v1.0.0.1
StocketBase
- <?php
-
- declare(strict_types=1);
-
- require_once __DIR__ . '/includes/config.php';
- require_once __DIR__ . '/includes/database.php';
- require_once __DIR__ . '/includes/auth.php';
- require_once __DIR__ . '/includes/csrf.php';
- require_once __DIR__ . '/includes/block-editor.php';
- require_once __DIR__ . '/includes/site-front.php';
- require_once __DIR__ . '/includes/activity-log.php';
- require_once __DIR__ . '/includes/indexnow.php';
- require_once __DIR__ . '/includes/avatar.php';
- require_once __DIR__ . '/includes/product-versions.php';
- require_once __DIR__ . '/includes/tags.php';
- require_once __DIR__ . '/includes/login-throttle.php';
- require_once __DIR__ . '/includes/two-factor.php';
-
- Auth::boot();
- Auth::requireLogin();
-
- $currentUser = Auth::user();
- $currentRole = Auth::role();
- SiteFront::settings();
- $view = $_GET['view'] ?? 'overview';
- $allowedViews = ['overview', 'products', 'product-edit', 'categories', 'orders', 'order-detail', 'customers', 'customer-detail', 'discounts', 'reviews', 'pages', 'stats', 'security', 'trash'];
- if (!in_array($view, $allowedViews, true)) {
- $view = 'overview';
- }
-
- $flashMessage = null;
- $flashType = 'success';
-
- if ($_SERVER['REQUEST_METHOD'] === 'POST') {
- if (empty($_POST) && (int) ($_SERVER['CONTENT_LENGTH'] ?? 0) > 0) {
- $flashMessage = 'That file is too big for your server. The limit is ' . ini_get('upload_max_filesize') . ', ask your host if you need more.';
- $flashType = 'error';
- } elseif (!Csrf::verify($_POST['csrf_token'] ?? null)) {
- $flashMessage = 'Your session expired. Please try again.';
- $flashType = 'error';
- } else {
- $action = $_POST['action'] ?? '';
-
- if (in_array($action, ['upload_product_file', 'delete_product_file', 'save_product_file_labels'], true)) {
- [$flashMessage, $flashType, $fileProductId] = require __DIR__ . '/dashboard-actions/product-files.php';
- if ($flashType === 'success' && $fileProductId !== null) {
- header('Location: dashboard.php?view=product-edit&id=' . (int) $fileProductId . '&saved=1#product-files');
- exit;
- }
- }
-
- if ($action === 'save_product') {
- [$flashMessage, $flashType, $redirectId] = require __DIR__ . '/dashboard-actions/save-product.php';
- if ($redirectId !== null) {
- ActivityLog::record('product.save', 'product', (int) $redirectId, trim((string) ($_POST['title'] ?? '')) . ' [' . (string) ($_POST['publish_action'] ?? '') . ']');
- ProductVersions::snapshot((int) $redirectId, (int) $currentUser['id'], (string) $currentUser['display_name']);
-
- if (ProductTags::isEnabled() && isset($_POST['tags'])) {
- $taggedProduct = Database::site()->prepare('SELECT created_by FROM products WHERE id = :id');
- $taggedProduct->execute(['id' => (int) $redirectId]);
- $taggedAuthor = $taggedProduct->fetchColumn();
-
- if ($taggedAuthor !== false && ((int) $taggedAuthor === (int) $currentUser['id'] || Auth::hasRoleAtLeast(Auth::ROLE_STORE_OWNER))) {
- ProductTags::sync((int) $redirectId, ProductTags::parse((string) $_POST['tags']));
- }
- }
-
- IndexNow::notifyProduct((int) $redirectId);
- header('Location: dashboard.php?view=product-edit&id=' . $redirectId . '&saved=1');
- exit;
- }
- }
-
- if ($action === 'restore_version') {
- [$flashMessage, $flashType, $restoredId] = require __DIR__ . '/dashboard-actions/restore-version.php';
- if ($restoredId !== null) {
- IndexNow::notifyProduct((int) $restoredId);
