
||||||
|
foreach ($rows as $row) {
|
||||||
|
fputcsv($handle, array_map(
|
||||||
|
fn (CsvColumn $column) => $this->stringify(($column->value)($row)),
|
||||||
|
$columns
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
fclose($handle);
|
||||||
|
}
|
||||||
|
|
||||||
|
private function stringify(mixed $value): string
|
||||||
|
{
|
||||||
|
if ($value === null) {
|
||||||
|
return '';
|
||||||
|
}
|
||||||
|
|
||||||
|
if (is_array($value)) {
|
||||||
|
return json_encode($value);
|
||||||
|
}
|
||||||
|
|
||||||
|
return (string) $value;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -24,6 +24,7 @@ class StorefrontLabels
|
|||||||
'nav.account' => ['en' => 'Account', 'el' => 'Λογαριασμός'],
|
'nav.account' => ['en' => 'Account', 'el' => 'Λογαριασμός'],
|
||||||
'nav.back' => ['en' => 'Back', 'el' => 'Πίσω'],
|
'nav.back' => ['en' => 'Back', 'el' => 'Πίσω'],
|
||||||
'nav.contact' => ['en' => 'Contact', 'el' => 'Επικοινωνία'],
|
'nav.contact' => ['en' => 'Contact', 'el' => 'Επικοινωνία'],
|
||||||
|
'nav.close' => ['en' => 'Close', 'el' => 'Κλείσιμο'],
|
||||||
'cart.empty' => ['en' => 'Your cart is empty', 'el' => 'Το καλάθι σας είναι άδειο'],
|
'cart.empty' => ['en' => 'Your cart is empty', 'el' => 'Το καλάθι σας είναι άδειο'],
|
||||||
'cart.checkout' => ['en' => 'Checkout', 'el' => 'Ολοκλήρωση Παραγγελίας'],
|
'cart.checkout' => ['en' => 'Checkout', 'el' => 'Ολοκλήρωση Παραγγελίας'],
|
||||||
'cart.total' => ['en' => 'Total', 'el' => 'Σύνολο'],
|
'cart.total' => ['en' => 'Total', 'el' => 'Σύνολο'],
|
||||||
@@ -38,6 +39,7 @@ class StorefrontLabels
|
|||||||
'auth.login' => ['en' => 'Log In', 'el' => 'Σύνδεση'],
|
'auth.login' => ['en' => 'Log In', 'el' => 'Σύνδεση'],
|
||||||
'auth.logout' => ['en' => 'Log Out', 'el' => 'Αποσύνδεση'],
|
'auth.logout' => ['en' => 'Log Out', 'el' => 'Αποσύνδεση'],
|
||||||
'search.placeholder' => ['en' => 'Search products…', 'el' => 'Αναζήτηση προϊόντων…'],
|
'search.placeholder' => ['en' => 'Search products…', 'el' => 'Αναζήτηση προϊόντων…'],
|
||||||
|
'search.results_for' => ['en' => 'Search results for ', 'el' => 'Αποτελέσματα αναζήτησης για '],
|
||||||
'customer_reviews' => [
|
'customer_reviews' => [
|
||||||
'en' => '{0} No customer reviews|{1} :count customer review|[2,*] :count customer reviews',
|
'en' => '{0} No customer reviews|{1} :count customer review|[2,*] :count customer reviews',
|
||||||
'el' => '{0} Καμία αξιολόγηση πελάτη|{1} :count αξιολόγηση πελάτη|[2,*] :count αξιολογήσεις πελατών',
|
'el' => '{0} Καμία αξιολόγηση πελάτη|{1} :count αξιολόγηση πελάτη|[2,*] :count αξιολογήσεις πελατών',
|
||||||
@@ -66,6 +68,7 @@ class StorefrontLabels
|
|||||||
'en' => '{0} No products found|{1} Showing :first–:last of :total result|[2,*] Showing :first–:last of :total results',
|
'en' => '{0} No products found|{1} Showing :first–:last of :total result|[2,*] Showing :first–:last of :total results',
|
||||||
'el' => '{0} Δεν βρέθηκαν προϊόντα|{1} Εμφάνιση :first–:last από :total αποτέλεσμα|[2,*] Εμφάνιση :first–:last από :total αποτελέσματα',
|
'el' => '{0} Δεν βρέθηκαν προϊόντα|{1} Εμφάνιση :first–:last από :total αποτέλεσμα|[2,*] Εμφάνιση :first–:last από :total αποτελέσματα',
|
||||||
],
|
],
|
||||||
|
'shop.all_products' => ['en' => 'All Products', 'el' => 'Όλα τα Προϊόντα'],
|
||||||
'shop.sort_label' => ['en' => 'Sort products', 'el' => 'Ταξινόμηση προϊόντων'],
|
'shop.sort_label' => ['en' => 'Sort products', 'el' => 'Ταξινόμηση προϊόντων'],
|
||||||
'shop.sort_default' => ['en' => 'Default sorting', 'el' => 'Προεπιλεγμένη ταξινόμηση'],
|
'shop.sort_default' => ['en' => 'Default sorting', 'el' => 'Προεπιλεγμένη ταξινόμηση'],
|
||||||
'shop.sort_popularity' => ['en' => 'Popularity', 'el' => 'Δημοφιλή'],
|
'shop.sort_popularity' => ['en' => 'Popularity', 'el' => 'Δημοφιλή'],
|
||||||
|
|||||||
@@ -2,25 +2,31 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Logging;
|
namespace Modules\Core\Logging;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
use Illuminate\Database\Eloquent\Model;
|
use Illuminate\Database\Eloquent\Model;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Thin wrapper around Spatie Activity Log that standardises the log channel,
|
* Thin wrapper around Spatie Activity Log that standardises the log channel,
|
||||||
* actor (authenticated staff member), and property shape for all domain events.
|
* actor, and property shape for all domain events.
|
||||||
*
|
*
|
||||||
* All logs are written to the 'lunar' channel. The subject is always an
|
* All logs are written to the 'lunar' channel. The subject is always an
|
||||||
* Eloquent model, and the actor is resolved from the 'staff' guard at call time.
|
* Eloquent model. $causer defaults to the 'staff' guard's current user —
|
||||||
|
* every existing caller of this class is admin-side — but can be passed
|
||||||
|
* explicitly for a non-staff actor (e.g. a customer editing their own
|
||||||
|
* address on the `web` guard — see Modules\Core\Customer\Services\
|
||||||
|
* CustomerAccountService, which passes the acting User rather than
|
||||||
|
* relying on this default resolving to null for a web-guard session).
|
||||||
*/
|
*/
|
||||||
class ActivityLogService
|
class ActivityLogService
|
||||||
{
|
{
|
||||||
/**
|
/**
|
||||||
* Log a creation event. $attributes describes the initial state.
|
* Log a creation event. $attributes describes the initial state.
|
||||||
*/
|
*/
|
||||||
public function created(Model $subject, array $attributes): void
|
public function created(Model $subject, array $attributes, ?Authenticatable $causer = null): void
|
||||||
{
|
{
|
||||||
activity('lunar')
|
activity('lunar')
|
||||||
->performedOn($subject)
|
->performedOn($subject)
|
||||||
->causedBy(auth('staff')->user())
|
->causedBy($causer ?? auth('staff')->user())
|
||||||
->withProperties(['attributes' => $attributes])
|
->withProperties(['attributes' => $attributes])
|
||||||
->log('created');
|
->log('created');
|
||||||
}
|
}
|
||||||
@@ -28,11 +34,11 @@ class ActivityLogService
|
|||||||
/**
|
/**
|
||||||
* Log an update event. $old holds the previous values, $attributes the new ones.
|
* Log an update event. $old holds the previous values, $attributes the new ones.
