Compare commits

..
6 Commits
18 changed files with 873 additions and 7 deletions
+53
View File
@@ -4,6 +4,59 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
## [0.21.1] - 2026-09-25
### Changed
- `GuestOrderClaimer` and its `UserAuthenticated` listener moved from 3dealer's own
`App\Services`/`App\Listeners` into `Modules\Core\Customer\Services\GuestOrderClaimer` /
`Listeners\ClaimGuestOrdersOnLogin`, registered in `CustomerServiceProvider` — attaching a
placed guest order to an account once its billing `contact_email` case-insensitively matches
the account's email (only ever safe right after the shopper has proved they own that email: a
login code, or 3dealer's own email-change confirmation) was already core-appropriate logic
with no 3dealer-specific behavior. `Account\EmailController::verify()` now calls the core
service directly.
## [0.21.0] - 2026-09-25
### Added
- `Modules\Core\File` — a generic, storage-backend-agnostic file registry: `Models\File` (a
`files` table row per stored file — disk, path, original name, mime, size, a `purpose` tag,
and a nullable polymorphic owner), `Services\FileService` (store/retrieve/download/exists/
delete/list/`pruneUnowned`, delegating every actual byte-level operation to a
`Contracts\FileAdapterInterface` resolved per disk — `Adapters\LocalFileAdapter` today, the
same contextual-binding pattern `Shipping\Contracts\CarrierFulfillmentInterface` already uses
per carrier, so a future `S3FileAdapter` is one class and one more match arm, nothing else
changes), and `Http\Controllers\DownloadFileController` — a signed-URL-only route
(`files.download`) any consuming app can mint a link to, serving either inline (a preview) or
as a forced download (`?download=1`).
- `Modules\Core\File\Http\Controllers\UploadFileController` — an abstract base for "accept an
upload, validate it, store it via `FileService`, return its id" endpoints. Which
extensions/sizes are acceptable is deliberately left to a concrete subclass's own
`purpose()`/`validationRules()` overrides (ordinary server-side PHP, never trusting anything
the request itself claims about its own limits) — a real policy decision that can differ per
site and even per product/field, not something a shared base class or config file could
express safely.
- `boboko:file:prune-unowned {purpose}` — deletes every unowned `File` of a given purpose past
its grace period (`--hours`, default 24). Generic: any consuming app schedules it once per
purpose string it stores files under.
- `Modules\Core\Cart\Events\CartLineAdded`/`Checkout\Events\OrderPlaced` listeners
(`File\Listeners\AttachCustomFieldFileToCartLine`/`TransferCustomFieldFileOwnership`) that
re-point a `File`'s ownership from unowned → the real `CartLine` once one exists, then from
that `CartLine` → the `OrderLine` an order is placed with — so a File referenced by a product
custom field survives the cart it originated from being cleared, without ever being copied.
### Changed
- The admin order-lines table's collapsible details dropdown (next to the existing price
breakdown) now shows a product's custom-field answers (`OrderLine.meta.custom_fields`) — a
bordered table matching the existing price-breakdown one, with a thumbnail preview and a
download-icon link for a file answer, resolved through `File\Services\FileService`'s signed
route. Previously never shown anywhere in the admin.
- 3dealer's product custom-field photo upload (`CustomFieldUploadController`), cart line meta
(`CartController::customFieldsMeta()`), and pruning (formerly its own `PruneCustomFieldUploads`
command) now go through `Modules\Core\File` instead of a bespoke `Crypt::encryptString({disk,
path, name, mime})` reference scheme — a cart/order line's file answer is now just a `File`
row's `file_id`, with `File` as the single source of truth for every other detail.
## [0.20.2] - 2026-09-25
### Changed
+2 -1
View File
@@ -2,7 +2,7 @@
"name": "boboko/core",
"description": "Core module — authentication and shared panel behaviour",
"type": "library",
"version": "0.20.2",
"version": "0.21.1",
"autoload": {
"psr-4": {
"Modules\\Core\\": "src/"
@@ -43,6 +43,7 @@
"Modules\\Core\\Providers\\CatalogServiceProvider",
"Modules\\Core\\Providers\\CartServiceProvider",
"Modules\\Core\\Providers\\ReviewServiceProvider",
"Modules\\Core\\Providers\\FileServiceProvider",
"Modules\\Core\\Providers\\ShippingServiceProvider",
"Modules\\Core\\Providers\\OrderServiceProvider",
"Modules\\Core\\Providers\\PrivacyServiceProvider"
@@ -0,0 +1,50 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Schema;
/**
* A generic, storage-backend-agnostic file registry — Modules\Core\File\
* Services\FileService's own backing table. `disk`/`path` are whatever
* Laravel's Storage facade already understands (local, s3, ...); this
* table adds what Flysystem itself has no concept of: who a file
* belongs to, why it was uploaded, and whether anything still needs it.
