WebOrbiton
v1.0.0.1

StocketBase

44 lines · 933 B
  1. <?php
  2. ​
  3. declare(strict_types=1);
  4. ​
  5. if (count(get_included_files()) === 1) {
  6. http_response_code(403);
  7. exit;
  8. }
  9. ​
  10. $productId = (int) ($_POST['product_id'] ?? 0);
  11. ​
  12. if ($productId <= 0) {
  13. exit;
  14. }
  15. ​
  16. $db = Database::site();
  17. $statement = $db->prepare('SELECT * FROM products WHERE id = :id LIMIT 1');
  18. $statement->execute(['id' => $productId]);
  19. $product = $statement->fetch();
  20. ​
  21. if (!$product) {
  22. exit;
  23. }
  24. ​
  25. $isOwner = (int) $product['created_by'] === (int) $currentUser['id'];
  26. $canDeleteAny = Auth::hasRoleAtLeast(Auth::ROLE_STORE_OWNER);
  27. ​
  28. if (!$isOwner && !$canDeleteAny) {
  29. exit;
  30. }
  31. ​
  32. if ($isOwner && !$canDeleteAny && $product['status'] !== 'draft') {
  33. exit;
  34. }
  35. ​
  36. if ($product['deleted_at'] !== null) {
  37. exit;
  38. }
  39. ​
  40. $trash = $db->prepare(
  41. "UPDATE products SET trashed_status = status, status = 'draft', scheduled_at = NULL, deleted_at = NOW() WHERE id = :id AND deleted_at IS NULL"
  42. );
  43. $trash->execute(['id' => $productId]);
  44. ​