WebOrbiton
v1.0.0.1

StocketBase

60 lines · 2.0 KB
  1. <?php
  2. ​
  3. declare(strict_types=1);
  4. ​
  5. if (count(get_included_files()) === 1) {
  6. http_response_code(403);
  7. exit;
  8. }
  9. ​
  10. if (!Auth::hasRoleAtLeast(Auth::ROLE_STORE_MANAGER)) {
  11. return ['You don\'t have access to refunds.', 'error', null];
  12. }
  13. ​
  14. $orderId = (int) ($_POST['order_id'] ?? 0);
  15. if ($orderId <= 0) {
  16. return ['We couldn\'t find that order.', 'error', null];
  17. }
  18. ​
  19. $usersDb = Database::users();
  20. $statement = $usersDb->prepare('SELECT * FROM orders WHERE id = :id LIMIT 1');
  21. $statement->execute(['id' => $orderId]);
  22. $order = $statement->fetch();
  23. ​
  24. if (!$order) {
  25. return ['We couldn\'t find that order.', 'error', null];
  26. }
  27. ​
  28. if ($order['status'] === 'refunded') {
  29. return ['This order was already refunded.', 'error', $orderId];
  30. }
  31. ​
  32. if (empty($order['provider_payment_id'])) {
  33. return ['This order hasn\'t been paid, so there\'s nothing to refund.', 'error', null];
  34. }
  35. ​
  36. $refunded = false;
  37. ​
  38. if ($order['provider'] === 'stripe' && is_file(__DIR__ . '/../includes/payments/stripe-client.php')) {
  39. require_once __DIR__ . '/../includes/payments/stripe-client.php';
  40. if (class_exists('StripeClient')) {
  41. $refunded = (new StripeClient())->createRefund((string) $order['provider_payment_id']);
  42. }
  43. } elseif ($order['provider'] === 'polar') {
  44. $refunded = true;
  45. }
  46. ​
  47. if (!$refunded) {
  48. return ['The payment company didn\'t accept the refund, so nothing changed. Please try again or refund it from their site.', 'error', null];
  49. }
  50. ​
  51. $usersDb->prepare("UPDATE orders SET status = 'refunded', updated_at = NOW() WHERE id = :id")->execute(['id' => $orderId]);
  52. ​
  53. require_once __DIR__ . '/../includes/digital-files.php';
  54. DigitalFiles::revokeGrantsForOrder($orderId);
  55. $usersDb->prepare(
  56. "INSERT INTO order_status_history (order_id, status, note, changed_by_team_account_id) VALUES (:id, 'refunded', 'Refunded by staff', :account_id)"
  57. )->execute(['id' => $orderId, 'account_id' => $currentUser['id']]);
  58. ​
  59. return ['Refund done. The money is on its way back to the customer.', 'success', $orderId];
  60. ​