Compare commits

..

12 Commits

Author SHA1 Message Date
45e92602ed feat(ticketing): add entry reservations management for admin app
- Introduced new routes for entry reservations in admin app, including form, index, store, and download functionalities.
- Created a migration to add the "Reserva de Tickets" menu item to the admin app.
- Updated MenuSeeder to include the new menu item for ticket reservations.
- Developed a PDF view for entry reservations.
- Implemented tests for the EntryReservationController and EntryReservationService to ensure proper functionality and access control.
- Refactored test setup to use a dedicated schema creation trait for better isolation and maintainability.
2026-10-02 12:20:25 -03:00
f10237eb1f feat(ticket): implement DesfileEntryReservationController and related services for ticket reservations 2026-10-02 11:50:47 -03:00
ab5bc43760 feat(ticket): implement EntryReservationService for managing ticket reservations 2026-10-02 11:50:39 -03:00
47b2e8e030 Refactor entry reservation handling by generalizing ticket reservations
- Renamed `desfile_entry_reservations` to `entry_reservations` and `desfile_reservation_batches` to `reservation_batches`.
- Updated models, services, and requests to use the new `EntryReservation` model from the `Ticket` domain instead of the deleted `Desfile` model.
- Introduced a new `EntryReservationPaymentType` enum to manage payment types.
- Modified database migrations to ensure data integrity during the transition.
- Updated tests to reflect changes in the database schema and model relationships.
- Ensured that existing functionality remains intact while improving code organization and clarity.
2026-10-02 11:03:00 -03:00
856b9a6706 refactor: update menu code references from 'onticket.adminapp.tickets' to 'adminapp.tickets' 2026-10-01 10:29:06 -03:00
3ddff7e0ee feat(tests): enhance AdminAppTicketEventScopeTest with soft deletes and active ticket filtering 2026-10-01 09:47:32 -03:00
22de61c8c0 feat(tests): add AdminAppTicketEventScopeTest for event-based ticket management 2026-10-01 09:46:47 -03:00
2d11263adc feat(ticket): add event_id support to ticket service methods; update search, cancel, and refund calculations 2026-10-01 09:46:29 -03:00
c975b5d51d feat(menu): update ticket routes to use new menu code; add tests for menu access and route validation 2026-10-01 09:41:26 -03:00
c7afb70196 feat(staff): implement event scope for staff management; update controllers, services, and resources to handle event_id; add tests for event-based access 2026-10-01 09:25:25 -03:00
31955f862d feat(sale): implement event scope for sales, totals, and modifications; add tests for event-based access 2026-10-01 09:20:43 -03:00
bb4495c6cc feat(users): add event_id to users table and update related resources 2026-10-01 08:56:35 -03:00
108 changed files with 3321 additions and 1559 deletions

View File

@@ -8,6 +8,7 @@ use App\Domains\Commerce\Catalog\Enums\InventorySubject;
use App\Domains\Commerce\Catalog\Services\CatalogInventoryService;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Ticketing\Ticket\Models\EntryReservation;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Shared\Attachable\Models\Attachment;
use Illuminate\Database\Eloquent\Attributes\Fillable;
@@ -147,6 +148,12 @@ class CatalogItem extends Model
return $this->hasMany(Ticket::class, 'source_catalog_item_id');
}
/** @return HasMany<EntryReservation, $this> */
public function entryReservations(): HasMany
{
return $this->hasMany(EntryReservation::class);
}
/** @return BelongsToMany<Attribute, $this> */
public function attributes(): BelongsToMany
{
@@ -266,13 +273,13 @@ class CatalogItem extends Model
{
$this->variants
->filter(fn (Variant $variant): bool => $variant->exists)
->loadMissing('desfileEntryReservations');
->loadMissing('entryReservations');
return $this->variants
->each(fn (Variant $variant) => $variant->setRelation('catalogItem', $this))
->filter(fn (Variant $variant): bool => $variant->hasOnlyActiveEventDates()
&& (! $variant->relationLoaded('desfileEntryReservations')
|| $variant->desfileEntryReservations->isEmpty())
&& (! $variant->relationLoaded('entryReservations')
|| $variant->entryReservations->isEmpty())
&& (($includedVariantId !== null && $variant->id === $includedVariantId)
|| ($variant->isSellable() && (
$this->inventory_policy === InventoryPolicy::Unlimited

View File

@@ -2,8 +2,8 @@
namespace App\Domains\Commerce\Catalog\Models;
use App\Domains\Ticketing\Desfile\Models\EntryReservation;
use App\Domains\Ticketing\Event\Models\EventDate;
use App\Domains\Ticketing\Ticket\Models\EntryReservation;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Shared\Attachable\Models\Attachment;
use Illuminate\Database\Eloquent\Attributes\Fillable;
@@ -76,7 +76,7 @@ class Variant extends Model
}
/** @return HasMany<EntryReservation, $this> */
public function desfileEntryReservations(): HasMany
public function entryReservations(): HasMany
{
return $this->hasMany(EntryReservation::class);
}

View File

@@ -7,8 +7,8 @@ use App\Domains\Commerce\Catalog\Models\Inventory;
use App\Domains\Commerce\Catalog\Models\StockReservation;
use App\Domains\Commerce\Catalog\Models\StockReservationLine;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Ticketing\Desfile\Models\EntryReservation;
use App\Domains\Ticketing\Event\Models\EventDate;
use App\Domains\Ticketing\Ticket\Models\EntryReservation;
use Illuminate\Support\Collection;
class VariantReplacementService

View File

@@ -34,8 +34,3 @@ Bajo `/v1/adminapp/tenant/featured-groups`, con `auth:sanctum` y `adminapp.tenan
## Dependencias y reglas
Usa `Attachable` para imágenes/archivos, `Tenant` para aislamiento y `Ticket`/`Event` para vigencia y fechas. `Cart` y `Purchase` consumen sus precios, variantes e inventario. Los cambios de stock deben pasar por `CatalogInventoryService` para conservar reservas y disponibilidad.
## Menús deprecados
Los menús `adminapp.combos` y `adminapp.categories` están retirados; las
categorías del catálogo y sus datos comerciales no se eliminan.

View File

@@ -13,8 +13,9 @@ class PurchaseRefundSummaryService
$total = TicketRefund::query()
->whereHas(
'purchaseItem.purchase',
fn (Builder $query): Builder => $query->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $purchase) => $purchase->where('event_id', $eventId))
fn (Builder $query): Builder => $query
->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $query): Builder => $query->where('event_id', $eventId))
)
->sum('amount');

View File

@@ -25,9 +25,8 @@ class TenantTransactionResetService
'carts' => $scope['cart_ids']->count(),
'cart_items' => $scope['cart_item_ids']->count(),
'tickets' => DB::table('tickets')->where('tenant_code', $tenantCode)->count(),
'entry_reservations' => DB::table('desfile_entry_reservations')
->whereIn('variant_id', DB::table('variantes')->whereIn('catalog_item_id',
DB::table('catalog_items')->where('tenant_code', $tenantCode)->select('id'))->select('id'))->count(),
'entry_reservations' => DB::table('entry_reservations')
->whereIn('catalog_item_id', DB::table('catalog_items')->where('tenant_code', $tenantCode)->select('id'))->count(),
'stock_reservations' => $this->reservationQuery($scope)->count(),
'purchase_changes' => DB::table('value_changes')
->where('tenant_code', $tenantCode)
@@ -50,10 +49,9 @@ class TenantTransactionResetService
$telepagosQr = DB::table('telepagos_qr')->whereIn('compra_id', $scope['purchase_ids'])->count();
$summary = [
'stock_reservations_deleted' => $this->reservationQuery($scope)->delete(),
'entry_reservations_deleted' => DB::table('desfile_entry_reservations')
->whereIn('variant_id', DB::table('variantes')->whereIn('catalog_item_id',
DB::table('catalog_items')->where('tenant_code', $tenantCode)->select('id'))->select('id'))->delete(),
'entry_reservation_batches_deleted' => DB::table('desfile_reservation_batches')->where('tenant_code', $tenantCode)->delete(),
'entry_reservations_deleted' => DB::table('entry_reservations')
->whereIn('catalog_item_id', DB::table('catalog_items')->where('tenant_code', $tenantCode)->select('id'))->delete(),
'entry_reservation_batches_deleted' => DB::table('reservation_batches')->where('tenant_code', $tenantCode)->delete(),
'tickets_deleted' => DB::table('tickets')->where('tenant_code', $tenantCode)->delete(),
'purchase_changes_deleted' => DB::table('value_changes')
->where('tenant_code', $tenantCode)

View File

@@ -13,7 +13,6 @@ use App\Domains\Commerce\Sale\Resources\AdminApp\SaleTicketResource;
use App\Domains\Commerce\Sale\Services\AdminAppSaleExcelService;
use App\Domains\Commerce\Sale\Services\AdminAppSalePdfService;
use App\Domains\Commerce\Sale\Services\AdminAppSaleService;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Http\Controllers\Controller;
use Illuminate\Http\Request;
use Illuminate\Http\Resources\Json\AnonymousResourceCollection;
@@ -28,20 +27,15 @@ class SaleController extends Controller
protected AdminAppSaleExcelService $saleExcelService,
) {}
private function eventId(Request $request): ?int
{
return app(EventScopeService::class)->eventId($request->user());
}
public function index(AdminAppSaleIndexRequest $request): AnonymousResourceCollection
{
$tenant = $request->user()->tenant()->firstOrFail();
return SaleResource::collection(
$this->saleService->sales($tenant, $request->validated(), $this->eventId($request))
$this->saleService->sales($tenant, $request->validated(), $request->user()->event_id)
)->additional([
'confirmed_sales_total' => $this->saleService->confirmedSalesTotal($tenant, $this->eventId($request)),
'refunded_total' => $this->saleService->refundedTotal($tenant, $this->eventId($request)),
'confirmed_sales_total' => $this->saleService->confirmedSalesTotal($tenant, $request->user()->event_id),
'refunded_total' => $this->saleService->refundedTotal($tenant, $request->user()->event_id),
]);
}
@@ -49,7 +43,7 @@ class SaleController extends Controller
{
$tenant = $request->user()->tenant()->firstOrFail();
return new SaleDetailResource($this->saleService->detail($tenant, $sale, $this->eventId($request)));
return new SaleDetailResource($this->saleService->detail($tenant, $sale, $request->user()->event_id));
}
public function tickets(Request $request, int $sale): AnonymousResourceCollection
@@ -57,7 +51,7 @@ class SaleController extends Controller
$tenant = $request->user()->tenant()->firstOrFail();
return SaleTicketResource::collection(
$this->saleService->tickets($tenant, $sale, $this->eventId($request))
$this->saleService->tickets($tenant, $sale, $request->user()->event_id)
);
}
@@ -65,14 +59,14 @@ class SaleController extends Controller
{
$tenant = $request->user()->tenant()->firstOrFail();
return new SaleResource($this->saleService->confirm($tenant, $sale, $this->eventId($request)));
return new SaleResource($this->saleService->confirm($tenant, $sale, $request->user()->event_id));
}
public function cancel(Request $request, int $sale): SaleResource
{
$tenant = $request->user()->tenant()->firstOrFail();
return new SaleResource($this->saleService->cancel($tenant, $sale, $this->eventId($request)));
return new SaleResource($this->saleService->cancel($tenant, $sale, $request->user()->event_id));
}
public function modifications(
@@ -82,7 +76,7 @@ class SaleController extends Controller
$this->saleService->modifications(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
$this->eventId($request),
$request->user()->event_id,
)
);
}
@@ -93,7 +87,7 @@ class SaleController extends Controller
return $this->salePdfService->downloadSales(
$tenant,
$this->saleService->salesForExport($tenant, $request->validated(), $this->eventId($request)),
$this->saleService->salesForExport($tenant, $request->validated(), $request->user()->event_id),
$request->validated('timezone'),
);
}
@@ -104,7 +98,7 @@ class SaleController extends Controller
return $this->salePdfService->downloadModifications(
$tenant,
$this->saleService->modificationsForExport($tenant, $request->validated(), $this->eventId($request)),
$this->saleService->modificationsForExport($tenant, $request->validated(), $request->user()->event_id),
$request->validated('timezone'),
);
}
@@ -115,7 +109,7 @@ class SaleController extends Controller
return $this->saleExcelService->downloadSales(
$tenant,
$this->saleService->salesForExport($tenant, $request->validated(), $this->eventId($request)),
$this->saleService->salesForExport($tenant, $request->validated(), $request->user()->event_id),
$request->validated('timezone'),
);
}
@@ -127,7 +121,7 @@ class SaleController extends Controller
return $this->saleExcelService->downloadModifications(
$tenant,
$this->saleService->modificationsForExport($tenant, $request->validated(), $this->eventId($request)),
$this->saleService->modificationsForExport($tenant, $request->validated(), $request->user()->event_id),
$request->validated('timezone'),
);
}

View File

@@ -23,9 +23,7 @@ class AdminAppSaleService
public function confirmedSalesTotal(Tenant $tenant, ?int $eventId = null): string
{
$total = Purchase::query()
->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId))
$total = $this->purchasesQuery($tenant, $eventId)
->where('status', Purchase::STATUS_PAID)
->sum('total');
@@ -57,9 +55,7 @@ class AdminAppSaleService
public function detail(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
{
return Purchase::query()
->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId))
return $this->purchasesQuery($tenant, $eventId)
->with('items')
->findOrFail($saleId);
}
@@ -139,9 +135,7 @@ class AdminAppSaleService
? $requestedDirection
: 'desc';
return Purchase::query()
->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId))
return $this->purchasesQuery($tenant, $eventId)
->when($filters['q'] ?? null, function (Builder $query, string $search): void {
$term = trim($search);
@@ -184,9 +178,13 @@ class AdminAppSaleService
return ValueChange::query()
->where('tenant_code', $tenant->codigo)
->where('trackable_type', (new Purchase)->getMorphClass())
->when($eventId !== null, fn (Builder $query) => $query->whereHasMorph(
'trackable', [Purchase::class],
fn (Builder $sales) => $sales->where('event_id', $eventId)))
->when($eventId !== null, fn (Builder $query): Builder => $query->whereHasMorph(
'trackable',
[Purchase::class],
fn (Builder $sales): Builder => $sales
->where('tenant_codigo', $tenant->codigo)
->where('event_id', $eventId),
))
->when($filters['q'] ?? null, function (Builder $query, string $search): void {
$term = trim($search);
@@ -228,11 +226,17 @@ class AdminAppSaleService
}
protected function findForTenant(Tenant $tenant, int $saleId, ?int $eventId = null): Purchase
{
return $this->purchasesQuery($tenant, $eventId)
->findOrFail($saleId);
}
/** @return Builder<Purchase> */
protected function purchasesQuery(Tenant $tenant, ?int $eventId): Builder
{
return Purchase::query()
->where('tenant_codigo', $tenant->codigo)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId))
->findOrFail($saleId);
->when($eventId !== null, fn (Builder $query): Builder => $query->where('event_id', $eventId));
}
protected function saleForResponse(Purchase $sale): Purchase

View File

@@ -29,11 +29,8 @@ Consume compras de `Purchase`, datos del tenant y entradas de `Logging`. No es d
La consulta paginada y la colección de exportación deben aplicar los mismos filtros para evitar diferencias entre pantalla, PDF y Excel.
Cuando el usuario autenticado tiene `event_id`, el controlador lo pasa al servicio como alcance obligatorio para ventas, totales, historial y exportaciones. El alcance se combina con el tenant y no se obtiene de los filtros enviados por el cliente. Los administradores sin `event_id` conservan el alcance del tenant.
El detalle, los tickets de una venta, la confirmación y la cancelación buscan la compra dentro del mismo alcance. Una venta de otro evento o sin evento devuelve 404 para un administrador con `event_id`, antes de ejecutar cualquier acción en `CheckoutService`.
El historial comparte con ventas los filtros de búsqueda, ID, fecha de venta y estado. En el historial, el estado se evalúa sobre `ValueChange.new_value`: representa el resultado de esa modificación y no el estado actual de la venta.
## Alcance por evento
Las rutas usan `adminapp.tenant:event`. Para admins de evento, listados, totales,
detalles, tickets de compras, confirmación, cancelación, historial y exportaciones
se filtran por `user.event_id` además del tenant. Las compras pertenecen a un
único evento. Un admin de tenant conserva acceso a sus compras de todos los eventos.