|
||||||
*/
|
*/
|
||||||
public function updated(Model $subject, array $old, array $attributes): void
|
public function updated(Model $subject, array $old, array $attributes, ?Authenticatable $causer = null): void
|
||||||
{
|
{
|
||||||
activity('lunar')
|
activity('lunar')
|
||||||
->performedOn($subject)
|
->performedOn($subject)
|
||||||
->causedBy(auth('staff')->user())
|
->causedBy($causer ?? auth('staff')->user())
|
||||||
->withProperties(['old' => $old, 'attributes' => $attributes])
|
->withProperties(['old' => $old, 'attributes' => $attributes])
|
||||||
->log('updated');
|
->log('updated');
|
||||||
}
|
}
|
||||||
@@ -40,11 +46,11 @@ class ActivityLogService
|
|||||||
/**
|
/**
|
||||||
* Log a failed operation. $attributes provides context (e.g. error message, service).
|
* Log a failed operation. $attributes provides context (e.g. error message, service).
|
||||||
*/
|
*/
|
||||||
public function failed(Model $subject, array $attributes): void
|
public function failed(Model $subject, array $attributes, ?Authenticatable $causer = null): void
|
||||||
{
|
{
|
||||||
activity('lunar')
|
activity('lunar')
|
||||||
->performedOn($subject)
|
->performedOn($subject)
|
||||||
->causedBy(auth('staff')->user())
|
->causedBy($causer ?? auth('staff')->user())
|
||||||
->withProperties(['attributes' => $attributes])
|
->withProperties(['attributes' => $attributes])
|
||||||
->log('failed');
|
->log('failed');
|
||||||
}
|
}
|
||||||
@@ -52,11 +58,11 @@ class ActivityLogService
|
|||||||
/**
|
/**
|
||||||
* Log a deletion event. $attributes provides context (e.g. reason, name).
|
* Log a deletion event. $attributes provides context (e.g. reason, name).
|
||||||
*/
|
*/
|
||||||
public function deleted(Model $subject, array $attributes): void
|
public function deleted(Model $subject, array $attributes, ?Authenticatable $causer = null): void
|
||||||
{
|
{
|
||||||
activity('lunar')
|
activity('lunar')
|
||||||
->performedOn($subject)
|
->performedOn($subject)
|
||||||
->causedBy(auth('staff')->user())
|
->causedBy($causer ?? auth('staff')->user())
|
||||||
->withProperties(['attributes' => $attributes])
|
->withProperties(['attributes' => $attributes])
|
||||||
->log('deleted');
|
->log('deleted');
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,148 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Logging\Privacy;
|
||||||
|
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
use Lunar\Models\Cart;
|
||||||
|
use Lunar\Models\CartAddress;
|
||||||
|
use Lunar\Models\Customer;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Lunar\Models\OrderAddress;
|
||||||
|
use Lunar\Models\Transaction;
|
||||||
|
use Modules\Core\Privacy\Contracts\PersonalDataProvider;
|
||||||
|
use Modules\Core\Privacy\DTOs\CustomerSubject;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureOutcome;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderErasureResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderExportResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\UserSubject;
|
||||||
|
use Spatie\Activitylog\Models\Activity;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Spatie's own activity_log table (Modules\Core\Logging\ActivityLogService,
|
||||||
|
* plus several Lunar models' native `use LogsActivity` — Customer,
|
||||||
|
* CartAddress, OrderAddress, Transaction) durably retains a full snapshot
|
||||||
|
* of whatever it logged in `properties` (created/updated/deleted
|
||||||
|
* attributes, including a before/after diff on update), completely
|
||||||
|
* independent of the real row it describes. Erasing/pseudonymizing
|
||||||
|
* Customer/Address/CartAddress/OrderAddress/Transaction elsewhere (see
|
||||||
|
* Customer\Privacy\CustomerDataProvider, Customer\Privacy\
|
||||||
|
* AddressDataProvider, Cart\Privacy\CartDataProvider, Order\Privacy\
|
||||||
|
* OrderDataProvider, Payment\Privacy\PaymentDataProvider) does nothing to
|
||||||
|
* this table — a full copy of the old PII survives here regardless.
|
||||||
|
*
|
||||||
|
* Redacts by SUBJECT only, never by `causer_id` — the causer is "who did
|
||||||
|
* this," not PII content, and erasing it would erode the audit trail's own
|
||||||
|
* purpose (see this provider's own eraseForUser(), which is a deliberate
|
||||||
|
* no-op). Genuinely Customer-scope only: every subject type here
|
||||||
|
* (Customer, Address, CartAddress, OrderAddress, Transaction) resolves to
|
||||||
|
* a business account via its own chain (Address/Customer directly;
|
||||||
|
* CartAddress via cart_id -> Cart.customer_id; OrderAddress/Transaction
|
||||||
|
* via order_id -> Order.customer_id) — none of it is a User's own data on
|
||||||
|
* its own.
|
||||||
|
*
|
||||||
|
* MUST run before Customer\Privacy\AddressDataProvider in
|
||||||
|
* config('core.privacy.providers') — that provider hard-deletes Address
|
||||||
|
* rows, and once gone there is no way to re-derive which activity_log
|
||||||
|
* rows (subject_type = Address) belonged to this customer. This provider
|
||||||
|
* resolves that address id list itself, before anything deletes it.
|
||||||
|
*/
|
||||||
|
class ActivityLogDataProvider implements PersonalDataProvider
|
||||||
|
{
|
||||||
|
private const REDACTED = '[redacted]';
|
||||||
|
|
||||||
|
public function name(): string
|
||||||
|
{
|
||||||
|
return 'activity_log';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$activities = Activity::query()
|
||||||
|
->where(fn ($query) => $this->scopeToCustomer($query, $subject->customerId))
|
||||||
|
->get();
|
||||||
|
|
||||||
|
return new ProviderExportResult('activity_log', $activities->map(fn (Activity $activity) => [
|
||||||
|
'id' => $activity->id,
|
||||||
|
'log_name' => $activity->log_name,
|
||||||
|
'description' => $activity->description,
|
||||||
|
'subject_type' => $activity->subject_type,
|
||||||
|
'subject_id' => $activity->subject_id,
|
||||||
|
'event' => $activity->event,
|
||||||
|
'properties' => $activity->properties?->toArray(),
|
||||||
|
'created_at' => $activity->created_at?->toIso8601String(),
|
||||||
|
])->all());
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
return new ProviderExportResult('activity_log', []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
$affected = Activity::query()
|
||||||
|
->where(fn ($query) => $this->scopeToCustomer($query, $subject->customerId))
|
||||||
|
->get();
|
||||||
|
|
||||||
|
if ($affected->isEmpty()) {
|
||||||
|
return new ProviderErasureResult('activity_log', ErasureOutcome::Skipped, 'No activity log entries for this customer.');
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach ($affected as $activity) {
|
||||||
|
$activity->update(['properties' => $this->redact($activity->properties?->toArray() ?? [])]);
|
||||||
|
}
|
||||||
|
|
||||||
|
return new ProviderErasureResult(
|
||||||
|
'activity_log',
|
||||||
|
ErasureOutcome::Pseudonymized,
|
||||||
|
'PII-bearing properties redacted on matching audit log entries; who/what/when metadata (log_name, subject, event, timestamp, causer) retained for audit integrity.'
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
return new ProviderErasureResult(
|
||||||
|
'activity_log',
|
||||||
|
ErasureOutcome::Skipped,
|
||||||
|
'A User only ever appears here as causer_id (who performed an action), not as the PII content of a log entry — redacting that would erode the audit trail\'s own record of who acted.'