*
* `owner_type`/`owner_id` are nullable — a file can (and, for a product
* custom-field photo, always does) exist before anything owns it yet: a
* shopper picks a photo on the product page and it's uploaded immediately
* (see 3dealer's CustomFieldUploadController), well before add-to-cart
* gives it a CartLine to belong to. FileService::attachOwner() re-points
* these columns once an owner exists, rather than creating a second row
* for the same physical file.
*
* `purpose` (e.g. 'custom-field-upload') lets one table serve unrelated
* future features without collision — FileService itself has no
* knowledge of what a purpose means, callers scope their own queries by
* it.
*/
return new class extends Migration
{
public function up(): void
{
Schema::create('files', function (Blueprint $table) {
$table->id();
$table->string('disk');
$table->string('path');
$table->string('original_name')->nullable();
$table->string('mime')->nullable();
$table->unsignedBigInteger('size')->nullable();
$table->string('purpose');
$table->nullableMorphs('owner');
$table->timestamps();
$table->index(['purpose', 'owner_type', 'owner_id']);
});
}
public function down(): void
{
Schema::dropIfExists('files');
}
};
@@ -0,0 +1,24 @@
<?php
namespace Modules\Core\Customer\Listeners;
use Modules\Core\Auth\Events\UserAuthenticated;
use Modules\Core\Customer\Services\GuestOrderClaimer;
/**
* Registered from Providers\CustomerServiceProvider — UserAuthenticated
* only fires after a valid login code, which is what makes matching
* placed guest orders by email safe (see GuestOrderClaimer's own
* docblock).
*/
class ClaimGuestOrdersOnLogin
{
public function __construct(
private readonly GuestOrderClaimer $claimer,
) {}
public function handle(UserAuthenticated $event): void
{
$this->claimer->claim($event->user);
}
}
@@ -0,0 +1,41 @@
<?php
namespace Modules\Core\Customer\Services;
use Illuminate\Contracts\Auth\Authenticatable;
use Lunar\Base\LunarUser;
use Lunar\Models\Order;
/**
* Attaches placed guest orders to an account when their billing email
* matches the account's email, case-insensitively. Only ever called right
* after the shopper has proved they own that email — a login code
* (Auth\Events\UserAuthenticated), or the code confirming an email change
* (a consuming app's own email-change flow, e.g. 3dealer's Account\
* EmailController::verify()) — which is what makes matching on email safe.
*
* Only orders with no customer_id AND no user_id are touched: an order
* already attached to any account (guest or otherwise) is left alone.
*/
class GuestOrderClaimer
{
public function claim(Authenticatable&LunarUser $user): int
{
$customer = $user->latestCustomer();
if (! $customer || ! $user->email) {
return 0;
}
return Order::query()
->whereNotNull('placed_at')
->whereNull('customer_id')
->whereNull('user_id')
->whereHas('billingAddress', fn ($query) => $query
->whereRaw('lower(contact_email) = ?', [strtolower($user->email)]))
->update([
'customer_id' => $customer->id,
'user_id' => $user->id,
]);
}
}
+48
View File
@@ -0,0 +1,48 @@
<?php
namespace Modules\Core\File\Adapters;
use Illuminate\Contracts\Filesystem\Filesystem;
use Illuminate\Http\UploadedFile;
use Modules\Core\File\Contracts\FileAdapterInterface;
use Symfony\Component\HttpFoundation\StreamedResponse;
/**
* Wraps Laravel's own 'local' Storage disk — see FileAdapterInterface's
* own docblock for why this exists as a named adapter rather than every
* caller reaching for Storage::disk('local') directly: swapping to a
* different backend later (S3FileAdapter, say) means adding one class and
* one contextual-binding entry, touching nothing that already uses
* FileService.
