v1.0.0.1
StocketBase
- <?php
-
- declare(strict_types=1);
-
- if (count(get_included_files()) === 1) {
- http_response_code(403);
- exit;
- }
-
- require_once __DIR__ . '/../includes/digital-files.php';
-
- $productId = (int) ($_POST['product_id'] ?? 0);
-
- $productStatement = Database::site()->prepare('SELECT id, created_by, title FROM products WHERE id = :id AND deleted_at IS NULL LIMIT 1');
- $productStatement->execute(['id' => $productId]);
- $fileProduct = $productStatement->fetch();
-
- if (!$fileProduct) {
- return ['We couldn\'t find that product.', 'error', null];
- }
-
- $canManageFiles = Auth::role() !== Auth::ROLE_CATALOG_ASSISTANT
- && ((int) $fileProduct['created_by'] === (int) $currentUser['id'] || Auth::hasRoleAtLeast(Auth::ROLE_STORE_OWNER));
-
- if (!$canManageFiles) {
- return ['You don\'t have access to this product\'s files.', 'error', null];
- }
-
- if ($action === 'upload_product_file') {
- [$stored, $message] = DigitalFiles::store($productId, $_FILES['product_file'] ?? null);
- if ($stored) {
- ActivityLog::record('product.file_upload', 'product', $productId, mb_substr((string) ($_FILES['product_file']['name'] ?? ''), 0, 120));
- }
-
- return [$message, $stored ? 'success' : 'error', $productId];
- }
-
- if ($action === 'save_product_file_labels') {
- $labels = is_array($_POST['button_label'] ?? null) ? $_POST['button_label'] : [];
- foreach (DigitalFiles::filesForProduct($productId) as $productFile) {
- $fileKey = (int) $productFile['id'];
- if (array_key_exists($fileKey, $labels)) {
- DigitalFiles::setButtonLabel($fileKey, (string) $labels[$fileKey]);
- }
- }
-
- return ['Button text saved.', 'success', $productId];
- }
-
- if ($action === 'delete_product_file') {
- $fileId = (int) ($_POST['file_id'] ?? 0);
- $file = DigitalFiles::find($fileId);
- if ($file === null || (int) $file['product_id'] !== $productId) {
- return ['We couldn\'t find that file.', 'error', $productId];
- }
-
- DigitalFiles::delete($fileId);
- ActivityLog::record('product.file_delete', 'product', $productId, mb_substr((string) $file['original_name'], 0, 120));
-
- return ['File deleted.', 'success', $productId];
- }
-
- return ['Something went wrong. Please try again.', 'error', $productId];
-