v1.0.0.1
StocketBase
- <?php
-
- declare(strict_types=1);
-
- require_once __DIR__ . '/includes/config.php';
- require_once __DIR__ . '/includes/database.php';
- require_once __DIR__ . '/includes/auth.php';
- require_once __DIR__ . '/includes/csrf.php';
- require_once __DIR__ . '/includes/activity-log.php';
-
- Auth::boot();
- Auth::requireRoleAtLeast(Auth::ROLE_STORE_OWNER);
-
- $currentUser = Auth::user();
- $currentRole = Auth::role();
- $db = Database::site();
-
- $flashMessage = null;
- $flashType = 'success';
-
- if ($_SERVER['REQUEST_METHOD'] === 'POST') {
- if (!Csrf::verify($_POST['csrf_token'] ?? null)) {
- $flashMessage = 'Your session expired. Please try again.';
- $flashType = 'error';
- } else {
- require __DIR__ . '/dashboard-actions/manage-analytics.php';
- ActivityLog::record('analytics.' . (string) ($_POST['action'] ?? ''));
- $flashMessage = 'Changes saved.';
- }
- }
-
- $editId = (int) ($_GET['edit'] ?? 0) ?: null;
- $editingScript = null;
- if ($editId !== null) {
- $statement = $db->prepare('SELECT * FROM analytics_scripts WHERE id = :id LIMIT 1');
- $statement->execute(['id' => $editId]);
- $editingScript = $statement->fetch() ?: null;
- }
-
- $scripts = $db->query('SELECT * FROM analytics_scripts ORDER BY created_at DESC')->fetchAll();
-
- $db->prepare('INSERT IGNORE INTO site_settings (setting_key, setting_value) VALUES (:key, :value)')
- ->execute(['key' => 'consent_footer_icon_enabled', 'value' => '0']);
-
- $consentSetting = $db->prepare('SELECT setting_value FROM site_settings WHERE setting_key = :key LIMIT 1');
- $consentSetting->execute(['key' => 'consent_manager_enabled']);
- $consentEnabled = ($consentSetting->fetch()['setting_value'] ?? '0') === '1';
- $consentSetting->execute(['key' => 'consent_footer_icon_enabled']);
- $consentFooterIconEnabled = ($consentSetting->fetch()['setting_value'] ?? '0') === '1';
-
- $dashActivePage = 'analytics';
- $dashPageTitle = 'Analytics';
-
- require __DIR__ . '/includes/dash-header.php';
-
- ?>
-
- <?php if ($flashMessage !== null): ?>
- <div class="dash-flash dash-flash-<?= htmlspecialchars($flashType) ?>"><?= Icons::icon($flashType === 'error' ? 'x' : 'check', 'icon icon-sm') ?><?= htmlspecialchars($flashMessage) ?></div>
- <?php endif; ?>
-
- <h1 class="dash-title"><?= Icons::icon("analytics", "icon icon-lg") ?>Analytics</h1>
-
- <div class="sidebar-box" style="max-width:640px;margin-bottom:24px;">
- <form method="post">
- <?= Csrf::field() ?>
- <input type="hidden" name="action" value="save_consent_settings">
- <label><input type="checkbox" name="consent_manager_enabled" <?= $consentEnabled ? 'checked' : '' ?>> Ask visitors for cookie consent (scripts marked below only run after they agree)</label>
- <label><input type="checkbox" name="consent_footer_icon_enabled" <?= $consentFooterIconEnabled ? 'checked' : '' ?>> Show a cookie icon in the footer so visitors can change their mind</label>
- <button type="submit" class="dash-btn dash-btn-primary" style="margin-top:12px;"><?= Icons::icon('check', 'icon icon-sm') ?>Save</button>
- </form>
- </div>
-
- <table class="dash-table">
- <thead><tr><th><?= Icons::icon('heading', 'icon icon-sm') ?>Name</th><th><?= Icons::icon('layout', 'icon icon-sm') ?>Placement</th><th><?= Icons::icon('shield', 'icon icon-sm') ?>Requires consent</th><th><?= Icons::icon('toggle', 'icon icon-sm') ?>Active</th><th></th></tr></thead>
- <tbody>
- <?php foreach ($scripts as $script): ?>
- <tr>
- <td><?= htmlspecialchars($script['name']) ?></td>
- <td><?= htmlspecialchars($script['placement']) ?></td>
- <td><?= $script['requires_consent'] ? 'Yes' : 'No' ?></td>
- <td><?= $script['is_active'] ? 'Yes' : 'No' ?></td>
- <td class="dash-table-actions">
- <a href="analytics.php?edit=<?= (int) $script['id'] ?>" class="dash-btn-small"><?= Icons::icon('edit', 'icon icon-sm') ?>Edit</a>
- <form method="post" style="display:inline;" onsubmit="return confirm('Delete this script? It will stop running on your store.');">
- <?= Csrf::field() ?>
- <input type="hidden" name="action" value="delete_analytics_script">
- <input type="hidden" name="script_id" value="<?= (int) $script['id'] ?>">
- <button type="submit" class="dash-btn-small dash-btn-danger"><?= Icons::icon('trash', 'icon icon-sm') ?>Delete</button>
- </form>
- </td>
- </tr>
- <?php endforeach; ?>
- <?php if (empty($scripts)): ?>
- <tr><td colspan="5">No tracking scripts yet. Add one for Google Analytics, a Meta pixel and so on.</td></tr>
- <?php endif; ?>
- </tbody>
- </table>
-
- <h2 class="dash-subtitle"><?= Icons::icon('plus', 'icon icon-sm') ?><?= $editingScript ? 'Edit script' : 'New script' ?></h2>
- <form method="post">
- <?= Csrf::field() ?>
- <input type="hidden" name="action" value="save_analytics_script">
- <?php if ($editingScript): ?>
- <input type="hidden" name="script_id" value="<?= (int) $editingScript['id'] ?>">
- <?php endif; ?>
-
- <label>Name</label>
- <input type="text" name="name" value="<?= htmlspecialchars($editingScript['name'] ?? '') ?>" required>
-
- <label>Code (paste it exactly as the service gives it to you)</label>
- <textarea name="script_code" rows="8" class="be-code"><?= htmlspecialchars($editingScript['script_code'] ?? '') ?></textarea>
-
- <label>Where to add it</label>
- <select name="placement">
- <option value="head" <?= ($editingScript['placement'] ?? 'head') === 'head' ? 'selected' : '' ?>>Page head (<head>, most common)</option>
- <option value="body_start" <?= ($editingScript['placement'] ?? '') === 'body_start' ? 'selected' : '' ?>>Top of the page (<body> start)</option>
- <option value="body_end" <?= ($editingScript['placement'] ?? '') === 'body_end' ? 'selected' : '' ?>>Bottom of the page (<body> end)</option>
- </select>
-
- <label><input type="checkbox" name="requires_consent" <?= ($editingScript['requires_consent'] ?? 1) ? 'checked' : '' ?>> Only run after the visitor accepts cookies</label>
- <label><input type="checkbox" name="is_active" <?= ($editingScript['is_active'] ?? 1) ? 'checked' : '' ?>> Turned on</label>
-
- <button type="submit" class="dash-btn dash-btn-primary" style="margin-top:16px;"><?= Icons::icon('check', 'icon icon-sm') ?>Save script</button>
- </form>
-
- <?php require __DIR__ . '/includes/dash-footer.php'; ?>
-