WebOrbiton
v1.0.0.1

StocketBase

64 lines · 2.2 KB
  1. <?php
  2. ​
  3. declare(strict_types=1);
  4. ​
  5. if (count(get_included_files()) === 1) {
  6. http_response_code(403);
  7. exit;
  8. }
  9. ​
  10. require_once __DIR__ . '/../includes/digital-files.php';
  11. ​
  12. $productId = (int) ($_POST['product_id'] ?? 0);
  13. ​
  14. $productStatement = Database::site()->prepare('SELECT id, created_by, title FROM products WHERE id = :id AND deleted_at IS NULL LIMIT 1');
  15. $productStatement->execute(['id' => $productId]);
  16. $fileProduct = $productStatement->fetch();
  17. ​
  18. if (!$fileProduct) {
  19. return ['We couldn\'t find that product.', 'error', null];
  20. }
  21. ​
  22. $canManageFiles = Auth::role() !== Auth::ROLE_CATALOG_ASSISTANT
  23. && ((int) $fileProduct['created_by'] === (int) $currentUser['id'] || Auth::hasRoleAtLeast(Auth::ROLE_STORE_OWNER));
  24. ​
  25. if (!$canManageFiles) {
  26. return ['You don\'t have access to this product\'s files.', 'error', null];
  27. }
  28. ​
  29. if ($action === 'upload_product_file') {
  30. [$stored, $message] = DigitalFiles::store($productId, $_FILES['product_file'] ?? null);
  31. if ($stored) {
  32. ActivityLog::record('product.file_upload', 'product', $productId, mb_substr((string) ($_FILES['product_file']['name'] ?? ''), 0, 120));
  33. }
  34. ​
  35. return [$message, $stored ? 'success' : 'error', $productId];
  36. }
  37. ​
  38. if ($action === 'save_product_file_labels') {
  39. $labels = is_array($_POST['button_label'] ?? null) ? $_POST['button_label'] : [];
  40. foreach (DigitalFiles::filesForProduct($productId) as $productFile) {
  41. $fileKey = (int) $productFile['id'];
  42. if (array_key_exists($fileKey, $labels)) {
  43. DigitalFiles::setButtonLabel($fileKey, (string) $labels[$fileKey]);
  44. }
  45. }
  46. ​
  47. return ['Button text saved.', 'success', $productId];
  48. }
  49. ​
  50. if ($action === 'delete_product_file') {
  51. $fileId = (int) ($_POST['file_id'] ?? 0);
  52. $file = DigitalFiles::find($fileId);
  53. if ($file === null || (int) $file['product_id'] !== $productId) {
  54. return ['We couldn\'t find that file.', 'error', $productId];
  55. }
  56. ​
  57. DigitalFiles::delete($fileId);
  58. ActivityLog::record('product.file_delete', 'product', $productId, mb_substr((string) $file['original_name'], 0, 120));
  59. ​
  60. return ['File deleted.', 'success', $productId];
  61. }
  62. ​
  63. return ['Something went wrong. Please try again.', 'error', $productId];
  64. ​