*/
class LocalFileAdapter implements FileAdapterInterface
{
public function __construct(
private readonly Filesystem $disk,
) {}
public function store(UploadedFile $file, string $directory): string
{
return $this->disk->putFile($directory, $file);
}
public function exists(string $path): bool
{
return $this->disk->exists($path);
}
public function delete(string $path): void
{
$this->disk->delete($path);
}
public function retrieve(string $path, ?string $name = null): StreamedResponse
{
return $this->disk->response($path, $name);
}
public function download(string $path, ?string $name = null): StreamedResponse
{
return $this->disk->download($path, $name);
}
}
@@ -0,0 +1,32 @@
<?php
namespace Modules\Core\File\Commands;
use Illuminate\Console\Command;
use Modules\Core\File\Services\FileService;
/**
* Generic wrapper around FileService::pruneUnowned() — see that method's
* own docblock for what "unowned" means and why the grace period exists.
* Any caller (3dealer's product custom-field photo uploads today, some
* other future upload feature tomorrow, in this app or another consuming
* app) schedules this once per purpose string it stores files under; this
* command itself has no opinion about what any given purpose means.
*/
class PruneUnownedFilesCommand extends Command
{
protected $signature = 'boboko:file:prune-unowned {purpose} {--hours=24 : Only delete unowned files older than this}';
protected $description = 'Delete unowned files of a given purpose past their grace period';
public function handle(FileService $files): int
{
$purpose = $this->argument('purpose');
$deleted = $files->pruneUnowned($purpose, now()->subHours((int) $this->option('hours')));
$this->info("Deleted {$deleted} unowned file(s) of purpose \"{$purpose}\".");
return self::SUCCESS;
}
}
@@ -0,0 +1,46 @@
<?php
namespace Modules\Core\File\Contracts;
use Illuminate\Http\UploadedFile;
use Symfony\Component\HttpFoundation\StreamedResponse;
/**
* One storage backend's actual byte-level operations — a disk name (see
* Modules\Core\File\Models\File::$disk) resolves to exactly one
* implementation of this via Modules\Core\File\Services\FileService's own
* contextual binding (see Providers\FileServiceProvider), the same
* pattern Shipping\Contracts\CarrierFulfillmentInterface uses to pick an
* AcsFulfillmentService/BoxNowFulfillmentService per carrier. FileService
* itself never touches a disk directly — every backend-specific detail
* (a local path, an S3 bucket/region, ...) lives entirely inside one
* adapter, so adding a new backend never touches FileService or any of
* its callers.
*/
interface FileAdapterInterface
{
/**
* Stores the file under $directory, returning the path to record on
* the File row (Models\File::$path) — backend-specific (a relative
* local path, an S3 object key, ...), meaningful only to this same
* adapter.
*/
public function store(UploadedFile $file, string $directory): string;
public function exists(string $path): bool;
public function delete(string $path): void;
/**
* Streams the file at $path straight to the browser, inline (the
* browser renders/previews it directly rather than prompting to save).
*/
public function retrieve(string $path, ?string $name = null): StreamedResponse;
/**
* Same bytes as retrieve(), but as a forced attachment — the browser
* always prompts to save, even for a type it could otherwise preview
* (an image inline in a new tab).
*/
public function download(string $path, ?string $name = null): StreamedResponse;
}
@@ -0,0 +1,45 @@
<?php
namespace Modules\Core\File\Http\Controllers;
use Illuminate\Http\Request;
use Illuminate\Routing\Controller;
use Modules\Core\File\Models\File;
use Modules\Core\File\Services\FileService;
use Symfony\Component\HttpFoundation\StreamedResponse;
/**
* Streams a File's bytes straight to the browser — inline by default (a
* browser-previewable type like an image opens/displays directly), or as
* a forced download with ?download=1 (e.g. an explicit "Download" button
* distinct from a thumbnail/preview link pointing at the same file). Only
* reachable via a short-lived signed URL — same auth model as
* Modules\Core\Shipping\Http\Controllers\DownloadShipmentLabelController
* (a valid signature IS the auth check, no separate staff/customer
* session check here) — so any caller that can mint a signed URL to this
* route (the storefront's own custom-field upload flow, or the admin
* order-line display) can hand a viewer a working link without this
* controller knowing anything about who they are or why they're allowed
* to see this particular file.
