v1.0.0.1
StocketBase
- <?php
-
- declare(strict_types=1);
-
- if (count(get_included_files()) === 1) {
- http_response_code(403);
- exit;
- }
-
- if (!Auth::hasRoleAtLeast(Auth::ROLE_STORE_MANAGER)) {
- return ['You don\'t have access to orders.', 'error', null];
- }
-
- $orderId = (int) ($_POST['order_id'] ?? 0);
- $allowedStatuses = ['pending', 'paid', 'processing', 'fulfilled', 'shipped', 'completed', 'canceled', 'refunded', 'failed'];
- $status = in_array($_POST['status'] ?? '', $allowedStatuses, true) ? $_POST['status'] : null;
- $trackingNumber = trim((string) ($_POST['tracking_number'] ?? ''));
- $trackingUrl = trim((string) ($_POST['tracking_url'] ?? ''));
- if ($trackingUrl !== '' && (!preg_match('#^https?://#i', $trackingUrl) || filter_var($trackingUrl, FILTER_VALIDATE_URL) === false)) {
- return ['The tracking link should start with http:// or https://.', 'error', $orderId > 0 ? $orderId : null];
- }
- $trackingNumber = mb_substr($trackingNumber, 0, 120);
- $note = mb_substr($note, 0, 2000);
- $note = trim((string) ($_POST['note'] ?? ''));
-
- if ($orderId <= 0 || $status === null) {
- return ['Something doesn\'t look right with that order. Please try again.', 'error', null];
- }
-
- $usersDb = Database::users();
- $statement = $usersDb->prepare('SELECT * FROM orders WHERE id = :id LIMIT 1');
- $statement->execute(['id' => $orderId]);
- $order = $statement->fetch();
-
- if (!$order) {
- return ['We couldn\'t find that order.', 'error', null];
- }
-
- $fulfilledAt = $order['fulfilled_at'];
- $shippedAt = $order['shipped_at'];
- if ($status === 'fulfilled' && $fulfilledAt === null) {
- $fulfilledAt = date('Y-m-d H:i:s');
- }
- if ($status === 'shipped' && $shippedAt === null) {
- $shippedAt = date('Y-m-d H:i:s');
- }
-
- $update = $usersDb->prepare(
- 'UPDATE orders SET status = :status, tracking_number = :tracking_number, tracking_url = :tracking_url,
- fulfilled_at = :fulfilled_at, shipped_at = :shipped_at, updated_at = NOW() WHERE id = :id'
- );
- $update->execute([
- 'status' => $status,
- 'tracking_number' => $trackingNumber !== '' ? $trackingNumber : null,
- 'tracking_url' => $trackingUrl !== '' ? $trackingUrl : null,
- 'fulfilled_at' => $fulfilledAt,
- 'shipped_at' => $shippedAt,
- 'id' => $orderId,
- ]);
-
- $usersDb->prepare(
- 'INSERT INTO order_status_history (order_id, status, note, changed_by_team_account_id) VALUES (:order_id, :status, :note, :account_id)'
- )->execute([
- 'order_id' => $orderId,
- 'status' => $status,
- 'note' => $note !== '' ? $note : null,
- 'account_id' => $currentUser['id'],
- ]);
-
- $notifyCustomer = isset($_POST['notify_customer']);
- $recipientEmail = null;
- if ($order['user_account_id']) {
- $accountStatement = $usersDb->prepare('SELECT email FROM user_accounts WHERE id = :id LIMIT 1');
- $accountStatement->execute(['id' => $order['user_account_id']]);
- $recipientEmail = $accountStatement->fetchColumn() ?: null;
- } else {
- $recipientEmail = $order['guest_email'] ?: null;
- }
-
- if ($notifyCustomer && $recipientEmail && is_file(__DIR__ . '/../includes/mailer.php') && is_file(__DIR__ . '/../includes/mail-templates.php')) {
- require_once __DIR__ . '/../includes/mailer.php';
- require_once __DIR__ . '/../includes/mail-templates.php';
- if (class_exists('Mailer') && class_exists('MailTemplates')) {
- $updatedOrder = array_merge($order, [
- 'status' => $status,
- 'tracking_number' => $trackingNumber !== '' ? $trackingNumber : null,
- 'tracking_url' => $trackingUrl !== '' ? $trackingUrl : null,
- ]);
- try {
- $email = MailTemplates::orderStatusEmail($updatedOrder, $status);
- Mailer::send($recipientEmail, $email['subject'], $email['html']);
- } catch (Throwable $mailException) {
- error_log('StocketBase: order status email failed — ' . $mailException->getMessage());
- return ['Status saved, but the email to the customer didn\'t go out.', 'error', $orderId];
- }
- }
- }
-
- return ['Status saved.', 'success', $orderId];
-