Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c7035d6782 | ||
|
|
4c0974bf84 | ||
|
|
4e15d8ef8c | ||
|
|
1c7efc6e4d | ||
|
|
59c57b37fc | ||
|
|
37b49963f6 | ||
|
|
050204f063 | ||
|
|
c0ae9d8996 | ||
|
|
cc1cf6ea7f | ||
|
|
0437057e5d | ||
|
|
0c169daf55 | ||
|
|
609a63c2f4 | ||
|
|
12aaa43f10 | ||
|
|
dcdc998eee | ||
|
|
a55697ce82 | ||
|
|
a411e6bbc1 | ||
|
|
910fa94395 | ||
|
|
fdd1899c34 | ||
|
|
3ad3a1b4d6 | ||
|
|
68233f43ef | ||
|
|
027f7e8982 | ||
|
|
c084eb47cb | ||
|
|
58d165acc3 | ||
|
|
44ad943eec | ||
|
|
2cc6f5e5f0 | ||
|
|
0babc6a96d | ||
|
|
89a3d4bbad | ||
|
|
ccb2666495 | ||
|
|
97004234f0 | ||
|
|
ea73cc3562 | ||
|
|
02816fb9e7 | ||
|
|
910ce0205d | ||
|
|
e532c32cab | ||
|
|
6a51b672c8 | ||
|
|
956e9e88a6 | ||
|
|
4489475840 | ||
|
|
e4e008167a | ||
|
|
a5f3008ce2 | ||
|
|
409e8204f6 | ||
|
|
8472649905 | ||
|
|
e7784364fd | ||
|
|
59303cf25f | ||
|
|
af380a7fa0 | ||
|
|
9f540cbaa4 |
+509
-27
@@ -4,9 +4,439 @@ All notable changes to this project will be documented in this file.
|
|||||||
|
|
||||||
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
||||||
|
|
||||||
|
## [0.20.0] - 2026-09-23
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `Modules\Core\Catalog\Support\ProductFilterBuilder::withVisibility()` — every storefront
|
||||||
|
product read (`ProductService::list()`/`getById()`/`getBySlug()`/`random()`/`facets()`/
|
||||||
|
`priceRange()`, and `ProductSearchService`) now excludes `status = "draft"` products unless
|
||||||
|
`APP_DEBUG` is true. Previously nothing filtered by status anywhere in this service — a draft
|
||||||
|
product was fully visible on the storefront in every environment, always.
|
||||||
|
- Per-product custom input fields (`Modules\Core\Catalog\Models\Product::$custom_fields`) — a
|
||||||
|
repeater on the product edit form lets a merchant define extra input a shopper fills in on
|
||||||
|
that product's page before adding it to cart (a reference photo upload, personalization
|
||||||
|
text, etc.), each field a `{key, type: text|textarea|file, label, required}` entry.
|
||||||
|
Deliberately not a Lunar `ProductOption`: an option's values are a fixed, admin-authored list
|
||||||
|
that define variants, which doesn't fit "the shopper uploads their own unique photo."
|
||||||
|
Required a new first-party `Product` model (registered via `ModelManifest::replace()`) purely
|
||||||
|
to add a cast and `$fillable` entry Lunar's own base model doesn't have for this column — see
|
||||||
|
that class's own docblock for two real Lunar-integration bugs this surfaced (below).
|
||||||
|
- `boboko:wipe-catalog` (`Modules\Core\Command\WipeCatalogCommand`) — irreversibly deletes every
|
||||||
|
Product and everything that only exists because of a product (variants, variant prices,
|
||||||
|
product-option assignments, images/media, associations, the `ImportMapping` rows tying them
|
||||||
|
back to an external source, the Meilisearch index), leaving catalog structure other products
|
||||||
|
could still reference untouched (ProductOption/ProductOptionValue definitions, Brands,
|
||||||
|
Collections, Tags, Customer Groups). Gated by an OTP emailed to a real Staff account (reusing
|
||||||
|
`Auth\Services\OtpService`, the same mechanism admin login already uses) plus typing the exact
|
||||||
|
product count back — not a plain yes/no confirm.
|
||||||
|
- `Modules\Core\Auth\Services\OtpService::generateAndSend()` gained an optional `$purpose`
|
||||||
|
parameter (default `'login'`, fully backward compatible) — `OtpMail` picks its subject/intro
|
||||||
|
copy from a small fixed set of known purposes, so a destructive-command confirmation code
|
||||||
|
reads as "Confirm: Wipe Catalog," not the login flow's "Your login code."
|
||||||
|
- `Modules\Core\Catalog\Services\SkuBackfillService` — the actual backfill logic behind
|
||||||
|
`boboko:catalog:backfill-skus`, extracted so `MigrateImport\RunMigrateImportJob` can also call
|
||||||
|
it automatically right after a Shopify import (gated on `$spec->source === 'shopify'`, the
|
||||||
|
only source that creates variants at all) — no separate manual step needed after a migration.
|
||||||
|
- `ProductSort::Popularity` — sorts by a new `order_count` field Meilisearch now indexes per
|
||||||
|
product (trailing-year, physical order lines only, aggregated across a product's variants) —
|
||||||
|
the same "popular" definition Lunar's own admin dashboard "Popular Products" widget already
|
||||||
|
uses. Not wired into the storefront's sort dropdown yet; callable directly via
|
||||||
|
`ProductService::list(sort: ProductSort::Popularity)`.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- `MigrateImport\Shopify\ShopifyExportImporter` created every variant with Lunar's own column
|
||||||
|
default `purchasable = 'always'` (purchasable regardless of stock) rather than respecting the
|
||||||
|
real `Variant Inventory Qty` the import itself provides — now explicitly set to `'in_stock'`.
|
||||||
|
Forward-only; does not retroactively touch variants from a prior import run.
|
||||||
|
- `WipeCatalogCommand::wipe()` used `chunkById()` while deleting rows inside the loop — a known
|
||||||
|
pitfall where `chunkById()` re-queries "id > lastSeenId" every iteration, so deleting rows
|
||||||
|
shrinks the table out from under it and can silently skip products that were never actually
|
||||||
|
deleted at all. Fixed by always re-querying the first N remaining rows instead of advancing
|
||||||
|
an id cursor, so every product is visited exactly once regardless of how many are deleted out
|
||||||
|
from under the query as it goes.
|
||||||
|
- `WipeCatalogCommand` called `delete()`, not `forceDelete()`, on `Product`/`ProductVariant` —
|
||||||
|
both use `SoftDeletes`, so an "irreversible" wipe only trashed rows, leaving them sitting in
|
||||||
|
the table. Combined with the `chunkById` bug above, this left ~185 zero-variant ghost
|
||||||
|
`Product` rows in practice, which then crashed the admin's own global search (Lunar's
|
||||||
|
`ProductResource::getGlobalSearchResultDetails()` assumes every returned product — trashed
|
||||||
|
ones deliberately included, by Lunar's own design — has at least one variant). Fixed to
|
||||||
|
`forceDelete()`; the existing ghost rows were removed directly (none had live order/cart
|
||||||
|
references). `wipe()` also now clears `'image'`-type `ImportMapping` rows, not just
|
||||||
|
`'product'`/`'variant'`.
|
||||||
|
- `ShopifyExportImporter::resolveOrImportImage()` trusted a cached `ImportMapping`'d `Media`
|
||||||
|
object unconditionally — now verifies the row still exists and is still attached to the
|
||||||
|
current product before reusing it, falling through to a fresh import/attach otherwise. Makes
|
||||||
|
a re-import robust to orphaned media regardless of what left them behind (e.g. a prior
|
||||||
|
`WipeCatalogCommand` run, before the fix above).
|
||||||
|
- Cart admin view (`Cart\Filament\Resources\CartResource\Pages\ViewCart`) 500'd
|
||||||
|
(`Lunar\Exceptions\MissingCurrencyPriceException`) for any cart still holding a line whose
|
||||||
|
purchasable no longer exists (e.g. after `boboko:wipe-catalog`) — `Cart::calculate()` now has
|
||||||
|
that exception caught, falling back to an uncalculated cart; every total field already
|
||||||
|
rendered `?->formatted() ?? '—'`, so the page degrades to showing "—" instead of a 500.
|
||||||
|
- Creating or editing a Payment Method offered "Capture mode" (Charge immediately / Hold now,
|
||||||
|
charge later) even for `cash-on-delivery`, whose driver has no `authorize()` method at
|
||||||
|
all — selecting "authorize" there would have fatally errored at checkout. Now hidden/
|
||||||
|
non-required unless the resolved driver implements `SupportsAuthorization`.
|
||||||
|
- `Lunar\Base\Traits\Searchable::indexer()` (and its sibling filterable/sortable-attribute
|
||||||
|
methods) resolve their configured indexer via `$config[self::class]` — but `self::class`
|
||||||
|
inside a trait method is a compile-time literal bound to whichever class first `use`s the
|
||||||
|
trait, so it always evaluates to `Lunar\Models\Product`, never a subclass, regardless of
|
||||||
|
which instance calls it. `config/lunar/search.php`'s `'indexers'` map must stay keyed by
|
||||||
|
`Lunar\Models\Product::class`, not the new `Product` subclass — keying it by the subclass
|
||||||
|
made the lookup miss entirely and silently fall back to a near-empty default indexer, wiping
|
||||||
|
every filterable/sortable attribute the index had. Caught live, reverted; documented in the
|
||||||
|
config file itself so it isn't repeated.
|
||||||
|
- `CustomerServiceProvider`/`CatalogServiceProvider` called `ModelManifest::replace()` directly
|
||||||
|
from `boot()` — `LunarServiceProvider` (lunarphp/core) calls `Facades\ModelManifest::
|
||||||
|
register()` from its OWN `boot()`, re-discovering every `Lunar\Models\*` class and silently
|
||||||
|
overwriting any `replace()` registered earlier in the provider boot order. Both now defer to
|
||||||
|
`$this->app->booted()`, which only runs once every provider's `boot()` has completed.
|
||||||
|
|
||||||
|
## [0.19.0] - 2026-09-18
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `Modules\Core\Payment\Contracts\RequiresFulfillmentType` — a payment driver can now declare
|
||||||
|
it only makes sense for one fulfillment type (carrier delivery vs. store pickup), the
|
||||||
|
payment-side mirror of `Shipping\Contracts\DeclaresFulfillmentType`. `CheckoutService::
|
||||||
|
getPaymentMethods()` excludes a method whose driver disagrees with the cart's currently
|
||||||
|
selected shipping method — `OfflinePaymentDriver` ("pay in store") now requires
|
||||||
|
`store_pickup`, `CashOnDeliveryPaymentDriver` requires `carrier`. Previously every enabled,
|
||||||
|
configured payment method was offered regardless of shipping choice, so a shopper picking a
|
||||||
|
courier delivery could still see "Pay in store" (no staff member present to take cash), and a
|
||||||
|
store-pickup shopper could see cash-on-delivery (meaningless — there is no delivery to collect
|
||||||
|
payment on). No constraint is imposed before a shipping option is selected.
|
||||||
|
- `Modules\Core\Payment\Events\PaymentDeferred` — dispatched by any payment driver whose
|
||||||
|
`Pending` result will never resolve via a later gateway callback (currently only
|
||||||
|
`CashOnDeliveryPaymentDriver`), distinct from a Stripe-style `Pending` that a webhook will
|
||||||
|
still resolve. Handled by the new `Modules\Core\Order\Listeners\
|
||||||
|
MarkOrderPlacedOnDeferredPayment`, which sets `Order::placed_at`, dispatches `OrderPlaced`,
|
||||||
|
and advances `status` past `awaiting_payment` — without ever touching `Order::paid`, which
|
||||||
|
still only flips via staff explicitly marking a COD order received.
|
||||||
|
- `Modules\Core\Order\Services\OrderPaymentResolutionService::resolveDeferredPayment()` — the
|
||||||
|
status-advance half of the above, reusing the same "advance past `awaiting_payment`" logic a
|
||||||
|
captured payment already uses.
|
||||||
|
- `Modules\Core\Checkout\Exceptions\NoShippingAddressException`.
|
||||||
|
- `Modules\Core\Shipping\Carriers\BoxNow\BoxNowClient::destinations()` — lists available Box
|
||||||
|
Now lockers (`GET /destinations`), backing a plain, self-hosted locker picker on checkout;
|
||||||
|
Box Now's own Destination Map JS widget only talks to their Production environment, making it
|
||||||
|
unusable while developing against Stage credentials.
|
||||||
|
- `config/shippingCarriers/boxnow.php`: `BOXNOW_PARTNER_ID` — issued alongside Box Now
|
||||||
|
credentials, consumed only by their client-side map widget, never by `BoxNowClient`'s own
|
||||||
|
REST authentication.
|
||||||
|
- A "Tracking history" list under each shipment on the order page (`Shipping\Extensions\
|
||||||
|
OrderShipmentsExtension`) — every recorded carrier checkpoint, oldest first, not just the
|
||||||
|
latest status.
|
||||||
|
- `Modules\Core\Review\Services\ReviewService` and `ReviewEvents\ReviewReplied` — extracted
|
||||||
|
from `ManageProductReviews`'s inline `$record->update()`, following the write-then-dispatch
|
||||||
|
pattern used everywhere else.
|
||||||
|
- `Modules\Core\Catalog\Services\StockService::decrementForOrder()` — extracted from
|
||||||
|
`DecrementStockOnOrderPlaced`, isolating the atomic stock-decrement SQL and Meilisearch
|
||||||
|
reindex from the listener itself.
|
||||||
|
- `Modules\Core\Order\Services\OrderStatusFlow::isValidTransition()` — the single source of
|
||||||
|
truth for "is this a legal next status," replacing several listeners' own hardcoded "only
|
||||||
|
fire from status X" comparisons.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- Cash-on-delivery orders were placed but never left `awaiting_payment`, were invisible in
|
||||||
|
customer order history, never decremented stock, and the storefront's own post-checkout
|
||||||
|
confirmation could never find them — `CashOnDeliveryPaymentDriver::pay()` returns `Pending`,
|
||||||
|
which dispatched no event at all, so nothing ever set `Order::placed_at` or advanced
|
||||||
|
`status`. Fixed by `PaymentDeferred`/`MarkOrderPlacedOnDeferredPayment` above.
|
||||||
|
- Staff marking a COD order "paid" (`OrderFulfillmentService::markPaid()`) flipped
|
||||||
|
`Order::paid`/`paid_at` but never recorded a `Transaction` row — no audit trail, and anything
|
||||||
|
reading `$order->transactions` (paid-amount displays included) saw nothing. Now records a
|
||||||
|
`capture` transaction via `TransactionRecorder`, the exact call site its own docblock had
|
||||||
|
already anticipated ("a future admin action ... can write a row the same way").
|
||||||
|
- A confirmed cash-on-delivery shipment dispatched via ACS or Box Now never actually told the
|
||||||
|
carrier to collect payment — `ShipmentRequest::$paymentMode`/`$amountToCollect` were defined
|
||||||
|
on the DTO but no caller ever populated them, permanently dead-coding both carriers' COD
|
||||||
|
branches (`AcsFulfillmentService`'s `Cod_Ammount`/`Cod_Payment_Way`, Box Now's
|
||||||
|
`amountToBeCollected`). `OrderViewExtension`'s "Create Shipment" action now derives both from
|
||||||
|
`OrderStatusFlow::isCod($order)` at dispatch time — never left to staff to remember.
|
||||||
|
- `Modules\Core\Shipping\Jobs\PollShipmentTrackingJob`: one shipment's tracking lookup failing
|
||||||
|
(a carrier 500, a malformed parcel response) aborted the rest of that carrier's shipments in
|
||||||
|
the same batch — now individually caught and reported per shipment.
|
||||||
|
- Every Box Now delivery request 400'd (`P405`, invalid phone number) for any customer whose
|
||||||
|
phone was stored in local Greek format rather than full international — `contactNumber` is
|
||||||
|
now normalized to `+30...` before every request.
|
||||||
|
- Creating a Box Now shipment 400'd (`P401`/`P402`) whenever `BOXNOW_ORIGIN_LOCATION_ID` or the
|
||||||
|
sender contact fields were unset — documented and confirmed against a live sandbox account.
|
||||||
|
- Selecting a Box Now locker at checkout, then making any unrelated address-form edit
|
||||||
|
afterward (even a delivery-instructions keystroke), silently discarded the locker choice —
|
||||||
|
`Lunar\Actions\Carts\AddAddress` deletes and recreates the cart's shipping address row on
|
||||||
|
every save, wiping whatever `meta` a prior save had written onto it.
|
||||||
|
`CheckoutService::setShippingAddress()` now carries the locker forward across that
|
||||||
|
recreation; `selectShippingOption()` clears it when switching away from Box Now, so a stale
|
||||||
|
locker never resurfaces if the shopper switches back later.
|
||||||
|
`Shipping\Extensions\OrderViewExtension`'s "Box Now locker ID" field is no longer locked
|
||||||
|
read-only once a customer choice exists — staff can override it.
|
||||||
|
- Creating a Box Now shipping method 500'd (`Array to string conversion` / invalid JSON insert)
|
||||||
|
— the vendor `ListShippingMethod` page's `CreateAction` builds its form inline, bypassing
|
||||||
|
`ShippingMethodResourceExtension`'s translated-name field entirely; `Filament\Pages\
|
||||||
|
ManageShippingRates`'s method picker and "Shipping Method" table column also queried/sorted
|
||||||
|
the now-JSON `name` column directly in SQL (`could not identify an ordering operator for type
|
||||||
|
json`), both resolved app-side instead.
|
||||||
|
- Creating or editing a Payment Method: `capture_mode` ("Charge immediately" / "Hold now,
|
||||||
|
charge later") was offered even for a driver with no `authorize()` method at all
|
||||||
|
(`CashOnDeliveryPaymentDriver`), which would have fatally errored at checkout had "authorize"
|
||||||
|
ever been selected — now hidden/non-required unless the driver implements
|
||||||
|
`SupportsAuthorization`. A spurious `validation.required` on the translated Name field, and
|
||||||
|
every new Payment Method silently saving at `position` 0 regardless of the intended
|
||||||
|
"last in the list" default — both traced to the same cause: an `Action::schema()` modal only
|
||||||
|
dehydrates fields backed by a real form component, so `fillForm()`'s defaults for `name`/
|
||||||
|
`position` were computed but never actually reached the saved record.
|
||||||
|
- `Modules\Core\Auth\Services\UserOtpService::generateAndSend()` now dispatches `UserCreated`
|
||||||
|
when a new `User` row is created — this event was previously never dispatched anywhere in
|
||||||
|
this package at all, despite listeners existing for it.
|
||||||
|
- Applied a deliberate queueing policy across every Order/Localization/Customer/Payment/
|
||||||
|
Catalog listener, judged case-by-case on "if the queue stalls for minutes/hours, does this
|
||||||
|
cause a real functional break, not just cosmetic staleness" — `RecordPaymentTransaction`,
|
||||||
|
`CompleteOrderOnPickedUp`, `CreateCustomerForUser`, and `DecrementStockOnOrderPlaced` stay
|
||||||
|
synchronous (a stalled queue would mean a real ordering violation or oversell risk); cache
|
||||||
|
flushes, activity logging, and carrier-checkpoint-driven fulfillment listeners are now queued.
|
||||||
|
|
||||||
|
## [0.18.1] - 2026-09-16
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `Modules\Core\Payment\Privacy\PaymentDataProvider` — `lunar_transactions` (`card_type`/
|
||||||
|
`last_four`) and `stripe_payment_intents` were previously uncovered by any Privacy provider.
|
||||||
|
Pseudonymizes card metadata on erasure (same tax/accounting retention reasoning as
|
||||||
|
`OrderDataProvider`); deletes the Stripe correlation rows outright, since their only purpose
|
||||||
|
(resolving an async webhook callback) has already been served by the time an erasure request
|
||||||
|
runs. No Stripe Customer object exists anywhere in this app to also request deletion of — see
|
||||||
|
`docs/payments.md` "Reconciliation".
|
||||||
|
- `Modules\Core\Auth\Privacy\UserSessionDataProvider` — `user_sessions` (`ip_address`,
|
||||||
|
`user_agent`) was previously uncovered. User-scope only; deleted outright on erasure, no legal
|
||||||
|
retention argument applies to login-session metadata.
|
||||||
|
- `Modules\Core\Logging\Privacy\ActivityLogDataProvider` — Spatie's `activity_log` table
|
||||||
|
(`Modules\Core\Logging\ActivityLogService`, plus several Lunar models' native `LogsActivity`)
|
||||||
|
durably retained full PII snapshots in `properties` even after the real row was erased
|
||||||
|
elsewhere. Redacts `properties` by subject (`Customer`/`Address`/`CartAddress`/`OrderAddress`/
|
||||||
|
`Transaction`) on erasure; deliberately never touches `causer_id`, which is an actor reference,
|
||||||
|
not PII content. Must run before `AddressDataProvider` in `config('core.privacy.providers')` —
|
||||||
|
see the class's own docblock.
|
||||||
|
- `ErasureOutcome::Failed` — a provider throwing an exception is now a genuine, distinct outcome
|
||||||
|
from `Skipped` (a deliberate no-op), surfaced in the erasure report rather than silently
|
||||||
|
aborting the request.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- `PrivacyService::completeErasure()` and `ExportDataSubjectJob::handle()` ran every registered
|
||||||
|
provider through a plain `array_map()` with no per-provider error handling — one provider
|
||||||
|
throwing aborted the entire request, discarding every other provider's already-computed
|
||||||
|
result and leaving the request stuck `Pending`/`Failed` with no report at all. Both now catch
|
||||||
|
per-provider (`PrivacyService::safeErase()`, `ExportDataSubjectJob::safeExport()`), logging the
|
||||||
|
exception and recording `ErasureOutcome::Failed`/`ProviderExportResult::$error` for that one
|
||||||
|
provider while every other provider's result is still recorded normally. Verified live:
|
||||||
|
simulating a throwing provider mid-erasure now correctly completes the request with a mixed
|
||||||
|
`erased`/`failed`/`erased` report instead of leaving it `Pending` forever.
|
||||||
|
- `CartDataProvider`/`OrderDataProvider` never covered PII-adjacent keys living in `Cart.meta`/
|
||||||
|
`Order.meta`/`OrderAddress.meta` — `recovery_consent*`, `payment_method`, `checkout_fingerprint`
|
||||||
|
(Cart), `terms_accepted*` (Order), and `box_now_locker` (OrderAddress) all survived an erasure
|
||||||
|
request untouched. Both providers now clear these keys alongside their existing address/
|
||||||
|
free-text field erasure.
|
||||||
|
- `CustomerDataProvider::eraseForUser()` left `otp_code`/`otp_expires_at`/`otp_attempts` on an
|
||||||
|
otherwise-erased `User` row. Now cleared alongside name/email.
|
||||||
|
- `Modules\Core\Privacy\Filament\Resources\DataErasureRequestResource`'s "Outcome" section
|
||||||
|
referenced `docs/privacy.md` directly in staff-facing UI text (meaningless to a user with no
|
||||||
|
repo access) and rendered the per-provider report as raw JSON strings via a `KeyValueEntry`
|
||||||
|
(the wrong component for a list of structured rows). Replaced with a plain-language
|
||||||
|
description and a proper `RepeatableEntry` table (Data category / Outcome badge / Reason).
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- The 5 existing Privacy providers (`CustomerDataProvider`, `AddressDataProvider`,
|
||||||
|
`OrderDataProvider`, `CartDataProvider`, `ReviewDataProvider`) moved out of
|
||||||
|
`Modules\Core\Privacy\Providers` into their owning domain module's own `Privacy/` subdirectory
|
||||||
|
(e.g. `Modules\Core\Order\Privacy\OrderDataProvider`) — `Modules\Core\Privacy` now owns only
|
||||||
|
the shared contract, request lifecycle, and DTOs/enums. Matters concretely if a module is ever
|
||||||
|
extracted into its own composer package: the provider that knows how to erase that module's
|
||||||
|
data now travels with it, rather than being stranded in `Privacy` depending on a package that
|
||||||
|
no longer ships in this repo. See `docs/privacy.md` for the full reasoning.
|
||||||
|
|
||||||
|
## [0.18.0] - 2026-09-16
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
Customer-portal backend groundwork — no routes/controllers/views yet (a storefront-facing UI is
|
||||||
|
3dealer's job once a frontend designer picks it up), but the boboko-owned services it needs to
|
||||||
|
call now exist:
|
||||||
|
|
||||||
|
- `Modules\Core\Auth\Services\UserOtpService::validate()` now actually logs the shopper in
|
||||||
|
(`Auth::login()`, `web` guard) — previously it only returned the `User` model with no session
|
||||||
|
established and no route/controller anywhere ever called it (the checkout page's "Login" tab
|
||||||
|
was a disabled placeholder). `Auth::login()` alone is enough to merge/associate any active
|
||||||
|
guest cart too — it fires `Illuminate\Auth\Events\Login`, which Lunar's own
|
||||||
|
`Lunar\Listeners\CartSessionAuthListener` (registered unconditionally in core, no opt-in
|
||||||
|
needed) already reacts to, honoring `config('lunar.cart.auth_policy')` (`'merge'` by default).
|
||||||
|
An earlier draft of this also called `Cart::associate()` directly from this service — removed
|
||||||
|
as redundant and actually wrong: it ran a second, separate association with a hardcoded
|
||||||
|
`'merge'` policy that ignored whatever a consumer had actually set `auth_policy` to. Also fixed
|
||||||
|
an unbounded brute-force window: a 6-digit code (1M combinations, was guessable for its full
|
||||||
|
10-minute expiry with no attempt cap) now invalidates itself after 5 wrong guesses
|
||||||
|
(`users.otp_attempts`, new column), forcing a fresh code request rather than leaving a live one
|
||||||
|
guessable indefinitely.
|
||||||
|
- `Modules\Core\Auth\Events\CustomerLoggedIn` — dispatched on every successful OTP login (new
|
||||||
|
user or returning), for a storefront to hook into (e.g. post-login redirect, analytics).
|
||||||
|
- `Modules\Core\Customer\Services\CustomerAccountService` — the storefront-facing "My Account"
|
||||||
|
API (mirrors `CartService`/`CheckoutService`'s shape): `orders()` (paginated, placed orders
|
||||||
|
only), `order()`, `addresses()`, `createAddress()`/`updateAddress()`/`deleteAddress()`,
|
||||||
|
`updateProfile()`. Every method is scoped to the given user's own `latestCustomer()` — there
|
||||||
|
is no method that accepts a bare order/address id without also requiring the owning user, so a
|
||||||
|
controller built on top of this can't leak one customer's data to another by trusting a
|
||||||
|
client-supplied id alone (verified live: a second customer attempting to read/edit the first's
|
||||||
|
address or order gets `AddressNotFoundException`/`OrderNotFoundException`, not the record).
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- `Modules\Core\Auth\Services\UserOtpService::validate()`'s wrong-guess counter (`otp_attempts`)
|
||||||
|
was read-check-increment-saved with no locking — two guesses fired in parallel for the same
|
||||||
|
user could each read the same pre-increment value and both save past `max_attempts`, letting an
|
||||||
|
attacker exceed the 5-guess lockout by parallelizing requests instead of sending them serially.
|
||||||
|
Now wrapped in a `DB::transaction()` with `lockForUpdate()` on the user row, so concurrent
|
||||||
|
guesses serialize correctly against the shared counter.
|
||||||
|
- The OTP code comparison used a plain `!=` rather than a timing-safe comparison. Now
|
||||||
|
`hash_equals()`.
|
||||||
|
|
||||||
|
## [0.17.5] - 2026-09-15
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Greek translations for `Lunar\Models\Country`/`State` reference data (`lang/el/countries.php`,
|
||||||
|
`lang/el/states.php`), keyed by the exact English spellings Lunar's own installer seeds for
|
||||||
|
Greece (fetched from `data.lunarphp.io/countries+states.json`). Loaded via
|
||||||
|
`loadTranslationsFrom()` under the `core::` namespace — a plain lang file, not
|
||||||
|
`Modules\Core\Localization`'s DB-backed `TranslationService`, since this is fixed reference
|
||||||
|
data, not admin-editable UI copy. A consuming app's storefront looks these up itself (e.g.
|
||||||
|
`__('core::countries.'.$country->name)`) — core has no storefront UI of its own to wire this
|
||||||
|
into.
|
||||||
|
- `Modules\Core\Order\Filament\Extensions\OrderActionsExtension::fixCaptureAction()` — reroutes
|
||||||
|
the backoffice "Capture" header action through `Modules\Core\Payment\Support\
|
||||||
|
TransactionDriverAdapter::capture()`, the same app-level payment pipeline checkout-time captures
|
||||||
|
use, instead of vendor Lunar's `Lunar\Models\Transaction::capture()` (which resolved
|
||||||
|
`Lunar\Facades\Payments`, an entirely separate, unused driver registry, and never dispatched
|
||||||
|
`Modules\Core\Payment\Events\PaymentCaptured`).
|
||||||
|
- `Modules\Core\Payment\Drivers\StripePaymentDriver::cardMetaFromIntent()` — extracts card
|
||||||
|
brand/last-four digits from the Stripe PaymentIntent's `latest_charge`, populated into
|
||||||
|
`PaymentResult::$meta` and mapped onto `Transaction.card_type`/`last_four` by
|
||||||
|
`Modules\Core\Order\Services\TransactionRecorder`. Fixes the admin activity log's "Payment of
|
||||||
|
:amount on card ending :last_four" line rendering with no digits, on both checkout-time and
|
||||||
|
manual captures. Only applies to transactions recorded after this change.
|
||||||
|
- `PaymentMethod.name` and `Lunar\Shipping\Models\ShippingMethod.name` are now locale-keyed JSON
|
||||||
|
columns, rendered in Filament via Lunar's own `Lunar\Admin\Support\Forms\Components\
|
||||||
|
TranslatedText` — one input per configured `Language` row, same shape/resolution as
|
||||||
|
Product/Collection names. Existing plain-string rows are preserved under the store's default
|
||||||
|
language on migration. `ShippingMethod` has no model cast/`ModelManifest` extension point
|
||||||
|
available (vendor table, `Contracts\ShippingMethod` exists but is never bound by the package),
|
||||||
|
so its translation is decoded/encoded at the Filament field boundary and via the new
|
||||||
|
`Modules\Core\Shipping\Support\ShippingMethodName::resolve()` helper, rather than a model cast.
|
||||||
|
- `Modules\Core\Shipping\Contracts\DeclaresFulfillmentType` — lets a shipping rate driver declare
|
||||||
|
whether it fulfils via carrier delivery or in-store pickup as a hardcoded fact about the driver
|
||||||
|
(`AcsRateDriver`, `BoxNowRateDriver` both declare `'carrier'`), instead of asking a merchant to
|
||||||
|
also pick "Carrier delivery" on every row regardless of driver. The merchant-facing "Fulfillment
|
||||||
|
type" Select (`ShippingMethod.data['fulfillment_type']`) now only appears for
|
||||||
|
table-rate-shipping's generic drivers (flat-rate, ship-by, free-shipping), which are genuinely
|
||||||
|
ambiguous, and moved next to `charge_by` instead of trailing at the end of the form,
|
||||||
|
disconnected from the decisions it relates to. `Modules\Core\Shipping\Support\
|
||||||
|
FulfillmentType::resolve()`/`isStorePickup()` is the new single source of truth, replacing a
|
||||||
|
direct `data['fulfillment_type']` read in `Order::isStorePickupOrder()`.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- `Modules\Core\Order\Listeners\ApplyResolvedPaymentStatus` never advanced `Order::status` past
|
||||||
|
`awaiting_payment` on a capture — only `paid`/`paid_at` were written, so a fully captured order
|
||||||
|
could sit indefinitely at "awaiting payment" until a staff member manually clicked "Update
|
||||||
|
Status". Now, on `PaymentCaptured` (not `PaymentAuthorized`), `status` advances to the next step
|
||||||
|
in the order's flow, but only when it's still exactly `awaiting_payment`, so a duplicate/delayed
|
||||||
|
capture event never regresses an order staff already moved further.
|
||||||
|
- `Lunar\DataTypes\ShippingOption::$collect` (the flag `docs/checkout.md` documents as the
|
||||||
|
mechanism for detecting a pickup option at checkout) was never actually set by any shipping rate
|
||||||
|
driver — `Modules\Core\Shipping\Concerns\ResolvesFixedPricing` now populates it from the same
|
||||||
|
`FulfillmentType` resolution `Order::isStorePickupOrder()` uses, closing a real gap between
|
||||||
|
documented and actual behavior.
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- `Modules\Core\Order\Filament\Extensions\OrderRefundActionsExtension` renamed to
|
||||||
|
`OrderActionsExtension` — the class now fixes both the refund and capture header actions on the
|
||||||
|
order page, not just refund.
|
||||||
|
- Removed the `lunarphp/stripe` dependency in favour of depending on `stripe/stripe-php` directly.
|
||||||
|
`Modules\Core\Payment\Drivers\StripePaymentDriver` had already replaced every bit of Lunar's own
|
||||||
|
Stripe payment flow (checkout, webhook processing) with its own — all that remained load-bearing
|
||||||
|
from the package was raw API-client access, amount conversion, and a correlation table, none of
|
||||||
|
which are Lunar-specific. Added first-party replacements: `Modules\Core\Payment\Support\
|
||||||
|
StripeManager`, `Modules\Core\Payment\Models\StripePaymentIntent`, `Modules\Core\Payment\Http\
|
||||||
|
Middleware\StripeWebhookMiddleware`, and a first-party copy of the vendor's
|
||||||
|
`create_stripe_payment_intents_table` migration (guarded with `Schema::hasTable()`). No behavior
|
||||||
|
change for consuming apps.
|
||||||
|
|
||||||
|
## [0.17.4] - 2026-09-15
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- `boboko:catalog:backfill-skus` — one-off Artisan command to generate a SKU
|
||||||
|
(`SKU-P{product_id}-V{variant_id}`) for every `Lunar\Models\ProductVariant` left with a `null`
|
||||||
|
SKU by the earlier Shopify import (the source export's `Variant SKU` column was genuinely blank
|
||||||
|
for these rows, not an importer mapping bug — see `Modules\MigrateImport\Shopify\
|
||||||
|
ShopifyExportImporter`). Only touches variants missing a SKU; `--dry-run` lists what would
|
||||||
|
change without writing.
|
||||||
|
|
||||||
|
## [0.17.3] - 2026-09-15
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Removed the `lunarphp/stripe` dependency in favour of depending on `stripe/stripe-php` directly.
|
||||||
|
`Modules\Core\Payment\Drivers\StripePaymentDriver` had already replaced every bit of Lunar's own
|
||||||
|
Stripe payment flow (checkout, webhook processing) with its own — all that remained load-bearing
|
||||||
|
from the package was raw API-client access, amount conversion, and a correlation table, none of
|
||||||
|
which are Lunar-specific. Added first-party replacements: `Modules\Core\Payment\Support\
|
||||||
|
StripeManager` (API client + `toStripeAmount()`/`fromStripeAmount()`), `Modules\Core\Payment\
|
||||||
|
Models\StripePaymentIntent` (now with a proper `context` array cast, replacing manual
|
||||||
|
`json_encode`/`json_decode`), and `Modules\Core\Payment\Http\Middleware\
|
||||||
|
StripeWebhookMiddleware`. Added `database/migrations/..._create_stripe_payment_intents_table.php`,
|
||||||
|
a first-party copy of the vendor migration (guarded with `Schema::hasTable()` so it's a no-op on
|
||||||
|
any environment that already has the table from the vendor package's own earlier migration run,
|
||||||
|
and only actually creates it on a genuinely fresh install). No behavior change for consuming
|
||||||
|
apps — same table, same driver contract, same webhook endpoint.
|
||||||
|
|
||||||
|
## [0.17.2] - 2026-09-15
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- `Modules\Core\Order\Listeners\ApplyResolvedPaymentStatus` never advanced `Order::status` past
|
||||||
|
`awaiting_payment` on a capture — only `paid`/`paid_at` were written, so a fully captured order
|
||||||
|
could sit indefinitely at "awaiting payment" until a staff member manually clicked "Update
|
||||||
|
Status". Now, on `PaymentCaptured` (not `PaymentAuthorized` — an authorization isn't yet
|
||||||
|
captured funds), `status` advances to the next step in the order's flow
|
||||||
|
(`Modules\Core\Order\Services\OrderStatusFlow::nextOptions()`) — but only when it's still
|
||||||
|
exactly `awaiting_payment`, so a duplicate/delayed capture event never regresses an order staff
|
||||||
|
already moved further.
|
||||||
|
- The backoffice "Capture" action on the order page (Filament) called vendor Lunar's
|
||||||
|
`Lunar\Models\Transaction::capture()` directly, which resolves `Lunar\Facades\Payments` — an
|
||||||
|
entirely separate, unused driver registry — and never dispatched `Modules\Core\Payment\Events\
|
||||||
|
PaymentCaptured`. This meant a manual capture from the admin panel never ran this app's own
|
||||||
|
payment pipeline at all (including the status-advance fix above). `Modules\Core\Order\Filament\
|
||||||
|
Extensions\OrderActionsExtension` (renamed from `OrderRefundActionsExtension`, since it now
|
||||||
|
fixes both the refund and capture header actions — see below) now routes capture through
|
||||||
|
`Modules\Core\Payment\Support\TransactionDriverAdapter::capture()`, the same app-level path
|
||||||
|
checkout-time captures use.
|
||||||
|
- `Modules\Core\Payment\Drivers\StripePaymentDriver` never extracted a card's brand/last four
|
||||||
|
digits from Stripe's response, so `Lunar\Models\Transaction::card_type`/`last_four` were always
|
||||||
|
empty and the admin's "Payment of :amount on card ending :last_four" activity-log line rendered
|
||||||
|
with no digits — reproduced on both checkout-time and manual captures. Added
|
||||||
|
`cardMetaFromIntent()`, reading `payment_method_details` off the PaymentIntent's `latest_charge`
|
||||||
|
(same source `lunarphp/stripe`'s own `StoreCharges` uses), populated into `PaymentResult::$meta`
|
||||||
|
from `resultFromIntent()` and `capture()`. `Modules\Core\Order\Services\TransactionRecorder`
|
||||||
|
now maps `meta['card_type']`/`meta['last_four']` onto the `Transaction` row. Only applies to
|
||||||
|
transactions recorded after this change — existing rows are not backfilled.
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- `Modules\Core\Order\Filament\Extensions\OrderRefundActionsExtension` renamed to
|
||||||
|
`OrderActionsExtension` — the class now fixes both the refund and capture header actions on the
|
||||||
|
order page, not just refund, so the old name undersold its scope.
|
||||||
|
|
||||||
## [0.17.1] - 2026-09-15
|
## [0.17.1] - 2026-09-15
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- `Modules\Core\Payment\Drivers\StripePaymentDriver::createAndConfirm()` only set
|
- `Modules\Core\Payment\Drivers\StripePaymentDriver::createAndConfirm()` only set
|
||||||
`automatic_payment_methods` when no `payment_method` was given — the actual checkout flow always
|
`automatic_payment_methods` when no `payment_method` was given — the actual checkout flow always
|
||||||
sends one, so it was omitted, and Stripe fell back to whatever payment methods are enabled in the
|
sends one, so it was omitted, and Stripe fell back to whatever payment methods are enabled in the
|
||||||
@@ -18,6 +448,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
## [0.17.0] - 2026-09-14
|
## [0.17.0] - 2026-09-14
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Order\Notifications\OrderPlacedNotification` — an order confirmation email,
|
- `Modules\Core\Order\Notifications\OrderPlacedNotification` — an order confirmation email,
|
||||||
registered against `Modules\Core\Checkout\Events\OrderPlaced` (fires exactly once per order,
|
registered against `Modules\Core\Checkout\Events\OrderPlaced` (fires exactly once per order,
|
||||||
regardless of `capture_mode`/driver). Previously only a Stripe (auto-captured) order triggered
|
regardless of `capture_mode`/driver). Previously only a Stripe (auto-captured) order triggered
|
||||||
@@ -33,7 +464,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
`always`/`backorder` variants are deliberately left alone (their stock has no purchasing
|
`always`/`backorder` variants are deliberately left alone (their stock has no purchasing
|
||||||
consequence, decrementing it would just make the column an inaccurate negative number). Also
|
consequence, decrementing it would just make the column an inaccurate negative number). Also
|
||||||
re-triggers Scout reindexing for every affected product, closing the gap `Modules\Core\Catalog\
|
re-triggers Scout reindexing for every affected product, closing the gap `Modules\Core\Catalog\
|
||||||
Services\ProductIndexer`'s own docblock flagged ("nothing currently reindexes a product when an
|
Services\ProductIndexer`'s own docblock flagged ("nothing currently reindexes a product when an
|
||||||
order decrements its stock") — the search index's `in_stock` filter now reflects the change
|
order decrements its stock") — the search index's `in_stock` filter now reflects the change
|
||||||
immediately rather than only on the next scheduled reindex.
|
immediately rather than only on the next scheduled reindex.
|
||||||
- `Modules\Core\Cart\Services\CartLifecycleService` — the single source of truth for the four
|
- `Modules\Core\Cart\Services\CartLifecycleService` — the single source of truth for the four
|
||||||
@@ -78,12 +509,13 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
courier might not reconcile cash for weeks after an order is already marked completed.
|
courier might not reconcile cash for weeks after an order is already marked completed.
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|
||||||
- **Order status model, redesigned from scratch.** `Order.status` is a single column again
|
- **Order status model, redesigned from scratch.** `Order.status` is a single column again
|
||||||
(a same-session 3-axis `payment_status`/`fulfillment_status`/`return_status` design was built,
|
(a same-session 3-axis `payment_status`/`fulfillment_status`/`return_status` design was built,
|
||||||
then abandoned before shipping — three independent selects let staff set any combination with no
|
then abandoned before shipping — three independent selects let staff set any combination with no
|
||||||
cross-field validation, and didn't map onto how staff actually think about an order: one linear
|
cross-field validation, and didn't map onto how staff actually think about an order: one linear
|
||||||
journey, not three simultaneous dials). Now driven by `Modules\Core\Order\Services\
|
journey, not three simultaneous dials). Now driven by `Modules\Core\Order\Services\
|
||||||
OrderStatusFlow`, a pure transition-table service offering exactly two sequences — carrier and
|
OrderStatusFlow`, a pure transition-table service offering exactly two sequences — carrier and
|
||||||
store-pickup (`Order::isStorePickupOrder()`) — never four; payment method (prepaid vs. COD)
|
store-pickup (`Order::isStorePickupOrder()`) — never four; payment method (prepaid vs. COD)
|
||||||
affects `Order::paid` only, not which sequence an order follows or where it sits in it. The
|
affects `Order::paid` only, not which sequence an order follows or where it sits in it. The
|
||||||
Filament order page's several guided buttons are replaced by three header actions: "Update
|
Filament order page's several guided buttons are replaced by three header actions: "Update
|
||||||
@@ -132,14 +564,14 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
redirect a parcel to a different locker than the one the customer picked at checkout; it's only
|
redirect a parcel to a different locker than the one the customer picked at checkout; it's only
|
||||||
editable for the (current, checkout-UI-less) case where nothing set it yet.
|
editable for the (current, checkout-UI-less) case where nothing set it yet.
|
||||||
- New "Shipments" section on the order page (`Modules\Core\Shipping\Extensions\
|
- New "Shipments" section on the order page (`Modules\Core\Shipping\Extensions\
|
||||||
OrderShipmentsExtension`, between Transactions and Timeline) — "Create Shipment" previously had no
|
OrderShipmentsExtension`, between Transactions and Timeline) — "Create Shipment" previously had no
|
||||||
counterpart anywhere to actually see what it created. One entry per `Shipment` record (a multi-box
|
counterpart anywhere to actually see what it created. One entry per `Shipment` record (a multi-box
|
||||||
Box Now order shows one entry per parcel), rendered as two inline-labelled lines — carrier +
|
Box Now order shows one entry per parcel), rendered as two inline-labelled lines — carrier +
|
||||||
tracking reference, then status + a "Created … · Locker …" helper line — rather than a grid of
|
tracking reference, then status + a "Created … · Locker …" helper line — rather than a grid of
|
||||||
individually stacked label/value blocks, which reads as a wall of repeated labels once the admin's
|
individually stacked label/value blocks, which reads as a wall of repeated labels once the admin's
|
||||||
main content area narrows below Filament's own grid breakpoint (1024px, common with the sidebar
|
main content area narrows below Filament's own grid breakpoint (1024px, common with the sidebar
|
||||||
open). Two actions per shipment: "Print Label" and "Cancel". Also added `Modules\Core\Shipping\
|
open). Two actions per shipment: "Print Label" and "Cancel". Also added `Modules\Core\Shipping\
|
||||||
Http\Controllers\DownloadShipmentLabelController` (short-lived signed URL, same auth model as
|
Http\Controllers\DownloadShipmentLabelController` (short-lived signed URL, same auth model as
|
||||||
Lunar's own vendor order-PDF download) — the only other place that called
|
Lunar's own vendor order-PDF download) — the only other place that called
|
||||||
`CarrierFulfillmentInterface::printLabel()` (`ManagePickupManifests`' bulk "Print" action)
|
`CarrierFulfillmentInterface::printLabel()` (`ManagePickupManifests`' bulk "Print" action)
|
||||||
discarded the returned bytes entirely; this is the first place in the codebase that actually
|
discarded the returned bytes entirely; this is the first place in the codebase that actually
|
||||||
@@ -152,16 +584,16 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
plain `int $shipment` and looking the record up directly in the controller.
|
plain `int $shipment` and looking the record up directly in the controller.
|
||||||
- `Modules\Core\Shipping\Enums\TrackingStatus::Failed` — previously unused — is now wired to the
|
- `Modules\Core\Shipping\Enums\TrackingStatus::Failed` — previously unused — is now wired to the
|
||||||
new `delivery_failed` status via `Modules\Core\Order\Listeners\
|
new `delivery_failed` status via `Modules\Core\Order\Listeners\
|
||||||
MarkDeliveryFailedOnCarrierCheckpoint`, from which staff can retry dispatch or convert to a
|
MarkDeliveryFailedOnCarrierCheckpoint`, from which staff can retry dispatch or convert to a
|
||||||
return.
|
return.
|
||||||
- Fixed a separate, unrelated bug hit while testing the above: `Lunar\Shipping\Models\
|
- Fixed a separate, unrelated bug hit while testing the above: `Lunar\Shipping\Models\
|
||||||
ShippingMethod::macro('isStorePickup', ...)` silently never registered — `Lunar\Base\Traits\
|
ShippingMethod::macro('isStorePickup', ...)` silently never registered — `Lunar\Base\Traits\
|
||||||
HasModelExtending::__callStatic()` (used by every `Lunar\Base\BaseModel` subclass that doesn't
|
HasModelExtending::__callStatic()` (used by every `Lunar\Base\BaseModel` subclass that doesn't
|
||||||
declare its own `macro()`, `ShippingMethod` included) intercepts *every* unmatched static call
|
declare its own `macro()`, `ShippingMethod` included) intercepts _every_ unmatched static call
|
||||||
and dispatches it as an instance call instead of forwarding to `Macroable`, so `hasMacro()` always
|
and dispatches it as an instance call instead of forwarding to `Macroable`, so `hasMacro()` always
|
||||||
returned `false` and every order was silently treated as carrier-fulfilled — including store-pickup
|
returned `false` and every order was silently treated as carrier-fulfilled — including store-pickup
|
||||||
ones. `Order::isStorePickupOrder()` (the only caller) now reads `ShippingMethod.data
|
ones. `Order::isStorePickupOrder()` (the only caller) now reads `ShippingMethod.data
|
||||||
['fulfillment_type']` directly instead of going through the broken macro.
|
['fulfillment_type']` directly instead of going through the broken macro.
|
||||||
- `CartResource::getEloquentQuery()` no longer filters to carts with a known `user_id`/
|
- `CartResource::getEloquentQuery()` no longer filters to carts with a known `user_id`/
|
||||||
`customer_id` — every cart is now listed, guest carts included. Reverses an earlier deliberate
|
`customer_id` — every cart is now listed, guest carts included. Reverses an earlier deliberate
|
||||||
exclusion (an anonymous cart has nothing a staff member could click into — no name, no email),
|
exclusion (an anonymous cart has nothing a staff member could click into — no name, no email),
|
||||||
@@ -210,7 +642,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
broke the relation manager's Livewire component mount, surfacing as a CSRF-token 419 redirect
|
broke the relation manager's Livewire component mount, surfacing as a CSRF-token 419 redirect
|
||||||
loop specifically on `/boboko/manifests/{id}`.
|
loop specifically on `/boboko/manifests/{id}`.
|
||||||
- "Create Shipment"'s ACS branch gained a "Number of packages" field (`ShipmentRequest::
|
- "Create Shipment"'s ACS branch gained a "Number of packages" field (`ShipmentRequest::
|
||||||
$packageCount`, already plumbed through to ACS's `Item_Quantity`/`persistMultipartVouchers()` but
|
$packageCount`, already plumbed through to ACS's `Item_Quantity`/`persistMultipartVouchers()` but
|
||||||
never exposed in the form) — more than 1 issues a main voucher plus a multi-part sub-voucher per
|
never exposed in the form) — more than 1 issues a main voucher plus a multi-part sub-voucher per
|
||||||
extra package, each its own `Shipment` row sharing the same total weight. The existing weight
|
extra package, each its own `Shipment` row sharing the same total weight. The existing weight
|
||||||
field was relabeled "Total weight (kg)" to make explicit that ACS bills by one total shipment
|
field was relabeled "Total weight (kg)" to make explicit that ACS bills by one total shipment
|
||||||
@@ -219,6 +651,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
## [0.16.3] - 2026-09-10
|
## [0.16.3] - 2026-09-10
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- Stripe `createAndConfirm()` built its `PaymentIntent` params with
|
- Stripe `createAndConfirm()` built its `PaymentIntent` params with
|
||||||
`'automatic_payment_methods' => isset($data['payment_method']) ? null : ['enabled' => true]`. The
|
`'automatic_payment_methods' => isset($data['payment_method']) ? null : ['enabled' => true]`. The
|
||||||
Stripe PHP SDK does not omit `null`-valued params from `create()` — it serializes them to an empty
|
Stripe PHP SDK does not omit `null`-valued params from `create()` — it serializes them to an empty
|
||||||
@@ -227,7 +660,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
`payment_method` was supplied (i.e. every real charge in this flow). Fixed by building `$params`
|
`payment_method` was supplied (i.e. every real charge in this flow). Fixed by building `$params`
|
||||||
conditionally so the key is either omitted entirely or set to `['enabled' => true]`, never `null`.
|
conditionally so the key is either omitted entirely or set to `['enabled' => true]`, never `null`.
|
||||||
- `Modules\Core\Payment\Filament\Resources\PaymentMethodResource`'s "Driver status" column only
|
- `Modules\Core\Payment\Filament\Resources\PaymentMethodResource`'s "Driver status" column only
|
||||||
flagged a payment method whose driver *class* no longer resolves (`driver_missing_at`) — it gave
|
flagged a payment method whose driver _class_ no longer resolves (`driver_missing_at`) — it gave
|
||||||
no indication when a driver resolves fine but fails `Configurable::isConfigured()` (e.g. Stripe
|
no indication when a driver resolves fine but fails `Configurable::isConfigured()` (e.g. Stripe
|
||||||
enabled in the DB with no `services.stripe.key` set), which `CheckoutService::getPaymentMethods()`
|
enabled in the DB with no `services.stripe.key` set), which `CheckoutService::getPaymentMethods()`
|
||||||
filters out identically. An admin had no way to tell "this method is silently absent at checkout
|
filters out identically. An admin had no way to tell "this method is silently absent at checkout
|
||||||
@@ -258,7 +691,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
`Lunar\Managers\CartSessionManager` memoizes one `Cart` instance per request, so this was true on
|
`Lunar\Managers\CartSessionManager` memoizes one `Cart` instance per request, so this was true on
|
||||||
every request where the checkout page's initial render had already calculated the cart. The
|
every request where the checkout page's initial render had already calculated the cart. The
|
||||||
result: after switching payment methods, the just-saved `meta['payment_method']` change was
|
result: after switching payment methods, the just-saved `meta['payment_method']` change was
|
||||||
persisted, but the cart's totals silently kept reflecting whichever method was calculated *first*
|
persisted, but the cart's totals silently kept reflecting whichever method was calculated _first_
|
||||||
in the request — a shopper switching from Cash in Hand to Cash on Delivery would keep seeing Cash
|
in the request — a shopper switching from Cash in Hand to Cash on Delivery would keep seeing Cash
|
||||||
in Hand's total, with no COD fee applied, until something else forced a fresh calculation. Fixed
|
in Hand's total, with no COD fee applied, until something else forced a fresh calculation. Fixed
|
||||||
by calling `$cart->recalculate()` instead, which forces the pipeline to re-run.
|
by calling `$cart->recalculate()` instead, which forces the pipeline to re-run.
|
||||||
@@ -266,6 +699,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
## [0.16.2] - 2026-09-09
|
## [0.16.2] - 2026-09-09
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- `Lunar\Base\ShippingManifest` is a request-lifetime singleton whose `getOptions()` re-runs the
|
- `Lunar\Base\ShippingManifest` is a request-lifetime singleton whose `getOptions()` re-runs the
|
||||||
shipping modifier pipeline without ever clearing its `$options` collection first, and whose
|
shipping modifier pipeline without ever clearing its `$options` collection first, and whose
|
||||||
`addOption()` keeps the first entry per `getIdentifier()` and silently drops any later one. In
|
`addOption()` keeps the first entry per `getIdentifier()` and silently drops any later one. In
|
||||||
@@ -282,16 +716,18 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
## [0.16.1] - 2026-09-09
|
## [0.16.1] - 2026-09-09
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- OTP login page (`resources/views/auth/filament/pages/login.blade.php`) had no visible spacing
|
- OTP login page (`resources/views/auth/filament/pages/login.blade.php`) had no visible spacing
|
||||||
between the email/OTP input, error text, and buttons following the Filament v3 → v4 upgrade.
|
between the email/OTP input, error text, and buttons following the Filament v3 → v4 upgrade.
|
||||||
The view relied on a bare `grid gap-y-4` Tailwind utility class, but since this view ships from
|
The view relied on a bare `grid gap-y-4` Tailwind utility class, but since this view ships from
|
||||||
the `boboko-core` package rather than a consuming app, that class was never present in any
|
the `boboko-core` package rather than a consuming app, that class was never present in any
|
||||||
host app's compiled Tailwind output. Replaced with an inline `style` (flex column, `row-gap:
|
host app's compiled Tailwind output. Replaced with an inline `style` (flex column, `row-gap:
|
||||||
1rem`) so the layout no longer depends on the consuming app's Tailwind content scanning.
|
1rem`) so the layout no longer depends on the consuming app's Tailwind content scanning.
|
||||||
|
|
||||||
## [0.16.0] - 2026-09-08
|
## [0.16.0] - 2026-09-08
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Checkout\Services\CheckoutService::setRecoveryConsent(bool $consent): Cart` — the
|
- `Modules\Core\Checkout\Services\CheckoutService::setRecoveryConsent(bool $consent): Cart` — the
|
||||||
shopper's promotional/abandoned-cart-recovery opt-in, given once during guest checkout and
|
shopper's promotional/abandoned-cart-recovery opt-in, given once during guest checkout and
|
||||||
deliberately independent of `setShippingAddress()`/`setBillingAddress()`: consent is a
|
deliberately independent of `setShippingAddress()`/`setBillingAddress()`: consent is a
|
||||||
@@ -307,9 +743,9 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
`Modules\Core\Checkout\Events\RecoveryConsentSet`. Newsletter opt-in is explicitly a separate
|
`Modules\Core\Checkout\Events\RecoveryConsentSet`. Newsletter opt-in is explicitly a separate
|
||||||
scope — never merged into this flag.
|
scope — never merged into this flag.
|
||||||
- `Modules\Core\Checkout\Services\CheckoutService::initiatePayment()` now requires `bool
|
- `Modules\Core\Checkout\Services\CheckoutService::initiatePayment()` now requires `bool
|
||||||
$termsAccepted` and `string $policyVersion` as mandatory parameters (not optional data a caller
|
$termsAccepted` and `string $policyVersion` as mandatory parameters (not optional data a caller
|
||||||
might omit) — throws the new `Modules\Core\Checkout\Exceptions\TermsNotAcceptedException`
|
might omit) — throws the new `Modules\Core\Checkout\Exceptions\TermsNotAcceptedException`
|
||||||
*before* `Cart::createOrder()` is ever called if `$termsAccepted` is `false`, so an order can
|
_before_ `Cart::createOrder()` is ever called if `$termsAccepted` is `false`, so an order can
|
||||||
never exist without a recorded acceptance (refused, not created-then-flagged). On success,
|
never exist without a recorded acceptance (refused, not created-then-flagged). On success,
|
||||||
writes `terms_accepted` (`true`), `terms_accepted_at` (ISO 8601), and
|
writes `terms_accepted` (`true`), `terms_accepted_at` (ISO 8601), and
|
||||||
`terms_accepted_policy_version` onto the created `Order`'s own `meta` — the durable,
|
`terms_accepted_policy_version` onto the created `Order`'s own `meta` — the durable,
|
||||||
@@ -330,6 +766,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
## [0.15.0] - 2026-09-07
|
## [0.15.0] - 2026-09-07
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|
||||||
- **Breaking:** `Modules\Core\Payment\Models\PaymentMethod` is now the full DB-instance layer for
|
- **Breaking:** `Modules\Core\Payment\Models\PaymentMethod` is now the full DB-instance layer for
|
||||||
Payment, same three-layer split (registry / DB instance / cross-cutting config) `Shipping`
|
Payment, same three-layer split (registry / DB instance / cross-cutting config) `Shipping`
|
||||||
already has via `ShippingMethod` — see `docs/payments.md`. Every value that used to live in
|
already has via `ShippingMethod` — see `docs/payments.md`. Every value that used to live in
|
||||||
@@ -339,13 +776,13 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
(admin-facing label, nothing played this role before), `capture_mode`, `captured_status`,
|
(admin-facing label, nothing played this role before), `capture_mode`, `captured_status`,
|
||||||
`authorized_status`, `position` (admin-controlled ordering, new — reorderable in the Filament
|
`authorized_status`, `position` (admin-controlled ordering, new — reorderable in the Filament
|
||||||
table), `driver_missing_at`. `config('lunar.payments.types')` is gone entirely; `config/
|
table), `driver_missing_at`. `config('lunar.payments.types')` is gone entirely; `config/
|
||||||
payment.php` now holds only `cart_pipeline` (genuinely cross-cutting — every store gets the
|
payment.php` now holds only `cart_pipeline` (genuinely cross-cutting — every store gets the
|
||||||
same pipeline wiring regardless of how many payment methods it configures).
|
same pipeline wiring regardless of how many payment methods it configures).
|
||||||
- **Breaking:** `Modules\Core\Payment\Services\PaymentDriverResolver` is deleted, replaced by
|
- **Breaking:** `Modules\Core\Payment\Services\PaymentDriverResolver` is deleted, replaced by
|
||||||
`Modules\Core\Payment\Services\PaymentDriverRegistry` — `register(string $key, string
|
`Modules\Core\Payment\Services\PaymentDriverRegistry` — `register(string $key, string
|
||||||
$driverClass)`/`resolve(string $key): ?object`/`all(): array<string, string>`. Deliberately
|
$driverClass)`/`resolve(string $key): ?object`/`all(): array<string, string>`. Deliberately
|
||||||
knows nothing about `PaymentMethod` or the database (mirrors `Lunar\Shipping\Managers\
|
knows nothing about `PaymentMethod` or the database (mirrors `Lunar\Shipping\Managers\
|
||||||
ShippingManager`'s built-in-methods + `Manager::extend()` split, purpose-built rather than
|
ShippingManager`'s built-in-methods + `Manager::extend()` split, purpose-built rather than
|
||||||
extending `Illuminate\Support\Manager` — Payment's drivers implement several independent
|
extending `Illuminate\Support\Manager` — Payment's drivers implement several independent
|
||||||
capability interfaces at once, not one uniform contract). Built-ins (`OfflinePaymentDriver`
|
capability interfaces at once, not one uniform contract). Built-ins (`OfflinePaymentDriver`
|
||||||
as `'offline'`, `StripePaymentDriver` as `'stripe'`) registered in
|
as `'offline'`, `StripePaymentDriver` as `'stripe'`) registered in
|
||||||
@@ -374,6 +811,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
should be called; that's a merchant decision). Skip-if-exists, same as before.
|
should be called; that's a merchant decision). Skip-if-exists, same as before.
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `php artisan boboko:payment:sync-drivers` — reconciles every `PaymentMethod` row's `driver`
|
- `php artisan boboko:payment:sync-drivers` — reconciles every `PaymentMethod` row's `driver`
|
||||||
against `PaymentDriverRegistry`, setting `driver_missing_at` when a driver no longer resolves
|
against `PaymentDriverRegistry`, setting `driver_missing_at` when a driver no longer resolves
|
||||||
(a package removed, a custom `register()` call deleted) and clearing it automatically if that
|
(a package removed, a custom `register()` call deleted) and clearing it automatically if that
|
||||||
@@ -404,9 +842,9 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
- `Modules\Core\Payment\Models\CoreTransaction` (a `Lunar\Models\Transaction` subclass) +
|
- `Modules\Core\Payment\Models\CoreTransaction` (a `Lunar\Models\Transaction` subclass) +
|
||||||
`Modules\Core\Payment\Support\TransactionDriverAdapter`, registered via
|
`Modules\Core\Payment\Support\TransactionDriverAdapter`, registered via
|
||||||
`Lunar\Facades\ModelManifest::replace(Lunar\Models\Contracts\Transaction::class,
|
`Lunar\Facades\ModelManifest::replace(Lunar\Models\Contracts\Transaction::class,
|
||||||
CoreTransaction::class)` — the same contract-swap mechanism already used elsewhere for
|
CoreTransaction::class)` — the same contract-swap mechanism already used elsewhere for
|
||||||
`Customer`/`Staff`. Fixes a real crash (`InvalidArgumentException: Driver [cash-on-delivery] not
|
`Customer`/`Staff`. Fixes a real crash (`InvalidArgumentException: Driver [cash-on-delivery] not
|
||||||
supported`) the first time anything called `$transaction->refund()`/`->capture()`:
|
supported`) the first time anything called `$transaction->refund()`/`->capture()`:
|
||||||
`Lunar\Models\Transaction::driver()` calls Lunar's own, entirely separate
|
`Lunar\Models\Transaction::driver()` calls Lunar's own, entirely separate
|
||||||
`Lunar\Facades\Payments::driver()` manager, which had never heard of any of this codebase's
|
`Lunar\Facades\Payments::driver()` manager, which had never heard of any of this codebase's
|
||||||
driver keys. `CoreTransaction::driver()` returns `TransactionDriverAdapter` instead, which
|
driver keys. `CoreTransaction::driver()` returns `TransactionDriverAdapter` instead, which
|
||||||
@@ -415,7 +853,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
system underneath, including correctly reporting failure (not a silently-faked success) when
|
system underneath, including correctly reporting failure (not a silently-faked success) when
|
||||||
the resolved driver doesn't implement `SupportsRefunds`/`SupportsCaptures`.
|
the resolved driver doesn't implement `SupportsRefunds`/`SupportsCaptures`.
|
||||||
- `TransactionDriverAdapter::refundVia(Transaction $transaction, ?string $driverKey, int $amount,
|
- `TransactionDriverAdapter::refundVia(Transaction $transaction, ?string $driverKey, int $amount,
|
||||||
?string $notes = null)` — refund through an explicitly chosen driver, independent of the one
|
?string $notes = null)` — refund through an explicitly chosen driver, independent of the one
|
||||||
the original payment went through (e.g. a cash-on-delivery order refunded via Bank Transfer,
|
the original payment went through (e.g. a cash-on-delivery order refunded via Bank Transfer,
|
||||||
which has no notion of the original offline payment at all). The order page's refund action
|
which has no notion of the original offline payment at all). The order page's refund action
|
||||||
gained a "Refund via" `Select` (every `PaymentDriverRegistry` driver implementing
|
gained a "Refund via" `Select` (every `PaymentDriverRegistry` driver implementing
|
||||||
@@ -450,18 +888,19 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
- New `payment_methods.refunded_status` column + form field (same `Select` pattern as
|
- New `payment_methods.refunded_status` column + form field (same `Select` pattern as
|
||||||
`captured_status`/`authorized_status`) — `ApplyResolvedPaymentStatus` now also reacts to
|
`captured_status`/`authorized_status`) — `ApplyResolvedPaymentStatus` now also reacts to
|
||||||
`PaymentRefunded`, so `Order.status` actually changes on a refund; before this, only the
|
`PaymentRefunded`, so `Order.status` actually changes on a refund; before this, only the
|
||||||
*derived* `Order::paymentStatus()` reflected a refund (reading `transactions` live), while the
|
_derived_ `Order::paymentStatus()` reflected a refund (reading `transactions` live), while the
|
||||||
stored `status` column — what admin filtering, customer emails, etc. actually key off — never
|
stored `status` column — what admin filtering, customer emails, etc. actually key off — never
|
||||||
moved. Resolves the ORIGINAL payment method for this lookup, not the refund event's own
|
moved. Resolves the ORIGINAL payment method for this lookup, not the refund event's own
|
||||||
`$type`: a refund routed through a different driver via `refundVia()` (e.g. cash-on-delivery
|
`$type`: a refund routed through a different driver via `refundVia()` (e.g. cash-on-delivery
|
||||||
refunded through Bank Transfer) carries the REFUND driver's registry key as `$event->type`,
|
refunded through Bank Transfer) carries the REFUND driver's registry key as `$event->type`,
|
||||||
which usually isn't even a real `PaymentMethod.type` — the listener now finds the order's
|
which usually isn't even a real `PaymentMethod.type` — the listener now finds the order's
|
||||||
earliest successful `capture`/`intent` transaction instead and reads `refunded_status` off
|
earliest successful `capture`/`intent` transaction instead and reads `refunded_status` off
|
||||||
*that* transaction's own `PaymentMethod` row, since that's the payment the refund is actually
|
_that_ transaction's own `PaymentMethod` row, since that's the payment the refund is actually
|
||||||
reversing. Deliberately no `void_status` yet — a void never moved money, so it doesn't carry
|
reversing. Deliberately no `void_status` yet — a void never moved money, so it doesn't carry
|
||||||
the same "the customer needs to see this changed" weight a refund does.
|
the same "the customer needs to see this changed" weight a refund does.
