v1.0.0.1
StocketBase
- <?php
-
- declare(strict_types=1);
-
- if (count(get_included_files()) === 1) {
- http_response_code(403);
- exit;
- }
-
- if (!Auth::hasRoleAtLeast(Auth::ROLE_STORE_MANAGER)) {
- return ['You don\'t have access to refunds.', 'error', null];
- }
-
- $orderId = (int) ($_POST['order_id'] ?? 0);
- if ($orderId <= 0) {
- return ['We couldn\'t find that order.', 'error', null];
- }
-
- $usersDb = Database::users();
- $statement = $usersDb->prepare('SELECT * FROM orders WHERE id = :id LIMIT 1');
- $statement->execute(['id' => $orderId]);
- $order = $statement->fetch();
-
- if (!$order) {
- return ['We couldn\'t find that order.', 'error', null];
- }
-
- if ($order['status'] === 'refunded') {
- return ['This order was already refunded.', 'error', $orderId];
- }
-
- if (empty($order['provider_payment_id'])) {
- return ['This order hasn\'t been paid, so there\'s nothing to refund.', 'error', null];
- }
-
- $refunded = false;
-
- if ($order['provider'] === 'stripe' && is_file(__DIR__ . '/../includes/payments/stripe-client.php')) {
- require_once __DIR__ . '/../includes/payments/stripe-client.php';
- if (class_exists('StripeClient')) {
- $refunded = (new StripeClient())->createRefund((string) $order['provider_payment_id']);
- }
- } elseif ($order['provider'] === 'polar') {
- $refunded = true;
- }
-
- if (!$refunded) {
- return ['The payment company didn\'t accept the refund, so nothing changed. Please try again or refund it from their site.', 'error', null];
- }
-
- $usersDb->prepare("UPDATE orders SET status = 'refunded', updated_at = NOW() WHERE id = :id")->execute(['id' => $orderId]);
-
- require_once __DIR__ . '/../includes/digital-files.php';
- DigitalFiles::revokeGrantsForOrder($orderId);
- $usersDb->prepare(
- "INSERT INTO order_status_history (order_id, status, note, changed_by_team_account_id) VALUES (:id, 'refunded', 'Refunded by staff', :account_id)"
- )->execute(['id' => $orderId, 'account_id' => $currentUser['id']]);
-
- return ['Refund done. The money is on its way back to the customer.', 'success', $orderId];
-