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
private function scopeToCustomer($query, int $customerId): void
|
||||||
|
{
|
||||||
|
$customerMorph = (new Customer)->getMorphClass();
|
||||||
|
$addressMorph = (new Address)->getMorphClass();
|
||||||
|
$cartAddressMorph = (new CartAddress)->getMorphClass();
|
||||||
|
$orderAddressMorph = (new OrderAddress)->getMorphClass();
|
||||||
|
$transactionMorph = (new Transaction)->getMorphClass();
|
||||||
|
|
||||||
|
$addressIds = Address::where('customer_id', $customerId)->pluck('id');
|
||||||
|
$cartIds = Cart::where('customer_id', $customerId)->pluck('id');
|
||||||
|
$cartAddressIds = CartAddress::whereIn('cart_id', $cartIds)->pluck('id');
|
||||||
|
$orderIds = Order::where('customer_id', $customerId)->pluck('id');
|
||||||
|
$orderAddressIds = OrderAddress::whereIn('order_id', $orderIds)->pluck('id');
|
||||||
|
$transactionIds = Transaction::whereIn('order_id', $orderIds)->pluck('id');
|
||||||
|
|
||||||
|
$query
|
||||||
|
->where(fn ($q) => $q->where('subject_type', $customerMorph)->where('subject_id', $customerId))
|
||||||
|
->orWhere(fn ($q) => $q->where('subject_type', $addressMorph)->whereIn('subject_id', $addressIds))
|
||||||
|
->orWhere(fn ($q) => $q->where('subject_type', $cartAddressMorph)->whereIn('subject_id', $cartAddressIds))
|
||||||
|
->orWhere(fn ($q) => $q->where('subject_type', $orderAddressMorph)->whereIn('subject_id', $orderAddressIds))
|
||||||
|
->orWhere(fn ($q) => $q->where('subject_type', $transactionMorph)->whereIn('subject_id', $transactionIds));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $properties
|
||||||
|
* @return array<string, mixed>
|
||||||
|
*/
|
||||||
|
private function redact(array $properties): array
|
||||||
|
{
|
||||||
|
return array_map(function ($value) {
|
||||||
|
if (is_array($value)) {
|
||||||
|
return array_map(fn () => self::REDACTED, $value);
|
||||||
|
}
|
||||||
|
|
||||||
|
return self::REDACTED;
|
||||||
|
}, $properties);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,68 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Commands;
|
||||||
|
|
||||||
|
use Illuminate\Console\Command;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Modules\Core\Order\Events\OrderCompleted;
|
||||||
|
use Modules\Core\Order\Services\OrderStatusWriter;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Auto-completes a carrier order once its 14-day return window has
|
||||||
|
* elapsed with no return requested — the automatic counterpart to the
|
||||||
|
* staff "Update Status" action's manual completion. Store-pickup orders
|
||||||
|
* have no return-window step at all (Modules\Core\Order\Listeners\
|
||||||
|
* CompleteOrderOnPickedUp completes them immediately), so this only ever
|
||||||
|
* touches carrier orders sitting in 'delivered' (the status also carrying
|
||||||
|
* "return window is open" — see AdvanceFulfillmentOnDelivered).
|
||||||
|
*
|
||||||
|
* Registered at exactly dailyAt('00:00') in
|
||||||
|
* Modules\Core\Providers\OrderServiceProvider — a compliance requirement
|
||||||
|
* that this run at exact midnight, not Laravel's own arbitrary default
|
||||||
|
* time for a plain daily() schedule.
|
||||||
|
*
|
||||||
|
* "When did the window open" is read from order_status_transitions rather
|
||||||
|
* than Order::updated_at, which any unrelated field write would bump —
|
||||||
|
* this is the concrete reason the audit table exists beyond pure logging.
|
||||||
|
*
|
||||||
|
* Window length is config('core.order.return_window_days') — a legal/
|
||||||
|
* policy value a store may need to change without a code deploy, not a
|
||||||
|
* hardcoded constant.
|
||||||
|
*/
|
||||||
|
class CloseExpiredReturnWindows extends Command
|
||||||
|
{
|
||||||
|
protected $signature = 'boboko:order:close-expired-return-windows';
|
||||||
|
|
||||||
|
protected $description = 'Auto-complete carrier orders whose return window has elapsed with no return requested.';
|
||||||
|
|
||||||
|
public function handle(OrderStatusWriter $writer): void
|
||||||
|
{
|
||||||
|
$cutoff = now()->subDays(config('core.order.return_window_days', 14));
|
||||||
|
|
||||||
|
$orderIds = Order::query()
|
||||||
|
->where('status', 'delivered')
|
||||||
|
->whereHas('statusTransitions', function ($query) use ($cutoff) {
|
||||||
|
$query->where('to_status', 'delivered')
|
||||||
|
->where('created_at', '<=', $cutoff);
|
||||||
|
})
|
||||||
|
->pluck('id');
|
||||||
|
|
||||||
|
$completed = 0;
|
||||||
|
|
||||||
|
foreach ($orderIds as $orderId) {
|
||||||
|
$order = Order::find($orderId);
|
||||||
|
|
||||||
|
if (! $order || $order->status !== 'delivered') {
|
||||||
|
continue; // idempotent no-op — moved on since the query ran
|
||||||
|
}
|
||||||
|
|
||||||
|
$writer->write($order, 'completed', self::class);
|
||||||
|
|
||||||
|
OrderCompleted::dispatch($order);
|
||||||
|
|
||||||
|
$completed++;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->components->info("Completed {$completed} order(s) past their return window.");
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\DTOs;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* What a Modules\Core\Order\Services\OrderFulfillmentService method
|
||||||
|
* returns instead of throwing/echoing a Filament notification directly —
|
||||||
|
* keeps that service usable outside a Filament action (a future API
|
||||||
|
* endpoint, a console command, a test) without dragging
|
||||||
|
* Filament\Notifications\Notification along. Modules\Core\Shipping\
|
||||||
|
* Extensions\OrderViewExtension is the one place that translates this
|
||||||
|
* into an actual on-screen notification.
|
||||||
|
*/
|
||||||
|
final class OrderFulfillmentResult
|
||||||
|
{
|
||||||
|
private function __construct(
|
||||||
|
public readonly bool $success,
|
||||||
|
public readonly string $message,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public static function success(string $message): self
|
||||||
|
{
|
||||||
|
return new self(true, $message);
|
||||||
|
}
|
||||||
|
|
||||||
|
public static function failure(string $message): self
|
||||||
|
{
|
||||||
|
return new self(false, $message);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The one terminal signal every notification/reporting concern that only
|
||||||
|
* cares about "this order is fully done" should listen to, regardless of
|
||||||
|
* which path actually got it there — dispatched by all four:
|
||||||
|
* Modules\Core\Order\Listeners\CompleteOrderOnPickedUp (store-pickup),
|
||||||
|
* Modules\Core\Order\Commands\CloseExpiredReturnWindows (carrier,
|
||||||
|
* automatic 14-day return-window expiry), or Modules\Core\Shipping\
|
||||||
|
* Extensions\OrderViewExtension's "Mark Completed" action (manual
|
||||||
|
* universal fallback, either branch).
|
||||||
|
*/
|
||||||
|
class OrderCompleted
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Modules\Core\Shipping\Models\ShipmentInfo;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by either of the two paths that move a carrier order's
|
||||||
|
* `status` to 'dispatched' — Modules\Core\Order\Listeners\
|
||||||
|
* AdvanceFulfillmentOnCarrierCheckpoint (automatic, reacting to a real
|
||||||
|
* carrier checkpoint) or Modules\Core\Order\Services\
|
||||||
|
* OrderFulfillmentService::createShipmentAndDispatch() (staff-driven, via
|
||||||
|
* the single "Update Status" action). $shipmentInfo is nullable
|
||||||
|
* specifically because of that second path — populated with the
|
||||||
|
* triggering checkpoint when it's real, null when staff drove it
|
||||||
|
* manually. Mirrors OrderDelivered's {order, shipmentInfo} shape, just
|
||||||
|
* with the nullability this one event additionally needs.