View File

@@ -4,7 +4,7 @@ use App\Domains\Commerce\Sale\Controllers\AdminApp\SaleController;
use Illuminate\Support\Facades\Route;
Route::prefix('v1/adminapp/tenant')
->middleware(['auth:sanctum', 'adminapp.tenant:event'])
->middleware(['auth:sanctum', 'adminapp.tenant'])
->group(function (): void {
Route::get('sales', [SaleController::class, 'index']);
Route::get('sales/pdf', [SaleController::class, 'downloadPdf']);

View File

@@ -20,6 +20,7 @@ class AdminAppAdministratorController extends Controller
return AdministratorResource::collection($this->administratorService->list(
$request->user()->tenant()->firstOrFail(),
$request->string('search')->trim()->toString() ?: null,
$request->user()->event_id,
));
}
@@ -28,6 +29,7 @@ class AdminAppAdministratorController extends Controller
return AdministratorResource::make($this->administratorService->create(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
$request->user()->event_id,
));
}
@@ -37,6 +39,7 @@ class AdminAppAdministratorController extends Controller
$request->user()->tenant()->firstOrFail(),
$administrator,
$request->validated(),
$request->user()->event_id,
));
}

View File

@@ -18,6 +18,7 @@ class AdministratorResource extends JsonResource
'dni' => $this->dni,
'email' => $this->email,
'rol_codigo' => $this->rol_codigo,
'event_id' => $this->event_id,
'role' => $this->whenLoaded('role', fn () => [
'codigo' => $this->role?->codigo,
'nombre' => $this->role?->nombre,

View File

@@ -19,9 +19,9 @@ class AdministratorService
public function __construct(private readonly ResetPasswordAttemptService $resetPasswordAttemptService) {}
/** @return Collection<int, User> */
public function list(Tenant $tenant, ?string $search = null): Collection
public function list(Tenant $tenant, ?string $search = null, ?int $eventId = null): Collection
{
return $this->query($tenant)->with('role')
return $this->query($tenant, $eventId)->with('role')
->when($search, fn (Builder $query, string $search) => $query->where(function (Builder $query) use ($search): void {
$query->where('nombre_apellido', 'like', "%{$search}%")
->orWhere('dni', 'like', "%{$search}%")
@@ -31,14 +31,15 @@ class AdministratorService
}
/** @param array<string, mixed> $data */
public function create(Tenant $tenant, array $data): User
public function create(Tenant $tenant, array $data, ?int $eventId = null): User
{
return DB::transaction(function () use ($tenant, $data): User {
return DB::transaction(function () use ($tenant, $data, $eventId): User {
$administrator = User::query()->create([
...$this->attributes($data),
'password' => Str::random(64),
'rol_codigo' => RoleCode::AdminApp->value,
'tenant_codigo' => $tenant->codigo,
'event_id' => $eventId,
]);
$this->resetPasswordAttemptService->createForAdminAppEmail(
$administrator->email,
@@ -50,10 +51,10 @@ class AdministratorService
}
/** @param array<string, mixed> $data */
public function update(Tenant $tenant, int $administratorId, array $data): User
public function update(Tenant $tenant, int $administratorId, array $data, ?int $eventId = null): User
{
return DB::transaction(function () use ($tenant, $administratorId, $data): User {
$administrator = $this->query($tenant)->lockForUpdate()->findOrFail($administratorId);
return DB::transaction(function () use ($tenant, $administratorId, $data, $eventId): User {
$administrator = $this->query($tenant, $eventId)->lockForUpdate()->findOrFail($administratorId);
$administrator->update($this->attributes($data));
return $administrator->load('role');
@@ -66,11 +67,11 @@ class AdministratorService
// Serialize deletions for this tenant, including requests already authenticated
// when another administrator removes their account.
Tenant::query()->whereKey($tenant->getKey())->lockForUpdate()->firstOrFail();
$administrator = $this->query($tenant)->lockForUpdate()->findOrFail($administratorId);
$administrator = $this->query($tenant, $actor->event_id)->lockForUpdate()->findOrFail($administratorId);
if ($administrator->is($actor)) {
throw ValidationException::withMessages(['administrator' => 'No podés eliminar tu propio usuario.']);
}
$activeAdministrators = $this->query($tenant)->lockForUpdate()->get();
$activeAdministrators = $this->query($tenant, $actor->event_id)->lockForUpdate()->get();
if ($activeAdministrators->count() <= 1) {
throw ValidationException::withMessages(['administrator' => 'El tenant debe conservar al menos un administrador.']);
}
@@ -80,10 +81,11 @@ class AdministratorService
});
}
private function query(Tenant $tenant): Builder
private function query(Tenant $tenant, ?int $eventId = null): Builder
{
return User::query()->where('tenant_codigo', $tenant->codigo)
->where('rol_codigo', RoleCode::AdminApp->value);
->where('rol_codigo', RoleCode::AdminApp->value)
->when($eventId !== null, fn (Builder $query): Builder => $query->where('event_id', $eventId));
}
/** @param array<string, mixed> $data

View File

@@ -55,6 +55,8 @@ No agrega tablas ni migraciones. No modifica el CRUD de escáneres ni el fronten
## Verificación
Cuando el actor tiene `event_id`, los nuevos administradores heredan su evento y el listado, la búsqueda, la edición y la baja se limitan a ese evento dentro del tenant. La comprobación de administradores activos también usa ese alcance. El evento se toma del usuario autenticado, no del cuerpo de la solicitud; sin `event_id` se conserva el comportamiento por tenant.
`php artisan test tests/Feature/Administrator/AdministratorControllerTest.php`
Las pruebas cubren CRUD, normalización y unicidad del email, establecimiento de

View File

@@ -1,9 +0,0 @@
<?php
namespace App\Domains\Core\Auth\Enums;
enum AdminScope: string
{
case Tenant = 'tenant';
case Event = 'event';
}

View File

@@ -3,7 +3,6 @@
namespace App\Domains\Core\Auth\Models;
use App\Domains\Commerce\Catalog\Models\Category;
use App\Domains\Core\Auth\Enums\AdminScope;
use App\Domains\Core\Authorization\Enums\RoleCode;
use App\Domains\Core\Authorization\Models\Role;
use App\Domains\Core\Tenant\Models\Tenant;
@@ -22,7 +21,7 @@ use Illuminate\Foundation\Auth\User as Authenticatable;
use Illuminate\Notifications\Notifiable;
use Laravel\Sanctum\HasApiTokens;
#[Fillable(['nombre_apellido', 'email', 'password', 'dni', 'telefono', 'google_id', 'rol_codigo', 'tenant_codigo', 'admin_scope', 'event_id'])]
#[Fillable(['nombre_apellido', 'email', 'password', 'dni', 'telefono', 'google_id', 'rol_codigo', 'tenant_codigo', 'event_id'])]
#[Hidden(['password', 'remember_token', 'active_email', 'active_google_id'])]
class User extends Authenticatable
{
@@ -31,7 +30,6 @@ class User extends Authenticatable
protected $attributes = [
'rol_codigo' => RoleCode::User->value,
'admin_scope' => AdminScope::Tenant->value,
];
protected static function newFactory(): UserFactory
@@ -95,13 +93,6 @@ class User extends Authenticatable
return $this->belongsTo(Event::class);
}
public function isTenantAdministrator(): bool
{
return $this->rol_codigo === RoleCode::AdminApp->value
&& $this->admin_scope === AdminScope::Tenant->value
&& $this->event_id === null;
}
/** @return BelongsToMany<Category, $this> */
public function scanCategories(): BelongsToMany
{

View File

@@ -20,11 +20,6 @@ class AdminAppMeResource extends JsonResource
return [
'user' => UserResource::make($this->resource),
'tenant' => TenantResource::make($this->tenant),
'event' => $this->whenLoaded('event', fn () => $this->event === null ? null : [
'id' => $this->event->id,
'title' => $this->event->title,
'tenant_code' => $this->event->tenant_code,
]),
];
}
}

View File

@@ -16,9 +16,6 @@ class ScannerMeResource extends JsonResource
return [
'user' => UserResource::make($this->resource),
'tenant' => TenantResource::make($this->tenant),
'event' => $this->whenLoaded('event', fn () => $this->event === null ? null : [
'id' => $this->event->id, 'title' => $this->event->title,
]),
];
}
}

View File

@@ -3,7 +3,6 @@
namespace App\Domains\Core\Auth\Resources;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Authorization\Enums\RoleCode;
use Illuminate\Http\Request;
use Illuminate\Http\Resources\Json\JsonResource;
@@ -25,8 +24,7 @@ class UserResource extends JsonResource
'telefono' => $this->telefono,
'rol_codigo' => $this->rol_codigo,
'tenant_codigo' => $this->tenant_codigo,
'admin_scope' => $this->when($this->rol_codigo === RoleCode::AdminApp->value, $this->admin_scope),
'event_id' => $this->when(in_array($this->rol_codigo, [RoleCode::AdminApp->value, RoleCode::Scanner->value], true), $this->event_id),
'event_id' => $this->event_id,
'categories' => $this->whenLoaded('scanCategories', fn () => $this->scanCategories
->map(fn ($category) => [
'id' => $category->id,

View File

@@ -1,27 +0,0 @@
<?php
namespace App\Domains\Core\Auth\Services;
use App\Domains\Core\Auth\Enums\AdminScope;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Authorization\Enums\RoleCode;
class AdminAppAccessService
{
public function hasValidScope(User $user): bool
{
if ($user->rol_codigo !== RoleCode::AdminApp->value
|| ! $user->tenant_codigo
|| ! $user->tenant()->exists()) {
return false;
}
if ($user->isTenantAdministrator()) {
return true;
}
return $user->admin_scope === AdminScope::Event->value
&& $user->event_id !== null
&& $user->event()->where('tenant_code', $user->tenant_codigo)->exists();
}
}

View File

@@ -20,7 +20,6 @@ class AdminAppContextService
->firstOrFail();
$user->setRelation('tenant', $tenant);
$user->load('event');
return $user;
}

View File

@@ -1,24 +0,0 @@
<?php
namespace App\Domains\Core\Auth\Services;
use App\Domains\Core\Auth\Enums\AdminScope;
use App\Domains\Core\Auth\Models\User;
use Illuminate\Auth\Access\AuthorizationException;
class EventScopeService
{
public function eventId(User $user): ?int
{
if ($user->admin_scope === AdminScope::Event->value || $user->event_id !== null) {
if ($user->event_id === null
|| ! $user->event()->where('tenant_code', $user->tenant_codigo)->exists()) {
throw new AuthorizationException;
}
return $user->event_id;
}
return null;
}
}

View File

@@ -10,7 +10,6 @@ use App\Domains\Core\Authorization\Enums\PermissionCode;
use App\Domains\Core\Authorization\Enums\RoleCode;
use App\Shared\Notification\Events\PasswordResetRequested;
use Carbon\CarbonImmutable;
use Illuminate\Auth\Access\AuthorizationException;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Facades\Log;
@@ -20,7 +19,6 @@ class PasswordLoginService
{
public function __construct(
private readonly ResetPasswordAttemptService $resetPasswordAttemptService,
private readonly AdminAppAccessService $adminAppAccessService,
) {}
/**
@@ -198,26 +196,6 @@ class PasswordLoginService
];
}
if ($requiredRole === RoleCode::AdminApp && ! $this->adminAppAccessService->hasValidScope($user)) {
$this->recordAttempt(
$user, $normalizedEmail, $attemptTenantCode,
LoginAttempt::OUTCOME_INVALID_CREDENTIALS, $ipAddress, $userAgent,
);
return ['outcome' => LoginAttempt::OUTCOME_INVALID_CREDENTIALS, 'user' => $user, 'locked_until' => null];
}
if ($requiredRole === RoleCode::Scanner) {
try {
app(EventScopeService::class)->eventId($user);
} catch (AuthorizationException) {
$this->recordAttempt($user, $normalizedEmail, $attemptTenantCode,
LoginAttempt::OUTCOME_INVALID_CREDENTIALS, $ipAddress, $userAgent);
return ['outcome' => LoginAttempt::OUTCOME_INVALID_CREDENTIALS, 'user' => $user, 'locked_until' => null];
}
}
$user->forceFill([
'failed_login_attempts' => 0,
'last_failed_login_at' => null,

View File

@@ -18,7 +18,6 @@ class ScannerContextService
->firstOrFail();
$user->setRelation('tenant', $tenant);
$user->load('event');
if ($tenant->requiresScannerCategoryValidation()) {
$categories = $user->scanCategories()

View File

@@ -17,6 +17,6 @@ Route::prefix('v1/adminapp')->group(function (): void {
Route::post('password/reset', ResetPasswordController::class)
->defaults('reset_role', 'adminapp')
->middleware('throttle:5,1');
Route::middleware(['auth:sanctum', 'adminapp.tenant:context'])
Route::middleware(['auth:sanctum', 'adminapp.tenant'])
->get('me', AdminAppMeController::class);
});

View File

@@ -2,7 +2,6 @@
namespace App\Domains\Core\Staff\Controllers;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Core\Staff\Requests\StoreStaffRequest;
use App\Domains\Core\Staff\Requests\UpdateStaffRequest;
use App\Domains\Core\Staff\Resources\StaffResource;
@@ -22,17 +21,12 @@ class AdminAppStaffController extends Controller
private readonly ScannerTicketService $scannerTicketService,
) {}
private function eventId(Request $request): ?int
{
return app(EventScopeService::class)->eventId($request->user());
}
public function index(Request $request): AnonymousResourceCollection
{
return StaffResource::collection($this->staffService->list(
$request->user()->tenant()->firstOrFail(),
$request->string('search')->trim()->toString() ?: null,
$this->eventId($request),
$request->user()->event_id,
));
}
@@ -41,7 +35,7 @@ class AdminAppStaffController extends Controller
return StaffResource::make($this->staffService->create(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
$this->eventId($request),
$request->user()->event_id,
));
}
@@ -51,13 +45,13 @@ class AdminAppStaffController extends Controller
$request->user()->tenant()->firstOrFail(),
$staff,
$request->validated(),
$this->eventId($request),
$request->user()->event_id,
));
}
public function destroy(Request $request, int $staff): Response
{
$this->staffService->delete($request->user()->tenant()->firstOrFail(), $staff, $this->eventId($request));
$this->staffService->delete($request->user()->tenant()->firstOrFail(), $staff, $request->user()->event_id);
return response()->noContent();
}
@@ -69,7 +63,7 @@ class AdminAppStaffController extends Controller
$scanner = $this->staffService->find(
$request->user()->tenant()->firstOrFail(),
$staff,
$this->eventId($request),
$request->user()->event_id,
);
return ScanAttemptResource::collection(

View File

@@ -14,11 +14,11 @@ class StaffResource extends JsonResource
{
return [
'id' => $this->id,
'event_id' => $this->event_id,
'nombre_apellido' => $this->nombre_apellido,
'dni' => $this->dni,
'email' => $this->email,
'rol_codigo' => $this->rol_codigo,
'event_id' => $this->event_id,
'role' => $this->whenLoaded('role', fn () => [
'codigo' => $this->role?->codigo,
'nombre' => $this->role?->nombre,

View File

@@ -8,7 +8,6 @@ use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\ResetPasswordAttemptService;
use App\Domains\Core\Authorization\Enums\RoleCode;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Database\Eloquent\Collection;
use Illuminate\Support\Arr;
@@ -39,7 +38,7 @@ class StaffService
}
/** @return Collection<int, Category> */
private function assignableCategories(Tenant $tenant, ?int $eventId = null): Collection
private function assignableCategories(Tenant $tenant): Collection
{
return Category::query()
->whereNull('categoria_id')
@@ -48,8 +47,6 @@ class StaffService
->orWhereHas('catalogItems', fn (Builder $items) => $items
->where('tenant_code', $tenant->codigo));
})
->when($eventId !== null, fn (Builder $query) => $query->whereHas(
'catalogItems', fn (Builder $items) => $items->where('tenant_code', $tenant->codigo)->where('event_id', $eventId)))
->orderBy('nombre')
->get();
}
@@ -57,11 +54,8 @@ class StaffService
/** @param array<string, mixed> $data */
public function create(Tenant $tenant, array $data, ?int $eventId = null): User
{
$eventId ??= $tenant->active_event_id;
Event::query()
->where('tenant_code', $tenant->codigo)->findOrFail($eventId);
$categoryIds = $this->categoryIdsFor($tenant, $data);
$this->assertCategoriesBelongToTenant($tenant, $categoryIds, $eventId);
$this->assertCategoriesBelongToTenant($tenant, $categoryIds);
return DB::transaction(function () use ($tenant, $data, $categoryIds, $eventId): User {
$staff = User::query()->create([
@@ -71,7 +65,6 @@ class StaffService
'rol_codigo' => RoleCode::Scanner->value,
'tenant_codigo' => $tenant->codigo,
'event_id' => $eventId,
'admin_scope' => $eventId === null ? 'tenant' : 'event',
]);
$staff->scanCategories()->sync($categoryIds);
$this->resetPasswordAttemptService->createForScannerEmail(
@@ -88,7 +81,7 @@ class StaffService
{
$staff = $this->find($tenant, $staffId, $eventId);
$categoryIds = $this->categoryIdsFor($tenant, $data);
$this->assertCategoriesBelongToTenant($tenant, $categoryIds, $eventId);
$this->assertCategoriesBelongToTenant($tenant, $categoryIds);
return DB::transaction(function () use ($staff, $data, $categoryIds): User {
$attributes = Arr::only($data, ['nombre_apellido', 'dni', 'email']);
@@ -120,14 +113,14 @@ class StaffService
return User::query()
->where('tenant_codigo', $tenant->codigo)
->where('rol_codigo', RoleCode::Scanner->value)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId));
->when($eventId !== null, fn (Builder $query): Builder => $query->where('event_id', $eventId));
}
/**
* @param array<string, mixed> $data
* @return array<int, int>
*/
private function categoryIdsFor(Tenant $tenant, array $data, ?int $eventId = null): array
private function categoryIdsFor(Tenant $tenant, array $data): array
{
if (! $tenant->requiresScannerCategoryValidation()) {
return [];
@@ -137,9 +130,9 @@ class StaffService
}
/** @param array<int, int> $categoryIds */
private function assertCategoriesBelongToTenant(Tenant $tenant, array $categoryIds, ?int $eventId = null): void
private function assertCategoriesBelongToTenant(Tenant $tenant, array $categoryIds): void
{
$validIds = $this->assignableCategories($tenant, $eventId)
$validIds = $this->assignableCategories($tenant)
->whereIn('id', $categoryIds)
->pluck('id');

View File

@@ -19,12 +19,4 @@ Recurso REST `/v1/adminapp/tenant/staff`, excepto detalle individual, protegido
Usa `Auth/User` como entidad de personal, `Authorization` para su rol, `Catalog/Category` para asignaciones y `Tenant` para aislamiento. Toda búsqueda, edición o borrado debe comprobar que el usuario pertenece al tenant autenticado.
## Alcance por evento
Los endpoints de Staff y su formulario aceptan `adminapp.tenant:event`. Un admin
de evento lista, edita, elimina y consulta el historial solo de scanners de su
evento. El backend asigna el evento al crear un scanner y no acepta cambios de
asignación desde el formulario. Las categorías autorizables se limitan a las
usadas por productos del evento. Los scanners aplican además su evento en
lectura de tickets, escaneo e historial. Los intentos registran `event_id` para
conservar el aislamiento aunque cambie la asignación del scanner.
Si el administrador autenticado tiene `event_id`, el alta de scanners hereda ese valor y las búsquedas, ediciones, bajas y consultas de intentos de escaneo se limitan a personal del mismo evento. El cliente no puede elegir ni cambiar el evento. Sin `event_id`, se mantiene el alcance por tenant.