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- Existing `PaymentMethod` rows seeded before this release (`cash-on-delivery`, `cash-in-hand`)
|
- Existing `PaymentMethod` rows seeded before this release (`cash-on-delivery`, `cash-in-hand`)
|
||||||
had `driver`/`capture_mode`/`captured_status` all `NULL` after the migration ran — a data
|
had `driver`/`capture_mode`/`captured_status` all `NULL` after the migration ran — a data
|
||||||
backfill was required (not automated by the migration itself) to restore them to a resolvable
|
backfill was required (not automated by the migration itself) to restore them to a resolvable
|
||||||
@@ -489,15 +928,18 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
## [0.14.0] - 2026-09-03
|
## [0.14.0] - 2026-09-03
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|
||||||
- **Breaking:** `Modules\Core\Catalog\Services\ProductSearchService::search()` now returns `Modules\Core\Catalog\DTOs\ProductListingResult` — the exact same shape `ProductService::list()` already returns — instead of a bare `Illuminate\Database\Eloquent\Collection<Product>` of hydrated models with no pagination at all. New signature: `search(string $query, ?ProductFilters $filters = null, ?ProductSort $sort = null, int $perPage = 24, int $page = 1): ProductListingResult`. `->products` is a real `LengthAwarePaginator` of plain, localized indexed-document arrays (not Eloquent models, not Scout's raw response) — a search results page and a category listing page are now interchangeable from a controller's perspective: same DTO, same `ProductCard::fromIndexed()` mapping, same pagination/sort/tag/price-slider handling. `->priceBounds`/`->availableTags` are scoped to the search query itself (delegated to `ProductService::priceSliderBounds()`/`availableTags()`, both of which already accepted a `$query` param for this).
|
- **Breaking:** `Modules\Core\Catalog\Services\ProductSearchService::search()` now returns `Modules\Core\Catalog\DTOs\ProductListingResult` — the exact same shape `ProductService::list()` already returns — instead of a bare `Illuminate\Database\Eloquent\Collection<Product>` of hydrated models with no pagination at all. New signature: `search(string $query, ?ProductFilters $filters = null, ?ProductSort $sort = null, int $perPage = 24, int $page = 1): ProductListingResult`. `->products` is a real `LengthAwarePaginator` of plain, localized indexed-document arrays (not Eloquent models, not Scout's raw response) — a search results page and a category listing page are now interchangeable from a controller's perspective: same DTO, same `ProductCard::fromIndexed()` mapping, same pagination/sort/tag/price-slider handling. `->priceBounds`/`->availableTags` are scoped to the search query itself (delegated to `ProductService::priceSliderBounds()`/`availableTags()`, both of which already accepted a `$query` param for this).
|
||||||
- `Modules\Core\Catalog\Services\ProductService::availableTags()` is now `public` (was `private`) and takes an optional `$query` parameter, so `ProductSearchService::search()` can reuse it directly instead of reimplementing the same facet call.
|
- `Modules\Core\Catalog\Services\ProductService::availableTags()` is now `public` (was `private`) and takes an optional `$query` parameter, so `ProductSearchService::search()` can reuse it directly instead of reimplementing the same facet call.
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Catalog\Support\ProductDocumentLocalizer` — the per-locale field resolution and raw-Meilisearch-response unwrapping (`withLocalizedFields()`, `hitsFrom()`) extracted out of `ProductService` into its own class, since `ProductSearchService` needed the exact same logic against the exact same kind of document. Both services now depend on this one class instead of `ProductService` owning logic a second service also needed.
|
- `Modules\Core\Catalog\Support\ProductDocumentLocalizer` — the per-locale field resolution and raw-Meilisearch-response unwrapping (`withLocalizedFields()`, `hitsFrom()`) extracted out of `ProductService` into its own class, since `ProductSearchService` needed the exact same logic against the exact same kind of document. Both services now depend on this one class instead of `ProductService` owning logic a second service also needed.
|
||||||
|
|
||||||
## [0.13.0] - 2026-09-03
|
## [0.13.0] - 2026-09-03
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|
||||||
- **Breaking:** `Payment` is now a genuinely standalone module — no direct calls into `Checkout`/`Order`, no reaching into their Eloquent models, communication only via events. The entire old `confirm()`-based flow is gone: `Modules\Core\Payment\Contracts\PaymentDriver` (and the already-stale `Modules\Core\Checkout\Contracts\PaymentDriver` duplicate), `Checkout\Events\PaymentConfirmed`, `Payment\Contracts\InitiatesPayment`, `Payment\DataTransferObjects\PaymentInitiation`, `Payment\Enums\PaymentInitiationMode`, `Payment\Events\PaymentSucceeded`/`PaymentFailed`, `Payment\Events\OrderPaymentStatusResolved`, and `Payment\Exceptions\PaymentNotConfirmedException` are all deleted. This flow was non-functional on `master` before this release — `CheckoutService::confirmPayment()` dispatched an event nothing listened for, so no order was ever placed after payment.
|
- **Breaking:** `Payment` is now a genuinely standalone module — no direct calls into `Checkout`/`Order`, no reaching into their Eloquent models, communication only via events. The entire old `confirm()`-based flow is gone: `Modules\Core\Payment\Contracts\PaymentDriver` (and the already-stale `Modules\Core\Checkout\Contracts\PaymentDriver` duplicate), `Checkout\Events\PaymentConfirmed`, `Payment\Contracts\InitiatesPayment`, `Payment\DataTransferObjects\PaymentInitiation`, `Payment\Enums\PaymentInitiationMode`, `Payment\Events\PaymentSucceeded`/`PaymentFailed`, `Payment\Events\OrderPaymentStatusResolved`, and `Payment\Exceptions\PaymentNotConfirmedException` are all deleted. This flow was non-functional on `master` before this release — `CheckoutService::confirmPayment()` dispatched an event nothing listened for, so no order was ever placed after payment.
|
||||||
- **Breaking:** Every payment operation is now its own explicit, opt-in contract, modeled on how real gateways (Stripe, Mastercard's own gateway, Nexi) actually split these operations — see `docs/payments.md`: `Modules\Core\Payment\Contracts\SupportsPay` (atomic authorize+capture), `SupportsAuthorization` (hold only), `SupportsCaptures` (settle a prior hold), `SupportsVoids` (release a prior hold without settling), `SupportsRefunds` (reverse settled funds), `HandlesPaymentCallback` (resolve an async pay()/authorize() later, from a webhook), and `Configurable` (`isConfigured()`, split out of the old single `PaymentDriver` interface). A driver implements only the operations its gateway actually supports.
|
- **Breaking:** Every payment operation is now its own explicit, opt-in contract, modeled on how real gateways (Stripe, Mastercard's own gateway, Nexi) actually split these operations — see `docs/payments.md`: `Modules\Core\Payment\Contracts\SupportsPay` (atomic authorize+capture), `SupportsAuthorization` (hold only), `SupportsCaptures` (settle a prior hold), `SupportsVoids` (release a prior hold without settling), `SupportsRefunds` (reverse settled funds), `HandlesPaymentCallback` (resolve an async pay()/authorize() later, from a webhook), and `Configurable` (`isConfigured()`, split out of the old single `PaymentDriver` interface). A driver implements only the operations its gateway actually supports.
|
||||||
- **Breaking:** Every amount flowing through these contracts is `Lunar\DataTypes\Price` (Lunar's own bundled minor-unit-value + `Currency` type) — never a bare `int` paired separately with a `Currency`. Each driver converts at its own boundary (e.g. `StripeManager::toStripeAmount()`/`fromStripeAmount()`); `Payment` itself only ever speaks Lunar's `Price`.
|
- **Breaking:** Every amount flowing through these contracts is `Lunar\DataTypes\Price` (Lunar's own bundled minor-unit-value + `Currency` type) — never a bare `int` paired separately with a `Currency`. Each driver converts at its own boundary (e.g. `StripeManager::toStripeAmount()`/`fromStripeAmount()`); `Payment` itself only ever speaks Lunar's `Price`.
|
||||||
@@ -506,6 +948,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
- `config/payment.php`'s `cash-on-delivery` entry gains `capture_mode` (`'pay'`, since `OfflinePaymentDriver` only implements `SupportsPay`) and `captured_status` (`'payment-offline'`, replacing the previously dead `'authorized' => 'awaiting-payment'` key, which nothing ever read).
|
- `config/payment.php`'s `cash-on-delivery` entry gains `capture_mode` (`'pay'`, since `OfflinePaymentDriver` only implements `SupportsPay`) and `captured_status` (`'payment-offline'`, replacing the previously dead `'authorized' => 'awaiting-payment'` key, which nothing ever read).
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Payment\DTOs\PaymentResult` — the one return shape every operation (`pay`, `authorize`, `capture`, `void`, `refund`, `handleCallback`) produces, regardless of gateway: `status` (`Modules\Core\Payment\Enums\PaymentResultStatus`: `Succeeded`/`Failed`/`Pending`), `reference`, `amount` (a `Price`), `failureReason`, `retriable` (real on Stripe/Mastercard's own soft-decline classification, always `false` on Nexi — it has no such signal), `raw` (the untouched gateway response, for audit), `meta`, and `continuation` (see below).
|
- `Modules\Core\Payment\DTOs\PaymentResult` — the one return shape every operation (`pay`, `authorize`, `capture`, `void`, `refund`, `handleCallback`) produces, regardless of gateway: `status` (`Modules\Core\Payment\Enums\PaymentResultStatus`: `Succeeded`/`Failed`/`Pending`), `reference`, `amount` (a `Price`), `failureReason`, `retriable` (real on Stripe/Mastercard's own soft-decline classification, always `false` on Nexi — it has no such signal), `raw` (the untouched gateway response, for audit), `meta`, and `continuation` (see below).
|
||||||
- `Modules\Core\Payment\DTOs\PaymentContinuation` / `Modules\Core\Payment\Enums\PaymentContinuationType` — what a caller does next with a `Pending` `PaymentResult`, gateway-agnostically (`Redirect` or `ClientSecret`), so a storefront controller never needs gateway-specific knowledge of e.g. Stripe's own `PaymentIntent` fields to drive a 3-D Secure/redirect continuation.
|
- `Modules\Core\Payment\DTOs\PaymentContinuation` / `Modules\Core\Payment\Enums\PaymentContinuationType` — what a caller does next with a `Pending` `PaymentResult`, gateway-agnostically (`Redirect` or `ClientSecret`), so a storefront controller never needs gateway-specific knowledge of e.g. Stripe's own `PaymentIntent` fields to drive a 3-D Secure/redirect continuation.
|
||||||
- Eight new events, one terminal pair per operation, replacing the old single `PaymentSucceeded`/`PaymentFailed`: `PaymentAuthorized`/`PaymentAuthorizationFailed`, `PaymentCaptured`/`PaymentCaptureFailed`, `PaymentVoided`/`PaymentVoidFailed`, `PaymentRefunded`/`PaymentRefundFailed`. `PaymentCaptured` is deliberately the same event whether money was taken via `pay()` (one gateway call) or `authorize()`→`capture()` (two calls) — "a payment has been captured" is the same business fact either way. Every event carries `{type, result: PaymentResult, context}` — `context` is an opaque bag the caller hands in and gets back untouched, so `Payment` never needs to know what a `Cart` or `Order` is.
|
- Eight new events, one terminal pair per operation, replacing the old single `PaymentSucceeded`/`PaymentFailed`: `PaymentAuthorized`/`PaymentAuthorizationFailed`, `PaymentCaptured`/`PaymentCaptureFailed`, `PaymentVoided`/`PaymentVoidFailed`, `PaymentRefunded`/`PaymentRefundFailed`. `PaymentCaptured` is deliberately the same event whether money was taken via `pay()` (one gateway call) or `authorize()`→`capture()` (two calls) — "a payment has been captured" is the same business fact either way. Every event carries `{type, result: PaymentResult, context}` — `context` is an opaque bag the caller hands in and gets back untouched, so `Payment` never needs to know what a `Cart` or `Order` is.
|
||||||
@@ -515,22 +958,26 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
- `docs/payments.md` — full design notes: the operation/contract table cross-referenced against Mastercard/Stripe/Nexi's real APIs, why `PaymentResult` normalizes only what every gateway can always provide, the async-correlation pattern, and what's explicitly out of scope (a `Transaction`-writing listener, the `stripe` config entry, frontend Stripe Elements integration).
|
- `docs/payments.md` — full design notes: the operation/contract table cross-referenced against Mastercard/Stripe/Nexi's real APIs, why `PaymentResult` normalizes only what every gateway can always provide, the async-correlation pattern, and what's explicitly out of scope (a `Transaction`-writing listener, the `stripe` config entry, frontend Stripe Elements integration).
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- `Modules\Core\Checkout\Services\CheckoutService::selectPaymentMethod()` crashed (`Call to a member function toArray() on null`) the first time it ran against a cart whose `meta` column was still a genuine SQL `NULL` (any freshly-created cart) — `Cart::$meta`'s `AsArrayObject` cast returns `null`, not an empty array-like object, for a `null` column. Fixed with a null-safe fallback.
|
- `Modules\Core\Checkout\Services\CheckoutService::selectPaymentMethod()` crashed (`Call to a member function toArray() on null`) the first time it ran against a cart whose `meta` column was still a genuine SQL `NULL` (any freshly-created cart) — `Cart::$meta`'s `AsArrayObject` cast returns `null`, not an empty array-like object, for a `null` column. Fixed with a null-safe fallback.
|
||||||
- `Modules\Core\Shipping\Carriers\Acs\AcsRateDriver`/`BoxNowRateDriver` referenced `Lunar\Shipping\DTOs\ShippingOptionRequest`, a namespace that doesn't exist in the installed `lunarphp/table-rate-shipping` version (the real class is `Lunar\Shipping\DataTransferObjects\ShippingOptionRequest`) — crashed `Illuminate\Support\Manager`'s interface-compatibility check the moment anything touched `ShippingManager::getSupportedDrivers()`, including simply adding a line to a cart (via `Modules\Core\Shipping\Listeners\FlushLivePricingCache`).
|
- `Modules\Core\Shipping\Carriers\Acs\AcsRateDriver`/`BoxNowRateDriver` referenced `Lunar\Shipping\DTOs\ShippingOptionRequest`, a namespace that doesn't exist in the installed `lunarphp/table-rate-shipping` version (the real class is `Lunar\Shipping\DataTransferObjects\ShippingOptionRequest`) — crashed `Illuminate\Support\Manager`'s interface-compatibility check the moment anything touched `ShippingManager::getSupportedDrivers()`, including simply adding a line to a cart (via `Modules\Core\Shipping\Listeners\FlushLivePricingCache`).
|
||||||
|
|
||||||
## [0.13.1] - 2026-09-03
|
## [0.13.1] - 2026-09-03
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Order\Listeners\RecordPaymentTransaction` — writes the `lunar_transactions` row for a successful `PaymentCaptured`/`PaymentAuthorized`/`PaymentVoided`/`PaymentRefunded` event, via a new `Modules\Core\Order\Services\TransactionRecorder` (moved here from `Payment\Services`, and rewritten to take a `PaymentResult` directly instead of the deleted `CaptureResult`/`RefundResult` DTOs — `Payment` never writes to `Order`'s models, `Transaction.order_id` being required is exactly why this lives in `Order`, same reasoning as `ApplyResolvedPaymentStatus`). Closes a real gap introduced in `0.13.0`: `Order::paymentStatus()` (which derives its answer entirely from `$order->transactions`) always resolved to `PaymentStatus::Offline` — its "no transactions at all" fallback — regardless of what actually happened, since nothing had ever written a row. Verified live: a captured offline payment now produces a `type: capture` transaction and `Order::paymentStatus()` correctly resolves to `captured`.
|
- `Modules\Core\Order\Listeners\RecordPaymentTransaction` — writes the `lunar_transactions` row for a successful `PaymentCaptured`/`PaymentAuthorized`/`PaymentVoided`/`PaymentRefunded` event, via a new `Modules\Core\Order\Services\TransactionRecorder` (moved here from `Payment\Services`, and rewritten to take a `PaymentResult` directly instead of the deleted `CaptureResult`/`RefundResult` DTOs — `Payment` never writes to `Order`'s models, `Transaction.order_id` being required is exactly why this lives in `Order`, same reasoning as `ApplyResolvedPaymentStatus`). Closes a real gap introduced in `0.13.0`: `Order::paymentStatus()` (which derives its answer entirely from `$order->transactions`) always resolved to `PaymentStatus::Offline` — its "no transactions at all" fallback — regardless of what actually happened, since nothing had ever written a row. Verified live: a captured offline payment now produces a `type: capture` transaction and `Order::paymentStatus()` correctly resolves to `captured`.
|
||||||
|
|
||||||
## [0.12.1] - 2026-09-03
|
## [0.12.1] - 2026-09-03
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- `Modules\Core\MigrateImport\Shopify\ShopifyExportImporter` now attaches a variant's `Variant Image` CSV column to that `ProductVariant`'s own `images()` media pivot (`media_product_variant`, `primary`/`position`). Previously the variant image was never read at all — every image from the CSV, including ones the export clearly scopes to one specific variant, went only into the product's own top-level gallery, so a variant swatch/option change had no way to show its own photo.
|
- `Modules\Core\MigrateImport\Shopify\ShopifyExportImporter` now attaches a variant's `Variant Image` CSV column to that `ProductVariant`'s own `images()` media pivot (`media_product_variant`, `primary`/`position`). Previously the variant image was never read at all — every image from the CSV, including ones the export clearly scopes to one specific variant, went only into the product's own top-level gallery, so a variant swatch/option change had no way to show its own photo.
|
||||||
- `Modules\Core\MigrateImport\Shopify\Resolvers\ProductOptionResolver::resolveOption()` now sets `label` (same value as `name`) when creating a `Lunar\Models\ProductOption`, not just `name`. A `ProductOption` with a null `label` crashes Lunar's own `ProductOptionIndexer::toSearchableArray()` (`foreach()` on `null`) the moment that option gets reindexed — every option created by the importer before this fix has a null `label` and needs a wipe-and-reimport (see `docs/shopify-reimport.md`, new in this release) to pick up the fix, since `firstOrCreate()` never revisits an already-existing row.
|
- `Modules\Core\MigrateImport\Shopify\Resolvers\ProductOptionResolver::resolveOption()` now sets `label` (same value as `name`) when creating a `Lunar\Models\ProductOption`, not just `name`. A `ProductOption` with a null `label` crashes Lunar's own `ProductOptionIndexer::toSearchableArray()` (`foreach()` on `null`) the moment that option gets reindexed — every option created by the importer before this fix has a null `label` and needs a wipe-and-reimport (see `docs/shopify-reimport.md`, new in this release) to pick up the fix, since `firstOrCreate()` never revisits an already-existing row.
|
||||||
- `product_reviews.product_id`'s foreign key had no `ON DELETE` clause, so deleting a reviewed `Product` threw a constraint violation instead of the review going with it, unlike every other product-dependent table. New migration adds `cascadeOnDelete()`.
|
- `product_reviews.product_id`'s foreign key had no `ON DELETE` clause, so deleting a reviewed `Product` threw a constraint violation instead of the review going with it, unlike every other product-dependent table. New migration adds `cascadeOnDelete()`.
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Catalog\Services\ProductIndexer::mapVariant()` now embeds `gtin`, `mpn`, `ean`, `backorder`, `unit_quantity`, `shippable`, `tax_ref`, and `dimensions` (length/width/height/weight/volume, each with `value`+`unit`) on every indexed variant — previously only `id`/`sku`/`stock`/`purchasable`/`options`/`prices`/`media` were embedded, so a search result or filter needing any of these had no way to get at them without a separate Postgres query per variant.
|
- `Modules\Core\Catalog\Services\ProductIndexer::mapVariant()` now embeds `gtin`, `mpn`, `ean`, `backorder`, `unit_quantity`, `shippable`, `tax_ref`, and `dimensions` (length/width/height/weight/volume, each with `value`+`unit`) on every indexed variant — previously only `id`/`sku`/`stock`/`purchasable`/`options`/`prices`/`media` were embedded, so a search result or filter needing any of these had no way to get at them without a separate Postgres query per variant.
|
||||||
- `ProductIndexer::toSearchableArray()` adds a top-level, filterable `skus` field (every variant's SKU, deduplicated) — filtering/matching by SKU no longer requires reaching into the nested `variants` array.
|
- `ProductIndexer::toSearchableArray()` adds a top-level, filterable `skus` field (every variant's SKU, deduplicated) — filtering/matching by SKU no longer requires reaching into the nested `variants` array.
|
||||||
- `docs/shopify-reimport.md` — runbook for wiping every imported product (cascading through Lunar so Meilisearch documents go too) and re-running the importer from scratch, needed whenever a fix like the two above only takes effect on newly-created rows.
|
- `docs/shopify-reimport.md` — runbook for wiping every imported product (cascading through Lunar so Meilisearch documents go too) and re-running the importer from scratch, needed whenever a fix like the two above only takes effect on newly-created rows.
|
||||||
@@ -538,12 +985,14 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
## [0.12.0] - 2026-09-03
|
## [0.12.0] - 2026-09-03
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|
||||||
- **Breaking:** `Modules\Core\Catalog\Services\ProductService::list()` now returns `Modules\Core\Catalog\DTOs\ProductListingResult` (`->products`: the same `Illuminate\Pagination\LengthAwarePaginator` as before, `->priceBounds`: a new `Modules\Core\Catalog\DTOs\PriceSliderBounds`) instead of returning the paginator directly. A caller doing `$service->list(...)->items()`/`->through(...)` must update to `$service->list(...)->products->items()`/`->through(...)`. This collapses what used to be two separate calls a controller had to orchestrate itself (`list()` for products, `priceRange()` + manual floor/ceil/"is this actually filtered" math for the slider) into one.
|
- **Breaking:** `Modules\Core\Catalog\Services\ProductService::list()` now returns `Modules\Core\Catalog\DTOs\ProductListingResult` (`->products`: the same `Illuminate\Pagination\LengthAwarePaginator` as before, `->priceBounds`: a new `Modules\Core\Catalog\DTOs\PriceSliderBounds`) instead of returning the paginator directly. A caller doing `$service->list(...)->items()`/`->through(...)` must update to `$service->list(...)->products->items()`/`->through(...)`. This collapses what used to be two separate calls a controller had to orchestrate itself (`list()` for products, `priceRange()` + manual floor/ceil/"is this actually filtered" math for the slider) into one.
|
||||||
- **Breaking:** `Modules\Core\Catalog\Services\ProductSearchService::search()`'s signature changed from `search(string $query, ?string $locale = null)` to `search(string $query, ?ProductFilters $filters = null, ?ProductSort $sort = null)` — the `$locale` parameter is gone (see "every configured language, always" below); `$filters`/`$sort` apply the same `Modules\Core\Catalog\Support\ProductFilterBuilder`/`ProductSort::toMeilisearchSort()` semantics `ProductService::list()` already used, so a text search can now be narrowed by price/brand/stock and sorted the same way a category listing can.
|
- **Breaking:** `Modules\Core\Catalog\Services\ProductSearchService::search()`'s signature changed from `search(string $query, ?string $locale = null)` to `search(string $query, ?ProductFilters $filters = null, ?ProductSort $sort = null)` — the `$locale` parameter is gone (see "every configured language, always" below); `$filters`/`$sort` apply the same `Modules\Core\Catalog\Support\ProductFilterBuilder`/`ProductSort::toMeilisearchSort()` semantics `ProductService::list()` already used, so a text search can now be narrowed by price/brand/stock and sorted the same way a category listing can.
|
||||||
- `ProductSearchService` now targets every configured store language's fields on every search (`Lunar\Models\Language::all()`), not just the current request locale plus the store's default language. The old `{current, default}` pairing silently stopped catching anything outside those two locales whenever they were equal (a single-language store, or a shopper browsing in the default language) — always searching every configured language closes that gap in both directions. See `docs/product-search.md`.
|
- `ProductSearchService` now targets every configured store language's fields on every search (`Lunar\Models\Language::all()`), not just the current request locale plus the store's default language. The old `{current, default}` pairing silently stopped catching anything outside those two locales whenever they were equal (a single-language store, or a shopper browsing in the default language) — always searching every configured language closes that gap in both directions. See `docs/product-search.md`.
|
||||||
- Extracted `Modules\Core\Catalog\Services\ProductService`'s private `buildFilter()` into a new standalone `Modules\Core\Catalog\Support\ProductFilterBuilder`, so `ProductSearchService` can apply the exact same Meilisearch filter-clause semantics to a text query, instead of reimplementing filter-building a second time.
|
- Extracted `Modules\Core\Catalog\Services\ProductService`'s private `buildFilter()` into a new standalone `Modules\Core\Catalog\Support\ProductFilterBuilder`, so `ProductSearchService` can apply the exact same Meilisearch filter-clause semantics to a text query, instead of reimplementing filter-building a second time.
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Catalog\Services\ProductService::priceSliderBounds()` — `priceRange()` rounded to whole currency units (floor/ceil) plus whether the given selected min/max actually narrows it, returned as a `PriceSliderBounds` DTO. Used internally by `list()` now; also callable directly for a caller (e.g. a text-search results page) that needs slider bounds without a full `list()` call.
|
- `Modules\Core\Catalog\Services\ProductService::priceSliderBounds()` — `priceRange()` rounded to whole currency units (floor/ceil) plus whether the given selected min/max actually narrows it, returned as a `PriceSliderBounds` DTO. Used internally by `list()` now; also callable directly for a caller (e.g. a text-search results page) that needs slider bounds without a full `list()` call.
|
||||||
- `Modules\Core\Catalog\Services\ProductService::priceRange()` gained an optional `string $query = ''` parameter, so a caller can scope the price range to a text search's own matches (pass the shopper's search text) instead of always spanning the whole catalog.
|
- `Modules\Core\Catalog\Services\ProductService::priceRange()` gained an optional `string $query = ''` parameter, so a caller can scope the price range to a text search's own matches (pass the shopper's search text) instead of always spanning the whole catalog.
|
||||||
- `Modules\Core\Catalog\Services\ProductService::random(int $limit)` — random products still scoped to the Meilisearch index's own channel/status visibility, unlike a raw `Product::inRandomOrder()` (which has no notion of that filtering). Meilisearch has no `ORDER BY RANDOM()` equivalent, so this fetches every matching id only (`attributesToRetrieve: ['id']`), shuffles in PHP, then fetches the full localized documents for just the ids picked, restoring the shuffled order afterward (Meilisearch's `id IN [...]` filter doesn't preserve list order on its own).
|
- `Modules\Core\Catalog\Services\ProductService::random(int $limit)` — random products still scoped to the Meilisearch index's own channel/status visibility, unlike a raw `Product::inRandomOrder()` (which has no notion of that filtering). Meilisearch has no `ORDER BY RANDOM()` equivalent, so this fetches every matching id only (`attributesToRetrieve: ['id']`), shuffles in PHP, then fetches the full localized documents for just the ids picked, restoring the shuffled order afterward (Meilisearch's `id IN [...]` filter doesn't preserve list order on its own).
|
||||||
@@ -554,11 +1003,13 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
## [0.11.1] - 2026-09-01
|
## [0.11.1] - 2026-09-01
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- `Modules\Core\Catalog\Services\RecommendationService::recommend()` built its result with the base `Illuminate\Support\Collection` (`collect()`) instead of `Illuminate\Database\Eloquent\Collection`, even though every element is a `Product` model. `ProductIndexer::toSearchableArray()` calling `->load(['media', 'variants.prices'])` on that result threw `BadMethodCallException: Method Illuminate\Support\Collection::load does not exist` — silently failing every `MakeSearchable` queue job for a saved product (visible only as `FAIL` in the queue log, with the real exception in `storage/logs/laravel.log`). Fixed by having `RecommendationService` accumulate into a real `Eloquent\Collection` from the start.
|
- `Modules\Core\Catalog\Services\RecommendationService::recommend()` built its result with the base `Illuminate\Support\Collection` (`collect()`) instead of `Illuminate\Database\Eloquent\Collection`, even though every element is a `Product` model. `ProductIndexer::toSearchableArray()` calling `->load(['media', 'variants.prices'])` on that result threw `BadMethodCallException: Method Illuminate\Support\Collection::load does not exist` — silently failing every `MakeSearchable` queue job for a saved product (visible only as `FAIL` in the queue log, with the real exception in `storage/logs/laravel.log`). Fixed by having `RecommendationService` accumulate into a real `Eloquent\Collection` from the start.
|
||||||
|
|
||||||
## [0.11.0] - 2026-09-01
|
## [0.11.0] - 2026-09-01
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Catalog\Services\RecommendationService` — computes "related products" for a given product as a configurable, ordered chain of strategies (`config('catalog.recommendation_rules')`), not one hardcoded rule. Tops up from each successive rule until the limit (default 4) is reached or every rule is exhausted — e.g. 3 products from a same-category rule plus 1 from a random fallback — deduplicated across rules so the same product is never returned twice. Ships with `Modules\Core\Catalog\Recommendations\SameCategoryRule` (other products sharing the source product's first collection) and `RandomRule` (the universal fallback, placed last in the default chain). A new rule is just a class implementing `Modules\Core\Catalog\Contracts\RecommendationRule`. Documented in `docs/product-recommendations.md`.
|
- `Modules\Core\Catalog\Services\RecommendationService` — computes "related products" for a given product as a configurable, ordered chain of strategies (`config('catalog.recommendation_rules')`), not one hardcoded rule. Tops up from each successive rule until the limit (default 4) is reached or every rule is exhausted — e.g. 3 products from a same-category rule plus 1 from a random fallback — deduplicated across rules so the same product is never returned twice. Ships with `Modules\Core\Catalog\Recommendations\SameCategoryRule` (other products sharing the source product's first collection) and `RandomRule` (the universal fallback, placed last in the default chain). A new rule is just a class implementing `Modules\Core\Catalog\Contracts\RecommendationRule`. Documented in `docs/product-recommendations.md`.
|
||||||
- `Modules\Core\Catalog\Services\ProductIndexer` embeds the result directly into each product's own Meilisearch document as `recommendations: [{id, name, price, image}, ...]` (`recommendations.id` filterable) — a product detail page renders its "related products" section with zero extra queries, same reasoning as the existing `collections` field. Deliberately embeds an `id` for the view to build a locale-correct URL from, not a resolved `href` — `product.show` is locale-prefixed, so a URL baked in at index time would only be correct for whichever locale happened to be active during that index run.
|
- `Modules\Core\Catalog\Services\ProductIndexer` embeds the result directly into each product's own Meilisearch document as `recommendations: [{id, name, price, image}, ...]` (`recommendations.id` filterable) — a product detail page renders its "related products" section with zero extra queries, same reasoning as the existing `collections` field. Deliberately embeds an `id` for the view to build a locale-correct URL from, not a resolved `href` — `product.show` is locale-prefixed, so a URL baked in at index time would only be correct for whichever locale happened to be active during that index run.
|
||||||
- `Modules\Core\Catalog\Events\ProductSaved`/`ProductDeleted`, dispatched from `Product::saved()`/`Product::deleted()` in `CatalogServiceProvider` (the latter fires for both a soft delete and a force delete, matching Scout's own `unsearchable()` trigger point) — feed `Modules\Core\Catalog\Listeners\ReindexProductsRecommendingProduct`, which reverse-searches Meilisearch for every product currently recommending the changed/deleted one (`recommendations.id = "..."` — there's no Postgres relation for this, a recommendation only exists inside the index) and re-indexes them via Scout's own `->searchable()`. Product creation is deliberately not hooked into this: a new product not yet appearing as a recommendation elsewhere is an accepted staleness window, the same tradeoff already documented for `in_stock`/`price` — see `docs/product-recommendations.md`.
|
- `Modules\Core\Catalog\Events\ProductSaved`/`ProductDeleted`, dispatched from `Product::saved()`/`Product::deleted()` in `CatalogServiceProvider` (the latter fires for both a soft delete and a force delete, matching Scout's own `unsearchable()` trigger point) — feed `Modules\Core\Catalog\Listeners\ReindexProductsRecommendingProduct`, which reverse-searches Meilisearch for every product currently recommending the changed/deleted one (`recommendations.id = "..."` — there's no Postgres relation for this, a recommendation only exists inside the index) and re-indexes them via Scout's own `->searchable()`. Product creation is deliberately not hooked into this: a new product not yet appearing as a recommendation elsewhere is an accepted staleness window, the same tradeoff already documented for `in_stock`/`price` — see `docs/product-recommendations.md`.
|
||||||
@@ -567,28 +1018,33 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
## [0.10.1] - 2026-09-01
|
## [0.10.1] - 2026-09-01
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Localization\Services\StorefrontLabels::all()` gains three keys found missing from `3dealer`'s actual `storefront.*` translation usage: `shop.price_min`, `shop.price_max`, `shop.reset` (the price-filter sidebar's min/max labels and its reset link). Picked up by `InstallLunarCommand`'s existing per-key upsert — re-running `lunar:install` on an already-installed store adds only these three rows, leaving everything already seeded or admin-edited untouched.
|
- `Modules\Core\Localization\Services\StorefrontLabels::all()` gains three keys found missing from `3dealer`'s actual `storefront.*` translation usage: `shop.price_min`, `shop.price_max`, `shop.reset` (the price-filter sidebar's min/max labels and its reset link). Picked up by `InstallLunarCommand`'s existing per-key upsert — re-running `lunar:install` on an already-installed store adds only these three rows, leaving everything already seeded or admin-edited untouched.
|
||||||
|
|
||||||
## [0.10.0] - 2026-08-31
|
## [0.10.0] - 2026-08-31
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|
||||||
- **Breaking:** Upgraded `lunarphp/lunar`, `lunarphp/core`, `lunarphp/stripe`, `lunarphp/table-rate-shipping`, and `lunarphp/search` to `1.5.0`, and `filament/filament` to `v4.12.6` — the first Filament v4 admin panel on this codebase. `lunarphp/filament3-2fa` and `kalnoy/nestedset` are gone, replaced by Filament v4's native two-factor auth and `lunarphp/nestedset`. Ran Filament's automated `filament-v4` migration tool across `src/`, then hand-fixed three bugs it introduced or left behind: a stale `$infolist` variable reference in `CartResource`'s `ViewCart` page (the parameter had been renamed to `$schema` but the body wasn't updated), `ShippingMethodResourceExtension` rewritten to call `getDefaultChildComponents()` (returns `array|Schema`) instead of the type-safe `getChildComponents()` (always `array<Component>`), and — unrelated to the tool, but surfaced by the same PHP version bump — `InvalidCouponException`'s `readonly $code` property illegally shadowing the built-in `Exception::$code`, renamed to `$couponCode`. `LunarStaff::addActivitylogExcept()` updated for the renamed `two_factor_secret`/`two_factor_recovery_codes` staff columns (now `app_authentication_secret`/`app_authentication_recovery_codes`; `two_factor_confirmed_at` removed). Consuming apps must run `composer update boboko/core --with-all-dependencies` and `php artisan migrate`.
|
- **Breaking:** Upgraded `lunarphp/lunar`, `lunarphp/core`, `lunarphp/stripe`, `lunarphp/table-rate-shipping`, and `lunarphp/search` to `1.5.0`, and `filament/filament` to `v4.12.6` — the first Filament v4 admin panel on this codebase. `lunarphp/filament3-2fa` and `kalnoy/nestedset` are gone, replaced by Filament v4's native two-factor auth and `lunarphp/nestedset`. Ran Filament's automated `filament-v4` migration tool across `src/`, then hand-fixed three bugs it introduced or left behind: a stale `$infolist` variable reference in `CartResource`'s `ViewCart` page (the parameter had been renamed to `$schema` but the body wasn't updated), `ShippingMethodResourceExtension` rewritten to call `getDefaultChildComponents()` (returns `array|Schema`) instead of the type-safe `getChildComponents()` (always `array<Component>`), and — unrelated to the tool, but surfaced by the same PHP version bump — `InvalidCouponException`'s `readonly $code` property illegally shadowing the built-in `Exception::$code`, renamed to `$couponCode`. `LunarStaff::addActivitylogExcept()` updated for the renamed `two_factor_secret`/`two_factor_recovery_codes` staff columns (now `app_authentication_secret`/`app_authentication_recovery_codes`; `two_factor_confirmed_at` removed). Consuming apps must run `composer update boboko/core --with-all-dependencies` and `php artisan migrate`.
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Checkout\Contracts\PaymentDriver` — the abstraction every payment provider implements: `confirm(Cart $cart, string $type, string $fingerprint, array $data): Order` and `isConfigured(): bool`. A driver only ever calls `CheckoutService::placeOrder()` once it has, by whatever mechanism is native to that gateway, independently confirmed payment — never Lunar's raw `Cart::createOrder()`. This is what lets the storefront checkout sequence stay uniform regardless of which provider is active: set addresses, select shipping, hand off to whichever driver is configured, and the driver decides when (or whether) the order gets created.
|
- `Modules\Core\Checkout\Contracts\PaymentDriver` — the abstraction every payment provider implements: `confirm(Cart $cart, string $type, string $fingerprint, array $data): Order` and `isConfigured(): bool`. A driver only ever calls `CheckoutService::placeOrder()` once it has, by whatever mechanism is native to that gateway, independently confirmed payment — never Lunar's raw `Cart::createOrder()`. This is what lets the storefront checkout sequence stay uniform regardless of which provider is active: set addresses, select shipping, hand off to whichever driver is configured, and the driver decides when (or whether) the order gets created.
|
||||||
- `Modules\Core\Payment\Drivers\OfflinePaymentDriver` — shared by every payment type with no real gateway to confirm against (`cash-in-hand`, `cash-on-delivery`): places the order immediately via `CheckoutService::placeOrder()`, then sets the order status from `config("lunar.payments.types.{$type}.authorized")` using the type actually confirmed, not a hardcoded key, since one driver instance serves multiple types.
|
- `Modules\Core\Payment\Drivers\OfflinePaymentDriver` — shared by every payment type with no real gateway to confirm against (`cash-in-hand`, `cash-on-delivery`): places the order immediately via `CheckoutService::placeOrder()`, then sets the order status from `config("lunar.payments.types.{$type}.authorized")` using the type actually confirmed, not a hardcoded key, since one driver instance serves multiple types.
|
||||||
- `Modules\Core\Payment\Drivers\StripePaymentDriver` — a fork, not a decoration, of `lunarphp/stripe`'s `StripePaymentType::authorize()`: that method is `final` and calls `Cart::createOrder()` directly with no seam to redirect into our fingerprint-checked `placeOrder()`, so this class reimplements its logic (intent retrieval, capture-on-policy, status mapping via `UpdateOrderFromIntent`) with that one substitution. Throws the new `Modules\Core\Payment\Exceptions\PaymentNotConfirmedException` on anything short of a genuinely confirmed payment intent — never falls through to placing an order on ambiguity.
|
- `Modules\Core\Payment\Drivers\StripePaymentDriver` — a fork, not a decoration, of `lunarphp/stripe`'s `StripePaymentType::authorize()`: that method is `final` and calls `Cart::createOrder()` directly with no seam to redirect into our fingerprint-checked `placeOrder()`, so this class reimplements its logic (intent retrieval, capture-on-policy, status mapping via `UpdateOrderFromIntent`) with that one substitution. Throws the new `Modules\Core\Payment\Exceptions\PaymentNotConfirmedException` on anything short of a genuinely confirmed payment intent — never falls through to placing an order on ambiguity.
|
||||||
- `CheckoutService::getPaymentMethods(): array` — every payment type currently offered to the storefront: every key in `config('lunar.payments.types')` that is both administratively enabled (`Modules\Core\Payment\Models\PaymentMethod::enabled`) and whose driver reports `isConfigured()` (e.g. Stripe with no API key set is never offered, regardless of the enabled toggle). `selectPaymentMethod(string $type)` and `confirmPayment(string $type, array $data)` both validate against this list, throwing the new `UnknownPaymentTypeException` for a type that isn't currently offered — re-checked in `confirmPayment()` too, since a type could be disabled between selection and confirmation.
|
- `CheckoutService::getPaymentMethods(): array` — every payment type currently offered to the storefront: every key in `config('lunar.payments.types')` that is both administratively enabled (`Modules\Core\Payment\Models\PaymentMethod::enabled`) and whose driver reports `isConfigured()` (e.g. Stripe with no API key set is never offered, regardless of the enabled toggle). `selectPaymentMethod(string $type)` and `confirmPayment(string $type, array $data)` both validate against this list, throwing the new `UnknownPaymentTypeException` for a type that isn't currently offered — re-checked in `confirmPayment()` too, since a type could be disabled between selection and confirmation.
|
||||||
- `CheckoutService::selectPaymentMethod()` snapshots `Cart::fingerprint()` into `cart->meta['checkout_fingerprint']` *after* saving the chosen type and recalculating — the fingerprint has to reflect the final total including any payment-type-specific adjustment (e.g. a COD surcharge), which only exists once `payment_method` is set. `confirmPayment()` reads this stored fingerprint internally rather than taking one as a parameter: a storefront should never need to know `Cart::fingerprint()` exists or capture it at exactly the right moment itself.
|
- `CheckoutService::selectPaymentMethod()` snapshots `Cart::fingerprint()` into `cart->meta['checkout_fingerprint']` _after_ saving the chosen type and recalculating — the fingerprint has to reflect the final total including any payment-type-specific adjustment (e.g. a COD surcharge), which only exists once `payment_method` is set. `confirmPayment()` reads this stored fingerprint internally rather than taking one as a parameter: a storefront should never need to know `Cart::fingerprint()` exists or capture it at exactly the right moment itself.
|
||||||
- `Modules\Core\Payment\Models\PaymentMethod` — one DB row per payment type key (matching `config('lunar.payments.types')`), `enabled` boolean plus a `data` jsonb column (starting with `fee`, the flat cash-on-delivery surcharge) — mirrors Lunar's own `Discount` model (a single jsonb column of keyed settings, not a fixed column per setting or a separate conditions table). Seeded idempotently by `InstallLunarCommand` (skip-if-exists per type, safe to re-run after installing a new payment-provider package), always `enabled: false` — a newly-seeded type shouldn't go live for shoppers before staff have configured and reviewed it. Admin-editable via the new `PaymentMethodResource` (inline enabled toggle, modal fee editor) under Settings.
|
- `Modules\Core\Payment\Models\PaymentMethod` — one DB row per payment type key (matching `config('lunar.payments.types')`), `enabled` boolean plus a `data` jsonb column (starting with `fee`, the flat cash-on-delivery surcharge) — mirrors Lunar's own `Discount` model (a single jsonb column of keyed settings, not a fixed column per setting or a separate conditions table). Seeded idempotently by `InstallLunarCommand` (skip-if-exists per type, safe to re-run after installing a new payment-provider package), always `enabled: false` — a newly-seeded type shouldn't go live for shoppers before staff have configured and reviewed it. Admin-editable via the new `PaymentMethodResource` (inline enabled toggle, modal fee editor) under Settings.
|
||||||
- `ApplyCashOnDeliveryFee` now reads its surcharge from `PaymentMethod` instead of static config, so it's admin-editable without a deploy.
|
- `ApplyCashOnDeliveryFee` now reads its surcharge from `PaymentMethod` instead of static config, so it's admin-editable without a deploy.
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- `CashOnDeliveryPaymentDriver` renamed to `OfflinePaymentDriver` and generalized to work for any offline-style type — it previously hardcoded `'cash-on-delivery'` when reading the post-placement order status from config, which would have silently read the wrong type's status the moment a second offline type (`cash-in-hand`) used it.
|
- `CashOnDeliveryPaymentDriver` renamed to `OfflinePaymentDriver` and generalized to work for any offline-style type — it previously hardcoded `'cash-on-delivery'` when reading the post-placement order status from config, which would have silently read the wrong type's status the moment a second offline type (`cash-in-hand`) used it.
|
||||||
|
|
||||||
## [0.9.0] - 2026-08-29
|
## [0.9.0] - 2026-08-29
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Cart\Services\CartService` — the boboko-owned API for all cart mutation, wrapping Lunar's `CartSession`/`Cart` primitives: `addLine()`, `updateLine()`, `removeLine()`, `clear()`, `applyCoupon()`/`removeCoupon()` (throws `InvalidCouponException` on an invalid code), and save-for-later (`saveForLater()`/`moveToCart()`/`activeLines()`/`savedLines()`, backed by a `meta.saved_for_later` flag and a new `Modules\Core\Cart\Pipelines\ZeroSavedForLaterPrice` cart-line pipeline step that zeroes a saved line's price so it's excluded from cart totals without being removed). Dispatches 8 real domain events (`CartLineAdded`/`Updated`/`Removed`/`Saved`/`MovedToCart`, `CartCleared`, `CartCouponApplied`/`Removed`) — none have a listener yet, built so a future concern (analytics, recovery) has something to attach to. Documented in `docs/cart.md`.
|
- `Modules\Core\Cart\Services\CartService` — the boboko-owned API for all cart mutation, wrapping Lunar's `CartSession`/`Cart` primitives: `addLine()`, `updateLine()`, `removeLine()`, `clear()`, `applyCoupon()`/`removeCoupon()` (throws `InvalidCouponException` on an invalid code), and save-for-later (`saveForLater()`/`moveToCart()`/`activeLines()`/`savedLines()`, backed by a `meta.saved_for_later` flag and a new `Modules\Core\Cart\Pipelines\ZeroSavedForLaterPrice` cart-line pipeline step that zeroes a saved line's price so it's excluded from cart totals without being removed). Dispatches 8 real domain events (`CartLineAdded`/`Updated`/`Removed`/`Saved`/`MovedToCart`, `CartCleared`, `CartCouponApplied`/`Removed`) — none have a listener yet, built so a future concern (analytics, recovery) has something to attach to. Documented in `docs/cart.md`.
|
||||||
- `Modules\Core\Checkout\Services\CheckoutService` — the boboko-owned API for the checkout stage (address → shipping selection → order placement), sitting between `CartService` and `Order`: `setShippingAddress()`/`setBillingAddress()`, `getShippingOptions()`/`selectShippingOption()` (throws the new `InvalidShippingOptionException` on an identifier that doesn't resolve — previously a silent no-op), and `placeOrder(string $fingerprint)` (the fingerprint is mandatory, not optional — forces re-confirmation via Lunar's own `FingerprintMismatchException` if the cart changed since the shopper last saw its total). Dispatches `ShippingAddressSet`/`BillingAddressSet`/`ShippingOptionSelected`/`OrderPlaced`, each carrying richer, already-resolved payload (e.g. the resolved `ShippingOption`, not just its identifier) than `CartService`'s events. No exception wrapping otherwise — Lunar's own `CartException`/`FingerprintMismatchException` are already the right shape for a storefront to render as form errors. Documented in `docs/checkout.md`.
|
- `Modules\Core\Checkout\Services\CheckoutService` — the boboko-owned API for the checkout stage (address → shipping selection → order placement), sitting between `CartService` and `Order`: `setShippingAddress()`/`setBillingAddress()`, `getShippingOptions()`/`selectShippingOption()` (throws the new `InvalidShippingOptionException` on an identifier that doesn't resolve — previously a silent no-op), and `placeOrder(string $fingerprint)` (the fingerprint is mandatory, not optional — forces re-confirmation via Lunar's own `FingerprintMismatchException` if the cart changed since the shopper last saw its total). Dispatches `ShippingAddressSet`/`BillingAddressSet`/`ShippingOptionSelected`/`OrderPlaced`, each carrying richer, already-resolved payload (e.g. the resolved `ShippingOption`, not just its identifier) than `CartService`'s events. No exception wrapping otherwise — Lunar's own `CartException`/`FingerprintMismatchException` are already the right shape for a storefront to render as form errors. Documented in `docs/checkout.md`.
|
||||||
- `Modules\Core\Cart\Filament\Resources\CartResource`'s list view now classifies every cart into one of four states — **Ongoing**, **Abandoned Cart**, **Abandoned Checkout**, **Completed** — instead of the previous two-tab Abandoned/Completed split, distinguishing a cart that never reached checkout from one that has a started-but-unplaced order (mirrors the real distinction in Lunar's own `Cart::scopeActive()`). Abandonment threshold is a fixed, configurable cutoff (`config('core.cart.abandoned_after')`, default 1 hour). Added a customer hyperlink (list column + a "View Customer" header action on the view page, both pointing straight at `customers/{id}` via the plain `customer_id` column, no extra query via the `customer` relation).
|
- `Modules\Core\Cart\Filament\Resources\CartResource`'s list view now classifies every cart into one of four states — **Ongoing**, **Abandoned Cart**, **Abandoned Checkout**, **Completed** — instead of the previous two-tab Abandoned/Completed split, distinguishing a cart that never reached checkout from one that has a started-but-unplaced order (mirrors the real distinction in Lunar's own `Cart::scopeActive()`). Abandonment threshold is a fixed, configurable cutoff (`config('core.cart.abandoned_after')`, default 1 hour). Added a customer hyperlink (list column + a "View Customer" header action on the view page, both pointing straight at `customers/{id}` via the plain `customer_id` column, no extra query via the `customer` relation).
|
||||||
@@ -598,17 +1054,20 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
- `AcsRateDriver::resolveLivePrice()` now falls back to the rate's own configured static price if the live ACS API call fails (previously: the shipping option silently disappeared from the list on any API error, including a brief outage). `ManageShippingRates` (our Filament subclass of the vendor rates page) now allows a static price to be configured and saved on a "live" rate specifically for this fallback — previously those fields were hidden and discarded on save for any live-priced rate.
|
- `AcsRateDriver::resolveLivePrice()` now falls back to the rate's own configured static price if the live ACS API call fails (previously: the shipping option silently disappeared from the list on any API error, including a brief outage). `ManageShippingRates` (our Filament subclass of the vendor rates page) now allows a static price to be configured and saved on a "live" rate specifically for this fallback — previously those fields were hidden and discarded on save for any live-priced rate.
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- Fixed a crash (`Attempt to read property "price" on null`) opening/editing a live-priced shipping rate with no fallback price configured yet — the vendor `ManageShippingRates` page's `afterStateHydrated` callback for the price field had no null-guard for a rate with zero `basePrices`, which is now the routine case for an unconfigured live rate.
|
- Fixed a crash (`Attempt to read property "price" on null`) opening/editing a live-priced shipping rate with no fallback price configured yet — the vendor `ManageShippingRates` page's `afterStateHydrated` callback for the price field had no null-guard for a rate with zero `basePrices`, which is now the routine case for an unconfigured live rate.
|
||||||
- Fixed the Filament admin panel's home URL (`/boboko/home`) incorrectly resolving to the Shipping module's `ManagePickupManifests` page instead of the Dashboard — Filament falls back to the first item of the first registered navigation group when no explicit `homeUrl()` is set, and `ManagePickupManifests` had no `navigationGroup`/`navigationSort` of its own. Fixed via explicit `navigationGroup = 'Sales'` / `navigationSort = 100`, placing it after Sales in the nav instead of first overall.
|
- Fixed the Filament admin panel's home URL (`/boboko/home`) incorrectly resolving to the Shipping module's `ManagePickupManifests` page instead of the Dashboard — Filament falls back to the first item of the first registered navigation group when no explicit `homeUrl()` is set, and `ManagePickupManifests` had no `navigationGroup`/`navigationSort` of its own. Fixed via explicit `navigationGroup = 'Sales'` / `navigationSort = 100`, placing it after Sales in the nav instead of first overall.
|
||||||
|
|
||||||
## [0.8.0] - 2026-08-27
|
## [0.8.0] - 2026-08-27
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Cart\Filament\Resources\CartResource` gives staff read-only visibility into carts in the Filament admin panel — Lunar ships no cart admin view at all. Scoped to carts with a known `user_id`/`customer_id` (an anonymous guest cart carries no identity staff could act on); list table shows customer/user, line/item counts (via Filament's built-in `->counts()`/`->sum()`, no per-row queries), currency, and last activity. List page has only two tabs, **Abandoned** (default active) and **Completed** — no "All" tab, so the list never runs an unfiltered fetch over the whole table. They key off whether the cart has a **placed** order (`orders.placed_at IS NOT NULL`), not `Cart::completed_at` — that column is declared/cast on the model but never actually written anywhere in Lunar core, so it's not a real signal; "Abandoned" mirrors Lunar's own `Cart::scopeActive()`. `getNavigationBadge()` shows the abandoned-cart count in the sidebar via a single `COUNT(*)` query, no rows loaded. View page runs `$cart->calculate()` once so line/cart totals (plain public properties Lunar never persists) are populated, without paying that cost per row in the list. Documented in `docs/cart.md`.
|
- `Modules\Core\Cart\Filament\Resources\CartResource` gives staff read-only visibility into carts in the Filament admin panel — Lunar ships no cart admin view at all. Scoped to carts with a known `user_id`/`customer_id` (an anonymous guest cart carries no identity staff could act on); list table shows customer/user, line/item counts (via Filament's built-in `->counts()`/`->sum()`, no per-row queries), currency, and last activity. List page has only two tabs, **Abandoned** (default active) and **Completed** — no "All" tab, so the list never runs an unfiltered fetch over the whole table. They key off whether the cart has a **placed** order (`orders.placed_at IS NOT NULL`), not `Cart::completed_at` — that column is declared/cast on the model but never actually written anywhere in Lunar core, so it's not a real signal; "Abandoned" mirrors Lunar's own `Cart::scopeActive()`. `getNavigationBadge()` shows the abandoned-cart count in the sidebar via a single `COUNT(*)` query, no rows loaded. View page runs `$cart->calculate()` once so line/cart totals (plain public properties Lunar never persists) are populated, without paying that cost per row in the list. Documented in `docs/cart.md`.
|
||||||
|
|
||||||
## [0.7.0] - 2026-08-27
|
## [0.7.0] - 2026-08-27
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Catalog\Services\CollectionService` provides category browsing/nav AND single-collection lookup from Meilisearch, mirroring `ProductService` exactly (`list()`, `getById()`, `getBySlug()`, same locale-resolution logic). `Modules\Core\Catalog\Services\CollectionIndexer` extends Lunar's own `Lunar\Search\CollectionIndexer` (which only carried `id`/`name`/`created_at`) to add `parent_id`, `_lft`/`_rgt` (nested-set tree position, filterable/sortable), `collection_group_id`, `slugs`, and `thumbnail`. `Modules\Core\Catalog\DTOs\CollectionFilters` supports `parentId` (children of a specific collection), `groupId`, and `rootOnly` (top-level collections, `parent_id IS NULL` — mutually exclusive with `parentId`). `Modules\Core\Catalog\Enums\CollectionSort` adds `Position` (`_lft:asc`, the recommended default for nav/tree UIs — matches admin arrangement order), `Name`, `Newest`. Must be registered in a consuming app's `config/lunar/search.php` (`Lunar\Models\Collection::class => CollectionIndexer::class`), same as `ProductIndexer`. Documented in `docs/collections.md`.
|
- `Modules\Core\Catalog\Services\CollectionService` provides category browsing/nav AND single-collection lookup from Meilisearch, mirroring `ProductService` exactly (`list()`, `getById()`, `getBySlug()`, same locale-resolution logic). `Modules\Core\Catalog\Services\CollectionIndexer` extends Lunar's own `Lunar\Search\CollectionIndexer` (which only carried `id`/`name`/`created_at`) to add `parent_id`, `_lft`/`_rgt` (nested-set tree position, filterable/sortable), `collection_group_id`, `slugs`, and `thumbnail`. `Modules\Core\Catalog\DTOs\CollectionFilters` supports `parentId` (children of a specific collection), `groupId`, and `rootOnly` (top-level collections, `parent_id IS NULL` — mutually exclusive with `parentId`). `Modules\Core\Catalog\Enums\CollectionSort` adds `Position` (`_lft:asc`, the recommended default for nav/tree UIs — matches admin arrangement order), `Name`, `Newest`. Must be registered in a consuming app's `config/lunar/search.php` (`Lunar\Models\Collection::class => CollectionIndexer::class`), same as `ProductIndexer`. Documented in `docs/collections.md`.
|
||||||
- `Modules\Core\Localization\Services\StorefrontLabels::all()` extracts the default storefront UI label list out of `InstallLunarCommand` into its own class, and adds every previously-missing key (`nav.contact`, `product.description`/`no_image`/`read_more`/`reviews`, `customer_reviews`, `pagination.*`, `review.*`, `shop.*`) that had already been seeded manually in some stores but was absent from the command's own list — bringing the code-side default back in sync with what a real store actually has. `InstallLunarCommand::seedStorefrontLabels()` now does a **per-key upsert** instead of an all-or-nothing "only seed if the group is empty" guard: a key already present in the database (including one an admin has since edited via the Filament **Language Lines** resource) is left untouched, and only missing keys are created via `TranslationService::create()`. This makes it safe to add new keys to `StorefrontLabels::all()` later and re-run `lunar:install` on an already-installed store without either silently skipping the new keys (the old guard's behavior) or reverting an admin's edits back to the hardcoded default. Documented in `docs/localization.md` ("Seeding").
|
- `Modules\Core\Localization\Services\StorefrontLabels::all()` extracts the default storefront UI label list out of `InstallLunarCommand` into its own class, and adds every previously-missing key (`nav.contact`, `product.description`/`no_image`/`read_more`/`reviews`, `customer_reviews`, `pagination.*`, `review.*`, `shop.*`) that had already been seeded manually in some stores but was absent from the command's own list — bringing the code-side default back in sync with what a real store actually has. `InstallLunarCommand::seedStorefrontLabels()` now does a **per-key upsert** instead of an all-or-nothing "only seed if the group is empty" guard: a key already present in the database (including one an admin has since edited via the Filament **Language Lines** resource) is left untouched, and only missing keys are created via `TranslationService::create()`. This makes it safe to add new keys to `StorefrontLabels::all()` later and re-run `lunar:install` on an already-installed store without either silently skipping the new keys (the old guard's behavior) or reverting an admin's edits back to the hardcoded default. Documented in `docs/localization.md` ("Seeding").
|
||||||
- `Modules\Core\Catalog\Services\CollectionIndexer` adds `ancestors` — `[{id, name}, ...]` ordered root-first (via the newly eager-loaded `ancestors` relation) — so a breadcrumb can render directly from `CollectionService::getById()`/`getBySlug()` with zero extra queries, and `product_count` — how many products are in a collection or any of its descendants, queried from the product Meilisearch index at collection-index time via the same `collection_ids` field `ProductFilters(collectionId:)` filters against. Documented in `docs/collections.md`, including the reindex-ordering gotcha (`product_count` needs the product index reindexed first).
|
- `Modules\Core\Catalog\Services\CollectionIndexer` adds `ancestors` — `[{id, name}, ...]` ordered root-first (via the newly eager-loaded `ancestors` relation) — so a breadcrumb can render directly from `CollectionService::getById()`/`getBySlug()` with zero extra queries, and `product_count` — how many products are in a collection or any of its descendants, queried from the product Meilisearch index at collection-index time via the same `collection_ids` field `ProductFilters(collectionId:)` filters against. Documented in `docs/collections.md`, including the reindex-ordering gotcha (`product_count` needs the product index reindexed first).
|
||||||
@@ -616,6 +1075,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
- `Modules\Core\Catalog\Services\ProductService::facets(string $field, ?ProductFilters $filters = null): array` returns Meilisearch facet value counts (e.g. `['Brand A' => 48, 'Brand B' => 135]`) for a discrete-value filterable field, scoped to the given filters. Uses Scout's plain `->options(['facets' => [...]])`, merged directly into the raw Meilisearch query the same way `filter`/`sort` already are — no adoption of Lunar's separate `SearchManager`/`Search` facade needed. `ProductService::priceRange(?ProductFilters $filters = null): array{min, max}` covers the numeric-field case `facets()` explicitly doesn't (`price` would otherwise return one "facet" per exact price) — backed by Meilisearch's `facetStats`, not `facetDistribution`. `priceRange()` always excludes `minPrice`/`maxPrice` from the filter it builds (via a new `$exclude` parameter on the private `buildFilter()`), so a price slider's own bounds don't shrink to whatever range is already selected on it; other filters (`collectionId`, `brand`, `inStockOnly`) still apply normally. Documented in `docs/product-listing.md`.
|
- `Modules\Core\Catalog\Services\ProductService::facets(string $field, ?ProductFilters $filters = null): array` returns Meilisearch facet value counts (e.g. `['Brand A' => 48, 'Brand B' => 135]`) for a discrete-value filterable field, scoped to the given filters. Uses Scout's plain `->options(['facets' => [...]])`, merged directly into the raw Meilisearch query the same way `filter`/`sort` already are — no adoption of Lunar's separate `SearchManager`/`Search` facade needed. `ProductService::priceRange(?ProductFilters $filters = null): array{min, max}` covers the numeric-field case `facets()` explicitly doesn't (`price` would otherwise return one "facet" per exact price) — backed by Meilisearch's `facetStats`, not `facetDistribution`. `priceRange()` always excludes `minPrice`/`maxPrice` from the filter it builds (via a new `$exclude` parameter on the private `buildFilter()`), so a price slider's own bounds don't shrink to whatever range is already selected on it; other filters (`collectionId`, `brand`, `inStockOnly`) still apply normally. Documented in `docs/product-listing.md`.