|
||||||
|
*/
|
||||||
|
class OrderDispatched
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
public readonly ?ShipmentInfo $shipmentInfo = null,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Modules\Core\Order\Services\OrderStatusWriter::markPaid()
|
||||||
|
* whenever Order::paid flips to true — entirely independent of the
|
||||||
|
* `status` column (see OrderStatusFlow's own docblock for why payment
|
||||||
|
* timing, especially for cash-on-delivery, cannot be modeled as a step in
|
||||||
|
* that sequence). Order::status changes are instead picked up generically
|
||||||
|
* by Modules\Core\Order\Events\OrderStatusUpdated (dispatched by
|
||||||
|
* OrderObserver whenever `status` changes, regardless of writer).
|
||||||
|
*/
|
||||||
|
class OrderPaidChanged
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
public readonly string $causeClass,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Modules\Core\Order\Services\OrderFulfillmentService::
|
||||||
|
* markPickedUp(), the staff-driven "Update Status" action's handling of
|
||||||
|
* the 'picked_up' target — the customer has collected a store-pickup
|
||||||
|
* order in person. Store-pickup only; a carrier order's equivalent
|
||||||
|
* "arrived" moment is OrderDelivered. Modules\Core\Order\Listeners\
|
||||||
|
* CompleteOrderOnPickedUp reacts to this by moving `status` straight to
|
||||||
|
* 'completed' — no return-window step for store-pickup, per the business
|
||||||
|
* design.
|
||||||
|
*/
|
||||||
|
class OrderPickedUp
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Modules\Core\Shipping\Extensions\OrderViewExtension's
|
||||||
|
* "Mark Ready" action, carrier branch (Order::isStorePickupOrder() ===
|
||||||
|
* false) — staff has packed/staged the order for carrier handoff.
|
||||||
|
* Staff-internal: nothing customer-facing happens at this moment, so no
|
||||||
|
* notification listens to this event (compare OrderReadyForPickup, which
|
||||||
|
* does trigger a customer email).
|
||||||
|
*/
|
||||||
|
class OrderReadyForDispatch
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Modules\Core\Shipping\Extensions\OrderViewExtension's
|
||||||
|
* "Mark Ready" action, store-pickup branch (Order::isStorePickupOrder()
|
||||||
|
* === true) — staff has packed/staged the order for the customer to
|
||||||
|
* collect in store. Drives Modules\Core\Order\Notifications\
|
||||||
|
* OrderPickupReadyNotification ("come collect your order").
|
||||||
|
*/
|
||||||
|
class OrderReadyForPickup
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Modules\Core\Order\Services\OrderStatusWriter::write()
|
||||||
|
* alongside the generic Modules\Core\Order\Events\OrderStatusUpdated
|
||||||
|
* (which Modules\Core\Order\Observers\OrderObserver dispatches for ANY
|
||||||
|
* `status` write, regardless of cause, and which
|
||||||
|
* OrderStatusUpdatedNotification already listens to). This event exists
|
||||||
|
* only because the audit trail (Modules\Core\Order\Listeners\
|
||||||
|
* RecordStatusTransition) needs $causeClass, which OrderStatusUpdated
|
||||||
|
* does not carry — OrderStatusWriter is the only writer of `status` this
|
||||||
|
* package has left, so it's the only place that needs to know its own
|
||||||
|
* cause.
|
||||||
|
*/
|
||||||
|
class OrderStatusChanged
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
public readonly Order $order,
|
||||||
|
public readonly ?string $previousStatus,
|
||||||
|
public readonly string $newStatus,
|
||||||
|
public readonly string $causeClass,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,210 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Filament\Extensions;
|
||||||
|
|
||||||
|
use Filament\Actions\Action;
|
||||||
|
use Filament\Forms\Components\Select;
|
||||||
|
use Filament\Notifications\Notification;
|
||||||
|
use Filament\Support\Exceptions\Halt;
|
||||||
|
use Lunar\Admin\Support\Extending\ViewPageExtension;
|
||||||
|
use Lunar\Models\Transaction;
|
||||||
|
use Modules\Core\Payment\Contracts\SupportsRefunds;
|
||||||
|
use Modules\Core\Payment\Models\CoreTransaction;
|
||||||
|
use Modules\Core\Payment\Services\PaymentDriverRegistry;
|
||||||
|
use Modules\Core\Payment\Support\TransactionDriverAdapter;
|
||||||
|
use ReflectionProperty;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Fixes a real bug in Lunar's own admin panel, not anything specific to how
|
||||||
|
* boboko resolves payment drivers: ManageOrder::getRefundAction() and
|
||||||
|
* ::getCaptureAction() (vendor/lunarphp/lunar/.../ManageOrder.php) both
|
||||||
|
* report a failed refund/capture by calling, in this order:
|
||||||
|
* $action->failureNotification(...); $action->failure(); $action->halt();
|
||||||
|
* but Filament\Actions\Concerns\InteractsWithActions::callMountedAction()
|
||||||
|
* only ever calls sendFailureNotification() from a match($action->getStatus())
|
||||||
|
* block that runs AFTER the action's call() returns normally — halt() throws
|
||||||
|
* Filament\Support\Exceptions\Halt, which is caught in an earlier catch block
|
||||||
|
* that rolls back the DB transaction and returns null, never reaching that
|
||||||
|
* match block. So the notification set via failureNotification() is built
|
||||||
|
* but never sent: the admin sees the modal just close/reset with no
|
||||||
|
* indication anything happened. This was always broken in Lunar; it was
|
||||||
|
* invisible before because nothing in this codebase's Transaction::driver()
|
||||||
|
* could return a real, honest failure — see Payment\Support\
|
||||||
|
* TransactionDriverAdapter's own docblock for that history.
|
||||||
|
*
|
||||||
|
* Fix, for refund: same notification fix, but the action() closure is
|
||||||
|
* replaced outright (not wrapped) rather than reused, because refund also
|
||||||
|
* needs a "Refund via" driver Select added to the modal (see
|
||||||
|
* fixRefundAction()) and the actual call routed through
|
||||||
|
* Payment\Support\TransactionDriverAdapter::refundVia() instead of
|
||||||
|
* Lunar\Models\Transaction::refund() — see fixRefundAction()'s own
|
||||||
|
* docblock.
|
||||||
|
*
|
||||||
|
* Fix, for capture: same notification fix, but the action() closure is
|
||||||
|
* also replaced outright — the actual call is routed through
|
||||||
|
* Payment\Support\TransactionDriverAdapter::capture() instead of
|
||||||
|
* Lunar\Models\Transaction::capture() (see fixCaptureAction()), so a
|
||||||
|
* manual backoffice capture goes through the app's own payment driver
|
||||||
|
* registry and dispatches Payment\Events\PaymentCaptured exactly like a
|
||||||
|
* checkout-time capture does — the vendor path resolved
|
||||||
|
* Lunar\Facades\Payments (an entirely separate, unused driver registry)
|
||||||
|
* and never dispatched that event, which is why Order::status used to
|
||||||
|
* stay stuck on 'awaiting_payment' after a manual capture even though
|
||||||
|
* Modules\Core\Order\Listeners\ApplyResolvedPaymentStatus now advances it
|
||||||
|
* on PaymentCaptured.
|
||||||
|
*/
|
||||||
|
class OrderActionsExtension extends ViewPageExtension
|
||||||
|
{
|
||||||
|
public function headerActions(array $actions): array
|
||||||
|
{
|
||||||
|
return array_map(
|
||||||
|
fn (Action $action) => match ($action->getName()) {
|
||||||
|
'refund' => $this->fixRefundAction($action),
|
||||||
|
'capture' => $this->fixCaptureAction($action),
|
||||||
|
default => $action,
|
||||||
|
},
|
||||||
|
$actions,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Combines both refund-only changes on top of the failure-notification
|
||||||
|
* fix every action here gets: adds a "Refund via" driver Select
|
||||||
|
* (defaulting to the transaction's own driver) to the modal, and
|
||||||
|
* replaces the actual refund call with one that honours that field —
|
||||||
|
* calling Payment\Support\TransactionDriverAdapter::refundVia()
|
||||||
|
* directly (bypassing Lunar\Models\Transaction::refund(), whose fixed
|
||||||
|
* refund(int $amount, $notes = null) signature has no room for a
|
||||||
|
* driver override) whenever the admin picked a driver other than the
|
||||||
|
* transaction's own. When left at the default, behaviour is identical
|
||||||
|
* to calling $transaction->refund() — refundVia() resolves to the same
|
||||||
|
* driver either way.