View File

@@ -4,7 +4,7 @@ use App\Domains\Core\Staff\Controllers\AdminAppStaffController;
use Illuminate\Support\Facades\Route;
Route::prefix('v1/adminapp/tenant')
->middleware(['auth:sanctum', 'adminapp.tenant:event'])
->middleware(['auth:sanctum', 'adminapp.tenant'])
->group(function (): void {
Route::get('staff/{staff}/scan-attempts', [AdminAppStaffController::class, 'scanAttempts']);
Route::apiResource('staff', AdminAppStaffController::class)->except('show');

View File

@@ -6,18 +6,18 @@ use App\Domains\Ticketing\Desfile\Requests\ExportEntryReservationsRequest;
use App\Domains\Ticketing\Desfile\Requests\IndexEntryReservationsRequest;
use App\Domains\Ticketing\Desfile\Requests\StoreEntryReservationsRequest;
use App\Domains\Ticketing\Desfile\Resources\EntryReservationResource;
use App\Domains\Ticketing\Desfile\Services\DesfileEntryReservationService;
use App\Domains\Ticketing\Desfile\Services\EntryReservationExcelService;
use App\Domains\Ticketing\Desfile\Services\EntryReservationPdfService;
use App\Domains\Ticketing\Desfile\Services\EntryReservationService;
use App\Domains\Ticketing\Ticket\Services\TicketPdfService;
use App\Http\Controllers\Controller;
use Illuminate\Http\Resources\Json\AnonymousResourceCollection;
use Illuminate\Http\Response;
use Symfony\Component\HttpFoundation\StreamedResponse;
class EntryReservationController extends Controller
class DesfileEntryReservationController extends Controller
{
public function index(IndexEntryReservationsRequest $request, EntryReservationService $service): AnonymousResourceCollection
public function index(IndexEntryReservationsRequest $request, DesfileEntryReservationService $service): AnonymousResourceCollection
{
return EntryReservationResource::collection(
$service->reservations($request->user(), $request->validated()),
@@ -26,7 +26,7 @@ class EntryReservationController extends Controller
public function downloadPdf(
ExportEntryReservationsRequest $request,
EntryReservationService $service,
DesfileEntryReservationService $service,
EntryReservationPdfService $pdf,
): Response {
$user = $request->user();
@@ -40,7 +40,7 @@ class EntryReservationController extends Controller
public function downloadExcel(
ExportEntryReservationsRequest $request,
EntryReservationService $service,
DesfileEntryReservationService $service,
EntryReservationExcelService $excel,
): StreamedResponse {
$user = $request->user();
@@ -55,7 +55,7 @@ class EntryReservationController extends Controller
public function downloadTicketPdf(
IndexEntryReservationsRequest $request,
int $reservation,
EntryReservationService $service,
DesfileEntryReservationService $service,
TicketPdfService $pdf,
): Response {
$user = $request->user();
@@ -66,7 +66,7 @@ class EntryReservationController extends Controller
);
}
public function store(StoreEntryReservationsRequest $request, EntryReservationService $service): AnonymousResourceCollection
public function store(StoreEntryReservationsRequest $request, DesfileEntryReservationService $service): AnonymousResourceCollection
{
return EntryReservationResource::collection($service->reserve(
$request->user(), $request->validated('idempotency_key'), $request->validated('rows'),
@@ -76,7 +76,7 @@ class EntryReservationController extends Controller
public function destroy(
IndexEntryReservationsRequest $request,
int $reservation,
EntryReservationService $service,
DesfileEntryReservationService $service,
): Response {
$service->cancel($request->user(), $reservation);

View File

@@ -1,54 +0,0 @@
<?php
namespace App\Domains\Ticketing\Desfile\Models;
use App\Domains\Commerce\Catalog\Models\Inventory;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Ticketing\Desfile\Enums\EntryReservationPaymentType;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
use Illuminate\Database\Eloquent\SoftDeletes;
#[Fillable([
'variant_id',
'ticket_id',
'inventory_id',
'batch_id',
'fecha_reserva',
'importe',
'tipo_pago',
])]
class EntryReservation extends Model
{
use SoftDeletes;
protected $table = 'desfile_entry_reservations';
protected function casts(): array
{
return [
'variant_id' => 'integer',
'fecha_reserva' => 'datetime',
'importe' => 'decimal:2',
'tipo_pago' => EntryReservationPaymentType::class,
];
}
/** @return BelongsTo<Variant, $this> */
public function variant(): BelongsTo
{
return $this->belongsTo(Variant::class)->withTrashed();
}
public function ticket(): BelongsTo
{
return $this->belongsTo(Ticket::class);
}
public function inventory(): BelongsTo
{
return $this->belongsTo(Inventory::class);
}
}

View File

@@ -2,7 +2,7 @@
namespace App\Domains\Ticketing\Desfile\Requests;
use App\Domains\Ticketing\Desfile\Enums\EntryReservationPaymentType;
use App\Domains\Ticketing\Ticket\Enums\EntryReservationPaymentType;
use Illuminate\Foundation\Http\FormRequest;
use Illuminate\Validation\Rule;

View File

@@ -2,7 +2,7 @@
namespace App\Domains\Ticketing\Desfile\Requests;
use App\Domains\Ticketing\Desfile\Enums\EntryReservationPaymentType;
use App\Domains\Ticketing\Ticket\Enums\EntryReservationPaymentType;
use Illuminate\Foundation\Http\FormRequest;
use Illuminate\Validation\Rule;

View File

@@ -15,6 +15,7 @@ class EntryReservationResource extends JsonResource
return [
'id' => $this->id,
'catalog_item_id' => $this->catalog_item_id,
'variant_id' => $this->variant_id,
'ticket_id' => $this->ticket_id,
'fecha_reserva' => $this->fecha_reserva->toIso8601String(),

View File

@@ -0,0 +1,31 @@
<?php
namespace App\Domains\Ticketing\Desfile\Services;
use App\Domains\Ticketing\Ticket\Services\EntryReservationPolicy;
use Illuminate\Validation\ValidationException;
class DesfileEntryReservationPolicy implements EntryReservationPolicy
{
public function validate(array $selections): void
{
$errors = [];
$seen = [];
foreach ($selections as $index => $selection) {
$variant = $selection['variant'];
if ($variant === null || $selection['inventory'] === null
|| isset($seen[$variant->id])
|| $variant->entryReservations()->lockForUpdate()->get()->isNotEmpty()) {
$errors["rows.{$index}.variant_id"] = 'La entrada ya no está disponible.';
}
if ($variant !== null) {
$seen[$variant->id] = true;
}
}
if ($errors !== []) {
throw ValidationException::withMessages($errors);
}
}
}

View File

@@ -0,0 +1,123 @@
<?php
namespace App\Domains\Ticketing\Desfile\Services;
use App\Domains\Commerce\Catalog\Models\CatalogItem;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Ticketing\Ticket\Models\EntryReservation;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Services\EntryReservationService as TicketEntryReservationService;
use Illuminate\Pagination\LengthAwarePaginator;
use Illuminate\Support\Collection;
use Illuminate\Validation\ValidationException;
/** Adapts the Desfile API and seat rules to the catalog-based reservation workflow. */
class DesfileEntryReservationService
{
private const SELECTION_RELATIONS = [
'variant.catalogItem.itemAttributes.attribute.options',
'variant.definitions.itemAttribute.attribute.options',
'variant.eventDates',
'variant.eventDate',
];
public function __construct(
private readonly TicketEntryReservationService $reservations,
private readonly DesfileEntryReservationPolicy $policy,
) {}
/**
* @param array{tipo_pago?: string|null, page?: int, per_page?: int} $filters
* @return LengthAwarePaginator<EntryReservation>
*/
public function reservations(User $user, array $filters = []): LengthAwarePaginator
{
$result = $this->reservations->reservations($user, [
...$filters, 'catalog_item_id' => $this->entryId($user),
]);
$result->getCollection()->loadMissing(self::SELECTION_RELATIONS);
return $result;
}
/**
* @param array{tipo_pago?: string|null} $filters
* @return Collection<int, EntryReservation>
*/
public function reservationsForExport(User $user, array $filters = []): Collection
{
return $this->reservations->reservationsForExport($user, [
...$filters, 'catalog_item_id' => $this->entryId($user),
])->loadMissing(self::SELECTION_RELATIONS);
}
public function reservationTicket(User $user, int $reservationId): Ticket
{
return $this->reservations->reservationTicket($user, $reservationId, $this->entryId($user));
}
public function cancel(User $user, int $reservationId): void
{
$this->reservations->cancel($user, $reservationId, $this->entryId($user));
}
/** @param list<array{variant_id: int, tipo_pago: string}> $rows */
public function reserve(User $user, string $key, array $rows): Collection
{
$this->authorize($user);
$entry = CatalogItem::query()->where('tenant_code', $user->tenant_codigo)
->where('slug', 'entrada')->firstOrFail();
$catalogRows = array_map(fn (array $row): array => [
...$row, 'catalog_item_id' => $entry->id,
], $rows);
try {
return $this->reservations->reserve($user, $key, $catalogRows, $this->policy)
->loadMissing(self::SELECTION_RELATIONS);
} catch (ValidationException $exception) {
// Keep the row fields used by the form and describe the selected seat.
$variants = $entry->variants()->whereKey(array_column($rows, 'variant_id'))
->with(['definitions.itemAttribute.attribute.options'])->get()->keyBy('id');
$errors = [];
foreach ($exception->errors() as $field => $messages) {
if (preg_match('/^rows\.(\d+)\.variant_id$/', $field, $match)) {
$index = (int) $match[1];
$label = $this->entryLabel($variants->get($rows[$index]['variant_id'] ?? null), $index);
$messages = array_map(fn (string $message): string => $label.': '.$message, $messages);
}
$errors[$field] = $messages;
}
throw ValidationException::withMessages($errors);
}
}
private function authorize(User $user): void
{
abort_unless($user->tenant_codigo === 'desfile_pura_tendencia', 403);
}
private function entryId(User $user): int
{
$this->authorize($user);
// Historical reservations remain accessible when the active event changes.
// A missing entry must not remove the catalog filter from the generic query.
return CatalogItem::query()->where('tenant_code', $user->tenant_codigo)
->where('slug', 'entrada')->value('id') ?? -1;
}
private function entryLabel(?Variant $variant, int $index): string
{
if ($variant === null) {
return 'Entrada '.($index + 1);
}
$values = $variant->selectionValues();
return collect(['tipo' => 'Tipo', 'sector' => 'Sector', 'fila' => 'Fila', 'asiento' => 'Asiento'])
->map(fn (string $label, string $key): string => $label.': '.($values->get($key) ?? 'sin especificar'))
->implode(', ');
}
}

View File

@@ -3,7 +3,7 @@
namespace App\Domains\Ticketing\Desfile\Services;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Desfile\Models\EntryReservation;
use App\Domains\Ticketing\Ticket\Models\EntryReservation;
use Illuminate\Support\Collection;
use PhpOffice\PhpSpreadsheet\Cell\DataType;
use PhpOffice\PhpSpreadsheet\Shared\Date;

View File

@@ -3,7 +3,7 @@
namespace App\Domains\Ticketing\Desfile\Services;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Desfile\Models\EntryReservation;
use App\Domains\Ticketing\Ticket\Models\EntryReservation;
use Barryvdh\DomPDF\Facade\Pdf;
use Barryvdh\DomPDF\PDF as DomPdf;
use Illuminate\Http\Response;

View File

@@ -2,7 +2,7 @@
namespace App\Domains\Ticketing\Desfile\Services;
use App\Domains\Ticketing\Desfile\Models\EntryReservation;
use App\Domains\Ticketing\Ticket\Models\EntryReservation;
use Illuminate\Support\Collection;
class EntryReservationReportService

View File

@@ -1,240 +0,0 @@
<?php
namespace App\Domains\Ticketing\Desfile\Services;
use App\Domains\Commerce\Catalog\Enums\InventoryPolicy;
use App\Domains\Commerce\Catalog\Models\CatalogItem;
use App\Domains\Commerce\Catalog\Models\Inventory;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Ticketing\Desfile\Enums\EntryReservationPaymentType;
use App\Domains\Ticketing\Desfile\Models\EntryReservation;
use App\Domains\Ticketing\Ticket\Exceptions\TicketGenerationException;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Services\TicketGeneratorService;
use App\Domains\Ticketing\Ticket\Services\TicketPresentationResolver;
use App\Domains\Ticketing\Ticket\Services\TicketValidityResolver;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Pagination\LengthAwarePaginator;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\DB;
use Illuminate\Validation\ValidationException;
class EntryReservationService
{
public function __construct(private readonly TicketGeneratorService $tickets) {}
/**
* @param array{tipo_pago?: string|null, page?: int, per_page?: int} $filters
* @return LengthAwarePaginator<EntryReservation>
*/
public function reservations(User $user, array $filters = []): LengthAwarePaginator
{
abort_unless($user->tenant_codigo === 'desfile_pura_tendencia', 403);
return $this->reservationsQuery($user, $filters)
->paginate(
perPage: $filters['per_page'] ?? 15,
pageName: 'page',
page: $filters['page'] ?? 1,
)
->withQueryString();
}
/**
* @param array{tipo_pago?: string|null} $filters
* @return Collection<int, EntryReservation>
*/
public function reservationsForExport(User $user, array $filters = []): Collection
{
abort_unless($user->tenant_codigo === 'desfile_pura_tendencia', 403);
return $this->reservationsQuery($user, $filters)->get();
}
public function reservationTicket(User $user, int $reservationId): Ticket
{
abort_unless($user->tenant_codigo === 'desfile_pura_tendencia', 403);
$reservation = EntryReservation::query()
->whereKey($reservationId)
->whereNotNull('ticket_id')
->whereHas('variant.catalogItem', fn (Builder $query): Builder => $query
->where('tenant_code', $user->tenant_codigo)
->where('slug', 'entrada'))
->with(['ticket' => fn ($query) => $query->with([
...TicketValidityResolver::RELATIONS,
...TicketPresentationResolver::RELATIONS,
])])
->firstOrFail();
return $reservation->ticket;
}
public function cancel(User $user, int $reservationId): void
{
abort_unless($user->tenant_codigo === 'desfile_pura_tendencia', 403);
DB::transaction(function () use ($user, $reservationId): void {
$reservation = EntryReservation::query()
->whereKey($reservationId)
->whereHas('variant.catalogItem', fn (Builder $query): Builder => $query
->where('tenant_code', $user->tenant_codigo)
->where('slug', 'entrada'))
->lockForUpdate()
->firstOrFail();
if ($reservation->ticket_id !== null) {
$ticket = Ticket::query()->lockForUpdate()->findOrFail($reservation->ticket_id);
if (! $ticket->can_cancel()) {
throw ValidationException::withMessages([
'status' => 'El ticket debe estar activo para poder cancelar la reserva.',
]);
}
$ticket->markAsCancelled();
$ticket->save();
}
if ($reservation->inventory_id !== null) {
$inventory = Inventory::query()->lockForUpdate()->findOrFail($reservation->inventory_id);
$inventory->releaseEntry(1);
}
$reservation->delete();
}, 3);
}
/** @param array{tipo_pago?: string|null} $filters */
private function reservationsQuery(User $user, array $filters = []): Builder
{
return EntryReservation::query()
->whereHas('variant.catalogItem', fn (Builder $query): Builder => $query
->where('tenant_code', $user->tenant_codigo)
->where('slug', 'entrada'))
->when(
$filters['tipo_pago'] ?? null,
fn (Builder $query, string $paymentType): Builder => $query->where('tipo_pago', $paymentType),
)
->with([
'variant.catalogItem.itemAttributes.attribute.options',
'variant.definitions.itemAttribute.attribute.options',
'variant.eventDates',
'variant.eventDate',
])
->orderByDesc('fecha_reserva')
->orderByDesc('id');
}
/** @param list<array{variant_id: int, tipo_pago: string}> $rows */
public function reserve(User $user, string $key, array $rows): Collection
{
abort_unless($user->tenant_codigo === 'desfile_pura_tendencia', 403);
$normalized = collect($rows)->map(fn (array $row): array => [
'variant_id' => (int) $row['variant_id'], 'tipo_pago' => $row['tipo_pago'],
])->sortBy('variant_id')->values()->all();
$hash = hash('sha256', json_encode($normalized, JSON_THROW_ON_ERROR));
return DB::transaction(function () use ($user, $key, $rows, $hash): Collection {
// Serialize retries by the same administrator, including the first insert.
User::query()->whereKey($user->id)->lockForUpdate()->firstOrFail();
$batch = DB::table('desfile_reservation_batches')
->where('user_id', $user->id)->where('idempotency_key', $key)->lockForUpdate()->first();
if ($batch !== null) {
abort_unless($batch->tenant_code === $user->tenant_codigo && hash_equals($batch->request_hash, $hash), 409,
'La clave de envío ya fue utilizada con otras entradas.');
return EntryReservation::query()->where('batch_id', $batch->id)->with('ticket')->orderBy('id')->get();
}
$tenant = $user->tenant()->firstOrFail();
$entry = CatalogItem::query()->forTenantCatalog($tenant)->where('slug', 'entrada')
->lockForUpdate()->firstOrFail();
$ids = array_column($rows, 'variant_id');
$variants = $entry->variants()->whereKey($ids)->orderBy('id')->lockForUpdate()->get();
$inventories = Inventory::query()->whereKey($variants->pluck('inventory_id')->filter()->unique())
->orderBy('id')->lockForUpdate()->get()->keyBy('id');
$variants->load([
'eventDates', 'eventDate',
'desfileEntryReservations' => fn ($query) => $query->lockForUpdate(),
]);
foreach ($variants as $variant) {
$variant->setRelation('inventory', $inventories->get($variant->inventory_id));
}
$entry->setRelation('variants', $variants);
$available = $entry->visibleVariants()->keyBy('id');
$requirements = [];
$errors = [];
foreach ($rows as $index => $row) {
$variant = $available->get($row['variant_id']);
if ($variant === null || $variant->inventory === null) {
$errors["rows.{$index}.variant_id"] = $this->entryLabel($variants->firstWhere('id', $row['variant_id']), $index).': la entrada ya no está disponible.';
continue;
}
$requirements[$variant->inventory_id] = ($requirements[$variant->inventory_id] ?? 0) + 1;
}
if ($errors !== []) {
throw ValidationException::withMessages($errors);
}
$tracked = $entry->inventory_policy !== InventoryPolicy::Unlimited;
foreach ($requirements as $inventoryId => $quantity) {
if ($tracked && $inventories[$inventoryId]->availableStock() < $quantity) {
foreach ($rows as $index => $row) {
$variant = $available[$row['variant_id']];
if ($variant->inventory_id === $inventoryId) {
$errors["rows.{$index}.variant_id"] = $this->entryLabel($variant, $index).': no hay stock suficiente para reservar las entradas seleccionadas.';
}
}
}
}
if ($errors !== []) {
throw ValidationException::withMessages($errors);
}
$batchId = DB::table('desfile_reservation_batches')->insertGetId([
'user_id' => $user->id, 'tenant_code' => $tenant->codigo,
'idempotency_key' => $key, 'request_hash' => $hash,
'created_at' => now(), 'updated_at' => now(),
]);
foreach ($requirements as $inventoryId => $quantity) {
$inventories[$inventoryId]->reserveEntry($quantity, $tracked);
}
$reservations = collect();
foreach ($rows as $index => $row) {
$variant = $available[$row['variant_id']];
$payment = EntryReservationPaymentType::from($row['tipo_pago']);
try {
$ticket = $this->tickets->generate($entry, $user, 1, $variant->id)->sole();
} catch (TicketGenerationException $exception) {
throw ValidationException::withMessages([
"rows.{$index}.variant_id" => $this->entryLabel($variant, $index).': no se pudo emitir el ticket. '.$exception->getMessage(),
]);
}
$reservation = EntryReservation::query()->create([
'batch_id' => $batchId, 'ticket_id' => $ticket->id,
'variant_id' => $variant->id, 'inventory_id' => $variant->inventory_id,
'fecha_reserva' => now(), 'tipo_pago' => $payment,
'importe' => $payment === EntryReservationPaymentType::Free ? 0 : $variant->getPrice(),
]);
$reservations->push($reservation->setRelation('ticket', $ticket));
}
return $reservations;
}, 3);
}
private function entryLabel(?Variant $variant, int $index): string
{
if ($variant === null) {
return 'Entrada '.($index + 1);
}
$values = $variant->selectionValues();
return collect(['tipo' => 'Tipo', 'sector' => 'Sector', 'fila' => 'Fila', 'asiento' => 'Asiento'])
->map(fn (string $label, string $key): string => $label.': '.($values->get($key) ?? 'sin especificar'))
->implode(', ');
}
}