*
* Looks the File up manually from a plain {file} id rather than relying
* on implicit route-model-binding — registered via loadRoutesFrom() with
* no middleware group (see Providers\FileServiceProvider::boot()), so
* SubstituteBindings never runs and a type-hinted File parameter would
* silently resolve to an empty, non-existent model instead of 404ing.
*/
class DownloadFileController extends Controller
{
public function __invoke(Request $request, int $file, FileService $files): StreamedResponse
{
if (! $request->hasValidSignature()) {
abort(401);
}
$file = File::findOrFail($file);
abort_unless($files->exists($file), 404);
return $request->boolean('download') ? $files->download($file) : $files->retrieve($file);
}
}
@@ -0,0 +1,76 @@
<?php
namespace Modules\Core\File\Http\Controllers;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\Request;
use Illuminate\Routing\Controller;
use Illuminate\Support\Facades\Validator;
use Modules\Core\File\Services\FileService;
/**
* The generic "accept an upload, validate it, store it via FileService,
* return its id" flow — what varies per use case (which extensions/sizes
* are acceptable) is deliberately NOT configurable here, and NEVER trusts
* anything the request itself claims about its own limits: a client could
* simply lie about them. purpose()/validationRules() are protected hooks
* a concrete subclass overrides instead — an ordinary PHP method a caller
* writes once per upload policy, not request input, so the actual limit
* enforced is always whatever server-side code says it is. Different
* products can even need different limits (a 3D-print reference photo
* vs. a video upload, say) — that's still a subclass's own store()
* override deciding which rule set applies to a given request, not
* something this base class or a shared config file could express.
*/
abstract class UploadFileController extends Controller
{
/**
* The File row's `purpose` tag (see Models\File) — also the storage
* directory it lands under (FileService::store()'s single $purpose
* param doubles as both).
*/
abstract protected function purpose(): string;
/**
* Laravel validation rules for the incoming request, keyed exactly as
* $request->all() would be. Must include a 'file' rule accepting an
* uploaded file — this class always reads the file from that key.
*
* @return array<string, array<int, mixed>>
*/
abstract protected function validationRules(Request $request): array;
public function store(Request $request, FileService $files): JsonResponse
{
$validator = Validator::make(
$request->all(),
$this->validationRules($request),
$this->validationMessages($request),
$this->validationAttributes($request),
);
if ($validator->fails()) {
return response()->json(['error' => $validator->errors()->first('file')], 422);
}
$file = $files->store($request->file('file'), $this->purpose());
return response()->json(['file_id' => $file->id]);
}
/**
* @return array<string, string>
*/
protected function validationMessages(Request $request): array
{
return [];
}
/**
* @return array<string, string>
*/
protected function validationAttributes(Request $request): array
{
return [];
}
}
@@ -0,0 +1,44 @@
<?php
namespace Modules\Core\File\Listeners;
use Modules\Core\Cart\Events\CartLineAdded;
use Modules\Core\File\Models\File;
use Modules\Core\File\Services\FileService;
/**
* A custom-field photo is uploaded (and gets its own File row, unowned)
* the moment a shopper picks it on the product page — before add-to-cart
* even runs (see 3dealer's CustomFieldUploadController). The storefront's
* add-to-cart request only carries that File's `id` in its custom_fields
* answer (see CartController::customFieldsMeta()); this is what actually
* gives the File an owner, once the real CartLine it belongs to exists.
*
* Listens for Cart\Events\CartLineAdded rather than reaching back into
* the cart after CartService::addLine() returns — that event already
* carries the exact CartLine Lunar resolved/created, with no need to
* re-match it by meta (ambiguous whenever two lines share a purchasable +
* similar meta).
*/
class AttachCustomFieldFileToCartLine
{
public function __construct(
private readonly FileService $files,
) {}
public function handle(CartLineAdded $event): void
{
$fileIds = collect($event->line->meta['custom_fields'] ?? [])
->pluck('file_id')
->filter()
->all();
if ($fileIds === []) {
return;
}
File::query()
->whereIn('id', $fileIds)
->each(fn (File $file) => $this->files->attachOwner($file, $event->line));
}
}
@@ -0,0 +1,62 @@
<?php
namespace Modules\Core\File\Listeners;
use Lunar\Models\OrderLine;
use Modules\Core\Checkout\Events\OrderPlaced;
use Modules\Core\File\Models\File;
use Modules\Core\File\Services\FileService;
/**
* Lunar\Pipelines\Order\Creation\CreateOrderLines copies a CartLine's
* meta (custom_fields included) onto its new OrderLine verbatim — so an
* order's custom-field file answer keeps the exact same `file_id` its
* originating cart line's meta already had (see 3dealer's CartController::
* customFieldsMeta(), which stores only that id — File is the single
* source of truth for disk/path/name/mime, never duplicated into meta).