|
||||||
|
*
|
||||||
|
* The Select is appended to Lunar's own schema closure (read via
|
||||||
|
* reflection — HasSchema::$schema has no public getter) rather than
|
||||||
|
* replacing it outright, so the transaction/amount/notes/confirm
|
||||||
|
* fields Lunar already built are untouched.
|
||||||
|
*/
|
||||||
|
private function fixRefundAction(Action $action): Action
|
||||||
|
{
|
||||||
|
$originalSchema = $this->readProtectedProperty($action, 'schema');
|
||||||
|
|
||||||
|
$action->schema(function (array $arguments) use ($action, $originalSchema) {
|
||||||
|
$fields = is_callable($originalSchema)
|
||||||
|
? $action->evaluate($originalSchema, $arguments)
|
||||||
|
: ($originalSchema ?? []);
|
||||||
|
|
||||||
|
return [
|
||||||
|
...$fields,
|
||||||
|
Select::make('driver')
|
||||||
|
->label('Refund via')
|
||||||
|
->options(fn () => $this->refundCapableDriverLabels())
|
||||||
|
->default(fn ($get) => $this->driverKeyForTransaction($get('transaction')))
|
||||||
|
->native(false)
|
||||||
|
->required(),
|
||||||
|
];
|
||||||
|
});
|
||||||
|
|
||||||
|
return $action->action(function (array $data, Action $action) {
|
||||||
|
$transaction = Transaction::find($data['transaction']);
|
||||||
|
|
||||||
|
if (! $transaction instanceof CoreTransaction) {
|
||||||
|
$action->failureNotification(fn () => Notification::make('refund_failure')->danger()->title('Transaction not found.'))
|
||||||
|
->sendFailureNotification();
|
||||||
|
|
||||||
|
throw new Halt;
|
||||||
|
}
|
||||||
|
|
||||||
|
$adapter = app(TransactionDriverAdapter::class);
|
||||||
|
$driverKey = $data['driver'] ?? $adapter->driverKeyFor($transaction);
|
||||||
|
|
||||||
|
$response = $adapter->refundVia($transaction, $driverKey, (int) bcmul((string) $data['amount'], (string) $transaction->order->currency->factor), $data['notes'] ?? null);
|
||||||
|
|
||||||
|
if (! $response->success) {
|
||||||
|
$action->failureNotification(
|
||||||
|
fn () => Notification::make('refund_failure')->color('danger')->title($response->message)
|
||||||
|
)->sendFailureNotification();
|
||||||
|
|
||||||
|
throw new Halt;
|
||||||
|
}
|
||||||
|
|
||||||
|
$action->success();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Mirrors fixRefundAction()'s notification fix, but for the "amount"
|
||||||
|
* field already on the vendor schema — no extra field needed, since
|
||||||
|
* capture always goes back through the transaction's own original
|
||||||
|
* driver (there's no equivalent to refunding via a different driver).
|
||||||
|
*/
|
||||||
|
private function fixCaptureAction(Action $action): Action
|
||||||
|
{
|
||||||
|
return $action->action(function (array $data, Action $action) {
|
||||||
|
$transaction = Transaction::find($data['transaction']);
|
||||||
|
|
||||||
|
if (! $transaction instanceof CoreTransaction) {
|
||||||
|
$action->failureNotification(fn () => Notification::make('capture_failure')->danger()->title('Transaction not found.'))
|
||||||
|
->sendFailureNotification();
|
||||||
|
|
||||||
|
throw new Halt;
|
||||||
|
}
|
||||||
|
|
||||||
|
$response = app(TransactionDriverAdapter::class)->capture(
|
||||||
|
$transaction,
|
||||||
|
(int) bcmul((string) $data['amount'], (string) $transaction->order->currency->factor),
|
||||||
|
);
|
||||||
|
|
||||||
|
if (! $response->success) {
|
||||||
|
$action->failureNotification(
|
||||||
|
fn () => Notification::make('capture_failure')->color('danger')->title($response->message)
|
||||||
|
)->sendFailureNotification();
|
||||||
|
|
||||||
|
throw new Halt;
|
||||||
|
}
|
||||||
|
|
||||||
|
$action->success();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return array<string, string>
|
||||||
|
*/
|
||||||
|
private function refundCapableDriverLabels(): array
|
||||||
|
{
|
||||||
|
$registry = app(PaymentDriverRegistry::class);
|
||||||
|
|
||||||
|
$labels = [];
|
||||||
|
|
||||||
|
foreach ($registry->all() as $key => $driverClass) {
|
||||||
|
if (app($driverClass) instanceof SupportsRefunds) {
|
||||||
|
$labels[$key] = $registry->label($key) ?? $key;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return $labels;
|
||||||
|
}
|
||||||
|
|
||||||
|
private function driverKeyForTransaction(mixed $transactionId): ?string
|
||||||
|
{
|
||||||
|
if (blank($transactionId)) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
$transaction = Transaction::find($transactionId);
|
||||||
|
|
||||||
|
if (! $transaction instanceof CoreTransaction) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
return app(TransactionDriverAdapter::class)->driverKeyFor($transaction);
|
||||||
|
}
|
||||||
|
|
||||||
|
private function readProtectedProperty(object $object, string $property): mixed
|
||||||
|
{
|
||||||
|
$reflected = new ReflectionProperty($object, $property);
|
||||||
|
$reflected->setAccessible(true);
|
||||||
|
|
||||||
|
return $reflected->getValue($object);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,50 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Filament\Extensions;
|
||||||
|
|
||||||
|
use Filament\Actions\BulkAction;
|
||||||
|
use Filament\Support\Exceptions\Halt;
|
||||||
|
use Filament\Tables\Table;
|
||||||
|
use Lunar\Admin\Support\Extending\BaseExtension;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Same fix as OrderActionsExtension, applied to the order lines
|
||||||
|
* table's "bulk_refund" toolbar action (Lunar\Admin\...\OrderItemsTable::
|
||||||
|
* getBulkRefundAction()) — see that class's docblock for the underlying
|
||||||
|
* Filament bug (failureNotification()+failure()+halt() never actually
|
||||||
|
* sends the notification, because halt()'s Halt exception is caught before
|
||||||
|
* Filament reaches the code that would send it).