View File

@@ -1,26 +1,26 @@
<?php
use App\Domains\Ticketing\Desfile\Controllers\DesfileEntryReservationController;
use App\Domains\Ticketing\Desfile\Controllers\EntryController;
use App\Domains\Ticketing\Desfile\Controllers\EntryReservationController;
use Illuminate\Support\Facades\Route;
Route::get('v1/adminapp/tenant/desfile/entry-reservations', [EntryReservationController::class, 'index'])
Route::get('v1/adminapp/tenant/desfile/entry-reservations', [DesfileEntryReservationController::class, 'index'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:adminapp.desfile.reservas'])
->name('adminapp.desfile.entry-reservations.index');
Route::get('v1/adminapp/tenant/desfile/entry-reservations/pdf', [EntryReservationController::class, 'downloadPdf'])
Route::get('v1/adminapp/tenant/desfile/entry-reservations/pdf', [DesfileEntryReservationController::class, 'downloadPdf'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:adminapp.desfile.reservas'])
->name('adminapp.desfile.entry-reservations.pdf');
Route::get('v1/adminapp/tenant/desfile/entry-reservations/excel', [EntryReservationController::class, 'downloadExcel'])
Route::get('v1/adminapp/tenant/desfile/entry-reservations/excel', [DesfileEntryReservationController::class, 'downloadExcel'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:adminapp.desfile.reservas'])
->name('adminapp.desfile.entry-reservations.excel');
Route::get('v1/adminapp/tenant/desfile/entry-reservations/{reservation}/ticket/pdf', [EntryReservationController::class, 'downloadTicketPdf'])
Route::get('v1/adminapp/tenant/desfile/entry-reservations/{reservation}/ticket/pdf', [DesfileEntryReservationController::class, 'downloadTicketPdf'])
->whereNumber('reservation')
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:adminapp.desfile.reservas'])
->name('adminapp.desfile.entry-reservations.ticket.pdf');
Route::post('v1/adminapp/tenant/desfile/entry-reservations', [EntryReservationController::class, 'store'])
Route::post('v1/adminapp/tenant/desfile/entry-reservations', [DesfileEntryReservationController::class, 'store'])
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:adminapp.desfile.reservas'])
->name('adminapp.desfile.entry-reservations.store');
Route::delete('v1/adminapp/tenant/desfile/entry-reservations/{reservation}', [EntryReservationController::class, 'destroy'])
Route::delete('v1/adminapp/tenant/desfile/entry-reservations/{reservation}', [DesfileEntryReservationController::class, 'destroy'])
->whereNumber('reservation')
->middleware(['auth:sanctum', 'adminapp.tenant', 'tenant.menu:adminapp.desfile.reservas'])
->name('adminapp.desfile.entry-reservations.destroy');

View File

@@ -2,7 +2,6 @@
namespace App\Domains\Ticketing\Event\Controllers\AdminApp;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Ticketing\Event\Models\EventDate;
use App\Domains\Ticketing\Event\Requests\RescheduleEventDateRequest;
use App\Domains\Ticketing\Event\Requests\StoreEventDateRequest;
@@ -20,8 +19,7 @@ class EventController extends Controller
public function show(Request $request): EventResource
{
return EventResource::make(
$this->eventService->forTenant($request->user()->tenant()->firstOrFail(),
app(EventScopeService::class)->eventId($request->user()))
$this->eventService->forTenant($request->user()->tenant()->firstOrFail())
);
}
@@ -30,8 +28,7 @@ class EventController extends Controller
return EventResource::make(
$this->eventService->updateForTenant(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
app(EventScopeService::class)->eventId($request->user())
$request->validated()
)
);
}
@@ -42,7 +39,6 @@ class EventController extends Controller
$this->eventService->createDateForTenant(
$request->user()->tenant()->firstOrFail(),
$request->validated(),
app(EventScopeService::class)->eventId($request->user()),
)
);
}

View File

@@ -15,27 +15,14 @@ use Illuminate\Database\Eloquent\Relations\BelongsTo;
use Illuminate\Database\Eloquent\Relations\BelongsToMany;
use Illuminate\Database\Eloquent\Relations\HasMany;
#[Fillable(['client_id', 'tenant_code', 'slug', 'event_category_id', 'title', 'subtitle', 'description', 'location', 'exact_location', 'date_text', 'published_at', 'attachment_id', 'allow_ticket_refund', 'allow_ticket_total_refund', 'allow_ticket_partial_refund', 'ticket_partial_refund_percentage'])]
#[Fillable(['client_id', 'tenant_code', 'slug', 'event_category_id', 'title', 'subtitle', 'description', 'location', 'exact_location', 'date_text', 'published_at', 'attachment_id'])]
class Event extends Model
{
use HasFactory;
protected function casts(): array
{
return ['allow_ticket_refund' => 'boolean', 'allow_ticket_total_refund' => 'boolean',
'allow_ticket_partial_refund' => 'boolean', 'ticket_partial_refund_percentage' => 'decimal:2', 'client_id' => 'integer', 'published_at' => 'datetime', 'exact_location' => 'array'];
}
public function allow_refund(): bool
{
return (bool) $this->allow_ticket_refund
&& ((bool) $this->allow_ticket_total_refund || $this->allow_partial_refund());
}
public function allow_partial_refund(): bool
{
return (bool) $this->allow_ticket_refund && (bool) $this->allow_ticket_partial_refund
&& (float) $this->ticket_partial_refund_percentage > 0;
return ['client_id' => 'integer', 'published_at' => 'datetime', 'exact_location' => 'array'];
}
/** @return BelongsTo<Tenant, $this> */

View File

@@ -26,10 +26,10 @@ class EventResource extends JsonResource
'date_text' => $this->date_text,
'published_at' => $this->published_at?->toIso8601String(),
'attachment_id' => $this->attachment_id,
'allow_ticket_refund' => $this->allow_ticket_refund,
'allow_ticket_total_refund' => $this->allow_ticket_total_refund,
'allow_ticket_partial_refund' => $this->allow_ticket_partial_refund,
'ticket_partial_refund_percentage' => $this->ticket_partial_refund_percentage,
'allow_ticket_refund' => $this->tenant->allow_ticket_refund,
'allow_ticket_total_refund' => $this->tenant->allow_ticket_total_refund,
'allow_ticket_partial_refund' => $this->tenant->allow_ticket_partial_refund,
'ticket_partial_refund_percentage' => $this->tenant->ticket_partial_refund_percentage,
'dates' => EventDateResource::collection(
app(EventDateGroupingService::class)->group($this->dates)
),

View File

@@ -2,19 +2,18 @@
namespace App\Domains\Ticketing\Event\Services;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Commerce\Cart\Services\InvalidateEventDateCartsService;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Commerce\Catalog\Services\StockReservationService;
use App\Domains\Commerce\Catalog\Services\VariantReplacementService;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Enums\EventDateChangeType;
use App\Domains\Ticketing\Event\Events\EventDateRescheduled;
use App\Domains\Ticketing\Event\Events\EventDateSuspended;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Ticketing\Event\Models\EventDate;
use App\Domains\Ticketing\Event\Models\EventDateChange;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\DB;
@@ -35,22 +34,22 @@ class EventService
private readonly InvalidateEventDateCartsService $invalidateEventDateCarts,
) {}
public function forTenant(Tenant $tenant, ?int $eventId = null): Event
public function forTenant(Tenant $tenant): Event
{
return $this->resolveEvent($tenant, $eventId)->load(['dates.validityTime', 'socialMedia']);
return $tenant->activeEvent->load(['dates.validityTime', 'socialMedia']);
}
/** @param array<string, mixed> $data */
public function updateForTenant(Tenant $tenant, array $data, ?int $eventId = null): Event
public function updateForTenant(Tenant $tenant, array $data): Event
{
return DB::transaction(function () use ($tenant, $data, $eventId): Event {
$event = $this->resolveEvent($tenant, $eventId);
return DB::transaction(function () use ($tenant, $data): Event {
$event = $tenant->activeEvent;
$event->update([
'title' => $data['title'],
'location' => $data['location'],
...array_intersect_key($data, ['attachment_id' => true, 'exact_location' => true]),
]);
$event->update([
$tenant->update([
...array_intersect_key($data, array_flip([
'allow_ticket_refund',
'allow_ticket_total_refund',
@@ -70,10 +69,10 @@ class EventService
}
/** @param array{date: string, start_time: string, end_time: string} $data */
public function createDateForTenant(Tenant $tenant, array $data, ?int $eventId = null): EventDate
public function createDateForTenant(Tenant $tenant, array $data): EventDate
{
return DB::transaction(function () use ($tenant, $data, $eventId): EventDate {
$event = $this->resolveEvent($tenant, $eventId);
return DB::transaction(function () use ($tenant, $data): EventDate {
$event = $tenant->activeEvent;
$attributes = $this->dateAttributes($data);
if ($event->dates()->where($attributes)->exists()) {
@@ -94,7 +93,7 @@ class EventService
?User $createdBy = null,
): EventDate {
return DB::transaction(function () use ($tenant, $eventDate, $data, $createdBy): EventDate {
$source = $this->lockedDateForTenant($tenant, $eventDate, $createdBy);
$source = $this->lockedDateForTenant($tenant, $eventDate);
if ($source->suspended_at !== null) {
throw ValidationException::withMessages([
@@ -173,7 +172,7 @@ class EventService
?User $createdBy = null,
): EventDate {
return DB::transaction(function () use ($tenant, $eventDate, $createdBy): EventDate {
$date = $this->lockedDateForTenant($tenant, $eventDate, $createdBy);
$date = $this->lockedDateForTenant($tenant, $eventDate);
if ($date->rescheduled_to_event_date_id !== null) {
throw ValidationException::withMessages([
@@ -217,18 +216,10 @@ class EventService
});
}
private function resolveEvent(Tenant $tenant, ?int $eventId): Event
{
return Event::query()->where('tenant_code', $tenant->codigo)
->findOrFail($eventId ?? $tenant->active_event_id);
}
private function lockedDateForTenant(Tenant $tenant, EventDate $eventDate, ?User $actor = null): EventDate
private function lockedDateForTenant(Tenant $tenant, EventDate $eventDate): EventDate
{
return $tenant->eventDates()
->whereKey($eventDate->getKey())
->when($actor !== null && ! $actor->isTenantAdministrator(),
fn ($query) => $query->where('event_id', app(EventScopeService::class)->eventId($actor)))
->lockForUpdate()
->firstOrFail();
}

View File

@@ -37,10 +37,10 @@ se guardan en el evento. Sin evento activo se conservan las redes propias del te
## API
Los endpoints de AdminApp usan `auth:sanctum` y `adminapp.tenant:event`:
Los endpoints de AdminApp usan `auth:sanctum` y `adminapp.tenant`:
- `GET/PUT /v1/adminapp/tenant/event`: acceso al evento asociado al usuario con scope de evento;
para admins de tenant se conserva el evento activo.
- `GET/PUT /v1/adminapp/tenant/event`: acceso al evento seleccionado para el
storefront de evento único.
- `POST /v1/adminapp/tenant/event-dates`: crea una fecha para ese evento.
- `POST /v1/adminapp/tenant/event-dates/{eventDate}/reschedule` y
`POST /v1/adminapp/tenant/event-dates/{eventDate}/suspend`: cambios de fecha.
@@ -53,8 +53,3 @@ una lista de eventos ni existe todavía una pantalla para gestionarlos.
Las fechas se vinculan con variantes de `Catalog`, que a su vez pueden generar
tickets. Los avisos por suspensión y reprogramación se construyen dinámicamente
después de excluir los cambios que el usuario ya vio tres veces.
La configuración de devoluciones se persiste en `events`, se entrega en
`EventResource` y se aplica al evento de cada ticket. La migración inicial copia
los valores anteriores del tenant a sus eventos. Las fechas se autorizan por
tenant y por evento antes de cualquier suspensión o reprogramación.