* That id is enough to find the File row directly, with no need to match
* an OrderLine back to "the" CartLine it came from.
*
* Re-points ownership (not a copy — the same File row) from whatever
* CartLine owned it to this OrderLine, so a customer's placed order keeps
* its file even after the cart it came from is later cleared (see
* Modules\Core\Cart\Services\CartService, or a checkout-complete cart
* reset) — FileService::pruneUnowned() only ever removes UNOWNED files,
* but a File left pointing at a since-deleted CartLine would be just as
* orphaned in practice; this listener is what keeps that from ever
* happening for a real, placed order.
*
* Listens for Checkout\Events\OrderPlaced, not an OrderLine model event —
* that's the one place in this codebase an order is reliably known to be
* placed exactly once (see that event's own docblock), and it hands over
* the whole Order with every line already loaded.
*/
class TransferCustomFieldFileOwnership
{
public function __construct(
private readonly FileService $files,
) {}
public function handle(OrderPlaced $event): void
{
foreach ($event->order->lines as $line) {
$this->transferLine($line);
}
}
private function transferLine(OrderLine $line): void
{
$fileIds = collect($line->meta['custom_fields'] ?? [])
->pluck('file_id')
->filter()
->all();
if ($fileIds === []) {
return;
}
File::query()
->whereIn('id', $fileIds)
->each(fn (File $file) => $this->files->attachOwner($file, $line));
}
}
+28
View File
@@ -0,0 +1,28 @@
<?php
namespace Modules\Core\File\Models;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\MorphTo;
/**
* A row per physical file Modules\Core\File\Services\FileService has
* stored — see that migration's own docblock for why `owner_type`/
* `owner_id` are nullable and what `purpose` is for.
*/
class File extends Model
{
protected $guarded = [];
protected function casts(): array
{
return [
'size' => 'integer',
];
}
public function owner(): MorphTo
{
return $this->morphTo();
}
}
+135
View File
@@ -0,0 +1,135 @@
<?php
namespace Modules\Core\File\Services;
use Illuminate\Contracts\Container\Container;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Http\UploadedFile;
use Illuminate\Support\Carbon;
use Illuminate\Support\Collection;
use Modules\Core\File\Contracts\FileAdapterInterface;
use Modules\Core\File\Models\File;
use Symfony\Component\HttpFoundation\StreamedResponse;
/**
* Orchestrates the `files` table (ownership, purpose, cleanup — see that
* migration's own docblock) on top of whichever FileAdapterInterface a
* disk resolves to (see Providers\FileServiceProvider's contextual
* binding) — never touches a disk or a raw path itself. Knows nothing
* about custom fields, carts, or orders specifically; every caller
* (3dealer's custom-field upload flow today, some other future
* file-upload need tomorrow) supplies its own `purpose` string and owner
* model, and scopes its own queries by them.
*
* `purpose` also doubles as the storage directory a file lands under
* (store() passes it straight through as the adapter's own $directory) —
* one string to name both, rather than every caller supplying two
* near-identical values for what's really the same distinction ("which
* kind of upload is this").
*/
class FileService
{
public function __construct(
private readonly Container $container,
) {}
public function store(UploadedFile $file, string $purpose, string $disk = 'local'): File
{
$path = $this->adapter($disk)->store($file, $purpose);
return File::create([
'disk' => $disk,
'path' => $path,
'original_name' => $file->getClientOriginalName(),
'mime' => $file->getMimeType(),
'size' => $file->getSize(),
'purpose' => $purpose,
]);
}
/**
* Re-points an existing File at its owner — called once an owner
* actually exists (e.g. a shopper's picked-but-not-yet-added photo
* gets a CartLine the moment it's added to the cart). Never creates a
* second row for the same physical file.