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|
||||||
- **Breaking:** Renamed the `Product` module to `Catalog`, flattened. Every class under `Modules\Core\Product\*` (`Contracts`, `DTOs`, `Enums`, `Services`, `Observers`, `Filament\Extensions`, `OptionTypes`) now lives under `Modules\Core\Catalog\*` at the same sub-path — e.g. `Modules\Core\Product\Services\ProductService` is now `Modules\Core\Catalog\Services\ProductService`, `Modules\Core\Product\DTOs\ProductFilters` is now `Modules\Core\Catalog\DTOs\ProductFilters`. Class names themselves are unchanged (still `ProductService`, `ProductIndexer`, `ProductFilters`, etc.) — only the namespace/folder moved, to make room for `Collection` as a sibling concern under the same `Catalog` umbrella rather than a disconnected top-level module. Consuming apps must update every `use Modules\Core\Product\...` import and any FQCN reference (`config/lunar/search.php`'s indexer registration, service provider bindings).
|
- **Breaking:** Renamed the `Product` module to `Catalog`, flattened. Every class under `Modules\Core\Product\*` (`Contracts`, `DTOs`, `Enums`, `Services`, `Observers`, `Filament\Extensions`, `OptionTypes`) now lives under `Modules\Core\Catalog\*` at the same sub-path — e.g. `Modules\Core\Product\Services\ProductService` is now `Modules\Core\Catalog\Services\ProductService`, `Modules\Core\Product\DTOs\ProductFilters` is now `Modules\Core\Catalog\DTOs\ProductFilters`. Class names themselves are unchanged (still `ProductService`, `ProductIndexer`, `ProductFilters`, etc.) — only the namespace/folder moved, to make room for `Collection` as a sibling concern under the same `Catalog` umbrella rather than a disconnected top-level module. Consuming apps must update every `use Modules\Core\Product\...` import and any FQCN reference (`config/lunar/search.php`'s indexer registration, service provider bindings).
|
||||||
- **Breaking:** `Modules\Core\Providers\ProductServiceProvider` renamed to `Modules\Core\Providers\CatalogServiceProvider` (composer.json's provider list updated accordingly) — it now only wires `Catalog`-namespace classes (`ProductOptionTypeManager`, `ProductOptionReindexObserver`), so the name follows the same by-concern convention as `LocalizationServiceProvider`/`ReviewServiceProvider`.
|
- **Breaking:** `Modules\Core\Providers\ProductServiceProvider` renamed to `Modules\Core\Providers\CatalogServiceProvider` (composer.json's provider list updated accordingly) — it now only wires `Catalog`-namespace classes (`ProductOptionTypeManager`, `ProductOptionReindexObserver`), so the name follows the same by-concern convention as `LocalizationServiceProvider`/`ReviewServiceProvider`.
|
||||||
- **Breaking:** `Modules\Core\Review`'s flat `Extensions/`/`Pages/` folders now nest under `Filament/`, matching the strict per-concern subfolder convention already applied to `Product`(now `Catalog`)/`Localization`. `Modules\Core\Review\Extensions\ProductResourceExtension` is now `Modules\Core\Review\Filament\Extensions\ProductResourceExtension`; `Modules\Core\Review\Pages\ManageProductReviews` is now `Modules\Core\Review\Filament\Pages\ManageProductReviews`. `Modules\Core\Review\Models\ProductReview` is unchanged.
|
- **Breaking:** `Modules\Core\Review`'s flat `Extensions/`/`Pages/` folders now nest under `Filament/`, matching the strict per-concern subfolder convention already applied to `Product`(now `Catalog`)/`Localization`. `Modules\Core\Review\Extensions\ProductResourceExtension` is now `Modules\Core\Review\Filament\Extensions\ProductResourceExtension`; `Modules\Core\Review\Pages\ManageProductReviews` is now `Modules\Core\Review\Filament\Pages\ManageProductReviews`. `Modules\Core\Review\Models\ProductReview` is unchanged.
|
||||||
@@ -624,29 +1084,35 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
## [0.6.1] - 2026-08-27
|
## [0.6.1] - 2026-08-27
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Product\Contracts\ProductOptionTypeInterface` describes how a category of `Lunar\Models\ProductOption` (e.g. "Color", "Size") behaves — what structured data its values carry in their free-form `meta` jsonb column, and how an admin edits it via Filament — without introducing a new model. Registered via `Modules\Core\Product\Services\ProductOptionTypeManager::get()->register([...])` (a singleton registry, same shape as `Modules\Core\Notification\NotificationRegistry`) from a service provider's `boot()`. An admin then picks one per `ProductOption` from an "Option Type" dropdown on the option's own edit form (added by `Modules\Core\Product\Filament\Extensions\ProductOptionResourceExtension`), stored in `ProductOption::meta['option_type']` — deliberately not tied to the option's `handle`, since a shop's own handle naming shouldn't have to match a type's key. `Modules\Core\Product\Filament\Extensions\ValuesRelationManagerExtension` hooks Lunar's own `ValuesRelationManager` (both extensions via `LunarPanel::extensions()`, registered in `CorePlugin`) to append the resolved type's meta form fields to the stock "Values" tab — no fork of Lunar's classes needed. Ships a reference implementation, `Modules\Core\Product\OptionTypes\ColorOptionType`, registered automatically by the new `Modules\Core\Providers\ProductServiceProvider`. Documented in `docs/product-options.md`.
|
- `Modules\Core\Product\Contracts\ProductOptionTypeInterface` describes how a category of `Lunar\Models\ProductOption` (e.g. "Color", "Size") behaves — what structured data its values carry in their free-form `meta` jsonb column, and how an admin edits it via Filament — without introducing a new model. Registered via `Modules\Core\Product\Services\ProductOptionTypeManager::get()->register([...])` (a singleton registry, same shape as `Modules\Core\Notification\NotificationRegistry`) from a service provider's `boot()`. An admin then picks one per `ProductOption` from an "Option Type" dropdown on the option's own edit form (added by `Modules\Core\Product\Filament\Extensions\ProductOptionResourceExtension`), stored in `ProductOption::meta['option_type']` — deliberately not tied to the option's `handle`, since a shop's own handle naming shouldn't have to match a type's key. `Modules\Core\Product\Filament\Extensions\ValuesRelationManagerExtension` hooks Lunar's own `ValuesRelationManager` (both extensions via `LunarPanel::extensions()`, registered in `CorePlugin`) to append the resolved type's meta form fields to the stock "Values" tab — no fork of Lunar's classes needed. Ships a reference implementation, `Modules\Core\Product\OptionTypes\ColorOptionType`, registered automatically by the new `Modules\Core\Providers\ProductServiceProvider`. Documented in `docs/product-options.md`.
|
||||||
- `Modules\Core\Product\Services\ProductIndexer::mapVariant()` now includes each option's `handle` (alongside its translated name) in a variant's indexed `options[]` — previously only the translated `option`/`value` names and `meta` were indexed, with no stable, locale-independent identifier for which option a value belongs to.
|
- `Modules\Core\Product\Services\ProductIndexer::mapVariant()` now includes each option's `handle` (alongside its translated name) in a variant's indexed `options[]` — previously only the translated `option`/`value` names and `meta` were indexed, with no stable, locale-independent identifier for which option a value belongs to.
|
||||||
- `Modules\Core\Product\Observers\ProductOptionReindexObserver`, wired in the new `Modules\Core\Providers\ProductServiceProvider`, keeps Meilisearch in sync when a `ProductOption` or `ProductOptionValue` is saved or deleted — e.g. picking an Option Type or editing a color's hex. `ProductIndexer::mapVariant()` embeds each option value's `meta` directly into a product's indexed document, but saving the option/value never fires the *product's* own save events, so without this a changed hex would only reach the index on that product's next unrelated reindex. The observer resolves every `Lunar\Models\Product` whose variants use the changed option (or option value) via the `product_option_value_product_variant` pivot, and calls `->searchable()` on each.
|
- `Modules\Core\Product\Observers\ProductOptionReindexObserver`, wired in the new `Modules\Core\Providers\ProductServiceProvider`, keeps Meilisearch in sync when a `ProductOption` or `ProductOptionValue` is saved or deleted — e.g. picking an Option Type or editing a color's hex. `ProductIndexer::mapVariant()` embeds each option value's `meta` directly into a product's indexed document, but saving the option/value never fires the _product's_ own save events, so without this a changed hex would only reach the index on that product's next unrelated reindex. The observer resolves every `Lunar\Models\Product` whose variants use the changed option (or option value) via the `product_option_value_product_variant` pivot, and calls `->searchable()` on each.
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|
||||||
- **Breaking:** `Modules\Core\Product\Services\ProductIndexer`'s indexed `collections` field is now an array of `{id, name}` objects instead of two parallel arrays (`collections` as bare ID strings, `collection_names` as translated names joined only by array index). `collection_names` is removed. Filtering by collection now targets the nested field `collections.id` (Meilisearch supports filtering on nested object fields), not bare `collections` — `Modules\Core\Product\Services\ProductService::buildFilter()` updated accordingly; `ProductFilters(collectionId: ...)`'s public API is unchanged. Run `php artisan lunar:meilisearch:setup` then `lunar:search:index --refresh` after upgrading (see docs/product-listing.md "Gotchas").
|
- **Breaking:** `Modules\Core\Product\Services\ProductIndexer`'s indexed `collections` field is now an array of `{id, name}` objects instead of two parallel arrays (`collections` as bare ID strings, `collection_names` as translated names joined only by array index). `collection_names` is removed. Filtering by collection now targets the nested field `collections.id` (Meilisearch supports filtering on nested object fields), not bare `collections` — `Modules\Core\Product\Services\ProductService::buildFilter()` updated accordingly; `ProductFilters(collectionId: ...)`'s public API is unchanged. Run `php artisan lunar:meilisearch:setup` then `lunar:search:index --refresh` after upgrading (see docs/product-listing.md "Gotchas").
|
||||||
- **Breaking:** `ProductIndexer`'s indexed `review_count`/`average_rating` top-level keys are folded into the existing `reviews` key: `reviews` is now `{items, count, average_rating}` instead of a bare array with `review_count`/`average_rating` as separate sibling keys. `reviews` (the array of review items) moved to `reviews.items`.
|
- **Breaking:** `ProductIndexer`'s indexed `review_count`/`average_rating` top-level keys are folded into the existing `reviews` key: `reviews` is now `{items, count, average_rating}` instead of a bare array with `review_count`/`average_rating` as separate sibling keys. `reviews` (the array of review items) moved to `reviews.items`.
|
||||||
|
|
||||||
## [0.6.0] - 2026-08-27
|
## [0.6.0] - 2026-08-27
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Localization\Models\LanguageLine` extends `spatie/laravel-translation-loader`'s `LanguageLine` to fall back to the store's actual default language (`LanguageCache::defaultLocale()`, backed by Lunar's `languages.default` flag) instead of the package's stock behavior of falling back to the static `config('app.fallback_locale')` — the two were previously disconnected, so changing the default language via the Filament **Languages** resource had no effect on which locale an untranslated storefront label silently fell back to. Swapped in automatically via `config('translation-loader.model')` in `LocalizationServiceProvider::register()`; no consuming app changes needed. Documented in `docs/localization.md` ("Fallback locale follows the store's default language").
|
- `Modules\Core\Localization\Models\LanguageLine` extends `spatie/laravel-translation-loader`'s `LanguageLine` to fall back to the store's actual default language (`LanguageCache::defaultLocale()`, backed by Lunar's `languages.default` flag) instead of the package's stock behavior of falling back to the static `config('app.fallback_locale')` — the two were previously disconnected, so changing the default language via the Filament **Languages** resource had no effect on which locale an untranslated storefront label silently fell back to. Swapped in automatically via `config('translation-loader.model')` in `LocalizationServiceProvider::register()`; no consuming app changes needed. Documented in `docs/localization.md` ("Fallback locale follows the store's default language").
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|
||||||
- **Breaking:** `Modules\Core\Catalog\ProductService::list()` now returns a real `Illuminate\Pagination\LengthAwarePaginator` (built from the localized Meilisearch hits) instead of a plain `array{data, meta}` — gives callers normal Laravel pagination behaviour (`$products->links()`, standard JSON serialization) without ever touching Scout's raw `paginateRaw()` response directly. `getById()`/`getBySlug()` are unaffected (still return `?array`).
|
- **Breaking:** `Modules\Core\Catalog\ProductService::list()` now returns a real `Illuminate\Pagination\LengthAwarePaginator` (built from the localized Meilisearch hits) instead of a plain `array{data, meta}` — gives callers normal Laravel pagination behaviour (`$products->links()`, standard JSON serialization) without ever touching Scout's raw `paginateRaw()` response directly. `getById()`/`getBySlug()` are unaffected (still return `?array`).
|
||||||
- `ProductService::withLocalizedFields()` (used by `list()`, `getById()`, `getBySlug()`) no longer hardcodes `name`/`description` as the only translated fields — it now reads every `TranslatedText` attribute on `Product` from `Lunar\Base\AttributeManifest` (the same source Lunar's own indexer reads), so a store's own custom translated attributes (e.g. `seo_title`, `seo_description`) are resolved and locale-stripped automatically with no code change here. Raw `{handle}_{locale}` keys (e.g. `name_el`, `seo_title_en`) are now stripped from every returned product, not just `name_*`/`description_*`.
|
- `ProductService::withLocalizedFields()` (used by `list()`, `getById()`, `getBySlug()`) no longer hardcodes `name`/`description` as the only translated fields — it now reads every `TranslatedText` attribute on `Product` from `Lunar\Base\AttributeManifest` (the same source Lunar's own indexer reads), so a store's own custom translated attributes (e.g. `seo_title`, `seo_description`) are resolved and locale-stripped automatically with no code change here. Raw `{handle}_{locale}` keys (e.g. `name_el`, `seo_title_en`) are now stripped from every returned product, not just `name_*`/`description_*`.
|
||||||
- Extracted `Modules\Core\Localization\Services\LanguageCache` (cached read layer over Lunar's `languages` table: `all()`, `defaultLocale()`, `availableLocales()`, `forget()`) out of `LocaleMiddleware`, which previously owned this as private/static methods despite not being middleware-specific behavior. `LocaleMiddleware` now takes `LanguageCache` via constructor injection. `LocaleMiddleware::defaultLocale()`/`forgetLanguagesCache()` (static) are removed — use `app(LanguageCache::class)` or inject `LanguageCache` directly.
|
- Extracted `Modules\Core\Localization\Services\LanguageCache` (cached read layer over Lunar's `languages` table: `all()`, `defaultLocale()`, `availableLocales()`, `forget()`) out of `LocaleMiddleware`, which previously owned this as private/static methods despite not being middleware-specific behavior. `LocaleMiddleware` now takes `LanguageCache` via constructor injection. `LocaleMiddleware::defaultLocale()`/`forgetLanguagesCache()` (static) are removed — use `app(LanguageCache::class)` or inject `LanguageCache` directly.
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- `Modules\Core\MigrateImport\JudgeMe\Resolvers\ProductResolver::resolve()` picked whichever `lunar_urls` row matched a slug first, which can be a soft-deleted product left behind by an earlier import batch rather than the current live one — a store can easily end up with more than one `Product` row sharing the same slug across re-imports, since a soft-deleted product's URL row isn't cleaned up. This silently broke every downstream lookup for that handle (e.g. `Modules\Core\MigrateImport\JudgeMe\JudgeMeExportImporter` logging "no product found for handle, skipping review" and dropping the row, even though a live product with that exact handle existed). Rewrote as a join against `lunar_products` — via `Product::query()`, so Eloquent's `SoftDeletes` global scope excludes trashed rows — so only a URL pointing at a live product resolves.
|
- `Modules\Core\MigrateImport\JudgeMe\Resolvers\ProductResolver::resolve()` picked whichever `lunar_urls` row matched a slug first, which can be a soft-deleted product left behind by an earlier import batch rather than the current live one — a store can easily end up with more than one `Product` row sharing the same slug across re-imports, since a soft-deleted product's URL row isn't cleaned up. This silently broke every downstream lookup for that handle (e.g. `Modules\Core\MigrateImport\JudgeMe\JudgeMeExportImporter` logging "no product found for handle, skipping review" and dropping the row, even though a live product with that exact handle existed). Rewrote as a join against `lunar_products` — via `Product::query()`, so Eloquent's `SoftDeletes` global scope excludes trashed rows — so only a URL pointing at a live product resolves.
|
||||||
- `Modules\Core\Review\Models\ProductReview` had no `registerMediaConversions()` at all, unlike `Product`/`ProductVariant` which get one automatically from Lunar's own `Lunar\Base\StandardMediaDefinitions`. `Modules\Core\Search\ProductIndexer::mapMedia()` is shared across product, variant, and review media and always requests the `small` conversion — the first time a review had an attached image, indexing it threw `Spatie\MediaLibrary\MediaCollections\Exceptions\InvalidConversion`, silently failing the product's `MakeSearchable` queue job (and everything queued after it, since Scout batches). Added a matching `small` conversion (300×300, same fit/border/background as Lunar's standard one) directly on `ProductReview`.
|
- `Modules\Core\Review\Models\ProductReview` had no `registerMediaConversions()` at all, unlike `Product`/`ProductVariant` which get one automatically from Lunar's own `Lunar\Base\StandardMediaDefinitions`. `Modules\Core\Search\ProductIndexer::mapMedia()` is shared across product, variant, and review media and always requests the `small` conversion — the first time a review had an attached image, indexing it threw `Spatie\MediaLibrary\MediaCollections\Exceptions\InvalidConversion`, silently failing the product's `MakeSearchable` queue job (and everything queued after it, since Scout batches). Added a matching `small` conversion (300×300, same fit/border/background as Lunar's standard one) directly on `ProductReview`.
|
||||||
|
|
||||||
### Breaking
|
### Breaking
|
||||||
|
|
||||||
- Merged `Modules\Core\Catalog` and `Modules\Core\Search` into a single `Modules\Core\Product` concern, since both existed purely to serve `Product` (browsing/filtering vs. indexing/full-text search — two services, one concern), following a stricter subfolder convention (`Contracts/`, `Enums/`, `Services/`, `DTOs/`, `Models/`, etc. per concern) going forward:
|
- Merged `Modules\Core\Catalog` and `Modules\Core\Search` into a single `Modules\Core\Product` concern, since both existed purely to serve `Product` (browsing/filtering vs. indexing/full-text search — two services, one concern), following a stricter subfolder convention (`Contracts/`, `Enums/`, `Services/`, `DTOs/`, `Models/`, etc. per concern) going forward:
|
||||||
- `Modules\Core\Catalog\ProductService` → `Modules\Core\Product\Services\ProductService`
|
- `Modules\Core\Catalog\ProductService` → `Modules\Core\Product\Services\ProductService`
|
||||||
- `Modules\Core\Catalog\ProductFilters` → `Modules\Core\Product\DTOs\ProductFilters`
|
- `Modules\Core\Catalog\ProductFilters` → `Modules\Core\Product\DTOs\ProductFilters`
|
||||||
@@ -655,6 +1121,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
- `Modules\Core\Search\ProductSearchService` → `Modules\Core\Product\Services\ProductSearchService`
|
- `Modules\Core\Search\ProductSearchService` → `Modules\Core\Product\Services\ProductSearchService`
|
||||||
|
|
||||||
Consuming apps must update any direct references — notably `config/lunar/search.php`'s `'indexers'` map, which points at `ProductIndexer` by FQCN. `Modules\Core\Catalog\ProductOptionTypeInterface` (in-progress, not yet wired to anything) was deliberately left in place rather than moved.
|
Consuming apps must update any direct references — notably `config/lunar/search.php`'s `'indexers'` map, which points at `ProductIndexer` by FQCN. `Modules\Core\Catalog\ProductOptionTypeInterface` (in-progress, not yet wired to anything) was deliberately left in place rather than moved.
|
||||||
|
|
||||||
- Reorganized `Modules\Core\Localization` under the same stricter per-concern subfolder convention — `Events/`, `Filament/`, `Listeners/` were already correctly categorized; four loose root files moved into typed buckets by structural role:
|
- Reorganized `Modules\Core\Localization` under the same stricter per-concern subfolder convention — `Events/`, `Filament/`, `Listeners/` were already correctly categorized; four loose root files moved into typed buckets by structural role:
|
||||||
- `Modules\Core\Localization\LocaleMiddleware` → `Modules\Core\Localization\Middleware\LocaleMiddleware`
|
- `Modules\Core\Localization\LocaleMiddleware` → `Modules\Core\Localization\Middleware\LocaleMiddleware`
|
||||||
- `Modules\Core\Localization\LanguageCacheObserver` → `Modules\Core\Localization\Observers\LanguageCacheObserver`
|
- `Modules\Core\Localization\LanguageCacheObserver` → `Modules\Core\Localization\Observers\LanguageCacheObserver`
|
||||||
@@ -666,26 +1133,31 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
## [0.5.4] - 2026-08-26
|
## [0.5.4] - 2026-08-26
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Catalog\ProductService::list()` accepts a `sort` parameter (new `ProductSort` enum: `PriceAsc`, `PriceDesc`, `Newest`), translated into a Meilisearch `sort` clause — `list()` previously had no way to order results, since it always searches with an empty query string and so has no relevance score to fall back on. `Modules\Core\Search\ProductIndexer::getSortableFields()` now also marks `price` sortable (Lunar's base indexer only marks `created_at`/`updated_at`/`skus`/`status`). Requires re-syncing index settings (`php artisan lunar:meilisearch:setup`) on existing stores. Documented in `docs/product-listing.md` ("Sorting").
|
- `Modules\Core\Catalog\ProductService::list()` accepts a `sort` parameter (new `ProductSort` enum: `PriceAsc`, `PriceDesc`, `Newest`), translated into a Meilisearch `sort` clause — `list()` previously had no way to order results, since it always searches with an empty query string and so has no relevance score to fall back on. `Modules\Core\Search\ProductIndexer::getSortableFields()` now also marks `price` sortable (Lunar's base indexer only marks `created_at`/`updated_at`/`skus`/`status`). Requires re-syncing index settings (`php artisan lunar:meilisearch:setup`) on existing stores. Documented in `docs/product-listing.md` ("Sorting").
|
||||||
|
|
||||||
## [0.5.3] - 2026-08-26
|
## [0.5.3] - 2026-08-26
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- `Modules\Core\Search\ProductIndexer::toSearchableArray()` threw `column reference "id" is ambiguous` on Postgres when computing `channel_ids` — `$model->channels()->wherePivot('enabled', true)->pluck('id')` joins `lunar_channels` and `lunar_channelables`, both of which have an `id` column, and the unqualified `pluck('id')` left Postgres unable to resolve which table's column to select (SQLite/MySQL tolerated the ambiguity). Qualified as `pluck('lunar_channels.id')`.
|
- `Modules\Core\Search\ProductIndexer::toSearchableArray()` threw `column reference "id" is ambiguous` on Postgres when computing `channel_ids` — `$model->channels()->wherePivot('enabled', true)->pluck('id')` joins `lunar_channels` and `lunar_channelables`, both of which have an `id` column, and the unqualified `pluck('id')` left Postgres unable to resolve which table's column to select (SQLite/MySQL tolerated the ambiguity). Qualified as `pluck('lunar_channels.id')`.
|
||||||
|
|
||||||
## [0.5.2] - 2026-08-26
|
## [0.5.2] - 2026-08-26
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- `Modules\Core\Localization\LocaleMiddleware`'s shared view data only ever surfaced a single alternate locale (`altLocale`/`altLocaleUrl`, found via `firstWhere('code', '!=', $current)`) — correct by coincidence for a 2-language store, but silently dropped every locale past the first "other" one found for a 3+ language store, with no error. Replaced with `altLocales`, a collection of every other configured language (`code`, `name`, `url` for the current route each), so a language switcher or `hreflang` tags scale to any number of locales. Documented in `docs/localization.md` ("Shared view data — language switcher and `hreflang` tags").
|
- `Modules\Core\Localization\LocaleMiddleware`'s shared view data only ever surfaced a single alternate locale (`altLocale`/`altLocaleUrl`, found via `firstWhere('code', '!=', $current)`) — correct by coincidence for a 2-language store, but silently dropped every locale past the first "other" one found for a 3+ language store, with no error. Replaced with `altLocales`, a collection of every other configured language (`code`, `name`, `url` for the current route each), so a language switcher or `hreflang` tags scale to any number of locales. Documented in `docs/localization.md` ("Shared view data — language switcher and `hreflang` tags").
|
||||||
|
|
||||||
## [0.5.1] - 2026-08-25
|
## [0.5.1] - 2026-08-25
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- `Modules\Core\Search\ProductIndexer` now indexes `channel_ids` (filterable) — Lunar's base indexer only marks `status` as filterable, not channel assignment, so storefront search couldn't otherwise scope results to products actually assigned and enabled on the current sales channel. Computed from `$product->channels()->wherePivot('enabled', true)`. Ported from an older `Products` branch whose remote had been deleted; the branch's other, now-superseded `ProductIndexer` changes were dropped in favor of the richer indexer already on `master` (collections, price, variants, reviews — see `0.5.0`).
|
- `Modules\Core\Search\ProductIndexer` now indexes `channel_ids` (filterable) — Lunar's base indexer only marks `status` as filterable, not channel assignment, so storefront search couldn't otherwise scope results to products actually assigned and enabled on the current sales channel. Computed from `$product->channels()->wherePivot('enabled', true)`. Ported from an older `Products` branch whose remote had been deleted; the branch's other, now-superseded `ProductIndexer` changes were dropped in favor of the richer indexer already on `master` (collections, price, variants, reviews — see `0.5.0`).
|
||||||
|
|
||||||
## [0.5.0] - 2026-08-24
|
## [0.5.0] - 2026-08-24
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- **`Modules\Core\Catalog\ProductService`**: storefront product listing/filtering (`list()`) and single-product lookup (`getById()`, `getBySlug()`), reading directly from the Meilisearch index rather than the database — one data source, no `->get()` model hydration. Returns plain arrays (not Eloquent models), meant to be called directly from a consuming app's controllers.
|
- **`Modules\Core\Catalog\ProductService`**: storefront product listing/filtering (`list()`) and single-product lookup (`getById()`, `getBySlug()`), reading directly from the Meilisearch index rather than the database — one data source, no `->get()` model hydration. Returns plain arrays (not Eloquent models), meant to be called directly from a consuming app's controllers.
|
||||||
- `ProductFilters` DTO: optional `collectionId`, `brand`, `minPrice`, `maxPrice`, translated into a Meilisearch `filter` expression.
|
- `ProductFilters` DTO: optional `collectionId`, `brand`, `minPrice`, `maxPrice`, translated into a Meilisearch `filter` expression.
|
||||||
- Listing results are locale-aware: `withLocalizedFields()` resolves `name`/`description` from the indexer's per-locale fields, falling back to the store's default language (via `LocaleMiddleware::defaultLocale()`) when the current locale has no translation yet, instead of rendering blank.
|
- Listing results are locale-aware: `withLocalizedFields()` resolves `name`/`description` from the indexer's per-locale fields, falling back to the store's default language (via `LocaleMiddleware::defaultLocale()`) when the current locale has no translation yet, instead of rendering blank.
|
||||||
@@ -696,26 +1168,29 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
- `docs/lunar.md` "Gotchas": three new entries hit while building this — `ProductOption`/`ProductOptionValue::name` isn't `attribute_data` (so `translateAttribute()` silently returns `null` for it), a running `queue:work` process not picking up an edited Scout indexer class, and Scout's `paginateRaw()->items()` on the Meilisearch driver returning the whole raw response rather than a hit list.
|
- `docs/lunar.md` "Gotchas": three new entries hit while building this — `ProductOption`/`ProductOptionValue::name` isn't `attribute_data` (so `translateAttribute()` silently returns `null` for it), a running `queue:work` process not picking up an edited Scout indexer class, and Scout's `paginateRaw()->items()` on the Meilisearch driver returning the whole raw response rather than a hit list.
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- The admin login form (`Modules\Core\Auth\Filament\Pages\Login`) had no way back from the OTP-entry step to the email step short of reloading the page. A `back()` method resets to the email step; a "← Back" link/button is shown on the OTP step only.
|
- The admin login form (`Modules\Core\Auth\Filament\Pages\Login`) had no way back from the OTP-entry step to the email step short of reloading the page. A `back()` method resets to the email step; a "← Back" link/button is shown on the OTP step only.
|
||||||
|
|
||||||
## [0.4.0] - 2026-08-06
|
## [0.4.0] - 2026-08-06
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- **Locale-prefixed routing** (`Modules\Core\Localization\LocaleMiddleware`): a `locale` route-middleware alias, opt-in per shop (not pushed onto the `web` group globally, since admin/Livewire/webhook routes must not be locale-redirected). Reads the first URL segment against Lunar's own `languages` table, sets `App::setLocale()`, and redirects unprefixed/unknown-locale requests to a resolved locale (`Accept-Language` match → default language → first language). Every locale is prefixed, including the default (`/el/...`, `/en/...`), never a bare root — avoids the hreflang/duplicate-content ambiguity of a bare-root default locale.
|
- **Locale-prefixed routing** (`Modules\Core\Localization\LocaleMiddleware`): a `locale` route-middleware alias, opt-in per shop (not pushed onto the `web` group globally, since admin/Livewire/webhook routes must not be locale-redirected). Reads the first URL segment against Lunar's own `languages` table, sets `App::setLocale()`, and redirects unprefixed/unknown-locale requests to a resolved locale (`Accept-Language` match → default language → first language). Every locale is prefixed, including the default (`/el/...`, `/en/...`), never a bare root — avoids the hreflang/duplicate-content ambiguity of a bare-root default locale.
|
||||||
- Language list cached with `Cache::rememberForever()`, invalidated via `Modules\Core\Localization\LanguageCacheObserver` dispatching `LanguageCreated`/`LanguageUpdated`/`LanguageDeleted` events (see below) rather than doing the work itself.
|
- Language list cached with `Cache::rememberForever()`, invalidated via `Modules\Core\Localization\LanguageCacheObserver` dispatching `LanguageCreated`/`LanguageUpdated`/`LanguageDeleted` events (see below) rather than doing the work itself.
|
||||||
- **Language rename safety**: renaming a `Language::code` (e.g. `el` → `gr`) no longer strands existing translations. `MigrateTranslationsForRenamedLanguage` (listening on `LanguageUpdated`) migrates every affected `LanguageLine.text` key from the old code to the new one and flushes both codes' translation caches — closing a real data-loss gap where a rename would otherwise make existing `LanguageLine` translations permanently unreachable.
|
- **Language rename safety**: renaming a `Language::code` (e.g. `el` → `gr`) no longer strands existing translations. `MigrateTranslationsForRenamedLanguage` (listening on `LanguageUpdated`) migrates every affected `LanguageLine.text` key from the old code to the new one and flushes both codes' translation caches — closing a real data-loss gap where a rename would otherwise make existing `LanguageLine` translations permanently unreachable.
|
||||||
- **Storefront UI label translations**: pulled in `spatie/laravel-translation-loader` (self-registers via Composer package auto-discovery; its loader *extends* Laravel's file-based `FileLoader` and merges DB translations on top — existing Filament/Lunar vendor `lang/` strings are unaffected). Labels are looked up via Laravel's native `__('storefront.nav.cart')`, kept in its own `storefront` group so nothing collides with Lunar/Filament's own translation groups.
|
- **Storefront UI label translations**: pulled in `spatie/laravel-translation-loader` (self-registers via Composer package auto-discovery; its loader _extends_ Laravel's file-based `FileLoader` and merges DB translations on top — existing Filament/Lunar vendor `lang/` strings are unaffected). Labels are looked up via Laravel's native `__('storefront.nav.cart')`, kept in its own `storefront` group so nothing collides with Lunar/Filament's own translation groups.
|
||||||
- `Modules\Core\Command\InstallLunarCommand` (overriding `lunar:install`) seeds a starter set of ~15 common e-shop labels (`nav.*`, `cart.*`, `product.*`, `auth.*`, `search.*`, English + Greek), idempotently guarded so it's safe on every boot.
|
- `Modules\Core\Command\InstallLunarCommand` (overriding `lunar:install`) seeds a starter set of ~15 common e-shop labels (`nav.*`, `cart.*`, `product.*`, `auth.*`, `search.*`, English + Greek), idempotently guarded so it's safe on every boot.
|
||||||
- `Modules\Core\Localization\TranslationReader::group('storefront')` returns the whole reduced/cached label array for a locale (backed by `LanguageLine`'s own forever-cache) — for sharing to a view as `$labels` or `@json()`-ing to JS, on top of `__()` for single-key Blade lookups.
|
- `Modules\Core\Localization\TranslationReader::group('storefront')` returns the whole reduced/cached label array for a locale (backed by `LanguageLine`'s own forever-cache) — for sharing to a view as `$labels` or `@json()`-ing to JS, on top of `__()` for single-key Blade lookups.
|
||||||
- **Admin UI**: `Modules\Core\Localization\Filament\Resources\LanguageLineResource` (registered in `CorePlugin`) lists/searches/filters `language_lines` and edits each row's `group`, `key`, and one text input per locale currently in `lunar_languages` — locale columns/inputs are generated dynamically from the language list, so a new language needs no resource changes.
|
- **Admin UI**: `Modules\Core\Localization\Filament\Resources\LanguageLineResource` (registered in `CorePlugin`) lists/searches/filters `language_lines` and edits each row's `group`, `key`, and one text input per locale currently in `lunar_languages` — locale columns/inputs are generated dynamically from the language list, so a new language needs no resource changes.
|
||||||
- **Event-driven writes**: `Modules\Core\Localization\TranslationService` (`create`/`update`/`delete`) is the single write path for `LanguageLine` — the Filament resource's Create/Edit/Delete pages route through it rather than Filament's default direct-model writes. Dispatches `TranslationCreated`/`TranslationUpdated` (carries the full pre-update `{group, key, text}` snapshot, so a bare rename is tracked the same as a text edit)/`TranslationDeleted`, each handled by two listeners:
|
- **Event-driven writes**: `Modules\Core\Localization\TranslationService` (`create`/`update`/`delete`) is the single write path for `LanguageLine` — the Filament resource's Create/Edit/Delete pages route through it rather than Filament's default direct-model writes. Dispatches `TranslationCreated`/`TranslationUpdated` (carries the full pre-update `{group, key, text}` snapshot, so a bare rename is tracked the same as a text edit)/`TranslationDeleted`, each handled by two listeners:
|
||||||
- `FlushTranslationCache` — closes a real gap in `LanguageLine`'s own self-invalidation, which only flushes locales/groups present *after* a save. Flushes the union of old and new group+locale combinations, so a locale removed from `text`, or a `group`/`key` rename, can't leave a stale cached array behind.
|
- `FlushTranslationCache` — closes a real gap in `LanguageLine`'s own self-invalidation, which only flushes locales/groups present _after_ a save. Flushes the union of old and new group+locale combinations, so a locale removed from `text`, or a `group`/`key` rename, can't leave a stale cached array behind.
|
||||||
- `LogTranslationActivity` — audits every write via the existing `Modules\Core\Logging\ActivityLogService` (`lunar` activity log channel), same `created`/`updated`/`deleted` shape as every other domain write in this project. Properties are flattened with `Arr::dot()` before logging (`text.en`, `text.el` instead of a nested `text` object) since Filament's Activity resource renders `properties` with a flat `KeyValue` field that can't display nested arrays.
|
- `LogTranslationActivity` — audits every write via the existing `Modules\Core\Logging\ActivityLogService` (`lunar` activity log channel), same `created`/`updated`/`deleted` shape as every other domain write in this project. Properties are flattened with `Arr::dot()` before logging (`text.en`, `text.el` instead of a nested `text` object) since Filament's Activity resource renders `properties` with a flat `KeyValue` field that can't display nested arrays.
|
||||||
- `Modules\Core\Providers\LocalizationServiceProvider` — split out of the growing `CoreServiceProvider` (per this project's own "split when a provider does too much" convention) to own all locale/translation middleware, observer, and event-listener registration.
|
- `Modules\Core\Providers\LocalizationServiceProvider` — split out of the growing `CoreServiceProvider` (per this project's own "split when a provider does too much" convention) to own all locale/translation middleware, observer, and event-listener registration.
|
||||||
|
|
||||||
## [0.3.0] - 2026-07-12
|
## [0.3.0] - 2026-07-12
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- **Meilisearch product search**: pulled in `lunarphp/search` (Lunar's driver-agnostic search abstraction — `database`/`meilisearch`/`typesense` engines, selectable via Scout's own `SCOUT_DRIVER` config) and `lunarphp/meilisearch`, wiring Meilisearch in as the search engine for products.
|
- **Meilisearch product search**: pulled in `lunarphp/search` (Lunar's driver-agnostic search abstraction — `database`/`meilisearch`/`typesense` engines, selectable via Scout's own `SCOUT_DRIVER` config) and `lunarphp/meilisearch`, wiring Meilisearch in as the search engine for products.
|
||||||
- `Search\ProductIndexer` overrides Lunar's own indexer to strip HTML tags from string fields (e.g. `name_en`, `description_en`) before they reach the search index — Lunar's default indexer sends raw attribute HTML straight through, which pollutes relevance ranking and highlighting with markup.
|
- `Search\ProductIndexer` overrides Lunar's own indexer to strip HTML tags from string fields (e.g. `name_en`, `description_en`) before they reach the search index — Lunar's default indexer sends raw attribute HTML straight through, which pollutes relevance ranking and highlighting with markup.
|
||||||
- Meilisearch itself is treated as app-level infrastructure, not a `boboko-core` concern: the actual Meilisearch container, host port, and master key live in each consuming app's own `docker-compose.yml`/`.env` (e.g. `3dealer`), the same way Postgres and Valkey do — `boboko-core` only declares the PHP package dependency and the indexing code.
|
- Meilisearch itself is treated as app-level infrastructure, not a `boboko-core` concern: the actual Meilisearch container, host port, and master key live in each consuming app's own `docker-compose.yml`/`.env` (e.g. `3dealer`), the same way Postgres and Valkey do — `boboko-core` only declares the PHP package dependency and the indexing code.
|
||||||
@@ -723,17 +1198,20 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
## [0.2.0] - 2026-07-10
|
## [0.2.0] - 2026-07-10
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- **Product reviews** (`Modules\Core\Review`): a new `ProductReview` model + `product_reviews` table (plain, unprefixed — same convention as `import_mappings`), linked to Lunar's `Product` via a `Product::reviews()` macro (registered in `CorePlugin`, since `Lunar\Models\Product` is a vendor model and can't be edited directly).
|
- **Product reviews** (`Modules\Core\Review`): a new `ProductReview` model + `product_reviews` table (plain, unprefixed — same convention as `import_mappings`), linked to Lunar's `Product` via a `Product::reviews()` macro (registered in `CorePlugin`, since `Lunar\Models\Product` is a vendor model and can't be edited directly).
|
||||||
- **JudgeMe CSV review importer** (`MigrateImport\JudgeMe\JudgeMeExportImporter`), wired into the existing `boboko:migrate:import --source=judgeme --type=export` command: reads a Judge.me review export, resolves each row's `product_handle` to a Lunar product via `Lunar\Models\Url`, and creates/updates `ProductReview` rows idempotently via `import_mappings` (`source=judgeme`, `source_type=review`, keyed on Judge.me's `metaobject_handle`). Rows with no matching product are skipped with a logged warning rather than failing the whole import.
|
- **JudgeMe CSV review importer** (`MigrateImport\JudgeMe\JudgeMeExportImporter`), wired into the existing `boboko:migrate:import --source=judgeme --type=export` command: reads a Judge.me review export, resolves each row's `product_handle` to a Lunar product via `Lunar\Models\Url`, and creates/updates `ProductReview` rows idempotently via `import_mappings` (`source=judgeme`, `source_type=review`, keyed on Judge.me's `metaobject_handle`). Rows with no matching product are skipped with a logged warning rather than failing the whole import.
|
||||||
- Review images (`picture_urls` in the CSV) are downloaded and stored as real media via Spatie MediaLibrary (`ProductReview::IMAGES_COLLECTION`), not just linked by URL — consistent with how product images are handled.
|
- Review images (`picture_urls` in the CSV) are downloaded and stored as real media via Spatie MediaLibrary (`ProductReview::IMAGES_COLLECTION`), not just linked by URL — consistent with how product images are handled.
|
||||||
- **Admin UI**: a new "Reviews" sub-navigation page on the product edit screen (`Review\Pages\ManageProductReviews`, wired via `Review\Extensions\ProductResourceExtension`), listing rating/title/reviewer with View, Reply, and Delete actions. The Reply action lets staff write/edit a reply directly from the table, setting `replied_at`. The View modal shows full review detail (body, reviewer email, location, source, dates, reply, downloaded images).
|
- **Admin UI**: a new "Reviews" sub-navigation page on the product edit screen (`Review\Pages\ManageProductReviews`, wired via `Review\Extensions\ProductResourceExtension`), listing rating/title/reviewer with View, Reply, and Delete actions. The Reply action lets staff write/edit a reply directly from the table, setting `replied_at`. The View modal shows full review detail (body, reviewer email, location, source, dates, reply, downloaded images).
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- `Shopify\ShopifyExportImporter` never wrote a Lunar `Url` (slug) row for imported products, despite `docs/shopify-import.md` specifying it should — meaning no code outside the importer itself could resolve "which Lunar product has handle X" (only the importer's own private `import_mappings` bookkeeping could). It now creates/updates a default `Url` row (`slug` = Shopify handle) per product on every import, which the new JudgeMe review importer depends on for product resolution.
|
- `Shopify\ShopifyExportImporter` never wrote a Lunar `Url` (slug) row for imported products, despite `docs/shopify-import.md` specifying it should — meaning no code outside the importer itself could resolve "which Lunar product has handle X" (only the importer's own private `import_mappings` bookkeeping could). It now creates/updates a default `Url` row (`slug` = Shopify handle) per product on every import, which the new JudgeMe review importer depends on for product resolution.
|
||||||
|
|
||||||
## [0.1.0] - 2026-07-09
|
## [0.1.0] - 2026-07-09
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- **Shipping**: registered Lunar's `lunarphp/table-rate-shipping` plugin (`ShippingPlugin`) directly on `CorePlugin`, so table-rate shipping is available to every consumer app without per-app wiring.
|
- **Shipping**: registered Lunar's `lunarphp/table-rate-shipping` plugin (`ShippingPlugin`) directly on `CorePlugin`, so table-rate shipping is available to every consumer app without per-app wiring.
|
||||||
- **Product migration/import framework** (`Modules\Core\MigrateImport`): a source-agnostic pipeline for importing a vendor's product catalog into Lunar.
|
- **Product migration/import framework** (`Modules\Core\MigrateImport`): a source-agnostic pipeline for importing a vendor's product catalog into Lunar.
|
||||||
- `boboko:migrate:import` Artisan command — interactively prompts for source, type (export/API), and credentials or file path, then dispatches the import as a queued job (`RunMigrateImportJob`) on the default queue. The file-path prompt resolves relative to `storage/app/private/imports/`, so answering e.g. `shopify` picks up the first CSV found in `imports/shopify/` automatically.
|
- `boboko:migrate:import` Artisan command — interactively prompts for source, type (export/API), and credentials or file path, then dispatches the import as a queued job (`RunMigrateImportJob`) on the default queue. The file-path prompt resolves relative to `storage/app/private/imports/`, so answering e.g. `shopify` picks up the first CSV found in `imports/shopify/` automatically.
|
||||||
@@ -748,6 +1226,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
- `CONTRIBUTE.md` — local dev setup (path-repo + `bin/dc-core.sh`), and the manual DB-verification workflow used to build this feature.
|
- `CONTRIBUTE.md` — local dev setup (path-repo + `bin/dc-core.sh`), and the manual DB-verification workflow used to build this feature.
|
||||||
|
|
||||||
### Fixed
|
### Fixed
|
||||||
|
|
||||||
- `ProductOptionResolver` created duplicate `ProductOption`/`ProductOptionValue` rows when the same option or value appeared with different casing across products (e.g. Shopify export rows using both "Size" and "size"), and could create a duplicate value within a single product's own variant rows due to relying on a stale lazy-loaded relation. Both now resolve by normalized (slugified) identity queried fresh from the database.
|
- `ProductOptionResolver` created duplicate `ProductOption`/`ProductOptionValue` rows when the same option or value appeared with different casing across products (e.g. Shopify export rows using both "Size" and "size"), and could create a duplicate value within a single product's own variant rows due to relying on a stale lazy-loaded relation. Both now resolve by normalized (slugified) identity queried fresh from the database.
|
||||||
- `boboko:migrate:import` could dispatch an import job with a blank file path (silent no-op failure) if the file-path prompt was answered empty; it now re-prompts until a valid, existing file is given.
|
- `boboko:migrate:import` could dispatch an import job with a blank file path (silent no-op failure) if the file-path prompt was answered empty; it now re-prompts until a valid, existing file is given.
|
||||||
|
|
||||||
@@ -756,6 +1235,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
|
|||||||
First release.
|
First release.
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
||||||
- OTP-based authentication built around `User` instead of `Customer` (`UserOtpService`, `UserOtpMail`), replacing the earlier customer-scoped OTP flow.
|
- OTP-based authentication built around `User` instead of `Customer` (`UserOtpService`, `UserOtpMail`), replacing the earlier customer-scoped OTP flow.
|
||||||
- `UserCreated` event with a `CreateCustomerForUser` listener to provision a Lunar customer automatically when a user is created.
|
- `UserCreated` event with a `CreateCustomerForUser` listener to provision a Lunar customer automatically when a user is created.
|
||||||
- `UserRelationManager` for managing users from the customer resource in the panel.
|
- `UserRelationManager` for managing users from the customer resource in the panel.
|
||||||
@@ -766,7 +1246,9 @@ First release.
|
|||||||
- `docs/modules.md` documenting module structure.
|
- `docs/modules.md` documenting module structure.
|
||||||
|
|
||||||
### Removed
|
### Removed
|
||||||
|
|
||||||
- `CustomerOtpMail` and `CustomerOtpService`, superseded by the user-based OTP flow.
|
- `CustomerOtpMail` and `CustomerOtpService`, superseded by the user-based OTP flow.
|
||||||
|
|
||||||
### Dependencies
|
### Dependencies
|
||||||
|
|
||||||
- Added explicit `symfony/yaml` requirement (used directly by `Stoic::loadConfig()`).
|
- Added explicit `symfony/yaml` requirement (used directly by `Stoic::loadConfig()`).
|
||||||
|
|||||||
@@ -1,6 +1,9 @@
|
|||||||
# Core Module
|
# Core Module
|
||||||
|
|
||||||
A Laravel module providing authentication, notifications, activity logging, CLI tooling, and functional types on top of the [Lunar](https://lunarphp.io) admin panel. Designed to be consumed as a standalone Composer package.
|
A Laravel module providing authentication, localization, product search/catalog, privacy/GDPR
|
||||||
|
tooling, notifications, activity logging, CLI tooling, and functional types on top of the
|
||||||
|
[Lunar](https://lunarphp.io) e-commerce package. Designed to be consumed as a standalone Composer
|
||||||
|
package by any Lunar-based e-shop.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -8,13 +11,83 @@ A Laravel module providing authentication, notifications, activity logging, CLI
|
|||||||
|
|
||||||
### OTP Authentication
|
### OTP Authentication
|
||||||
|
|
||||||
Passwordless login for both staff (Lunar panel) and customers via 6-digit codes delivered by email. Codes expire after 10 minutes. The Lunar panel login page is a two-step flow: email → OTP. Rate-limited to 5 attempts.
|
Passwordless login for both staff (Lunar panel) and customers via 6-digit codes delivered by
|
||||||
|
email. Codes expire after 10 minutes, rate-limited to 5 attempts. The Lunar panel login page is a
|
||||||
|
two-step flow (email → OTP) with a back button to return from the code step to the email step.
|
||||||
|
|
||||||
See [`docs/otp-auth.md`](docs/otp-auth.md).
|
See [`docs/otp-auth.md`](docs/otp-auth.md).
|
||||||
|
|
||||||
|
### Localization
|
||||||
|
|
||||||
|
Locale-prefixed routing (`Modules\Core\Localization\LocaleMiddleware`) — a `locale` route
|
||||||
|
middleware, opt-in per shop, that resolves and redirects to the correct language segment
|
||||||
|
(`/el/...`, `/en/...`) based on Lunar's own language list, with caching and rename-safe
|
||||||
|
translation migration. Also brings in storefront UI label translations
|
||||||
|
(`spatie/laravel-translation-loader`) with an admin-editable `LanguageLine` resource.
|
||||||
|
|
||||||
|
See [`docs/localization.md`](docs/localization.md).
|
||||||
|
|
||||||
|
### Product Search & Catalog
|
||||||
|
|
||||||
|
Two complementary services on top of Meilisearch:
|
||||||
|
|
||||||
|
- **`Modules\Core\Search\ProductSearchService`** — locale-aware full-text product search.
|
||||||
|
- **`Modules\Core\Catalog\ProductService`** — listing/filtering (by collection, brand, price
|
||||||
|
range) and single-product lookup by id or slug, reading directly from the Meilisearch index
|
||||||
|
rather than the database.
|
||||||
|
|
||||||
|
Both are backed by `Modules\Core\Search\ProductIndexer`, which extends Lunar's own indexer with
|
||||||
|
collections, price, variants, media, tags, and reviews — everything needed for both a listing
|
||||||
|
page and a full product detail page from one index.
|
||||||
|
|
||||||
|
See [`docs/product-search.md`](docs/product-search.md) and
|
||||||
|
[`docs/product-listing.md`](docs/product-listing.md).
|
||||||
|
|
||||||
|
### Product Reviews
|
||||||
|
|
||||||
|
`Modules\Core\Review\ProductReview` — ratings/reviews with staff replies, a Filament sub-navigation
|
||||||
|
page on the product edit screen, and automatic re-indexing (via `ReviewServiceProvider`) whenever
|
||||||
|
a review is created, updated, or deleted, so a product's Meilisearch document never goes stale.
|
||||||
|
|
||||||
|
### Privacy / GDPR Data-Subject Requests
|
||||||
|
|
||||||
|
Right of access (export) and right of erasure, built as an extensible contract
|
||||||
|
(`Modules\Core\Privacy\Contracts\PersonalDataProvider`) rather than a fixed table list — any
|
||||||
|
module can register its own data without core knowing it exists.
|
||||||
|
|
||||||
|
- **Two independent scopes**: erasing/exporting a Lunar `Customer` (business account) is never
|
||||||
|
the same operation as erasing/exporting a `User` (individual login) — a `Customer` erasure
|
||||||
|
never touches any linked `User`'s login, and a `User` erasure never touches a `Customer`
|
||||||
|
account's own data. See `docs/privacy.md` "User-scope vs Customer-scope".
|
||||||
|
- **Cancellable grace period** (default 30 days, configurable) before anything is actually
|
||||||
|
erased — logging back in during the window automatically reverts the request, mirroring
|
||||||
|
Shopify's own account-deletion flow. Immediate erasure exists but is staff-only by type, never
|
||||||
|
reachable from a self-service flow.
|
||||||
|
- **Sole-owner cascade**: erasing the last remaining `User` on a `Customer` also opens a (grace
|
||||||
|
period) erasure request for that now-orphaned `Customer`, so its PII doesn't sit unreachable
|
||||||
|
forever — traced back to the triggering request so login-reactivation can revert exactly that
|
||||||
|
cascade.
|
||||||
|
- **Queued export**: gathering data and writing a CSV-per-provider zip (via the generic,
|
||||||
|
reusable `Modules\Core\Export\CsvWriter`) runs as a background job; a consuming app hooks its
|
||||||
|
own notification onto the completion event via the Notification Registry (below).
|
||||||
|
|
||||||
|
See [`docs/privacy.md`](docs/privacy.md).
|
||||||
|
|
||||||
|
### Shopify Migration
|
||||||
|
|
||||||
|
`Modules\Core\MigrateImport\Shopify\ShopifyExportImporter` — imports a Shopify CSV product export
|
||||||
|
(products, variants, images, collections, tags, prices) into Lunar, idempotently re-runnable via
|
||||||
|
an `import_mappings` table. Part of a source-agnostic import framework
|
||||||
|
(`boboko:migrate:import`) designed to support additional sources later.
|
||||||
|
|
||||||
|
See [`docs/shopify-import.md`](docs/shopify-import.md).
|
||||||
|
|
||||||
### Notification Registry
|
### Notification Registry
|
||||||
|
|
||||||
An event-driven notification system. Each notification class declares which event it listens to and who to notify — the registry wires up the listener automatically. All notifications extend `BaseNotification` which implements `ShouldQueue`, so delivery is async. Supports optional delays.
|
An event-driven notification system. Each notification class declares which event it listens to
|
||||||
|
and who to notify — the registry wires up the listener automatically. All notifications extend
|
||||||
|
`BaseNotification`, which implements `ShouldQueue`, so delivery is async. Supports optional
|
||||||
|
delays.
|
||||||
|
|
||||||
**Creating a notification:**
|
**Creating a notification:**
|
||||||
|
|
||||||
@@ -33,9 +106,13 @@ class MyNotification extends BaseNotification
|
|||||||
NotificationRegistry::get()->register([MyNotification::class]);
|
NotificationRegistry::get()->register([MyNotification::class]);
|
||||||
```
|
```
|
||||||
|
|
||||||
|
See [`docs/notifications.md`](docs/notifications.md).
|
||||||
|
|
||||||
### Activity Logging
|
### Activity Logging
|
||||||
|
|
||||||
Thin wrapper around [Spatie Laravel Activity Log](https://github.com/spatie/laravel-activitylog). Four standardized methods: `created()`, `updated()`, `failed()`, `deleted()`. Logs to the `lunar` channel and auto-resolves the actor from the staff session.
|
Thin wrapper around [Spatie Laravel Activity Log](https://github.com/spatie/laravel-activitylog).
|
||||||
|
Four standardized methods: `created()`, `updated()`, `failed()`, `deleted()`. Logs to the `lunar`
|
||||||
|
channel and auto-resolves the actor from the staff session.
|
||||||
|
|
||||||
See [`docs/activity-log.md`](docs/activity-log.md).
|
See [`docs/activity-log.md`](docs/activity-log.md).
|
||||||
|
|
||||||
@@ -43,8 +120,11 @@ See [`docs/activity-log.md`](docs/activity-log.md).
|
|||||||
|
|
||||||
- Custom OTP login page replacing the default Lunar panel login
|
- Custom OTP login page replacing the default Lunar panel login
|
||||||
- `StaffResourceExtension` — removes password field from Lunar's staff resource
|
- `StaffResourceExtension` — removes password field from Lunar's staff resource
|
||||||
- `CustomerResourceExtension` — replaces default address relation manager with a custom implementation
|
- `CustomerResourceExtension` — replaces default address relation manager with a custom
|
||||||
- `CorePlugin` — configures panel path, branding, logos, navigation items, and activity log field exclusions for staff
|
implementation
|
||||||
|
- Table-rate shipping (`ShippingPlugin`) registered by default
|
||||||
|
- `CorePlugin` — configures panel path, branding, logos, navigation items, and activity log
|
||||||
|
field exclusions for staff
|
||||||
|
|
||||||
Register the plugin in your Lunar panel provider:
|
Register the plugin in your Lunar panel provider:
|
||||||
|
|
||||||
@@ -52,30 +132,36 @@ Register the plugin in your Lunar panel provider:
|
|||||||
->plugin(\Modules\Core\CorePlugin::make())
|
->plugin(\Modules\Core\CorePlugin::make())
|
||||||
```
|
```
|
||||||
|
|
||||||
|
See [`docs/lunar.md`](docs/lunar.md) for the full Lunar reference and non-obvious gotchas hit
|
||||||
|
while building against it.
|
||||||
|
|
||||||
### CLI Commands
|
### CLI Commands
|
||||||
|
|
||||||
| Command | Description |
|
| Command | Description |
|
||||||
|---|---|
|
|---|---|
|
||||||
| `core:create-admin` | Create a Lunar admin user |
|
| `boboko:anonymize` | Dummy-scrub personal data in `users`/`lunar_customers` for local dev safety (local environment only — **not** the GDPR erasure tool; see Privacy above for that) |
|
||||||
| `core:anonymize` | GDPR anonymization of users and customers (local only) |
|
| `boboko:export` | Dump database + storage files to a timestamped zip |
|
||||||
| `core:export` | Dump database + storage files to a timestamped zip |
|
| `boboko:import` | Restore from a `boboko:export` zip archive |
|
||||||
| `core:import` | Restore from a zip export (runs anonymize automatically, local only) |
|
| `boboko:export:cleanup` | Delete old export zips, keep N most recent |
|
||||||
| `core:export-cleanup` | Delete old export zips, keep N most recent |
|
| `boboko:migrate:import` | Import a vendor product catalog (Shopify, etc.) into Lunar |
|
||||||
|
| `boboko:privacy:process-erasure-requests` | Dispatch an erasure job for every due GDPR erasure request (wire into your own scheduler) |
|
||||||
|
| `lunar:create-admin` | Create a Lunar admin user (overrides Lunar's own command) |
|
||||||
|
| `lunar:install` | Seed default Lunar store data — countries, channel, currency, tax zone, attributes, product type (overrides Lunar's own command) |
|
||||||
|
|
||||||
### Functional Types
|
### Functional Types
|
||||||
|
|
||||||
Result and Option monads for explicit error handling without exceptions.
|
Result and Option types for explicit error handling without exceptions.
|
||||||
|
|
||||||
```php
|
```php
|
||||||
// Result<T, E>
|
// Result<T, E>
|
||||||
$result = Success::of($value);
|
$result = Success::create($value);
|
||||||
$result = Error::of('something went wrong');
|
$result = Error::create('something went wrong');
|
||||||
$result->map(fn($v) => ...)->flatMap(fn($v) => ...);
|
$result->map(fn($v) => ...)->flatMap(fn($v) => ...);
|
||||||
|
|
||||||
// Option<T>
|
// Option<T>
|
||||||
$option = Option::fromValue($nullableValue);
|
$option = Some::create($value);
|
||||||
$option->getOrElse('default');
|
$option = None::create();
|
||||||
$option->map(fn($v) => ...)->filter(fn($v) => $v > 0);
|
$option->map(fn($v) => ...);
|
||||||
```
|
```
|
||||||
|
|
||||||
---
|
---
|
||||||
@@ -102,17 +188,22 @@ Then run:
|
|||||||
|
|
||||||
```bash
|
```bash
|
||||||
composer require boboko/core
|
composer require boboko/core
|
||||||
|
php artisan vendor:publish --tag=core-config
|
||||||
php artisan vendor:publish --tag=core-assets
|
php artisan vendor:publish --tag=core-assets
|
||||||
php artisan migrate
|
php artisan migrate
|
||||||
```
|
```
|
||||||
|
|
||||||
|
For local core development alongside a consuming app (path-repo symlink + Docker mount), see
|
||||||
|
[`docs/modules.md`](docs/modules.md) "Docker Compose: the local-core mount".
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Requirements
|
## Requirements
|
||||||
|
|
||||||
- PHP 8.2+
|
- PHP 8.5+
|
||||||
- Laravel 11+
|
- Laravel 12+
|
||||||
- Lunar (lunarphp/lunar + lunarphp/admin)
|
- Lunar 1.3 (`lunarphp/lunar`)
|
||||||
|
- Meilisearch (for product search/listing/catalog)
|
||||||
- Spatie Laravel Activity Log
|
- Spatie Laravel Activity Log
|
||||||
|
|
||||||
---
|
---
|
||||||
@@ -120,7 +211,12 @@ php artisan migrate
|
|||||||
## Documentation
|
## Documentation
|
||||||
|
|
||||||
- [`docs/otp-auth.md`](docs/otp-auth.md) — OTP authentication flow
|
- [`docs/otp-auth.md`](docs/otp-auth.md) — OTP authentication flow
|
||||||
|
- [`docs/localization.md`](docs/localization.md) — Locale-prefixed routing and storefront translations
|
||||||
|
- [`docs/product-search.md`](docs/product-search.md) — Full-text product search
|
||||||
|
- [`docs/product-listing.md`](docs/product-listing.md) — Product listing/filtering/detail catalog service
|
||||||
|
- [`docs/privacy.md`](docs/privacy.md) — GDPR right of access/erasure, User-scope vs Customer-scope
|
||||||
|
- [`docs/shopify-import.md`](docs/shopify-import.md) — Shopify CSV → Lunar field mapping and import design
|
||||||
- [`docs/activity-log.md`](docs/activity-log.md) — Activity logging
|
- [`docs/activity-log.md`](docs/activity-log.md) — Activity logging
|
||||||
- [`docs/lunar.md`](docs/lunar.md) — Lunar framework reference
|
|
||||||
- [`docs/notifications.md`](docs/notifications.md) — Notification registry
|
- [`docs/notifications.md`](docs/notifications.md) — Notification registry
|
||||||
|
- [`docs/lunar.md`](docs/lunar.md) — Lunar framework reference and gotchas
|
||||||
- [`docs/modules.md`](docs/modules.md) — Module architecture, Customer/User pairing, provider registration pitfalls
|
- [`docs/modules.md`](docs/modules.md) — Module architecture, Customer/User pairing, provider registration pitfalls
|
||||||
|
|||||||
+4
-3
@@ -2,7 +2,7 @@
|
|||||||
"name": "boboko/core",
|
"name": "boboko/core",
|
||||||
"description": "Core module — authentication and shared panel behaviour",
|
"description": "Core module — authentication and shared panel behaviour",
|
||||||
"type": "library",
|
"type": "library",
|
||||||
"version": "0.17.1",
|
"version": "0.20.0",
|
||||||
"autoload": {
|
"autoload": {
|
||||||
"psr-4": {
|
"psr-4": {
|
||||||
"Modules\\Core\\": "src/"
|
"Modules\\Core\\": "src/"
|
||||||
@@ -18,7 +18,7 @@
|
|||||||
"lunarphp/search": "*",
|
"lunarphp/search": "*",
|
||||||
"lunarphp/meilisearch": "*",
|
"lunarphp/meilisearch": "*",
|
||||||
"spatie/laravel-translation-loader": "^2.8",
|
"spatie/laravel-translation-loader": "^2.8",
|
||||||
"lunarphp/stripe": "^1.5"
|
"stripe/stripe-php": "^16.6"
|
||||||
},
|
},
|
||||||
"require-dev": {
|
"require-dev": {
|
||||||
"fakerphp/faker": "^1.23",
|
"fakerphp/faker": "^1.23",
|
||||||
@@ -44,7 +44,8 @@
|
|||||||
"Modules\\Core\\Providers\\CartServiceProvider",
|
"Modules\\Core\\Providers\\CartServiceProvider",
|
||||||
"Modules\\Core\\Providers\\ReviewServiceProvider",
|
"Modules\\Core\\Providers\\ReviewServiceProvider",
|
||||||
"Modules\\Core\\Providers\\ShippingServiceProvider",
|
"Modules\\Core\\Providers\\ShippingServiceProvider",
|
||||||
"Modules\\Core\\Providers\\OrderServiceProvider"
|
"Modules\\Core\\Providers\\OrderServiceProvider",
|
||||||
|
"Modules\\Core\\Providers\\PrivacyServiceProvider"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -16,6 +16,43 @@ return [
|
|||||||
|
|
||||||
'auto_create_customer_for_user' => true,
|
'auto_create_customer_for_user' => true,
|
||||||
|
|
||||||
|
/*
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
| Privacy / GDPR data-subject requests
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| 'providers' lists every Modules\Core\Privacy\Contracts\PersonalDataProvider
|
||||||
|
| that should be consulted for right-of-access/right-of-erasure requests. A
|
||||||
|
| module never needs to be known to core in advance — it just adds its own
|
||||||
|
| provider class here, the same way config('lunar.search.indexers') maps a
|
||||||
|
| model to its indexer. See docs/privacy.md.
|
||||||
|
|
|
||||||
|
| 'grace_period_days' is how long an erasure request stays cancellable
|
||||||
|
| (account deactivated, not yet erased) before it's actually processed by
|
||||||
|
| the privacy:process-erasure-requests scheduled command.