View File

@@ -4,7 +4,7 @@ use App\Domains\Ticketing\Event\Controllers\AdminApp\EventController;
use Illuminate\Support\Facades\Route;
Route::prefix('v1/adminapp/tenant')
->middleware(['auth:sanctum', 'adminapp.tenant:event'])
->middleware(['auth:sanctum', 'adminapp.tenant'])
->group(function (): void {
Route::get('event', [EventController::class, 'show']);
Route::put('event', [EventController::class, 'update']);

View File

@@ -0,0 +1,94 @@
<?php
namespace App\Domains\Ticketing\Ticket\Controllers\AdminApp;
use App\Domains\Ticketing\Ticket\Requests\ExportEntryReservationsRequest;
use App\Domains\Ticketing\Ticket\Requests\IndexEntryReservationsRequest;
use App\Domains\Ticketing\Ticket\Requests\StoreEntryReservationsRequest;
use App\Domains\Ticketing\Ticket\Resources\EntryReservationFormResource;
use App\Domains\Ticketing\Ticket\Resources\EntryReservationResource;
use App\Domains\Ticketing\Ticket\Services\EntryReservationExcelService;
use App\Domains\Ticketing\Ticket\Services\EntryReservationFormService;
use App\Domains\Ticketing\Ticket\Services\EntryReservationPdfService;
use App\Domains\Ticketing\Ticket\Services\EntryReservationService;
use App\Domains\Ticketing\Ticket\Services\TicketPdfService;
use App\Http\Controllers\Controller;
use Illuminate\Http\Resources\Json\AnonymousResourceCollection;
use Illuminate\Http\Response;
use Symfony\Component\HttpFoundation\StreamedResponse;
class EntryReservationController extends Controller
{
public function form(IndexEntryReservationsRequest $request, EntryReservationFormService $service): EntryReservationFormResource
{
return new EntryReservationFormResource($service->get(
$request->user()->tenant()->firstOrFail(), $request->user()->event_id,
));
}
public function index(IndexEntryReservationsRequest $request, EntryReservationService $service): AnonymousResourceCollection
{
return EntryReservationResource::collection(
$service->reservations($request->user(), $request->validated()),
);
}
public function downloadPdf(
ExportEntryReservationsRequest $request,
EntryReservationService $service,
EntryReservationPdfService $pdf,
): Response {
$user = $request->user();
return $pdf->download(
$user->tenant()->firstOrFail(),
$service->reservationsForExport($user, $request->validated()),
$request->validated('timezone'),
);
}
public function downloadExcel(
ExportEntryReservationsRequest $request,
EntryReservationService $service,
EntryReservationExcelService $excel,
): StreamedResponse {
$user = $request->user();
return $excel->download(
$user->tenant()->firstOrFail(),
$service->reservationsForExport($user, $request->validated()),
$request->validated('timezone'),
);
}
public function downloadTicketPdf(
IndexEntryReservationsRequest $request,
int $reservation,
EntryReservationService $service,
TicketPdfService $pdf,
): Response {
$user = $request->user();
return $pdf->download(
$user->tenant()->firstOrFail(),
collect([$service->reservationTicket($user, $reservation)]),
);
}
public function store(StoreEntryReservationsRequest $request, EntryReservationService $service): AnonymousResourceCollection
{
return EntryReservationResource::collection($service->reserve(
$request->user(), $request->validated('idempotency_key'), $request->validated('rows'),
));
}
public function destroy(
IndexEntryReservationsRequest $request,
int $reservation,
EntryReservationService $service,
): Response {
$service->cancel($request->user(), $reservation);
return response()->noContent();
}
}

View File

@@ -29,7 +29,7 @@ class TicketController extends Controller
$tenant = $request->user()->tenant()->firstOrFail();
return new AdminAppTicketCollection(
$this->ticketService->search($tenant, $request->validated())
$this->ticketService->search($tenant, $request->validated(), $request->user()->event_id)
);
}
@@ -37,7 +37,7 @@ class TicketController extends Controller
{
$tenant = $request->user()->tenant()->firstOrFail();
return new AdminAppTicketResource($this->ticketService->cancel($tenant, $ticket));
return new AdminAppTicketResource($this->ticketService->cancel($tenant, $ticket, $request->user()->event_id));
}
public function calculateRefund(Request $request, int $ticket): AdminAppTicketRefundCalculationResource
@@ -45,7 +45,7 @@ class TicketController extends Controller
$tenant = $request->user()->tenant()->firstOrFail();
return new AdminAppTicketRefundCalculationResource(
$this->ticketService->calculateRefund($tenant, $ticket)
$this->ticketService->calculateRefund($tenant, $ticket, $request->user()->event_id)
);
}
@@ -69,7 +69,7 @@ class TicketController extends Controller
return $this->ticketPdfService->download(
$tenant,
$this->ticketService->ticketsForExport($tenant, $request->validated()),
$this->ticketService->ticketsForExport($tenant, $request->validated(), $request->user()->event_id),
$request->validated('timezone'),
);
}
@@ -80,7 +80,7 @@ class TicketController extends Controller
return $this->ticketExcelService->download(
$tenant,
$this->ticketService->ticketsForExport($tenant, $request->validated()),
$this->ticketService->ticketsForExport($tenant, $request->validated(), $request->user()->event_id),
$request->validated('timezone'),
);
}

View File

@@ -1,6 +1,6 @@
<?php
namespace App\Domains\Ticketing\Desfile\Enums;
namespace App\Domains\Ticketing\Ticket\Enums;
enum EntryReservationPaymentType: string
{

View File

@@ -0,0 +1,87 @@
<?php
namespace App\Domains\Ticketing\Ticket\Models;
use App\Domains\Commerce\Catalog\Models\CatalogItem;
use App\Domains\Commerce\Catalog\Models\Inventory;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Ticketing\Ticket\Enums\EntryReservationPaymentType;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
use Illuminate\Database\Eloquent\SoftDeletes;
use Illuminate\Validation\ValidationException;
#[Fillable([
'catalog_item_id',
'variant_id',
'ticket_id',
'inventory_id',
'batch_id',
'fecha_reserva',
'importe',
'tipo_pago',
])]
class EntryReservation extends Model
{
use SoftDeletes;
protected $table = 'entry_reservations';
protected function casts(): array
{
return [
'catalog_item_id' => 'integer',
'variant_id' => 'integer',
'fecha_reserva' => 'datetime',
'importe' => 'decimal:2',
'tipo_pago' => EntryReservationPaymentType::class,
];
}
protected static function booted(): void
{
static::saving(function (self $reservation): void {
if ($reservation->variant_id === null) {
return;
}
$variant = Variant::withTrashed()->findOrFail($reservation->variant_id);
// Existing variant-based callers can keep creating reservations as before.
$reservation->catalog_item_id ??= $variant->catalog_item_id;
if ($reservation->catalog_item_id !== $variant->catalog_item_id) {
throw ValidationException::withMessages([
'variant_id' => 'La variante no pertenece al ítem del catálogo seleccionado.',
]);
}
});
}
/** @return BelongsTo<CatalogItem, $this> */
public function catalogItem(): BelongsTo
{
return $this->belongsTo(CatalogItem::class)->withTrashed();
}
/** @return BelongsTo<ReservationBatch, $this> */
public function batch(): BelongsTo
{
return $this->belongsTo(ReservationBatch::class, 'batch_id');
}
/** @return BelongsTo<Variant, $this> */
public function variant(): BelongsTo
{
return $this->belongsTo(Variant::class)->withTrashed();
}
public function ticket(): BelongsTo
{
return $this->belongsTo(Ticket::class);
}
public function inventory(): BelongsTo
{
return $this->belongsTo(Inventory::class);
}
}

View File

@@ -0,0 +1,37 @@
<?php
namespace App\Domains\Ticketing\Ticket\Models;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Tenant\Models\Tenant;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\BelongsTo;
use Illuminate\Database\Eloquent\Relations\HasMany;
#[Fillable(['user_id', 'tenant_code', 'idempotency_key', 'request_hash'])]
class ReservationBatch extends Model
{
protected function casts(): array
{
return ['user_id' => 'integer'];
}
/** @return BelongsTo<User, $this> */
public function user(): BelongsTo
{
return $this->belongsTo(User::class)->withTrashed();
}
/** @return BelongsTo<Tenant, $this> */
public function tenant(): BelongsTo
{
return $this->belongsTo(Tenant::class, 'tenant_code', 'codigo');
}
/** @return HasMany<EntryReservation, $this> */
public function reservations(): HasMany
{
return $this->hasMany(EntryReservation::class, 'batch_id');
}
}

View File

@@ -11,7 +11,6 @@ use Illuminate\Database\Eloquent\Relations\BelongsTo;
#[Fillable([
'tenant_code',
'event_id',
'scanner_user_id',
'ticket_id',
'data',
@@ -44,7 +43,6 @@ class ScanAttempt extends Model
{
return [
'scanner_user_id' => 'integer',
'event_id' => 'integer',
'ticket_id' => 'integer',
'result' => ScanAttemptResult::class,
'created_at' => 'datetime',

View File

@@ -7,7 +7,6 @@ use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Commerce\Purchase\Models\PurchaseItem;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Desfile\Models\EntryReservation;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Ticketing\Ticket\Services\ResolvedTicketValidity;
use App\Domains\Ticketing\Ticket\Services\ResolvedValidityGroup;
@@ -148,9 +147,7 @@ class Ticket extends Model
public function allow_refund(): bool
{
return $this->event_id === null
? ($this->tenant?->allow_refund() ?? false)
: ($this->event?->allow_refund() ?? false);
return $this->tenant?->allow_refund() ?? false;
}
public function allowRefund(): bool

View File

@@ -0,0 +1,13 @@
<?php
namespace App\Domains\Ticketing\Ticket\Requests;
use App\Shared\Rules\ValidTimezone;
class ExportEntryReservationsRequest extends IndexEntryReservationsRequest
{
public function rules(): array
{
return [...parent::rules(), 'timezone' => ['required', 'string', new ValidTimezone]];
}
}

View File

@@ -0,0 +1,26 @@
<?php
namespace App\Domains\Ticketing\Ticket\Requests;
use App\Domains\Ticketing\Ticket\Enums\EntryReservationPaymentType;
use Illuminate\Foundation\Http\FormRequest;
use Illuminate\Validation\Rule;
class IndexEntryReservationsRequest extends FormRequest
{
public function authorize(): bool
{
return $this->user()?->tenant_codigo === 'onticket';
}
public function rules(): array
{
return [
'catalog_item_id' => ['sometimes', 'nullable', 'integer', 'min:1'],
'variant_id' => ['sometimes', 'nullable', 'integer', 'min:1'],
'tipo_pago' => ['sometimes', 'nullable', Rule::enum(EntryReservationPaymentType::class)],
'page' => ['sometimes', 'integer', 'min:1'],
'per_page' => ['sometimes', 'integer', 'min:1', 'max:100'],
];
}
}

View File

@@ -0,0 +1,21 @@
<?php
namespace App\Domains\Ticketing\Ticket\Requests;
use App\Domains\Ticketing\Ticket\Enums\EntryReservationPaymentType;
use Illuminate\Validation\Rule;
class StoreEntryReservationsRequest extends IndexEntryReservationsRequest
{
public function rules(): array
{
return [
'idempotency_key' => ['required', 'uuid'],
'rows' => ['required', 'array', 'list', 'min:1', 'max:100'],
'rows.*' => ['required', 'array:catalog_item_id,variant_id,tipo_pago'],
'rows.*.catalog_item_id' => ['required', 'integer', 'min:1'],
'rows.*.variant_id' => ['sometimes', 'nullable', 'integer', 'min:1'],
'rows.*.tipo_pago' => ['required', Rule::enum(EntryReservationPaymentType::class)],
];
}
}

View File

@@ -0,0 +1,14 @@
<?php
namespace App\Domains\Ticketing\Ticket\Resources;
use Illuminate\Http\Request;
use Illuminate\Http\Resources\Json\JsonResource;
class EntryReservationFormResource extends JsonResource
{
public function toArray(Request $request): array
{
return $this->resource;
}
}

View File

@@ -0,0 +1,28 @@
<?php
namespace App\Domains\Ticketing\Ticket\Resources;
use Illuminate\Http\Request;
use Illuminate\Http\Resources\Json\JsonResource;
class EntryReservationResource extends JsonResource
{
public function toArray(Request $request): array
{
return [
'id' => $this->id,
'catalog_item_id' => $this->catalog_item_id,
'variant_id' => $this->variant_id,
'catalog_item' => ['id' => $this->catalog_item_id, 'name' => $this->catalogItem?->nombre],
'variant' => $this->variant === null ? null : [
'id' => $this->variant_id,
'label' => $this->variant->getSelectionLabel(),
],
'ticket_id' => $this->ticket_id,
'fecha_reserva' => $this->fecha_reserva->toIso8601String(),
'tipo_pago' => $this->tipo_pago->value,
'tipo_pago_label' => $this->tipo_pago->label(),
'importe' => $this->importe,
];
}
}

View File

@@ -32,7 +32,7 @@ class ScanAttemptResource extends JsonResource
ScanAttemptResult::Processing => 'Error',
ScanAttemptResult::Accepted => 'Verificado',
ScanAttemptResult::InvalidQr => 'QR no pertenece al evento',
ScanAttemptResult::TicketNotFound => 'QR no pertenece al evento',
ScanAttemptResult::TicketNotFound => 'Error',
ScanAttemptResult::CategoryForbidden => 'Error',
ScanAttemptResult::AlreadyScanned => 'Usado',
ScanAttemptResult::Expired => 'Vencido',

View File

@@ -9,7 +9,6 @@ use App\Domains\Commerce\Purchase\Models\PurchaseItem;
use App\Domains\Commerce\Purchase\Services\PurchaseRefundSummaryService;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Models\TicketRefund;
use Illuminate\Database\Eloquent\Builder;
@@ -24,7 +23,6 @@ class AdminAppTicketService
...TicketValidityResolver::RELATIONS,
...TicketPresentationResolver::RELATIONS,
'tenant',
'event',
'user',
'scannerUser',
'sourceCatalogItem.category',
@@ -43,9 +41,9 @@ class AdminAppTicketService
/**
* @param array{q?: string|null, category?: string|null, product?: string|null, type?: string|null, date?: string|null, size?: string|null, status?: string|null, page?: int, per_page?: int, sort_by?: string|null, sort_direction?: string|null} $filters
*/
public function search(Tenant $tenant, array $filters = []): AdminAppTicketResult
public function search(Tenant $tenant, array $filters = [], ?int $eventId = null): AdminAppTicketResult
{
$query = $this->baseQuery($tenant, $filters);
$query = $this->baseQuery($tenant, $filters, $eventId);
$countQuery = clone $query;
$databaseSorted = $this->applyDatabaseSort($query, $tenant, $filters);
@@ -79,7 +77,7 @@ class AdminAppTicketService
tickets: $tickets,
scannedTickets: $scannedTickets,
totalTickets: $totalTickets,
refundedTotal: $this->refundSummaryService->totalForTenant($tenant),
refundedTotal: $this->refundSummaryService->totalForTenant($tenant, $eventId),
);
}
@@ -87,9 +85,9 @@ class AdminAppTicketService
* @param array{q?: string|null, category?: string|null, product?: string|null, type?: string|null, date?: string|null, size?: string|null, status?: string|null, sort_by?: string|null, sort_direction?: string|null} $filters
* @return Collection<int, Ticket>
*/
public function ticketsForExport(Tenant $tenant, array $filters = []): Collection
public function ticketsForExport(Tenant $tenant, array $filters = [], ?int $eventId = null): Collection
{
$query = $this->baseQuery($tenant, $filters);
$query = $this->baseQuery($tenant, $filters, $eventId);
$databaseSorted = $this->applyDatabaseSort($query, $tenant, $filters);
$tickets = $query
->with(self::RELATIONS)
@@ -99,11 +97,10 @@ class AdminAppTicketService
return $databaseSorted ? $tickets : $this->sortTickets($tickets, $tenant, $filters);
}
public function cancel(Tenant $tenant, int $ticketId): Ticket
public function cancel(Tenant $tenant, int $ticketId, ?int $eventId = null): Ticket
{
return DB::transaction(function () use ($tenant, $ticketId): Ticket {
$ticket = Ticket::query()
->where('tenant_code', $tenant->codigo)
return DB::transaction(function () use ($tenant, $ticketId, $eventId): Ticket {
$ticket = $this->ticketsQuery($tenant, $eventId)
->lockForUpdate()
->findOrFail($ticketId);
@@ -126,10 +123,9 @@ class AdminAppTicketService
* partial: string|null,
* }
*/
public function calculateRefund(Tenant $tenant, int $ticketId): array
public function calculateRefund(Tenant $tenant, int $ticketId, ?int $eventId = null): array
{
$ticket = Ticket::query()
->where('tenant_code', $tenant->codigo)
$ticket = $this->ticketsQuery($tenant, $eventId)
->findOrFail($ticketId);
if (! $ticket->can_refund()) {
@@ -147,20 +143,19 @@ class AdminAppTicketService
]);
}
$configuration = $ticket->event_id === null ? $tenant : $ticket->event;
$unitPrice = (float) $purchaseItem->precio_unitario;
$itemTotal = (float) $purchaseItem->total;
$itemRefundedAmount = $this->refundedAmountForPurchaseItem($purchaseItem);
$remainingItemAmount = max(0.0, round($itemTotal - $itemRefundedAmount, 2));
$total = null;
if ($configuration->allow_refund() && $configuration->allow_ticket_total_refund && $unitPrice <= $remainingItemAmount) {
if ($tenant->allow_refund() && $tenant->allow_ticket_total_refund && $unitPrice <= $remainingItemAmount) {
$total = number_format($unitPrice, 2, '.', '');
}
$partial = null;
if ($configuration->allow_refund() && $configuration->allow_partial_refund()) {
$partialAmount = $this->refundAmount($purchaseItem, $configuration, 'partial');
if ($tenant->allow_refund() && $tenant->allow_partial_refund()) {
$partialAmount = $this->refundAmount($purchaseItem, $tenant, 'partial');
if ($partialAmount <= $remainingItemAmount) {
$partial = number_format($partialAmount, 2, '.', '');
}
@@ -179,13 +174,11 @@ class AdminAppTicketService
?User $createdBy = null,
): Ticket {
return DB::transaction(function () use ($tenant, $ticketId, $refundType, $createdBy): Ticket {
$ticket = Ticket::query()
->where('tenant_code', $tenant->codigo)
$ticket = $this->ticketsQuery($tenant, $createdBy?->event_id)
->lockForUpdate()
->findOrFail($ticketId);
$configuration = $ticket->event_id === null ? $tenant : $ticket->event;
$this->ensureRefundIsAllowed($configuration, $refundType);
$this->ensureRefundIsAllowed($tenant, $refundType);
if (! $ticket->can_refund()) {
if ($ticket->status !== Ticket::STATUS_ACTIVE) {
@@ -209,7 +202,7 @@ class AdminAppTicketService
]);
}
$refundAmount = $this->refundAmount($purchaseItem, $configuration, $refundType);
$refundAmount = $this->refundAmount($purchaseItem, $tenant, $refundType);
$refundedAmount = round(
$this->refundedAmountForPurchaseItem($purchaseItem) + $refundAmount,
2,
@@ -290,7 +283,7 @@ class AdminAppTicketService
->sum('amount'), 2);
}
private function ensureRefundIsAllowed(Tenant|Event $tenant, string $refundType): void
private function ensureRefundIsAllowed(Tenant $tenant, string $refundType): void
{
$isAllowed = match ($refundType) {
TicketRefund::TYPE_PARTIAL => $tenant->allow_refund() && $tenant->allow_partial_refund(),
@@ -304,7 +297,7 @@ class AdminAppTicketService
}
}
private function refundAmount(PurchaseItem $purchaseItem, Tenant|Event $tenant, string $refundType): float
private function refundAmount(PurchaseItem $purchaseItem, Tenant $tenant, string $refundType): float
{
$ticketAmount = (float) $purchaseItem->precio_unitario;
@@ -318,12 +311,11 @@ class AdminAppTicketService
* @param array{q?: string|null, category?: string|null, product?: string|null, type?: string|null, date?: string|null, size?: string|null, status?: string|null, page?: int, per_page?: int} $filters
* @return Builder<Ticket>
*/
private function baseQuery(Tenant $tenant, array $filters): Builder
private function baseQuery(Tenant $tenant, array $filters, ?int $eventId = null): Builder
{
$search = trim((string) ($filters['q'] ?? ''));
$query = Ticket::query()
->where('tenant_code', $tenant->codigo)
$query = $this->ticketsQuery($tenant, $eventId)
->when($search !== '', function (Builder $query) use ($search): void {
$this->applySearchFilter($query, $search);
})
@@ -363,6 +355,14 @@ class AdminAppTicketService
return $query;
}
/** @return Builder<Ticket> */
private function ticketsQuery(Tenant $tenant, ?int $eventId): Builder
{
return Ticket::query()
->where('tenant_code', $tenant->codigo)
->when($eventId !== null, fn (Builder $query): Builder => $query->where('tickets.event_id', $eventId));
}
/** @param Builder<Ticket> $query */
private function applySearchFilter(Builder $query, string $search): void
{