|
||||||
|
*/
|
||||||
|
class OrderItemsTableExtension extends BaseExtension
|
||||||
|
{
|
||||||
|
public function extendTable(Table $table): Table
|
||||||
|
{
|
||||||
|
return $table->toolbarActions(
|
||||||
|
array_map(
|
||||||
|
fn ($action) => $action instanceof BulkAction && $action->getName() === 'bulk_refund'
|
||||||
|
? $this->fixFailureNotification($action)
|
||||||
|
: $action,
|
||||||
|
$table->getToolbarActions(),
|
||||||
|
),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
private function fixFailureNotification(BulkAction $action): BulkAction
|
||||||
|
{
|
||||||
|
$originalAction = $action->getActionFunction();
|
||||||
|
|
||||||
|
if ($originalAction === null) {
|
||||||
|
return $action;
|
||||||
|
}
|
||||||
|
|
||||||
|
return $action->action(function (array $arguments) use ($action, $originalAction) {
|
||||||
|
try {
|
||||||
|
return $action->evaluate($originalAction, $arguments);
|
||||||
|
} catch (Halt $exception) {
|
||||||
|
$action->sendFailureNotification();
|
||||||
|
|
||||||
|
throw $exception;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,49 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Filament\Extensions;
|
||||||
|
|
||||||
|
use Filament\Infolists\Components\TextEntry;
|
||||||
|
use Lunar\Admin\Support\Extending\ViewPageExtension;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Modules\Core\Payment\Models\PaymentMethod;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Adds a "Payment Method" entry to the order summary sidebar — previously
|
||||||
|
* nowhere on the order page told staff which payment method a shopper
|
||||||
|
* actually used. Reads Order.meta['payment_method'] (written by
|
||||||
|
* Modules\Core\Checkout\Services\CheckoutService::initiatePayment()), the
|
||||||
|
* same source Modules\Core\Order\Services\OrderStatusFlow::isCod() reads,
|
||||||
|
* so this entry and the "Mark Paid" action's visibility always agree on
|
||||||
|
* what payment method an order used. Falls back to the most recent
|
||||||
|
* Transaction.driver for an order placed before that field existed.
|
||||||
|
*
|
||||||
|
* Uses the extendOrderSummarySchema hook, same as the deleted 3-axis
|
||||||
|
* OrderStatusSummaryExtension did — see that class's git history for the
|
||||||
|
* hook's own docblock/rationale.
|
||||||
|
*/
|
||||||
|
class OrderPaymentMethodSummaryExtension extends ViewPageExtension
|
||||||
|
{
|
||||||
|
public function extendOrderSummarySchema(array $schema): array
|
||||||
|
{
|
||||||
|
$schema[] = TextEntry::make('payment_method')
|
||||||
|
->label('Payment method')
|
||||||
|
->state(fn (Order $record) => $this->resolveLabel($record))
|
||||||
|
->placeholder('—')
|
||||||
|
->alignEnd();
|
||||||
|
|
||||||
|
return $schema;
|
||||||
|
}
|
||||||
|
|
||||||
|
private function resolveLabel(Order $record): ?string
|
||||||
|
{
|
||||||
|
$type = $record->meta['payment_method'] ?? $record->transactions()->latest('id')->value('driver');
|
||||||
|
|
||||||
|
if ($type === null) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
$method = PaymentMethod::where('type', $type)->first();
|
||||||
|
|
||||||
|
return $method?->translate('name') ?? $type;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Filament\Extensions;
|
||||||
|
|
||||||
|
use Filament\Infolists\Components\RepeatableEntry;
|
||||||
|
use Lunar\Admin\Support\Extending\ViewPageExtension;
|
||||||
|
use Modules\Core\Order\Filament\Infolists\TransactionEntry;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Swaps Lunar\Admin\Support\Infolists\Components\Transaction for our own
|
||||||
|
* TransactionEntry in the order page's transactions list — same component,
|
||||||
|
* different Blade view, so a Transaction.meta['notes'] value (written by
|
||||||
|
* a manual/attested driver like Payment\Drivers\BankTransferPaymentDriver)
|
||||||
|
* actually renders somewhere, instead of only the notes column Lunar's own
|
||||||
|
* view reads (see TransactionEntry's own docblock for why that column is
|
||||||
|
* usually empty for a successful manual payment/refund).
|
||||||
|
*
|
||||||
|
* Uses the extendTransactionsRepeatableEntry hook ManageOrder's own
|
||||||
|
* DisplaysTransactions trait already calls
|
||||||
|
* (getTransactionsRepeatableEntry() → callStaticLunarHook(
|
||||||
|
* 'extendTransactionsRepeatableEntry', ...)) — a class/component swap via
|
||||||
|
* a Lunar-provided hook, the same category of extension already used
|
||||||
|
* throughout CorePlugin, not a Blade view-path override.
|
||||||
|
*/
|
||||||
|
class OrderTransactionsExtension extends ViewPageExtension
|
||||||
|
{
|
||||||
|
public function extendTransactionsRepeatableEntry(RepeatableEntry $entry): RepeatableEntry
|
||||||
|
{
|
||||||
|
return $entry->schema([
|
||||||
|
TransactionEntry::make('transaction_detail'),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Filament\Infolists;
|
||||||
|
|
||||||
|
use Lunar\Admin\Support\Infolists\Components\Transaction as LunarTransactionEntry;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Same component as Lunar's own Transaction infolist entry — only the
|
||||||
|
* Blade view differs, to also show Transaction.meta['notes'] (what
|
||||||
|
* Payment\Drivers\BankTransferPaymentDriver and any other manual/attested
|
||||||
|
* driver write a staff-entered note into — see that driver's own
|
||||||
|
* docblock) when the notes column itself is empty. The notes column is
|
||||||
|
* populated by Order\Services\TransactionRecorder from
|
||||||
|
* PaymentResult::$failureReason, which is only ever set on a FAILED
|
||||||
|
* result — a successful manual payment/refund's note would otherwise be
|
||||||
|
* recorded (Transaction.meta) but never shown anywhere in the admin
|
||||||
|
* panel, since Lunar's own view only ever reads the notes column.
|
||||||
|
*
|
||||||
|
* Registered in place of Lunar's own Transaction component via
|
||||||
|
* Order\Filament\Extensions\OrderTransactionsExtension's
|
||||||
|
* extendTransactionsRepeatableEntry() hook (see that class), not a
|
||||||
|
* view-path override — this is the same "swap the concrete
|
||||||
|
* class/component" pattern already used throughout CorePlugin
|
||||||
|
* (LunarPanel::extensions()), rather than shadowing Lunar's Blade file
|
||||||
|
* from underneath it.
|
||||||
|
*/
|
||||||
|
class TransactionEntry extends LunarTransactionEntry
|
||||||
|
{
|
||||||
|
protected string $view = 'core::order.infolists.transaction';
|
||||||
|
}
|
||||||
@@ -0,0 +1,49 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Listeners;
|
||||||
|
|
||||||
|
use Modules\Core\Order\Events\OrderDispatched;
|
||||||
|
use Modules\Core\Order\Services\OrderStatusWriter;
|
||||||
|
use Modules\Core\Shipping\Enums\TrackingStatus;
|
||||||
|
use Modules\Core\Shipping\Events\ShipmentStatusUpdatedByCarrier;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The automatic half of "Dispatched" — the manual fallback is the staff
|
||||||
|
* "Update Status" action (Modules\Core\Shipping\Extensions\
|
||||||
|
* OrderViewExtension). Listens to ShipmentStatusUpdatedByCarrier directly,
|
||||||
|
* the same event Modules\Core\Order\Listeners\DeriveOrderDeliveredFromShipment
|
||||||
|
* listens to.
|
||||||
|
*
|
||||||
|
* Reacts to either TrackingStatus::CollectedFromSender (the carrier
|
||||||
|
* collected the parcel from the merchant) or InTransit directly, for a
|
||||||
|
* carrier that skips straight there without a distinct collection
|
||||||
|
* checkpoint.
|
||||||
|
*
|
||||||
|
* Guarded to only fire from 'ready_for_dispatch' — a late/duplicate
|
||||||
|
* checkpoint, or an order the manual action already advanced, is a
|
||||||
|
* silent no-op.