- header('Location: dashboard.php?view=product-edit&id=' . $restoredId . '&saved=1');
- exit;
- }
- }
-
- if (in_array($action, ['restore_product', 'purge_product', 'empty_trash'], true)) {
- $trashedId = require __DIR__ . '/dashboard-actions/trash-product.php';
- if ($action === 'restore_product' && $trashedId > 0) {
- IndexNow::notifyProduct($trashedId);
- }
- header('Location: dashboard.php?view=' . ($action === 'restore_product' && $trashedId > 0 ? 'products' : 'trash') . '&saved=1');
- exit;
- }
-
- if (in_array($action, ['totp_begin', 'totp_cancel', 'totp_confirm', 'totp_disable', 'totp_regenerate'], true)) {
- [$flashMessage, $flashType, $securityDone] = require __DIR__ . '/dashboard-actions/security.php';
- if ($securityDone) {
- header('Location: dashboard.php?view=security');
- exit;
- }
- }
-
- if ($action === 'delete_product') {
- $deletedProduct = Database::site()->prepare('SELECT title, slug, status FROM products WHERE id = :id');
- $deletedProduct->execute(['id' => (int) ($_POST['product_id'] ?? 0)]);
- $deletedProduct = $deletedProduct->fetch() ?: [];
- require __DIR__ . '/dashboard-actions/delete-product.php';
- ActivityLog::record('product.trash', 'product', (int) ($_POST['product_id'] ?? 0), (string) ($deletedProduct['title'] ?? ''));
- if (($deletedProduct['status'] ?? '') === 'published') {
- IndexNow::notifyRemoved((string) $deletedProduct['slug'], (int) ($_POST['product_id'] ?? 0));
- }
- header('Location: dashboard.php?view=products&deleted=1');
- exit;
- }
-
- if ($action === 'moderate_product') {
- require __DIR__ . '/dashboard-actions/moderate-product.php';
- ActivityLog::record('product.moderate', 'product', (int) ($_POST['product_id'] ?? 0), (string) ($_POST['decision'] ?? ''));
- IndexNow::notifyProduct((int) ($_POST['product_id'] ?? 0));
- header('Location: dashboard.php?view=products&moderated=1');
- exit;
- }
-
- if ($action === 'save_category') {
- require __DIR__ . '/dashboard-actions/save-category.php';
- ActivityLog::record('category.save', 'category', (int) ($_POST['category_id'] ?? 0) ?: null, trim((string) ($_POST['name'] ?? '')));
- header('Location: dashboard.php?view=categories&saved=1');
- exit;
- }
-
- if ($action === 'delete_category') {
- require __DIR__ . '/dashboard-actions/delete-category.php';
- ActivityLog::record('category.delete', 'category', (int) ($_POST['category_id'] ?? 0));
- header('Location: dashboard.php?view=categories&deleted=1');
- exit;
- }
-
- if ($action === 'toggle_category_menu') {
- require __DIR__ . '/dashboard-actions/toggle-category-menu.php';
- header('Location: dashboard.php?view=categories');
- exit;
- }
-
- if ($action === 'save_page') {
- require __DIR__ . '/dashboard-actions/save-page.php';
- ActivityLog::record('page.save', 'page', (int) ($_POST['page_id'] ?? 0) ?: null, trim((string) ($_POST['title'] ?? '')));
- header('Location: dashboard.php?view=pages&saved=1');
- exit;
- }
-
- if ($action === 'delete_page') {
- require __DIR__ . '/dashboard-actions/delete-page.php';
- ActivityLog::record('page.delete', 'page', (int) ($_POST['page_id'] ?? 0));
- header('Location: dashboard.php?view=pages&deleted=1');
- exit;
- }
-
- if ($action === 'update_order_status') {
- [$flashMessage, $flashType, $orderId] = require __DIR__ . '/dashboard-actions/save-order-status.php';
- if ($orderId !== null && $flashType === 'success') {
- ActivityLog::record('order.status', 'order', (int) $orderId, (string) ($_POST['status'] ?? ''));