View File

@@ -0,0 +1,89 @@
<?php
namespace App\Domains\Ticketing\Ticket\Services;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Ticket\Models\EntryReservation;
use Illuminate\Support\Collection;
use PhpOffice\PhpSpreadsheet\Cell\DataType;
use PhpOffice\PhpSpreadsheet\Shared\Date;
use PhpOffice\PhpSpreadsheet\Spreadsheet;
use PhpOffice\PhpSpreadsheet\Style\Alignment;
use PhpOffice\PhpSpreadsheet\Style\Fill;
use PhpOffice\PhpSpreadsheet\Writer\Xlsx;
use Symfony\Component\HttpFoundation\StreamedResponse;
class EntryReservationExcelService
{
public function __construct(private readonly EntryReservationReportService $report) {}
/** @param Collection<int, EntryReservation> $reservations */
public function download(Tenant $tenant, Collection $reservations, string $timeZone): StreamedResponse
{
$generatedAt = now();
$rows = $this->report->rows($reservations);
$spreadsheet = new Spreadsheet;
$spreadsheet->getProperties()
->setCreator('Shopit')
->setTitle('Reservas de tickets')
->setSubject($tenant->nombre);
$sheet = $spreadsheet->getActiveSheet();
$sheet->setTitle('Reservas');
$sheet->fromArray([
'Ítem',
'Variante',
'ID',
'Fecha',
'Importe',
'Pago',
], null, 'A1');
foreach ($rows as $index => $reservation) {
$row = $index + 2;
foreach (['A' => 'item', 'B' => 'variant'] as $column => $key) {
$sheet->setCellValueExplicit("{$column}{$row}", $reservation[$key], DataType::TYPE_STRING);
}
$sheet->setCellValueExplicit(
"C{$row}",
$reservation['ticket_id'] === null ? '-' : (string) $reservation['ticket_id'],
DataType::TYPE_STRING,
);
$sheet->setCellValue(
"D{$row}",
Date::dateTimeToExcel($reservation['fecha_reserva']->copy()->timezone($timeZone)),
);
if ($reservation['importe'] !== null) {
$sheet->setCellValue("E{$row}", (float) $reservation['importe']);
}
$sheet->setCellValueExplicit("F{$row}", $reservation['pago'], DataType::TYPE_STRING);
}
$lastRow = max(2, $rows->count() + 1);
$sheet->getStyle("D2:D{$lastRow}")->getNumberFormat()->setFormatCode('dd/mm/yyyy hh:mm');
$sheet->getStyle("E2:E{$lastRow}")->getNumberFormat()->setFormatCode('$ #,##0.00');
$sheet->getStyle('A1:F1')->applyFromArray([
'font' => ['bold' => true, 'color' => ['rgb' => 'FFFFFF']],
'fill' => [
'fillType' => Fill::FILL_SOLID,
'startColor' => ['rgb' => '26382E'],
],
'alignment' => ['vertical' => Alignment::VERTICAL_CENTER],
]);
$sheet->getRowDimension(1)->setRowHeight(24);
$sheet->freezePane('A2');
$sheet->setAutoFilter("A1:F{$lastRow}");
foreach (['A' => 30, 'B' => 60, 'C' => 16, 'D' => 20, 'E' => 16, 'F' => 18] as $column => $width) {
$sheet->getColumnDimension($column)->setWidth($width);
}
$filename = 'reservas_tickets_'.$tenant->codigo.'_'
.$generatedAt->copy()->timezone($timeZone)->format('Ymd_His').'.xlsx';
return response()->streamDownload(function () use ($spreadsheet): void {
(new Xlsx($spreadsheet))->save('php://output');
$spreadsheet->disconnectWorksheets();
}, $filename, [
'Content-Type' => 'application/vnd.openxmlformats-officedocument.spreadsheetml.sheet',
]);
}
}

View File

@@ -0,0 +1,65 @@
<?php
namespace App\Domains\Ticketing\Ticket\Services;
use App\Domains\Commerce\Catalog\Enums\InventoryPolicy;
use App\Domains\Commerce\Catalog\Models\CatalogItem;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Ticket\Enums\EntryReservationPaymentType;
use Illuminate\Database\Eloquent\Builder;
class EntryReservationFormService
{
public function get(Tenant $tenant, ?int $eventId = null): array
{
$items = CatalogItem::query()->where('tenant_code', $tenant->codigo)->where('has_tickets', true)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId))
->with([
'inventory', 'itemAttributes.attribute.options',
'variants' => fn ($query) => $query->orderBy('id'),
'variants.inventory', 'variants.definitions.itemAttribute.attribute.options',
'variants.eventDates', 'variants.eventDate',
])->orderBy('nombre')->orderBy('id')->get();
$filterItems = $items->map(fn (CatalogItem $item): array => [
'id' => $item->id, 'name' => $item->nombre,
'variants' => $item->variants->map(function (Variant $variant) use ($item): array {
$variant->setRelation('catalogItem', $item);
return ['id' => $variant->id, 'label' => $variant->getSelectionLabel()];
})->values()->all(),
])->values()->all();
$reservationEventId = $eventId ?? $tenant->active_event_id;
$available = $items->filter(fn (CatalogItem $item): bool => ! $item->isBundle()
&& $item->isSaleOpen()
&& ($reservationEventId === null || $item->event_id === $reservationEventId))
->map(function (CatalogItem $item): ?array {
$tracked = $item->inventory_policy !== InventoryPolicy::Unlimited;
$requiresVariant = $item->variants->isNotEmpty();
$variants = $item->variants->filter(function (Variant $variant) use ($item, $tracked): bool {
$variant->setRelation('catalogItem', $item);
return $variant->isSellable()
&& (! $tracked || ($variant->inventory?->availableStock() ?? 0) > 0);
})->map(fn (Variant $variant): array => [
'id' => $variant->id, 'label' => $variant->getSelectionLabel(),
'price' => $variant->getPrice(),
'available_stock' => $tracked ? $variant->inventory->availableStock() : null,
])->values()->all();
if (($requiresVariant && $variants === [])
|| (! $requiresVariant && $tracked && ($item->inventory?->availableStock() ?? 0) <= 0)) {
return null;
}
return [
'id' => $item->id, 'name' => $item->nombre, 'price' => $item->getPrice(),
'requires_variant' => $requiresVariant, 'variants' => $variants,
'available_stock' => $tracked ? $item->inventory?->availableStock() : null,
];
})->filter()->values()->all();
return ['payment_types' => EntryReservationPaymentType::options(), 'items' => $available, 'filter_items' => $filterItems];
}
}

View File

@@ -0,0 +1,51 @@
<?php
namespace App\Domains\Ticketing\Ticket\Services;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Ticket\Models\EntryReservation;
use Barryvdh\DomPDF\Facade\Pdf;
use Barryvdh\DomPDF\PDF as DomPdf;
use Illuminate\Http\Response;
use Illuminate\Support\Collection;
class EntryReservationPdfService
{
public function __construct(private readonly EntryReservationReportService $report) {}
/** @param Collection<int, EntryReservation> $reservations */
public function download(Tenant $tenant, Collection $reservations, string $timeZone): Response
{
$generatedAt = now();
$rows = $this->report->rows($reservations);
$pdf = Pdf::loadView('pdf.adminapp.entry-reservations', [
'tenant' => $tenant,
'reservations' => $rows,
'generatedAt' => $generatedAt,
'timeZone' => $timeZone,
])->setPaper('a4', 'landscape');
$this->addPageNumbers($pdf);
return $pdf->download(
'reservas_tickets_'.$tenant->codigo.'_'
.$generatedAt->copy()->timezone($timeZone)->format('Ymd_His').'.pdf'
);
}
private function addPageNumbers(DomPdf $pdf): void
{
$pdf->render();
$domPdf = $pdf->getDomPDF();
$font = $domPdf->getFontMetrics()->getFont('DejaVu Sans');
$domPdf->getCanvas()->page_text(
385,
575,
'Página {PAGE_NUM} de {PAGE_COUNT}',
$font,
7,
[0.48, 0.52, 0.49],
);
}
}

View File

@@ -0,0 +1,21 @@
<?php
namespace App\Domains\Ticketing\Ticket\Services;
use App\Domains\Commerce\Catalog\Models\CatalogItem;
use App\Domains\Commerce\Catalog\Models\Inventory;
use App\Domains\Commerce\Catalog\Models\Variant;
use Illuminate\Validation\ValidationException;
interface EntryReservationPolicy
{
/**
* Validate additional rules after selections are resolved and locked, before
* stock or tickets change. Idempotent replays do not run this validation.
*
* @param array<int, array{item: CatalogItem, variant: Variant|null, inventory: Inventory|null}> $selections
*
* @throws ValidationException
*/
public function validate(array $selections): void;
}

View File

@@ -0,0 +1,21 @@
<?php
namespace App\Domains\Ticketing\Ticket\Services;
use App\Domains\Ticketing\Ticket\Models\EntryReservation;
use Illuminate\Support\Collection;
class EntryReservationReportService
{
public function rows(Collection $reservations): Collection
{
return $reservations->values()->map(fn (EntryReservation $reservation): array => [
'item' => $reservation->catalogItem?->nombre ?? '-',
'variant' => $reservation->variant?->getSelectionLabel() ?? 'Sin variante',
'ticket_id' => $reservation->ticket_id,
'fecha_reserva' => $reservation->fecha_reserva,
'importe' => $reservation->importe,
'pago' => $reservation->tipo_pago->label(),
]);
}
}