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
|
||||||
|
'privacy' => [
|
||||||
|
'providers' => [
|
||||||
|
// ActivityLogDataProvider MUST run before AddressDataProvider —
|
||||||
|
// it resolves which activity_log rows belong to this customer
|
||||||
|
// (including ones keyed by an Address id) before
|
||||||
|
// AddressDataProvider hard-deletes those Address rows. See that
|
||||||
|
// provider's own class docblock.
|
||||||
|
\Modules\Core\Logging\Privacy\ActivityLogDataProvider::class,
|
||||||
|
\Modules\Core\Customer\Privacy\CustomerDataProvider::class,
|
||||||
|
\Modules\Core\Customer\Privacy\AddressDataProvider::class,
|
||||||
|
\Modules\Core\Order\Privacy\OrderDataProvider::class,
|
||||||
|
\Modules\Core\Cart\Privacy\CartDataProvider::class,
|
||||||
|
\Modules\Core\Review\Privacy\ReviewDataProvider::class,
|
||||||
|
\Modules\Core\Payment\Privacy\PaymentDataProvider::class,
|
||||||
|
\Modules\Core\Auth\Privacy\UserSessionDataProvider::class,
|
||||||
|
],
|
||||||
|
|
||||||
|
'grace_period_days' => 30,
|
||||||
|
],
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|--------------------------------------------------------------------------
|
|--------------------------------------------------------------------------
|
||||||
| Cart Abandonment Threshold
|
| Cart Abandonment Threshold
|
||||||
@@ -65,4 +102,29 @@ return [
|
|||||||
'return_window_days' => 14,
|
'return_window_days' => 14,
|
||||||
],
|
],
|
||||||
|
|
||||||
|
/*
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
| Storefront OTP Login
|
||||||
|
|--------------------------------------------------------------------------
|
||||||
|
|
|
||||||
|
| Modules\Core\Auth\Services\UserOtpService's passwordless login.
|
||||||
|
| max_attempts caps how many wrong codes a shopper can guess against ONE
|
||||||
|
| generated code before it's invalidated outright. generation_limit/
|
||||||
|
| generation_decay_minutes cap how often a NEW code can be requested for
|
||||||
|
| the same email — independent of max_attempts, since generating a fresh
|
||||||
|
| code also resets the guess count, so an attempt cap alone doesn't stop
|
||||||
|
| an attacker from just requesting a new code every few tries. This same
|
||||||
|
| limit is also what stands between a malicious/careless caller and
|
||||||
|
| mail-bombing one inbox.
|
||||||
|
|
|
||||||
|
*/
|
||||||
|
|
||||||
|
'auth' => [
|
||||||
|
'otp' => [
|
||||||
|
'max_attempts' => 5,
|
||||||
|
'generation_limit' => 3,
|
||||||
|
'generation_decay_minutes' => 10,
|
||||||
|
],
|
||||||
|
],
|
||||||
|
|
||||||
];
|
];
|
||||||
|
|||||||
@@ -13,12 +13,25 @@
|
|||||||
|
|
|
|
||||||
| Set these via environment variables — never commit real values.
|
| Set these via environment variables — never commit real values.
|
||||||
|
|
|
|
||||||
|
| Box Now has two environments (see their Partner API manual, section 2):
|
||||||
|
| Stage/Sandbox for testing, Production once live. Each has its own
|
||||||
|
| client_id/client_secret pair and its own base_url/location_api_url —
|
||||||
|
| there is no shared "switch an env var" flag, since stage credentials
|
||||||
|
| don't work against the production host or vice versa.
|
||||||
|
|
|
||||||
| BOXNOW_BASE_URL Root REST endpoint for delivery-requests/parcels.
|
| BOXNOW_BASE_URL Root REST endpoint for delivery-requests/parcels.
|
||||||
| BOXNOW_LOCATION_API_URL Separate, faster endpoint for origins/destinations
|
| BOXNOW_LOCATION_API_URL Separate, faster endpoint for origins/destinations
|
||||||
| lookups (Box Now recommends this over the main
|
| lookups (Box Now recommends this over the main
|
||||||
| base URL for those two calls specifically).
|
| base URL for those two calls specifically).
|
||||||
| BOXNOW_CLIENT_ID OAuth2 client id.
|
| BOXNOW_CLIENT_ID OAuth2 client id.
|
||||||
| BOXNOW_CLIENT_SECRET OAuth2 client secret.
|
| BOXNOW_CLIENT_SECRET OAuth2 client secret.
|
||||||
|
| BOXNOW_PARTNER_ID Numeric partnerId Box Now issues alongside your
|
||||||
|
| credentials. NOT used for REST API authentication
|
||||||
|
| (BoxNowClient authenticates with client_id/
|
||||||
|
| client_secret alone) — this is only consumed by
|
||||||
|
| the client-side Destination Map widget config
|
||||||
|
| (_bn_map_widget_config.partnerId), confirmed
|
||||||
|
| against Box Now's own WooCommerce plugin source.
|
||||||
| BOXNOW_ORIGIN_LOCATION_ID Your warehouse's Box Now locationId, used as
|
| BOXNOW_ORIGIN_LOCATION_ID Your warehouse's Box Now locationId, used as
|
||||||
| the pickup origin on every delivery request.
|
| the pickup origin on every delivery request.
|
||||||
| BOXNOW_SENDER_* Static sender contact details reused on every
|
| BOXNOW_SENDER_* Static sender contact details reused on every
|
||||||
@@ -33,6 +46,7 @@ return [
|
|||||||
|
|
||||||
'client_id' => env('BOXNOW_CLIENT_ID'),
|
'client_id' => env('BOXNOW_CLIENT_ID'),
|
||||||
'client_secret' => env('BOXNOW_CLIENT_SECRET'),
|
'client_secret' => env('BOXNOW_CLIENT_SECRET'),
|
||||||
|
'partner_id' => env('BOXNOW_PARTNER_ID'),
|
||||||
|
|
||||||
'origin_location_id' => env('BOXNOW_ORIGIN_LOCATION_ID'),
|
'origin_location_id' => env('BOXNOW_ORIGIN_LOCATION_ID'),
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,22 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->timestamp('deactivated_at')->nullable()->after('otp_expires_at');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('deactivated_at');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,56 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('data_erasure_requests', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
// Polymorphic, not a fixed customer_id — a request targets either a
|
||||||
|
// Lunar Customer (business account) or a User (individual), never
|
||||||
|
// both at once. See docs/privacy.md "User-scope vs Customer-scope".
|
||||||
|
$table->string('subject_type');
|
||||||
|
$table->unsignedBigInteger('subject_id');
|
||||||
|
// Snapshot, not a live-looked-up value — the subject's email may
|
||||||
|
// change or the record may be gone by the time this is read.
|
||||||
|
$table->string('email')->nullable();
|
||||||
|
// Who asked for this: the subject themselves (self-service deletion)
|
||||||
|
// or a staff member acting on their behalf. Plain nullable type+id
|
||||||
|
// columns rather than morphs() — only ever one of two concrete actor
|
||||||
|
// types, not an open-ended polymorphic set.
|
||||||
|
$table->string('requested_by_type');
|
||||||
|
$table->unsignedBigInteger('requested_by_id');
|
||||||
|
$table->string('status')->default('pending');
|
||||||
|
// Set only on a Customer-scoped request that was auto-created because
|
||||||
|
// erasing a User left them as the sole remaining user on that Customer
|
||||||
|
// (see Modules\Core\Privacy\Listeners\CascadeCustomerErasureListener).
|
||||||
|
// Null for every normal, directly-requested erasure. Lets login-
|
||||||
|
// reactivation find and revert exactly the Customer request THIS
|
||||||
|
// User's cancellation caused, without touching an unrelated,
|
||||||
|
// independently-requested Customer erasure the User happens to be
|
||||||
|
// linked to.
|
||||||
|
$table->foreignId('caused_by_request_id')->nullable()->constrained('data_erasure_requests')->nullOnDelete();
|
||||||
|
// now() + config('core.privacy.grace_period_days') at creation time —
|
||||||
|
// when privacy:process-erasure-requests will actually run this.
|
||||||
|
$table->timestamp('scheduled_for');
|
||||||
|
$table->timestamp('cancelled_at')->nullable();
|
||||||
|
$table->timestamp('completed_at')->nullable();
|
||||||
|
// Every provider's outcome, written once the request completes —
|
||||||
|
// see Modules\Core\Privacy\ErasureReport. Null until then.
|
||||||
|
$table->json('report')->nullable();
|
||||||
|
$table->timestamps();
|
||||||
|
|
||||||
|
$table->index(['status', 'scheduled_for']);
|
||||||
|
$table->index(['subject_type', 'subject_id']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('data_erasure_requests');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('data_export_requests', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
// Polymorphic, not a fixed customer_id — see data_erasure_requests
|
||||||
|
// for the same shape and reasoning.
|
||||||
|
$table->string('subject_type');
|
||||||
|
$table->unsignedBigInteger('subject_id');
|
||||||
|
// Snapshot, not a live lookup — same reasoning as
|
||||||
|
// data_erasure_requests.email (see that migration).
|
||||||
|
$table->string('email')->nullable();
|
||||||
|
$table->string('status')->default('pending');
|
||||||
|
// Storage path of the assembled export .zip, set once the queued job
|
||||||
|
// finishes. Null while pending.
|
||||||
|
$table->string('file_path')->nullable();
|
||||||
|
$table->timestamp('completed_at')->nullable();
|
||||||
|
$table->timestamps();
|
||||||
|
|
||||||
|
$table->index('status');
|
||||||
|
$table->index(['subject_type', 'subject_id']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('data_export_requests');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,46 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
use Lunar\Base\Migration;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* First-party copy of lunarphp/stripe's own create_stripe_payment_intents_table
|
||||||
|
* migration (package removed in favour of depending on stripe/stripe-php
|
||||||
|
* directly — see Modules\Core\Payment\Support\StripeManager and
|
||||||
|
* Modules\Core\Payment\Models\StripePaymentIntent, which replace the
|
||||||
|
* package's own classes over this same table). Timestamped to run just
|
||||||
|
* before this app's own add_context_to_stripe_payment_intents migration,
|
||||||
|
* which already alters this table.
|
||||||
|
*
|
||||||
|
* Guarded with hasTable(): on any environment that already ran
|
||||||
|
* lunarphp/stripe's own copy of this migration before the package was
|
||||||
|
* removed, the table already exists — this migration is only the one that
|
||||||
|
* actually creates it on a fresh install/database from now on.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
if (Schema::hasTable($this->prefix.'stripe_payment_intents')) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
Schema::create($this->prefix.'stripe_payment_intents', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
$table->foreignId('cart_id')->constrained($this->prefix.'carts');
|
||||||
|
$table->foreignId('order_id')->nullable()->constrained($this->prefix.'orders');
|
||||||
|
$table->string('intent_id')->index();
|
||||||
|
$table->string('status')->nullable();
|
||||||
|
$table->string('event_id')->index()->nullable();
|
||||||
|
$table->timestamp('processing_at')->nullable();
|
||||||
|
$table->timestamp('processed_at')->nullable();
|
||||||
|
$table->timestamps();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists($this->prefix.'stripe_payment_intents');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Caps brute-forcing a 6-digit OTP code (1M combinations, 10-minute
|
||||||
|
* window, previously uncapped) — see Modules\Core\Auth\Services\
|
||||||
|
* UserOtpService::validate(), which now invalidates the code entirely
|
||||||
|
* (forcing a fresh generateAndSend()) once otp_attempts reaches its max,
|
||||||
|
* rather than leaving a live code guessable indefinitely within its
|
||||||
|
* expiry window.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->unsignedTinyInteger('otp_attempts')->default(0)->after('otp_expires_at');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table('users', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('otp_attempts');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A per-login session registry, independent of the actual session store
|
||||||
|
* driver (SESSION_DRIVER=redis in this app — no "sessions" table to
|
||||||
|
* purge by user_id the way the database driver would allow). Each
|
||||||
|
* successful OTP login (Modules\Core\Auth\Services\UserOtpService::
|
||||||
|
* validate()) records one row here and stamps the token into the
|
||||||
|
* Laravel session payload; Modules\Core\Auth\Http\Middleware\
|
||||||
|
* EnsureSessionNotRevoked checks it on every request. "Logout
|
||||||
|
* everywhere" (Modules\Core\Auth\Services\UserSessionService::
|
||||||
|
* revokeOtherSessions()) is then just marking every OTHER row
|
||||||
|
* revoked_at, no session-store-specific logic anywhere.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::create('user_sessions', function (Blueprint $table) {
|
||||||
|
$table->id();
|
||||||
|
$table->foreignId('user_id')->constrained()->cascadeOnDelete();
|
||||||
|
$table->string('token', 64)->unique();
|
||||||
|
$table->string('user_agent')->nullable();
|
||||||
|
$table->string('ip_address', 45)->nullable();
|
||||||
|
$table->timestamp('last_used_at');
|
||||||
|
$table->timestamp('revoked_at')->nullable();
|
||||||
|
$table->timestamps();
|
||||||
|
|
||||||
|
$table->index(['user_id', 'revoked_at']);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::dropIfExists('user_sessions');
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,65 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Lunar\Models\Language;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* PaymentMethod.name becomes a locale-keyed JSON array (e.g.
|
||||||
|
* {"en": "Cash On Delivery", "el": "Αντικαταβολή"}), rendered in Filament
|
||||||
|
* via Lunar's own Lunar\Admin\Support\Forms\Components\TranslatedText —
|
||||||
|
* the same reusable component/data-shape Product/Collection names already
|
||||||
|
* use (Lunar\Base\Traits\HasTranslations), just applied directly to a
|
||||||
|
* plain column here rather than through attribute_data, since
|
||||||
|
* PaymentMethod is a merchant-configured settings row, not a translatable
|
||||||
|
* catalog attribute.
|
||||||
|
*
|
||||||
|
* Existing plain-string rows are preserved under the store's default
|
||||||
|
* Language code (falls back to 'en' if no Language row exists yet — this
|
||||||
|
* migration can run before lunar:install seeds one) rather than dropped,
|
||||||
|
* so an already-configured payment method's name isn't blanked out.
|
||||||
|
*
|
||||||
|
* Uses a raw `ALTER COLUMN ... TYPE` rather than Blueprint::change()
|
||||||
|
* (which requires doctrine/dbal — not installed in this project) —
|
||||||
|
* Postgres-specific (this project runs on `pgsql`, per its own docker
|
||||||
|
* setup), with an explicit USING clause since json isn't implicitly
|
||||||
|
* castable from varchar.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
$defaultLocale = Language::where('default', true)->value('code') ?? 'en';
|
||||||
|
|
||||||
|
$existing = DB::table('payment_methods')->pluck('name', 'id');
|
||||||
|
|
||||||
|
DB::statement('ALTER TABLE payment_methods ALTER COLUMN name DROP DEFAULT');
|
||||||
|
DB::statement("ALTER TABLE payment_methods ALTER COLUMN name TYPE json USING NULL");
|
||||||
|
|
||||||
|
foreach ($existing as $id => $name) {
|
||||||
|
if ($name === null) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
DB::table('payment_methods')
|
||||||
|
->where('id', $id)
|
||||||
|
->update(['name' => json_encode([$defaultLocale => $name])]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
$defaultLocale = Language::where('default', true)->value('code') ?? 'en';
|
||||||
|
|
||||||
|
$existing = DB::table('payment_methods')->pluck('name', 'id');
|
||||||
|
|
||||||
|
DB::statement('ALTER TABLE payment_methods ALTER COLUMN name TYPE varchar(255) USING NULL');
|
||||||
|
|
||||||
|
foreach ($existing as $id => $name) {
|
||||||
|
$decoded = json_decode((string) $name, true);
|
||||||
|
$flat = is_array($decoded) ? ($decoded[$defaultLocale] ?? reset($decoded) ?: null) : $name;
|
||||||
|
|
||||||
|
DB::table('payment_methods')->where('id', $id)->update(['name' => $flat]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,74 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Lunar\Base\Migration;
|
||||||
|
use Lunar\Models\Language;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* ShippingMethod.name becomes a locale-keyed JSON array (e.g.
|
||||||
|
* {"en": "Standard Delivery", "el": "Κανονική Παράδοση"}), rendered in
|
||||||
|
* Filament via Lunar's own Lunar\Admin\Support\Forms\Components\
|
||||||
|
* TranslatedText (Modules\Core\Shipping\Extensions\
|
||||||
|
* ShippingMethodResourceExtension::replaceNameField()) — same shape/
|
||||||
|
* resolution as PaymentMethod.name (see its own migration,
|
||||||
|
* 2026_09_15_000001_make_payment_methods_name_translatable.php) and
|
||||||
|
* Product/Collection names (Lunar\Base\Traits\HasTranslations).
|
||||||
|
*
|
||||||
|
* ShippingMethod is a vendor (lunarphp/table-rate-shipping) table, but
|
||||||
|
* converting a vendor column's type via a migration is no different from
|
||||||
|
* any other schema change this project already makes against a vendor
|
||||||
|
* table (see database/migrations/2026_08_31_000001_create_payment_methods_table.php's
|
||||||
|
* sibling migrations for the same pattern against PaymentMethod) — there
|
||||||
|
* was no good reason to route this through `data.name` instead, unlike
|
||||||
|
* `data.fulfillment_type` which is a genuinely NEW field the vendor table
|
||||||
|
* never had at all.
|
||||||
|
*
|
||||||
|
* Existing plain-string rows are preserved under the store's default
|
||||||
|
* Language code (falls back to 'en' if no Language row exists yet)
|
||||||
|
* rather than dropped.
|
||||||
|
*
|
||||||
|
* Uses a raw `ALTER COLUMN ... TYPE` rather than Blueprint::change()
|
||||||
|
* (requires doctrine/dbal — not installed in this project) — Postgres-
|
||||||
|
* specific (this project runs on `pgsql`), with an explicit USING clause
|
||||||
|
* since json isn't implicitly castable from varchar.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
$table = $this->prefix.'shipping_methods';
|
||||||
|
$defaultLocale = Language::where('default', true)->value('code') ?? 'en';
|
||||||
|
|
||||||
|
// The column is NOT NULL (vendor migration never marked it
|
||||||
|
// nullable) — converting via `USING NULL` first, then
|
||||||
|
// backfilling with a second UPDATE, violates that constraint
|
||||||
|
// before the backfill ever runs. json_build_object() converts
|
||||||
|
// each existing string in place, in the same statement, so the
|
||||||
|
// column is never transiently NULL. $defaultLocale is inlined
|
||||||
|
// (not bound) — parameter binding inside an ALTER TABLE ... USING
|
||||||
|
// expression isn't reliable across drivers; it's a Language::code
|
||||||
|
// value we control, not user input, so quote_literal-safe
|
||||||
|
// interpolation here is fine.
|
||||||
|
$quotedLocale = DB::getPdo()->quote($defaultLocale);
|
||||||
|
|
||||||
|
DB::statement("ALTER TABLE {$table} ALTER COLUMN name TYPE json USING json_build_object({$quotedLocale}, name)");
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
$table = $this->prefix.'shipping_methods';
|
||||||
|
$defaultLocale = Language::where('default', true)->value('code') ?? 'en';
|
||||||
|
|
||||||
|
// Same NOT NULL constraint applies going back — ->>'{locale}'
|
||||||
|
// extracts the default locale's text value directly in the
|
||||||
|
// USING clause, falling back to the first key present via
|
||||||
|
// COALESCE for any row missing that locale (e.g. one only ever
|
||||||
|
// filled in via a non-default language).
|
||||||
|
$quotedLocale = DB::getPdo()->quote($defaultLocale);
|
||||||
|
|
||||||
|
DB::statement(
|
||||||
|
"ALTER TABLE {$table} ALTER COLUMN name TYPE varchar(255) ".
|
||||||
|
"USING COALESCE(name->>{$quotedLocale}, (SELECT value FROM json_each_text(name) LIMIT 1))"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Database\Migrations\Migration;
|
||||||
|
use Illuminate\Database\Schema\Blueprint;
|
||||||
|
use Illuminate\Support\Facades\Schema;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Per-product, customer-authored input fields — a personalized-statue
|
||||||
|
* product needing a reference photo upload and an optional engraving
|
||||||
|
* textarea, for example. Deliberately NOT modeled as a Lunar ProductOption
|
||||||
|
* (see Modules\Core\Catalog\Contracts\ProductOptionTypeInterface's own
|
||||||
|
* docblock): an option's values are a fixed, admin-authored list that
|
||||||
|
* define variants (Red/Green/Blue) — a photo upload has no such list, it's
|
||||||
|
* unique per order, and creates no variant at all. This is a genuinely
|
||||||
|
* different concept that happens to configure on the same product page.
|
||||||
|
*
|
||||||
|
* Array of {key, type: 'text'|'textarea'|'file', label, required} — `key`
|
||||||
|
* is what a submitted answer is keyed by in CartLine/OrderLine.meta (both
|
||||||
|
* already have a `meta` json column — see Modules\Core\Cart\Services\
|
||||||
|
* CartService::addLine()'s own $meta parameter), not a new table, since
|
||||||
|
* this is small, rarely-queried per-product config, the same reasoning
|
||||||
|
* ShippingMethod.data/PaymentMethod.data already follow for their own
|
||||||
|
* per-row settings.
|
||||||
|
*/
|
||||||
|
return new class extends Migration
|
||||||
|
{
|
||||||
|
public function up(): void
|
||||||
|
{
|
||||||
|
Schema::table(config('lunar.database.table_prefix').'products', function (Blueprint $table) {
|
||||||
|
$table->json('custom_fields')->nullable()->after('attribute_data');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
public function down(): void
|
||||||
|
{
|
||||||
|
Schema::table(config('lunar.database.table_prefix').'products', function (Blueprint $table) {
|
||||||
|
$table->dropColumn('custom_fields');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
+10
-2
@@ -49,7 +49,8 @@ boboko-test/
|
|||||||
app/
|
app/
|
||||||
Models/
|
Models/
|
||||||
Customer.php ← app-level model, extends Modules\Core\Customer\Models\Customer
|
Customer.php ← app-level model, extends Modules\Core\Customer\Models\Customer
|
||||||
User.php ← app-level model, dispatches Modules\Core\Auth\Events\UserCreated
|
User.php ← app-level model, no $dispatchesEvents needed — core dispatches
|
||||||
|
UserCreated itself (Modules\Core\Auth\Services\UserOtpService)
|
||||||
Staff.php ← app-level model, extends Modules\Core\Auth\Models\Staff
|
Staff.php ← app-level model, extends Modules\Core\Auth\Models\Staff
|
||||||
Lunar/
|
Lunar/
|
||||||
Extensions/ ← app's own Filament resource extensions (source of truth, wired in PanelServiceProvider)
|
Extensions/ ← app's own Filament resource extensions (source of truth, wired in PanelServiceProvider)
|
||||||
@@ -264,7 +265,14 @@ php artisan vendor:publish --tag=core-config
|
|||||||
'auto_create_customer_for_user' => false,
|
'auto_create_customer_for_user' => false,
|
||||||
```
|
```
|
||||||
|
|
||||||
Both listeners guard against the other direction re-triggering: they call `User::withoutEvents(...)` around `firstOrCreate`/save, so pairing a `Customer` never spuriously fires `UserCreated` (and vice versa) even if both directions are somehow active at once.
|
A guard against the other direction re-triggering is only needed where a real risk exists:
|
||||||
|
`App\Listeners\CreateUserForCustomerListener` (`boboko-test`, app-level) wraps its
|
||||||
|
`firstOrCreate` in `User::withoutEvents(...)`, since finding-or-creating a `User` there could
|
||||||
|
itself fire `UserCreated` and loop back into `CreateCustomerForUser`. `Modules\Core\Customer\
|
||||||
|
Listeners\CreateCustomerForUser` (core) needs no such guard — it calls a plain
|
||||||
|
`$model::create([])` on `Customer`, which has no `$dispatchesEvents`/model hooks of its own in
|
||||||
|
core that could re-trigger anything; the guard belongs only on the side that actually creates a
|
||||||
|
`User`.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
+55
-16
@@ -145,23 +145,20 @@ produced had it resolved synchronously.
|
|||||||
with no memory of the request that started the payment. Something has to persist enough to
|
with no memory of the request that started the payment. Something has to persist enough to
|
||||||
answer "which order/cart does gateway reference X belong to?" between the two calls.
|
answer "which order/cart does gateway reference X belong to?" between the two calls.
|
||||||
|
|
||||||
**Read directly from `lunarphp/stripe`'s own source** (`StripePaymentType::authorize()`,
|
The precedent for this originally came from reading `lunarphp/stripe`'s own source
|
||||||
`ProcessStripeWebhook`, `WebhookController`) to see how Lunar itself solves this — confirmed
|
(`StripePaymentType::authorize()`, `ProcessStripeWebhook`, `WebhookController`) — that package
|
||||||
it does **not** stash a generic opaque blob. It writes the correlating ids as real, typed
|
solved this the same way, writing the correlating ids as real, typed columns on its own
|
||||||
columns on `Lunar\Stripe\Models\StripePaymentIntent` (`cart_id`, `order_id`) at the moment the
|
`StripePaymentIntent` model rather than a generic opaque blob. **`lunarphp/stripe` has since
|
||||||
intent is created/first seen, then reads them back the same way when the webhook arrives:
|
been removed from this project** in favour of depending on `stripe/stripe-php` directly (see
|
||||||
|
CHANGELOG.md) — `Modules\Core\Payment\Models\StripePaymentIntent` is now a first-party model
|
||||||
|
over the same table shape, kept for exactly the same reason.
|
||||||
|
|
||||||
```php
|
**`StripePaymentDriver` follows this pattern**: it reads `cart_id`/`order_id` out of `$context`
|
||||||
// ProcessStripeWebhook::handle() — falls back through two real lookups,
|
at `pay()`/`authorize()` time and writes them onto its own `StripePaymentIntent` row (`src/
|
||||||
// neither of them a generic context blob:
|
Payment/Models/StripePaymentIntent.php`, table `stripe_payment_intents`), then reads them back
|
||||||
$cart = StripePaymentIntent::where('intent_id', $this->paymentIntentId)->first()?->cart
|
the same way in `handleCallback()`. No generic `context` json column beyond what that table
|
||||||
?: Cart::where('meta->payment_intent', '=', $this->paymentIntentId)->first();
|
already carries (`context`, added for a different purpose — see that migration's own
|
||||||
```
|
docblock), no new table.
|
||||||
|
|
||||||
**`StripePaymentDriver` follows this exact precedent**: it reads `cart_id`/`order_id` out of
|
|
||||||
`$context` at `pay()`/`authorize()` time and writes them onto its own `StripePaymentIntent`
|
|
||||||
row (a table already owned by `lunarphp/stripe`, already shaped for exactly this), then reads
|
|
||||||
them back the same way in `handleCallback()`. No generic `context` json column, no new table.
|
|
||||||
|
|
||||||
### This pattern is per-driver, not a shared table
|
### This pattern is per-driver, not a shared table
|
||||||
|
|
||||||
@@ -176,6 +173,48 @@ a shared generic one.
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## Reconciliation — a charge that succeeds on Stripe but is never written locally
|
||||||
|
|
||||||
|
This app never creates or reuses a Stripe **Customer** object — every PaymentIntent is a
|
||||||
|
one-off (`StripePaymentDriver::createAndConfirm()`'s own `$params` never includes a `customer`
|
||||||
|
key), and nothing calls Stripe's Customer API anywhere in this codebase. That's a deliberate
|
||||||
|
choice, not an oversight: a Customer object only earns its keep if something actually needs it
|
||||||
|
(saved/reusable payment methods, subscriptions, Stripe-side lifetime-value grouping across
|
||||||
|
orders) — none of which exist in this checkout flow today. Creating one anyway would just be
|
||||||
|
more PII sitting on a third party's servers for no functional benefit, and it would become
|
||||||
|
another cross-reference a future Payment privacy provider has to account for (detaching/
|
||||||
|
deleting the Customer on erasure, not just the local PaymentIntent row). If a real feature
|
||||||
|
needs it later (e.g. "save my card"), add it then, scoped to that feature.
|
||||||
|
|
||||||
|
The gap this creates: with no Customer object and no other identifying field previously sent
|
||||||
|
to Stripe, a PaymentIntent that succeeds on Stripe's side but is never written to our own DB
|
||||||
|
(e.g. a database outage at exactly the wrong moment, between Stripe confirming the charge and
|
||||||
|
`rememberIntent()`'s insert) would be **untraceable** back to a cart or order — nothing to
|
||||||
|
search Stripe's dashboard by except amount, timestamp, and card last-4.
|
||||||
|
|
||||||
|
**Fix**: `createAndConfirm()` now sets `metadata: ['cart_id' => ..., 'order_id' => ...]`
|
||||||
|
(`array_filter()`-ed, since `order_id` isn't known yet at initial `pay()`/`authorize()` time —
|
||||||
|
same null-coalesce `rememberIntent()` already does) on every PaymentIntent. This is metadata
|
||||||
|
only, visible on Stripe's own dashboard/API for manual reconciliation — it does not create a
|
||||||
|
Customer object and does not change anything about how `handleCallback()`/webhook correlation
|
||||||
|
works (that still goes through `stripe_payment_intents`, per "Async resolution" above). It's
|
||||||
|
purely a recovery aid for the case where our own write never happened at all.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## GDPR erasure/export
|
||||||
|
|
||||||
|
`Modules\Core\Payment\Privacy\PaymentDataProvider` covers `lunar_transactions`
|
||||||
|
(`card_type`/`last_four`) and `stripe_payment_intents` — see `docs/privacy.md` for the full
|
||||||
|
right-of-erasure/right-of-access design. Pseudonymizes card metadata on erasure (same
|
||||||
|
tax/accounting retention reasoning `Order`'s own provider uses) and deletes the Stripe
|
||||||
|
correlation rows outright, since their only purpose — resolving an async webhook callback, see
|
||||||
|
"Async resolution" above — has already been served by the time an erasure request runs. No
|
||||||
|
Stripe Customer object exists anywhere in this app (see "Reconciliation" above) for this
|
||||||
|
provider to also request deletion of.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
## Explicitly out of scope for this pass
|
## Explicitly out of scope for this pass
|
||||||
|
|
||||||
- **`Checkout`/`Order` wiring** — how `Checkout` calls into `Payment`, how `Order`/`Checkout`
|
- **`Checkout`/`Order` wiring** — how `Checkout` calls into `Payment`, how `Order`/`Checkout`
|
||||||
|
|||||||
+417
@@ -0,0 +1,417 @@
|
|||||||
|
# Privacy / GDPR Data-Subject Requests
|
||||||
|
|
||||||
|
`Modules\Core\Privacy` implements the right of access (export) and right of erasure for
|
||||||
|
customers, as an extensible contract rather than a fixed list of tables — any module (core,
|
||||||
|
or a future ERP/banking/etc. module) can register its own data without core knowing it exists.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## User-scope vs Customer-scope — two genuinely different operations
|
||||||
|
|
||||||
|
A Lunar `Customer` (business account: orders, addresses, buyer record) and a `User` (individual
|
||||||
|
login identity) are linked many-to-many via the `customer_user` pivot (see `docs/modules.md`
|
||||||
|
"Customer/User Pairing") — **one User can belong to many Customer accounts, and one Customer
|
||||||
|
account can have many linked Users.** This is the real shape of B2B multi-seat access: a person
|
||||||
|
can have login access to several separate business accounts, and a business account can have
|
||||||
|
several employees each with their own login.
|
||||||
|
|
||||||
|
That means "delete my personal data" and "delete this business account" are not the same request,
|
||||||
|
and conflating them is actively wrong:
|
||||||
|
|
||||||
|
- **Erasing a Customer must never touch any linked User's login or identity.** Erasing "Acme
|
||||||
|
Corp" must not deactivate or destroy access for the employees who work there — and must not
|
||||||
|
touch any *other* Customer account, even one sharing some of the same Users.
|
||||||
|
- **Erasing a User must never touch any Customer account's own data.** John asking to delete
|
||||||
|
*his* account must clear his name/email/login wherever it appears — and correctly end his
|
||||||
|
membership on every Customer he's linked to (detach the pivot) — but must not erase Acme Corp's
|
||||||
|
orders or addresses, and must not affect any other employee still linked to Acme Corp.
|
||||||
|
|
||||||
|
Every part of this module is split along that line — a `PersonalDataProvider`, a `PrivacyService`
|
||||||
|
method, a request record — is always explicitly **for a Customer** or **for a User**, never both
|
||||||
|
at once, and never one with an implicit cascade into the other.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Why an extensible contract, not a hardcoded script
|
||||||
|
|
||||||
|
A GDPR erasure/export request has to touch every module that holds personal data, but core can't
|
||||||
|
know in advance what future modules will exist or what data they'll hold — and different data
|
||||||
|
needs fundamentally different handling (freely erasable PII vs. financial records that must be
|
||||||
|
pseudonymized-not-deleted for legal retention vs. data that must be retained outright). There's
|
||||||
|
deliberately no central taxonomy for this in the contract — each module owns its own retention
|
||||||
|
judgment, since only the module that owns a table actually knows its legal requirements.
|
||||||
|
|
||||||
|
`Modules\Core\Privacy\Contracts\PersonalDataProvider` is the whole contract:
|
||||||
|
|
||||||
|
```php
|
||||||
|
interface PersonalDataProvider
|
||||||
|
{
|
||||||
|
public function name(): string;
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult;
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult;
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult;
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
Every provider implements all four methods. A provider with nothing relevant to one scope
|
||||||
|
implements that method as a no-op — `ErasureOutcome::Skipped` with a reason for erase, an empty
|
||||||
|
payload for export (e.g. `AddressDataProvider::eraseForUser()`, since addresses belong to a
|
||||||
|
Customer, not an individual).
|
||||||
|
|
||||||
|
A provider implementation lives inside the module that owns the data it erases/exports, under
|
||||||
|
that module's own `Privacy/` subdirectory (e.g. `Modules\Core\Order\Privacy\OrderDataProvider`,
|
||||||
|
`Modules\Core\Customer\Privacy\CustomerDataProvider`) — never inside `Modules\Core\Privacy`
|
||||||
|
itself, which only owns the shared contract (`Contracts\PersonalDataProvider`), the request
|
||||||
|
lifecycle (`Services\PrivacyManager`/`PrivacyService`), and the DTOs/enums every provider
|
||||||
|
returns. This mirrors how this codebase already handles other cross-cutting-but-domain-specific
|
||||||
|
code (e.g. a resource's own `Filament/Extensions/` subdirectory) — and matters concretely if a
|
||||||
|
module is ever extracted into its own composer package (see `docs/modules.md`): the provider
|
||||||
|
that knows how to erase that module's data must travel with it, not get stranded in `Privacy`
|
||||||
|
depending on a package that no longer ships in this repo.
|
||||||
|
|
||||||
|
A module registers by adding its provider class to `config('core.privacy.providers')` — the
|
||||||
|
same shape as Lunar's own `config('lunar.search.indexers')` model→indexer map:
|
||||||
|
|
||||||
|
```php
|
||||||
|
// config/core.php
|
||||||
|
'privacy' => [
|
||||||
|
'providers' => [
|
||||||
|
\Modules\Core\Customer\Privacy\CustomerDataProvider::class,
|
||||||
|
\Modules\Core\Customer\Privacy\AddressDataProvider::class,
|
||||||
|
\Modules\Core\Order\Privacy\OrderDataProvider::class,
|
||||||
|
\Modules\Core\Cart\Privacy\CartDataProvider::class,
|
||||||
|
\Modules\Core\Review\Privacy\ReviewDataProvider::class,
|
||||||
|
// A future module just adds its own provider here.
|
||||||
|
],
|
||||||
|
],
|
||||||
|
```
|
||||||
|
|
||||||
|
`PrivacyManager` resolves each class via the container and asserts every `name()` is unique —
|
||||||
|
two providers registering the same name throws, so a naming collision fails loudly at
|
||||||
|
resolution time rather than silently overwriting one provider's data in an export/report.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## `UserSubject` and `CustomerSubject` — identifying "the person" vs "the account"
|
||||||
|
|
||||||
|
Two separate value objects, not one — each deliberately carries only what its own scope needs, so
|
||||||
|
a provider can't accidentally reach across the boundary:
|
||||||
|
|
||||||
|
```php
|
||||||
|
class CustomerSubject
|
||||||
|
{
|
||||||
|
public readonly int $customerId;
|
||||||
|
// No userIds, no email — Customer-scope has no business knowing about logins.
|
||||||
|
}
|
||||||
|
|
||||||
|
class UserSubject
|
||||||
|
{
|
||||||
|
public readonly int $userId;
|
||||||
|
public readonly ?string $email;
|
||||||
|
// No customerId — one User can be linked to many Customers; a provider that
|
||||||
|
// needs to know which ones looks that up itself (e.g. to detach the pivot),
|
||||||
|
// rather than this value object assuming or privileging any single one.
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
`CustomerSubject::forCustomer(Customer $customer)` and `UserSubject::forUser($user)` build one
|
||||||
|
from the record staff (or the person themselves) look up.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Providers shipped in core
|
||||||
|
|
||||||
|
| Provider | `name()` | Lives in | Covers | Customer-scope | User-scope |
|
||||||
|
|---|---|---|---|---|---|
|
||||||
|
| `ActivityLogDataProvider` | `activity_log` | `Modules\Core\Logging\Privacy` | `activity_log` (Spatie) for subject types `Customer`/`Address`/`CartAddress`/`OrderAddress`/`Transaction` | **Pseudonymized** — `properties` redacted, who/what/when metadata kept | Skipped — `causer_id` is an actor reference, not PII content; see below |
|
||||||
|
| `CustomerDataProvider` | `customer` | `Modules\Core\Customer\Privacy` | `lunar_customers`, and separately the `User`'s own name/email/OTP fields | Erases the account's own fields only | Erases that User's name/email/OTP fields only, and detaches them from every linked Customer |
|
||||||
|
| `AddressDataProvider` | `addresses` | `Modules\Core\Customer\Privacy` | `lunar_addresses` | Erased (deleted outright) | Skipped — belongs to a Customer, not an individual |
|
||||||
|
| `OrderDataProvider` | `orders` | `Modules\Core\Order\Privacy` | `lunar_orders`, `lunar_order_addresses`, and their `meta` (`terms_accepted*`, `payment_method`, `box_now_locker`) | **Pseudonymized, not erased** — see below | Skipped — belongs to a Customer, not an individual |
|
||||||
|
| `CartDataProvider` | `carts` | `Modules\Core\Cart\Privacy` | `lunar_cart_addresses`, and `lunar_carts.meta` (`recovery_consent*`, `payment_method`, `checkout_fingerprint`) | Erased | Skipped — belongs to a Customer, not an individual |
|
||||||
|
| `ReviewDataProvider` | `reviews` | `Modules\Core\Review\Privacy` | `product_reviews` | Skipped — authored by an individual, not a business account | Pseudonymized by matching `reviewer_email`; rating/title/body text kept |
|
||||||
|
| `PaymentDataProvider` | `payments` | `Modules\Core\Payment\Privacy` | `lunar_transactions` (`card_type`/`last_four`), `stripe_payment_intents` | **Pseudonymized** — card metadata cleared, correlation rows deleted, amounts/statuses kept | Skipped — belongs to Customer-owned orders, not individual users |
|
||||||
|
| `UserSessionDataProvider` | `sessions` | `Modules\Core\Auth\Privacy` | `user_sessions` (`ip_address`, `user_agent`) | Skipped — belongs to an individual User, not a business account | Erased (deleted outright) |
|
||||||
|
|
||||||
|
`CustomerDataProvider` is the one provider that implements both scopes meaningfully, and keeps
|
||||||
|
them from touching each other — see the class docblock for the full reasoning.
|
||||||
|
|
||||||
|
### `activity_log` is redacted by subject, never by causer
|
||||||
|
|
||||||
|
`Modules\Core\Logging\ActivityLogService` (plus several Lunar models' own native `use
|
||||||
|
LogsActivity` — `Customer`, `CartAddress`, `OrderAddress`, `Transaction`) durably retains a full
|
||||||
|
snapshot of whatever it logged in `properties`, completely independent of the real row it
|
||||||
|
describes — erasing/pseudonymizing a `Customer`/`Address`/`Order`/etc. elsewhere does nothing to
|
||||||
|
this table on its own. `ActivityLogDataProvider::eraseForCustomer()` redacts `properties` on
|
||||||
|
every row whose **subject** (not causer) resolves back to that customer, across all five
|
||||||
|
PII-bearing subject types.
|
||||||
|
|
||||||
|
It deliberately never touches `causer_id` — the causer is "who performed this action," not PII
|
||||||
|
content, and erasing it would defeat the audit trail's own purpose. `eraseForUser()` is
|
||||||
|
therefore a no-op: a `User` appears in this table only as a causer, never as subject content, so
|
||||||
|
there's nothing to redact from the User side alone.
|
||||||
|
|
||||||
|
**Ordering dependency**: `ActivityLogDataProvider` must run *before* `AddressDataProvider` in
|
||||||
|
`config('core.privacy.providers')` — it resolves which `activity_log` rows are keyed by an
|
||||||
|
`Address` id while those Address rows still exist; `AddressDataProvider` then hard-deletes them.
|
||||||
|
Reversing the order would make matching those rows impossible once the addresses are gone.
|
||||||
|
|
||||||
|
**`ReviewDataProvider` needs review.** It moved from Customer-scope to User-scope on the
|
||||||
|
reasoning that authorship is a personal attribute, not a business-account attribute — but this
|
||||||
|
hasn't been fully validated against how reviews are actually attributed in this codebase. The
|
||||||
|
class carries a `NEEDS REVIEW` note; revisit before relying on it for a real request.
|
||||||
|
|
||||||
|
### Orders are pseudonymized, not deleted
|
||||||
|
|
||||||
|
GDPR Art. 17(3)(b) explicitly allows retaining data an erasure request would otherwise cover,
|
||||||
|
when a legal obligation requires it — tax/accounting law generally requires invoices be kept for
|
||||||
|
several years. `OrderDataProvider::eraseForCustomer()` clears the free-text PII fields on `Order`/
|
||||||
|
`OrderAddress` (`customer_reference`, `notes`, name/address/contact fields) but leaves the order
|
||||||
|
row, totals, line items, and tax data fully intact. Its `ProviderErasureResult` reports
|
||||||
|
`ErasureOutcome::Pseudonymized`, not `Erased` — a compliance report or admin UI can see exactly
|
||||||
|
why an order wasn't deleted without reading `OrderDataProvider`'s source.
|
||||||
|
|
||||||
|
### Reviews are matched by email — a real, documented limitation
|
||||||
|
|
||||||
|
`ProductReview` has no FK to Customer/User at all (see `docs/product-listing.md` "Reviews") —
|
||||||
|
it's deliberately anonymous, just free-text `reviewer_name`/`reviewer_email`. `ReviewDataProvider`
|
||||||
|
matches by `reviewer_email` against `UserSubject::$email`; a review submitted under a different
|
||||||
|
email than the one on file simply won't be found. There's no stronger signal available without
|
||||||
|
changing `ProductReview`'s schema.
|
||||||
|
|
||||||
|
### Staff/employee data is out of scope
|
||||||
|
|
||||||
|
`Staff` (admin/panel employees) is never a `UserSubject`/`CustomerSubject` at all — this feature
|
||||||
|
is scoped to customer-initiated and staff-initiated-on-a-customer's-behalf requests. An employee's
|
||||||
|
own data (a different HR/access-management concern) isn't reachable through this flow.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Erasure isn't immediate — a cancellable grace period
|
||||||
|
|
||||||
|
`PrivacyService` has parallel methods for each scope: `requestErasureForCustomer()` /
|
||||||
|
`requestErasureForUser()`. Neither erases anything immediately. Each opens a `DataErasureRequest`
|
||||||
|
(`pending`, `scheduled_for` = now + `config('core.privacy.grace_period_days')`, default 30). This
|
||||||
|
mirrors Shopify's own account-deletion flow: a window where the subject can change their mind
|
||||||
|
before anything is actually erased.
|
||||||
|
|
||||||
|
**Only the User-scoped request deactivates a login.** `requestErasureForCustomer()` deactivates
|
||||||
|
no one — a business-account erasure must never block anyone's access.
|
||||||
|
`requestErasureForUser()` deactivates that one User's login (blocks it — see
|
||||||
|
`Modules\Core\Auth\Services\UserOtpService` — nothing else changes).
|
||||||
|
|
||||||
|
```php
|
||||||
|
use Modules\Core\Privacy\Services\PrivacyService;
|
||||||
|
|
||||||
|
$service = app(PrivacyService::class);
|
||||||
|
|
||||||
|
// Customer-scoped: either the Customer itself (self-service) or a Staff member.
|
||||||
|
$request = $service->requestErasureForCustomer($customer, $requestedBy);
|
||||||
|
|
||||||
|
// User-scoped: either the User itself (self-service) or a Staff member.
|
||||||
|
$request = $service->requestErasureForUser($user, $requestedBy);
|
||||||
|
|
||||||
|
// Cancel before scheduled_for — for a User-scoped request, reactivates the
|
||||||
|
// account. A Customer-scoped request never deactivated anything, so there's
|
||||||
|
// nothing to reactivate for it.
|
||||||
|
$service->cancelErasure($request);
|
||||||
|
```
|
||||||
|
|
||||||
|
### Logging back in during the grace period cancels the request automatically
|
||||||
|
|
||||||
|
Authentication is never blocked by deactivation — `UserOtpService::validate()` still requires
|
||||||
|
the correct OTP code. Once validated, it dispatches `Modules\Core\Auth\Events\UserAuthenticated`;
|
||||||
|
`Modules\Core\Privacy\Listeners\CancelErasureOnLoginListener` (registered in
|
||||||
|
`PrivacyServiceProvider`, **queued** — see below) looks for a pending request keyed on *that
|
||||||
|
User's own id* — never a Customer-scoped one, since Customer-scope never deactivates a login in
|
||||||
|
the first place — and calls `cancelErasure()` on it, then reverts every Customer erasure request
|
||||||
|
it caused (see "The sole-owner cascade" below). Logging back in **is** the "I changed my mind"
|
||||||
|
action — no separate UI/flow needed for reactivation.
|
||||||
|
|
||||||
|
This listener is queued rather than synchronous, so login returns to the browser without waiting
|
||||||
|
on the bookkeeping. Nothing else in this codebase currently reads `deactivated_at` besides this
|
||||||
|
listener and `PrivacyService` itself — `UserOtpService::validate()` never gates the login on it —
|
||||||
|
so the brief window between the login response and the job actually running has no other consumer
|
||||||
|
to observe it as stale.
|
||||||
|
|
||||||
|
### The sole-owner cascade — erasing the last User on a Customer also erases the Customer
|
||||||
|
|
||||||
|
If a User is erased and they were the **only** User linked to a given Customer, that Customer's
|
||||||
|
data (orders, addresses, buyer record) becomes permanently unreachable through any login the
|
||||||
|
moment the User's identity is gone — nobody could ever again log in to exercise a data-subject
|
||||||
|
right over it. GDPR's data minimization principle (Art. 5(1)(c)) means it shouldn't just sit
|
||||||
|
there indefinitely with no legitimate purpose.
|
||||||
|
|
||||||
|
`requestErasureForUser()` and `requestImmediateErasureForUser()` both fire
|
||||||
|
`Modules\Core\Privacy\Events\UserErasureRequested` right after the request is created (and, for
|
||||||
|
the immediate path, before `completeErasure()` runs — see below).
|
||||||
|
`Modules\Core\Privacy\Listeners\CascadeCustomerErasureListener` (**queued**, registered in
|
||||||
|
`PrivacyServiceProvider`) handles it: for every Customer the User is linked to, if that User is
|
||||||
|
currently the *sole* linked User (count is 1, and that one User is this one — not just count ===
|
||||||
|
1, to be explicit rather than relying on an assumption), it opens a second, independent
|
||||||
|
grace-period request via `requestErasureForCustomer($customer, $user, causedByRequestId: ...)`.
|
||||||
|
Both requests then run through their own separate 30-day windows.
|
||||||
|
|
||||||
|
```
|
||||||
|
User erasure requested
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
UserErasureRequested event ──▶ CascadeCustomerErasureListener (queued)
|
||||||
|
│
|
||||||
|
▼
|
||||||
|
for each linked Customer: sole owner?
|
||||||
|
│ yes
|
||||||
|
▼
|
||||||
|
requestErasureForCustomer(..., causedByRequestId: <user request id>)
|
||||||
|
```
|
||||||
|
|
||||||
|
**Tracing the cascade — `caused_by_request_id`.** A cascade-created Customer request's
|
||||||
|
`caused_by_request_id` points back at the User request that triggered it. This is what lets
|
||||||
|
`CancelErasureOnLoginListener` revert *exactly* the cascade a User's own cancellation should
|
||||||
|
undo (via `DataErasureRequest::caused()`) without ever touching an unrelated, independently
|
||||||
|
staff-requested Customer erasure the User happens to still be linked to.
|
||||||
|
|
||||||
|
**Why this is queued, not synchronous.** `CascadeCustomerErasureListener` runs as an independent,
|
||||||
|
separately-retryable job rather than inline inside `requestErasureForUser()` — a failure in the
|
||||||
|
cascade check never rolls back or blocks the User's own request, and there's no
|
||||||
|
`DB::transaction()` wrapping needed, since the two writes (the User's request, and any cascaded
|
||||||
|
Customer request) aren't required to be atomic with each other.
|
||||||
|
|
||||||
|
**A known, accepted race on the immediate-erasure path only.** Because the listener is queued,
|
||||||
|
Eloquent re-fetches its models fresh when the job actually runs (see
|
||||||
|
`Illuminate\Queue\SerializesModels`) — so `$event->request->subject->customers` reflects the
|
||||||
|
*real* state at execution time, not a stale snapshot from dispatch time. For
|
||||||
|
`requestImmediateErasureForUser()`, that job may run before or after `completeErasure()` detaches
|
||||||
|
the User's memberships in the same call. If the detach happens first, the User is simply no
|
||||||
|
longer linked to anything by the time the cascade job runs, and nothing cascades — an accepted
|
||||||
|
race for that rare, staff-only path (see "Immediate erasure" below), not a concern for the
|
||||||
|
everyday `requestErasureForUser()` grace-period path, where nothing detaches until its own later,
|
||||||
|
separate `completeErasure()` run — well after the cascade job has had time to fire.
|
||||||
|
|
||||||
|
### Processing due requests — one job per request
|
||||||
|
|
||||||
|
`php artisan boboko:privacy:process-erasure-requests` finds every `pending` request whose
|
||||||
|
`scheduled_for` has passed and dispatches one `Modules\Core\Privacy\Jobs\EraseDataSubjectJob` per
|
||||||
|
request — it does not run `completeErasure()` inline itself. Each job independently calls
|
||||||
|
`PrivacyService::completeErasure()`, which checks the request's polymorphic `subject` and calls
|
||||||
|
either every registered provider's `eraseForCustomer()` or `eraseForUser()`, writing the full
|
||||||
|
per-provider outcome onto the request's `report` column and marking it `completed`. One job per
|
||||||
|
request means one request's failure (a provider throwing, a DB error) doesn't block or crash
|
||||||
|
processing of the others, and Laravel's normal per-job retry/failure handling applies to each
|
||||||
|
request independently. This package doesn't register a schedule itself; each consuming app wires
|
||||||
|
the command into its own scheduler (daily is reasonable), the same way it owns any other
|
||||||
|
scheduled task.
|
||||||
|
|
||||||
|
### Immediate erasure — staff-only, not self-service
|
||||||
|
|
||||||
|
`requestImmediateErasureForCustomer(Customer $customer, Staff $requestedBy): ErasureReport` and
|
||||||
|
`requestImmediateErasureForUser($user, Staff $requestedBy): ErasureReport` bypass the grace
|
||||||
|
period entirely and erase right away. Both are `Staff`-only **by type**, not just by convention —
|
||||||
|
their signatures take `Staff $requestedBy` specifically (not the union type the grace-period
|
||||||
|
methods accept), so a self-service/customer-facing code path can't reach either one even by
|
||||||
|
accident; calling with a `Customer`/`User` actor is a compile-time type error, not a runtime
|
||||||
|
check to remember.
|
||||||
|
|
||||||
|
This exists for a formal legal request or regulator inquiry that genuinely requires immediate
|
||||||
|
action, not as a convenience for an impatient customer. GDPR Art. 17 requires erasure "without
|
||||||
|
undue delay," but doesn't set a maximum number of days for a grace period, and a short, disclosed,
|
||||||
|
cancellable hold before executing a self-service request is a widely-used, generally accepted
|
||||||
|
pattern (the same one Shopify and most major platforms use) — it is **not** offered as a
|
||||||
|
same-click alternative on the self-service deletion flow, since doing so would mostly defeat the
|
||||||
|
grace period's purpose (protecting an impulsive requester from themselves). If a subject
|
||||||
|
explicitly insists on immediate deletion, that's a staff/support decision to make on the record
|
||||||
|
via one of these methods, not a checkbox exposed to every customer.
|
||||||
|
|
||||||
|
```php
|
||||||
|
$report = $service->requestImmediateErasureForCustomer($customer, $staffMember);
|
||||||
|
$report = $service->requestImmediateErasureForUser($user, $staffMember);
|
||||||
|
// Both run synchronously — no queueing, no grace period. $report is the same
|
||||||
|
// ErasureReport completeErasure() would produce.
|
||||||
|
```
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Export — queued, not synchronous
|
||||||
|
|
||||||
|
Export gathers real data across every registered provider — potentially slow, and there's no
|
||||||
|
reason to block whatever request triggered it (a customer clicking "export my data," an API
|
||||||
|
call). `requestExportForCustomer()`/`requestExportForUser()` are fast synchronous calls that only
|
||||||
|
create a `DataExportRequest` row and dispatch the actual work:
|
||||||
|
|
||||||
|
```php
|
||||||
|
$request = $service->requestExportForCustomer($customer);
|
||||||
|
$request = $service->requestExportForUser($user);
|
||||||
|
// $request->status is 'pending'; nothing has been gathered yet.
|
||||||
|
```
|
||||||
|
|
||||||
|
### The event chain
|
||||||
|
|
||||||
|
1. **`ExportDataSubjectJob`** (queued) checks the request's polymorphic `subject` and calls every
|
||||||
|
registered provider's `exportForCustomer()` or `exportForUser()` — all sequentially, in this
|
||||||
|
one job, not fanned out into one job per provider. Per-subject export work is small (a handful
|
||||||
|
of indexed queries per provider), so there's no real parallelism win, and one job means
|
||||||
|
"finished" is just "`handle()` returned," with no `Bus::batch()`/completion-counting needed. If
|
||||||
|
a future provider ever does something genuinely slow (an external API call, a generated PDF),
|
||||||
|
that's the point to reconsider a per-provider batch — not before.
|
||||||
|
2. Once every provider's data is gathered, the job fires **`PersonalDataGathered`**
|
||||||
|
(carries the request and the assembled `ExportReport`) — no file exists yet.
|
||||||
|
3. **`Modules\Core\Privacy\Listeners\WriteExportToCsvListener`** (registered in
|
||||||
|
`PrivacyServiceProvider`) handles that event: turns each provider's data into its own CSV (via
|
||||||
|
the generic `Modules\Core\Export\CsvWriter` — see below), zips them together, writes the zip to
|
||||||
|
`storage/app/exports/privacy/`, and updates the request (`status: completed`, `file_path`).
|
||||||
|
This is its own listener — not inline in the job — so the export *format* is swappable (an app
|
||||||
|
could unregister this and register a JSON-only listener instead) without touching how data is
|
||||||
|
gathered.
|
||||||
|
4. Once the file exists, that listener fires **`PersonalDataExportFileWritten`**.
|
||||||
|
5. Core has no opinion on how the subject is told. A consuming app registers its own notification
|
||||||
|
against `PersonalDataExportFileWritten` via `Modules\Core\Notification\NotificationRegistry` —
|
||||||
|
the same pattern as `App\Notifications\QuestionnaireResultsSentNotification` listening on
|
||||||
|
`App\Events\QuestionnaireResultsSent` (see `boboko-test` for a working example). Core
|
||||||
|
deliberately does not send an email itself.
|
||||||
|
|
||||||
|
### CSV shape
|
||||||
|
|
||||||
|
Every provider's `data` is either a list of associative arrays (addresses, orders, reviews — each
|
||||||
|
item becomes a row) or a single associative array (customer — becomes one row). Any nested array
|
||||||
|
value within a row (e.g. an order's `addresses` sub-array) is JSON-encoded into that one cell
|
||||||
|
rather than exploded into further columns — a generic, provider-agnostic rule in
|
||||||
|
`WriteExportToCsvListener`, not something each provider has to think about.
|
||||||
|
|
||||||
|
### `Modules\Core\Export\CsvWriter` — a generic, reusable piece
|
||||||
|
|
||||||
|
`CsvWriter::write(array $columns, iterable $rows, string $path)` has no knowledge of GDPR,
|
||||||
|
customers, or Lunar at all — a caller supplies a schema (`CsvColumn[]`, each just a header plus a
|
||||||
|
closure that pulls that column's value out of one record) and any iterable data source. It's used
|
||||||
|
here by `WriteExportToCsvListener`, but is equally usable for an unrelated future need — an admin
|
||||||
|
bulk catalog export, an accounting handoff — by supplying a different schema and row source;
|
||||||
|
nothing about it is GDPR-specific.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Audit trail
|
||||||
|
|
||||||
|
`DataErasureRequest` (`data_erasure_requests`) and `DataExportRequest` (`data_export_requests`)
|
||||||
|
are the audit records for erasure and export respectively. Both have a polymorphic `subject`
|
||||||
|
(`subject_type`/`subject_id`, pointing at either a Lunar `Customer` or a `User` — never both) —
|
||||||
|
`subject_type`/`subject_id`/`email` are stored as a **snapshot**, not looked up live, since the
|
||||||
|
whole point is for these tables to remain readable after the record they're about has been
|
||||||
|
erased. `DataErasureRequest::isForCustomer()` tells you which scope a given request is.
|
||||||
|
|
||||||
|
`DataErasureRequest.requested_by_type`/`requested_by_id` capture who asked for it (the subject
|
||||||
|
themselves, self-service; `Staff` acting on their behalf; or, for a cascade-created Customer
|
||||||
|
request, the User whose erasure caused it — see "The sole-owner cascade") at request time.
|
||||||
|
`DataErasureRequest.caused_by_request_id` is set only on a cascade-created Customer request,
|
||||||
|
pointing back at the User request that triggered it; null on every normal, directly-requested
|
||||||
|
erasure — see `DataErasureRequest::causedBy()`/`::caused()`.
|
||||||
|
`DataErasureRequest.report` holds the full per-provider outcome once `completeErasure()` runs;
|
||||||
|
`DataExportRequest.file_path` points at the generated zip once `WriteExportToCsvListener`
|
||||||
|
finishes.
|
||||||
|
|
||||||
|
**Not yet built**: a standalone "leave/remove from a Customer account" action — unlinking a User
|
||||||
|
from a Customer without any erasure involved (e.g. a teammate leaving a project, or an account
|
||||||
|
admin removing someone) — is a related but separate, smaller feature, deliberately out of scope
|
||||||
|
for this module so far. It shares the same pivot-detach primitive `CustomerDataProvider::
|
||||||
|
eraseForUser()` already uses as part of a full erasure, but as a standalone action it doesn't
|
||||||
|
exist yet.
