v1.0.0.1
StocketBase
- <?php
-
- declare(strict_types=1);
-
- if (count(get_included_files()) === 1) {
- http_response_code(403);
- exit;
- }
-
- require_once __DIR__ . '/../includes/currency.php';
-
- if (!Auth::hasRoleAtLeast(Auth::ROLE_STORE_MANAGER)) {
- return ['You don\'t have access to discounts.', 'error', false];
- }
-
- $db = Database::site();
-
- $discountId = (int) ($_POST['discount_id'] ?? 0) ?: null;
- $code = strtoupper(trim((string) ($_POST['code'] ?? '')));
- $description = trim((string) ($_POST['description'] ?? ''));
- $discountType = ($_POST['discount_type'] ?? 'percentage') === 'fixed_amount' ? 'fixed_amount' : 'percentage';
- $currencyCode = Currency::normalize((string) ($_POST['currency'] ?? SiteFront::settings()['store_currency'] ?? 'USD'));
- $rawValue = (string) ($_POST['value'] ?? '0');
-
- if ($discountType === 'percentage') {
- $value = max(1, min(100, (int) round((float) $rawValue)));
- } else {
- $value = (int) round(((float) $rawValue) * (10 ** Currency::decimals($currencyCode)));
- }
-
- $minOrderRaw = trim((string) ($_POST['min_order'] ?? ''));
- $minOrderCents = $minOrderRaw !== '' ? (int) round(((float) $minOrderRaw) * (10 ** Currency::decimals($currencyCode))) : null;
- $maxRedemptions = (int) ($_POST['max_redemptions'] ?? 0) ?: null;
- $isActive = isset($_POST['is_active']) ? 1 : 0;
-
- if ($code === '') {
- return ['Please type a code for the discount.', 'error', false];
- }
-
- try {
- if ($discountId !== null) {
- $update = $db->prepare(
- 'UPDATE discounts SET code = :code, description = :description, discount_type = :type, value = :value,
- currency = :currency, min_order_cents = :min_order, max_redemptions = :max_redemptions, is_active = :is_active,
- updated_at = NOW() WHERE id = :id'
- );
- $update->execute([
- 'code' => $code,
- 'description' => $description !== '' ? $description : null,
- 'type' => $discountType,
- 'value' => $value,
- 'currency' => $discountType === 'fixed_amount' ? $currencyCode : null,
- 'min_order' => $minOrderCents,
- 'max_redemptions' => $maxRedemptions,
- 'is_active' => $isActive,
- 'id' => $discountId,
- ]);
-
- return ['Discount saved.', 'success', true];
- }
-
- $insert = $db->prepare(
- 'INSERT INTO discounts (code, description, discount_type, value, currency, min_order_cents, max_redemptions, is_active, created_by)
- VALUES (:code, :description, :type, :value, :currency, :min_order, :max_redemptions, :is_active, :created_by)'
- );
- $insert->execute([
- 'code' => $code,
- 'description' => $description !== '' ? $description : null,
- 'type' => $discountType,
- 'value' => $value,
- 'currency' => $discountType === 'fixed_amount' ? $currencyCode : null,
- 'min_order' => $minOrderCents,
- 'max_redemptions' => $maxRedemptions,
- 'is_active' => $isActive,
- 'created_by' => $currentUser['id'],
- ]);
-
- return ['Discount created. Customers can use it now.', 'success', true];
- } catch (PDOException $exception) {
- if ((int) $exception->getCode() === 23000 || str_contains($exception->getMessage(), 'uq_discount_code')) {
- return ['That code is taken. Try a different one.', 'error', false];
- }
-
- error_log('StocketBase: could not save discount: ' . $exception->getMessage());
-
- return ['Something went wrong while saving. Please try again.', 'error', false];
- }
-