*/
public function attachOwner(File $file, Model $owner): File
{
$file->update([
'owner_type' => $owner->getMorphClass(),
'owner_id' => $owner->getKey(),
]);
return $file;
}
public function retrieve(File $file): StreamedResponse
{
return $this->adapter($file->disk)->retrieve($file->path, $file->original_name);
}
/**
* Same file as retrieve(), forced as a download (Content-Disposition:
* attachment) rather than served inline — for a button distinct from
* a preview link/thumbnail pointing at the same File.
*/
public function download(File $file): StreamedResponse
{
return $this->adapter($file->disk)->download($file->path, $file->original_name);
}
public function exists(File $file): bool
{
return $this->adapter($file->disk)->exists($file->path);
}
public function delete(File $file): void
{
$this->adapter($file->disk)->delete($file->path);
$file->delete();
}
/**
* @return Collection<int, File>
*/
public function list(string $purpose, ?Model $owner = null): Collection
{
return File::query()
->where('purpose', $purpose)
->when($owner, fn ($query) => $query
->where('owner_type', $owner->getMorphClass())
->where('owner_id', $owner->getKey()))
->get();
}
/**
* Deletes every File of the given purpose that has no owner yet and
* is older than $olderThan — the grace period covers a shopper still
* on the page with a picked-but-not-yet-added file. An owned File
* (whatever the owner type) is never touched here; callers that want
* owned files gone too should delete() them explicitly wherever that
* ownership itself ends (e.g. a CartLine being removed).
*
* @return int number of files deleted
*/
public function pruneUnowned(string $purpose, Carbon $olderThan): int
{
$files = File::query()
->where('purpose', $purpose)
->whereNull('owner_type')
->where('created_at', '<', $olderThan)
->get();
foreach ($files as $file) {
$this->delete($file);
}
return $files->count();
}
private function adapter(string $disk): FileAdapterInterface
{
return $this->container->make(FileAdapterInterface::class, ['disk' => $disk]);
}
}
+7
View File
@@ -0,0 +1,7 @@
<?php
use Illuminate\Support\Facades\Route;
use Modules\Core\File\Http\Controllers\DownloadFileController;
Route::get('files/{file}/download', DownloadFileController::class)
->name('files.download');
@@ -3,22 +3,60 @@
namespace Modules\Core\Order\Filament\Extensions;
use Filament\Actions\BulkAction;
use Filament\Support\Colors\Color;
use Filament\Support\Exceptions\Halt;
use Filament\Tables\Columns\Layout\Panel;
use Filament\Tables\Columns\TextColumn;
use Filament\Tables\Table;
use Illuminate\Support\Facades\Blade;
use Illuminate\Support\Facades\URL;
use Illuminate\Support\HtmlString;
use Lunar\Admin\Support\Extending\BaseExtension;
use Lunar\Models\OrderLine;
use Modules\Core\File\Models\File;
/**
* Same fix as OrderActionsExtension, applied to the order lines
* table's "bulk_refund" toolbar action (Lunar\Admin\...\OrderItemsTable::
* getBulkRefundAction()) — see that class's docblock for the underlying
* Filament bug (failureNotification()+failure()+halt() never actually
* sends the notification, because halt()'s Halt exception is caught before
* Filament reaches the code that would send it).
* extendTable() has two unrelated jobs: the "bulk_refund" toolbar-action
* fix (see fixFailureNotification()'s own docblock — a genuine Filament
* bug), and adding a "Custom Fields" entry to each order line's own
* collapsible details dropdown (Lunar\Admin\...\OrderItemsTable::
* getOrderLinesTableColumns()'s Panel — the same one already showing
* stock level, notes, and the price_breakdowns table) — the shopper's
* answers to Product::$custom_fields (a reference photo, personalization
* text, ...), stored on OrderLine.meta by 3dealer's CartController::
* customFieldsMeta() and, until now, never shown anywhere in the admin.