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Greek translations for Lunar\Models\Country::name, keyed by the exact
|
||||||
|
* English spelling Lunar's own installer seeds (`lunar:import:address-data`
|
||||||
|
* fetches http://data.lunarphp.io/countries+states.json — see
|
||||||
|
* vendor/lunarphp/core/src/Console/Commands/Import/AddressData.php).
|
||||||
|
* `Country`/`State` have no i18n support of their own (plain string
|
||||||
|
* columns, no translatable trait) — this is a plain Laravel lang file, not
|
||||||
|
* Modules\Core\Localization's DB-backed TranslationService, since these
|
||||||
|
* names are fixed reference data seeded once, not editable UI copy (see
|
||||||
|
* docs/localization.md). A consuming app's storefront looks this up
|
||||||
|
* itself, e.g. __('core::countries.'.$country->name) — core has no
|
||||||
|
* storefront UI of its own to wire this into (see docs/lunar.md).
|
||||||
|
*
|
||||||
|
* Only Greece is covered — this store operates within Greece; add further
|
||||||
|
* countries here as needed.
|
||||||
|
*/
|
||||||
|
return [
|
||||||
|
'Greece' => 'Ελλάδα',
|
||||||
|
];
|
||||||
@@ -0,0 +1,52 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Greek translations for Lunar\Models\State::name, keyed by the exact
|
||||||
|
* English spelling Lunar's own installer seeds for Greece
|
||||||
|
* (`lunar:import:address-data` — see lang/el/countries.php's own docblock
|
||||||
|
* for the full explanation of why this is a plain lang file, not
|
||||||
|
* Modules\Core\Localization's TranslationService).
|
||||||
|
*
|
||||||
|
* Covers every Greek state/regional-unit row in Lunar's seed dataset —
|
||||||
|
* scoped to Greece only, matching this store's operating country.
|
||||||
|
*/
|
||||||
|
return [
|
||||||
|
'Achaea Regional Unit' => 'Περιφερειακή Ενότητα Αχαΐας',
|
||||||
|
'Aetolia-Acarnania Regional Unit' => 'Περιφερειακή Ενότητα Αιτωλοακαρνανίας',
|
||||||
|
'Arcadia Prefecture' => 'Νομός Αρκαδίας',
|
||||||
|
'Argolis Regional Unit' => 'Περιφερειακή Ενότητα Αργολίδας',
|
||||||
|
'Attica Region' => 'Περιφέρεια Αττικής',
|
||||||
|
'Boeotia Regional Unit' => 'Περιφερειακή Ενότητα Βοιωτίας',
|
||||||
|
'Central Greece Region' => 'Περιφέρεια Στερεάς Ελλάδας',
|
||||||
|
'Central Macedonia' => 'Κεντρική Μακεδονία',
|
||||||
|
'Chania Regional Unit' => 'Περιφερειακή Ενότητα Χανίων',
|
||||||
|
'Corfu Prefecture' => 'Νομός Κέρκυρας',
|
||||||
|
'Corinthia Regional Unit' => 'Περιφερειακή Ενότητα Κορινθίας',
|
||||||
|
'Crete Region' => 'Περιφέρεια Κρήτης',
|
||||||
|
'Drama Regional Unit' => 'Περιφερειακή Ενότητα Δράμας',
|
||||||
|
'East Attica Regional Unit' => 'Περιφερειακή Ενότητα Ανατολικής Αττικής',
|
||||||
|
'East Macedonia and Thrace' => 'Ανατολική Μακεδονία και Θράκη',
|
||||||
|
'Epirus Region' => 'Περιφέρεια Ηπείρου',
|
||||||
|
'Euboea' => 'Εύβοια',
|
||||||
|
'Grevena Prefecture' => 'Νομός Γρεβενών',
|
||||||
|
'Imathia Regional Unit' => 'Περιφερειακή Ενότητα Ημαθίας',
|
||||||
|
'Ioannina Regional Unit' => 'Περιφερειακή Ενότητα Ιωαννίνων',
|
||||||
|
'Ionian Islands Region' => 'Περιφέρεια Ιονίων Νήσων',
|
||||||
|
'Karditsa Regional Unit' => 'Περιφερειακή Ενότητα Καρδίτσας',
|
||||||
|
'Kastoria Regional Unit' => 'Περιφερειακή Ενότητα Καστοριάς',
|
||||||
|
'Kefalonia Prefecture' => 'Νομός Κεφαλληνίας',
|
||||||
|
'Kilkis Regional Unit' => 'Περιφερειακή Ενότητα Κιλκίς',
|
||||||
|
'Kozani Prefecture' => 'Νομός Κοζάνης',
|
||||||
|
'Laconia' => 'Λακωνία',
|
||||||
|
'Larissa Prefecture' => 'Νομός Λάρισας',
|
||||||
|
'Lefkada Regional Unit' => 'Περιφερειακή Ενότητα Λευκάδας',
|
||||||
|
'Pella Regional Unit' => 'Περιφερειακή Ενότητα Πέλλας',
|
||||||
|
'Peloponnese Region' => 'Περιφέρεια Πελοποννήσου',
|
||||||
|
'Phthiotis Prefecture' => 'Νομός Φθιώτιδας',
|
||||||
|
'Preveza Prefecture' => 'Νομός Πρέβεζας',
|
||||||
|
'Serres Prefecture' => 'Νομός Σερρών',
|
||||||
|
'South Aegean' => 'Νότιο Αιγαίο',
|
||||||
|
'Thessaloniki Regional Unit' => 'Περιφερειακή Ενότητα Θεσσαλονίκης',
|
||||||
|
'West Greece Region' => 'Περιφέρεια Δυτικής Ελλάδας',
|
||||||
|
'West Macedonia Region' => 'Περιφέρεια Δυτικής Μακεδονίας',
|
||||||
|
];
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
<p>Hi {{ $name }},</p>
|
<p>Hi {{ $name }},</p>
|
||||||
|
|
||||||
<p>Your login code is:</p>
|
<p>{{ $intro }}</p>
|
||||||
|
|
||||||
<p style="font-size: 2rem; font-weight: bold; letter-spacing: 0.25rem;">{{ $code }}</p>
|
<p style="font-size: 2rem; font-weight: bold; letter-spacing: 0.25rem;">{{ $code }}</p>
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Lunar\Base\LunarUser;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by UserOtpService::validate() on every successful OTP login, not just
|
||||||
|
* a first-time one. Modules\Core\Privacy listens on this to auto-cancel a pending
|
||||||
|
* DataErasureRequest — logging back in during the grace period is the "I changed
|
||||||
|
* my mind" action (see Modules\Core\Privacy\Listeners\CancelErasureOnLoginListener),
|
||||||
|
* which needs $user->customers to resolve any pending request. Typed as
|
||||||
|
* Authenticatable&LunarUser rather than plain Authenticatable (unlike the sibling
|
||||||
|
* UserCreated event) specifically because that listener depends on it — every real
|
||||||
|
* User in this codebase implements LunarUser (see docs/lunar.md "LunarUser trait"),
|
||||||
|
* and User is the only Authenticatable entity in this project (Customer is not —
|
||||||
|
* see docs/modules.md "Customer/User Pairing").
|
||||||
|
*/
|
||||||
|
class UserAuthenticated
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly Authenticatable&LunarUser $user,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Exceptions;
|
||||||
|
|
||||||
|
use RuntimeException;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Thrown by Modules\Core\Auth\Services\UserOtpService::generateAndSend()
|
||||||
|
* when an email has requested too many codes too quickly — caps both
|
||||||
|
* mail-bombing one inbox and the "just request a fresh code to reset my
|
||||||
|
* guess count" loophole a per-code attempt cap alone doesn't close.
|
||||||
|
*/
|
||||||
|
class OtpThrottledException extends RuntimeException
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly int $availableInSeconds,
|
||||||
|
) {
|
||||||
|
parent::__construct("Too many code requests. Try again in {$availableInSeconds} second(s).");
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,50 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Http\Middleware;
|
||||||
|
|
||||||
|
use Closure;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Facades\Auth;
|
||||||
|
use Modules\Core\Auth\Services\UserSessionService;
|
||||||
|
use Symfony\Component\HttpFoundation\Response;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The enforcement half of the session registry — see
|
||||||
|
* Modules\Core\Auth\Services\UserSessionService's own docblock. Not
|
||||||
|
* auto-registered anywhere (no routes/kernel wiring exist in this
|
||||||
|
* package — see Modules\Core\Customer\Services\CustomerAccountService's
|
||||||
|
* own docblock for why this branch stops at services); a consuming app
|
||||||
|
* adds this to its `web` middleware group (after `auth`) to actually get
|
||||||
|
* "logout everywhere" enforcement.
|
||||||
|
*
|
||||||
|
* A request with no recorded UserSession at all (see
|
||||||
|
* UserSessionService::currentSession()'s own docblock) is let through —
|
||||||
|
* only an EXPLICITLY revoked session is rejected.
|
||||||
|
*/
|
||||||
|
class EnsureSessionNotRevoked
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly UserSessionService $sessions,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public function handle(Request $request, Closure $next): Response
|
||||||
|
{
|
||||||
|
if (! Auth::check()) {
|
||||||
|
return $next($request);
|
||||||
|
}
|
||||||
|
|
||||||
|
$session = $this->sessions->currentSession();
|
||||||
|
|
||||||
|
if ($session && $session->isRevoked()) {
|
||||||
|
Auth::logout();
|
||||||
|
$request->session()->invalidate();
|
||||||
|
$request->session()->regenerateToken();
|
||||||
|
|
||||||
|
abort(401, 'Your session has been revoked. Please log in again.');
|
||||||
|
}
|
||||||
|
|
||||||
|
$session?->update(['last_used_at' => now()]);
|
||||||
|
|
||||||
|
return $next($request);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -6,20 +6,47 @@ use Illuminate\Mail\Mailable;
|
|||||||
use Illuminate\Mail\Mailables\Content;
|
use Illuminate\Mail\Mailables\Content;
|
||||||
use Illuminate\Mail\Mailables\Envelope;
|
use Illuminate\Mail\Mailables\Envelope;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The one OTP email template for every use of Auth\Services\OtpService —
|
||||||
|
* not just admin login. A code confirming a destructive Artisan command
|
||||||
|
* (e.g. Command\WipeCatalogCommand) reuses the exact same generation/
|
||||||
|
* validation mechanism as login, but "Your login code" as the subject
|
||||||
|
* would be actively misleading for that — the recipient never initiated a
|
||||||
|
* login. $purpose is a small, fixed set of known keys (see
|
||||||
|
* COPY_BY_PURPOSE), not free text — a typo'd/unknown purpose falls back
|
||||||
|
* to 'login' rather than rendering a blank subject/intro.
|
||||||
|
*/
|
||||||
class OtpMail extends Mailable
|
class OtpMail extends Mailable
|
||||||
{
|
{
|
||||||
|
private const COPY_BY_PURPOSE = [
|
||||||
|
'login' => [
|
||||||
|
'subject' => 'Your login code',
|
||||||
|
'intro' => 'Your login code is:',
|
||||||
|
],
|
||||||
|
'wipe-catalog' => [
|
||||||
|
'subject' => 'Confirm: Wipe Catalog',
|
||||||
|
'intro' => 'Someone requested to permanently delete every product in the catalog. If this was you, enter this code to confirm:',
|
||||||
|
],
|
||||||
|
];
|
||||||
|
|
||||||
public function __construct(
|
public function __construct(
|
||||||
public readonly string $name,
|
public readonly string $name,
|
||||||
public readonly string $code,
|
public readonly string $code,
|
||||||
|
public readonly string $purpose = 'login',
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
public function envelope(): Envelope
|
public function envelope(): Envelope
|
||||||
{
|
{
|
||||||
return new Envelope(subject: 'Your login code');
|
return new Envelope(subject: $this->copy()['subject']);
|
||||||
}
|
}
|
||||||
|
|
||||||
public function content(): Content
|
public function content(): Content
|
||||||
{
|
{
|
||||||
return new Content(view: 'core::auth.mail.otp');
|
return new Content(view: 'core::auth.mail.otp', with: ['intro' => $this->copy()['intro']]);
|
||||||
|
}
|
||||||
|
|
||||||
|
private function copy(): array
|
||||||
|
{
|
||||||
|
return self::COPY_BY_PURPOSE[$this->purpose] ?? self::COPY_BY_PURPOSE['login'];
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,33 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Models;
|
||||||
|
|
||||||
|
use Illuminate\Database\Eloquent\Model;
|
||||||
|
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* One row per login (see Modules\Core\Auth\Services\UserOtpService::
|
||||||
|
* validate()) — see that table's own migration docblock for why this
|
||||||
|
* exists independent of the actual session-store driver.
|
||||||
|
*/
|
||||||
|
class UserSession extends Model
|
||||||
|
{
|
||||||
|
protected $guarded = [];
|
||||||
|
|
||||||
|
protected $casts = [
|
||||||
|
'last_used_at' => 'datetime',
|
||||||
|
'revoked_at' => 'datetime',
|
||||||
|
];
|
||||||
|
|
||||||
|
public function user(): BelongsTo
|
||||||
|
{
|
||||||
|
$model = config('auth.providers.users.model');
|
||||||
|
|
||||||
|
return $this->belongsTo($model);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function isRevoked(): bool
|
||||||
|
{
|
||||||
|
return $this->revoked_at !== null;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,68 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Privacy;
|
||||||
|
|
||||||
|
use Modules\Core\Auth\Models\UserSession;
|
||||||
|
use Modules\Core\Privacy\Contracts\PersonalDataProvider;
|
||||||
|
use Modules\Core\Privacy\DTOs\CustomerSubject;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureOutcome;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderErasureResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderExportResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\UserSubject;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Login-session device/location metadata (user_sessions) — ip_address and
|
||||||
|
* user_agent are device/location fingerprinting data tied 1:1 to a User via
|
||||||
|
* user_id, never to a Customer (business account), so this is User-scope
|
||||||
|
* only. No legal retention requirement applies to session metadata the way
|
||||||
|
* it does to Order (there's no tax/accounting reason to keep old login IPs
|
||||||
|
* around), so rows are deleted outright rather than pseudonymized.
|
||||||
|
*
|
||||||
|
* A hard delete here is safe regardless of whether the User row itself has
|
||||||
|
* already been erased — CustomerDataProvider::eraseForUser() nulls the
|
||||||
|
* User's own name/email but never touches user_sessions, and the table's
|
||||||
|
* own user_id FK is cascadeOnDelete() only if the User row itself were
|
||||||
|
* hard-deleted, which it never is (erasure here means "identity nulled,"
|
||||||
|
* not "row removed" — see docs/modules.md "Customer/User Pairing").
|
||||||
|
*/
|
||||||
|
class UserSessionDataProvider implements PersonalDataProvider
|
||||||
|
{
|
||||||
|
public function name(): string
|
||||||
|
{
|
||||||
|
return 'sessions';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
return new ProviderExportResult('sessions', []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$sessions = UserSession::where('user_id', $subject->userId)->get();
|
||||||
|
|
||||||
|
return new ProviderExportResult('sessions', $sessions->map(fn (UserSession $session) => [
|
||||||
|
'id' => $session->id,
|
||||||
|
'ip_address' => $session->ip_address,
|
||||||
|
'user_agent' => $session->user_agent,
|
||||||
|
'last_used_at' => $session->last_used_at?->toIso8601String(),
|
||||||
|
'revoked_at' => $session->revoked_at?->toIso8601String(),
|
||||||
|
])->all());
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
return new ProviderErasureResult('sessions', ErasureOutcome::Skipped, 'Login sessions belong to individual Users, not Customer accounts.');
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
$deleted = UserSession::where('user_id', $subject->userId)->delete();
|
||||||
|
|
||||||
|
if ($deleted === 0) {
|
||||||
|
return new ProviderErasureResult('sessions', ErasureOutcome::Skipped, 'No login sessions for this user.');
|
||||||
|
}
|
||||||
|
|
||||||
|
return new ProviderErasureResult('sessions', ErasureOutcome::Erased);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -11,7 +11,13 @@ class OtpService
|
|||||||
private const EXPIRY_MINUTES = 10;
|
private const EXPIRY_MINUTES = 10;
|
||||||
private const CODE_LENGTH = 6;
|
private const CODE_LENGTH = 6;
|
||||||
|
|
||||||
public function generateAndSend(string $email): bool
|
/**
|
||||||
|
* $purpose is forwarded as-is to OtpMail, which only recognizes a
|
||||||
|
* fixed set of keys (see its own COPY_BY_PURPOSE) — an unrecognized
|
||||||
|
* value there just falls back to 'login' rather than failing here, so
|
||||||
|
* this method has nothing of its own to validate.
|
||||||
|
*/
|
||||||
|
public function generateAndSend(string $email, string $purpose = 'login'): bool
|
||||||
{
|
{
|
||||||
$staff = Staff::where('email', $email)->first();
|
$staff = Staff::where('email', $email)->first();
|
||||||
|
|
||||||
@@ -25,7 +31,7 @@ class OtpService
|
|||||||
$staff->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES);
|
$staff->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES);
|
||||||
$staff->save();
|
$staff->save();
|
||||||
|
|
||||||
Mail::to($staff->email)->send(new OtpMail($staff->first_name, $code));
|
Mail::to($staff->email)->send(new OtpMail($staff->first_name, $code, $purpose));
|
||||||
|
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,23 +2,97 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Auth\Services;
|
namespace Modules\Core\Auth\Services;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Facades\Auth;
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Illuminate\Support\Facades\Event;
|
||||||
use Illuminate\Support\Facades\Mail;
|
use Illuminate\Support\Facades\Mail;
|
||||||
|
use Illuminate\Support\Facades\RateLimiter;
|
||||||
|
use Modules\Core\Auth\Events\UserAuthenticated;
|
||||||
|
use Modules\Core\Auth\Events\UserCreated;
|
||||||
|
use Modules\Core\Auth\Exceptions\OtpThrottledException;
|
||||||
use Modules\Core\Auth\Mail\UserOtpMail;
|
use Modules\Core\Auth\Mail\UserOtpMail;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The storefront's passwordless login — a shopper supplies only an email
|
||||||
|
* (Shopify-style), gets a 6-digit code, and validate() authenticates the
|
||||||
|
* `web` guard via Auth::login().
|
||||||
|
*
|
||||||
|
* That alone is enough to merge/associate any active guest cart into the
|
||||||
|
* now-known customer — Auth::login() fires Illuminate\Auth\Events\Login,
|
||||||
|
* which Lunar's own Lunar\Listeners\CartSessionAuthListener (registered
|
||||||
|
* unconditionally in LunarServiceProvider::boot(), no opt-in needed)
|
||||||
|
* already listens to, calling CartSession::associate() with
|
||||||
|
* config('lunar.cart.auth_policy') — 'merge' by default, 'override' if a
|
||||||
|
* consumer changes that config. Deliberately no cart-association call
|
||||||
|
* here: doing our own on top would run a SECOND merge attempt with a
|
||||||
|
* hardcoded policy that ignores whatever the consumer configured.
|
||||||
|
*
|
||||||
|
* generateAndSend()'s find-or-create already triggers the full
|
||||||
|
* Customer/User pairing cascade for a genuinely new email — see
|
||||||
|
* Modules\Core\Auth\Events\UserCreated's own docblock and
|
||||||
|
* Modules\Core\Customer\Listeners\CreateCustomerForUser.
|
||||||
|
*
|
||||||
|
* Two independent throttles, both configured under core.auth.otp — see
|
||||||
|
* config/core.php's own comment for why they're separate: max_attempts
|
||||||
|
* caps wrong guesses against ONE code; generation_limit caps how often a
|
||||||
|
* NEW code can be requested for the same email at all (closes both the
|
||||||
|
* "regenerate to reset my guess count" loophole and mail-bombing one
|
||||||
|
* inbox).
|
||||||
|
*
|
||||||
|
* validate() also records a UserSessionService entry for the new login —
|
||||||
|
* see that class's own docblock for the "logout everywhere" registry
|
||||||
|
* this feeds (Modules\Core\Auth\Http\Middleware\EnsureSessionNotRevoked
|
||||||
|
* is the enforcement half; a consuming app must add it to its own
|
||||||
|
* middleware stack). $request is optional purely so this service stays
|
||||||
|
* callable from a context with no HTTP request at all (a console
|
||||||
|
* command, a test) — user-agent/ip are simply not recorded when omitted.
|
||||||
|
*/
|
||||||
class UserOtpService
|
class UserOtpService
|
||||||
{
|
{
|
||||||
private const EXPIRY_MINUTES = 10;
|
private const EXPIRY_MINUTES = 10;
|
||||||
private const CODE_LENGTH = 6;
|
private const CODE_LENGTH = 6;
|
||||||
|
|
||||||
|
public function __construct(
|
||||||
|
private readonly UserSessionService $sessions,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws OtpThrottledException if this email has requested too many
|
||||||
|
* codes within core.auth.otp.generation_decay_minutes
|
||||||
|
*/
|
||||||
public function generateAndSend(string $email): bool
|
public function generateAndSend(string $email): bool
|
||||||
{
|
{
|
||||||
|
$limiterKey = $this->generationLimiterKey($email);
|
||||||
|
$maxGenerations = (int) config('core.auth.otp.generation_limit', 3);
|
||||||
|
|
||||||
|
if (RateLimiter::tooManyAttempts($limiterKey, $maxGenerations)) {
|
||||||
|
throw new OtpThrottledException(RateLimiter::availableIn($limiterKey));
|
||||||
|
}
|
||||||
|
|
||||||
|
RateLimiter::hit($limiterKey, (int) config('core.auth.otp.generation_decay_minutes', 10) * 60);
|
||||||
|
|
||||||
$model = config('auth.providers.users.model');
|
$model = config('auth.providers.users.model');
|
||||||
$user = $model::firstOrCreate(['email' => $email]);
|
$user = $model::firstOrCreate(['email' => $email]);
|
||||||
|
|
||||||
|
// wasRecentlyCreated is Eloquent's own "did firstOrCreate() just
|
||||||
|
// INSERT, or did it find an existing row" flag — the only reliable
|
||||||
|
// way to tell them apart from firstOrCreate()'s return value alone.
|
||||||
|
// Without this check, a genuinely new signup never fired
|
||||||
|
// UserCreated at all (this class's own docblock claimed the
|
||||||
|
// Customer/User pairing cascade "already triggers" here, which was
|
||||||
|
// false as written — see Modules\Core\Customer\Listeners\
|
||||||
|
// CreateCustomerForUser, which depends entirely on this event).
|
||||||
|
if ($user->wasRecentlyCreated) {
|
||||||
|
Event::dispatch(new UserCreated($user));
|
||||||
|
}
|
||||||
|
|
||||||
$code = str_pad((string) random_int(0, 999999), self::CODE_LENGTH, '0', STR_PAD_LEFT);
|
$code = str_pad((string) random_int(0, 999999), self::CODE_LENGTH, '0', STR_PAD_LEFT);
|
||||||
|
|
||||||
$user->otp_code = $code;
|
$user->otp_code = $code;
|
||||||
$user->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES);
|
$user->otp_expires_at = now()->addMinutes(self::EXPIRY_MINUTES);
|
||||||
|
$user->otp_attempts = 0;
|
||||||
$user->save();
|
$user->save();
|
||||||
|
|
||||||
Mail::to($user->email)->send(new UserOtpMail($user->name ?? $user->email, $code));
|
Mail::to($user->email)->send(new UserOtpMail($user->name ?? $user->email, $code));
|
||||||
@@ -26,23 +100,70 @@ class UserOtpService
|
|||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
public function validate(string $email, string $code)
|
/**
|
||||||
|
* A wrong code counts against core.auth.otp.max_attempts and, once
|
||||||
|
* reached, invalidates the code entirely — the shopper must request
|
||||||
|
* a fresh one via generateAndSend() (itself throttled independently
|
||||||
|
* — see this class's own docblock) rather than being able to keep
|
||||||
|
* guessing against a still-live code for the rest of its 10-minute
|
||||||
|
* expiry window.
|
||||||
|
*/
|
||||||
|
public function validate(string $email, string $code, ?Request $request = null): ?Authenticatable
|
||||||
{
|
{
|
||||||
$model = config('auth.providers.users.model');
|
$model = config('auth.providers.users.model');
|
||||||
$user = $model::where('email', $email)->first();
|
|
||||||
|
|
||||||
if (! $user) {
|
// lockForUpdate() + a transaction make the read-check-increment-save
|
||||||
|
// below atomic across concurrent requests for the same user — without
|
||||||
|
// it, two guesses fired in parallel can each read the same
|
||||||
|
// pre-increment otp_attempts value and both save past
|
||||||
|
// max_attempts, letting an attacker exceed the lockout by
|
||||||
|
// parallelizing requests instead of sending them serially.
|
||||||
|
$result = DB::transaction(function () use ($model, $email, $code) {
|
||||||
|
$user = $model::where('email', $email)->lockForUpdate()->first();
|
||||||
|
|
||||||
|
if (! $user || ! $user->otp_expires_at || now()->isAfter($user->otp_expires_at)) {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (! $user->otp_expires_at || $user->otp_code != $code || now()->isAfter($user->otp_expires_at)) {
|
if (! hash_equals((string) $user->otp_code, $code)) {
|
||||||
|
$user->otp_attempts++;
|
||||||
|
|
||||||
|
if ($user->otp_attempts >= (int) config('core.auth.otp.max_attempts', 5)) {
|
||||||
|
$user->otp_code = null;
|
||||||
|
$user->otp_expires_at = null;
|
||||||
|
$user->otp_attempts = 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
$user->save();
|
||||||
|
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
$user->otp_code = null;
|
$user->otp_code = null;
|
||||||
$user->otp_expires_at = null;
|
$user->otp_expires_at = null;
|
||||||
|
$user->otp_attempts = 0;
|
||||||
$user->save();
|
$user->save();
|
||||||
|
|
||||||
return $user;
|
return $user;
|
||||||
|
});
|
||||||
|
|
||||||
|
if (! $result) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
RateLimiter::clear($this->generationLimiterKey($email));
|
||||||
|
|
||||||
|
Auth::login($result);
|
||||||
|
|
||||||
|
$this->sessions->record($result, $request);
|
||||||
|
|
||||||
|
Event::dispatch(new UserAuthenticated($result));
|
||||||
|
|
||||||
|
return $result;
|
||||||
|
}
|
||||||
|
|
||||||
|
private function generationLimiterKey(string $email): string
|
||||||
|
{
|
||||||
|
return 'otp-generate:'.strtolower($email);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,105 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Auth\Services;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Illuminate\Support\Str;
|
||||||
|
use Modules\Core\Auth\Models\UserSession;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The record/revoke half of the session registry — see
|
||||||
|
* database/migrations/2026_09_15_000001_create_user_sessions_table.php's
|
||||||
|
* own docblock for why this exists (SESSION_DRIVER=redis in this app has
|
||||||
|
* no "sessions" table to purge by user_id). The enforcement half is
|
||||||
|
* Modules\Core\Auth\Http\Middleware\EnsureSessionNotRevoked, which reads
|
||||||
|
* the token this class stamps into the session payload.
|
||||||
|
*/
|
||||||
|
class UserSessionService
|
||||||
|
{
|
||||||
|
private const SESSION_TOKEN_KEY = 'user_session_token';
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Called once, right after Auth::login() succeeds (see
|
||||||
|
* UserOtpService::validate()) — generates a fresh token, records it,
|
||||||
|
* and stamps it into the CURRENT session payload so
|
||||||
|
* EnsureSessionNotRevoked can look it up on later requests.
|
||||||
|
*/
|
||||||
|
public function record(Authenticatable $user, ?Request $request = null): UserSession
|
||||||
|
{
|
||||||
|
$token = Str::random(64);
|
||||||
|
|
||||||
|
$session = UserSession::create([
|
||||||
|
'user_id' => $user->getAuthIdentifier(),
|
||||||
|
'token' => $token,
|
||||||
|
'user_agent' => $request?->userAgent(),
|
||||||
|
'ip_address' => $request?->ip(),
|
||||||
|
'last_used_at' => now(),
|
||||||
|
]);
|
||||||
|
|
||||||
|
session([self::SESSION_TOKEN_KEY => $token]);
|
||||||
|
|
||||||
|
return $session;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Revokes every OTHER active session for $user — the current one
|
||||||
|
* (matched by the token in the CURRENT session payload) is left
|
||||||
|
* alone, matching Laravel's own logoutOtherDevices() semantics
|
||||||
|
* (there just isn't a password to re-verify against here — this is a
|
||||||
|
* passwordless account, so revocation is simply "every row that
|
||||||
|
* isn't the one making this request").
|
||||||
|
*
|
||||||
|
* Known, deliberately accepted gap: this requires only a currently
|
||||||
|
* valid session, not a freshly-completed login — so anyone holding
|
||||||
|
* an already-authenticated session (e.g. someone who sits down at an
|
||||||
|
* account left logged in on a shared/public PC) can use this to
|
||||||
|
* evict the real owner's OTHER sessions just as easily as the real
|
||||||
|
* owner could use it to evict an intruder's. A stricter version would
|
||||||
|
* require a fresh OTP re-verification (e.g. within the last few
|
||||||
|
* minutes) before allowing this call. Left as-is for now — revisit if
|
||||||
|
* this turns out to matter in practice, rather than building
|
||||||
|
* abuse-resistance against a threat model nobody's confirmed is real
|
||||||
|
* for this storefront.
|
||||||
|
*/
|
||||||
|
public function revokeOtherSessions(Authenticatable $user): int
|
||||||
|
{
|
||||||
|
$currentToken = session(self::SESSION_TOKEN_KEY);
|
||||||
|
|
||||||
|
return UserSession::query()
|
||||||
|
->where('user_id', $user->getAuthIdentifier())
|
||||||
|
->whereNull('revoked_at')
|
||||||
|
->when($currentToken, fn ($query) => $query->where('token', '!=', $currentToken))
|
||||||
|
->update(['revoked_at' => now()]);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Revokes EVERY session for $user, current one included — for a
|
||||||
|
* "this account may be compromised" response, not a routine logout.
|
||||||
|
*/
|
||||||
|
public function revokeAllSessions(Authenticatable $user): int
|
||||||
|
{
|
||||||
|
return UserSession::query()
|
||||||
|
->where('user_id', $user->getAuthIdentifier())
|
||||||
|
->whereNull('revoked_at')
|
||||||
|
->update(['revoked_at' => now()]);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return UserSession|null null if the CURRENT session has no
|
||||||
|
* recorded token at all (e.g. a session predating this feature, or
|
||||||
|
* one Auth::login() established outside UserOtpService) — treated
|
||||||
|
* as valid by EnsureSessionNotRevoked rather than rejected, since
|
||||||
|
* there's nothing to have been revoked.
|
||||||
|
*/
|
||||||
|
public function currentSession(): ?UserSession
|
||||||
|
{
|
||||||
|
$token = session(self::SESSION_TOKEN_KEY);
|
||||||
|
|
||||||
|
if (! $token) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
return UserSession::where('token', $token)->first();
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -14,6 +14,7 @@ use Illuminate\Database\Eloquent\Collection as EloquentCollection;
|
|||||||
use Illuminate\Support\Facades\Blade;
|
use Illuminate\Support\Facades\Blade;
|
||||||
use Lunar\Admin\Filament\Resources\CustomerResource;
|
use Lunar\Admin\Filament\Resources\CustomerResource;
|
||||||
use Lunar\Admin\Filament\Resources\ProductResource\Pages\EditProduct;
|
use Lunar\Admin\Filament\Resources\ProductResource\Pages\EditProduct;
|
||||||
|
use Lunar\Exceptions\MissingCurrencyPriceException;
|
||||||
use Lunar\Models\Cart;
|
use Lunar\Models\Cart;
|
||||||
use Lunar\Models\CartLine;
|
use Lunar\Models\CartLine;
|
||||||
use Lunar\Models\ProductVariant;
|
use Lunar\Models\ProductVariant;
|
||||||
@@ -47,6 +48,17 @@ class ViewCart extends ViewRecord
|
|||||||
* own OrderItemsTable loads for an order's line items (`with(['purchasable'])`,
|
* own OrderItemsTable loads for an order's line items (`with(['purchasable'])`,
|
||||||
* see vendor/lunarphp/lunar/.../OrderItemsTable::getDefaultTable()) — so
|
* see vendor/lunarphp/lunar/.../OrderItemsTable::getDefaultTable()) — so
|
||||||
* rendering the product grid doesn't N+1 per line.
|
* rendering the product grid doesn't N+1 per line.
|
||||||
|
*
|
||||||
|
* calculate() throws Lunar\Exceptions\MissingCurrencyPriceException
|
||||||
|
* (vendor PricingManager) the moment ANY line's purchasable has no
|
||||||
|
* price row for the cart's currency — including a line whose
|
||||||
|
* purchasable no longer exists at all (a deleted ProductVariant still
|
||||||
|
* referenced by cart_lines.purchasable_id), which 500'd this whole
|
||||||
|
* page rather than just leaving that one line unpriced. The Lines
|
||||||
|
* section below already guards every purchasable-derived field with
|
||||||
|
* `instanceof ProductVariant` and renders fine with $cart left
|
||||||
|
* uncalculated — subTotal/total/etc. simply won't be populated, which
|
||||||
|
* reads as a stale/pending state rather than a broken page.
|
||||||
*/
|
*/
|
||||||
protected function resolveRecord(int|string $key): Cart
|
protected function resolveRecord(int|string $key): Cart
|
||||||
{
|
{
|
||||||
@@ -58,7 +70,11 @@ class ViewCart extends ViewRecord
|
|||||||
EloquentCollection::make($cart->lines->pluck('purchasable')->filter(fn ($p) => $p instanceof ProductVariant))
|
EloquentCollection::make($cart->lines->pluck('purchasable')->filter(fn ($p) => $p instanceof ProductVariant))
|
||||||
->loadMissing(['product.thumbnail', 'images', 'values']);
|
->loadMissing(['product.thumbnail', 'images', 'values']);
|
||||||
|
|
||||||
|
try {
|
||||||
return $cart->calculate();
|
return $cart->calculate();
|
||||||
|
} catch (MissingCurrencyPriceException) {
|
||||||
|
return $cart;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
public function infolist(Schema $schema): Schema
|
public function infolist(Schema $schema): Schema
|
||||||
|
|||||||
@@ -0,0 +1,108 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Cart\Privacy;
|
||||||
|
|
||||||
|
use Lunar\Models\Cart;
|
||||||
|
use Lunar\Models\CartAddress;
|
||||||
|
use Modules\Core\Privacy\Contracts\PersonalDataProvider;
|
||||||
|
use Modules\Core\Privacy\DTOs\CustomerSubject;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureOutcome;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderErasureResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderExportResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\UserSubject;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Carts and cart addresses (lunar_carts, lunar_cart_addresses) belong to the
|
||||||
|
* Customer (business account) via customer_id, not to an individual User, so this
|
||||||
|
* is Customer-scope only. Unlike Order/OrderAddress, an abandoned cart has no
|
||||||
|
* legal retention requirement, so its addresses are freely deleted. The Cart row
|
||||||
|
* itself is left alone (any completed order it produced is handled separately by
|
||||||
|
* OrderDataProvider, which is what retention law actually cares about) — only its
|
||||||
|
* address PII is removed.
|
||||||
|
*
|
||||||
|
* Also covers Cart.meta's own PII-adjacent keys — Modules\Core\Checkout\Services\
|
||||||
|
* CheckoutService::setRecoveryConsent()/selectPaymentMethod() write
|
||||||
|
* recovery_consent/recovery_consent_at/recovery_consent_policy_version and
|
||||||
|
* payment_method/checkout_fingerprint directly onto this same Cart row, which the
|
||||||
|
* address-only erase above never touched. Kept Customer-scope, consistent with
|
||||||
|
* how Cart itself is already classified — see docs/privacy.md for the
|
||||||
|
* User-vs-Customer discussion this raised.
|
||||||
|
*/
|
||||||
|
class CartDataProvider implements PersonalDataProvider
|
||||||
|
{
|
||||||
|
private const META_KEYS = [
|
||||||
|
'recovery_consent',
|
||||||
|
'recovery_consent_at',
|
||||||
|
'recovery_consent_policy_version',
|
||||||
|
'payment_method',
|
||||||
|
'checkout_fingerprint',
|
||||||
|
];
|
||||||
|
|
||||||
|
public function name(): string
|
||||||
|
{
|
||||||
|
return 'carts';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$carts = Cart::where('customer_id', $subject->customerId)->get();
|
||||||
|
|
||||||
|
$addresses = CartAddress::whereIn('cart_id', $carts->pluck('id'))->get();
|
||||||
|
|
||||||
|
return new ProviderExportResult('carts', [
|
||||||
|
'addresses' => $addresses->map(fn (CartAddress $address) => [
|
||||||
|
'type' => $address->type,
|
||||||
|
'first_name' => $address->first_name,
|
||||||
|
'last_name' => $address->last_name,
|
||||||
|
'line_one' => $address->line_one,
|
||||||
|
'city' => $address->city,
|
||||||
|
'postcode' => $address->postcode,
|
||||||
|
'contact_email' => $address->contact_email,
|
||||||
|
'contact_phone' => $address->contact_phone,
|
||||||
|
])->all(),
|
||||||
|
'carts' => $carts->map(fn (Cart $cart) => [
|
||||||
|
'id' => $cart->id,
|
||||||
|
'meta' => $this->metaOnly($cart),
|
||||||
|
])->all(),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
return new ProviderExportResult('carts', []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
$carts = Cart::where('customer_id', $subject->customerId)->get();
|
||||||
|
|
||||||
|
CartAddress::whereIn('cart_id', $carts->pluck('id'))->delete();
|
||||||
|
|
||||||
|
foreach ($carts as $cart) {
|
||||||
|
$meta = (array) $cart->meta;
|
||||||
|
|
||||||
|
foreach (self::META_KEYS as $key) {
|
||||||
|
unset($meta[$key]);
|
||||||
|
}
|
||||||
|
|
||||||
|
$cart->update(['meta' => $meta]);
|
||||||
|
}
|
||||||
|
|
||||||
|
return new ProviderErasureResult('carts', ErasureOutcome::Erased);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
return new ProviderErasureResult('carts', ErasureOutcome::Skipped, 'Carts belong to Customer accounts, not individual users.');
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return array<string, mixed>
|
||||||
|
*/
|
||||||
|
private function metaOnly(Cart $cart): array
|
||||||
|
{
|
||||||
|
$meta = (array) $cart->meta;
|
||||||
|
|
||||||
|
return array_intersect_key($meta, array_flip(self::META_KEYS));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -14,6 +14,7 @@ enum ProductSort: string
|
|||||||
case PriceAsc = 'price_asc';
|
case PriceAsc = 'price_asc';
|
||||||
case PriceDesc = 'price_desc';
|
case PriceDesc = 'price_desc';
|
||||||
case Newest = 'newest';
|
case Newest = 'newest';
|
||||||
|
case Popularity = 'popularity';
|
||||||
|
|
||||||
public function toMeilisearchSort(): string
|
public function toMeilisearchSort(): string
|
||||||
{
|
{
|
||||||
@@ -21,6 +22,12 @@ enum ProductSort: string
|
|||||||
self::PriceAsc => 'price:asc',
|
self::PriceAsc => 'price:asc',
|
||||||
self::PriceDesc => 'price:desc',
|
self::PriceDesc => 'price:desc',
|
||||||
self::Newest => 'created_at:desc',
|
self::Newest => 'created_at:desc',
|
||||||
|
// order_count — see Modules\Core\Catalog\Services\
|
||||||
|
// ProductIndexer::toSearchableArray()'s own docblock: the same
|
||||||
|
// trailing-year, physical-order-line-count definition Lunar's
|
||||||
|
// own admin dashboard "Popular Products" widget already uses,
|
||||||
|
// aggregated per product rather than per variant.
|
||||||
|
self::Popularity => 'order_count:desc',
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,11 +2,17 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Catalog\Listeners;
|
namespace Modules\Core\Catalog\Listeners;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Queue\ShouldQueue;
|
||||||
use Lunar\Models\Product;
|
use Lunar\Models\Product;
|
||||||
use Modules\Core\Catalog\Events\ProductDeleted;
|
use Modules\Core\Catalog\Events\ProductDeleted;
|
||||||
use Modules\Core\Catalog\Events\ProductSaved;
|
use Modules\Core\Catalog\Events\ProductSaved;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
* Queued — a Meilisearch filter query plus N reindex calls with no
|
||||||
|
* same-request reader; a few seconds of stale `recommendations` on a
|
||||||
|
* referencing product's storefront page is a cosmetic, not correctness,
|
||||||
|
* concern (see the class's own docblock below).
|
||||||
|
*
|
||||||
* Keeps every product's embedded `recommendations` field (see
|
* Keeps every product's embedded `recommendations` field (see
|
||||||
* ProductIndexer) in sync when a product they recommend changes or is
|
* ProductIndexer) in sync when a product they recommend changes or is
|
||||||
* removed. Unlike Modules\Core\Catalog\Observers\ProductOptionReindexObserver's
|
* removed. Unlike Modules\Core\Catalog\Observers\ProductOptionReindexObserver's
|
||||||
@@ -27,7 +33,7 @@ use Modules\Core\Catalog\Events\ProductSaved;
|
|||||||
* SCOUT_QUEUE is configured) reindex job per matched product — this
|
* SCOUT_QUEUE is configured) reindex job per matched product — this
|
||||||
* listener itself does no synchronous Meilisearch writing.
|
* listener itself does no synchronous Meilisearch writing.
|
||||||
*/
|
*/
|
||||||
class ReindexProductsRecommendingProduct
|
class ReindexProductsRecommendingProduct implements ShouldQueue
|
||||||
{
|
{
|
||||||
public function handleSaved(ProductSaved $event): void
|
public function handleSaved(ProductSaved $event): void
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -0,0 +1,52 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Catalog\Models;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Registered via Lunar\Facades\ModelManifest::replace(Lunar\Models\
|
||||||
|
* Product::class, self::class) — see Providers\CatalogServiceProvider —
|
||||||
|
* purely to add a cast AND fillable entry for `custom_fields` (see the
|
||||||
|
* migration adding that column: database/migrations/
|
||||||
|
* ..._add_custom_fields_to_products_table.php). Without the fillable
|
||||||
|
* entry, Lunar\Models\Product's own $fillable allowlist (attribute_data,
|
||||||
|
* product_type_id, status, brand_id — custom_fields isn't in it) silently
|
||||||
|
* drops the field on every mass-assignment save (Filament's own
|
||||||
|
* $record->update($data)) — no error, no exception, the admin form shows
|
||||||
|
* the repeater's rows as saved right up until the next page load, when
|
||||||
|
* they're simply gone. Caught in practice.
|
||||||
|
*
|
||||||
|
* ModelManifest::replace() only changes what code resolving Product
|
||||||
|
* through the CONTRACT (app(Contracts\Product::class), Filament's own
|
||||||
|
* ProductResource — its $model is ProductContract::class, not the
|
||||||
|
* concrete class) or the morph map receives — it does NOT retroactively
|
||||||
|
* change what a hardcoded `Lunar\Models\Product::query()`/`::find()`
|
||||||
|
* elsewhere in this codebase (or Lunar's own internals, e.g. the
|
||||||
|
* scheduled Meilisearch reindex command — see CatalogServiceProvider,
|
||||||
|
* which references this subclass by name specifically so that path picks
|
||||||
|
* it up too) resolves to. Most of this codebase's existing Product
|
||||||
|
* references are plain type-hints (they accept whichever instance is
|
||||||
|
* handed to them, subclass included) or don't touch `custom_fields` at
|
||||||
|
* all, so they're unaffected either way.
|
||||||
|
*/
|
||||||
|
class Product extends \Lunar\Models\Product
|
||||||
|
{
|
||||||
|
// NOT `protected $casts = [...]` — that property assignment REPLACES
|
||||||
|
// the parent's own $casts array wholesale rather than merging with
|
||||||
|
// it (PHP class property redeclaration has no merge semantics), which
|
||||||
|
// would silently drop every cast Lunar\Models\Product already
|
||||||
|
// defines (attribute_data, status, etc.). mergeCasts() is Eloquent's
|
||||||
|
// own documented mechanism for a subclass adding to, not replacing,
|
||||||
|
// its parent's casts.
|
||||||
|
public function __construct(array $attributes = [])
|
||||||
|
{
|
||||||
|
parent::__construct($attributes);
|
||||||
|
|
||||||
|
$this->mergeCasts([
|
||||||
|
'custom_fields' => 'array',
|
||||||
|
]);
|
||||||
|
|
||||||
|
$this->mergeFillable([
|
||||||
|
'custom_fields',
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -5,6 +5,7 @@ namespace Modules\Core\Catalog\Services;
|
|||||||
use Illuminate\Database\Eloquent\Builder;
|
use Illuminate\Database\Eloquent\Builder;
|
||||||
use Illuminate\Database\Eloquent\Model;
|
use Illuminate\Database\Eloquent\Model;
|
||||||
use Lunar\Models\Currency;
|
use Lunar\Models\Currency;
|
||||||
|
use Lunar\Models\OrderLine;
|
||||||
use Lunar\Models\Price;
|
use Lunar\Models\Price;
|
||||||
use Lunar\Models\Product;
|
use Lunar\Models\Product;
|
||||||
use Lunar\Models\ProductVariant;
|
use Lunar\Models\ProductVariant;
|
||||||
@@ -103,6 +104,7 @@ class ProductIndexer extends BaseProductIndexer
|
|||||||
return [
|
return [
|
||||||
...parent::getSortableFields(),
|
...parent::getSortableFields(),
|
||||||
'price',
|
'price',
|
||||||
|
'order_count',
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -139,6 +141,12 @@ class ProductIndexer extends BaseProductIndexer
|
|||||||
->all();
|
->all();
|
||||||
$data['slugs'] = $model->urls->pluck('slug')->unique()->values()->all();
|
$data['slugs'] = $model->urls->pluck('slug')->unique()->values()->all();
|
||||||
$data['skus'] = $model->variants->pluck('sku')->filter()->unique()->values()->all();
|
$data['skus'] = $model->variants->pluck('sku')->filter()->unique()->values()->all();
|
||||||
|
// Only decoded correctly when $model is an instance of
|
||||||
|
// Modules\Core\Catalog\Models\Product (the custom_fields cast
|
||||||
|
// lives there, not on the base Lunar\Models\Product) — see
|
||||||
|
// CatalogServiceProvider's own comment on why the scheduled
|
||||||
|
// reindex command references that subclass by name specifically.
|
||||||
|
$data['custom_fields'] = $model->custom_fields ?? [];
|
||||||
$data['tags'] = $model->tags->pluck('value')->all();
|
$data['tags'] = $model->tags->pluck('value')->all();
|
||||||
$data['media'] = $model->media->map(fn (Media $media) => $this->mapMedia($media))->all();
|
$data['media'] = $model->media->map(fn (Media $media) => $this->mapMedia($media))->all();
|
||||||
$data['variants'] = $model->variants->map(fn (ProductVariant $variant) => $this->mapVariant($variant, $currency))->all();
|
$data['variants'] = $model->variants->map(fn (ProductVariant $variant) => $this->mapVariant($variant, $currency))->all();
|
||||||
@@ -155,6 +163,24 @@ class ProductIndexer extends BaseProductIndexer
|
|||||||
$data['in_stock'] = $model->variants->contains(
|
$data['in_stock'] = $model->variants->contains(
|
||||||
fn (ProductVariant $variant) => $variant->canBeFulfilledAtQuantity(1)
|
fn (ProductVariant $variant) => $variant->canBeFulfilledAtQuantity(1)
|
||||||
);
|
);
|
||||||
|
// Same "popular" definition as Lunar's own admin dashboard widget
|
||||||
|
// (Lunar\Admin\Filament\Widgets\Dashboard\Orders\
|
||||||
|
// PopularProductsTable) — order-line COUNT, not summed quantity,
|
||||||
|
// over the trailing year, physical lines only — just aggregated
|
||||||
|
// per PRODUCT here (across all its variants) rather than per
|
||||||
|
// variant/identifier, since a storefront "sort by popularity"
|
||||||
|
// ranks products, not individual variant SKUs. Necessarily as
|
||||||
|
// stale as any other reindex-time field here (in_stock, price) —
|
||||||
|
// there's no live equivalent without a query per page load.
|
||||||
|
$data['order_count'] = OrderLine::query()
|
||||||
|
->whereIn('purchasable_id', $model->variants->pluck('id'))
|
||||||
|
->where('purchasable_type', 'product_variant')
|
||||||
|
->where('type', 'physical')
|
||||||
|
->whereHas('order', fn ($query) => $query->whereBetween('placed_at', [
|
||||||
|
now()->subYear()->startOfDay(),
|
||||||
|
now()->endOfDay(),
|
||||||
|
]))
|
||||||
|
->count();
|
||||||
$data['recommendations'] = app(RecommendationService::class)
|
$data['recommendations'] = app(RecommendationService::class)
|
||||||
->recommend($model)
|
->recommend($model)
|
||||||
->load(['media', 'variants.prices'])
|
->load(['media', 'variants.prices'])
|
||||||
|
|||||||
@@ -254,7 +254,10 @@ class ProductService
|
|||||||
public function random(int $limit): array
|
public function random(int $limit): array
|
||||||
{
|
{
|
||||||
$raw = Product::search('')
|
$raw = Product::search('')
|
||||||
->options(['attributesToRetrieve' => ['id']])
|
->options([
|
||||||
|
'attributesToRetrieve' => ['id'],
|
||||||
|
'filter' => $this->filterBuilder->withVisibility(),
|
||||||
|
])
|
||||||
->raw();
|
->raw();
|
||||||
|
|
||||||
$ids = collect($raw['hits'] ?? [])->pluck('id')->shuffle()->take($limit)->values();
|
$ids = collect($raw['hits'] ?? [])->pluck('id')->shuffle()->take($limit)->values();
|
||||||
@@ -287,7 +290,7 @@ class ProductService
|
|||||||
private function findAllWhere(string $filter, int $limit = 1000): array
|
private function findAllWhere(string $filter, int $limit = 1000): array
|
||||||
{
|
{
|
||||||
$paginator = Product::search('')
|
$paginator = Product::search('')
|
||||||
->options(['filter' => $filter])
|
->options(['filter' => $this->filterBuilder->withVisibility($filter)])
|
||||||
->paginateRaw(perPage: $limit, page: 1);
|
->paginateRaw(perPage: $limit, page: 1);
|
||||||
|
|
||||||
return collect($this->localizer->hitsFrom($paginator))
|
return collect($this->localizer->hitsFrom($paginator))
|
||||||
|
|||||||
@@ -0,0 +1,56 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Catalog\Services;
|
||||||
|
|
||||||
|
use Lunar\Models\ProductVariant;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Generates a SKU for every ProductVariant missing one — extracted out of
|
||||||
|
* Command\BackfillMissingSkusCommand (which becomes a thin CLI wrapper
|
||||||
|
* around this, keeping --dry-run/progress-bar concerns out of the
|
||||||
|
* reusable logic) so MigrateImport\RunMigrateImportJob can also call it
|
||||||
|
* directly, right after a Shopify import, with no CLI concerns at all.
|
||||||
|
*
|
||||||
|
* Format is "SKU-P{product_id}-V{variant_id}": deterministic and
|
||||||
|
* guaranteed unique without a uniqueness check, since product_id/
|
||||||
|
* variant_id already are. Only variants with a null `sku` are touched —
|
||||||
|
* not an importer bug when one shows up after a Shopify import, the
|
||||||
|
* source CSV rows genuinely had no `Variant SKU` value (see
|
||||||
|
* MigrateImport\Shopify\ShopifyExportImporter).
|
||||||
|
*/
|
||||||
|
class SkuBackfillService
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param ?callable(ProductVariant, string): void $onEach invoked
|
||||||
|
* once per variant with the sku about to be written (or, when
|
||||||
|
* $dryRun is true, that WOULD be written) — the command's own
|
||||||
|
* --dry-run listing and progress bar hook in here without this
|
||||||
|
* service knowing anything about console output.
|
||||||
|
* @return int the number of variants processed
|
||||||
|
*/
|
||||||
|
public function backfill(bool $dryRun = false, ?callable $onEach = null): int
|
||||||
|
{
|
||||||
|
$query = ProductVariant::query()->whereNull('sku');
|
||||||
|
$total = $query->count();
|
||||||
|
|
||||||
|
if ($total === 0) {
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
$query->chunkById(500, function ($variants) use ($dryRun, $onEach) {
|
||||||
|
foreach ($variants as $variant) {
|
||||||
|
$sku = "SKU-P{$variant->product_id}-V{$variant->id}";
|
||||||
|
|
||||||
|
if (! $dryRun) {
|
||||||
|
$variant->update(['sku' => $sku]);
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($onEach !== null) {
|
||||||
|
$onEach($variant, $sku);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
return $total;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,71 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Catalog\Services;
|
||||||
|
|
||||||
|
use Illuminate\Support\Facades\DB;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Lunar\Models\Product;
|
||||||
|
use Lunar\Models\ProductVariant;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The one place ProductVariant::stock is written as a result of an order —
|
||||||
|
* previously this lived entirely inside Modules\Core\Order\Listeners\
|
||||||
|
* DecrementStockOnOrderPlaced, a listener with no Service behind it at
|
||||||
|
* all, even though stock (the column, its invariants — "never negative",
|
||||||
|
* "only in_stock variants") is fundamentally a Catalog concern, not an
|
||||||
|
* Order one. That listener is now a thin caller of this class, matching
|
||||||
|
* how every other module's event reaction delegates its actual write to
|
||||||
|
* a Service (e.g. Modules\Core\Order\Listeners\RecordPaymentTransaction
|
||||||
|
* -> Modules\Core\Order\Services\TransactionRecorder).
|
||||||
|
*
|
||||||
|
* Only decrements for `purchasable === 'in_stock'` variants — 'always' and
|
||||||
|
* 'backorder' variants are deliberately allowed to sell past (or without
|
||||||
|
* regard to) their stock count already (see ProductVariant::
|
||||||
|
* canBeFulfilledAtQuantity()), so decrementing their stock would just make
|
||||||
|
* that column an inaccurate, decreasingly-negative number with no purchasing
|
||||||
|
* consequence. Only `OrderLine::type === 'physical'` lines are considered —
|
||||||
|
* a digital line has no stock to decrement (ProductVariant::getType()).
|
||||||
|
*
|
||||||
|
* A single UPDATE per variant (`DB::table(...)->update()` with a raw
|
||||||
|
* expression), not a read-then-write on the Eloquent model — avoids a
|
||||||
|
* lost-update race between two orders decrementing the same variant
|
||||||
|
* concurrently, and skips Modules\Core\Catalog\Services\ProductIndexer::
|
||||||
|
* stock's staleness gap for the DB value itself even though the search
|
||||||
|
* index still only refreshes on the next reindex event/nightly job (see
|
||||||
|
* that class's own docblock).
|
||||||
|
*
|
||||||
|
* Never lets stock go negative (`GREATEST(stock - qty, 0)` via a raw
|
||||||
|
* expression) — an order can still be placed against a variant whose stock
|
||||||
|
* was already fully consumed by another concurrent order (Lunar has no
|
||||||
|
* stock-reservation step at cart/checkout time), so this is a best-effort
|
||||||
|
* count, not a hard inventory guarantee.
|
||||||
|
*/
|
||||||
|
class StockService
|
||||||
|
{
|
||||||
|
public function decrementForOrder(Order $order): void
|
||||||
|
{
|
||||||
|
$lines = $order->lines()
|
||||||
|
->where('type', 'physical')
|
||||||
|
->where('purchasable_type', ProductVariant::morphName())
|
||||||
|
->get(['purchasable_id', 'quantity']);
|
||||||
|
|
||||||
|
if ($lines->isEmpty()) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach ($lines as $line) {
|
||||||
|
DB::table((new ProductVariant())->getTable())
|
||||||
|
->where('id', $line->purchasable_id)
|
||||||
|
->where('purchasable', 'in_stock')
|
||||||
|
->update([
|
||||||
|
'stock' => DB::raw('GREATEST(stock - '.(int) $line->quantity.', 0)'),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
$productIds = ProductVariant::whereIn('id', $lines->pluck('purchasable_id'))
|
||||||
|
->pluck('product_id')
|
||||||
|
->unique();
|
||||||
|
|
||||||
|
Product::whereIn('id', $productIds)->get()->each->searchable();
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -10,6 +10,13 @@ use Modules\Core\Catalog\DTOs\ProductFilters;
|
|||||||
* out of ProductService (where it originated, scoped to browsing/filtering
|
* out of ProductService (where it originated, scoped to browsing/filtering
|
||||||
* without a search term) so ProductSearchService can apply the exact same
|
* without a search term) so ProductSearchService can apply the exact same
|
||||||
* filter semantics to a text query too, rather than reimplementing it.
|
* filter semantics to a text query too, rather than reimplementing it.
|
||||||
|
*
|
||||||
|
* Also the single place that composes the draft-visibility clause (see
|
||||||
|
* withVisibility()) — every Meilisearch `filter` string ProductService
|
||||||
|
* constructs, including the handful of ad-hoc ones that don't call build()
|
||||||
|
* at all (getById()/getBySlug()'s id lookup, random()'s id-only fetch),
|
||||||
|
* goes through this class so none of them can silently omit it the way a
|
||||||
|
* status filter was missing everywhere until now.
|
||||||
*/
|
*/
|
||||||
class ProductFilterBuilder
|
class ProductFilterBuilder
|
||||||
{
|
{
|
||||||
@@ -19,10 +26,10 @@ class ProductFilterBuilder
|
|||||||
* ProductService::priceRange() excludes 'price' so a price slider's own
|
* ProductService::priceRange() excludes 'price' so a price slider's own
|
||||||
* bounds don't shrink to whatever range is already selected on it.
|
* bounds don't shrink to whatever range is already selected on it.
|
||||||
*/
|
*/
|
||||||
public function build(?ProductFilters $filters, array $exclude = []): ?string
|
public function build(?ProductFilters $filters, array $exclude = []): string
|
||||||
{
|
{
|
||||||
if ($filters === null) {
|
if ($filters === null) {
|
||||||
return null;
|
return $this->withVisibility();
|
||||||
}
|
}
|
||||||
|
|
||||||
$clauses = Collection::make([
|
$clauses = Collection::make([
|
||||||
@@ -36,6 +43,27 @@ class ProductFilterBuilder
|
|||||||
'inStockOnly' => $filters->inStockOnly ? 'in_stock = true' : null,
|
'inStockOnly' => $filters->inStockOnly ? 'in_stock = true' : null,
|
||||||
])->except($exclude)->filter();
|
])->except($exclude)->filter();
|
||||||
|
|
||||||
return $clauses->isEmpty() ? null : $clauses->join(' AND ');
|
return $this->withVisibility($clauses->isEmpty() ? null : $clauses->join(' AND '));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A draft product (status = 'draft', see Lunar\Filament\Resources\
|
||||||
|
* ProductResource's own status Select) is only ever visible while
|
||||||
|
* APP_DEBUG is true — a merchant/developer previewing an unfinished
|
||||||
|
* product locally or on a staging box, never a real storefront
|
||||||
|
* visitor. Every ProductService method that builds a Meilisearch
|
||||||
|
* `filter` string, build() included, calls this rather than passing
|
||||||
|
* $rawClause straight to Product::search() — the one seam that
|
||||||
|
* guarantees none of them can omit the visibility rule.
|
||||||
|
*
|
||||||
|
* Always returns a non-empty string (never null) — a bare
|
||||||
|
* 'status = "published"' is itself a complete, valid Meilisearch
|
||||||
|
* filter on its own when $rawClause is null.
|
||||||
|
*/
|
||||||
|
public function withVisibility(?string $rawClause = null): string
|
||||||
|
{
|
||||||
|
$visibility = config('app.debug') ? null : 'status = "published"';
|
||||||
|
|
||||||
|
return Collection::make([$visibility, $rawClause])->filter()->join(' AND ');
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,18 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Checkout\Exceptions;
|
||||||
|
|
||||||
|
use RuntimeException;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Thrown by CheckoutService::selectBoxNowLocker() when the cart has no
|
||||||
|
* shipping address yet to attach the chosen locker's meta to — the
|
||||||
|
* storefront must call setShippingAddress() first.
|
||||||
|
*/
|
||||||
|
class NoShippingAddressException extends RuntimeException
|
||||||
|
{
|
||||||
|
public function __construct()
|
||||||
|
{
|
||||||
|
parent::__construct('Cannot select a Box Now locker before a shipping address is set.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -10,6 +10,7 @@ use Lunar\Base\Addressable;
|
|||||||
use Lunar\DataTypes\ShippingOption;
|
use Lunar\DataTypes\ShippingOption;
|
||||||
use Lunar\Facades\ShippingManifest;
|
use Lunar\Facades\ShippingManifest;
|
||||||
use Lunar\Models\Cart;
|
use Lunar\Models\Cart;
|
||||||
|
use Lunar\Shipping\Models\ShippingMethod;
|
||||||
use Modules\Core\Cart\Services\CartService;
|
use Modules\Core\Cart\Services\CartService;
|
||||||
use Modules\Core\Checkout\Events\BillingAddressSet;
|
use Modules\Core\Checkout\Events\BillingAddressSet;
|
||||||
use Modules\Core\Checkout\Events\PaymentMethodSelected;
|
use Modules\Core\Checkout\Events\PaymentMethodSelected;
|
||||||
@@ -17,12 +18,15 @@ use Modules\Core\Checkout\Events\RecoveryConsentSet;
|
|||||||
use Modules\Core\Checkout\Events\ShippingAddressSet;
|
use Modules\Core\Checkout\Events\ShippingAddressSet;
|
||||||
use Modules\Core\Checkout\Events\ShippingOptionSelected;
|
use Modules\Core\Checkout\Events\ShippingOptionSelected;
|
||||||
use Modules\Core\Checkout\Exceptions\InvalidShippingOptionException;
|
use Modules\Core\Checkout\Exceptions\InvalidShippingOptionException;
|
||||||
|
use Modules\Core\Checkout\Exceptions\NoShippingAddressException;
|
||||||
use Modules\Core\Checkout\Exceptions\TermsNotAcceptedException;
|
use Modules\Core\Checkout\Exceptions\TermsNotAcceptedException;
|
||||||
use Modules\Core\Checkout\Exceptions\UnknownPaymentTypeException;
|
use Modules\Core\Checkout\Exceptions\UnknownPaymentTypeException;
|
||||||
|
use Modules\Core\Payment\Contracts\RequiresFulfillmentType;
|
||||||
use Modules\Core\Payment\DTOs\PaymentResult;
|
use Modules\Core\Payment\DTOs\PaymentResult;
|
||||||
use Modules\Core\Payment\Models\PaymentMethod;
|
use Modules\Core\Payment\Models\PaymentMethod;
|
||||||
use Modules\Core\Payment\Services\PaymentDriverRegistry;
|
use Modules\Core\Payment\Services\PaymentDriverRegistry;
|
||||||
use Modules\Core\Payment\Services\PaymentMethodCache;
|
use Modules\Core\Payment\Services\PaymentMethodCache;
|
||||||
|
use Modules\Core\Shipping\Support\FulfillmentType;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Storefront-facing checkout operations, mirroring
|
* Storefront-facing checkout operations, mirroring
|
||||||
@@ -49,9 +53,35 @@ class CheckoutService
|
|||||||
private readonly PaymentMethodCache $paymentMethods,
|
private readonly PaymentMethodCache $paymentMethods,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Lunar\Actions\Carts\AddAddress (behind Cart::setShippingAddress())
|
||||||
|
* always deletes the cart's existing shipping address row and inserts
|
||||||
|
* a brand new one — it has no notion of "update in place." Every field
|
||||||
|
* on the new row therefore starts blank, including `meta`, which is
|
||||||
|
* where selectBoxNowLocker() stores the shopper's chosen locker. Since
|
||||||
|
* the checkout page autosaves the address form on every field change
|
||||||
|
* (not just once), any edit made after picking a locker — even an
|
||||||
|
* unrelated one, like delivery instructions — silently wiped the
|
||||||
|
* locker choice by recreating the row out from under it.
|
||||||
|
*
|
||||||
|
* Carries the previous row's box_now_locker forward onto the new one
|
||||||
|
* so the two features don't stomp on each other, without needing
|
||||||
|
* Lunar's own AddAddress action to change. The old row's meta is read
|
||||||
|
* BEFORE Lunar deletes it, since afterward there's nothing left to
|
||||||
|
* read.
|
||||||
|
*/
|
||||||
public function setShippingAddress(array|Addressable $address): Cart
|
public function setShippingAddress(array|Addressable $address): Cart
|
||||||
{
|
{
|
||||||
$cart = $this->cart->currentOrCreate()->setShippingAddress($address);
|
$cartBefore = $this->cart->currentOrCreate();
|
||||||
|
$boxNowLocker = $cartBefore->shippingAddress?->meta['box_now_locker'] ?? null;
|
||||||
|
|
||||||
|
$cart = $cartBefore->setShippingAddress($address);
|
||||||
|
|
||||||
|
if ($boxNowLocker !== null) {
|
||||||
|
$newAddress = $cart->shippingAddress;
|
||||||
|
$newAddress->meta = [...($newAddress->meta?->toArray() ?? []), 'box_now_locker' => $boxNowLocker];
|
||||||
|
$newAddress->save();
|
||||||
|
}
|
||||||
|
|
||||||
Event::dispatch(new ShippingAddressSet($cart, $address));
|
Event::dispatch(new ShippingAddressSet($cart, $address));
|
||||||
|
|
||||||
@@ -141,15 +171,71 @@ class CheckoutService
|
|||||||
|
|
||||||
$cart = $cartBefore->setShippingOption($option);
|
$cart = $cartBefore->setShippingOption($option);
|
||||||
|
|
||||||
|
// Switching away from Box Now leaves a stale box_now_locker on the
|
||||||
|
// address's meta (see setShippingAddress()'s own docblock for why
|
||||||
|
// it survives address-row recreation) — irrelevant while a
|
||||||
|
// different method is selected, but wrong if the shopper later
|
||||||
|
// switches BACK to Box Now and it resurfaces as if still chosen,
|
||||||
|
// possibly for a locker that no longer exists/fits. Cleared here,
|
||||||
|
// the one place that knows the method just changed.
|
||||||
|
if ($identifier !== 'box-now') {
|
||||||
|
$address = $cart->shippingAddress;
|
||||||
|
|
||||||
|
if ($address && isset($address->meta['box_now_locker'])) {
|
||||||
|
$meta = $address->meta->toArray();
|
||||||
|
unset($meta['box_now_locker']);
|
||||||
|
$address->meta = $meta;
|
||||||
|
$address->save();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
Event::dispatch(new ShippingOptionSelected($cart, $option));
|
Event::dispatch(new ShippingOptionSelected($cart, $option));
|
||||||
|
|
||||||
return $cart;
|
return $cart;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Records the shopper's chosen Box Now locker on the cart's shipping
|
||||||
|
* address (Cart\Addresses::shippingAddress()->meta['box_now_locker']),
|
||||||
|
* not on the cart itself — Lunar\Pipelines\Order\Creation\
|
||||||
|
* CreateOrderAddresses copies every cart address's full attributes
|
||||||
|
* (meta included) onto the new order address when the order is placed,
|
||||||
|
* so this is what Modules\Core\Shipping\Carriers\BoxNow\
|
||||||
|
* BoxNowFulfillmentService and Modules\Core\Shipping\Extensions\
|
||||||
|
* OrderViewExtension already expect to find at
|
||||||
|
* $order->shippingAddress->meta['box_now_locker']['locationId'].
|
||||||
|
*
|
||||||
|
* No validation against Box Now's own /destinations list here — this
|
||||||
|
* mirrors setShippingAddress()'s leniency (see its own docblock/the
|
||||||
|
* class-level note on required-field enforcement happening at the
|
||||||
|
* payment gate, not mid-checkout). An invalid/stale locationId still
|
||||||
|
* surfaces later, at BoxNowFulfillmentService::createShipment() time.
|
||||||
|
*
|
||||||
|
* @throws NoShippingAddressException if the cart has no shipping
|
||||||
|
* address yet
|
||||||
|
*/
|
||||||
|
public function selectBoxNowLocker(array $locker): Cart
|
||||||
|
{
|
||||||
|
$cart = $this->cart->currentOrCreate();
|
||||||
|
$address = $cart->shippingAddress;
|
||||||
|
|
||||||
|
if (! $address) {
|
||||||
|
throw new NoShippingAddressException();
|
||||||
|
}
|
||||||
|
|
||||||
|
$address->meta = [
|
||||||
|
...($address->meta?->toArray() ?? []),
|
||||||
|
'box_now_locker' => $locker,
|
||||||
|
];
|
||||||
|
$address->save();
|
||||||
|
|
||||||
|
return $cart;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Every payment method currently offered to the storefront, ordered by
|
* Every payment method currently offered to the storefront, ordered by
|
||||||
* Modules\Core\Payment\Models\PaymentMethod::position — a row is
|
* Modules\Core\Payment\Models\PaymentMethod::position — a row is
|
||||||
* offered only when ALL three checks pass, each meaning something
|
* offered only when ALL four checks pass, each meaning something
|
||||||
* different to an admin diagnosing why a method isn't showing up (see
|
* different to an admin diagnosing why a method isn't showing up (see
|
||||||
* docs/payments.md):
|
* docs/payments.md):
|
||||||
* 1. `enabled` — an admin turned it on.
|
* 1. `enabled` — an admin turned it on.
|
||||||
@@ -160,17 +246,61 @@ class CheckoutService
|
|||||||
* vanished driver can never silently look "available").
|
* vanished driver can never silently look "available").
|
||||||
* 3. the resolved driver reports Configurable::isConfigured() — its
|
* 3. the resolved driver reports Configurable::isConfigured() — its
|
||||||
* own runtime requirements (e.g. an API key) are met.
|
* own runtime requirements (e.g. an API key) are met.
|
||||||
|
* 4. its driver's RequiresFulfillmentType (if it declares one)
|
||||||
|
* agrees with the cart's currently selected shipping method's own
|
||||||
|
* fulfillment type (Modules\Core\Shipping\Support\
|
||||||
|
* FulfillmentType::resolve()) — "Pay in store" offered alongside
|
||||||
|
* a courier delivery makes no sense (no staff member present at
|
||||||
|
* handoff to take cash), and cash-on-delivery alongside store
|
||||||
|
* pickup is equally meaningless (OfflinePaymentDriver already
|
||||||
|
* covers that in-person moment). A cart with no shipping option
|
||||||
|
* selected yet imposes no constraint here — every method is
|
||||||
|
* offered until a fulfillment type is actually known, the same
|
||||||
|
* leniency setShippingAddress()'s own docblock describes for
|
||||||
|
* required-field enforcement happening at the payment gate, not
|
||||||
|
* mid-checkout.
|
||||||
*
|
*
|
||||||
* @return Collection<int, PaymentMethod>
|
* @return Collection<int, PaymentMethod>
|
||||||
*/
|
*/
|
||||||
public function getPaymentMethods(): Collection
|
public function getPaymentMethods(): Collection
|
||||||
{
|
{
|
||||||
|
$fulfillmentType = $this->currentFulfillmentType();
|
||||||
|
|
||||||
return $this->paymentMethods->all()
|
return $this->paymentMethods->all()
|
||||||
->filter(fn (PaymentMethod $method) => $method->enabled && $method->driver_missing_at === null)
|
->filter(fn (PaymentMethod $method) => $method->enabled && $method->driver_missing_at === null)
|
||||||
->filter(fn (PaymentMethod $method) => $this->paymentDrivers->resolve($method->driver)?->isConfigured() ?? false)
|
->filter(function (PaymentMethod $method) use ($fulfillmentType) {
|
||||||
|
$driver = $this->paymentDrivers->resolve($method->driver);
|
||||||
|
|
||||||
|
if (! $driver?->isConfigured()) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($fulfillmentType === null || ! $driver instanceof RequiresFulfillmentType) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
return $driver->requiredFulfillmentType() === $fulfillmentType;
|
||||||
|
})
|
||||||
->values();
|
->values();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @return 'carrier'|'store_pickup'|null null when the cart has no
|
||||||
|
* shipping option selected yet
|
||||||
|
*/
|
||||||
|
private function currentFulfillmentType(): ?string
|
||||||
|
{
|
||||||
|
$identifier = $this->cart->currentOrCreate()->shippingAddress?->shipping_option;
|
||||||
|
|
||||||
|
if ($identifier === null) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
$method = ShippingMethod::where('code', $identifier)->first();
|
||||||
|
|
||||||
|
return $method ? FulfillmentType::resolve($method) : null;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Records which payment type the shopper picked (Cart::meta
|
* Records which payment type the shopper picked (Cart::meta
|
||||||
* ['payment_method']) — read by Modules\Core\Payment\Pipelines\
|
* ['payment_method']) — read by Modules\Core\Payment\Pipelines\
|
||||||
|
|||||||
@@ -0,0 +1,51 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Command;
|
||||||
|
|
||||||
|
use Illuminate\Console\Command;
|
||||||
|
use Lunar\Models\ProductVariant;
|
||||||
|
use Modules\Core\Catalog\Services\SkuBackfillService;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* CLI wrapper (--dry-run, a progress bar) around Catalog\Services\
|
||||||
|
* SkuBackfillService — see that class's own docblock for the actual
|
||||||
|
* backfill logic, also called automatically after a Shopify import (see
|
||||||
|
* MigrateImport\RunMigrateImportJob).