View File

@@ -0,0 +1,313 @@
<?php
namespace App\Domains\Ticketing\Ticket\Services;
use App\Domains\Commerce\Catalog\Enums\InventoryPolicy;
use App\Domains\Commerce\Catalog\Models\CatalogItem;
use App\Domains\Commerce\Catalog\Models\Inventory;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Ticketing\Ticket\Enums\EntryReservationPaymentType;
use App\Domains\Ticketing\Ticket\Exceptions\TicketGenerationException;
use App\Domains\Ticketing\Ticket\Models\EntryReservation;
use App\Domains\Ticketing\Ticket\Models\ReservationBatch;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use Illuminate\Database\Eloquent\Builder;
use Illuminate\Database\Eloquent\Collection;
use Illuminate\Pagination\LengthAwarePaginator;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Validator;
use Illuminate\Validation\Rule;
use Illuminate\Validation\ValidationException;
/** Application workflow for one ticket per selected catalog item / variant. */
class EntryReservationService
{
private const SELECTION_RELATIONS = [
'catalogItem',
'variant.catalogItem.itemAttributes.attribute.options',
'variant.definitions.itemAttribute.attribute.options',
'variant.eventDates',
'variant.eventDate',
];
public function __construct(private readonly TicketGeneratorService $tickets) {}
/**
* @param array{catalog_item_id?: int, variant_id?: int, tipo_pago?: string|null, page?: int, per_page?: int} $filters
* @return LengthAwarePaginator<EntryReservation>
*/
public function reservations(User $user, array $filters = []): LengthAwarePaginator
{
return $this->reservationsQuery($user, $filters)
->paginate(perPage: $filters['per_page'] ?? 15, page: $filters['page'] ?? 1)
->withQueryString();
}
/**
* @param array{catalog_item_id?: int, variant_id?: int, tipo_pago?: string|null} $filters
* @return Collection<int, EntryReservation>
*/
public function reservationsForExport(User $user, array $filters = []): Collection
{
return $this->reservationsQuery($user, $filters)->get();
}
public function reservationTicket(User $user, int $reservationId, ?int $catalogItemId = null): Ticket
{
$reservation = $this->reservationsQuery($user, ['catalog_item_id' => $catalogItemId])
->whereKey($reservationId)->whereNotNull('ticket_id')
->with(['ticket' => fn ($query) => $query->with([
...TicketValidityResolver::RELATIONS,
...TicketPresentationResolver::RELATIONS,
])])->firstOrFail();
return $reservation->ticket;
}
public function cancel(User $user, int $reservationId, ?int $catalogItemId = null): void
{
DB::transaction(function () use ($user, $reservationId, $catalogItemId): void {
$reservation = $this->reservationsQuery($user, ['catalog_item_id' => $catalogItemId])
->whereKey($reservationId)->lockForUpdate()->firstOrFail();
if ($reservation->ticket_id !== null) {
$ticket = Ticket::query()->whereKey($reservation->ticket_id)->lockForUpdate()->firstOrFail();
if (! $ticket->can_cancel()) {
throw ValidationException::withMessages([
'status' => 'El ticket debe estar activo para poder cancelar la reserva.',
]);
}
$ticket->markAsCancelled();
$ticket->save();
}
if ($reservation->inventory_id !== null) {
$inventory = Inventory::query()->whereKey($reservation->inventory_id)->lockForUpdate()->firstOrFail();
$inventory->releaseEntry(1);
}
$reservation->delete();
}, 3);
}
/**
* Each row reserves one unit. Prices and inventory are resolved on the server.
*
* @param list<array{catalog_item_id: int, variant_id?: int|null, tipo_pago: string}> $rows
* @return Collection<int, EntryReservation>
*/
public function reserve(User $user, string $key, array $rows, ?EntryReservationPolicy $policy = null): Collection
{
$validated = Validator::make(['idempotency_key' => $key, 'rows' => $rows], [
'idempotency_key' => ['required', 'uuid'],
'rows' => ['required', 'array', 'list', 'min:1', 'max:100'],
'rows.*' => ['required', 'array:catalog_item_id,variant_id,tipo_pago'],
'rows.*.catalog_item_id' => ['required', 'integer', 'min:1'],
'rows.*.variant_id' => ['sometimes', 'nullable', 'integer', 'min:1'],
'rows.*.tipo_pago' => ['required', Rule::enum(EntryReservationPaymentType::class)],
])->validate();
$rows = array_map(fn (array $row): array => [
'catalog_item_id' => (int) $row['catalog_item_id'],
'variant_id' => isset($row['variant_id']) ? (int) $row['variant_id'] : null,
'tipo_pago' => $row['tipo_pago'],
], $validated['rows']);
$hash = $this->requestHash($rows);
return DB::transaction(function () use ($user, $key, $rows, $hash, $policy): Collection {
User::query()->whereKey($user->id)->lockForUpdate()->firstOrFail();
$tenant = $user->tenant()->firstOrFail();
$batch = ReservationBatch::query()->where('user_id', $user->id)
->where('idempotency_key', $key)->lockForUpdate()->first();
if ($batch !== null) {
abort_unless($batch->tenant_code === $tenant->codigo && $this->matchesBatch($batch, $rows, $hash),
409, 'La clave de envío ya fue utilizada con otra selección.');
// A scope change must not expose any part of a previously submitted batch.
if ($user->event_id !== null) {
abort_if($batch->reservations()->withTrashed()
->whereDoesntHave('catalogItem', fn (Builder $query) => $query
->where('tenant_code', $user->tenant_codigo)
->where('event_id', $user->event_id))
->exists(), 403);
}
return $batch->reservations()->with([...self::SELECTION_RELATIONS, 'ticket'])->orderBy('id')->get();
}
$eventId = $user->event_id ?? $tenant->active_event_id;
$items = CatalogItem::query()->where('tenant_code', $tenant->codigo)
->when($eventId !== null, fn (Builder $query) => $query->where('event_id', $eventId))
->whereKey(array_column($rows, 'catalog_item_id'))->orderBy('id')->lockForUpdate()->get()->keyBy('id');
$variants = Variant::query()->whereIn('catalog_item_id', $items->keys())
->whereKey(array_filter(array_column($rows, 'variant_id')))
->orderBy('id')->lockForUpdate()->get()->keyBy('id');
$variants->load(['eventDates', 'eventDate']);
$inventoryIds = $items->pluck('inventory_id')->merge($variants->pluck('inventory_id'))->filter()->unique();
$inventories = Inventory::query()->whereKey($inventoryIds)->orderBy('id')->lockForUpdate()->get()->keyBy('id');
$selections = [];
$requirements = [];
$errors = [];
foreach ($rows as $index => $row) {
$item = $items->get($row['catalog_item_id']);
$variant = $row['variant_id'] !== null ? $variants->get($row['variant_id']) : null;
$field = $this->selectionField($row, $index);
if ($item === null || ! $item->has_tickets || ! $item->isSaleOpen()) {
$errors[$field] = 'El ítem no está disponible para reservar tickets en este catálogo.';
continue;
}
if ($item->isBundle()) {
$errors[$field] = 'Seleccioná el ítem que emite el ticket; los paquetes requieren reservar sus componentes.';
continue;
}
if ($row['variant_id'] !== null) {
if ($variant === null || $variant->catalog_item_id !== $item->id) {
$errors[$field] = 'La variante no pertenece al ítem del catálogo seleccionado.';
continue;
}
$variant->setRelation('catalogItem', $item);
if (! $variant->isSellable()) {
$errors[$field] = 'La variante ya no está disponible.';
continue;
}
} elseif ($item->variants()->exists()) {
$errors["rows.{$index}.variant_id"] = 'Seleccioná una variante del ítem del catálogo.';
continue;
}
$selection = $variant ?? $item;
$inventory = $inventories->get($selection->inventory_id);
$tracked = $item->inventory_policy !== InventoryPolicy::Unlimited;
if ($inventory === null && ($selection->inventory_id !== null || $tracked)) {
$errors[$field] = 'La selección no tiene un inventario disponible.';
continue;
}
$selection->setRelation('inventory', $inventory);
$selections[$index] = ['item' => $item, 'variant' => $variant, 'inventory' => $inventory];
if ($inventory !== null) {
$requirement = $requirements[$inventory->id] ?? ['quantity' => 0, 'tracked' => false];
$requirements[$inventory->id] = [
'quantity' => $requirement['quantity'] + 1,
'tracked' => $requirement['tracked'] || $tracked,
];
}
}
if ($errors !== []) {
throw ValidationException::withMessages($errors);
}
$policy?->validate($selections);
foreach ($requirements as $inventoryId => $requirement) {
if ($requirement['tracked'] && $inventories[$inventoryId]->availableStock() < $requirement['quantity']) {
foreach ($selections as $index => $selection) {
if ($selection['inventory']?->id === $inventoryId) {
$errors[$this->selectionField($rows[$index], $index)] = 'No hay stock suficiente para reservar la selección.';
}
}
}
}
if ($errors !== []) {
throw ValidationException::withMessages($errors);
}
$batch = ReservationBatch::query()->create([
'user_id' => $user->id, 'tenant_code' => $tenant->codigo,
'idempotency_key' => $key, 'request_hash' => $hash,
]);
foreach ($requirements as $inventoryId => $requirement) {
$inventories[$inventoryId]->reserveEntry($requirement['quantity'], $requirement['tracked']);
}
$reservations = new Collection;
foreach ($selections as $index => $selection) {
$item = $selection['item'];
$variant = $selection['variant'];
try {
$ticket = $this->tickets->generate($item, $user, 1, $variant?->id)->sole();
} catch (TicketGenerationException $exception) {
throw ValidationException::withMessages([
$this->selectionField($rows[$index], $index) => 'No se pudo emitir el ticket. '.$exception->getMessage(),
]);
}
$payment = EntryReservationPaymentType::from($rows[$index]['tipo_pago']);
$reservation = EntryReservation::query()->create([
'batch_id' => $batch->id, 'ticket_id' => $ticket->id,
'catalog_item_id' => $variant?->catalog_item_id ?? $item->id,
'variant_id' => $variant?->id, 'inventory_id' => $selection['inventory']?->id,
'fecha_reserva' => now(), 'tipo_pago' => $payment,
'importe' => $payment === EntryReservationPaymentType::Free ? 0 : ($variant ?? $item)->getPrice(),
]);
$reservations->push($reservation->setRelation('ticket', $ticket)
->setRelation('catalogItem', $item)->setRelation('variant', $variant));
}
return $reservations->loadMissing(self::SELECTION_RELATIONS);
}, 3);
}
/** @param array<string, mixed> $filters */
private function reservationsQuery(User $user, array $filters = []): Builder
{
abort_unless($user->tenant_codigo !== null && $user->tenant_codigo !== '', 403);
return EntryReservation::query()
->whereHas('catalogItem', fn (Builder $query) => $query->where('tenant_code', $user->tenant_codigo)
->when($user->event_id !== null, fn (Builder $query) => $query->where('event_id', $user->event_id)))
->when($filters['catalog_item_id'] ?? null, fn (Builder $query, int $id) => $query->where('catalog_item_id', $id))
->when($filters['variant_id'] ?? null, fn (Builder $query, int $id) => $query->where('variant_id', $id))
->when($filters['tipo_pago'] ?? null, fn (Builder $query, string $type) => $query->where('tipo_pago', $type))
->with(self::SELECTION_RELATIONS)
->orderByDesc('fecha_reserva')->orderByDesc('id');
}
/** @param array{variant_id: int|null} $row */
private function selectionField(array $row, int $index): string
{
return "rows.{$index}.".($row['variant_id'] !== null ? 'variant_id' : 'catalog_item_id');
}
/** @param list<array{catalog_item_id: int, variant_id: int|null, tipo_pago: string}> $rows */
private function requestHash(array $rows): string
{
$normalized = collect($rows)->sortBy([
['catalog_item_id', 'asc'], ['variant_id', 'asc'], ['tipo_pago', 'asc'],
])->values()->all();
return hash('sha256', json_encode($normalized, JSON_THROW_ON_ERROR));
}
/** @param list<array{catalog_item_id: int, variant_id: int|null, tipo_pago: string}> $rows */
private function matchesBatch(ReservationBatch $batch, array $rows, string $hash): bool
{
if (hash_equals($batch->request_hash, $hash)) {
return true;
}
if (collect($rows)->contains(fn (array $row) => $row['variant_id'] === null)) {
return false;
}
// Older batches fingerprinted variant and payment only. Check the persisted
// catalog IDs too, so compatibility cannot replay a different catalog item.
$legacyRows = collect($rows)->map(fn (array $row) => [
'variant_id' => $row['variant_id'], 'tipo_pago' => $row['tipo_pago'],
])->sortBy('variant_id')->values()->all();
$legacyHash = hash('sha256', json_encode($legacyRows, JSON_THROW_ON_ERROR));
if (! hash_equals($batch->request_hash, $legacyHash)) {
return false;
}
$storedRows = $batch->reservations()->withTrashed()->get()->map(fn (EntryReservation $reservation) => [
'catalog_item_id' => $reservation->catalog_item_id,
'variant_id' => $reservation->variant_id,
'tipo_pago' => $reservation->tipo_pago->value,
])->all();
return hash_equals($this->requestHash($storedRows), $hash);
}
}

View File

@@ -3,7 +3,6 @@
namespace App\Domains\Ticketing\Ticket\Services;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Ticketing\Ticket\Enums\ScanAttemptResult;
use App\Domains\Ticketing\Ticket\Models\ScanAttempt;
use App\Domains\Ticketing\Ticket\Models\Ticket;
@@ -28,7 +27,6 @@ class ScannerTicketService
->with('ticket.sourceCatalogItem.category')
->where('tenant_code', $scanner->tenant_codigo)
->where('scanner_user_id', $scanner->getKey())
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)))
->when($search !== '', function (Builder $query) use ($search): void {
$attemptedAtDate = $this->parseSearchDate($search);
@@ -62,7 +60,6 @@ class ScannerTicketService
->with('ticket.sourceCatalogItem.category')
->where('tenant_code', $scanner->tenant_codigo)
->where('scanner_user_id', $scanner->getKey())
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)))
->when($search !== '', function (Builder $query) use ($search): void {
$attemptedAtDate = $this->parseSearchDate($search);
$attemptedAtDayMonth = $this->parseSearchDayMonth($search);
@@ -109,7 +106,6 @@ class ScannerTicketService
->with('ticket')
->where('tenant_code', $scanner->tenant_codigo)
->where('scanner_user_id', $scanner->getKey())
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)))
->findOrFail($scanAttemptId);
$scanAttempt->ticket?->loadMissing($this->relations());
@@ -117,11 +113,6 @@ class ScannerTicketService
return $scanAttempt;
}
private function eventId(User $scanner): ?int
{
return app(EventScopeService::class)->eventId($scanner);
}
private function parseSearchDate(string $search): ?string
{
if (preg_match('/^(\d{4})-(\d{2})-(\d{2})$/', $search, $matches) === 1) {
@@ -163,8 +154,7 @@ class ScannerTicketService
{
$query = $this->baseQuery()
->where('tenant_code', $scanner->tenant_codigo)
->where('ticket', $ticketUuid)
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)));
->where('ticket', $ticketUuid);
if ($this->requiresCategoryValidation($scanner)) {
$categoryIds = $this->scannerCategoryIds($scanner);
@@ -188,7 +178,6 @@ class ScannerTicketService
$scanAttempt = ScanAttempt::query()->create([
'tenant_code' => $scanner->tenant_codigo,
'scanner_user_id' => $scanner->getKey(),
'event_id' => $this->eventId($scanner),
'data' => $this->serializeScannedData($scannedData),
'result' => ScanAttemptResult::Processing,
]);
@@ -211,7 +200,6 @@ class ScannerTicketService
$ticket = $this->baseQuery()
->where('tenant_code', $scanner->tenant_codigo)
->where('ticket', $scannedData)
->when($this->eventId($scanner) !== null, fn (Builder $query) => $query->where('event_id', $this->eventId($scanner)))
->lockForUpdate()
->firstOrFail();
$ticketId = (int) $ticket->getKey();

View File

@@ -89,6 +89,10 @@ Bajo `/v1/adminapp/tenant`, protegido por `auth:sanctum`, `adminapp.tenant` y el
`TicketPdfService` genera la descarga y `TicketResource`/`ValidityTimeResource` definen las respuestas.
Si el administrador autenticado tiene `event_id`, las consultas de Tickets y sus exportaciones se limitan a `tickets.event_id` dentro del tenant. Los contadores usan el mismo alcance y el total reembolsado se limita a las compras del evento. Sin `event_id`, se conserva el alcance por tenant.
La cancelación, el cálculo de reembolso y el reembolso buscan el ticket dentro de ese alcance antes de validar o ejecutar la operación. Un ticket de otro evento o sin evento devuelve 404 para un administrador con evento asignado. El alcance se obtiene del usuario autenticado, no de los parámetros del cliente.
## Dependencias y reglas
Depende de `Purchase`, `Catalog`, `Tenant` y `Auth`. La generación debe ser idempotente ante reintentos del evento. `TicketNotAvailableException` y `TicketGenerationException` separan indisponibilidad de errores de generación.

View File

@@ -1,11 +1,24 @@
<?php
use App\Domains\Ticketing\Ticket\Controllers\AdminApp\EntryReservationController;
use App\Domains\Ticketing\Ticket\Controllers\AdminApp\TicketController;
use Illuminate\Support\Facades\Route;
Route::prefix('v1/adminapp/tenant')
->middleware(['auth:sanctum', 'adminapp.tenant'])
->group(function (): void {
Route::prefix('entry-reservations')->middleware('tenant.menu:adminapp.ticket-reservations')
->group(function (): void {
Route::get('form', [EntryReservationController::class, 'form'])->name('adminapp.entry-reservations.form');
Route::get('/', [EntryReservationController::class, 'index'])->name('adminapp.entry-reservations.index');
Route::post('/', [EntryReservationController::class, 'store'])->name('adminapp.entry-reservations.store');
Route::get('pdf', [EntryReservationController::class, 'downloadPdf'])->name('adminapp.entry-reservations.pdf');
Route::get('excel', [EntryReservationController::class, 'downloadExcel'])->name('adminapp.entry-reservations.excel');
Route::get('{reservation}/ticket/pdf', [EntryReservationController::class, 'downloadTicketPdf'])
->whereNumber('reservation')->name('adminapp.entry-reservations.ticket.pdf');
Route::delete('{reservation}', [EntryReservationController::class, 'destroy'])
->whereNumber('reservation')->name('adminapp.entry-reservations.destroy');
});
Route::get('tickets', [TicketController::class, 'index'])
->middleware('tenant.menu:adminapp.tickets')
->name('adminapp.tickets.index');

View File

@@ -2,7 +2,6 @@
namespace App\Http\Middleware;
use App\Domains\Core\Auth\Services\AdminAppAccessService;
use App\Domains\Core\Authorization\Enums\RoleCode;
use Closure;
use Illuminate\Auth\Access\AuthorizationException;
@@ -11,12 +10,10 @@ use Symfony\Component\HttpFoundation\Response;
class EnsureAdminAppTenant
{
public function __construct(private readonly AdminAppAccessService $accessService) {}
/**
* Ensure the authenticated user is an AdminApp user bound to a tenant.
*/
public function handle(Request $request, Closure $next, string $access = 'tenant'): Response
public function handle(Request $request, Closure $next): Response
{
$user = $request->user();
@@ -24,9 +21,6 @@ class EnsureAdminAppTenant
! $user
|| $user->rol_codigo !== RoleCode::AdminApp->value
|| ! $user->tenant_codigo
|| ! $this->accessService->hasValidScope($user)
// Only routes implementing event authorization may accept event administrators.
|| (! in_array($access, ['context', 'event'], true) && ! $user->isTenantAdministrator())
) {
throw new AuthorizationException;
}

View File

@@ -2,7 +2,6 @@
namespace App\Http\Middleware;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Domains\Core\Authorization\Enums\PermissionCode;
use App\Domains\Core\Authorization\Enums\RoleCode;
use Closure;
@@ -28,8 +27,6 @@ class EnsureScannerTenant
throw new AuthorizationException;
}
app(EventScopeService::class)->eventId($user);
return $next($request);
}
}

View File

@@ -2,10 +2,9 @@
namespace App\Shared\Forms\Controllers\AdminApp;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Http\Controllers\Controller;
use App\Shared\Forms\Resources\EventFormResource;
use App\Shared\Forms\Services\EventFormService;
use App\Http\Controllers\Controller;
use Illuminate\Http\Request;
class EventFormController extends Controller
@@ -16,8 +15,7 @@ class EventFormController extends Controller
{
return EventFormResource::make(
$this->eventFormService->get(
$request->user('sanctum')->tenant()->firstOrFail(),
app(EventScopeService::class)->eventId($request->user())
$request->user('sanctum')->tenant()->firstOrFail()
)
);
}

View File

@@ -2,10 +2,9 @@
namespace App\Shared\Forms\Controllers\AdminApp;
use App\Domains\Core\Auth\Services\EventScopeService;
use App\Http\Controllers\Controller;
use App\Shared\Forms\Resources\StaffFormResource;
use App\Shared\Forms\Services\StaffFormService;
use App\Http\Controllers\Controller;
use Illuminate\Http\Request;
class StaffFormController extends Controller
@@ -16,8 +15,7 @@ class StaffFormController extends Controller
{
return StaffFormResource::make(
$this->staffFormService->get(
$request->user('sanctum')->tenant()->firstOrFail(),
app(EventScopeService::class)->eventId($request->user())
$request->user('sanctum')->tenant()->firstOrFail()
)
);
}

View File

@@ -5,7 +5,7 @@ namespace App\Shared\Forms\Services;
use App\Domains\Commerce\Catalog\Models\CatalogItem;
use App\Domains\Commerce\Catalog\Models\Variant;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Desfile\Enums\EntryReservationPaymentType;
use App\Domains\Ticketing\Ticket\Enums\EntryReservationPaymentType;
class DesfileEntryReservationFormService
{

View File

@@ -4,17 +4,14 @@ namespace App\Shared\Forms\Services;
use App\Domains\Core\Tenant\Models\SocialMedia;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Event\Models\Event;
use Illuminate\Database\Eloquent\Collection;
class EventFormService
{
/** @return array{social_media: Collection<int, SocialMedia>} */
public function get(Tenant $tenant, ?int $eventId = null): array
public function get(Tenant $tenant): array
{
$event = $eventId === null ? $tenant->activeEvent
: Event::query()
->where('tenant_code', $tenant->codigo)->findOrFail($eventId);
$event = $tenant->activeEvent;
$urls = $event?->socialMedia()
->pluck('event_social_media.url', 'social_media.code') ?? collect();