*
* Finds that Panel via $table->getCollapsibleColumnsLayout() — NOT
* $table->getColumns(), which two earlier attempts at this both reached
* for. HasColumns::pushColumns() flattens every Panel/Split into leaf
* columns at table-build time and stores THAT flat list as
* $this->columns (what getColumns() returns); the original nested
* Panel/Stack objects actually used for rendering are kept separately —
* in $this->columnsLayout for a non-collapsible layout component, or
* $this->collapsibleColumnsLayout for one that IS collapsible (this
* order-lines Panel is, via ->collapsible()). So `$column instanceof
* Panel` over getColumns() can never match anything — Panel/Split
* instances simply never appear in that array at all — and a fix built
* on that check silently mutated nothing. A first attempt building a
* brand new Panel and re-calling $table->columns() on top of the
* existing setup fixed nothing either and instead rendered as a stray
* empty extra column outside the dropdown (caught by actually opening
* the order page). Mutates the found Panel's Stack in place via
* Stack::schema(), the one part of both earlier attempts that actually
* worked once the right object was found.
*
* Its own TextColumn rather than reusing the Panel's existing KeyValue:
* KeyValue's own Blade view HTML-escapes every value ({{ $value }}),
* which can't render a clickable link for a file answer.
*/
class OrderItemsTableExtension extends BaseExtension
{
public function extendTable(Table $table): Table
{
if ($table->getCollapsibleColumnsLayout() instanceof Panel) {
$this->addCustomFieldsColumn($table->getCollapsibleColumnsLayout());
}
return $table->toolbarActions(
array_map(
fn ($action) => $action instanceof BulkAction && $action->getName() === 'bulk_refund'
@@ -29,6 +67,88 @@ class OrderItemsTableExtension extends BaseExtension
);
}
private function addCustomFieldsColumn(Panel $panel): void
{
$stack = $panel->getComponents()[0] ?? null;
if ($stack === null) {
return;
}
$stack->schema([
...$stack->getComponents(),
TextColumn::make('custom_fields')
->label('Custom Fields')
->visible(fn (OrderLine $record) => filled($record->meta['custom_fields'] ?? null))
->getStateUsing(fn (OrderLine $record) => $this->renderCustomFields($record))
->html(),
]);
}
/**
* Same table markup/classes as this Panel's own existing KeyValue
* component (Lunar\Admin's price_breakdowns, right above this in the
* dropdown — see lunarpanel::tables.components.key-value) for visual
* consistency, rebuilt here rather than reused: KeyValue's Blade view
* HTML-escapes every value ({{ $value }}), which can't render a
* thumbnail/download link for a file answer.
*/
private function renderCustomFields(OrderLine $record): HtmlString
{
$rows = collect($record->meta['custom_fields'] ?? [])
->map(fn (array $field) => sprintf(
'<tr class="divide-x divide-gray-950/10 dark:divide-white/10"><td class="p-2 font-medium whitespace-nowrap">%s</td><td class="p-2">%s</td></tr>',
e($field['label']),
$field['type'] === 'file' ? $this->fileCell($field) : e($field['value'] ?? ''),
))
->implode('');
return new HtmlString(
'<div class="w-full mt-2 overflow-hidden overflow-x-auto ring-1 ring-inset ring-gray-950/10 dark:ring-white/10 rounded bg-white/70 dark:bg-white/5">'
.'<table class="min-w-full text-xs divide-y divide-gray-950/10 dark:divide-white/10"><tbody class="divide-y divide-gray-950/10 dark:divide-white/10">'
.$rows
.'</tbody></table></div>',
);
}
/**
* A thumbnail (previewable image types only — an inline-signed URL to
* the same File; see FileService::retrieve()) alongside an icon-only
* download link forcing Content-Disposition: attachment (FileService::
* download()) — two separate signed URLs, not one reused with a query
* string appended after signing, since a signature covers the exact
* query parameters present when it was minted.