|
||||||
|
*/
|
||||||
|
class BackfillMissingSkusCommand extends Command
|
||||||
|
{
|
||||||
|
protected $signature = 'boboko:catalog:backfill-skus {--dry-run : List what would change without writing}';
|
||||||
|
|
||||||
|
protected $description = 'Generate a SKU for every product variant that is missing one';
|
||||||
|
|
||||||
|
public function handle(SkuBackfillService $backfill): void
|
||||||
|
{
|
||||||
|
$dryRun = (bool) $this->option('dry-run');
|
||||||
|
|
||||||
|
$total = ProductVariant::query()->whereNull('sku')->count();
|
||||||
|
|
||||||
|
if ($total === 0) {
|
||||||
|
$this->info('No variants are missing a SKU.');
|
||||||
|
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->info(($dryRun ? '[dry-run] ' : '') . "Backfilling SKUs for {$total} variant(s)...");
|
||||||
|
|
||||||
|
$bar = $this->output->createProgressBar($total);
|
||||||
|
$bar->start();
|
||||||
|
|
||||||
|
$backfill->backfill($dryRun, function (ProductVariant $variant, string $sku) use ($dryRun, $bar) {
|
||||||
|
if ($dryRun) {
|
||||||
|
$this->newLine();
|
||||||
|
$this->line("Variant {$variant->id}: sku => {$sku}");
|
||||||
|
}
|
||||||
|
|
||||||
|
$bar->advance();
|
||||||
|
});
|
||||||
|
|
||||||
|
$bar->finish();
|
||||||
|
$this->newLine();
|
||||||
|
$this->info($dryRun ? 'Dry run complete — no changes were written.' : 'Done.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -66,6 +66,16 @@ class InstallLunarCommand extends Command
|
|||||||
]);
|
]);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (! Language::where('code', 'el')->exists()) {
|
||||||
|
$this->components->info('Adding Greek language');
|
||||||
|
|
||||||
|
Language::create([
|
||||||
|
'code' => 'el',
|
||||||
|
'name' => 'Greek',
|
||||||
|
'default' => false,
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
if (! Currency::whereDefault(true)->exists()) {
|
if (! Currency::whereDefault(true)->exists()) {
|
||||||
$this->components->info('Adding a default currency (USD)');
|
$this->components->info('Adding a default currency (USD)');
|
||||||
|
|
||||||
@@ -310,7 +320,10 @@ class InstallLunarCommand extends Command
|
|||||||
|
|
||||||
PaymentMethod::create([
|
PaymentMethod::create([
|
||||||
'type' => 'cash-on-delivery',
|
'type' => 'cash-on-delivery',
|
||||||
'name' => 'Cash on Delivery',
|
'name' => [
|
||||||
|
'en' => 'Cash on Delivery',
|
||||||
|
'el' => 'Αντικαταβολή',
|
||||||
|
],
|
||||||
'driver' => 'cash-on-delivery',
|
'driver' => 'cash-on-delivery',
|
||||||
'capture_mode' => 'pay',
|
'capture_mode' => 'pay',
|
||||||
'position' => 0,
|
'position' => 0,
|
||||||
|
|||||||
@@ -0,0 +1,47 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Command;
|
||||||
|
|
||||||
|
use Illuminate\Console\Command;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureRequestStatus;
|
||||||
|
use Modules\Core\Privacy\Jobs\EraseDataSubjectJob;
|
||||||
|
use Modules\Core\Privacy\Models\DataErasureRequest;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Finds every erasure request whose grace period (config('core.privacy.
|
||||||
|
* grace_period_days')) has passed and dispatches one EraseDataSubjectJob per
|
||||||
|
* request — see docs/privacy.md. This command itself just finds due requests and
|
||||||
|
* dispatches; the actual erasure work happens in the queue, one job per request,
|
||||||
|
* so one failing request doesn't block the others. Meant to run daily via the
|
||||||
|
* scheduler; each consuming app wires that in its own Console\Kernel (or
|
||||||
|
* bootstrap/app.php schedule closure on Laravel 11+), the same way it owns any
|
||||||
|
* other scheduled task — this package doesn't register schedules itself.
|
||||||
|
*/
|
||||||
|
class ProcessErasureRequestsCommand extends Command
|
||||||
|
{
|
||||||
|
protected $signature = 'boboko:privacy:process-erasure-requests';
|
||||||
|
|
||||||
|
protected $description = 'Dispatch an erasure job for every pending data-erasure request whose grace period has passed';
|
||||||
|
|
||||||
|
public function handle(): void
|
||||||
|
{
|
||||||
|
$due = DataErasureRequest::where('status', ErasureRequestStatus::Pending)
|
||||||
|
->where('scheduled_for', '<=', now())
|
||||||
|
->get();
|
||||||
|
|
||||||
|
if ($due->isEmpty()) {
|
||||||
|
$this->info('No due erasure requests.');
|
||||||
|
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach ($due as $request) {
|
||||||
|
EraseDataSubjectJob::dispatch($request);
|
||||||
|
|
||||||
|
$scope = $request->isForCustomer() ? 'customer' : 'user';
|
||||||
|
$this->info("Dispatched erasure job for {$scope} #{$request->subject_id} (request #{$request->id})");
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->info('Dispatched '.$due->count().' erasure job(s).');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,199 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Command;
|
||||||
|
|
||||||
|
use Illuminate\Console\Command;
|
||||||
|
use Lunar\Models\Product;
|
||||||
|
use Modules\Core\Auth\Models\Staff;
|
||||||
|
use Modules\Core\Auth\Services\OtpService;
|
||||||
|
use Modules\Core\MigrateImport\Models\ImportMapping;
|
||||||
|
|
||||||
|
use function Laravel\Prompts\password;
|
||||||
|
use function Laravel\Prompts\text;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Irreversibly deletes every Product and everything that only exists
|
||||||
|
* because of a product — variants, variant prices, product-option value
|
||||||
|
* assignments, product images/media, product associations, the
|
||||||
|
* ImportMapping rows tying them back to an external source, and the
|
||||||
|
* Meilisearch product index. Deliberately does NOT touch catalog
|
||||||
|
* STRUCTURE other products could still reference: ProductOption/
|
||||||
|
* ProductOptionValue definitions ("Size", "Color" as reusable option
|
||||||
|
* types), Brands, Collections, Tags, Customer Groups — none of those are
|
||||||
|
* products, they're config a merchant would otherwise have to rebuild
|
||||||
|
* from scratch.
|
||||||
|
*
|
||||||
|
* Two gates a destructive, whole-catalog, irreversible operation
|
||||||
|
* warrants — deliberately NOT restricted to non-production on top of
|
||||||
|
* these; a real, legitimate use case is wiping a client's demo/seed
|
||||||
|
* catalog on a production database right before real launch, and the OTP
|
||||||
|
* below already proves the operator has real staff access, not just
|
||||||
|
* shell access to wherever `php artisan` happens to be runnable:
|
||||||
|
* 1. An OTP emailed to a real Staff account (reusing Auth\Services\
|
||||||
|
* OtpService — the exact mechanism admin login already uses).
|
||||||
|
* 2. Typing the literal product count back, not just "yes" — a plain
|
||||||
|
* confirm() is too easy to reflexively accept; forcing the operator
|
||||||
|
* to read and retype the actual number they're about to delete is a
|
||||||
|
* last check against running this against the wrong environment/
|
||||||
|
* database by mistake.
|
||||||
|
*
|
||||||
|
* Deletes via Eloquent model instances, not DB::table()->delete() —
|
||||||
|
* Product/ProductVariant use Spatie's InteractsWithMedia (see Lunar\Base\
|
||||||
|
* Traits\HasMedia), which only cleans up media files/rows on a real model
|
||||||
|
* `deleted` event, never on a raw query-builder delete.
|
||||||
|
*/
|
||||||
|
class WipeCatalogCommand extends Command
|
||||||
|
{
|
||||||
|
protected $signature = 'boboko:wipe-catalog {--email= : Staff email to send the confirmation code to}';
|
||||||
|
|
||||||
|
protected $description = 'Irreversibly delete every product, variant, and related catalog data';
|
||||||
|
|
||||||
|
public function handle(OtpService $otp): int
|
||||||
|
{
|
||||||
|
// withTrashed() — a prior soft-delete-only bug in this command
|
||||||
|
// (fixed in wipe() below) could leave ghost rows a plain count()
|
||||||
|
// would never see, silently reporting "nothing to do" while they
|
||||||
|
// sit there breaking other things (e.g. the admin's own global
|
||||||
|
// search, which assumes every returned product has variants).
|
||||||
|
$productCount = Product::withTrashed()->count();
|
||||||
|
|
||||||
|
if ($productCount === 0) {
|
||||||
|
$this->info('No products exist — nothing to do.');
|
||||||
|
|
||||||
|
return self::SUCCESS;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (! $this->authorize($otp)) {
|
||||||
|
return self::FAILURE;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->warn("This will PERMANENTLY delete {$productCount} product(s) and everything that only exists because of them (variants, prices, images, product-option assignments, associations). This cannot be undone.");
|
||||||
|
|
||||||
|
$typed = text(label: "Type the product count ({$productCount}) to confirm");
|
||||||
|
|
||||||
|
if ($typed !== (string) $productCount) {
|
||||||
|
$this->error('Count did not match — aborted, nothing was deleted.');
|
||||||
|
|
||||||
|
return self::FAILURE;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->wipe();
|
||||||
|
|
||||||
|
$this->info("Deleted {$productCount} product(s) and all related data.");
|
||||||
|
|
||||||
|
return self::SUCCESS;
|
||||||
|
}
|
||||||
|
|
||||||
|
private function authorize(OtpService $otp): bool
|
||||||
|
{
|
||||||
|
$email = $this->option('email') ?? text(
|
||||||
|
label: 'Staff email to send a confirmation code to',
|
||||||
|
validate: fn (string $value) => Staff::where('email', $value)->exists()
|
||||||
|
? null
|
||||||
|
: 'No staff account with that email exists.',
|
||||||
|
);
|
||||||
|
|
||||||
|
if (! $otp->generateAndSend($email, purpose: 'wipe-catalog')) {
|
||||||
|
$this->error('Could not send a confirmation code to that email.');
|
||||||
|
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->info("A confirmation code was sent to {$email}.");
|
||||||
|
|
||||||
|
$code = password(label: 'Enter the confirmation code');
|
||||||
|
|
||||||
|
if ($otp->validate($email, $code) === null) {
|
||||||
|
$this->error('Invalid or expired code — aborted, nothing was deleted.');
|
||||||
|
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Every step below goes through a real Eloquent relation, never a raw
|
||||||
|
* table name — Lunar's own table prefix is configurable
|
||||||
|
* (config('lunar.database.table_prefix'), applied in BaseModel's
|
||||||
|
* constructor), so a hardcoded 'lunar_...' string would silently
|
||||||
|
* no-op on an install using a different one.
|
||||||
|
*
|
||||||
|
* Order matters: product_associations and the product/product_option
|
||||||
|
* pivot have a real FK to `products` but no ON DELETE CASCADE (both
|
||||||
|
* RESTRICT, Laravel's own default), so they're detached before the
|
||||||
|
* product/variant rows they reference — deleting a product that
|
||||||
|
* still has either would throw. ProductVariant's own `prices` (a
|
||||||
|
* plain morph, HasPrices trait — no FK constraint at all) would
|
||||||
|
* otherwise silently orphan rather than throw, so it's cleared the
|
||||||
|
* same way regardless. media_variant and product_option_value_
|
||||||
|
* product_variant DO cascade at the DB level (see their own
|
||||||
|
* migrations), so deleting the variant itself is enough for those two.
|
||||||
|
*
|
||||||
|
* Deliberately NOT chunkById() — that re-queries "id > lastSeenId"
|
||||||
|
* every iteration, but deleting rows inside the loop shrinks the
|
||||||
|
* table out from under it: any product whose id fell in a range
|
||||||
|
* chunkById() had already stepped past could be silently skipped and
|
||||||
|
* never actually deleted at all. Caught in practice — the first real
|
||||||
|
* run of this command left orphaned Media rows (Spatie's own
|
||||||
|
* deleteAllMedia(), fired from Product's `deleting` event, never ran
|
||||||
|
* for the skipped products) whose 'image' ImportMapping rows then
|
||||||
|
* caused a LATER Shopify re-import to silently reuse those now-
|
||||||
|
* orphaned Media objects instead of importing fresh ones — see
|
||||||
|
* MigrateImport\Shopify\ShopifyExportImporter::resolveOrImportImage()'s
|
||||||
|
* own docblock for that half of the same incident. Always re-querying
|
||||||
|
* the first N remaining rows (never advancing an id cursor) guarantees
|
||||||
|
* every product is actually visited exactly once, however many are
|
||||||
|
* deleted out from under the query as it goes.
|
||||||
|
*/
|
||||||
|
private function wipe(): void
|
||||||
|
{
|
||||||
|
ImportMapping::whereIn('source_type', ['product', 'variant', 'image'])->delete();
|
||||||
|
|
||||||
|
while (true) {
|
||||||
|
// withTrashed(): Product/ProductVariant both use SoftDeletes
|
||||||
|
// — a plain query would stop seeing a product the moment
|
||||||
|
// forceDelete() below actually removes it, which is fine, but
|
||||||
|
// WITHOUT withTrashed() here this loop would never even
|
||||||
|
// fetch a row that a previous, buggy run of this command
|
||||||
|
// (or any other code) had already soft-deleted without
|
||||||
|
// force-deleting it. Ghost rows like that are exactly what
|
||||||
|
// this command exists to remove.
|
||||||
|
$products = Product::withTrashed()
|
||||||
|
->with(['variants' => fn ($query) => $query->withTrashed(), 'associations', 'inverseAssociations'])
|
||||||
|
->limit(100)
|
||||||
|
->get();
|
||||||
|
|
||||||
|
if ($products->isEmpty()) {
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach ($products as $product) {
|
||||||
|
$product->associations()->delete();
|
||||||
|
$product->inverseAssociations()->delete();
|
||||||
|
$product->productOptions()->detach();
|
||||||
|
|
||||||
|
foreach ($product->variants as $variant) {
|
||||||
|
$variant->prices()->delete();
|
||||||
|
// NOT delete() — Product/ProductVariant both use
|
||||||
|
// SoftDeletes, and a plain delete() only sets
|
||||||
|
// deleted_at, leaving the row (and, for Product, its
|
||||||
|
// media) sitting in the table. This command's whole
|
||||||
|
// purpose is an irreversible wipe; a soft-deleted
|
||||||
|
// ghost row is the opposite of that. Caught in
|
||||||
|
// practice — a prior run's plain delete() left 185
|
||||||
|
// ghost Product rows with zero real variants, which
|
||||||
|
// then crashed the admin's own global search
|
||||||
|
// (Lunar\Admin\Filament\Resources\ProductResource::
|
||||||
|
// getGlobalSearchResultDetails() assumes
|
||||||
|
// $record->variants->first() is never null).
|
||||||
|
$variant->forceDelete();
|
||||||
|
}
|
||||||
|
|
||||||
|
$product->forceDelete();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
Product::removeAllFromSearch();
|
||||||
|
}
|
||||||
|
}
|
||||||
+71
-5
@@ -7,7 +7,11 @@ use Lunar\Admin\Filament\Resources\OrderResource\Pages\Components\OrderItemsTabl
|
|||||||
use Filament\Contracts\Plugin;
|
use Filament\Contracts\Plugin;
|
||||||
use Filament\Panel;
|
use Filament\Panel;
|
||||||
use Illuminate\Database\Eloquent\Relations\HasMany;
|
use Illuminate\Database\Eloquent\Relations\HasMany;
|
||||||
|
use Illuminate\Database\Eloquent\Relations\MorphMany;
|
||||||
use Illuminate\Support\Facades\Mail;
|
use Illuminate\Support\Facades\Mail;
|
||||||
|
use Lunar\Admin\Filament\Resources\CustomerResource;
|
||||||
|
use Lunar\Admin\Filament\Resources\CustomerResource\Pages\EditCustomer;
|
||||||
|
use Lunar\Admin\Filament\Resources\CustomerResource\Pages\ViewCustomer;
|
||||||
use Lunar\Admin\Filament\Resources\ProductOptionResource;
|
use Lunar\Admin\Filament\Resources\ProductOptionResource;
|
||||||
use Lunar\Admin\Filament\Resources\ProductOptionResource\RelationManagers\ValuesRelationManager;
|
use Lunar\Admin\Filament\Resources\ProductOptionResource\RelationManagers\ValuesRelationManager;
|
||||||
use Lunar\Admin\Filament\Resources\OrderResource;
|
use Lunar\Admin\Filament\Resources\OrderResource;
|
||||||
@@ -15,6 +19,7 @@ use Lunar\Admin\Filament\Resources\ProductResource;
|
|||||||
use Lunar\Admin\Filament\Resources\StaffResource;
|
use Lunar\Admin\Filament\Resources\StaffResource;
|
||||||
use Lunar\Admin\Models\Staff as LunarStaff;
|
use Lunar\Admin\Models\Staff as LunarStaff;
|
||||||
use Lunar\Admin\Support\Facades\LunarPanel;
|
use Lunar\Admin\Support\Facades\LunarPanel;
|
||||||
|
use Lunar\Models\Customer;
|
||||||
use Lunar\Models\Product;
|
use Lunar\Models\Product;
|
||||||
use Lunar\Shipping\Filament\Resources\ShippingMethodResource;
|
use Lunar\Shipping\Filament\Resources\ShippingMethodResource;
|
||||||
use Lunar\Shipping\Filament\Resources\ShippingMethodResource\Pages\ListShippingMethod;
|
use Lunar\Shipping\Filament\Resources\ShippingMethodResource\Pages\ListShippingMethod;
|
||||||
@@ -28,9 +33,15 @@ use Modules\Core\Catalog\Filament\Extensions\ValuesRelationManagerExtension;
|
|||||||
use Modules\Core\Localization\Filament\Resources\LanguageLineResource;
|
use Modules\Core\Localization\Filament\Resources\LanguageLineResource;
|
||||||
use Modules\Core\Order\Filament\Extensions\OrderItemsTableExtension;
|
use Modules\Core\Order\Filament\Extensions\OrderItemsTableExtension;
|
||||||
use Modules\Core\Order\Filament\Extensions\OrderPaymentMethodSummaryExtension;
|
use Modules\Core\Order\Filament\Extensions\OrderPaymentMethodSummaryExtension;
|
||||||
use Modules\Core\Order\Filament\Extensions\OrderRefundActionsExtension;
|
use Modules\Core\Order\Filament\Extensions\OrderActionsExtension;
|
||||||
use Modules\Core\Order\Filament\Extensions\OrderTransactionsExtension;
|
use Modules\Core\Order\Filament\Extensions\OrderTransactionsExtension;
|
||||||
use Modules\Core\Payment\Filament\Resources\PaymentMethodResource;
|
use Modules\Core\Payment\Filament\Resources\PaymentMethodResource;
|
||||||
|
use Modules\Core\Privacy\Filament\Extensions\CustomerErasureActionsExtension;
|
||||||
|
use Modules\Core\Privacy\Filament\Extensions\CustomerErasureRelationsExtension;
|
||||||
|
use Modules\Core\Privacy\Filament\Resources\DataErasureRequestResource;
|
||||||
|
use Modules\Core\Privacy\Filament\Resources\DataExportRequestResource;
|
||||||
|
use Modules\Core\Privacy\Models\DataErasureRequest;
|
||||||
|
use Modules\Core\Privacy\Models\DataExportRequest;
|
||||||
use Modules\Core\Review\Filament\Extensions\ProductResourceExtension;
|
use Modules\Core\Review\Filament\Extensions\ProductResourceExtension;
|
||||||
use Modules\Core\Review\Models\ProductReview;
|
use Modules\Core\Review\Models\ProductReview;
|
||||||
use Modules\Core\Shipping\Extensions\OrderShipmentsExtension;
|
use Modules\Core\Shipping\Extensions\OrderShipmentsExtension;
|
||||||
@@ -56,6 +67,8 @@ class CorePlugin implements Plugin
|
|||||||
->login(Login::class)
|
->login(Login::class)
|
||||||
->resources([
|
->resources([
|
||||||
LanguageLineResource::class,
|
LanguageLineResource::class,
|
||||||
|
DataErasureRequestResource::class,
|
||||||
|
DataExportRequestResource::class,
|
||||||
CartResource::class,
|
CartResource::class,
|
||||||
PaymentMethodResource::class,
|
PaymentMethodResource::class,
|
||||||
ShipmentResource::class,
|
ShipmentResource::class,
|
||||||
@@ -70,13 +83,66 @@ class CorePlugin implements Plugin
|
|||||||
ValuesRelationManager::class => ValuesRelationManagerExtension::class,
|
ValuesRelationManager::class => ValuesRelationManagerExtension::class,
|
||||||
ShippingMethodResource::class => ShippingMethodResourceExtension::class,
|
ShippingMethodResource::class => ShippingMethodResourceExtension::class,
|
||||||
ListShippingMethod::class => ShippingMethodListExtension::class,
|
ListShippingMethod::class => ShippingMethodListExtension::class,
|
||||||
ManageOrder::class => [OrderViewExtension::class, OrderRefundActionsExtension::class, OrderTransactionsExtension::class, OrderPaymentMethodSummaryExtension::class, OrderShipmentsExtension::class],
|
ManageOrder::class => [OrderViewExtension::class, OrderActionsExtension::class, OrderTransactionsExtension::class, OrderPaymentMethodSummaryExtension::class, OrderShipmentsExtension::class],
|
||||||
OrderItemsTable::class => OrderItemsTableExtension::class,
|
OrderItemsTable::class => OrderItemsTableExtension::class,
|
||||||
|
// headerActions() is resolved per PAGE class, not per resource class —
|
||||||
|
// unlike extendForm()/extendTable(), which really are resource-keyed
|
||||||
|
// (called statically from the Resource class itself). Registering this
|
||||||
|
// under CustomerResource::class would silently never fire; it has to be
|
||||||
|
// keyed by each concrete page it should appear on. Layered with
|
||||||
|
// whatever extension the consuming app registers for the same page —
|
||||||
|
// LunarPanel::extensions() merges per key, and this one only touches
|
||||||
|
// headerActions(), so it never conflicts with an app's own extension
|
||||||
|
// (see docs/modules.md "Layering Module and App Configuration").
|
||||||
|
EditCustomer::class => CustomerErasureActionsExtension::class,
|
||||||
|
ViewCustomer::class => CustomerErasureActionsExtension::class,
|
||||||
|
// getRelations(), unlike headerActions(), genuinely is resolved
|
||||||
|
// statically from the Resource class itself — CustomerResource::class
|
||||||
|
// is the correct key here.
|
||||||
|
CustomerResource::class => CustomerErasureRelationsExtension::class,
|
||||||
]);
|
]);
|
||||||
|
|
||||||
Product::macro('reviews', function (): HasMany {
|
// resolveRelationUsing(), not macro() — Illuminate\Database\Eloquent\
|
||||||
/** @var Product $this */
|
// Model does not use the Macroable trait in this Laravel version, so
|
||||||
return $this->hasMany(ProductReview::class);
|
// Product::macro(...)/Customer::macro(...)/$userModel::macro(...)
|
||||||
|
// silently fall through to Model::__callStatic(), which instantiates
|
||||||
|
// the model and tries to call the method as a real one, hitting
|
||||||
|
// newQuery()->getConnection() — this crashes every console command
|
||||||
|
// and every request, since CorePlugin::register() runs during
|
||||||
|
// provider registration, before the DB connection is configured
|
||||||
|
// ("Call to a member function connection() on null"). This bit us
|
||||||
|
// once already; resolveRelationUsing() is Eloquent's real, intended,
|
||||||
|
// connection-free extension point for exactly this (Order::
|
||||||
|
// resolveRelationUsing('shipments', ...) in ShippingServiceProvider
|
||||||
|
// already uses it correctly).
|
||||||
|
Product::resolveRelationUsing('reviews', function (Product $product): HasMany {
|
||||||
|
return $product->hasMany(ProductReview::class);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Customer::erasureRequests()/exportRequests() and the User-model
|
||||||
|
// equivalents below let a relation manager scope
|
||||||
|
// DataErasureRequest/DataExportRequest to one specific subject — both
|
||||||
|
// tables use a plain subject_type/subject_id pair rather than Laravel's
|
||||||
|
// usual morphs() convention, since one column pair identifies either a
|
||||||
|
// Customer or a User (see docs/privacy.md "User-scope vs Customer-scope"),
|
||||||
|
// so this is a MorphMany built by hand rather than a bare Eloquent
|
||||||
|
// convention lookup.
|
||||||
|
Customer::resolveRelationUsing('erasureRequests', function (Customer $customer): MorphMany {
|
||||||
|
return $customer->morphMany(DataErasureRequest::class, 'subject', 'subject_type', 'subject_id');
|
||||||
|
});
|
||||||
|
|
||||||
|
Customer::resolveRelationUsing('exportRequests', function (Customer $customer): MorphMany {
|
||||||
|
return $customer->morphMany(DataExportRequest::class, 'subject', 'subject_type', 'subject_id');
|
||||||
|
});
|
||||||
|
|
||||||
|
$userModel = config('auth.providers.users.model');
|
||||||
|
|
||||||
|
$userModel::resolveRelationUsing('erasureRequests', function ($user): MorphMany {
|
||||||
|
return $user->morphMany(DataErasureRequest::class, 'subject', 'subject_type', 'subject_id');
|
||||||
|
});
|
||||||
|
|
||||||
|
$userModel::resolveRelationUsing('exportRequests', function ($user): MorphMany {
|
||||||
|
return $user->morphMany(DataExportRequest::class, 'subject', 'subject_type', 'subject_id');
|
||||||
});
|
});
|
||||||
|
|
||||||
LunarStaff::addActivitylogExcept([
|
LunarStaff::addActivitylogExcept([
|
||||||
|
|||||||
@@ -0,0 +1,22 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dispatched by Modules\Core\Customer\Services\CustomerAccountService::
|
||||||
|
* createAddress(). $causer is carried explicitly (unlike e.g.
|
||||||
|
* Modules\Core\Payment\Events\PaymentMethodCreated, which is always
|
||||||
|
* staff-caused implicitly) because this write happens on the `web`
|
||||||
|
* guard, not `staff` — a listener logging this needs to know who to
|
||||||
|
* attribute it to without guessing a guard.
|
||||||
|
*/
|
||||||
|
class CustomerAddressCreated
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
public readonly Address $address,
|
||||||
|
public readonly Authenticatable $causer,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
|
||||||
|
class CustomerAddressDeleted
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $address Snapshot of the deleted
|
||||||
|
* row — already gone from the database by dispatch time.
|
||||||
|
*/
|
||||||
|
public function __construct(
|
||||||
|
public readonly array $address,
|
||||||
|
public readonly Authenticatable $causer,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
|
||||||
|
class CustomerAddressUpdated
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $old Snapshot of the changed
|
||||||
|
* attributes before the update.
|
||||||
|
*/
|
||||||
|
public function __construct(
|
||||||
|
public readonly Address $address,
|
||||||
|
public readonly array $old,
|
||||||
|
public readonly Authenticatable $causer,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Events;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Modules\Core\Customer\Models\Customer;
|
||||||
|
|
||||||
|
class CustomerProfileUpdated
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $old Snapshot of the changed
|
||||||
|
* attributes before the update.
|
||||||
|
*/
|
||||||
|
public function __construct(
|
||||||
|
public readonly Customer $customer,
|
||||||
|
public readonly array $old,
|
||||||
|
public readonly Authenticatable $causer,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Exceptions;
|
||||||
|
|
||||||
|
use RuntimeException;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Thrown by Modules\Core\Customer\Services\CustomerAccountService when an
|
||||||
|
* address id doesn't belong to the customer making the request — never
|
||||||
|
* a plain 404/ModelNotFoundException, so a storefront can't probe for
|
||||||
|
* another customer's address ids by trying sequential ones and reading
|
||||||
|
* the response shape.
|
||||||
|
*/
|
||||||
|
class AddressNotFoundException extends RuntimeException
|
||||||
|
{
|
||||||
|
public function __construct()
|
||||||
|
{
|
||||||
|
parent::__construct('Address not found.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Exceptions;
|
||||||
|
|
||||||
|
use RuntimeException;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Thrown by Modules\Core\Customer\Services\CustomerAccountService when an
|
||||||
|
* order id doesn't belong to the customer making the request (or isn't
|
||||||
|
* placed yet) — never a plain 404/ModelNotFoundException, so a
|
||||||
|
* storefront can't probe for another customer's order ids.
|
||||||
|
*/
|
||||||
|
class OrderNotFoundException extends RuntimeException
|
||||||
|
{
|
||||||
|
public function __construct()
|
||||||
|
{
|
||||||
|
parent::__construct('Order not found.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -6,6 +6,19 @@ use Lunar\Facades\ModelManifest;
|
|||||||
use Lunar\Models\Contracts\Customer as CustomerContract;
|
use Lunar\Models\Contracts\Customer as CustomerContract;
|
||||||
use Modules\Core\Auth\Events\UserCreated;
|
use Modules\Core\Auth\Events\UserCreated;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Deliberately NOT queued, even though UserCreated (requesting an OTP
|
||||||
|
* code) and the login that follows it (submitting the code) are normally
|
||||||
|
* separate requests with a real time gap between them — that gap is not
|
||||||
|
* a guarantee this code controls. A busy/backed-up queue (a deploy in
|
||||||
|
* progress, a crashed worker, a traffic spike) could make this job run
|
||||||
|
* AFTER the shopper has already logged in and something has read
|
||||||
|
* $user->latestCustomer() (Modules\Core\Customer\Services\
|
||||||
|
* CustomerAccountService), silently returning null for a legitimately
|
||||||
|
* paired user with no retry anywhere to catch it. Kept synchronous so the
|
||||||
|
* Customer always exists by the time UserCreated's dispatch call returns,
|
||||||
|
* regardless of queue health.
|
||||||
|
*/
|
||||||
class CreateCustomerForUser
|
class CreateCustomerForUser
|
||||||
{
|
{
|
||||||
public function handle(UserCreated $event): void
|
public function handle(UserCreated $event): void
|
||||||
|
|||||||
@@ -0,0 +1,65 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Listeners;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Queue\ShouldQueue;
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressCreated;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressDeleted;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressUpdated;
|
||||||
|
use Modules\Core\Customer\Events\CustomerProfileUpdated;
|
||||||
|
use Modules\Core\Logging\ActivityLogService;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Same pattern as Payment\Listeners\LogPaymentMethodActivity — routes
|
||||||
|
* Modules\Core\Customer\Services\CustomerAccountService's own events
|
||||||
|
* through the shared Logging\ActivityLogService, giving every
|
||||||
|
* shopper-initiated address/profile change an audit trail (previously
|
||||||
|
* none existed at all for account self-service writes). $causer is
|
||||||
|
* passed through explicitly on every call, since these events are
|
||||||
|
* `web`-guard-caused, not `staff`-guard — see ActivityLogService's own
|
||||||
|
* docblock for why that parameter exists.
|
||||||
|
*
|
||||||
|
* Queued — a pure audit-log write with no same-request reader; the
|
||||||
|
* shopper's own request doesn't need this to complete before responding.
|
||||||
|
*/
|
||||||
|
class LogCustomerAccountActivity implements ShouldQueue
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly ActivityLogService $activityLog,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public function handleAddressCreated(CustomerAddressCreated $event): void
|
||||||
|
{
|
||||||
|
$this->activityLog->created($event->address, $event->address->getAttributes(), $event->causer);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function handleAddressUpdated(CustomerAddressUpdated $event): void
|
||||||
|
{
|
||||||
|
$this->activityLog->updated(
|
||||||
|
$event->address,
|
||||||
|
$event->old,
|
||||||
|
$event->address->only(array_keys($event->old)),
|
||||||
|
$event->causer,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function handleAddressDeleted(CustomerAddressDeleted $event): void
|
||||||
|
{
|
||||||
|
$subject = (new Address)->forceFill($event->address);
|
||||||
|
$subject->exists = true;
|
||||||
|
$subject->id = $event->address['id'];
|
||||||
|
|
||||||
|
$this->activityLog->deleted($subject, $event->address, $event->causer);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function handleProfileUpdated(CustomerProfileUpdated $event): void
|
||||||
|
{
|
||||||
|
$this->activityLog->updated(
|
||||||
|
$event->customer,
|
||||||
|
$event->old,
|
||||||
|
$event->customer->only(array_keys($event->old)),
|
||||||
|
$event->causer,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,63 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Privacy;
|
||||||
|
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
use Modules\Core\Privacy\Contracts\PersonalDataProvider;
|
||||||
|
use Modules\Core\Privacy\DTOs\CustomerSubject;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureOutcome;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderErasureResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderExportResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\UserSubject;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A customer's saved addresses (lunar_addresses) — belong to the Customer
|
||||||
|
* (business account) via customer_id, not to an individual User, so this is
|
||||||
|
* Customer-scope only. No legal retention requirement of their own (unlike
|
||||||
|
* OrderAddress, handled by OrderDataProvider), so they're freely deleted outright
|
||||||
|
* rather than pseudonymized in place.
|
||||||
|
*/
|
||||||
|
class AddressDataProvider implements PersonalDataProvider
|
||||||
|
{
|
||||||
|
public function name(): string
|
||||||
|
{
|
||||||
|
return 'addresses';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$addresses = Address::where('customer_id', $subject->customerId)->get();
|
||||||
|
|
||||||
|
return new ProviderExportResult('addresses', $addresses->map(fn (Address $address) => [
|
||||||
|
'id' => $address->id,
|
||||||
|
'first_name' => $address->first_name,
|
||||||
|
'last_name' => $address->last_name,
|
||||||
|
'company_name' => $address->company_name,
|
||||||
|
'line_one' => $address->line_one,
|
||||||
|
'line_two' => $address->line_two,
|
||||||
|
'line_three' => $address->line_three,
|
||||||
|
'city' => $address->city,
|
||||||
|
'state' => $address->state,
|
||||||
|
'postcode' => $address->postcode,
|
||||||
|
'contact_email' => $address->contact_email,
|
||||||
|
'contact_phone' => $address->contact_phone,
|
||||||
|
])->all());
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
return new ProviderExportResult('addresses', []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
Address::where('customer_id', $subject->customerId)->delete();
|
||||||
|
|
||||||
|
return new ProviderErasureResult('addresses', ErasureOutcome::Erased);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
return new ProviderErasureResult('addresses', ErasureOutcome::Skipped, 'Addresses belong to Customer accounts, not individual users.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,122 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Privacy;
|
||||||
|
|
||||||
|
use Lunar\Models\Customer;
|
||||||
|
use Modules\Core\Privacy\Contracts\PersonalDataProvider;
|
||||||
|
use Modules\Core\Privacy\DTOs\CustomerSubject;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureOutcome;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderErasureResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderExportResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\UserSubject;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The Customer record itself (lunar_customers) and, on the User side, the User's
|
||||||
|
* own name/email. This is the one provider that implements both scopes
|
||||||
|
* meaningfully, and they are deliberately kept from touching each other's data:
|
||||||
|
*
|
||||||
|
* - eraseForCustomer() clears the account's own fields (name, company, tax id)
|
||||||
|
* only — it never touches any linked User's login or identity, even though
|
||||||
|
* $customer->users exists. Erasing a business account must not destroy the
|
||||||
|
* login access of every person who works there.
|
||||||
|
* - eraseForUser() clears that one person's name/email only — it never touches
|
||||||
|
* the Customer record's own fields, and it also detaches the User from every
|
||||||
|
* Customer they're linked to (the customer_user pivot — see docs/modules.md
|
||||||
|
* "Customer/User Pairing"), since erasing a person's identity should end
|
||||||
|
* their membership everywhere, without erasing the business accounts
|
||||||
|
* themselves or any other User still linked to them.
|
||||||
|
*
|
||||||
|
* No legal retention requirement applies to this table on its own, so both
|
||||||
|
* directions are freely erased — Order/OrderAddress, which DO have a retention
|
||||||
|
* requirement, are handled separately by OrderDataProvider.
|
||||||
|
*/
|
||||||
|
class CustomerDataProvider implements PersonalDataProvider
|
||||||
|
{
|
||||||
|
public function name(): string
|
||||||
|
{
|
||||||
|
return 'customer';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$customer = Customer::find($subject->customerId);
|
||||||
|
|
||||||
|
return new ProviderExportResult('customer', $customer ? [
|
||||||
|
'id' => $customer->id,
|
||||||
|
'title' => $customer->title,
|
||||||
|
'first_name' => $customer->first_name,
|
||||||
|
'last_name' => $customer->last_name,
|
||||||
|
'company_name' => $customer->company_name,
|
||||||
|
'tax_identifier' => $customer->tax_identifier,
|
||||||
|
'meta' => $customer->meta,
|
||||||
|
'users' => $customer->users->map(fn ($user) => [
|
||||||
|
'id' => $user->id,
|
||||||
|
'name' => $user->name,
|
||||||
|
'email' => $user->email,
|
||||||
|
])->all(),
|
||||||
|
] : []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$model = config('auth.providers.users.model');
|
||||||
|
$user = $model::find($subject->userId);
|
||||||
|
|
||||||
|
return new ProviderExportResult('customer', $user ? [
|
||||||
|
'id' => $user->id,
|
||||||
|
'name' => $user->name,
|
||||||
|
'email' => $user->email,
|
||||||
|
'customers' => $user->customers->map(fn (Customer $customer) => [
|
||||||
|
'id' => $customer->id,
|
||||||
|
'company_name' => $customer->company_name,
|
||||||
|
])->all(),
|
||||||
|
] : []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
$customer = Customer::find($subject->customerId);
|
||||||
|
|
||||||
|
if (! $customer) {
|
||||||
|
return new ProviderErasureResult('customer', ErasureOutcome::Skipped, 'Customer record not found.');
|
||||||
|
}
|
||||||
|
|
||||||
|
$customer->update([
|
||||||
|
'title' => null,
|
||||||
|
'first_name' => 'Erased',
|
||||||
|
'last_name' => "Customer #{$customer->id}",
|
||||||
|
'company_name' => null,
|
||||||
|
'tax_identifier' => null,
|
||||||
|
'account_ref' => null,
|
||||||
|
'meta' => null,
|
||||||
|
]);
|
||||||
|
|
||||||
|
return new ProviderErasureResult('customer', ErasureOutcome::Erased);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
$model = config('auth.providers.users.model');
|
||||||
|
$user = $model::find($subject->userId);
|
||||||
|
|
||||||
|
if (! $user) {
|
||||||
|
return new ProviderErasureResult('customer', ErasureOutcome::Skipped, 'User record not found.');
|
||||||
|
}
|
||||||
|
|
||||||
|
$user->customers()->detach();
|
||||||
|
|
||||||
|
$user->update([
|
||||||
|
'name' => null,
|
||||||
|
'email' => "erased-user-{$user->id}@example.invalid",
|
||||||
|
// A live OTP code left on an otherwise-erased row is a residual
|
||||||
|
// secret tied to an identity that no longer exists here — clear
|
||||||
|
// it alongside name/email rather than leaving it to expire on
|
||||||
|
// its own 10-minute window.
|
||||||
|
'otp_code' => null,
|
||||||
|
'otp_expires_at' => null,
|
||||||
|
'otp_attempts' => 0,
|
||||||
|
]);
|
||||||
|
|
||||||
|
return new ProviderErasureResult('customer', ErasureOutcome::Erased);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,255 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Customer\Services;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
|
use Illuminate\Pagination\LengthAwarePaginator;
|
||||||
|
use Illuminate\Support\Arr;
|
||||||
|
use Illuminate\Support\Facades\Event;
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use LogicException;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressCreated;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressDeleted;
|
||||||
|
use Modules\Core\Customer\Events\CustomerAddressUpdated;
|
||||||
|
use Modules\Core\Customer\Events\CustomerProfileUpdated;
|
||||||
|
use Modules\Core\Customer\Exceptions\AddressNotFoundException;
|
||||||
|
use Modules\Core\Customer\Exceptions\OrderNotFoundException;
|
||||||
|
use Modules\Core\Customer\Models\Customer;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The storefront-facing "My Account" API — mirrors Modules\Core\Cart\
|
||||||
|
* Services\CartService's shape, one boboko-owned service a storefront
|
||||||
|
* calls, so Lunar's own Customer/Order/Address models stay an
|
||||||
|
* implementation detail. Every method is scoped to the given
|
||||||
|
* Authenticatable's own Customer::latestCustomer() (see docs/modules.md
|
||||||
|
* "Customer/User Pairing") — there is no method here that accepts a bare
|
||||||
|
* order/address id without also requiring the owning user, precisely so
|
||||||
|
* a controller built on top of this can't accidentally leak one
|
||||||
|
* customer's data to another by trusting a client-supplied id alone.
|
||||||
|
*
|
||||||
|
* $user->latestCustomer() can be null for a User that has no paired
|
||||||
|
* Customer yet (shouldn't happen via the normal OTP-login cascade — see
|
||||||
|
* Modules\Core\Auth\Events\UserCreated — but is defended against anyway,
|
||||||
|
* since nothing stops a User row existing without one, e.g. seeded data)
|
||||||
|
* — every method returns an empty/null result rather than throwing in
|
||||||
|
* that case, since "no customer paired yet" isn't a not-found error, it's
|
||||||
|
* a legitimately empty account.
|
||||||
|
*
|
||||||
|
* Address/profile writes go through an explicit column allowlist
|
||||||
|
* (WRITABLE_ADDRESS_FIELDS/WRITABLE_PROFILE_FIELDS) rather than trusting
|
||||||
|
* Lunar\Models\Address/Customer's own $guarded = [] — that flag makes
|
||||||
|
* every column mass-assignable at the model layer, including
|
||||||
|
* customer_id on addresses, so a caller passing through an unfiltered
|
||||||
|
* request array (a real risk for a storefront controller built directly
|
||||||
|
* against this service) could otherwise reassign an address to a
|
||||||
|
* different customer entirely, or overwrite created_at/id. Arr::only()
|
||||||
|
* silently drops anything not on the allowlist rather than erroring —
|
||||||
|
* this is a safety boundary, not form validation (a storefront still
|
||||||
|
* validates its own request shape before calling this).
|
||||||
|
*
|
||||||
|
* Authorization here IS the ownership scoping itself, not a separate
|
||||||
|
* layer bolted on top — there is deliberately no Laravel Policy/Gate
|
||||||
|
* class for Order/Address, since a policy is meaningless without a
|
||||||
|
* controller calling authorize() against it, and this branch is scoped
|
||||||
|
* to backend services only (no routes/controllers — see the branch's own
|
||||||
|
* commit history). Every public method below takes Authenticatable $user
|
||||||
|
* as a required first argument and resolves everything else (Order,
|
||||||
|
* Address, Customer) strictly through that user's own
|
||||||
|
* latestCustomer() — there is no method that looks anything up by a bare
|
||||||
|
* id alone. A future storefront controller cannot "forget" the
|
||||||
|
* authorization check the way it could with a separate policy class,
|
||||||
|
* because the check IS how every lookup happens; skipping it isn't an
|
||||||
|
* option the method signatures allow.
|
||||||
|
*/
|
||||||
|
class CustomerAccountService
|
||||||
|
{
|
||||||
|
private const WRITABLE_ADDRESS_FIELDS = [
|
||||||
|
'title', 'first_name', 'last_name', 'company_name',
|
||||||
|
'line_one', 'line_two', 'line_three', 'city', 'state', 'postcode',
|
||||||
|
'delivery_instructions', 'contact_email', 'contact_phone',
|
||||||
|
'country_id', 'shipping_default', 'billing_default',
|
||||||
|
];
|
||||||
|
|
||||||
|
private const WRITABLE_PROFILE_FIELDS = [
|
||||||
|
'title', 'first_name', 'last_name', 'company_name', 'vat_no',
|
||||||
|
];
|
||||||
|
|
||||||
|
public function customer(Authenticatable $user): ?Customer
|
||||||
|
{
|
||||||
|
/** @var Customer|null */
|
||||||
|
return $user->latestCustomer();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Placed orders only (placed_at IS NOT NULL) — a draft/abandoned
|
||||||
|
* order with no placed_at is checkout-in-progress state, not
|
||||||
|
* something that belongs in order history.
|
||||||
|
*/
|
||||||
|
public function orders(Authenticatable $user, int $perPage = 15): LengthAwarePaginator
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
if (! $customer) {
|
||||||
|
return new LengthAwarePaginator([], 0, $perPage);
|
||||||
|
}
|
||||||
|
|
||||||
|
return $customer->orders()
|
||||||
|
->whereNotNull('placed_at')
|
||||||
|
->latest('placed_at')
|
||||||
|
->paginate($perPage);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws OrderNotFoundException if $orderId doesn't belong to this
|
||||||
|
* customer, or belongs to a draft (never placed) order
|
||||||
|
*/
|
||||||
|
public function order(Authenticatable $user, int $orderId): Order
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
$order = $customer
|
||||||
|
?->orders()
|
||||||
|
->whereNotNull('placed_at')
|
||||||
|
->with(['lines', 'shippingAddress', 'billingAddress', 'transactions', 'shipments'])
|
||||||
|
->find($orderId);
|
||||||
|
|
||||||
|
if (! $order) {
|
||||||
|
throw new OrderNotFoundException;
|
||||||
|
}
|
||||||
|
|
||||||
|
return $order;
|
||||||
|
}
|
||||||
|
|
||||||
|
public function addresses(Authenticatable $user): iterable
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
return $customer?->addresses ?? collect();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $data Any key not in
|
||||||
|
* WRITABLE_ADDRESS_FIELDS is silently dropped — see this class's
|
||||||
|
* own docblock.
|
||||||
|
*/
|
||||||
|
public function createAddress(Authenticatable $user, array $data): Address
|
||||||
|
{
|
||||||
|
$customer = $this->customerOrFail($user);
|
||||||
|
|
||||||
|
$address = $customer->addresses()->create(Arr::only($data, self::WRITABLE_ADDRESS_FIELDS));
|
||||||
|
|
||||||
|
$this->enforceSingleDefault($customer, $address);
|
||||||
|
$address->refresh();
|
||||||
|
|
||||||
|
Event::dispatch(new CustomerAddressCreated($address, $user));
|
||||||
|
|
||||||
|
return $address;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws AddressNotFoundException if $addressId doesn't belong to
|
||||||
|
* this customer
|
||||||
|
*/
|
||||||
|
public function updateAddress(Authenticatable $user, int $addressId, array $data): Address
|
||||||
|
{
|
||||||
|
$address = $this->ownedAddress($user, $addressId);
|
||||||
|
$old = $address->only(array_keys(Arr::only($data, self::WRITABLE_ADDRESS_FIELDS)));
|
||||||
|
|
||||||
|
$address->update(Arr::only($data, self::WRITABLE_ADDRESS_FIELDS));
|
||||||
|
|
||||||
|
$this->enforceSingleDefault($address->customer, $address);
|
||||||
|
$address->refresh();
|
||||||
|
|
||||||
|
Event::dispatch(new CustomerAddressUpdated($address, $old, $user));
|
||||||
|
|
||||||
|
return $address;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws AddressNotFoundException if $addressId doesn't belong to
|
||||||
|
* this customer
|
||||||
|
*/
|
||||||
|
public function deleteAddress(Authenticatable $user, int $addressId): void
|
||||||
|
{
|
||||||
|
$address = $this->ownedAddress($user, $addressId);
|
||||||
|
$snapshot = $address->getAttributes();
|
||||||
|
|
||||||
|
$address->delete();
|
||||||
|
|
||||||
|
Event::dispatch(new CustomerAddressDeleted($snapshot, $user));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Lunar has no built-in action enforcing "at most one shipping
|
||||||
|
* default / one billing default per customer" — a raw update() could
|
||||||
|
* otherwise leave two addresses both flagged shipping_default. Runs
|
||||||
|
* after every create/update, unconditionally (cheap — at most two
|
||||||
|
* single-row UPDATEs, only fired when the just-written address
|
||||||
|
* itself is a default), clearing the flag on every OTHER address of
|
||||||
|
* the same customer.
|
||||||
|
*/
|
||||||
|
private function enforceSingleDefault(Customer $customer, Address $address): void
|
||||||
|
{
|
||||||
|
if ($address->shipping_default) {
|
||||||
|
$customer->addresses()->where('id', '!=', $address->id)->update(['shipping_default' => false]);
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($address->billing_default) {
|
||||||
|
$customer->addresses()->where('id', '!=', $address->id)->update(['billing_default' => false]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws AddressNotFoundException if $addressId doesn't belong to
|
||||||
|
* this customer
|
||||||
|
*/
|
||||||
|
private function ownedAddress(Authenticatable $user, int $addressId): Address
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
$address = $customer?->addresses()->find($addressId);
|
||||||
|
|
||||||
|
if (! $address) {
|
||||||
|
throw new AddressNotFoundException;
|
||||||
|
}
|
||||||
|
|
||||||
|
return $address;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $data Any key not in
|
||||||
|
* WRITABLE_PROFILE_FIELDS is silently dropped — see this class's
|
||||||
|
* own docblock.
|
||||||
|
*/
|
||||||
|
public function updateProfile(Authenticatable $user, array $data): Customer
|
||||||
|
{
|
||||||
|
$customer = $this->customerOrFail($user);
|
||||||
|
$old = $customer->only(array_keys(Arr::only($data, self::WRITABLE_PROFILE_FIELDS)));
|
||||||
|
|
||||||
|
$customer->update(Arr::only($data, self::WRITABLE_PROFILE_FIELDS));
|
||||||
|
$customer->refresh();
|
||||||
|
|
||||||
|
Event::dispatch(new CustomerProfileUpdated($customer, $old, $user));
|
||||||
|
|
||||||
|
return $customer;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @throws LogicException if $user has no paired Customer at all —
|
||||||
|
* distinct from AddressNotFoundException/OrderNotFoundException
|
||||||
|
* (which mean "this id isn't yours"), this means the account
|
||||||
|
* itself is in an invariant-violating state the normal OTP-login
|
||||||
|
* cascade should never produce.
|
||||||
|
*/
|
||||||
|
private function customerOrFail(Authenticatable $user): Customer
|
||||||
|
{
|
||||||
|
$customer = $this->customer($user);
|
||||||
|
|
||||||
|
if (! $customer) {
|
||||||
|
throw new LogicException('This user has no paired Customer record.');
|
||||||
|
}
|
||||||
|
|
||||||
|
return $customer;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Export;
|
||||||
|
|
||||||
|
use Closure;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* One column in a CsvWriter schema: a header label plus a closure that pulls this
|
||||||
|
* column's value out of one record. The closure doesn't care what shape a record
|
||||||
|
* is — an array, an Eloquent model, a DTO — so the same CsvWriter serves any
|
||||||
|
* domain (GDPR export, an admin catalog export, an accounting export) by simply
|
||||||
|
* being handed a different column schema and a different row source.
|
||||||
|
*/
|
||||||
|
final class CsvColumn
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param Closure(mixed):((string|int|float|null)) $value
|
||||||
|
*/
|
||||||
|
public function __construct(
|
||||||
|
public readonly string $header,
|
||||||
|
public readonly Closure $value,
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -0,0 +1,45 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Export;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A generic columns + rows -> CSV file writer. No knowledge of any domain (GDPR,
|
||||||
|
* catalog, accounting, ...) — a caller supplies the schema (CsvColumn[]) and the
|
||||||
|
* data source (any iterable of records), and this writes one CSV. Reusable for
|
||||||
|
* any future bulk-export need without modification.
|
||||||
|
*/
|
||||||
|
class CsvWriter
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @param array<int, CsvColumn> $columns
|
||||||
|
* @param iterable<mixed> $rows
|
||||||
|
*/
|
||||||
|
public function write(array $columns, iterable $rows, string $path): void
|
||||||
|
{
|
||||||
|
$handle = fopen($path, 'w');
|
||||||
|
|
||||||
|
fputcsv($handle, array_map(fn (CsvColumn $column) => $column->header, $columns));
|
||||||
|
|
||||||
|
foreach ($rows as $row) {
|
||||||
|
fputcsv($handle, array_map(
|
||||||
|
fn (CsvColumn $column) => $this->stringify(($column->value)($row)),
|
||||||
|
$columns
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
fclose($handle);
|
||||||
|
}
|
||||||
|
|
||||||
|
private function stringify(mixed $value): string
|
||||||
|
{
|
||||||
|
if ($value === null) {
|
||||||
|
return '';
|
||||||
|
}
|
||||||
|
|
||||||
|
if (is_array($value)) {
|
||||||
|
return json_encode($value);
|
||||||
|
}
|
||||||
|
|
||||||
|
return (string) $value;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -2,12 +2,21 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Localization\Listeners;
|
namespace Modules\Core\Localization\Listeners;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Queue\ShouldQueue;
|
||||||
use Modules\Core\Localization\Events\LanguageCreated;
|
use Modules\Core\Localization\Events\LanguageCreated;
|
||||||
use Modules\Core\Localization\Events\LanguageDeleted;
|
use Modules\Core\Localization\Events\LanguageDeleted;
|
||||||
use Modules\Core\Localization\Events\LanguageUpdated;
|
use Modules\Core\Localization\Events\LanguageUpdated;
|
||||||
use Modules\Core\Localization\Services\LanguageCache;
|
use Modules\Core\Localization\Services\LanguageCache;
|
||||||
|
|
||||||
class FlushLanguageCache
|
/**
|
||||||
|
* Queued — the only reader of this cache is Modules\Core\Localization\
|
||||||
|
* Middleware\LocaleMiddleware on a LATER storefront request, never the
|
||||||
|
* same admin request that edited/created/deleted the Language row (that
|
||||||
|
* request redirects to a fresh page read straight from the DB, not this
|
||||||
|
* cache). A few seconds of eventual consistency before the queue worker
|
||||||
|
* picks this up is an acceptable trade for not blocking the admin save.
|
||||||
|
*/
|
||||||
|
class FlushLanguageCache implements ShouldQueue
|
||||||
{
|
{
|
||||||
public function __construct(private readonly LanguageCache $languages) {}
|
public function __construct(private readonly LanguageCache $languages) {}
|
||||||
|
|
||||||
|
|||||||
@@ -2,6 +2,7 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Localization\Listeners;
|
namespace Modules\Core\Localization\Listeners;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Queue\ShouldQueue;
|
||||||
use Illuminate\Support\Facades\Cache;
|
use Illuminate\Support\Facades\Cache;
|
||||||
use Modules\Core\Localization\Events\TranslationCreated;
|
use Modules\Core\Localization\Events\TranslationCreated;
|
||||||
use Modules\Core\Localization\Events\TranslationDeleted;
|
use Modules\Core\Localization\Events\TranslationDeleted;
|
||||||
@@ -15,8 +16,13 @@ use Spatie\TranslationLoader\LanguageLine;
|
|||||||
* `group`/`key` (the old group's cached array never gets told a row left it).
|
* `group`/`key` (the old group's cached array never gets told a row left it).
|
||||||
* This listener flushes every group+locale combination touched by either the
|
* This listener flushes every group+locale combination touched by either the
|
||||||
* old or new state so nothing can remain stale.
|
* old or new state so nothing can remain stale.
|
||||||
|
*
|
||||||
|
* Queued — this cache backs `__('storefront.*')` lookups on a LATER
|
||||||
|
* storefront request, never the same admin request that just edited the
|
||||||
|
* translation (Filament redirects to a fresh index read straight from the
|
||||||
|
* DB, not this cache). Safe to let a queue worker pick up.
|
||||||
*/
|
*/
|
||||||
class FlushTranslationCache
|
class FlushTranslationCache implements ShouldQueue
|
||||||
{
|
{
|
||||||
public function handle(TranslationCreated|TranslationUpdated|TranslationDeleted $event): void
|
public function handle(TranslationCreated|TranslationUpdated|TranslationDeleted $event): void
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -2,6 +2,7 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Localization\Listeners;
|
namespace Modules\Core\Localization\Listeners;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Queue\ShouldQueue;
|
||||||
use Illuminate\Support\Arr;
|
use Illuminate\Support\Arr;
|
||||||
use Modules\Core\Localization\Events\TranslationCreated;
|
use Modules\Core\Localization\Events\TranslationCreated;
|
||||||
use Modules\Core\Localization\Events\TranslationDeleted;
|
use Modules\Core\Localization\Events\TranslationDeleted;
|
||||||
@@ -9,7 +10,12 @@ use Modules\Core\Localization\Events\TranslationUpdated;
|
|||||||
use Modules\Core\Logging\ActivityLogService;
|
use Modules\Core\Logging\ActivityLogService;
|
||||||
use Spatie\TranslationLoader\LanguageLine;
|
use Spatie\TranslationLoader\LanguageLine;
|
||||||
|
|
||||||
class LogTranslationActivity
|
/**
|
||||||
|
* Queued — a pure audit-log write with no same-request reader (Filament
|
||||||
|
* redirects to a fresh index page after save, which doesn't read the
|
||||||
|
* activity log at all).
|
||||||
|
*/
|
||||||
|
class LogTranslationActivity implements ShouldQueue
|
||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly ActivityLogService $activityLog,
|
private readonly ActivityLogService $activityLog,
|
||||||
|
|||||||
@@ -2,6 +2,7 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Localization\Listeners;
|
namespace Modules\Core\Localization\Listeners;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Queue\ShouldQueue;
|
||||||
use Illuminate\Support\Facades\Cache;
|
use Illuminate\Support\Facades\Cache;
|
||||||
use Modules\Core\Localization\Events\LanguageUpdated;
|
use Modules\Core\Localization\Events\LanguageUpdated;
|
||||||
use Spatie\TranslationLoader\LanguageLine;
|
use Spatie\TranslationLoader\LanguageLine;
|
||||||
@@ -12,8 +13,15 @@ use Spatie\TranslationLoader\LanguageLine;
|
|||||||
* getTranslationsForGroup($newCode, ...) would silently return nothing for
|
* getTranslationsForGroup($newCode, ...) would silently return nothing for
|
||||||
* that locale even though the translated content still exists. Move the
|
* that locale even though the translated content still exists. Move the
|
||||||
* text.{oldCode} key to text.{newCode} on every affected row instead.
|
* text.{oldCode} key to text.{newCode} on every affected row instead.
|
||||||
|
*
|
||||||
|
* Queued — this walks every LanguageLine row containing the old locale key
|
||||||
|
* with no upper bound, and nothing in the same request needs the migration
|
||||||
|
* to have completed before responding (a rename is a rare admin action;
|
||||||
|
* the affected storefront locale is briefly unavailable until the queue
|
||||||
|
* worker finishes, the same window that already exists before this
|
||||||
|
* listener runs at all).
|
||||||
*/
|
*/
|
||||||
class MigrateTranslationsForRenamedLanguage
|
class MigrateTranslationsForRenamedLanguage implements ShouldQueue
|
||||||
{
|
{
|
||||||
public function handle(LanguageUpdated $event): void
|
public function handle(LanguageUpdated $event): void
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -2,25 +2,31 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Logging;
|
namespace Modules\Core\Logging;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Auth\Authenticatable;
|
||||||
use Illuminate\Database\Eloquent\Model;
|
use Illuminate\Database\Eloquent\Model;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Thin wrapper around Spatie Activity Log that standardises the log channel,
|
* Thin wrapper around Spatie Activity Log that standardises the log channel,
|
||||||
* actor (authenticated staff member), and property shape for all domain events.
|
* actor, and property shape for all domain events.
|
||||||
*
|
*
|
||||||
* All logs are written to the 'lunar' channel. The subject is always an
|
* All logs are written to the 'lunar' channel. The subject is always an
|
||||||
* Eloquent model, and the actor is resolved from the 'staff' guard at call time.
|
* Eloquent model. $causer defaults to the 'staff' guard's current user —
|
||||||
|
* every existing caller of this class is admin-side — but can be passed
|
||||||
|
* explicitly for a non-staff actor (e.g. a customer editing their own
|
||||||
|
* address on the `web` guard — see Modules\Core\Customer\Services\
|
||||||
|
* CustomerAccountService, which passes the acting User rather than
|
||||||
|
* relying on this default resolving to null for a web-guard session).
|
||||||
*/
|
*/
|
||||||
class ActivityLogService
|
class ActivityLogService
|
||||||
{
|
{
|
||||||
/**
|
/**
|
||||||
* Log a creation event. $attributes describes the initial state.
|
* Log a creation event. $attributes describes the initial state.
|
||||||
*/
|
*/
|
||||||
public function created(Model $subject, array $attributes): void
|
public function created(Model $subject, array $attributes, ?Authenticatable $causer = null): void
|
||||||
{
|
{
|
||||||
activity('lunar')
|
activity('lunar')
|
||||||
->performedOn($subject)
|
->performedOn($subject)
|
||||||
->causedBy(auth('staff')->user())
|
->causedBy($causer ?? auth('staff')->user())
|
||||||
->withProperties(['attributes' => $attributes])
|
->withProperties(['attributes' => $attributes])
|
||||||
->log('created');
|
->log('created');
|
||||||
}
|
}
|
||||||
@@ -28,11 +34,11 @@ class ActivityLogService
|
|||||||
/**
|
/**
|
||||||
* Log an update event. $old holds the previous values, $attributes the new ones.
|
* Log an update event. $old holds the previous values, $attributes the new ones.
|
||||||
*/
|
*/
|
||||||
public function updated(Model $subject, array $old, array $attributes): void
|
public function updated(Model $subject, array $old, array $attributes, ?Authenticatable $causer = null): void
|
||||||
{
|
{
|
||||||
activity('lunar')
|
activity('lunar')
|
||||||
->performedOn($subject)
|
->performedOn($subject)
|
||||||
->causedBy(auth('staff')->user())
|
->causedBy($causer ?? auth('staff')->user())
|
||||||
->withProperties(['old' => $old, 'attributes' => $attributes])
|
->withProperties(['old' => $old, 'attributes' => $attributes])
|
||||||
->log('updated');
|
->log('updated');
|
||||||
}
|
}
|
||||||
@@ -40,11 +46,11 @@ class ActivityLogService
|
|||||||
/**
|
/**
|
||||||
* Log a failed operation. $attributes provides context (e.g. error message, service).
|
* Log a failed operation. $attributes provides context (e.g. error message, service).
|
||||||
*/
|
*/
|
||||||
public function failed(Model $subject, array $attributes): void
|
public function failed(Model $subject, array $attributes, ?Authenticatable $causer = null): void
|
||||||
{
|
{
|
||||||
activity('lunar')
|
activity('lunar')
|
||||||
->performedOn($subject)
|
->performedOn($subject)
|
||||||
->causedBy(auth('staff')->user())
|
->causedBy($causer ?? auth('staff')->user())
|
||||||
->withProperties(['attributes' => $attributes])
|
->withProperties(['attributes' => $attributes])
|
||||||
->log('failed');
|
->log('failed');
|
||||||
}
|
}
|
||||||
@@ -52,11 +58,11 @@ class ActivityLogService
|
|||||||
/**
|
/**
|
||||||
* Log a deletion event. $attributes provides context (e.g. reason, name).
|
* Log a deletion event. $attributes provides context (e.g. reason, name).
|
||||||
*/
|
*/
|
||||||
public function deleted(Model $subject, array $attributes): void
|
public function deleted(Model $subject, array $attributes, ?Authenticatable $causer = null): void
|
||||||
{
|
{
|
||||||
activity('lunar')
|
activity('lunar')
|
||||||
->performedOn($subject)
|
->performedOn($subject)
|
||||||
->causedBy(auth('staff')->user())
|
->causedBy($causer ?? auth('staff')->user())
|
||||||
->withProperties(['attributes' => $attributes])
|
->withProperties(['attributes' => $attributes])
|
||||||
->log('deleted');
|
->log('deleted');
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,148 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Logging\Privacy;
|
||||||
|
|
||||||
|
use Lunar\Models\Address;
|
||||||
|
use Lunar\Models\Cart;
|
||||||
|
use Lunar\Models\CartAddress;
|
||||||
|
use Lunar\Models\Customer;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Lunar\Models\OrderAddress;
|
||||||
|
use Lunar\Models\Transaction;
|
||||||
|
use Modules\Core\Privacy\Contracts\PersonalDataProvider;
|
||||||
|
use Modules\Core\Privacy\DTOs\CustomerSubject;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureOutcome;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderErasureResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderExportResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\UserSubject;
|
||||||
|
use Spatie\Activitylog\Models\Activity;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Spatie's own activity_log table (Modules\Core\Logging\ActivityLogService,
|
||||||
|
* plus several Lunar models' native `use LogsActivity` — Customer,
|
||||||
|
* CartAddress, OrderAddress, Transaction) durably retains a full snapshot
|
||||||
|
* of whatever it logged in `properties` (created/updated/deleted
|
||||||
|
* attributes, including a before/after diff on update), completely
|
||||||
|
* independent of the real row it describes. Erasing/pseudonymizing
|
||||||
|
* Customer/Address/CartAddress/OrderAddress/Transaction elsewhere (see
|
||||||
|
* Customer\Privacy\CustomerDataProvider, Customer\Privacy\
|
||||||
|
* AddressDataProvider, Cart\Privacy\CartDataProvider, Order\Privacy\
|
||||||
|
* OrderDataProvider, Payment\Privacy\PaymentDataProvider) does nothing to
|
||||||
|
* this table — a full copy of the old PII survives here regardless.
|
||||||
|
*
|
||||||
|
* Redacts by SUBJECT only, never by `causer_id` — the causer is "who did
|
||||||
|
* this," not PII content, and erasing it would erode the audit trail's own
|
||||||
|
* purpose (see this provider's own eraseForUser(), which is a deliberate
|
||||||
|
* no-op). Genuinely Customer-scope only: every subject type here
|
||||||
|
* (Customer, Address, CartAddress, OrderAddress, Transaction) resolves to
|
||||||
|
* a business account via its own chain (Address/Customer directly;
|
||||||
|
* CartAddress via cart_id -> Cart.customer_id; OrderAddress/Transaction
|
||||||
|
* via order_id -> Order.customer_id) — none of it is a User's own data on
|
||||||
|
* its own.
|
||||||
|
*
|
||||||
|
* MUST run before Customer\Privacy\AddressDataProvider in
|
||||||
|
* config('core.privacy.providers') — that provider hard-deletes Address
|
||||||
|
* rows, and once gone there is no way to re-derive which activity_log
|
||||||
|
* rows (subject_type = Address) belonged to this customer. This provider
|
||||||
|
* resolves that address id list itself, before anything deletes it.
|
||||||
|
*/
|
||||||
|
class ActivityLogDataProvider implements PersonalDataProvider
|
||||||
|
{
|
||||||
|
private const REDACTED = '[redacted]';
|
||||||
|
|
||||||
|
public function name(): string
|
||||||
|
{
|
||||||
|
return 'activity_log';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$activities = Activity::query()
|
||||||
|
->where(fn ($query) => $this->scopeToCustomer($query, $subject->customerId))
|
||||||
|
->get();
|
||||||
|
|
||||||
|
return new ProviderExportResult('activity_log', $activities->map(fn (Activity $activity) => [
|
||||||
|
'id' => $activity->id,
|
||||||
|
'log_name' => $activity->log_name,
|
||||||
|
'description' => $activity->description,
|
||||||
|
'subject_type' => $activity->subject_type,
|
||||||
|
'subject_id' => $activity->subject_id,
|
||||||
|
'event' => $activity->event,
|
||||||
|
'properties' => $activity->properties?->toArray(),
|
||||||
|
'created_at' => $activity->created_at?->toIso8601String(),
|
||||||
|
])->all());
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
return new ProviderExportResult('activity_log', []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
$affected = Activity::query()
|
||||||
|
->where(fn ($query) => $this->scopeToCustomer($query, $subject->customerId))
|
||||||
|
->get();
|
||||||
|
|
||||||
|
if ($affected->isEmpty()) {
|
||||||
|
return new ProviderErasureResult('activity_log', ErasureOutcome::Skipped, 'No activity log entries for this customer.');
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach ($affected as $activity) {
|
||||||
|
$activity->update(['properties' => $this->redact($activity->properties?->toArray() ?? [])]);
|
||||||
|
}
|
||||||
|
|
||||||
|
return new ProviderErasureResult(
|
||||||
|
'activity_log',
|
||||||
|
ErasureOutcome::Pseudonymized,
|
||||||
|
'PII-bearing properties redacted on matching audit log entries; who/what/when metadata (log_name, subject, event, timestamp, causer) retained for audit integrity.'