|
||||||
|
*/
|
||||||
|
class AdvanceFulfillmentOnCarrierCheckpoint
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly OrderStatusWriter $writer,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public function handle(ShipmentStatusUpdatedByCarrier $event): void
|
||||||
|
{
|
||||||
|
if ($event->shipmentInfo->status !== TrackingStatus::InTransit
|
||||||
|
&& $event->shipmentInfo->status !== TrackingStatus::CollectedFromSender) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$order = $event->shipmentInfo->shipment->order;
|
||||||
|
|
||||||
|
if (! $order || $order->status !== 'ready_for_dispatch') {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->writer->write($order, 'dispatched', self::class);
|
||||||
|
|
||||||
|
OrderDispatched::dispatch($order, $event->shipmentInfo);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Listeners;
|
||||||
|
|
||||||
|
use Modules\Core\Order\Events\OrderDelivered;
|
||||||
|
use Modules\Core\Order\Services\OrderStatusWriter;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Writes `status` to 'delivered' once a carrier confirms delivery, rather
|
||||||
|
* than jumping straight to 'completed'. Carrier orders get a return
|
||||||
|
* window between delivery and completion (see Modules\Core\Order\
|
||||||
|
* Commands\CloseExpiredReturnWindows, which auto-completes an order once
|
||||||
|
* that window elapses) — 'delivered' is both "the parcel arrived" and
|
||||||
|
* "the return window is now open"; nothing distinguishes those as
|
||||||
|
* separate instants, they're the same moment, so there is only the one
|
||||||
|
* status value.
|
||||||
|
*
|
||||||
|
* Kept separate from Modules\Core\Order\Listeners\
|
||||||
|
* DeriveOrderDeliveredFromShipment, which only ever dispatches
|
||||||
|
* OrderDelivered — deriving "was this delivered" and acting on it by
|
||||||
|
* writing `status` are deliberately two different listeners.
|
||||||
|
*
|
||||||
|
* Guarded to only fire from 'dispatched' — a duplicate/late Delivered
|
||||||
|
* checkpoint, or an order a manual action already moved past, is a
|
||||||
|
* silent no-op.
|
||||||
|
*/
|
||||||
|
class AdvanceFulfillmentOnDelivered
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly OrderStatusWriter $writer,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public function handle(OrderDelivered $event): void
|
||||||
|
{
|
||||||
|
$order = $event->order;
|
||||||
|
|
||||||
|
if ($order->status !== 'dispatched') {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->writer->write($order, 'delivered', self::class);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -5,34 +5,53 @@ namespace Modules\Core\Order\Listeners;
|
|||||||
use Illuminate\Support\Facades\Event;
|
use Illuminate\Support\Facades\Event;
|
||||||
use Lunar\Models\Order;
|
use Lunar\Models\Order;
|
||||||
use Modules\Core\Checkout\Events\OrderPlaced;
|
use Modules\Core\Checkout\Events\OrderPlaced;
|
||||||
|
use Modules\Core\Order\Enums\PaymentStatus;
|
||||||
|
use Modules\Core\Order\Services\OrderStatusFlow;
|
||||||
|
use Modules\Core\Order\Services\OrderStatusWriter;
|
||||||
|
use Modules\Core\Order\Support\OrderStatus;
|
||||||
use Modules\Core\Payment\Events\PaymentAuthorized;
|
use Modules\Core\Payment\Events\PaymentAuthorized;
|
||||||
use Modules\Core\Payment\Events\PaymentCaptured;
|
use Modules\Core\Payment\Events\PaymentCaptured;
|
||||||
|
use Modules\Core\Payment\Events\PaymentRefunded;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* The only place an Order's status column is written in reaction to a
|
* Registered against PaymentCaptured, PaymentAuthorized, AND
|
||||||
* payment outcome. Registered against BOTH PaymentCaptured and
|
* PaymentRefunded (see OrderServiceProvider).
|
||||||
* PaymentAuthorized (see OrderServiceProvider) — same handler either way,
|
*
|
||||||
* since both carry the same {type, result, context} shape and only differ
|
* PaymentCaptured writes both Order::paid/paid_at (via
|
||||||
* in which config key decides the resulting status.
|
* OrderStatusWriter::markPaid()) AND advances `status` out of
|
||||||
|
* 'awaiting_payment' to the next step in the order's flow (see
|
||||||
|
* OrderStatusFlow::nextOptions()) — re-confirmed with the user: a
|
||||||
|
* captured payment, manual or via Stripe's webhook, should never leave an
|
||||||
|
* order sitting at 'awaiting_payment'. Only fires when status is still
|
||||||
|
* exactly 'awaiting_payment', so a duplicate/delayed capture event never
|
||||||
|
* regresses an order staff already advanced further. PaymentAuthorized
|
||||||
|
* only marks paid — an authorization is not yet captured funds, so
|
||||||
|
* status stays put until the actual capture.
|
||||||
|
*
|
||||||
|
* A refund still moves `status` (returned -> refunded/partially_refunded)
|
||||||
|
* — refunds are a normal step in Modules\Core\Order\Services\
|
||||||
|
* OrderStatusFlow's own sequence, unlike captures. Derives
|
||||||
|
* Refunded/PartialRefund from Modules\Core\Order\Support\OrderStatus::
|
||||||
|
* payment() — the existing, unchanged derived-enum logic, reused rather
|
||||||
|
* than reimplemented.
|
||||||
*
|
*
|
||||||
* Reads $event->context['order_id'] to find which Order this outcome
|
* Reads $event->context['order_id'] to find which Order this outcome
|
||||||
* belongs to — Payment has no concept of an Order, so this is the one
|
* belongs to — Payment has no concept of an Order.
|
||||||
* place that context key gets consumed on the Order side (Payment's own
|
|
||||||
* StripePaymentDriver reads $context['order_id'] independently, for its
|
|
||||||
* own unrelated correlation need — see that class's rememberIntent()).
|
|
||||||
*
|
*
|
||||||
* Loads and saves the model (not a bulk ::whereKey()->update()) so
|
* Dispatches Checkout\Events\OrderPlaced itself, once placed_at is set.
|
||||||
* Order::observe()'s updated() hook fires and OrderStatusUpdated goes out
|
* Never fires from the PaymentRefunded path — a refund can only ever
|
||||||
* the same as any other status write — see that event's own docblock for
|
* happen after an order was already placed.
|
||||||
* why it's meant to fire "regardless of what wrote it."
|
|
||||||
*
|
*
|
||||||
* Dispatches Checkout\Events\OrderPlaced itself, once placed_at is set —
|
* Deliberately does NOT react to PaymentVoided.
|
||||||
* see that event's own docblock for why this, not CheckoutService, is now
|
|
||||||
* the dispatch point.
|
|
||||||
*/
|
*/
|
||||||
class ApplyResolvedPaymentStatus
|
class ApplyResolvedPaymentStatus
|
||||||
{
|
{
|
||||||
public function handle(PaymentCaptured|PaymentAuthorized $event): void
|
public function __construct(
|
||||||
|
private readonly OrderStatusWriter $writer,
|
||||||
|
private readonly OrderStatusFlow $flow,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public function handle(PaymentCaptured|PaymentAuthorized|PaymentRefunded $event): void
|
||||||
{
|
{
|
||||||
$orderId = $event->context['order_id'] ?? null;
|
$orderId = $event->context['order_id'] ?? null;
|
||||||
|
|
||||||
@@ -42,22 +61,59 @@ class ApplyResolvedPaymentStatus
|
|||||||
|
|
||||||
$order = Order::findOrFail($orderId);
|
$order = Order::findOrFail($orderId);
|
||||||
|
|
||||||
$configKey = $event instanceof PaymentCaptured ? 'captured_status' : 'authorized_status';
|
if ($event instanceof PaymentRefunded) {
|
||||||
$status = config("lunar.payments.types.{$event->type}.{$configKey}");
|
$this->applyRefund($order, $event);
|
||||||
|
|
||||||
if ($status === null) {
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
$wasPlaced = ! blank($order->placed_at);
|
$wasPlaced = ! blank($order->placed_at);
|
||||||
|
|
||||||
$order->update([
|
$this->writer->markPaid($order, $event::class);
|
||||||
'status' => $status,
|
|
||||||
'placed_at' => $order->placed_at ?? now(),
|
if ($event instanceof PaymentCaptured) {
|
||||||
]);
|
$this->advancePastAwaitingPayment($order, $event);
|
||||||
|
}
|
||||||
|
|
||||||
if (! $wasPlaced) {
|
if (! $wasPlaced) {
|
||||||
|
$order->update(['placed_at' => $order->placed_at ?? now()]);
|
||||||
Event::dispatch(new OrderPlaced($order));
|
Event::dispatch(new OrderPlaced($order));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private function advancePastAwaitingPayment(Order $order, PaymentCaptured $event): void
|
||||||
|
{
|
||||||
|
if ($order->status !== 'awaiting_payment') {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$next = $this->flow->nextOptions($order);
|
||||||
|
$target = array_key_first($next);
|
||||||
|
|
||||||
|
if ($target !== null) {
|
||||||
|
$this->writer->write($order, $target, $event::class);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Requires the refund Transaction row to already exist (Modules\Core\
|
||||||
|
* Order\Listeners\RecordPaymentTransaction must run first — see
|
||||||
|
* OrderServiceProvider's listener registration order for
|
||||||
|
* PaymentRefunded), so the relation is refreshed here rather than
|
||||||
|
* trusted from a possibly-stale $order instance.