*/
private function fileCell(array $field): string
{
$file = File::find($field['file_id'] ?? null);
if ($file === null) {
return __('lunarpanel::global.na');
}
$previewUrl = URL::temporarySignedRoute('files.download', now()->addHours(2), ['file' => $file->id]);
$downloadUrl = URL::temporarySignedRoute('files.download', now()->addHours(2), ['file' => $file->id, 'download' => 1]);
$previewable = ['image/jpeg', 'image/png', 'image/webp', 'image/gif'];
$thumbnail = in_array($file->mime, $previewable, true)
? sprintf(
'<a href="%s" target="_blank" rel="noopener"><img src="%s" alt="" style="width:2.5rem;height:2.5rem;object-fit:cover;border-radius:0.375rem;vertical-align:middle"></a>',
$previewUrl,
$previewUrl,
)
: '';
return sprintf(
'<div style="display:flex;align-items:center;gap:0.5rem">%s<span>%s</span><a href="%s" title="Download" style="color:rgb(%s);display:inline-flex">%s</a></div>',
$thumbnail,
e($file->original_name),
$downloadUrl,
Color::Blue[600],
Blade::render('<x-filament::icon icon="heroicon-o-arrow-down-tray" style="width:1rem;height:1rem"/>'),
);
}
private function fixFailureNotification(BulkAction $action): BulkAction
{
$originalAction = $action->getActionFunction();
@@ -6,11 +6,13 @@ use Illuminate\Support\Facades\Event;
use Illuminate\Support\ServiceProvider;
use Lunar\Facades\ModelManifest;
use Lunar\Models\Contracts\Customer as LunarCustomer;
use Modules\Core\Auth\Events\UserAuthenticated;
use Modules\Core\Auth\Events\UserCreated;
use Modules\Core\Customer\Events\CustomerAddressCreated;
use Modules\Core\Customer\Events\CustomerAddressDeleted;
use Modules\Core\Customer\Events\CustomerAddressUpdated;
use Modules\Core\Customer\Events\CustomerProfileUpdated;
use Modules\Core\Customer\Listeners\ClaimGuestOrdersOnLogin;
use Modules\Core\Customer\Listeners\CreateCustomerForUser;
use Modules\Core\Customer\Listeners\LogCustomerAccountActivity;
use Modules\Core\Customer\Models\Customer;
@@ -35,6 +37,7 @@ class CustomerServiceProvider extends ServiceProvider
$this->app->booted(fn () => ModelManifest::replace(LunarCustomer::class, Customer::class));
Event::listen(UserCreated::class, CreateCustomerForUser::class);
Event::listen(UserAuthenticated::class, ClaimGuestOrdersOnLogin::class);
Event::listen(CustomerAddressCreated::class, [LogCustomerAccountActivity::class, 'handleAddressCreated']);
Event::listen(CustomerAddressUpdated::class, [LogCustomerAccountActivity::class, 'handleAddressUpdated']);
+51
View File
@@ -0,0 +1,51 @@
<?php
namespace Modules\Core\Providers;
use Illuminate\Support\Facades\Event;
use Illuminate\Support\Facades\Storage;
use Illuminate\Support\ServiceProvider;
use InvalidArgumentException;
use Modules\Core\Cart\Events\CartLineAdded;
use Modules\Core\Checkout\Events\OrderPlaced;
use Modules\Core\File\Adapters\LocalFileAdapter;
use Modules\Core\File\Commands\PruneUnownedFilesCommand;
use Modules\Core\File\Contracts\FileAdapterInterface;
use Modules\Core\File\Listeners\AttachCustomFieldFileToCartLine;
use Modules\Core\File\Listeners\TransferCustomFieldFileOwnership;
class FileServiceProvider extends ServiceProvider
{
public function register(): void
{
// Same pattern as ShippingServiceProvider's CarrierFulfillmentInterface
// binding — a plain param ('disk' here, 'carrier' there) picks which
// concrete adapter Modules\Core\File\Services\FileService actually
// talks to. Adding a real S3FileAdapter later is one class plus one
// more match arm here; nothing that already calls FileService changes.
$this->app->bind(FileAdapterInterface::class, function ($app, array $params) {
$disk = $params['disk'] ?? 'local';
return match ($disk) {
'local' => new LocalFileAdapter(Storage::disk($disk)),
default => throw new InvalidArgumentException("No FileAdapterInterface available for disk \"{$disk}\"."),
};
});
}
public function boot(): void
{
// Signed-URL auth only, same model as Shipping\Http\Controllers\
// DownloadShipmentLabelController — see that route's own docblock.
// Migrations live in the shared database/migrations directory
// CoreServiceProvider already loads; nothing more to register here.
$this->loadRoutesFrom(__DIR__.'/../File/routes/web.php');
Event::listen(CartLineAdded::class, AttachCustomFieldFileToCartLine::class);
Event::listen(OrderPlaced::class, TransferCustomFieldFileOwnership::class);
if ($this->app->runningInConsole()) {
$this->commands([PruneUnownedFilesCommand::class]);
}
}
}