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
return new ProviderErasureResult(
|
||||||
|
'activity_log',
|
||||||
|
ErasureOutcome::Skipped,
|
||||||
|
'A User only ever appears here as causer_id (who performed an action), not as the PII content of a log entry — redacting that would erode the audit trail\'s own record of who acted.'
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
private function scopeToCustomer($query, int $customerId): void
|
||||||
|
{
|
||||||
|
$customerMorph = (new Customer)->getMorphClass();
|
||||||
|
$addressMorph = (new Address)->getMorphClass();
|
||||||
|
$cartAddressMorph = (new CartAddress)->getMorphClass();
|
||||||
|
$orderAddressMorph = (new OrderAddress)->getMorphClass();
|
||||||
|
$transactionMorph = (new Transaction)->getMorphClass();
|
||||||
|
|
||||||
|
$addressIds = Address::where('customer_id', $customerId)->pluck('id');
|
||||||
|
$cartIds = Cart::where('customer_id', $customerId)->pluck('id');
|
||||||
|
$cartAddressIds = CartAddress::whereIn('cart_id', $cartIds)->pluck('id');
|
||||||
|
$orderIds = Order::where('customer_id', $customerId)->pluck('id');
|
||||||
|
$orderAddressIds = OrderAddress::whereIn('order_id', $orderIds)->pluck('id');
|
||||||
|
$transactionIds = Transaction::whereIn('order_id', $orderIds)->pluck('id');
|
||||||
|
|
||||||
|
$query
|
||||||
|
->where(fn ($q) => $q->where('subject_type', $customerMorph)->where('subject_id', $customerId))
|
||||||
|
->orWhere(fn ($q) => $q->where('subject_type', $addressMorph)->whereIn('subject_id', $addressIds))
|
||||||
|
->orWhere(fn ($q) => $q->where('subject_type', $cartAddressMorph)->whereIn('subject_id', $cartAddressIds))
|
||||||
|
->orWhere(fn ($q) => $q->where('subject_type', $orderAddressMorph)->whereIn('subject_id', $orderAddressIds))
|
||||||
|
->orWhere(fn ($q) => $q->where('subject_type', $transactionMorph)->whereIn('subject_id', $transactionIds));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $properties
|
||||||
|
* @return array<string, mixed>
|
||||||
|
*/
|
||||||
|
private function redact(array $properties): array
|
||||||
|
{
|
||||||
|
return array_map(function ($value) {
|
||||||
|
if (is_array($value)) {
|
||||||
|
return array_map(fn () => self::REDACTED, $value);
|
||||||
|
}
|
||||||
|
|
||||||
|
return self::REDACTED;
|
||||||
|
}, $properties);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -7,6 +7,7 @@ use Illuminate\Contracts\Queue\ShouldQueue;
|
|||||||
use Illuminate\Foundation\Bus\Dispatchable;
|
use Illuminate\Foundation\Bus\Dispatchable;
|
||||||
use Illuminate\Queue\InteractsWithQueue;
|
use Illuminate\Queue\InteractsWithQueue;
|
||||||
use Illuminate\Queue\SerializesModels;
|
use Illuminate\Queue\SerializesModels;
|
||||||
|
use Modules\Core\Catalog\Services\SkuBackfillService;
|
||||||
|
|
||||||
class RunMigrateImportJob implements ShouldQueue
|
class RunMigrateImportJob implements ShouldQueue
|
||||||
{
|
{
|
||||||
@@ -20,9 +21,19 @@ class RunMigrateImportJob implements ShouldQueue
|
|||||||
) {
|
) {
|
||||||
}
|
}
|
||||||
|
|
||||||
public function handle(): void
|
public function handle(SkuBackfillService $skuBackfill): void
|
||||||
{
|
{
|
||||||
$importer = ImporterFactory::make($this->spec);
|
$importer = ImporterFactory::make($this->spec);
|
||||||
$importer->import($this->spec);
|
$importer->import($this->spec);
|
||||||
|
|
||||||
|
// Only Shopify's importer creates ProductVariant rows at all (see
|
||||||
|
// Shopify\ShopifyExportImporter) — JudgeMe never touches products,
|
||||||
|
// so running this for that source would just be a guaranteed
|
||||||
|
// no-op query every time. Source CSV rows genuinely can have no
|
||||||
|
// `Variant SKU` value; see SkuBackfillService's own docblock for
|
||||||
|
// why that's synthesized rather than treated as an importer bug.
|
||||||
|
if ($this->spec->source === 'shopify') {
|
||||||
|
$skuBackfill->backfill();
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -163,6 +163,12 @@ class ShopifyExportImporter implements Importer
|
|||||||
$variant->sku = trim((string) ($row['Variant SKU'] ?? '')) ?: null;
|
$variant->sku = trim((string) ($row['Variant SKU'] ?? '')) ?: null;
|
||||||
$variant->stock = (int) ($row['Variant Inventory Qty'] ?? 0);
|
$variant->stock = (int) ($row['Variant Inventory Qty'] ?? 0);
|
||||||
$variant->shippable = filter_var($row['Variant Requires Shipping'] ?? 'true', FILTER_VALIDATE_BOOLEAN);
|
$variant->shippable = filter_var($row['Variant Requires Shipping'] ?? 'true', FILTER_VALIDATE_BOOLEAN);
|
||||||
|
// Lunar's own column default is 'always' (purchasable regardless of
|
||||||
|
// stock) — wrong for an imported catalogue, whose Variant Inventory
|
||||||
|
// Qty is real, meaningful stock data. 'in_stock' makes purchasability
|
||||||
|
// actually respect it (see Modules\Core\Catalog\Services\
|
||||||
|
// StockService's own docblock on the three purchasable values).
|
||||||
|
$variant->purchasable = 'in_stock';
|
||||||
$variant->save();
|
$variant->save();
|
||||||
|
|
||||||
ImportMapping::record(self::SOURCE, 'variant', $externalId, $variant);
|
ImportMapping::record(self::SOURCE, 'variant', $externalId, $variant);
|
||||||
@@ -239,7 +245,23 @@ class ShopifyExportImporter implements Importer
|
|||||||
|
|
||||||
$existing = ImportMapping::resolve(self::SOURCE, 'image', $externalId);
|
$existing = ImportMapping::resolve(self::SOURCE, 'image', $externalId);
|
||||||
|
|
||||||
if ($existing instanceof Media) {
|
// ImportMapping is a durable record of "we already imported this,"
|
||||||
|
// but the Media row it points at can go stale — e.g. Command\
|
||||||
|
// WipeCatalogCommand deletes every Product (media included, via
|
||||||
|
// Spatie's own model-delete cleanup) without knowing this mapping
|
||||||
|
// exists, since the mapping ISN'T scoped to a single Product to
|
||||||
|
// clean up alongside it. Re-running an import afterward used to
|
||||||
|
// trust the cached Media object unconditionally — it still existed
|
||||||
|
// as a PHP object even though its underlying row (and file) were
|
||||||
|
// long gone, so every re-imported product silently got zero
|
||||||
|
// media, no error, no warning. Falls through to a fresh import
|
||||||
|
// whenever the mapping doesn't resolve to a real, still-attached
|
||||||
|
// Media row.
|
||||||
|
if ($existing instanceof Media
|
||||||
|
&& Media::whereKey($existing->getKey())->exists()
|
||||||
|
&& $existing->model_type === $product->getMorphClass()
|
||||||
|
&& (int) $existing->model_id === $product->id
|
||||||
|
) {
|
||||||
return $existing;
|
return $existing;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+50
-39
@@ -32,10 +32,6 @@ use ReflectionProperty;
|
|||||||
* could return a real, honest failure — see Payment\Support\
|
* could return a real, honest failure — see Payment\Support\
|
||||||
* TransactionDriverAdapter's own docblock for that history.
|
* TransactionDriverAdapter's own docblock for that history.
|
||||||
*
|
*
|
||||||
* Fix, for capture: wrap the action's own action() closure so that, on
|
|
||||||
* Halt, we call $action->sendFailureNotification() ourselves before letting
|
|
||||||
* the Halt continue propagating — everything else is untouched.
|
|
||||||
*
|
|
||||||
* Fix, for refund: same notification fix, but the action() closure is
|
* Fix, for refund: same notification fix, but the action() closure is
|
||||||
* replaced outright (not wrapped) rather than reused, because refund also
|
* replaced outright (not wrapped) rather than reused, because refund also
|
||||||
* needs a "Refund via" driver Select added to the modal (see
|
* needs a "Refund via" driver Select added to the modal (see
|
||||||
@@ -43,15 +39,28 @@ use ReflectionProperty;
|
|||||||
* Payment\Support\TransactionDriverAdapter::refundVia() instead of
|
* Payment\Support\TransactionDriverAdapter::refundVia() instead of
|
||||||
* Lunar\Models\Transaction::refund() — see fixRefundAction()'s own
|
* Lunar\Models\Transaction::refund() — see fixRefundAction()'s own
|
||||||
* docblock.
|
* docblock.
|
||||||
|
*
|
||||||
|
* Fix, for capture: same notification fix, but the action() closure is
|
||||||
|
* also replaced outright — the actual call is routed through
|
||||||
|
* Payment\Support\TransactionDriverAdapter::capture() instead of
|
||||||
|
* Lunar\Models\Transaction::capture() (see fixCaptureAction()), so a
|
||||||
|
* manual backoffice capture goes through the app's own payment driver
|
||||||
|
* registry and dispatches Payment\Events\PaymentCaptured exactly like a
|
||||||
|
* checkout-time capture does — the vendor path resolved
|
||||||
|
* Lunar\Facades\Payments (an entirely separate, unused driver registry)
|
||||||
|
* and never dispatched that event, which is why Order::status used to
|
||||||
|
* stay stuck on 'awaiting_payment' after a manual capture even though
|
||||||
|
* Modules\Core\Order\Listeners\ApplyResolvedPaymentStatus now advances it
|
||||||
|
* on PaymentCaptured.
|
||||||
*/
|
*/
|
||||||
class OrderRefundActionsExtension extends ViewPageExtension
|
class OrderActionsExtension extends ViewPageExtension
|
||||||
{
|
{
|
||||||
public function headerActions(array $actions): array
|
public function headerActions(array $actions): array
|
||||||
{
|
{
|
||||||
return array_map(
|
return array_map(
|
||||||
fn (Action $action) => match ($action->getName()) {
|
fn (Action $action) => match ($action->getName()) {
|
||||||
'refund' => $this->fixRefundAction($action),
|
'refund' => $this->fixRefundAction($action),
|
||||||
'capture' => $this->fixFailureNotification($action),
|
'capture' => $this->fixCaptureAction($action),
|
||||||
default => $action,
|
default => $action,
|
||||||
},
|
},
|
||||||
$actions,
|
$actions,
|
||||||
@@ -123,6 +132,41 @@ class OrderRefundActionsExtension extends ViewPageExtension
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Mirrors fixRefundAction()'s notification fix, but for the "amount"
|
||||||
|
* field already on the vendor schema — no extra field needed, since
|
||||||
|
* capture always goes back through the transaction's own original
|
||||||
|
* driver (there's no equivalent to refunding via a different driver).
|
||||||
|
*/
|
||||||
|
private function fixCaptureAction(Action $action): Action
|
||||||
|
{
|
||||||
|
return $action->action(function (array $data, Action $action) {
|
||||||
|
$transaction = Transaction::find($data['transaction']);
|
||||||
|
|
||||||
|
if (! $transaction instanceof CoreTransaction) {
|
||||||
|
$action->failureNotification(fn () => Notification::make('capture_failure')->danger()->title('Transaction not found.'))
|
||||||
|
->sendFailureNotification();
|
||||||
|
|
||||||
|
throw new Halt;
|
||||||
|
}
|
||||||
|
|
||||||
|
$response = app(TransactionDriverAdapter::class)->capture(
|
||||||
|
$transaction,
|
||||||
|
(int) bcmul((string) $data['amount'], (string) $transaction->order->currency->factor),
|
||||||
|
);
|
||||||
|
|
||||||
|
if (! $response->success) {
|
||||||
|
$action->failureNotification(
|
||||||
|
fn () => Notification::make('capture_failure')->color('danger')->title($response->message)
|
||||||
|
)->sendFailureNotification();
|
||||||
|
|
||||||
|
throw new Halt;
|
||||||
|
}
|
||||||
|
|
||||||
|
$action->success();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @return array<string, string>
|
* @return array<string, string>
|
||||||
*/
|
*/
|
||||||
@@ -163,37 +207,4 @@ class OrderRefundActionsExtension extends ViewPageExtension
|
|||||||
|
|
||||||
return $reflected->getValue($object);
|
return $reflected->getValue($object);
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* Wraps the action's own configured action() closure so that, if it
|
|
||||||
* halts (Lunar's closures throw via $action->halt() to signal failure —
|
|
||||||
* see this class's own docblock for why that alone never sends the
|
|
||||||
* notification queued via failureNotification()), we send that
|
|
||||||
* notification ourselves before letting the Halt continue propagating
|
|
||||||
* (still needed — it's what stops callMountedAction() from treating
|
|
||||||
* this as a success and closing the modal/committing the DB transaction).
|
|
||||||
*
|
|
||||||
* $this->evaluate() (not a plain call) matches exactly how Action::call()
|
|
||||||
* itself invokes the closure — Lunar's closures type-hint $data/$record/
|
|
||||||
* $action and rely on Filament's own container-style parameter
|
|
||||||
* resolution, not positional arguments.
|
|
||||||
*/
|
|
||||||
private function fixFailureNotification(Action $action): Action
|
|
||||||
{
|
|
||||||
$originalAction = $action->getActionFunction();
|
|
||||||
|
|
||||||
if ($originalAction === null) {
|
|
||||||
return $action;
|
|
||||||
}
|
|
||||||
|
|
||||||
return $action->action(function (array $arguments) use ($action, $originalAction) {
|
|
||||||
try {
|
|
||||||
return $action->evaluate($originalAction, $arguments);
|
|
||||||
} catch (Halt $exception) {
|
|
||||||
$action->sendFailureNotification();
|
|
||||||
|
|
||||||
throw $exception;
|
|
||||||
}
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
@@ -8,7 +8,7 @@ use Filament\Tables\Table;
|
|||||||
use Lunar\Admin\Support\Extending\BaseExtension;
|
use Lunar\Admin\Support\Extending\BaseExtension;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Same fix as OrderRefundActionsExtension, applied to the order lines
|
* Same fix as OrderActionsExtension, applied to the order lines
|
||||||
* table's "bulk_refund" toolbar action (Lunar\Admin\...\OrderItemsTable::
|
* table's "bulk_refund" toolbar action (Lunar\Admin\...\OrderItemsTable::
|
||||||
* getBulkRefundAction()) — see that class's docblock for the underlying
|
* getBulkRefundAction()) — see that class's docblock for the underlying
|
||||||
* Filament bug (failureNotification()+failure()+halt() never actually
|
* Filament bug (failureNotification()+failure()+halt() never actually
|
||||||
|
|||||||
@@ -42,6 +42,8 @@ class OrderPaymentMethodSummaryExtension extends ViewPageExtension
|
|||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
return PaymentMethod::where('type', $type)->value('name') ?? $type;
|
$method = PaymentMethod::where('type', $type)->first();
|
||||||
|
|
||||||
|
return $method?->translate('name') ?? $type;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,12 +2,19 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Order\Listeners;
|
namespace Modules\Core\Order\Listeners;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Queue\ShouldQueue;
|
||||||
use Modules\Core\Order\Events\OrderDispatched;
|
use Modules\Core\Order\Events\OrderDispatched;
|
||||||
|
use Modules\Core\Order\Services\OrderStatusFlow;
|
||||||
use Modules\Core\Order\Services\OrderStatusWriter;
|
use Modules\Core\Order\Services\OrderStatusWriter;
|
||||||
use Modules\Core\Shipping\Enums\TrackingStatus;
|
use Modules\Core\Shipping\Enums\TrackingStatus;
|
||||||
use Modules\Core\Shipping\Events\ShipmentStatusUpdatedByCarrier;
|
use Modules\Core\Shipping\Events\ShipmentStatusUpdatedByCarrier;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
* Queued — see Modules\Core\Order\Listeners\DeriveOrderDeliveredFromShipment's
|
||||||
|
* own docblock: ShipmentStatusUpdatedByCarrier comes from a scheduled
|
||||||
|
* polling job, not a webhook, so nothing needs this to complete before a
|
||||||
|
* request returns.
|
||||||
|
*
|
||||||
* The automatic half of "Dispatched" — the manual fallback is the staff
|
* The automatic half of "Dispatched" — the manual fallback is the staff
|
||||||
* "Update Status" action (Modules\Core\Shipping\Extensions\
|
* "Update Status" action (Modules\Core\Shipping\Extensions\
|
||||||
* OrderViewExtension). Listens to ShipmentStatusUpdatedByCarrier directly,
|
* OrderViewExtension). Listens to ShipmentStatusUpdatedByCarrier directly,
|
||||||
@@ -19,14 +26,17 @@ use Modules\Core\Shipping\Events\ShipmentStatusUpdatedByCarrier;
|
|||||||
* carrier that skips straight there without a distinct collection
|
* carrier that skips straight there without a distinct collection
|
||||||
* checkpoint.
|
* checkpoint.
|
||||||
*
|
*
|
||||||
* Guarded to only fire from 'ready_for_dispatch' — a late/duplicate
|
* Guarded by OrderStatusFlow::isValidTransition() rather than a hardcoded
|
||||||
* checkpoint, or an order the manual action already advanced, is a
|
* "only fire from 'ready_for_dispatch'" comparison — the single source of
|
||||||
* silent no-op.
|
* truth for the status graph lives there, not duplicated here. A
|
||||||
|
* late/duplicate checkpoint, or an order the manual action already
|
||||||
|
* advanced, is a silent no-op either way.
|
||||||
*/
|
*/
|
||||||
class AdvanceFulfillmentOnCarrierCheckpoint
|
class AdvanceFulfillmentOnCarrierCheckpoint implements ShouldQueue
|
||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly OrderStatusWriter $writer,
|
private readonly OrderStatusWriter $writer,
|
||||||
|
private readonly OrderStatusFlow $flow,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
public function handle(ShipmentStatusUpdatedByCarrier $event): void
|
public function handle(ShipmentStatusUpdatedByCarrier $event): void
|
||||||
@@ -38,7 +48,7 @@ class AdvanceFulfillmentOnCarrierCheckpoint
|
|||||||
|
|
||||||
$order = $event->shipmentInfo->shipment->order;
|
$order = $event->shipmentInfo->shipment->order;
|
||||||
|
|
||||||
if (! $order || $order->status !== 'ready_for_dispatch') {
|
if (! $order || ! $this->flow->isValidTransition($order, 'dispatched')) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -2,10 +2,18 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Order\Listeners;
|
namespace Modules\Core\Order\Listeners;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Queue\ShouldQueue;
|
||||||
use Modules\Core\Order\Events\OrderDelivered;
|
use Modules\Core\Order\Events\OrderDelivered;
|
||||||
|
use Modules\Core\Order\Services\OrderStatusFlow;
|
||||||
use Modules\Core\Order\Services\OrderStatusWriter;
|
use Modules\Core\Order\Services\OrderStatusWriter;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
* Queued — OrderDelivered is only ever dispatched from Modules\Core\Order\
|
||||||
|
* Listeners\DeriveOrderDeliveredFromShipment, itself queued (see that
|
||||||
|
* class's own docblock: the triggering ShipmentStatusUpdatedByCarrier
|
||||||
|
* comes from a scheduled polling job, not a request with a page waiting
|
||||||
|
* on the result).
|
||||||
|
*
|
||||||
* Writes `status` to 'delivered' once a carrier confirms delivery, rather
|
* Writes `status` to 'delivered' once a carrier confirms delivery, rather
|
||||||
* than jumping straight to 'completed'. Carrier orders get a return
|
* than jumping straight to 'completed'. Carrier orders get a return
|
||||||
* window between delivery and completion (see Modules\Core\Order\
|
* window between delivery and completion (see Modules\Core\Order\
|
||||||
@@ -20,21 +28,23 @@ use Modules\Core\Order\Services\OrderStatusWriter;
|
|||||||
* OrderDelivered — deriving "was this delivered" and acting on it by
|
* OrderDelivered — deriving "was this delivered" and acting on it by
|
||||||
* writing `status` are deliberately two different listeners.
|
* writing `status` are deliberately two different listeners.
|
||||||
*
|
*
|
||||||
* Guarded to only fire from 'dispatched' — a duplicate/late Delivered
|
* Guarded by OrderStatusFlow::isValidTransition() rather than a hardcoded
|
||||||
|
* "only fire from 'dispatched'" comparison. A duplicate/late Delivered
|
||||||
* checkpoint, or an order a manual action already moved past, is a
|
* checkpoint, or an order a manual action already moved past, is a
|
||||||
* silent no-op.
|
* silent no-op either way.
|
||||||
*/
|
*/
|
||||||
class AdvanceFulfillmentOnDelivered
|
class AdvanceFulfillmentOnDelivered implements ShouldQueue
|
||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly OrderStatusWriter $writer,
|
private readonly OrderStatusWriter $writer,
|
||||||
|
private readonly OrderStatusFlow $flow,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
public function handle(OrderDelivered $event): void
|
public function handle(OrderDelivered $event): void
|
||||||
{
|
{
|
||||||
$order = $event->order;
|
$order = $event->order;
|
||||||
|
|
||||||
if ($order->status !== 'dispatched') {
|
if (! $this->flow->isValidTransition($order, 'delivered')) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -2,12 +2,8 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Order\Listeners;
|
namespace Modules\Core\Order\Listeners;
|
||||||
|
|
||||||
use Illuminate\Support\Facades\Event;
|
|
||||||
use Lunar\Models\Order;
|
use Lunar\Models\Order;
|
||||||
use Modules\Core\Checkout\Events\OrderPlaced;
|
use Modules\Core\Order\Services\OrderPaymentResolutionService;
|
||||||
use Modules\Core\Order\Enums\PaymentStatus;
|
|
||||||
use Modules\Core\Order\Services\OrderStatusWriter;
|
|
||||||
use Modules\Core\Order\Support\OrderStatus;
|
|
||||||
use Modules\Core\Payment\Events\PaymentAuthorized;
|
use Modules\Core\Payment\Events\PaymentAuthorized;
|
||||||
use Modules\Core\Payment\Events\PaymentCaptured;
|
use Modules\Core\Payment\Events\PaymentCaptured;
|
||||||
use Modules\Core\Payment\Events\PaymentRefunded;
|
use Modules\Core\Payment\Events\PaymentRefunded;
|
||||||
@@ -16,34 +12,24 @@ use Modules\Core\Payment\Events\PaymentRefunded;
|
|||||||
* Registered against PaymentCaptured, PaymentAuthorized, AND
|
* Registered against PaymentCaptured, PaymentAuthorized, AND
|
||||||
* PaymentRefunded (see OrderServiceProvider).
|
* PaymentRefunded (see OrderServiceProvider).
|
||||||
*
|
*
|
||||||
* A capture/authorization only ever writes Order::paid/paid_at (via
|
* A thin reactor — resolves which Order this outcome belongs to (Payment
|
||||||
* OrderStatusWriter::markPaid()) — never `status`. Confirmed with the
|
* has no concept of an Order, so this reads $event->context['order_id'])
|
||||||
* user: status leaving 'awaiting_payment' is always a staff-driven
|
* and hands off to Modules\Core\Order\Services\
|
||||||
* "Update Status" click, regardless of payment method — no special-casing
|
* OrderPaymentResolutionService for the actual decisions: whether to mark
|
||||||
* prepaid vs. cash-on-delivery. A prepaid order briefly sitting at
|
* the order paid, whether/how far to advance `status`, and what a refund
|
||||||
* 'awaiting_payment' with paid = true (until staff notice and advance it)
|
* does to it. See that service's own docblock, and its methods' own
|
||||||
* is expected, not a bug.
|
* docblocks, for the full business reasoning (re-confirmed with the
|
||||||
*
|
* user): a captured payment, manual or via Stripe's webhook, should
|
||||||
* A refund still moves `status` (returned -> refunded/partially_refunded)
|
* never leave an order sitting at 'awaiting_payment'; an authorization
|
||||||
* — refunds are a normal step in Modules\Core\Order\Services\
|
* only marks paid, since it isn't yet captured funds; a refund is a
|
||||||
* OrderStatusFlow's own sequence, unlike captures. Derives
|
* normal step in the order's own status sequence, unlike a capture.
|
||||||
* Refunded/PartialRefund from Modules\Core\Order\Support\OrderStatus::
|
|
||||||
* payment() — the existing, unchanged derived-enum logic, reused rather
|
|
||||||
* than reimplemented.
|
|
||||||
*
|
|
||||||
* Reads $event->context['order_id'] to find which Order this outcome
|
|
||||||
* belongs to — Payment has no concept of an Order.
|
|
||||||
*
|
|
||||||
* Dispatches Checkout\Events\OrderPlaced itself, once placed_at is set.
|
|
||||||
* Never fires from the PaymentRefunded path — a refund can only ever
|
|
||||||
* happen after an order was already placed.
|
|
||||||
*
|
*
|
||||||
* Deliberately does NOT react to PaymentVoided.
|
* Deliberately does NOT react to PaymentVoided.
|
||||||
*/
|
*/
|
||||||
class ApplyResolvedPaymentStatus
|
class ApplyResolvedPaymentStatus
|
||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly OrderStatusWriter $writer,
|
private readonly OrderPaymentResolutionService $resolution,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
public function handle(PaymentCaptured|PaymentAuthorized|PaymentRefunded $event): void
|
public function handle(PaymentCaptured|PaymentAuthorized|PaymentRefunded $event): void
|
||||||
@@ -57,40 +43,11 @@ class ApplyResolvedPaymentStatus
|
|||||||
$order = Order::findOrFail($orderId);
|
$order = Order::findOrFail($orderId);
|
||||||
|
|
||||||
if ($event instanceof PaymentRefunded) {
|
if ($event instanceof PaymentRefunded) {
|
||||||
$this->applyRefund($order, $event);
|
$this->resolution->resolveRefund($order, $event::class);
|
||||||
|
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
$wasPlaced = ! blank($order->placed_at);
|
$this->resolution->resolveCaptureOrAuthorization($order, $event::class, isCapture: $event instanceof PaymentCaptured);
|
||||||
|
|
||||||
$this->writer->markPaid($order, $event::class);
|
|
||||||
|
|
||||||
if (! $wasPlaced) {
|
|
||||||
$order->update(['placed_at' => $order->placed_at ?? now()]);
|
|
||||||
Event::dispatch(new OrderPlaced($order));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Requires the refund Transaction row to already exist (Modules\Core\
|
|
||||||
* Order\Listeners\RecordPaymentTransaction must run first — see
|
|
||||||
* OrderServiceProvider's listener registration order for
|
|
||||||
* PaymentRefunded), so the relation is refreshed here rather than
|
|
||||||
* trusted from a possibly-stale $order instance.
|
|
||||||
*/
|
|
||||||
private function applyRefund(Order $order, PaymentRefunded $event): void
|
|
||||||
{
|
|
||||||
$order->load('transactions');
|
|
||||||
|
|
||||||
$target = match (OrderStatus::payment($order)) {
|
|
||||||
PaymentStatus::Refunded => 'refunded',
|
|
||||||
PaymentStatus::PartialRefund => 'partially_refunded',
|
|
||||||
default => null,
|
|
||||||
};
|
|
||||||
|
|
||||||
if ($target !== null && $order->status !== $target) {
|
|
||||||
$this->writer->write($order, $target, $event::class);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -4,9 +4,19 @@ namespace Modules\Core\Order\Listeners;
|
|||||||
|
|
||||||
use Modules\Core\Order\Events\OrderCompleted;
|
use Modules\Core\Order\Events\OrderCompleted;
|
||||||
use Modules\Core\Order\Events\OrderPickedUp;
|
use Modules\Core\Order\Events\OrderPickedUp;
|
||||||
|
use Modules\Core\Order\Services\OrderStatusFlow;
|
||||||
use Modules\Core\Order\Services\OrderStatusWriter;
|
use Modules\Core\Order\Services\OrderStatusWriter;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
* Deliberately NOT queued — OrderPickedUp is dispatched from a staff
|
||||||
|
* Filament action (see OrderFulfillmentService::markPickedUp()), and the
|
||||||
|
* page staff are looking at needs to show `status` as 'completed'
|
||||||
|
* immediately after they click, not still 'picked_up' until a queue
|
||||||
|
* worker catches up. Unlike ShipmentStatusUpdatedByCarrier's listeners
|
||||||
|
* (queued — dispatched from a scheduled polling job with no page waiting
|
||||||
|
* on the result), this one has a real same-request/same-page-load
|
||||||
|
* dependency.
|
||||||
|
*
|
||||||
* The store-pickup mirror of AdvanceFulfillmentOnDelivered — reacts to
|
* The store-pickup mirror of AdvanceFulfillmentOnDelivered — reacts to
|
||||||
* OrderPickedUp (dispatched by Modules\Core\Order\Services\
|
* OrderPickedUp (dispatched by Modules\Core\Order\Services\
|
||||||
* OrderFulfillmentService::markPickedUp() the moment staff confirm the
|
* OrderFulfillmentService::markPickedUp() the moment staff confirm the
|
||||||
@@ -15,20 +25,22 @@ use Modules\Core\Order\Services\OrderStatusWriter;
|
|||||||
* business design — unlike the carrier branch, there is no 'delivered'
|
* business design — unlike the carrier branch, there is no 'delivered'
|
||||||
* intermediate value on this path.
|
* intermediate value on this path.
|
||||||
*
|
*
|
||||||
* Guarded to only fire from 'picked_up' — a duplicate dispatch (e.g. a
|
* Guarded by OrderStatusFlow::isValidTransition() rather than a hardcoded
|
||||||
* stale page re-submitting the action) is a silent no-op.
|
* "only fire from 'picked_up'" comparison. A duplicate dispatch (e.g. a
|
||||||
|
* stale page re-submitting the action) is a silent no-op either way.
|
||||||
*/
|
*/
|
||||||
class CompleteOrderOnPickedUp
|
class CompleteOrderOnPickedUp
|
||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly OrderStatusWriter $writer,
|
private readonly OrderStatusWriter $writer,
|
||||||
|
private readonly OrderStatusFlow $flow,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
public function handle(OrderPickedUp $event): void
|
public function handle(OrderPickedUp $event): void
|
||||||
{
|
{
|
||||||
$order = $event->order;
|
$order = $event->order;
|
||||||
|
|
||||||
if ($order->status !== 'picked_up') {
|
if (! $this->flow->isValidTransition($order, 'completed')) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -2,63 +2,38 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Order\Listeners;
|
namespace Modules\Core\Order\Listeners;
|
||||||
|
|
||||||
use Illuminate\Support\Facades\DB;
|
use Modules\Core\Catalog\Services\StockService;
|
||||||
use Lunar\Models\Product;
|
|
||||||
use Lunar\Models\ProductVariant;
|
|
||||||
use Modules\Core\Checkout\Events\OrderPlaced;
|
use Modules\Core\Checkout\Events\OrderPlaced;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* The only place ProductVariant::stock is written as a result of an order —
|
* Deliberately NOT queued — unlike this codebase's other queued side
|
||||||
* fires once per order regardless of capture_mode/driver, same reasoning as
|
* effects (cache flushes, audit logs, search reindexes), a stalled queue
|
||||||
* Modules\Core\Order\Notifications\OrderPlacedNotification: OrderPlaced is
|
* here isn't just cosmetic staleness: it widens the window in which
|
||||||
* dispatched exactly once, from the one place an order's placed_at
|
* another order can be accepted against stock this order already
|
||||||
* actually gets set (Modules\Core\Order\Listeners\ApplyResolvedPaymentStatus),
|
* committed (Lunar has no stock-reservation step at checkout time to
|
||||||
* so this can't double-decrement across a capture/authorize/refund sequence
|
* begin with — see StockService's own "Never lets stock go negative"
|
||||||
* the way listening to PaymentCaptured directly could.
|
* note — so some oversell race already exists, but a queue stall of
|
||||||
|
* minutes/hours extends that window far past the sub-millisecond one a
|
||||||
|
* synchronous write leaves open). StockService's atomic `GREATEST(stock -
|
||||||
|
* qty, 0)` SQL still protects against a LOST update between two orders
|
||||||
|
* decrementing the same variant concurrently; running it synchronously
|
||||||
|
* keeps the exposure window as small as possible on top of that.
|
||||||
*
|
*
|
||||||
* Only decrements for `purchasable === 'in_stock'` variants — 'always' and
|
* The actual decrement logic lives in Modules\Core\Catalog\Services\
|
||||||
* 'backorder' variants are deliberately allowed to sell past (or without
|
* StockService — stock (the column, its invariants) is a Catalog concern,
|
||||||
* regard to) their stock count already (see ProductVariant::
|
* not an Order one; this listener is just the "an order was placed"
|
||||||
* canBeFulfilledAtQuantity()), so decrementing their stock would just make
|
* trigger. Fires once per order regardless of capture_mode/driver, same
|
||||||
* that column an inaccurate, decreasingly-negative number with no purchasing
|
* reasoning as Modules\Core\Order\Notifications\OrderPlacedNotification:
|
||||||
* consequence. Only `OrderLine::type === 'physical'` lines are considered —
|
* OrderPlaced is dispatched exactly once, from the one place an order's
|
||||||
* a digital line has no stock to decrement (ProductVariant::getType()).
|
* placed_at actually gets set (Modules\Core\Order\Listeners\
|
||||||
*
|
* ApplyResolvedPaymentStatus), so this can't double-decrement across a
|
||||||
* A single UPDATE per variant (`DB::table(...)->decrement()`), not a
|
* capture/authorize/refund sequence the way listening to PaymentCaptured
|
||||||
* read-then-write on the Eloquent model — avoids a lost-update race between
|
* directly could.
|
||||||
* two orders decrementing the same variant concurrently, and skips
|
|
||||||
* Modules\Core\Catalog\Services\ProductIndexer::stock's staleness gap for
|
|
||||||
* the DB value itself even though the search index still only refreshes on
|
|
||||||
* the next reindex event/nightly job (see that class's own docblock).
|
|
||||||
*
|
|
||||||
* Never lets stock go negative (`GREATEST(stock - qty, 0)` via a raw
|
|
||||||
* expression) — an order can still be placed against a variant whose stock
|
|
||||||
* was already fully consumed by another concurrent order (Lunar has no
|
|
||||||
* stock-reservation step at cart/checkout time), so this is a best-effort
|
|
||||||
* count, not a hard inventory guarantee.
|
|
||||||
*/
|
*/
|
||||||
class DecrementStockOnOrderPlaced
|
class DecrementStockOnOrderPlaced
|
||||||
{
|
{
|
||||||
public function handle(OrderPlaced $event): void
|
public function handle(OrderPlaced $event): void
|
||||||
{
|
{
|
||||||
$lines = $event->order->lines()
|
app(StockService::class)->decrementForOrder($event->order);
|
||||||
->where('type', 'physical')
|
|
||||||
->where('purchasable_type', ProductVariant::morphName())
|
|
||||||
->get(['purchasable_id', 'quantity']);
|
|
||||||
|
|
||||||
foreach ($lines as $line) {
|
|
||||||
DB::table((new ProductVariant())->getTable())
|
|
||||||
->where('id', $line->purchasable_id)
|
|
||||||
->where('purchasable', 'in_stock')
|
|
||||||
->update([
|
|
||||||
'stock' => DB::raw('GREATEST(stock - '.(int) $line->quantity.', 0)'),
|
|
||||||
]);
|
|
||||||
}
|
|
||||||
|
|
||||||
$productIds = ProductVariant::whereIn('id', $lines->pluck('purchasable_id'))
|
|
||||||
->pluck('product_id')
|
|
||||||
->unique();
|
|
||||||
|
|
||||||
Product::whereIn('id', $productIds)->get()->each->searchable();
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,17 +2,23 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Order\Listeners;
|
namespace Modules\Core\Order\Listeners;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Queue\ShouldQueue;
|
||||||
use Modules\Core\Order\Events\OrderDelivered;
|
use Modules\Core\Order\Events\OrderDelivered;
|
||||||
use Modules\Core\Shipping\Enums\TrackingStatus;
|
use Modules\Core\Shipping\Enums\TrackingStatus;
|
||||||
use Modules\Core\Shipping\Events\ShipmentStatusUpdatedByCarrier;
|
use Modules\Core\Shipping\Events\ShipmentStatusUpdatedByCarrier;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
* Queued — ShipmentStatusUpdatedByCarrier is dispatched from
|
||||||
|
* Modules\Core\Shipping\Jobs\PollShipmentTrackingJob, a scheduled job with
|
||||||
|
* no HTTP request waiting on a response, so there is no same-request
|
||||||
|
* timing pressure for any of this event's listeners (unlike a webhook).
|
||||||
|
*
|
||||||
* Translates a carrier tracking checkpoint into OrderDelivered — the event
|
* Translates a carrier tracking checkpoint into OrderDelivered — the event
|
||||||
* OrderDeliveredNotification (via NotificationRegistry) actually listens
|
* OrderDeliveredNotification (via NotificationRegistry) actually listens
|
||||||
* to. Kept separate from the notification itself so the "is this checkpoint
|
* to. Kept separate from the notification itself so the "is this checkpoint
|
||||||
* a delivery" filtering doesn't leak into notification code.
|
* a delivery" filtering doesn't leak into notification code.
|
||||||
*/
|
*/
|
||||||
class DeriveOrderDeliveredFromShipment
|
class DeriveOrderDeliveredFromShipment implements ShouldQueue
|
||||||
{
|
{
|
||||||
public function handle(ShipmentStatusUpdatedByCarrier $event): void
|
public function handle(ShipmentStatusUpdatedByCarrier $event): void
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -2,20 +2,28 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Order\Listeners;
|
namespace Modules\Core\Order\Listeners;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Queue\ShouldQueue;
|
||||||
|
use Modules\Core\Order\Services\OrderStatusFlow;
|
||||||
use Modules\Core\Order\Services\OrderStatusWriter;
|
use Modules\Core\Order\Services\OrderStatusWriter;
|
||||||
use Modules\Core\Shipping\Enums\TrackingStatus;
|
use Modules\Core\Shipping\Enums\TrackingStatus;
|
||||||
use Modules\Core\Shipping\Events\ShipmentStatusUpdatedByCarrier;
|
use Modules\Core\Shipping\Events\ShipmentStatusUpdatedByCarrier;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
* Queued — see Modules\Core\Order\Listeners\DeriveOrderDeliveredFromShipment's
|
||||||
|
* own docblock: ShipmentStatusUpdatedByCarrier comes from a scheduled
|
||||||
|
* polling job, not a webhook.
|
||||||
|
*
|
||||||
* Wires TrackingStatus::Failed to the 'delivery_failed' status for the
|
* Wires TrackingStatus::Failed to the 'delivery_failed' status for the
|
||||||
* first time — previously an unused enum case. Guarded to only fire from
|
* first time — previously an unused enum case. Guarded by
|
||||||
* 'dispatched': a stale/duplicate checkpoint, or an order a manual action
|
* OrderStatusFlow::isValidTransition() rather than a hardcoded "only fire
|
||||||
* already moved past, is a silent no-op.
|
* from 'dispatched'" comparison. A stale/duplicate checkpoint, or an
|
||||||
|
* order a manual action already moved past, is a silent no-op either way.
|
||||||
*/
|
*/
|
||||||
class MarkDeliveryFailedOnCarrierCheckpoint
|
class MarkDeliveryFailedOnCarrierCheckpoint implements ShouldQueue
|
||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly OrderStatusWriter $writer,
|
private readonly OrderStatusWriter $writer,
|
||||||
|
private readonly OrderStatusFlow $flow,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
public function handle(ShipmentStatusUpdatedByCarrier $event): void
|
public function handle(ShipmentStatusUpdatedByCarrier $event): void
|
||||||
@@ -26,7 +34,7 @@ class MarkDeliveryFailedOnCarrierCheckpoint
|
|||||||
|
|
||||||
$order = $event->shipmentInfo->shipment->order;
|
$order = $event->shipmentInfo->shipment->order;
|
||||||
|
|
||||||
if (! $order || $order->status !== 'dispatched') {
|
if (! $order || ! $this->flow->isValidTransition($order, 'delivery_failed')) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,66 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Listeners;
|
||||||
|
|
||||||
|
use Illuminate\Support\Facades\Event;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Modules\Core\Checkout\Events\OrderPlaced;
|
||||||
|
use Modules\Core\Order\Services\OrderPaymentResolutionService;
|
||||||
|
use Modules\Core\Payment\Events\PaymentDeferred;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Deliberately NOT queued — the storefront's own post-checkout
|
||||||
|
* confirmation page (Modules\Core\Checkout\Http\Controllers\
|
||||||
|
* CheckoutController::orderStatus()/confirmation(), per docs/checkout.md)
|
||||||
|
* looks up the order by placed_at being set immediately after
|
||||||
|
* initiatePayment() returns; a stalled queue would show the shopper a
|
||||||
|
* blank/failed confirmation for an order that, in the database, already
|
||||||
|
* exists and was genuinely placed. Same reasoning as
|
||||||
|
* DecrementStockOnOrderPlaced staying synchronous — this is the listener
|
||||||
|
* that makes DecrementStockOnOrderPlaced fire at all for a COD order (see
|
||||||
|
* OrderServiceProvider: OrderPlaced => DecrementStockOnOrderPlaced),
|
||||||
|
* so queueing this one would just move the same stock-oversell risk one
|
||||||
|
* hop earlier.
|
||||||
|
*
|
||||||
|
* A thin reactor, same shape as ApplyResolvedPaymentStatus — the actual
|
||||||
|
* decisions ("this order counts as placed the moment a deferred-payment
|
||||||
|
* driver resolves, independent of Order::paid" and "such an order also
|
||||||
|
* has nothing to sit at awaiting_payment for") live in PaymentDeferred's
|
||||||
|
* and OrderPaymentResolutionService::resolveDeferredPayment()'s own
|
||||||
|
* docblocks, re-confirmed with the user; this only extracts the order id
|
||||||
|
* and applies both, guarded against a duplicate/replayed event the same
|
||||||
|
* way OrderPaymentResolutionService::resolveCaptureOrAuthorization() is.
|
||||||
|
*
|
||||||
|
* Without the status advance below, a COD order was left sitting at
|
||||||
|
* 'awaiting_payment' forever — placed_at/OrderPlaced alone fixed order
|
||||||
|
* visibility and stock decrement, but nothing ever moved `status` off its
|
||||||
|
* initial value, since resolveCaptureOrAuthorization() only does that for
|
||||||
|
* an actual capture. Caught and fixed after the fact.
|
||||||
|
*/
|
||||||
|
class MarkOrderPlacedOnDeferredPayment
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly OrderPaymentResolutionService $resolution,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
public function handle(PaymentDeferred $event): void
|
||||||
|
{
|
||||||
|
$orderId = $event->context['order_id'] ?? null;
|
||||||
|
|
||||||
|
if ($orderId === null) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$order = Order::findOrFail($orderId);
|
||||||
|
|
||||||
|
$this->resolution->resolveDeferredPayment($order, self::class);
|
||||||
|
|
||||||
|
if (! blank($order->placed_at)) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$order->update(['placed_at' => now()]);
|
||||||
|
|
||||||
|
Event::dispatch(new OrderPlaced($order));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -10,6 +10,17 @@ use Modules\Core\Payment\Events\PaymentRefunded;
|
|||||||
use Modules\Core\Payment\Events\PaymentVoided;
|
use Modules\Core\Payment\Events\PaymentVoided;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
* Deliberately NOT queued, despite looking like a pure audit-trail write
|
||||||
|
* with no same-request reader — Modules\Core\Providers\
|
||||||
|
* OrderServiceProvider registers this to run BEFORE
|
||||||
|
* Modules\Core\Order\Listeners\ApplyResolvedPaymentStatus for
|
||||||
|
* PaymentRefunded specifically, because that listener's refund-status
|
||||||
|
* resolution reads the Transaction row this listener just wrote. Queueing
|
||||||
|
* this would run it asynchronously while ApplyResolvedPaymentStatus (sync)
|
||||||
|
* proceeds immediately, almost certainly executing before the queued job
|
||||||
|
* and silently breaking that read. See OrderServiceProvider's own
|
||||||
|
* registration-order comment.
|
||||||
|
*
|
||||||
* Writes the Transaction row for a successful payment outcome — the
|
* Writes the Transaction row for a successful payment outcome — the
|
||||||
* "record what happened" half of reacting to Payment's events, separate
|
* "record what happened" half of reacting to Payment's events, separate
|
||||||
* from Modules\Core\Order\Listeners\ApplyResolvedPaymentStatus's "update
|
* from Modules\Core\Order\Listeners\ApplyResolvedPaymentStatus's "update
|
||||||
|
|||||||
@@ -2,11 +2,16 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Order\Listeners;
|
namespace Modules\Core\Order\Listeners;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Queue\ShouldQueue;
|
||||||
use Modules\Core\Order\Events\OrderPaidChanged;
|
use Modules\Core\Order\Events\OrderPaidChanged;
|
||||||
use Modules\Core\Order\Events\OrderStatusChanged;
|
use Modules\Core\Order\Events\OrderStatusChanged;
|
||||||
use Modules\Core\Order\Services\OrderStatusTransitionRecorder;
|
use Modules\Core\Order\Services\OrderStatusTransitionRecorder;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
* Queued — a pure history-log write with no same-request reader anywhere
|
||||||
|
* in the codebase (no Filament page renders order_status_transitions
|
||||||
|
* immediately after a status change; it's browsed later, if at all).
|
||||||
|
*
|
||||||
* The one place order_status_transitions rows actually get written —
|
* The one place order_status_transitions rows actually get written —
|
||||||
* listens to OrderStatusChanged (every write of the single `status`
|
* listens to OrderStatusChanged (every write of the single `status`
|
||||||
* column, via Modules\Core\Order\Services\OrderStatusWriter::write()) and
|
* column, via Modules\Core\Order\Services\OrderStatusWriter::write()) and
|
||||||
@@ -15,7 +20,7 @@ use Modules\Core\Order\Services\OrderStatusTransitionRecorder;
|
|||||||
* one consistent audit trail entry ('paid', with a null from_status)
|
* one consistent audit trail entry ('paid', with a null from_status)
|
||||||
* rather than a second, separate table.
|
* rather than a second, separate table.
|
||||||
*/
|
*/
|
||||||
class RecordStatusTransition
|
class RecordStatusTransition implements ShouldQueue
|
||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly OrderStatusTransitionRecorder $recorder,
|
private readonly OrderStatusTransitionRecorder $recorder,
|
||||||
|
|||||||
@@ -0,0 +1,148 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Privacy;
|
||||||
|
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Lunar\Models\OrderAddress;
|
||||||
|
use Modules\Core\Privacy\Contracts\PersonalDataProvider;
|
||||||
|
use Modules\Core\Privacy\DTOs\CustomerSubject;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureOutcome;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderErasureResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderExportResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\UserSubject;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Orders and order addresses (lunar_orders, lunar_order_addresses) belong to the
|
||||||
|
* Customer (business account) via customer_id, not to an individual User, so this
|
||||||
|
* is Customer-scope only. They're also subject to legal retention (tax/accounting
|
||||||
|
* law generally requires invoices be kept for several years — GDPR Art. 17(3)(b)
|
||||||
|
* explicitly allows this to override an erasure request). eraseForCustomer()
|
||||||
|
* therefore pseudonymizes the PII-bearing free-text fields in place rather than
|
||||||
|
* deleting the order: totals, line items, tax data, and the order itself all
|
||||||
|
* remain intact and auditable.
|
||||||
|
*
|
||||||
|
* Also covers PII-adjacent keys living in Order.meta and OrderAddress.meta —
|
||||||
|
* Modules\Core\Checkout\Services\CheckoutService::initiatePayment() writes
|
||||||
|
* terms_accepted/terms_accepted_at/terms_accepted_policy_version/payment_method
|
||||||
|
* onto Order.meta, and Modules\Core\Shipping\Carriers\BoxNow\
|
||||||
|
* BoxNowFulfillmentService writes the shopper's chosen box_now_locker onto
|
||||||
|
* OrderAddress.meta — neither of which the free-text column erase above ever
|
||||||
|
* touched. Kept Customer-scope, consistent with Order/OrderAddress themselves.
|
||||||
|
*/
|
||||||
|
class OrderDataProvider implements PersonalDataProvider
|
||||||
|
{
|
||||||
|
private const ORDER_META_KEYS = [
|
||||||
|
'terms_accepted',
|
||||||
|
'terms_accepted_at',
|
||||||
|
'terms_accepted_policy_version',
|
||||||
|
'payment_method',
|
||||||
|
];
|
||||||
|
|
||||||
|
private const ADDRESS_META_KEYS = [
|
||||||
|
'box_now_locker',
|
||||||
|
];
|
||||||
|
|
||||||
|
public function name(): string
|
||||||
|
{
|
||||||
|
return 'orders';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$orders = Order::where('customer_id', $subject->customerId)->with('addresses')->get();
|
||||||
|
|
||||||
|
return new ProviderExportResult('orders', $orders->map(fn (Order $order) => [
|
||||||
|
'id' => $order->id,
|
||||||
|
'reference' => $order->reference,
|
||||||
|
'status' => $order->status,
|
||||||
|
'total' => $order->total?->decimal(),
|
||||||
|
'placed_at' => $order->placed_at?->toIso8601String(),
|
||||||
|
'meta' => $this->onlyKeys((array) $order->meta, self::ORDER_META_KEYS),
|
||||||
|
'addresses' => $order->addresses->map(fn (OrderAddress $address) => [
|
||||||
|
'type' => $address->type,
|
||||||
|
'first_name' => $address->first_name,
|
||||||
|
'last_name' => $address->last_name,
|
||||||
|
'line_one' => $address->line_one,
|
||||||
|
'city' => $address->city,
|
||||||
|
'postcode' => $address->postcode,
|
||||||
|
'contact_email' => $address->contact_email,
|
||||||
|
'contact_phone' => $address->contact_phone,
|
||||||
|
'meta' => $this->onlyKeys((array) $address->meta, self::ADDRESS_META_KEYS),
|
||||||
|
])->all(),
|
||||||
|
])->all());
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
return new ProviderExportResult('orders', []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
$orders = Order::where('customer_id', $subject->customerId)->with('addresses')->get();
|
||||||
|
|
||||||
|
if ($orders->isEmpty()) {
|
||||||
|
return new ProviderErasureResult('orders', ErasureOutcome::Skipped, 'No orders for this customer.');
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach ($orders as $order) {
|
||||||
|
$order->update([
|
||||||
|
'customer_reference' => null,
|
||||||
|
'notes' => null,
|
||||||
|
'meta' => $this->withoutKeys((array) $order->meta, self::ORDER_META_KEYS),
|
||||||
|
]);
|
||||||
|
|
||||||
|
foreach ($order->addresses as $address) {
|
||||||
|
$address->update([
|
||||||
|
'title' => null,
|
||||||
|
'first_name' => 'Erased',
|
||||||
|
'last_name' => 'Customer',
|
||||||
|
'company_name' => null,
|
||||||
|
'tax_identifier' => null,
|
||||||
|
'line_one' => null,
|
||||||
|
'line_two' => null,
|
||||||
|
'line_three' => null,
|
||||||
|
'delivery_instructions' => null,
|
||||||
|
'contact_email' => null,
|
||||||
|
'contact_phone' => null,
|
||||||
|
'meta' => $this->withoutKeys((array) $address->meta, self::ADDRESS_META_KEYS),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return new ProviderErasureResult(
|
||||||
|
'orders',
|
||||||
|
ErasureOutcome::Pseudonymized,
|
||||||
|
'Order and address free-text fields and PII-bearing meta keys cleared; order records, totals, and line items retained for legal/tax record-keeping.'