|
||||||
|
*/
|
||||||
|
private function applyRefund(Order $order, PaymentRefunded $event): void
|
||||||
|
{
|
||||||
|
$order->load('transactions');
|
||||||
|
|
||||||
|
$target = match (OrderStatus::payment($order)) {
|
||||||
|
PaymentStatus::Refunded => 'refunded',
|
||||||
|
PaymentStatus::PartialRefund => 'partially_refunded',
|
||||||
|
default => null,
|
||||||
|
};
|
||||||
|
|
||||||
|
if ($target !== null && $order->status !== $target) {
|
||||||
|
$this->writer->write($order, $target, $event::class);
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,39 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Listeners;
|
||||||
|
|
||||||
|
use Modules\Core\Order\Events\OrderCompleted;
|
||||||
|
use Modules\Core\Order\Events\OrderPickedUp;
|
||||||
|
use Modules\Core\Order\Services\OrderStatusWriter;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The store-pickup mirror of AdvanceFulfillmentOnDelivered — reacts to
|
||||||
|
* OrderPickedUp (dispatched by Modules\Core\Order\Services\
|
||||||
|
* OrderFulfillmentService::markPickedUp() the moment staff confirm the
|
||||||
|
* customer collected the order) by moving `status` straight to
|
||||||
|
* 'completed'. No return-window step for store-pickup orders, per the
|
||||||
|
* business design — unlike the carrier branch, there is no 'delivered'
|
||||||
|
* intermediate value on this path.
|
||||||
|
*
|
||||||
|
* Guarded to only fire from 'picked_up' — a duplicate dispatch (e.g. a
|
||||||
|
* stale page re-submitting the action) is a silent no-op.
|
||||||
|
*/
|
||||||
|
class CompleteOrderOnPickedUp
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly OrderStatusWriter $writer,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public function handle(OrderPickedUp $event): void
|
||||||
|
{
|
||||||
|
$order = $event->order;
|
||||||
|
|
||||||
|
if ($order->status !== 'picked_up') {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->writer->write($order, 'completed', self::class);
|
||||||
|
|
||||||
|
OrderCompleted::dispatch($order);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,64 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Listeners;
|
||||||
|
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Lunar\Models\Product;
|
||||||
|
use Lunar\Models\ProductVariant;
|
||||||
|
use Modules\Core\Checkout\Events\OrderPlaced;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The only place ProductVariant::stock is written as a result of an order —
|
||||||
|
* fires once per order regardless of capture_mode/driver, same reasoning as
|
||||||
|
* Modules\Core\Order\Notifications\OrderPlacedNotification: OrderPlaced is
|
||||||
|
* dispatched exactly once, from the one place an order's placed_at
|
||||||
|
* actually gets set (Modules\Core\Order\Listeners\ApplyResolvedPaymentStatus),
|
||||||
|
* so this can't double-decrement across a capture/authorize/refund sequence
|
||||||
|
* the way listening to PaymentCaptured directly could.
|
||||||
|
*
|
||||||
|
* Only decrements for `purchasable === 'in_stock'` variants — 'always' and
|
||||||
|
* 'backorder' variants are deliberately allowed to sell past (or without
|
||||||
|
* regard to) their stock count already (see ProductVariant::
|
||||||
|
* canBeFulfilledAtQuantity()), so decrementing their stock would just make
|
||||||
|
* that column an inaccurate, decreasingly-negative number with no purchasing
|
||||||
|
* consequence. Only `OrderLine::type === 'physical'` lines are considered —
|
||||||
|
* a digital line has no stock to decrement (ProductVariant::getType()).
|
||||||
|
*
|
||||||
|
* A single UPDATE per variant (`DB::table(...)->decrement()`), not a
|
||||||
|
* read-then-write on the Eloquent model — avoids a lost-update race between
|
||||||
|
* two orders decrementing the same variant concurrently, and skips
|
||||||
|
* Modules\Core\Catalog\Services\ProductIndexer::stock's staleness gap for
|
||||||
|
* the DB value itself even though the search index still only refreshes on
|
||||||
|
* the next reindex event/nightly job (see that class's own docblock).
|
||||||
|
*
|
||||||
|
* Never lets stock go negative (`GREATEST(stock - qty, 0)` via a raw
|
||||||
|
* expression) — an order can still be placed against a variant whose stock
|
||||||
|
* was already fully consumed by another concurrent order (Lunar has no
|
||||||
|
* stock-reservation step at cart/checkout time), so this is a best-effort
|
||||||
|
* count, not a hard inventory guarantee.
|
||||||
|
*/
|
||||||
|
class DecrementStockOnOrderPlaced
|
||||||
|
{
|
||||||
|
public function handle(OrderPlaced $event): void
|
||||||
|
{
|
||||||
|
$lines = $event->order->lines()
|
||||||
|
->where('type', 'physical')
|
||||||
|
->where('purchasable_type', ProductVariant::morphName())
|
||||||
|
->get(['purchasable_id', 'quantity']);
|
||||||
|
|
||||||
|
foreach ($lines as $line) {
|
||||||
|
DB::table((new ProductVariant())->getTable())
|
||||||
|
->where('id', $line->purchasable_id)
|
||||||
|
->where('purchasable', 'in_stock')
|
||||||
|
->update([
|
||||||
|
'stock' => DB::raw('GREATEST(stock - '.(int) $line->quantity.', 0)'),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
$productIds = ProductVariant::whereIn('id', $lines->pluck('purchasable_id'))
|
||||||
|
->pluck('product_id')
|
||||||
|
->unique();
|
||||||
|
|
||||||
|
Product::whereIn('id', $productIds)->get()->each->searchable();
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,35 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Listeners;
|
||||||
|
|
||||||
|
use Modules\Core\Order\Services\OrderStatusWriter;
|
||||||
|
use Modules\Core\Shipping\Enums\TrackingStatus;
|
||||||
|
use Modules\Core\Shipping\Events\ShipmentStatusUpdatedByCarrier;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Wires TrackingStatus::Failed to the 'delivery_failed' status for the
|
||||||
|
* first time — previously an unused enum case. Guarded to only fire from
|
||||||
|
* 'dispatched': a stale/duplicate checkpoint, or an order a manual action
|
||||||
|
* already moved past, is a silent no-op.
|
||||||
|
*/
|
||||||
|
class MarkDeliveryFailedOnCarrierCheckpoint
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly OrderStatusWriter $writer,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public function handle(ShipmentStatusUpdatedByCarrier $event): void
|
||||||
|
{
|
||||||
|
if ($event->shipmentInfo->status !== TrackingStatus::Failed) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$order = $event->shipmentInfo->shipment->order;
|
||||||
|
|
||||||
|
if (! $order || $order->status !== 'dispatched') {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->writer->write($order, 'delivery_failed', self::class);
|
||||||
|
}
|
||||||
|
}
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user