- header('Location: dashboard.php?view=order-detail&id=' . $orderId . '&saved=1');
- exit;
- }
- }
-
- if ($action === 'refund_order') {
- [$flashMessage, $flashType, $orderId] = require __DIR__ . '/dashboard-actions/refund-order.php';
- if ($orderId !== null && $flashType === 'success') {
- ActivityLog::record('order.refund', 'order', (int) $orderId);
- header('Location: dashboard.php?view=order-detail&id=' . $orderId . '&saved=1');
- exit;
- }
- }
-
- if ($action === 'save_discount') {
- [$flashMessage, $flashType, $discountSaved] = require __DIR__ . '/dashboard-actions/save-discount.php';
- if ($discountSaved) {
- ActivityLog::record('discount.save', 'discount', (int) ($_POST['discount_id'] ?? 0) ?: null, trim((string) ($_POST['code'] ?? '')));
- header('Location: dashboard.php?view=discounts&saved=1');
- exit;
- }
- }
-
- if ($action === 'delete_discount') {
- require __DIR__ . '/dashboard-actions/delete-discount.php';
- ActivityLog::record('discount.delete', 'discount', (int) ($_POST['discount_id'] ?? 0));
- header('Location: dashboard.php?view=discounts&deleted=1');
- exit;
- }
-
- if ($action === 'moderate_review') {
- require __DIR__ . '/dashboard-actions/moderate-review.php';
- header('Location: dashboard.php?view=reviews&moderated=1');
- exit;
- }
- }
- }
-
- $dashView = $view;
- $dashPageTitle = 'Dashboard';
- $dashLoadBlockEditor = $view === 'product-edit';
-
- require __DIR__ . '/includes/dash-header.php';
-
- ?>
-
- <?php if ($flashMessage !== null): ?>
- <div class="dash-flash dash-flash-<?= htmlspecialchars($flashType) ?>"><?= Icons::icon($flashType === 'error' ? 'x' : 'check', 'icon icon-sm') ?><?= htmlspecialchars($flashMessage) ?></div>
- <?php endif; ?>
-
- <?php if (isset($_GET['saved'])): ?>
- <div class="dash-flash dash-flash-success"><?= Icons::icon('check', 'icon icon-sm') ?>Changes saved.</div>
- <?php endif; ?>
- <?php if (isset($_GET['deleted'])): ?>
- <div class="dash-flash dash-flash-success"><?= Icons::icon('check', 'icon icon-sm') ?>Deleted.</div>
- <?php endif; ?>
- <?php if (isset($_GET['moderated'])): ?>
- <div class="dash-flash dash-flash-success"><?= Icons::icon('check', 'icon icon-sm') ?>Status updated.</div>
- <?php endif; ?>
-
- <?php
- switch ($view) {
- case 'overview':
- require __DIR__ . '/dashboard-views/overview.php';
- break;
- case 'products':
- require __DIR__ . '/dashboard-views/products.php';
- break;
- case 'product-edit':
- require __DIR__ . '/dashboard-views/product-edit.php';
- break;
- case 'categories':
- require __DIR__ . '/dashboard-views/categories.php';
- break;
- case 'orders':
- require __DIR__ . '/dashboard-views/orders.php';
- break;
- case 'order-detail':
- require __DIR__ . '/dashboard-views/order-detail.php';
- break;
- case 'customers':
- require __DIR__ . '/dashboard-views/customers.php';
- break;
- case 'customer-detail':
- require __DIR__ . '/dashboard-views/customer-detail.php';
- break;
- case 'discounts':
- require __DIR__ . '/dashboard-views/discounts.php';
- break;
- case 'reviews':
- require __DIR__ . '/dashboard-views/reviews.php';
- break;
- case 'pages':
- require __DIR__ . '/dashboard-views/pages.php';
- break;
- case 'stats':
- require __DIR__ . '/dashboard-views/stats.php';
- break;
- case 'security':
- require __DIR__ . '/dashboard-views/security.php';
- break;
- case 'trash':
- require __DIR__ . '/dashboard-views/trash.php';
- break;
- }
- ?>
-
- <?php require __DIR__ . '/includes/dash-footer.php'; ?>
-