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
return new ProviderErasureResult('orders', ErasureOutcome::Skipped, 'Orders belong to Customer accounts, not individual users.');
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $meta
|
||||||
|
* @param array<int, string> $keys
|
||||||
|
* @return array<string, mixed>
|
||||||
|
*/
|
||||||
|
private function onlyKeys(array $meta, array $keys): array
|
||||||
|
{
|
||||||
|
return array_intersect_key($meta, array_flip($keys));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $meta
|
||||||
|
* @param array<int, string> $keys
|
||||||
|
* @return array<string, mixed>
|
||||||
|
*/
|
||||||
|
private function withoutKeys(array $meta, array $keys): array
|
||||||
|
{
|
||||||
|
foreach ($keys as $key) {
|
||||||
|
unset($meta[$key]);
|
||||||
|
}
|
||||||
|
|
||||||
|
return $meta;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -8,6 +8,8 @@ use Modules\Core\Order\DTOs\OrderFulfillmentResult;
|
|||||||
use Modules\Core\Order\Events\OrderPickedUp;
|
use Modules\Core\Order\Events\OrderPickedUp;
|
||||||
use Modules\Core\Order\Events\OrderReadyForDispatch;
|
use Modules\Core\Order\Events\OrderReadyForDispatch;
|
||||||
use Modules\Core\Order\Events\OrderReadyForPickup;
|
use Modules\Core\Order\Events\OrderReadyForPickup;
|
||||||
|
use Modules\Core\Payment\DTOs\PaymentResult;
|
||||||
|
use Modules\Core\Payment\Enums\PaymentResultStatus;
|
||||||
use Modules\Core\Shipping\Contracts\CarrierFulfillmentInterface;
|
use Modules\Core\Shipping\Contracts\CarrierFulfillmentInterface;
|
||||||
use Modules\Core\Shipping\DTOs\ShipmentRequest;
|
use Modules\Core\Shipping\DTOs\ShipmentRequest;
|
||||||
use Throwable;
|
use Throwable;
|
||||||
@@ -31,6 +33,7 @@ class OrderFulfillmentService
|
|||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly OrderStatusWriter $writer,
|
private readonly OrderStatusWriter $writer,
|
||||||
private readonly OrderStatusFlow $flow,
|
private readonly OrderStatusFlow $flow,
|
||||||
|
private readonly TransactionRecorder $transactions,
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
public function markReady(Order $order): OrderFulfillmentResult
|
public function markReady(Order $order): OrderFulfillmentResult
|
||||||
@@ -121,6 +124,39 @@ class OrderFulfillmentService
|
|||||||
return OrderFulfillmentResult::failure('This order cannot be marked paid right now.');
|
return OrderFulfillmentResult::failure('This order cannot be marked paid right now.');
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// canMarkPaid() only ever returns true for an order whose payment
|
||||||
|
// method resolves to the cash-on-delivery DRIVER (see
|
||||||
|
// OrderStatusFlow::isCod(), which checks PaymentMethod::driver,
|
||||||
|
// never the merchant-chosen `type` slug directly — a store could
|
||||||
|
// name that method "cod", "pay-on-delivery", anything). Such an
|
||||||
|
// order never runs through Payment's pay()/authorize() flow at
|
||||||
|
// checkout, so nothing else records a Transaction for it. Money
|
||||||
|
// changes hands right here, at this click, so this is the one
|
||||||
|
// place that write can happen; there is no earlier Payment event
|
||||||
|
// to hang it off of the way Modules\Core\Order\Listeners\
|
||||||
|
// RecordPaymentTransaction does for a gateway driver. See
|
||||||
|
// TransactionRecorder's own docblock — it already anticipated
|
||||||
|
// exactly this "manually-triggered ... from Filament" call site.
|
||||||
|
//
|
||||||
|
// $driver below is the payment method's own `type` slug (whatever
|
||||||
|
// the merchant named it, e.g. 'cash-on-delivery' or 'cod') —
|
||||||
|
// Transaction.driver's established meaning everywhere else in this
|
||||||
|
// codebase (see RecordPaymentTransaction/TransactionRecorder's own
|
||||||
|
// docblocks) is that type key, never the underlying driver CLASS.
|
||||||
|
// No fallback guess here: CheckoutService::initiatePayment() always
|
||||||
|
// writes Order.meta['payment_method'] before charging, and
|
||||||
|
// canMarkPaid() already guarantees this order got that far.
|
||||||
|
$this->transactions->record(
|
||||||
|
$order,
|
||||||
|
type: 'capture',
|
||||||
|
driver: (string) $order->meta['payment_method'],
|
||||||
|
result: new PaymentResult(
|
||||||
|
status: PaymentResultStatus::Succeeded,
|
||||||
|
reference: 'cod-manual-'.$order->id,
|
||||||
|
amount: $order->total,
|
||||||
|
),
|
||||||
|
);
|
||||||
|
|
||||||
$this->writer->markPaid($order, self::class.'::markPaid');
|
$this->writer->markPaid($order, self::class.'::markPaid');
|
||||||
|
|
||||||
return OrderFulfillmentResult::success('Order marked as paid.');
|
return OrderFulfillmentResult::success('Order marked as paid.');
|
||||||
|
|||||||
@@ -0,0 +1,108 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Order\Services;
|
||||||
|
|
||||||
|
use Illuminate\Support\Facades\Event;
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Modules\Core\Checkout\Events\OrderPlaced;
|
||||||
|
use Modules\Core\Order\Enums\PaymentStatus;
|
||||||
|
use Modules\Core\Order\Support\OrderStatus;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The actual business decisions behind reacting to a payment outcome —
|
||||||
|
* previously these lived entirely inside Modules\Core\Order\Listeners\
|
||||||
|
* ApplyResolvedPaymentStatus, a listener with no Service behind it, even
|
||||||
|
* though "should this order be marked paid," "should its status advance,
|
||||||
|
* and to what," and "what does a refund do to status" are all genuine
|
||||||
|
* decisions about Order state, not side effects of Payment's own events.
|
||||||
|
* That listener is now a thin reactor: extract the order id from
|
||||||
|
* $event->context, load the Order, call this service, done.
|
||||||
|
*
|
||||||
|
* See ApplyResolvedPaymentStatus's own docblock for the full business
|
||||||
|
* reasoning (re-confirmed with the user) behind each rule enforced here —
|
||||||
|
* this class only re-documents what's specific to the decision logic
|
||||||
|
* itself, not the "why" already recorded there.
|
||||||
|
*/
|
||||||
|
class OrderPaymentResolutionService
|
||||||
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly OrderStatusWriter $writer,
|
||||||
|
private readonly OrderStatusFlow $flow,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A captured or authorized payment: marks the order paid (capture
|
||||||
|
* only — an authorization is not yet captured funds), advances status
|
||||||
|
* out of 'awaiting_payment' (capture only), and marks the order
|
||||||
|
* placed if this is the first payment outcome it's seen.
|
||||||
|
*/
|
||||||
|
public function resolveCaptureOrAuthorization(Order $order, string $causeClass, bool $isCapture): void
|
||||||
|
{
|
||||||
|
$wasPlaced = ! blank($order->placed_at);
|
||||||
|
|
||||||
|
$this->writer->markPaid($order, $causeClass);
|
||||||
|
|
||||||
|
if ($isCapture) {
|
||||||
|
$this->advancePastAwaitingPayment($order, $causeClass);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (! $wasPlaced) {
|
||||||
|
$order->update(['placed_at' => $order->placed_at ?? now()]);
|
||||||
|
Event::dispatch(new OrderPlaced($order));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A deferred-capture payment (currently only cash-on-delivery — see
|
||||||
|
* Payment\Events\PaymentDeferred's own docblock): no money has moved,
|
||||||
|
* so unlike resolveCaptureOrAuthorization() this never calls
|
||||||
|
* $writer->markPaid() — Order::paid stays false until staff explicitly
|
||||||
|
* mark it received. But per OrderStatusFlow's own docblock, payment
|
||||||
|
* method never affects the status SEQUENCE at all — a COD order has
|
||||||
|
* nothing to "await" at checkout (no payment attempt happens), so
|
||||||
|
* 'awaiting_payment' is simply the wrong first status for it. Reuses
|
||||||
|
* the exact same advancePastAwaitingPayment() a capture uses, since
|
||||||
|
* the status-sequence logic itself doesn't differ by payment method,
|
||||||
|
* only whether `paid` also flips alongside it.
|
||||||
|
*/
|
||||||
|
public function resolveDeferredPayment(Order $order, string $causeClass): void
|
||||||
|
{
|
||||||
|
$this->advancePastAwaitingPayment($order, $causeClass);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Requires the refund Transaction row to already exist (Modules\Core\
|
||||||
|
* Order\Listeners\RecordPaymentTransaction must run first — see
|
||||||
|
* OrderServiceProvider's listener registration order for
|
||||||
|
* PaymentRefunded), so the relation is refreshed here rather than
|
||||||
|
* trusted from a possibly-stale $order instance.
|
||||||
|
*/
|
||||||
|
public function resolveRefund(Order $order, string $causeClass): void
|
||||||
|
{
|
||||||
|
$order->load('transactions');
|
||||||
|
|
||||||
|
$target = match (OrderStatus::payment($order)) {
|
||||||
|
PaymentStatus::Refunded => 'refunded',
|
||||||
|
PaymentStatus::PartialRefund => 'partially_refunded',
|
||||||
|
default => null,
|
||||||
|
};
|
||||||
|
|
||||||
|
if ($target !== null && $order->status !== $target) {
|
||||||
|
$this->writer->write($order, $target, $causeClass);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private function advancePastAwaitingPayment(Order $order, string $causeClass): void
|
||||||
|
{
|
||||||
|
if ($order->status !== 'awaiting_payment') {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
$next = $this->flow->nextOptions($order);
|
||||||
|
$target = array_key_first($next);
|
||||||
|
|
||||||
|
if ($target !== null) {
|
||||||
|
$this->writer->write($order, $target, $causeClass);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -133,6 +133,22 @@ class OrderStatusFlow
|
|||||||
return ! $order->paid && $this->isCod($order);
|
return ! $order->paid && $this->isCod($order);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Whether moving $order to $to is a valid transition from its CURRENT
|
||||||
|
* status — the single source of truth for "is this a legal next step,"
|
||||||
|
* so a caller reacting to an external event (a carrier tracking
|
||||||
|
* checkpoint, a staff action) doesn't need to hardcode its own "only
|
||||||
|
* fire from status X" guard duplicating what nextOptions() already
|
||||||
|
* knows. See e.g. Modules\Core\Order\Listeners\
|
||||||
|
* AdvanceFulfillmentOnCarrierCheckpoint, which used to compare
|
||||||
|
* $order->status to a literal 'ready_for_dispatch' inline instead of
|
||||||
|
* asking this class.
|
||||||
|
*/
|
||||||
|
public function isValidTransition(Order $order, string $to): bool
|
||||||
|
{
|
||||||
|
return array_key_exists($to, $this->nextOptions($order));
|
||||||
|
}
|
||||||
|
|
||||||
private function label(string $status): string
|
private function label(string $status): string
|
||||||
{
|
{
|
||||||
return (string) str($status)->replace('_', ' ')->title();
|
return (string) str($status)->replace('_', ' ')->title();
|
||||||
|
|||||||
@@ -49,6 +49,8 @@ class TransactionRecorder
|
|||||||
'reference' => $result->reference,
|
'reference' => $result->reference,
|
||||||
'status' => $result->status->name,
|
'status' => $result->status->name,
|
||||||
'notes' => $result->failureReason,
|
'notes' => $result->failureReason,
|
||||||
|
'card_type' => $result->meta['card_type'] ?? null,
|
||||||
|
'last_four' => $result->meta['last_four'] ?? null,
|
||||||
'meta' => $result->meta,
|
'meta' => $result->meta,
|
||||||
]);
|
]);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,38 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Payment\Contracts;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Optional contract a payment driver implements to declare it only makes
|
||||||
|
* sense for one fulfillment type — the payment-side mirror of
|
||||||
|
* Modules\Core\Shipping\Contracts\DeclaresFulfillmentType. Two concrete
|
||||||
|
* cases exist today, both hardcoded facts about the driver rather than a
|
||||||
|
* merchant configuration choice:
|
||||||
|
* - OfflinePaymentDriver ("pay in store," cash-in-hand) only makes
|
||||||
|
* sense when the shopper collects in person — meaningless for a
|
||||||
|
* carrier delivery, where no staff member is present to take the
|
||||||
|
* cash.
|
||||||
|
* - CashOnDeliveryPaymentDriver only makes sense when a carrier
|
||||||
|
* physically hands over the parcel and collects payment at that
|
||||||
|
* moment — meaningless for store pickup, which already has
|
||||||
|
* OfflinePaymentDriver for exactly that in-person moment.
|
||||||
|
*
|
||||||
|
* A driver that doesn't implement this (Stripe, bank transfer) has no
|
||||||
|
* fulfillment-type constraint — offered regardless of the cart's
|
||||||
|
* currently selected shipping method's fulfillment type.
|
||||||
|
*
|
||||||
|
* Read by Modules\Core\Checkout\Services\CheckoutService::
|
||||||
|
* getPaymentMethods(), which excludes a method whose driver implements
|
||||||
|
* this and disagrees with the cart's current fulfillment type (via
|
||||||
|
* Modules\Core\Shipping\Support\FulfillmentType::resolve() on the
|
||||||
|
* currently selected ShippingMethod). A cart with no shipping option
|
||||||
|
* selected yet imposes no constraint — every method is offered until a
|
||||||
|
* fulfillment type is actually known.
|
||||||
|
*/
|
||||||
|
interface RequiresFulfillmentType
|
||||||
|
{
|
||||||
|
/**
|
||||||
|
* @return 'carrier'|'store_pickup'
|
||||||
|
*/
|
||||||
|
public function requiredFulfillmentType(): string;
|
||||||
|
}
|
||||||
@@ -22,7 +22,7 @@ use Modules\Core\Payment\Events\PaymentRefunded;
|
|||||||
* chooses this driver explicitly in the refund action, independent of
|
* chooses this driver explicitly in the refund action, independent of
|
||||||
* which driver the original payment went through (see
|
* which driver the original payment went through (see
|
||||||
* Payment\Support\TransactionDriverAdapter::refundVia() and
|
* Payment\Support\TransactionDriverAdapter::refundVia() and
|
||||||
* Order\Filament\Extensions\OrderRefundActionsExtension). pay() exists so
|
* Order\Filament\Extensions\OrderActionsExtension). pay() exists so
|
||||||
* the same driver also covers receiving a payment by bank transfer, but
|
* the same driver also covers receiving a payment by bank transfer, but
|
||||||
* the admin UI for that (bank reference, notes, proof-of-transfer upload)
|
* the admin UI for that (bank reference, notes, proof-of-transfer upload)
|
||||||
* is deliberately not built yet — see the follow-up work tracked from this
|
* is deliberately not built yet — see the follow-up work tracked from this
|
||||||
|
|||||||
@@ -5,9 +5,11 @@ namespace Modules\Core\Payment\Drivers;
|
|||||||
use Illuminate\Support\Str;
|
use Illuminate\Support\Str;
|
||||||
use Lunar\DataTypes\Price;
|
use Lunar\DataTypes\Price;
|
||||||
use Modules\Core\Payment\Contracts\Configurable;
|
use Modules\Core\Payment\Contracts\Configurable;
|
||||||
|
use Modules\Core\Payment\Contracts\RequiresFulfillmentType;
|
||||||
use Modules\Core\Payment\Contracts\SupportsPay;
|
use Modules\Core\Payment\Contracts\SupportsPay;
|
||||||
use Modules\Core\Payment\DTOs\PaymentResult;
|
use Modules\Core\Payment\DTOs\PaymentResult;
|
||||||
use Modules\Core\Payment\Enums\PaymentResultStatus;
|
use Modules\Core\Payment\Enums\PaymentResultStatus;
|
||||||
|
use Modules\Core\Payment\Events\PaymentDeferred;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Cash-on-delivery/cash-on-pickup — the shopper pays staff in person, at
|
* Cash-on-delivery/cash-on-pickup — the shopper pays staff in person, at
|
||||||
@@ -31,20 +33,46 @@ use Modules\Core\Payment\Enums\PaymentResultStatus;
|
|||||||
* marking it received (Modules\Core\Order\Services\
|
* marking it received (Modules\Core\Order\Services\
|
||||||
* OrderFulfillmentService::markPaid()), offered by the single "Update
|
* OrderFulfillmentService::markPaid()), offered by the single "Update
|
||||||
* Status" action at any time, independent of status.
|
* Status" action at any time, independent of status.
|
||||||
|
*
|
||||||
|
* Despite returning Pending, this order IS fully placed the moment pay()
|
||||||
|
* returns — unlike a Stripe 3-D Secure Pending, nothing will ever resolve
|
||||||
|
* this into a later PaymentCaptured/PaymentAuthorized (COD has no gateway
|
||||||
|
* callback at all). Without PaymentDeferred, no listener ever set
|
||||||
|
* Order::placed_at for a COD order: invisible in customer order history,
|
||||||
|
* no stock decrement (Modules\Core\Order\Listeners\
|
||||||
|
* DecrementStockOnOrderPlaced only reacts to Checkout\Events\OrderPlaced),
|
||||||
|
* and the storefront's own post-checkout confirmation could never find it
|
||||||
|
* — a real bug, not a hypothetical, caught and fixed after the fact. See
|
||||||
|
* PaymentDeferred's own docblock for the full reasoning.
|
||||||
*/
|
*/
|
||||||
class CashOnDeliveryPaymentDriver implements Configurable, SupportsPay
|
class CashOnDeliveryPaymentDriver implements Configurable, SupportsPay, RequiresFulfillmentType
|
||||||
{
|
{
|
||||||
public function isConfigured(): bool
|
public function isConfigured(): bool
|
||||||
{
|
{
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* "On delivery" is the operative word — a carrier physically hands
|
||||||
|
* over the parcel and collects payment at that moment. Meaningless
|
||||||
|
* for store pickup, which already has OfflinePaymentDriver for the
|
||||||
|
* equivalent in-person moment.
|
||||||
|
*/
|
||||||
|
public function requiredFulfillmentType(): string
|
||||||
|
{
|
||||||
|
return 'carrier';
|
||||||
|
}
|
||||||
|
|
||||||
public function pay(string $type, Price $amount, array $data = [], array $context = []): PaymentResult
|
public function pay(string $type, Price $amount, array $data = [], array $context = []): PaymentResult
|
||||||
{
|
{
|
||||||
return new PaymentResult(
|
$result = new PaymentResult(
|
||||||
status: PaymentResultStatus::Pending,
|
status: PaymentResultStatus::Pending,
|
||||||
reference: 'cod-'.Str::uuid(),
|
reference: 'cod-'.Str::uuid(),
|
||||||
amount: $amount,
|
amount: $amount,
|
||||||
);
|
);
|
||||||
|
|
||||||
|
PaymentDeferred::dispatch($type, $result, $context);
|
||||||
|
|
||||||
|
return $result;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ namespace Modules\Core\Payment\Drivers;
|
|||||||
use Illuminate\Support\Str;
|
use Illuminate\Support\Str;
|
||||||
use Lunar\DataTypes\Price;
|
use Lunar\DataTypes\Price;
|
||||||
use Modules\Core\Payment\Contracts\Configurable;
|
use Modules\Core\Payment\Contracts\Configurable;
|
||||||
|
use Modules\Core\Payment\Contracts\RequiresFulfillmentType;
|
||||||
use Modules\Core\Payment\Contracts\SupportsPay;
|
use Modules\Core\Payment\Contracts\SupportsPay;
|
||||||
use Modules\Core\Payment\DTOs\PaymentResult;
|
use Modules\Core\Payment\DTOs\PaymentResult;
|
||||||
use Modules\Core\Payment\Enums\PaymentResultStatus;
|
use Modules\Core\Payment\Enums\PaymentResultStatus;
|
||||||
@@ -25,7 +26,7 @@ use Modules\Core\Payment\Events\PaymentCaptured;
|
|||||||
* none) purely so PaymentCaptured, and anything downstream keying on it,
|
* none) purely so PaymentCaptured, and anything downstream keying on it,
|
||||||
* have something to identify this attempt by.
|
* have something to identify this attempt by.
|
||||||
*/
|
*/
|
||||||
class OfflinePaymentDriver implements Configurable, SupportsPay
|
class OfflinePaymentDriver implements Configurable, SupportsPay, RequiresFulfillmentType
|
||||||
{
|
{
|
||||||
/**
|
/**
|
||||||
* Always true — no external dependency to be missing.
|
* Always true — no external dependency to be missing.
|
||||||
@@ -35,6 +36,16 @@ class OfflinePaymentDriver implements Configurable, SupportsPay
|
|||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Cash-in-hand requires a staff member physically present to take the
|
||||||
|
* payment — meaningless for a carrier delivery, where no such person
|
||||||
|
* exists at handoff.
|
||||||
|
*/
|
||||||
|
public function requiredFulfillmentType(): string
|
||||||
|
{
|
||||||
|
return 'store_pickup';
|
||||||
|
}
|
||||||
|
|
||||||
public function pay(string $type, Price $amount, array $data = [], array $context = []): PaymentResult
|
public function pay(string $type, Price $amount, array $data = [], array $context = []): PaymentResult
|
||||||
{
|
{
|
||||||
$reference = 'offline-'.Str::uuid();
|
$reference = 'offline-'.Str::uuid();
|
||||||
|
|||||||
@@ -4,9 +4,6 @@ namespace Modules\Core\Payment\Drivers;
|
|||||||
|
|
||||||
use Lunar\DataTypes\Price;
|
use Lunar\DataTypes\Price;
|
||||||
use Lunar\Models\Currency;
|
use Lunar\Models\Currency;
|
||||||
use Lunar\Stripe\Facades\Stripe;
|
|
||||||
use Lunar\Stripe\Managers\StripeManager;
|
|
||||||
use Lunar\Stripe\Models\StripePaymentIntent;
|
|
||||||
use Modules\Core\Payment\Contracts\Configurable;
|
use Modules\Core\Payment\Contracts\Configurable;
|
||||||
use Modules\Core\Payment\Contracts\HandlesPaymentCallback;
|
use Modules\Core\Payment\Contracts\HandlesPaymentCallback;
|
||||||
use Modules\Core\Payment\Contracts\SupportsAuthorization;
|
use Modules\Core\Payment\Contracts\SupportsAuthorization;
|
||||||
@@ -26,17 +23,20 @@ use Modules\Core\Payment\Events\PaymentRefundFailed;
|
|||||||
use Modules\Core\Payment\Events\PaymentRefunded;
|
use Modules\Core\Payment\Events\PaymentRefunded;
|
||||||
use Modules\Core\Payment\Events\PaymentVoidFailed;
|
use Modules\Core\Payment\Events\PaymentVoidFailed;
|
||||||
use Modules\Core\Payment\Events\PaymentVoided;
|
use Modules\Core\Payment\Events\PaymentVoided;
|
||||||
|
use Modules\Core\Payment\Models\StripePaymentIntent;
|
||||||
|
use Modules\Core\Payment\Support\StripeManager;
|
||||||
use Stripe\Exception\ApiErrorException;
|
use Stripe\Exception\ApiErrorException;
|
||||||
use Stripe\PaymentIntent;
|
use Stripe\PaymentIntent;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Talks to Stripe's PaymentIntent API directly — deliberately NOT via
|
* Talks to Stripe's PaymentIntent API directly — deliberately NOT via
|
||||||
* Lunar\Stripe\Facades\Stripe::createIntent()/fetchOrCreateIntent(), which
|
* Lunar's own checkout flow (lunarphp/stripe, since removed — see
|
||||||
* take a Lunar\Models\Cart and derive amount/currency from it. Payment
|
* Modules\Core\Payment\Support\StripeManager's own docblock), which took a
|
||||||
* must never receive a Cart (see docs/payments.md) — pay()/authorize()
|
* Lunar\Models\Cart and derived amount/currency from it. Payment must
|
||||||
* already receive $amount explicitly as their own required Lunar Price
|
* never receive a Cart (see docs/payments.md) — pay()/authorize() already
|
||||||
* parameter (see PaymentResult's own docblock), the caller's job to
|
* receive $amount explicitly as their own required Lunar Price parameter
|
||||||
* assemble, same as every other driver.
|
* (see PaymentResult's own docblock), the caller's job to assemble, same
|
||||||
|
* as every other driver.
|
||||||
*
|
*
|
||||||
* Every amount that crosses this class's own boundary is converted right
|
* Every amount that crosses this class's own boundary is converted right
|
||||||
* there: Lunar's Price -> Stripe's minor-unit int going INTO a gateway
|
* there: Lunar's Price -> Stripe's minor-unit int going INTO a gateway
|
||||||
@@ -45,12 +45,11 @@ use Stripe\PaymentIntent;
|
|||||||
* Nothing outside this class ever sees a Stripe-scaled integer.
|
* Nothing outside this class ever sees a Stripe-scaled integer.
|
||||||
*
|
*
|
||||||
* Correlating a later handleCallback() (a separate request — a webhook)
|
* Correlating a later handleCallback() (a separate request — a webhook)
|
||||||
* back to whatever $context identified this attempt is solved the same
|
* back to whatever $context identified this attempt is solved via real
|
||||||
* way lunarphp/stripe's own StripePaymentType/ProcessStripeWebhook solve
|
* cart_id/order_id columns on Modules\Core\Payment\Models\
|
||||||
* it: real cart_id/order_id columns on Lunar\Stripe\Models\
|
* StripePaymentIntent (a table this app now owns outright, already shaped
|
||||||
* StripePaymentIntent (a table already owned by lunarphp/stripe, already
|
* for exactly this), not a generic context blob. See docs/payments.md
|
||||||
* shaped for exactly this), not a generic context blob. See
|
* "Async resolution" for the full reasoning.
|
||||||
* docs/payments.md "Async resolution" for the full reasoning.
|
|
||||||
*/
|
*/
|
||||||
class StripePaymentDriver implements
|
class StripePaymentDriver implements
|
||||||
Configurable,
|
Configurable,
|
||||||
@@ -61,16 +60,18 @@ class StripePaymentDriver implements
|
|||||||
SupportsRefunds,
|
SupportsRefunds,
|
||||||
HandlesPaymentCallback
|
HandlesPaymentCallback
|
||||||
{
|
{
|
||||||
|
public function __construct(
|
||||||
|
private readonly StripeManager $stripe,
|
||||||
|
) {}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Same key lunarphp/stripe's own StripeManager reads its API key from
|
* Same key StripeManager reads its API key from — no key, no usable
|
||||||
* (Stripe::setApiKey(config('services.stripe.key'))) — no key, no
|
* driver.
|
||||||
* usable driver.
|
|
||||||
*/
|
*/
|
||||||
public function isConfigured(): bool
|
public function isConfigured(): bool
|
||||||
{
|
{
|
||||||
return filled(config('services.stripe.key'));
|
return filled(config('services.stripe.key'));
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Atomic charge — capture_method: automatic. Stripe still frequently
|
* Atomic charge — capture_method: automatic. Stripe still frequently
|
||||||
* confirms into requires_action/requires_confirmation rather than
|
* confirms into requires_action/requires_confirmation rather than
|
||||||
@@ -114,8 +115,27 @@ class StripePaymentDriver implements
|
|||||||
$params['payment_method'] = $data['payment_method'];
|
$params['payment_method'] = $data['payment_method'];
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Reconciliation safety net: this app never creates a Stripe Customer
|
||||||
|
// object and attaches no other identifying info to the PaymentIntent
|
||||||
|
// (see docs/payments.md "Reconciliation" for the full reasoning), so
|
||||||
|
// without this, a charge that succeeds on Stripe's side but is never
|
||||||
|
// written to our own DB (e.g. a DB outage at exactly the wrong
|
||||||
|
// moment) would be untraceable back to a cart/order — nothing to
|
||||||
|
// search Stripe's dashboard by except amount/time/card last-4.
|
||||||
|
// array_filter() drops order_id when it's not yet known (still null
|
||||||
|
// in $context at initial pay()/authorize() time — see
|
||||||
|
// rememberIntent()'s own null-coalesce for the same case).
|
||||||
|
$metadata = array_filter([
|
||||||
|
'cart_id' => $context['cart_id'] ?? null,
|
||||||
|
'order_id' => $context['order_id'] ?? null,
|
||||||
|
]);
|
||||||
|
|
||||||
|
if ($metadata !== []) {
|
||||||
|
$params['metadata'] = $metadata;
|
||||||
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
$paymentIntent = Stripe::getClient()->paymentIntents->create($params);
|
$paymentIntent = $this->stripe->getClient()->paymentIntents->create($params);
|
||||||
} catch (ApiErrorException $e) {
|
} catch (ApiErrorException $e) {
|
||||||
return $this->declined($type, $amount, $e, $context, authorizing: $captureMethod === 'manual');
|
return $this->declined($type, $amount, $e, $context, authorizing: $captureMethod === 'manual');
|
||||||
}
|
}
|
||||||
@@ -129,7 +149,7 @@ class StripePaymentDriver implements
|
|||||||
{
|
{
|
||||||
[$intentModel, $type, $context] = $this->resolveIntentModel($reference, $context, $data['type'] ?? '');
|
[$intentModel, $type, $context] = $this->resolveIntentModel($reference, $context, $data['type'] ?? '');
|
||||||
|
|
||||||
$paymentIntent = Stripe::getClient()->paymentIntents->retrieve($reference);
|
$paymentIntent = $this->stripe->getClient()->paymentIntents->retrieve($reference);
|
||||||
|
|
||||||
$authorizing = $paymentIntent->capture_method === PaymentIntent::CAPTURE_METHOD_MANUAL;
|
$authorizing = $paymentIntent->capture_method === PaymentIntent::CAPTURE_METHOD_MANUAL;
|
||||||
|
|
||||||
@@ -137,7 +157,7 @@ class StripePaymentDriver implements
|
|||||||
// automatic capture_method, but Stripe stopped short of
|
// automatic capture_method, but Stripe stopped short of
|
||||||
// capturing (rare, but the API contract allows it) — finish
|
// capturing (rare, but the API contract allows it) — finish
|
||||||
// the job pay() started.
|
// the job pay() started.
|
||||||
$paymentIntent = Stripe::getClient()->paymentIntents->capture($reference);
|
$paymentIntent = $this->stripe->getClient()->paymentIntents->capture($reference);
|
||||||
}
|
}
|
||||||
|
|
||||||
$intentModel?->update(['status' => $paymentIntent->status]);
|
$intentModel?->update(['status' => $paymentIntent->status]);
|
||||||
@@ -152,7 +172,7 @@ class StripePaymentDriver implements
|
|||||||
[$intentModel, $type, $context] = $this->resolveIntentModel($reference, $context);
|
[$intentModel, $type, $context] = $this->resolveIntentModel($reference, $context);
|
||||||
|
|
||||||
try {
|
try {
|
||||||
$paymentIntent = Stripe::getClient()->paymentIntents->capture($reference, [
|
$paymentIntent = $this->stripe->getClient()->paymentIntents->capture($reference, [
|
||||||
'amount_to_capture' => StripeManager::toStripeAmount($amount->value, $amount->currency),
|
'amount_to_capture' => StripeManager::toStripeAmount($amount->value, $amount->currency),
|
||||||
]);
|
]);
|
||||||
} catch (ApiErrorException $e) {
|
} catch (ApiErrorException $e) {
|
||||||
@@ -171,6 +191,7 @@ class StripePaymentDriver implements
|
|||||||
reference: $paymentIntent->id,
|
reference: $paymentIntent->id,
|
||||||
amount: $amount,
|
amount: $amount,
|
||||||
raw: $paymentIntent->toArray(),
|
raw: $paymentIntent->toArray(),
|
||||||
|
meta: $this->cardMetaFromIntent($paymentIntent),
|
||||||
);
|
);
|
||||||
|
|
||||||
$paymentIntent->status === PaymentIntent::STATUS_SUCCEEDED
|
$paymentIntent->status === PaymentIntent::STATUS_SUCCEEDED
|
||||||
@@ -185,7 +206,7 @@ class StripePaymentDriver implements
|
|||||||
[$intentModel, $type, $context] = $this->resolveIntentModel($reference, $context);
|
[$intentModel, $type, $context] = $this->resolveIntentModel($reference, $context);
|
||||||
|
|
||||||
try {
|
try {
|
||||||
$paymentIntent = Stripe::getClient()->paymentIntents->cancel($reference);
|
$paymentIntent = $this->stripe->getClient()->paymentIntents->cancel($reference);
|
||||||
} catch (ApiErrorException $e) {
|
} catch (ApiErrorException $e) {
|
||||||
$result = $this->failure($amount, $e, $reference);
|
$result = $this->failure($amount, $e, $reference);
|
||||||
PaymentVoidFailed::dispatch($type, $result, $context);
|
PaymentVoidFailed::dispatch($type, $result, $context);
|
||||||
@@ -216,7 +237,7 @@ class StripePaymentDriver implements
|
|||||||
[$intentModel, $type, $context] = $this->resolveIntentModel($reference, $context);
|
[$intentModel, $type, $context] = $this->resolveIntentModel($reference, $context);
|
||||||
|
|
||||||
try {
|
try {
|
||||||
$refund = Stripe::getClient()->refunds->create([
|
$refund = $this->stripe->getClient()->refunds->create([
|
||||||
'payment_intent' => $reference,
|
'payment_intent' => $reference,
|
||||||
'amount' => StripeManager::toStripeAmount($amount->value, $amount->currency),
|
'amount' => StripeManager::toStripeAmount($amount->value, $amount->currency),
|
||||||
]);
|
]);
|
||||||
@@ -253,7 +274,7 @@ class StripePaymentDriver implements
|
|||||||
'order_id' => $context['order_id'] ?? null,
|
'order_id' => $context['order_id'] ?? null,
|
||||||
'status' => $paymentIntent->status,
|
'status' => $paymentIntent->status,
|
||||||
'payment_type' => $type,
|
'payment_type' => $type,
|
||||||
'context' => json_encode($context),
|
'context' => $context,
|
||||||
]);
|
]);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -278,28 +299,10 @@ class StripePaymentDriver implements
|
|||||||
return [
|
return [
|
||||||
$intentModel,
|
$intentModel,
|
||||||
$intentModel?->payment_type ?? $typeFallback,
|
$intentModel?->payment_type ?? $typeFallback,
|
||||||
$this->decodeContext($intentModel) ?? $context,
|
$intentModel?->context ?? $context,
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* StripePaymentIntent is a vendor model (lunarphp/stripe) with no cast
|
|
||||||
* declared for our own 'context' column (added by boboko-core's own
|
|
||||||
* migration, see database/migrations/..._add_context_to_stripe_
|
|
||||||
* payment_intents.php) — we can't edit the vendor model to add one, so
|
|
||||||
* decode manually here instead of assuming Eloquent already did it.
|
|
||||||
*
|
|
||||||
* @return array<string, mixed>|null
|
|
||||||
*/
|
|
||||||
private function decodeContext(?StripePaymentIntent $intentModel): ?array
|
|
||||||
{
|
|
||||||
if (! $intentModel || ! $intentModel->context) {
|
|
||||||
return null;
|
|
||||||
}
|
|
||||||
|
|
||||||
return json_decode($intentModel->context, associative: true) ?: null;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Converts a live Stripe PaymentIntent's own amount/currency back
|
* Converts a live Stripe PaymentIntent's own amount/currency back
|
||||||
* into Lunar's Price — the one place this class reads a Stripe
|
* into Lunar's Price — the one place this class reads a Stripe
|
||||||
@@ -341,6 +344,7 @@ class StripePaymentDriver implements
|
|||||||
amount: $amount,
|
amount: $amount,
|
||||||
failureReason: $paymentIntent->last_payment_error->message ?? null,
|
failureReason: $paymentIntent->last_payment_error->message ?? null,
|
||||||
raw: $paymentIntent->toArray(),
|
raw: $paymentIntent->toArray(),
|
||||||
|
meta: $status === PaymentResultStatus::Pending ? [] : $this->cardMetaFromIntent($paymentIntent),
|
||||||
continuation: $continuation,
|
continuation: $continuation,
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -363,6 +367,40 @@ class StripePaymentDriver implements
|
|||||||
return $result;
|
return $result;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* card_type/last_four for Modules\Core\Order\Services\
|
||||||
|
* TransactionRecorder to map onto Transaction (see PaymentResult::
|
||||||
|
* $meta's own docblock) — same fields, same source
|
||||||
|
* (payment_method_details on the underlying Charge) as lunarphp/
|
||||||
|
* stripe's own StoreCharges, just reached via latest_charge instead of
|
||||||
|
* an order-level charge list, since this driver has no Order/Cart to
|
||||||
|
* enumerate charges from.
|
||||||
|
*
|
||||||
|
* @return array{card_type?: string, last_four?: string}
|
||||||
|
*/
|
||||||
|
private function cardMetaFromIntent(PaymentIntent $paymentIntent): array
|
||||||
|
{
|
||||||
|
$chargeId = $paymentIntent->latest_charge;
|
||||||
|
|
||||||
|
if (blank($chargeId)) {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
|
||||||
|
$charge = $this->stripe->getCharge(is_string($chargeId) ? $chargeId : $chargeId->id);
|
||||||
|
|
||||||
|
$paymentType = collect($charge->payment_method_details)->keys()->first();
|
||||||
|
$details = collect($charge->payment_method_details)->first();
|
||||||
|
|
||||||
|
if (blank($details)) {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
|
||||||
|
return array_filter([
|
||||||
|
'card_type' => $details['brand'] ?? $paymentType,
|
||||||
|
'last_four' => $details['last4'] ?? null,
|
||||||
|
], fn ($value) => filled($value));
|
||||||
|
}
|
||||||
|
|
||||||
private function declined(string $type, Price $amount, ApiErrorException $e, array $context, bool $authorizing): PaymentResult
|
private function declined(string $type, Price $amount, ApiErrorException $e, array $context, bool $authorizing): PaymentResult
|
||||||
{
|
{
|
||||||
$result = $this->failure($amount, $e);
|
$result = $this->failure($amount, $e);
|
||||||
|
|||||||
@@ -0,0 +1,46 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Payment\Events;
|
||||||
|
|
||||||
|
use Illuminate\Foundation\Events\Dispatchable;
|
||||||
|
use Modules\Core\Payment\DTOs\PaymentResult;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* "This order has no money to collect yet, and never will via a gateway
|
||||||
|
* callback — nothing further will ever resolve this PaymentResult's
|
||||||
|
* Pending status into Captured/Authorized." Distinct from a Stripe-style
|
||||||
|
* Pending (3-D Secure, still resolving asynchronously via a later webhook
|
||||||
|
* or client-side confirmation) — that case correctly dispatches nothing
|
||||||
|
* yet, since PaymentCaptured/PaymentAuthorized WILL still follow once
|
||||||
|
* resolved.
|
||||||
|
*
|
||||||
|
* Dispatched by Modules\Core\Payment\Drivers\CashOnDeliveryPaymentDriver::
|
||||||
|
* pay() the moment it returns Pending — a COD order is fully placed at
|
||||||
|
* that instant, with reconciliation (Order::paid) happening independently,
|
||||||
|
* anywhere from same-day to months later, entirely outside any gateway's
|
||||||
|
* knowledge. Any other current or future "deferred capture, no gateway
|
||||||
|
* callback" driver dispatches this the same way, rather than each
|
||||||
|
* reinventing its own "mark placed" event.
|
||||||
|
*
|
||||||
|
* Handled by Modules\Core\Order\Listeners\MarkOrderPlacedOnDeferredPayment
|
||||||
|
* — sets ONLY Order::placed_at and fires Checkout\Events\OrderPlaced.
|
||||||
|
* Deliberately does not touch Order::paid/paid_at (see
|
||||||
|
* OrderStatusWriter::markPaid(), the only path that ever does) or create a
|
||||||
|
* Transaction row (RecordPaymentTransaction listens to PaymentCaptured/
|
||||||
|
* PaymentAuthorized/PaymentVoided/PaymentRefunded only — correctly not
|
||||||
|
* this event, since no money has moved and there is nothing to record
|
||||||
|
* yet).
|
||||||
|
*/
|
||||||
|
class PaymentDeferred
|
||||||
|
{
|
||||||
|
use Dispatchable;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param array<string, mixed> $context
|
||||||
|
*/
|
||||||
|
public function __construct(
|
||||||
|
public readonly string $type,
|
||||||
|
public readonly PaymentResult $result,
|
||||||
|
public readonly array $context = [],
|
||||||
|
) {}
|
||||||
|
}
|
||||||
@@ -3,16 +3,21 @@
|
|||||||
namespace Modules\Core\Payment\Filament\Resources;
|
namespace Modules\Core\Payment\Filament\Resources;
|
||||||
|
|
||||||
use Filament\Actions\Action;
|
use Filament\Actions\Action;
|
||||||
|
use Filament\Forms\Components\Hidden;
|
||||||
use Filament\Forms\Components\Select;
|
use Filament\Forms\Components\Select;
|
||||||
use Filament\Forms\Components\TextInput;
|
use Filament\Forms\Components\TextInput;
|
||||||
use Filament\Resources\Resource;
|
use Filament\Resources\Resource;
|
||||||
use Filament\Schemas\Components\Component;
|
use Filament\Schemas\Components\Component;
|
||||||
|
use Filament\Schemas\Components\Utilities\Get;
|
||||||
|
use InvalidArgumentException;
|
||||||
use Filament\Tables\Columns\IconColumn;
|
use Filament\Tables\Columns\IconColumn;
|
||||||
use Filament\Tables\Columns\TextColumn;
|
use Filament\Tables\Columns\TextColumn;
|
||||||
use Filament\Tables\Columns\ToggleColumn;
|
use Filament\Tables\Columns\ToggleColumn;
|
||||||
use Filament\Tables\Table;
|
use Filament\Tables\Table;
|
||||||
use Illuminate\Support\Facades\Event;
|
use Illuminate\Support\Facades\Event;
|
||||||
|
use Lunar\Admin\Support\Forms\Components\TranslatedText;
|
||||||
use Modules\Core\Payment\Contracts\Configurable;
|
use Modules\Core\Payment\Contracts\Configurable;
|
||||||
|
use Modules\Core\Payment\Contracts\SupportsAuthorization;
|
||||||
use Modules\Core\Payment\Events\PaymentMethodsReordered;
|
use Modules\Core\Payment\Events\PaymentMethodsReordered;
|
||||||
use Modules\Core\Payment\Filament\Resources\PaymentMethodResource\Pages\ListPaymentMethods;
|
use Modules\Core\Payment\Filament\Resources\PaymentMethodResource\Pages\ListPaymentMethods;
|
||||||
use Modules\Core\Payment\Models\PaymentMethod;
|
use Modules\Core\Payment\Models\PaymentMethod;
|
||||||
@@ -59,9 +64,9 @@ class PaymentMethodResource extends Resource
|
|||||||
{
|
{
|
||||||
protected static ?string $model = PaymentMethod::class;
|
protected static ?string $model = PaymentMethod::class;
|
||||||
|
|
||||||
protected static string|\BackedEnum|null $navigationIcon = 'heroicon-o-credit-card';
|
protected static string | \BackedEnum | null $navigationIcon = 'heroicon-o-credit-card';
|
||||||
|
|
||||||
protected static string|\UnitEnum|null $navigationGroup = 'Settings';
|
protected static string | \UnitEnum | null $navigationGroup = 'Settings';
|
||||||
|
|
||||||
protected static ?string $modelLabel = 'Payment Method';
|
protected static ?string $modelLabel = 'Payment Method';
|
||||||
|
|
||||||
@@ -76,7 +81,7 @@ class PaymentMethodResource extends Resource
|
|||||||
->sortable(),
|
->sortable(),
|
||||||
TextColumn::make('name')
|
TextColumn::make('name')
|
||||||
->label('Name')
|
->label('Name')
|
||||||
->searchable(),
|
->state(fn (PaymentMethod $record) => $record->translate('name')),
|
||||||
TextColumn::make('type')
|
TextColumn::make('type')
|
||||||
->label('Type'),
|
->label('Type'),
|
||||||
TextColumn::make('driver')
|
TextColumn::make('driver')
|
||||||
@@ -124,10 +129,9 @@ class PaymentMethodResource extends Resource
|
|||||||
public static function getFormComponents(): array
|
public static function getFormComponents(): array
|
||||||
{
|
{
|
||||||
return [
|
return [
|
||||||
TextInput::make('name')
|
TranslatedText::make('name')
|
||||||
->label('Name')
|
->label('Name')
|
||||||
->required()
|
->required(),
|
||||||
->maxLength(255),
|
|
||||||
TextInput::make('type')
|
TextInput::make('type')
|
||||||
->label('Type')
|
->label('Type')
|
||||||
->helperText('Machine-facing slug — stored on the cart/order, used by other code to identify this method. Cannot be changed once orders reference it.')
|
->helperText('Machine-facing slug — stored on the cart/order, used by other code to identify this method. Cannot be changed once orders reference it.')
|
||||||
@@ -144,7 +148,31 @@ class PaymentMethodResource extends Resource
|
|||||||
])
|
])
|
||||||
->default('pay')
|
->default('pay')
|
||||||
->live()
|
->live()
|
||||||
->required(),
|
// Only meaningful for a driver that actually implements
|
||||||
|
// SupportsAuthorization — CheckoutService::initiatePayment()
|
||||||
|
// calls $driver->authorize() when capture_mode is
|
||||||
|
// "authorize", which fatals on a driver missing that method
|
||||||
|
// entirely (e.g. CashOnDeliveryPaymentDriver, which only
|
||||||
|
// ever implements SupportsPay: the shopper pays staff in
|
||||||
|
// person, at an unknown future moment — there is no
|
||||||
|
// "hold now, settle later" operation to offer for that at
|
||||||
|
// all). Hidden rather than merely disabled, since a
|
||||||
|
// hidden field is also excluded from validation/dehydration
|
||||||
|
// — required() below would otherwise still block saving.
|
||||||
|
->visible(fn (Get $get) => static::driverSupportsAuthorization($get('driver')))
|
||||||
|
->required(fn (Get $get) => static::driverSupportsAuthorization($get('driver'))),
|
||||||
|
// Every OTHER fillForm() value not backed by a real component
|
||||||
|
// here is silently dropped — an Action::schema() modal only
|
||||||
|
// dehydrates fields present in its own schema, unlike a
|
||||||
|
// resource's form(); ListPaymentMethods::getHeaderActions()'s
|
||||||
|
// CreateAction::fillForm() used to set 'position' this same
|
||||||
|
// way and it never reached PaymentMethodService::create(),
|
||||||
|
// so every new method saved with the column's raw DB default
|
||||||
|
// (0) regardless of what fillForm() computed. Hidden here
|
||||||
|
// purely so it actually dehydrates; the table's own
|
||||||
|
// reorderable('position') drag-and-drop remains the real
|
||||||
|
// staff-facing way to change it afterward.
|
||||||
|
Hidden::make('position'),
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -153,9 +181,23 @@ class PaymentMethodResource extends Resource
|
|||||||
return Select::make('driver')
|
return Select::make('driver')
|
||||||
->label('Driver')
|
->label('Driver')
|
||||||
->options(fn () => app(PaymentDriverRegistry::class)->labels())
|
->options(fn () => app(PaymentDriverRegistry::class)->labels())
|
||||||
|
->live()
|
||||||
->required();
|
->required();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private static function driverSupportsAuthorization(?string $driver): bool
|
||||||
|
{
|
||||||
|
if (! $driver) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
return app(PaymentDriverRegistry::class)->resolve($driver) instanceof SupportsAuthorization;
|
||||||
|
} catch (InvalidArgumentException) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
public static function getPages(): array
|
public static function getPages(): array
|
||||||
{
|
{
|
||||||
return [
|
return [
|
||||||
@@ -180,7 +222,7 @@ class PaymentMethodResource extends Resource
|
|||||||
->icon('heroicon-o-pencil-square')
|
->icon('heroicon-o-pencil-square')
|
||||||
->schema(static::getFormComponents())
|
->schema(static::getFormComponents())
|
||||||
->fillForm(fn (PaymentMethod $record) => $record->only([
|
->fillForm(fn (PaymentMethod $record) => $record->only([
|
||||||
'name', 'type', 'driver', 'capture_mode',
|
'name', 'type', 'driver', 'capture_mode', 'position',
|
||||||
]))
|
]))
|
||||||
->action(fn (PaymentMethod $record, array $data) => app(PaymentMethodService::class)->update($record, $data));
|
->action(fn (PaymentMethod $record, array $data) => app(PaymentMethodService::class)->update($record, $data));
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,8 +2,10 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Payment\Filament\Resources\PaymentMethodResource\Pages;
|
namespace Modules\Core\Payment\Filament\Resources\PaymentMethodResource\Pages;
|
||||||
|
|
||||||
|
use Filament\Actions\CreateAction;
|
||||||
use Filament\Actions;
|
use Filament\Actions;
|
||||||
use Filament\Resources\Pages\ListRecords;
|
use Filament\Resources\Pages\ListRecords;
|
||||||
|
use Lunar\Models\Language;
|
||||||
use Modules\Core\Payment\Filament\Resources\PaymentMethodResource;
|
use Modules\Core\Payment\Filament\Resources\PaymentMethodResource;
|
||||||
use Modules\Core\Payment\Models\PaymentMethod;
|
use Modules\Core\Payment\Models\PaymentMethod;
|
||||||
use Modules\Core\Payment\Services\PaymentMethodService;
|
use Modules\Core\Payment\Services\PaymentMethodService;
|
||||||
@@ -15,12 +17,21 @@ class ListPaymentMethods extends ListRecords
|
|||||||
protected function getHeaderActions(): array
|
protected function getHeaderActions(): array
|
||||||
{
|
{
|
||||||
return [
|
return [
|
||||||
Actions\CreateAction::make()
|
CreateAction::make()
|
||||||
->schema(PaymentMethodResource::getFormComponents())
|
->schema(PaymentMethodResource::getFormComponents())
|
||||||
->fillForm(fn () => [
|
->fillForm(fn () => [
|
||||||
'position' => (PaymentMethod::max('position') ?? 0) + 1,
|
'position' => (PaymentMethod::max('position') ?? 0) + 1,
|
||||||
'enabled' => false,
|
'enabled' => false,
|
||||||
'data' => [],
|
'data' => [],
|
||||||
|
// TranslatedText's own default() (getLanguageDefaults())
|
||||||
|
// never reaches this mounted action's initial state —
|
||||||
|
// unlike a resource's own form(), an Action::schema()
|
||||||
|
// modal starts from exactly what fillForm() returns, so
|
||||||
|
// `name` was landing as null rather than the expected
|
||||||
|
// per-locale array, and every locale's sub-input
|
||||||
|
// silently failed to bind to it (required() on the
|
||||||
|
// default locale then correctly rejected the null).
|
||||||
|
'name' => Language::pluck('code')->mapWithKeys(fn (string $code) => [$code => ''])->all(),
|
||||||
])
|
])
|
||||||
// Every PaymentMethod write goes through PaymentMethodService
|
// Every PaymentMethod write goes through PaymentMethodService
|
||||||
// — see PaymentMethodResource's own docblock — so this
|
// — see PaymentMethodResource's own docblock — so this
|
||||||
|
|||||||
@@ -9,18 +9,17 @@ use Modules\Core\Payment\Drivers\StripePaymentDriver;
|
|||||||
use Stripe\Webhook;
|
use Stripe\Webhook;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* A boboko-owned webhook endpoint for Stripe — deliberately NOT
|
* A boboko-owned webhook endpoint for Stripe — never went through Lunar's
|
||||||
* lunarphp/stripe's own route (vendor/lunarphp/stripe/routes/webhooks.php),
|
* own Payments::driver('stripe') flow (the flow StripePaymentDriver was
|
||||||
* which dispatches into Lunar's own Payments::driver('stripe') flow (the
|
* built to replace, see that class's own docblock), and lunarphp/stripe
|
||||||
* flow StripePaymentDriver was built to replace, see that class's own
|
* has since been removed entirely (see Modules\Core\Payment\Support\
|
||||||
* docblock). Signature verification is handled by
|
* StripeManager's own docblock). Signature verification is handled by
|
||||||
* Lunar\Stripe\Http\Middleware\StripeWebhookMiddleware, registered on this
|
* Modules\Core\Payment\Http\Middleware\StripeWebhookMiddleware, registered
|
||||||
* route (see src/Payment/routes/webhooks.php) — pure Stripe SDK
|
* on this route (see src/Payment/routes/webhooks.php) — pure Stripe SDK
|
||||||
* verification + event-type filtering, safe to reuse even though this
|
* verification + event-type filtering. This controller verifies the
|
||||||
* controller never touches the rest of that vendor package's flow. This
|
* signature again itself (Webhook::constructEvent()) to get the
|
||||||
* controller verifies the signature again itself (Webhook::constructEvent())
|
* constructed Event object — the middleware doesn't stash one anywhere
|
||||||
* to get the constructed Event object — the middleware doesn't stash one
|
* reusable, it only gates the request through.
|
||||||
* anywhere reusable, it only gates the request through.
|
|
||||||
*
|
*
|
||||||
* Resolves the driver directly by class, not via
|
* Resolves the driver directly by class, not via
|
||||||
* Modules\Core\Payment\Services\PaymentDriverRegistry — this endpoint is
|
* Modules\Core\Payment\Services\PaymentDriverRegistry — this endpoint is
|
||||||
|
|||||||
@@ -0,0 +1,51 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Payment\Http\Middleware;
|
||||||
|
|
||||||
|
use Closure;
|
||||||
|
use Illuminate\Http\Request;
|
||||||
|
use Stripe\Exception\SignatureVerificationException;
|
||||||
|
use Stripe\Exception\UnexpectedValueException;
|
||||||
|
use Stripe\Webhook;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* First-party replacement for Lunar\Stripe\Http\Middleware\
|
||||||
|
* StripeWebhookMiddleware (lunarphp/stripe removed — see
|
||||||
|
* Modules\Core\Payment\Support\StripeManager's own docblock). Registered
|
||||||
|
* on the same route as before (src/Payment/routes/webhooks.php) purely to
|
||||||
|
* gate malformed/irrelevant requests before they reach
|
||||||
|
* Modules\Core\Payment\Http\Controllers\StripeWebhookController, which
|
||||||
|
* re-verifies the signature itself (see that controller's own docblock)
|
||||||
|
* to get the constructed Event object — this duplication predates the
|
||||||
|
* package removal and is left unchanged here.
|
||||||
|
*/
|
||||||
|
class StripeWebhookMiddleware
|
||||||
|
{
|
||||||
|
public function handle(Request $request, ?Closure $next = null)
|
||||||
|
{
|
||||||
|
$secret = config('services.stripe.webhooks.lunar');
|
||||||
|
$stripeSig = $request->header('Stripe-Signature');
|
||||||
|
|
||||||
|
try {
|
||||||
|
$event = Webhook::constructEvent(
|
||||||
|
$request->getContent(),
|
||||||
|
$stripeSig,
|
||||||
|
$secret
|
||||||
|
);
|
||||||
|
} catch (UnexpectedValueException|SignatureVerificationException $e) {
|
||||||
|
abort(400, $e->getMessage());
|
||||||
|
}
|
||||||
|
|
||||||
|
if (! in_array(
|
||||||
|
$event->type,
|
||||||
|
[
|
||||||
|
'payment_intent.payment_failed',
|
||||||
|
'payment_intent.succeeded',
|
||||||
|
]
|
||||||
|
)) {
|
||||||
|
return response('', 200);
|
||||||
|
}
|
||||||
|
|
||||||
|
return $next($request);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -2,6 +2,7 @@
|
|||||||
|
|
||||||
namespace Modules\Core\Payment\Listeners;
|
namespace Modules\Core\Payment\Listeners;
|
||||||
|
|
||||||
|
use Illuminate\Contracts\Queue\ShouldQueue;
|
||||||
use Modules\Core\Logging\ActivityLogService;
|
use Modules\Core\Logging\ActivityLogService;
|
||||||
use Modules\Core\Payment\Events\PaymentMethodCreated;
|
use Modules\Core\Payment\Events\PaymentMethodCreated;
|
||||||
use Modules\Core\Payment\Events\PaymentMethodDeleted;
|
use Modules\Core\Payment\Events\PaymentMethodDeleted;
|
||||||
@@ -9,6 +10,8 @@ use Modules\Core\Payment\Events\PaymentMethodUpdated;
|
|||||||
use Modules\Core\Payment\Models\PaymentMethod;
|
use Modules\Core\Payment\Models\PaymentMethod;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
* Queued — a pure audit-log write with no same-request reader.
|
||||||
|
*
|
||||||
* Same pattern as Localization\Listeners\LogTranslationActivity — routes
|
* Same pattern as Localization\Listeners\LogTranslationActivity — routes
|
||||||
* PaymentMethodService's own events through the existing
|
* PaymentMethodService's own events through the existing
|
||||||
* Logging\ActivityLogService instead of PaymentMethod separately opting
|
* Logging\ActivityLogService instead of PaymentMethod separately opting
|
||||||
@@ -29,7 +32,7 @@ use Modules\Core\Payment\Models\PaymentMethod;
|
|||||||
* forcing into a one-subject shape or adding a new method to the shared
|
* forcing into a one-subject shape or adding a new method to the shared
|
||||||
* service for.
|
* service for.
|
||||||
*/
|
*/
|
||||||
class LogPaymentMethodActivity
|
class LogPaymentMethodActivity implements ShouldQueue
|
||||||
{
|
{
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly ActivityLogService $activityLog,
|
private readonly ActivityLogService $activityLog,
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ namespace Modules\Core\Payment\Models;
|
|||||||
|
|
||||||
use Illuminate\Database\Eloquent\Casts\AsArrayObject;
|
use Illuminate\Database\Eloquent\Casts\AsArrayObject;
|
||||||
use Illuminate\Database\Eloquent\Model;
|
use Illuminate\Database\Eloquent\Model;
|
||||||
|
use Lunar\Base\Traits\HasTranslations;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* A merchant-configured payment method — the DB-instance layer, admin
|
* A merchant-configured payment method — the DB-instance layer, admin
|
||||||
@@ -11,7 +12,16 @@ use Illuminate\Database\Eloquent\Model;
|
|||||||
* shipping_methods table already has (see docs/payments.md):
|
* shipping_methods table already has (see docs/payments.md):
|
||||||
* - type: unique, machine-facing slug (Cart::meta['payment_method'],
|
* - type: unique, machine-facing slug (Cart::meta['payment_method'],
|
||||||
* ApplyPaymentMethodFee's lookup key, every Payment event's $type).
|
* ApplyPaymentMethodFee's lookup key, every Payment event's $type).
|
||||||
* - name: admin-facing label.
|
* - name: admin-facing label, locale-keyed JSON (e.g.
|
||||||
|
* {"en": "Cash On Delivery", "el": "Αντικαταβολή"}) — same shape/
|
||||||
|
* resolution as Product/Collection names (Lunar\Base\Traits\
|
||||||
|
* HasTranslations), just applied directly to this column rather than
|
||||||
|
* through attribute_data, since this is a merchant settings row, not
|
||||||
|
* a catalog attribute. Rendered in Filament via Lunar's own
|
||||||
|
* Lunar\Admin\Support\Forms\Components\TranslatedText — one input per
|
||||||
|
* configured Language row, no bespoke translation UI. Resolve a
|
||||||
|
* display string with $method->translate('name') (locale defaults to
|
||||||
|
* app()->getLocale(), falling back to the store's default language).
|
||||||
* - driver: the Modules\Core\Payment\Services\PaymentDriverRegistry key
|
* - driver: the Modules\Core\Payment\Services\PaymentDriverRegistry key
|
||||||
* — NOT the same as `type`, and not unique (two rows can share one
|
* — NOT the same as `type`, and not unique (two rows can share one
|
||||||
* driver, e.g. two differently-named offline-style methods).
|
* driver, e.g. two differently-named offline-style methods).
|
||||||
@@ -28,12 +38,15 @@ use Illuminate\Database\Eloquent\Model;
|
|||||||
*/
|
*/
|
||||||
class PaymentMethod extends Model
|
class PaymentMethod extends Model
|
||||||
{
|
{
|
||||||
|
use HasTranslations;
|
||||||
|
|
||||||
protected $guarded = [];
|
protected $guarded = [];
|
||||||
|
|
||||||
protected $casts = [
|
protected $casts = [
|
||||||
'enabled' => 'boolean',
|
'enabled' => 'boolean',
|
||||||
'position' => 'integer',
|
'position' => 'integer',
|
||||||
'driver_missing_at' => 'datetime',
|
'driver_missing_at' => 'datetime',
|
||||||
|
'name' => 'array',
|
||||||
'data' => AsArrayObject::class,
|
'data' => AsArrayObject::class,
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,32 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Payment\Models;
|
||||||
|
|
||||||
|
use Lunar\Base\BaseModel;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* First-party replacement for Lunar\Stripe\Models\StripePaymentIntent (the
|
||||||
|
* lunarphp/stripe package was removed — see Modules\Core\Payment\Support\
|
||||||
|
* StripeManager's own docblock). Same table (lunar_stripe_payment_intents,
|
||||||
|
* created by database/migrations/..._create_stripe_payment_intents_table,
|
||||||
|
* a first-party copy of the vendor migration), including the app-owned
|
||||||
|
* `context`/`payment_type` columns Modules\Core\Payment\Drivers\
|
||||||
|
* StripePaymentDriver::handleCallback() needs to recover $context/$type
|
||||||
|
* across the separate request a webhook arrives on — see that class's own
|
||||||
|
* docblock for "Async resolution".
|
||||||
|
*
|
||||||
|
* Extends Lunar\Base\BaseModel (from lunarphp/core, unaffected by removing
|
||||||
|
* lunarphp/stripe) purely so table-prefix resolution
|
||||||
|
* (config('lunar.database.table_prefix')) stays identical to how the
|
||||||
|
* vendor model resolved it — this table was created under that prefix.
|
||||||
|
*/
|
||||||
|
class StripePaymentIntent extends BaseModel
|
||||||
|
{
|
||||||
|
protected $table = 'stripe_payment_intents';
|
||||||
|
|
||||||
|
protected $guarded = [];
|
||||||
|
|
||||||
|
protected $casts = [
|
||||||
|
'context' => 'array',
|
||||||
|
];
|
||||||
|
}
|
||||||
@@ -0,0 +1,108 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Payment\Privacy;
|
||||||
|
|
||||||
|
use Lunar\Models\Order;
|
||||||
|
use Lunar\Models\Transaction;
|
||||||
|
use Modules\Core\Payment\Models\StripePaymentIntent;
|
||||||
|
use Modules\Core\Privacy\Contracts\PersonalDataProvider;
|
||||||
|
use Modules\Core\Privacy\DTOs\CustomerSubject;
|
||||||
|
use Modules\Core\Privacy\Enums\ErasureOutcome;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderErasureResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\ProviderExportResult;
|
||||||
|
use Modules\Core\Privacy\DTOs\UserSubject;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Payment records (lunar_transactions, stripe_payment_intents) belong to the
|
||||||
|
* Customer (business account) via the Order they're attached to, not to an
|
||||||
|
* individual User, so this is Customer-scope only — same chain
|
||||||
|
* OrderDataProvider already uses (Order.customer_id).
|
||||||
|
*
|
||||||
|
* Like Order itself, payment/transaction records are subject to the same
|
||||||
|
* tax/accounting legal retention argument (GDPR Art. 17(3)(b)) — a payment
|
||||||
|
* record is part of the same financial audit trail as the order it settled,
|
||||||
|
* so this pseudonymizes the card-identifying fields in place rather than
|
||||||
|
* deleting the transaction: amount, status, and the transaction/order link
|
||||||
|
* all remain intact and auditable.
|
||||||
|
*
|
||||||
|
* No Stripe Customer object exists anywhere in this app (see docs/
|
||||||
|
* payments.md "Reconciliation") — there is nothing to request deletion of
|
||||||
|
* on Stripe's side. The only local, erasable PII is the card brand/last-4
|
||||||
|
* on Transaction and the cart_id/order_id/context correlation row on
|
||||||
|
* stripe_payment_intents, which is deleted outright once its Order is
|
||||||
|
* settled (its only purpose was resolving an async webhook callback — see
|
||||||
|
* docs/payments.md "Async resolution" — which has already happened by the
|
||||||
|
* time an erasure request would run).
|
||||||
|
*/
|
||||||
|
class PaymentDataProvider implements PersonalDataProvider
|
||||||
|
{
|
||||||
|
public function name(): string
|
||||||
|
{
|
||||||
|
return 'payments';
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForCustomer(CustomerSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
$orderIds = Order::where('customer_id', $subject->customerId)->pluck('id');
|
||||||
|
|
||||||
|
$transactions = Transaction::whereIn('order_id', $orderIds)->get();
|
||||||
|
$intents = StripePaymentIntent::whereIn('order_id', $orderIds)->get();
|
||||||
|
|
||||||
|
return new ProviderExportResult('payments', [
|
||||||
|
'transactions' => $transactions->map(fn (Transaction $transaction) => [
|
||||||
|
'id' => $transaction->id,
|
||||||
|
'order_id' => $transaction->order_id,
|
||||||
|
'type' => $transaction->type,
|
||||||
|
'status' => $transaction->status,
|
||||||
|
'amount' => $transaction->amount,
|
||||||
|
'card_type' => $transaction->card_type,
|
||||||
|
'last_four' => $transaction->last_four,
|
||||||
|
'reference' => $transaction->reference,
|
||||||
|
])->all(),
|
||||||
|
'stripe_payment_intents' => $intents->map(fn (StripePaymentIntent $intent) => [
|
||||||
|
'id' => $intent->id,
|
||||||
|
'order_id' => $intent->order_id,
|
||||||
|
'intent_id' => $intent->intent_id,
|
||||||
|
'status' => $intent->status,
|
||||||
|
])->all(),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function exportForUser(UserSubject $subject): ProviderExportResult
|
||||||
|
{
|
||||||
|
return new ProviderExportResult('payments', []);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForCustomer(CustomerSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
$orderIds = Order::where('customer_id', $subject->customerId)->pluck('id');
|
||||||
|
|
||||||
|
if ($orderIds->isEmpty()) {
|
||||||
|
return new ProviderErasureResult('payments', ErasureOutcome::Skipped, 'No orders, and therefore no payment records, for this customer.');
|
||||||
|
}
|
||||||
|
|
||||||
|
Transaction::whereIn('order_id', $orderIds)->update([
|
||||||
|
'card_type' => null,
|
||||||
|
'last_four' => null,
|
||||||
|
]);
|
||||||
|
|
||||||
|
// stripe_payment_intents only ever existed to correlate a webhook
|
||||||
|
// callback back to a cart/order (see docs/payments.md "Async
|
||||||
|
// resolution") — that correlation has already served its purpose by
|
||||||
|
// the time an erasure request runs, so these rows are deleted
|
||||||
|
// outright rather than pseudonymized, unlike Transaction, which is
|
||||||
|
// the actual audit-trail record.
|
||||||
|
StripePaymentIntent::whereIn('order_id', $orderIds)->delete();
|
||||||
|
|
||||||
|
return new ProviderErasureResult(
|
||||||
|
'payments',
|
||||||
|
ErasureOutcome::Pseudonymized,
|
||||||
|
'Card brand/last-four cleared from transaction records; amounts, statuses, and references retained for legal/tax record-keeping. Stripe correlation rows (no longer needed post-settlement) deleted.'
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function eraseForUser(UserSubject $subject): ProviderErasureResult
|
||||||
|
{
|
||||||
|
return new ProviderErasureResult('payments', ErasureOutcome::Skipped, 'Payments belong to Customer-owned orders, not individual users.');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,126 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
namespace Modules\Core\Payment\Support;
|
||||||
|
|
||||||
|
use Lunar\Models\Contracts\Currency as CurrencyContract;
|
||||||
|
use Stripe\Charge;
|
||||||
|
use Stripe\StripeClient;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* First-party replacement for Lunar\Stripe\Facades\Stripe +
|
||||||
|
* Lunar\Stripe\Managers\StripeManager — lunarphp/stripe was removed once
|
||||||
|
* Modules\Core\Payment\Drivers\StripePaymentDriver already replaced every
|
||||||
|
* bit of Lunar's own Stripe payment flow (see that class's own docblock);
|
||||||
|
* all that remained load-bearing from the package was raw API-client
|
||||||
|
* access and amount conversion, neither of which is Lunar-specific. Only
|
||||||
|
* the methods StripePaymentDriver actually called are kept — no
|
||||||
|
* fetchOrCreateIntent()/cart-bound helpers, which belonged to Lunar's own
|
||||||
|
* (unused) checkout flow.
|
||||||
|
*
|
||||||
|
* getClient()/getCharge() call the Stripe SDK directly rather than going
|
||||||
|
* through a facade — StripePaymentDriver resolves this class via the
|
||||||
|
* container instead, same as every other dependency it takes.
|
||||||
|
*/
|
||||||
|
class StripeManager
|
||||||
|
{
|
||||||
|
public function getClient(): StripeClient
|
||||||
|
{
|
||||||
|
return new StripeClient([
|
||||||
|
'api_key' => config('services.stripe.key'),
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
public function getCharge(string $chargeId): Charge
|
||||||
|
{
|
||||||
|
return $this->getClient()->charges->retrieve($chargeId);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Zero-decimal currencies, per Stripe. The amount sent to Stripe is the
|
||||||
|
* major unit amount as-is.
|
||||||
|
*
|
||||||
|
* @see https://docs.stripe.com/currencies#zero-decimal
|
||||||
|
*/
|
||||||
|
protected const ZERO_DECIMAL_CURRENCIES = [
|
||||||
|
'bif', 'clp', 'djf', 'gnf', 'jpy', 'kmf', 'krw', 'mga', 'pyg',
|
||||||
|
'rwf', 'ugx', 'vnd', 'vuv', 'xaf', 'xof', 'xpf',
|
||||||
|
];
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Three-decimal currencies, per Stripe. The amount sent to Stripe is the
|
||||||
|
* major unit amount multiplied by 1000.
|
||||||
|
*
|
||||||
|
* @see https://docs.stripe.com/currencies#three-decimal
|
||||||
|
*/
|
||||||
|
protected const THREE_DECIMAL_CURRENCIES = ['bhd', 'jod', 'kwd', 'omr', 'tnd'];
|
||||||
|
|
||||||
|
/**
|
||||||
|
* HUF, TWD and UGX are ISO zero-decimal currencies, but Stripe still
|
||||||
|
* requires amounts to be sent as if they had two decimal places.
|
||||||
|
*
|
||||||
|
* @see https://docs.stripe.com/currencies#special-cases
|
||||||
|
*/
|
||||||
|
protected const SPECIAL_ZERO_DECIMAL_CURRENCIES = ['huf', 'twd', 'ugx'];
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Convert a Lunar price value to the amount expected by Stripe.
|
||||||
|
*
|
||||||
|
* Lunar stores prices as integers scaled by `Currency::decimal_places`,
|
||||||
|
* which merchants can set independently of what Stripe expects for a
|
||||||
|
* given currency. This converts back to the major unit amount first,
|
||||||
|
* then re-scales it to whatever sub-unit Stripe requires for the
|
||||||
|
* currency, so the result is correct regardless of how the merchant has
|
||||||
|
* configured `Currency::decimal_places`.
|
||||||
|
*
|
||||||
|
* @see https://docs.stripe.com/currencies
|
||||||
|
*/
|
||||||
|
public static function toStripeAmount(int $value, CurrencyContract $currency): int
|
||||||
|
{
|
||||||
|
return self::rescale($value, max($currency->decimal_places, 0), self::stripeDecimalPlaces($currency));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Convert an amount received from Stripe back to a Lunar price value,
|
||||||
|
* scaled by `Currency::decimal_places`. Inverse of `toStripeAmount()`.
|
||||||
|
*/
|
||||||
|
public static function fromStripeAmount(int $amount, CurrencyContract $currency): int
|
||||||
|
{
|
||||||
|
return self::rescale($amount, self::stripeDecimalPlaces($currency), max($currency->decimal_places, 0));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The number of decimal places Stripe expects amounts in for a currency.
|
||||||
|
*/
|
||||||
|
protected static function stripeDecimalPlaces(CurrencyContract $currency): int
|
||||||
|
{
|
||||||
|
$code = strtolower($currency->code);
|
||||||
|
|
||||||
|
// UGX is also in the zero-decimal list; the special case takes precedence.
|
||||||
|
if (in_array($code, self::SPECIAL_ZERO_DECIMAL_CURRENCIES, true)) {
|
||||||
|
return 2;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (in_array($code, self::ZERO_DECIMAL_CURRENCIES, true)) {
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (in_array($code, self::THREE_DECIMAL_CURRENCIES, true)) {
|
||||||
|
return 3;
|
||||||
|
}
|
||||||
|
|
||||||
|
return 2;
|
||||||
|
}
|
||||||
|
|
||||||
|
protected static function rescale(int $value, int $fromDecimalPlaces, int $toDecimalPlaces): int
|
||||||
|
{
|
||||||
|
$exponent = $toDecimalPlaces - $fromDecimalPlaces;
|
||||||
|
|
||||||
|
if ($exponent >= 0) {
|
||||||
|
return $value * (10 ** $exponent);
|
||||||
|
}
|
||||||
|
|
||||||
|
$divisor = 10 ** (-$exponent);
|
||||||
|
|
||||||
|
return intdiv(abs($value) + intdiv($divisor, 2), $divisor) * ($value < 0 ? -1 : 1);
|
||||||
|
}
|
||||||
|
}
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user