v1.0.0.0
StocketBase
- <?php
-
- declare(strict_types=1);
-
- if (count(get_included_files()) === 1) {
- http_response_code(403);
- exit;
- }
-
- require_once __DIR__ . '/../includes/icons.php';
- require_once __DIR__ . '/../includes/social-icons.php';
-
- if (!Auth::hasRoleAtLeast(Auth::ROLE_STORE_OWNER)) {
- return;
- }
-
- $db = Database::site();
- $action = $_POST['action'] ?? '';
-
- function nextNavSortOrder(PDO $db): int
- {
- $max = $db->query('SELECT COALESCE(MAX(sort_order), -1) AS m FROM nav_items')->fetch();
- return ((int) $max['m']) + 1;
- }
-
- function sanitizeNavIcon(string $iconKeyRaw, string $iconSvgRaw): array
- {
- $iconKeyRaw = trim($iconKeyRaw);
-
- if ($iconKeyRaw === '' || $iconKeyRaw === 'none') {
- return [null, null];
- }
-
- if ($iconKeyRaw === 'custom') {
- $svg = SocialIcons::sanitizeCustomSvg($iconSvgRaw);
- return $svg !== '' ? ['custom', $svg] : [null, null];
- }
-
- if (Icons::isNavIcon($iconKeyRaw)) {
- return [$iconKeyRaw, null];
- }
-
- return [null, null];
- }
-
- if ($action === 'add_nav_item') {
- $itemType = in_array($_POST['item_type'] ?? '', ['category', 'page', 'custom'], true) ? $_POST['item_type'] : 'category';
- $labelOverride = trim((string) ($_POST['label_override'] ?? ''));
- [$iconKey, $iconSvg] = sanitizeNavIcon((string) ($_POST['icon_key'] ?? ''), (string) ($_POST['icon_svg'] ?? ''));
-
- if ($itemType === 'category') {
- $refId = (int) ($_POST['category_ref_id'] ?? 0);
- if ($refId <= 0) {
- return;
- }
- $exists = $db->prepare('SELECT id FROM categories WHERE id = :id LIMIT 1');
- $exists->execute(['id' => $refId]);
- if (!$exists->fetch()) {
- return;
- }
-
- $statement = $db->prepare(
- 'INSERT INTO nav_items (item_type, ref_id, label, icon_key, icon_svg, sort_order) VALUES (:type, :ref_id, :label, :icon_key, :icon_svg, :sort_order)'
- );
- $statement->execute([
- 'type' => 'category',
- 'ref_id' => $refId,
- 'label' => $labelOverride !== '' ? $labelOverride : null,
- 'icon_key' => $iconKey,
- 'icon_svg' => $iconSvg,
- 'sort_order' => nextNavSortOrder($db),
- ]);
- }
-
- if ($itemType === 'page') {
- $refId = (int) ($_POST['page_ref_id'] ?? 0);
- if ($refId <= 0) {
- return;
- }
- $exists = $db->prepare('SELECT id FROM pages WHERE id = :id LIMIT 1');
- $exists->execute(['id' => $refId]);
- if (!$exists->fetch()) {
- return;
- }
-
- $statement = $db->prepare(
- 'INSERT INTO nav_items (item_type, ref_id, label, icon_key, icon_svg, sort_order) VALUES (:type, :ref_id, :label, :icon_key, :icon_svg, :sort_order)'
- );
- $statement->execute([
- 'type' => 'page',
- 'ref_id' => $refId,
- 'label' => $labelOverride !== '' ? $labelOverride : null,
- 'icon_key' => $iconKey,
- 'icon_svg' => $iconSvg,
- 'sort_order' => nextNavSortOrder($db),
- ]);
- }
-
- if ($itemType === 'custom') {
- $label = trim((string) ($_POST['custom_label'] ?? ''));
- $url = trim((string) ($_POST['custom_url'] ?? ''));
- $target = isset($_POST['custom_new_tab']) ? '_blank' : '_self';
-
- if ($label === '' || $url === '') {
- return;
- }
-
- $statement = $db->prepare(
- 'INSERT INTO nav_items (item_type, ref_id, label, url, target, icon_key, icon_svg, sort_order) VALUES (:type, NULL, :label, :url, :target, :icon_key, :icon_svg, :sort_order)'
- );
- $statement->execute([
- 'type' => 'custom',
- 'label' => $label,
- 'url' => $url,
- 'target' => $target,
- 'icon_key' => $iconKey,
- 'icon_svg' => $iconSvg,
- 'sort_order' => nextNavSortOrder($db),
- ]);
- }
- }
-
- if ($action === 'update_nav_item_icon') {
- $navItemId = (int) ($_POST['nav_item_id'] ?? 0);
- if ($navItemId <= 0) {
- return;
- }
-
- [$iconKey, $iconSvg] = sanitizeNavIcon((string) ($_POST['icon_key'] ?? ''), (string) ($_POST['icon_svg'] ?? ''));
-
- $statement = $db->prepare('UPDATE nav_items SET icon_key = :icon_key, icon_svg = :icon_svg WHERE id = :id');
- $statement->execute([
- 'icon_key' => $iconKey,
- 'icon_svg' => $iconSvg,
- 'id' => $navItemId,
- ]);
- }
-
- if ($action === 'move_nav_item') {
- $navItemId = (int) ($_POST['nav_item_id'] ?? 0);
- $direction = $_POST['direction'] ?? '';
-
- if ($navItemId <= 0 || !in_array($direction, ['up', 'down'], true)) {
- return;
- }
-
- $currentStatement = $db->prepare('SELECT id, sort_order FROM nav_items WHERE id = :id LIMIT 1');
- $currentStatement->execute(['id' => $navItemId]);
- $current = $currentStatement->fetch();
-
- if (!$current) {
- return;
- }
-
- if ($direction === 'up') {
- $neighborStatement = $db->prepare(
- 'SELECT id, sort_order FROM nav_items WHERE sort_order < :sort_order ORDER BY sort_order DESC LIMIT 1'
- );
- } else {
- $neighborStatement = $db->prepare(
- 'SELECT id, sort_order FROM nav_items WHERE sort_order > :sort_order ORDER BY sort_order ASC LIMIT 1'
- );
- }
- $neighborStatement->execute(['sort_order' => $current['sort_order']]);
- $neighbor = $neighborStatement->fetch();
-
- if (!$neighbor) {
- return;
- }
-
- $swap = $db->prepare('UPDATE nav_items SET sort_order = :sort_order WHERE id = :id');
- $swap->execute(['sort_order' => $neighbor['sort_order'], 'id' => $current['id']]);
- $swap->execute(['sort_order' => $current['sort_order'], 'id' => $neighbor['id']]);
- }
-
- if ($action === 'delete_nav_item') {
- $navItemId = (int) ($_POST['nav_item_id'] ?? 0);
- if ($navItemId > 0) {
- $statement = $db->prepare('DELETE FROM nav_items WHERE id = :id');
- $statement->execute(['id' => $navItemId]);
- }
- }
-