v1.0.0.0
StocketBase
- <?php
-
- declare(strict_types=1);
-
- if (count(get_included_files()) === 1) {
- http_response_code(403);
- exit;
- }
-
- $productId = (int) ($_POST['product_id'] ?? 0);
-
- if ($productId <= 0) {
- exit;
- }
-
- $db = Database::site();
- $statement = $db->prepare('SELECT * FROM products WHERE id = :id LIMIT 1');
- $statement->execute(['id' => $productId]);
- $product = $statement->fetch();
-
- if (!$product) {
- exit;
- }
-
- $isOwner = (int) $product['created_by'] === (int) $currentUser['id'];
- $canDeleteAny = Auth::hasRoleAtLeast(Auth::ROLE_STORE_OWNER);
-
- if (!$isOwner && !$canDeleteAny) {
- exit;
- }
-
- if ($isOwner && !$canDeleteAny && $product['status'] !== 'draft') {
- exit;
- }
-
- if ($product['deleted_at'] !== null) {
- exit;
- }
-
- $trash = $db->prepare(
- "UPDATE products SET trashed_status = status, status = 'draft', scheduled_at = NULL, deleted_at = NOW() WHERE id = :id AND deleted_at IS NULL"
- );
- $trash->execute(['id' => $productId]);
-