View File

@@ -10,7 +10,7 @@ use Illuminate\Database\Eloquent\Collection;
class StaffFormService
{
/** @return array{categories: Collection<int, Category>} */
public function get(Tenant $tenant, ?int $eventId = null): array
public function get(Tenant $tenant): array
{
return [
'categories' => Category::query()
@@ -20,8 +20,6 @@ class StaffFormService
->orWhereHas('catalogItems', fn (Builder $items) => $items
->where('tenant_code', $tenant->codigo));
})
->when($eventId !== null, fn (Builder $query) => $query->whereHas(
'catalogItems', fn (Builder $items) => $items->where('tenant_code', $tenant->codigo)->where('event_id', $eventId)))
->orderBy('nombre')
->get(),
];

View File

@@ -12,33 +12,33 @@ use App\Shared\Forms\Controllers\AdminApp\TicketFormController;
use Illuminate\Support\Facades\Route;
Route::prefix('v1/adminapp/forms')
->middleware(['auth:sanctum', 'adminapp.tenant:event'])
->middleware(['auth:sanctum', 'adminapp.tenant'])
->group(function (): void {
Route::get('event', EventFormController::class);
Route::get(
'desfile/entry-reservation',
DesfileEntryReservationFormController::class
)->middleware('adminapp.tenant')->middleware('tenant.menu:adminapp.desfile.reservas')
)->middleware('tenant.menu:adminapp.desfile.reservas')
->name('adminapp.forms.desfile.entry-reservation');
Route::get('sale', SaleFormController::class);
Route::get('staff', StaffFormController::class);
Route::get('tickets-filter', TicketFilterFormController::class)->middleware('adminapp.tenant')
Route::get('tickets-filter', TicketFilterFormController::class)
->middleware('tenant.menu:adminapp.tickets')
->name('adminapp.forms.tickets-filter');
Route::get(
'fiesta-futbol-infantil/ticket',
TicketFormController::class
)->middleware('adminapp.tenant');
);
Route::get(
'fiesta-futbol-infantil/entry',
EntryFormController::class
)->middleware('adminapp.tenant');
);
Route::get(
'fiesta-futbol-infantil/merchandise',
MerchandiseFormController::class
)->middleware('adminapp.tenant');
);
Route::get(
'fiesta-futbol-infantil/food',
FoodFormController::class
)->middleware('adminapp.tenant');
);
});

View File

@@ -1,44 +0,0 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Support\Facades\DB;
return new class extends Migration
{
public function up(): void
{
DB::transaction(function (): void {
DB::table('tenants')
->join('events', 'events.id', '=', 'tenants.active_event_id')
->whereColumn('events.tenant_code', 'tenants.codigo')
->select('tenants.codigo', 'tenants.active_event_id')
->get()
->each(function (object $tenant): void {
DB::table('users')
->whereIn('rol_codigo', ['adminapp', 'scanner'])
->where('tenant_codigo', $tenant->codigo)
->where('admin_scope', 'tenant')
->whereNull('event_id')
->whereNull('deleted_at')
->update([
'admin_scope' => 'event',
'event_id' => $tenant->active_event_id,
'updated_at' => now(),
]);
});
// Missing or mismatched active events must not leave legacy staff with tenant-wide access.
DB::table('users')
->whereIn('rol_codigo', ['adminapp', 'scanner'])
->where('admin_scope', 'tenant')
->whereNull('event_id')
->whereNull('deleted_at')
->update(['admin_scope' => 'event', 'updated_at' => now()]);
});
}
public function down(): void
{
// Do not broaden permissions or overwrite subsequent assignments on rollback.
}
};

View File

@@ -1,38 +0,0 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::table('events', function (Blueprint $table): void {
$table->boolean('allow_ticket_refund')->default(false);
$table->boolean('allow_ticket_total_refund')->default(false);
$table->boolean('allow_ticket_partial_refund')->default(false);
$table->decimal('ticket_partial_refund_percentage', 5, 2)->default(0);
});
DB::table('tenants')->select([
'codigo', 'allow_ticket_refund', 'allow_ticket_total_refund',
'allow_ticket_partial_refund', 'ticket_partial_refund_percentage',
])->get()->each(function (object $tenant): void {
DB::table('events')->where('tenant_code', $tenant->codigo)->update([
'allow_ticket_refund' => $tenant->allow_ticket_refund,
'allow_ticket_total_refund' => $tenant->allow_ticket_total_refund,
'allow_ticket_partial_refund' => $tenant->allow_ticket_partial_refund,
'ticket_partial_refund_percentage' => $tenant->ticket_partial_refund_percentage ?? 0,
]);
});
}
public function down(): void
{
Schema::table('events', fn (Blueprint $table) => $table->dropColumn([
'allow_ticket_refund', 'allow_ticket_total_refund',
'allow_ticket_partial_refund', 'ticket_partial_refund_percentage',
]));
}
};

View File

@@ -1,22 +0,0 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Support\Facades\DB;
return new class extends Migration
{
public function up(): void
{
DB::transaction(function (): void {
$codes = ['adminapp.combos', 'adminapp.categories'];
DB::table('roles_menues')->whereIn('menu_codigo', $codes)->delete();
DB::table('tenants_menues')->whereIn('menu_code', $codes)->delete();
DB::table('menues')->whereIn('code', $codes)->delete();
});
}
public function down(): void
{
// Deprecated menus must not be restored by rollback.
}
};

View File

@@ -1,28 +0,0 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
Schema::table('scan_attempts', function (Blueprint $table): void {
$table->foreignId('event_id')->nullable()->constrained('events')->nullOnDelete();
$table->index(['scanner_user_id', 'event_id']);
});
DB::table('scan_attempts')->update([
'event_id' => DB::raw('(SELECT tickets.event_id FROM tickets WHERE tickets.id = scan_attempts.ticket_id)'),
]);
}
public function down(): void
{
Schema::table('scan_attempts', function (Blueprint $table): void {
$table->dropIndex(['scanner_user_id', 'event_id']);
$table->dropConstrainedForeignId('event_id');
});
}
};

View File

@@ -9,17 +9,20 @@ return new class extends Migration
public function up(): void
{
Schema::table('users', function (Blueprint $table): void {
// Existing administrators keep their tenant-wide access.
$table->string('admin_scope', 20)->default('tenant');
$table->foreignId('event_id')->nullable()->constrained('events')->nullOnDelete();
$table->foreignId('event_id')
->nullable()
->after('tenant_codigo')
->constrained('events')
->cascadeOnUpdate()
->restrictOnDelete();
});
}
public function down(): void
{
Schema::table('users', function (Blueprint $table): void {
$table->dropConstrainedForeignId('event_id');
$table->dropColumn('admin_scope');
$table->dropForeign(['event_id']);
$table->dropColumn('event_id');
});
}
};

View File

@@ -0,0 +1,53 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
return new class extends Migration
{
public function up(): void
{
// Validate before changing the schema, including soft-deleted reservations.
if (DB::table('desfile_entry_reservations as reservations')
->leftJoin('variantes', 'variantes.id', '=', 'reservations.variant_id')
->leftJoin('catalog_items', 'catalog_items.id', '=', 'variantes.catalog_item_id')
->whereNull('catalog_items.id')->exists()) {
throw new LogicException('No se puede determinar el catálogo de todas las reservas existentes.');
}
Schema::rename('desfile_reservation_batches', 'reservation_batches');
Schema::rename('desfile_entry_reservations', 'entry_reservations');
Schema::table('entry_reservations', function (Blueprint $table): void {
$table->foreignId('catalog_item_id')->nullable()
->constrained('catalog_items')->restrictOnDelete();
$table->unsignedBigInteger('variant_id')->nullable()->change();
});
DB::table('entry_reservations')->update([
'catalog_item_id' => DB::raw('(SELECT catalog_item_id FROM variantes WHERE variantes.id = entry_reservations.variant_id)'),
]);
Schema::table('entry_reservations', function (Blueprint $table): void {
$table->unsignedBigInteger('catalog_item_id')->nullable(false)->change();
});
}
public function down(): void
{
// The old schema cannot represent tickets without variants. Never discard them.
if (DB::table('entry_reservations')->whereNull('variant_id')->exists()) {
throw new LogicException('No se puede revertir mientras existan reservas sin variante.');
}
Schema::table('entry_reservations', function (Blueprint $table): void {
$table->dropConstrainedForeignId('catalog_item_id');
$table->unsignedBigInteger('variant_id')->nullable(false)->change();
});
Schema::rename('entry_reservations', 'desfile_entry_reservations');
Schema::rename('reservation_batches', 'desfile_reservation_batches');
}
};

View File

@@ -0,0 +1,82 @@
<?php
use Illuminate\Database\Migrations\Migration;
use Illuminate\Support\Facades\DB;
return new class extends Migration
{
private const MENU_CODE = 'adminapp.ticket-reservations';
private const TENANT_CODE = 'onticket';
public function up(): void
{
if (! DB::table('menues')->where('code', 'main.adminapp')->exists()) {
// Reference data is added by seeders on fresh installations.
return;
}
$now = now();
DB::transaction(function () use ($now): void {
DB::table('menues')->updateOrInsert(
['code' => self::MENU_CODE],
[
'label' => 'Reserva de Tickets',
'parent_menu_code' => 'main.adminapp',
'content_type' => 'dynamic',
'static_content_schema' => null,
'route' => '/admin/ticket-reservations',
'created_at' => $now,
'updated_at' => $now,
],
);
DB::table('tenants_menues')
->where('menu_code', self::MENU_CODE)
->where('tenant_code', '!=', self::TENANT_CODE)
->delete();
if (DB::table('tenants')->where('codigo', self::TENANT_CODE)->exists()) {
DB::table('tenants_menues')->updateOrInsert(
[
'tenant_code' => self::TENANT_CODE,
'menu_code' => self::MENU_CODE,
],
[
'static_content' => null,
'created_at' => $now,
'updated_at' => $now,
],
);
}
DB::table('roles')
->whereIn('codigo', ['admin', 'adminapp'])
->pluck('codigo')
->each(function (string $roleCode): void {
DB::table('roles_menues')->updateOrInsert([
'rol_codigo' => $roleCode,
'menu_codigo' => self::MENU_CODE,
]);
});
});
}
public function down(): void
{
DB::transaction(function (): void {
DB::table('tenants_menues')
->where('menu_code', self::MENU_CODE)
->delete();
DB::table('roles_menues')
->where('menu_codigo', self::MENU_CODE)
->delete();
DB::table('menues')
->where('code', self::MENU_CODE)
->delete();
});
}
};

View File

@@ -70,6 +70,18 @@ class MenuSeeder extends Seeder
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/catalog',
],
[
'code' => 'adminapp.combos',
'label' => 'Combos',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/combos',
],
[
'code' => 'adminapp.categories',
'label' => 'Categorías',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/categories',
],
[
'code' => 'adminapp.ventas',
'label' => 'Ventas',
@@ -88,6 +100,12 @@ class MenuSeeder extends Seeder
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/tickets',
],
[
'code' => 'adminapp.ticket-reservations',
'label' => 'Reserva de Tickets',
'parent_menu_code' => 'main.adminapp',
'route' => '/admin/ticket-reservations',
],
[
'code' => 'adminapp.fiesta-futbol-infantil.entradas',
'label' => 'Entradas',
@@ -230,8 +248,6 @@ class MenuSeeder extends Seeder
->whereIn('code', [
'admin.event',
'admin.catalog',
'adminapp.combos',
'adminapp.categories',
'admin.combos',
'admin.categories',
'admin.ventas',
@@ -308,6 +324,7 @@ class MenuSeeder extends Seeder
'adminapp.desfile.reservas',
];
$onTicketMenuCodes = [
'adminapp.ticket-reservations',
'event.index',
'event.category',
'event.detail',

View File

@@ -0,0 +1,57 @@
<!doctype html>
<html lang="es">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style>
@page { margin: 28px 34px 58px; }
body { color: #17211b; font-family: DejaVu Sans, sans-serif; font-size: 9px; margin: 0; }
h1 { font-size: 21px; margin: 0 0 3px; }
.subtitle { color: #66736b; margin: 0 0 18px; }
.summary { background: #eef5f1; border-left: 4px solid #198754; margin-bottom: 16px; padding: 9px 12px; }
.summary strong { font-size: 13px; }
table { border-collapse: collapse; width: 100%; }
thead { display: table-header-group; }
tr { page-break-inside: avoid; }
th { background: #26382e; color: #fff; font-size: 8px; letter-spacing: .4px; padding: 7px 6px; text-align: left; text-transform: uppercase; }
td { border-bottom: 1px solid #dfe7e2; padding: 7px 6px; vertical-align: top; }
tbody tr:nth-child(even) { background: #f7f9f8; }
.number { text-align: right; }
.empty { color: #66736b; padding: 24px; text-align: center; }
</style>
</head>
<body>
<h1>Reservas de tickets</h1>
<p class="subtitle">{{ $tenant->nombre }} · Generado el {{ $generatedAt->copy()->timezone($timeZone)->format('d/m/Y H:i') }}</p>
<div class="summary">
Reservas incluidas: <strong>{{ $reservations->count() }}</strong>
</div>
<table>
<thead>
<tr>
<th>Ítem</th>
<th>Variante</th>
<th>ID</th>
<th>Fecha</th>
<th class="number">Importe</th>
<th>Pago</th>
</tr>
</thead>
<tbody>
@forelse ($reservations as $reservation)
<tr>
<td>{{ $reservation['item'] }}</td>
<td>{{ $reservation['variant'] }}</td>
<td>{{ $reservation['ticket_id'] ?? '-' }}</td>
<td>{{ $reservation['fecha_reserva']->copy()->timezone($timeZone)->format('d/m/Y H:i') }}</td>
<td class="number">{{ $reservation['importe'] === null ? '-' : '$'.number_format((float) $reservation['importe'], 2, ',', '.') }}</td>
<td>{{ $reservation['pago'] }}</td>
</tr>
@empty
<tr><td class="empty" colspan="6">No hay reservas para los criterios seleccionados.</td></tr>
@endforelse
</tbody>
</table>
</body>
</html>

View File

@@ -1,236 +0,0 @@
<?php
namespace Tests\Feature\Auth;
use App\Domains\Core\Auth\Models\User;
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Facades\Schema;
use Illuminate\Testing\TestResponse;
use Tests\TestCase;
class AdminAppEventScopeTest extends TestCase
{
private User $user;
protected function setUp(): void
{
parent::setUp();
// Focused pre-migration schema: do not replay unrelated provisioning migrations.
// Tests\TestCase and tests/bootstrap.php enforce SQLite :memory:.
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->string('codigo')->unique();
$table->string('nombre');
$table->string('dominio');
$table->string('search_product_layout')->default('column_with_image');
$table->string('search_group_layout')->default('paginated');
});
Schema::create('events', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->string('title');
$table->timestamps();
});
Schema::create('users', function (Blueprint $table): void {
$table->id();
$table->string('nombre_apellido');
$table->string('email');
$table->string('active_email')->virtualAs('CASE WHEN deleted_at IS NULL THEN lower(email) ELSE NULL END');
$table->string('password');
$table->string('rol_codigo')->default('user');
$table->string('tenant_codigo')->nullable();
$table->softDeletes();
$table->timestamps();
$table->unique(['active_email', 'rol_codigo']);
});
Schema::create('menues', function (Blueprint $table): void {
$table->id();
$table->string('code')->unique();
$table->string('label');
$table->string('route');
$table->string('parent_menu_code')->nullable();
$table->string('content_type')->default('dynamic');
});
Schema::create('roles_menues', function (Blueprint $table): void {
$table->string('rol_codigo');
$table->string('menu_codigo');
});
Schema::create('tenants_menues', function (Blueprint $table): void {
$table->string('tenant_code');
$table->string('menu_code');
$table->json('static_content')->nullable();
$table->timestamps();
});
foreach ([
'2026_06_18_130006_create_personal_access_tokens_table.php',
'2026_07_28_000000_create_roles_and_permissions_tables.php',
'2026_07_29_000000_add_login_security_fields_to_users_table.php',
'2026_07_29_000100_create_login_attempts_table.php',
] as $file) {
(require database_path('migrations/'.$file))->up();
}
DB::table('roles')->insert(['codigo' => 'adminapp', 'nombre' => 'AdminApp']);
DB::table('tenants')->insert([
['codigo' => 'onticket', 'nombre' => 'OnTicket', 'dominio' => 'onticket.test'],
['codigo' => 'other', 'nombre' => 'Other', 'dominio' => 'other.test'],
]);
DB::table('events')->insert([
['id' => 1, 'tenant_code' => 'onticket', 'title' => 'Evento A'],
['id' => 2, 'tenant_code' => 'onticket', 'title' => 'Evento B'],
['id' => 3, 'tenant_code' => 'other', 'title' => 'Evento ajeno'],
]);
// An existing administrator must remain general after applying the new migration.
DB::table('users')->insert([
'id' => 1, 'nombre_apellido' => 'Admin', 'email' => 'admin@example.test',
'password' => Hash::make('secret123'), 'rol_codigo' => 'adminapp', 'tenant_codigo' => 'onticket',
]);
$this->scopeMigration()->up();
$this->user = User::query()->findOrFail(1);
DB::table('menues')->insert([
['code' => 'main.adminapp', 'label' => 'Administración', 'route' => '/', 'parent_menu_code' => null],
['code' => 'adminapp.ventas', 'label' => 'Ventas', 'route' => '/admin/ventas', 'parent_menu_code' => 'main.adminapp'],
]);
foreach (['main.adminapp', 'adminapp.ventas'] as $code) {
DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]);
DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]);
}
}
private function scopeMigration(): Migration
{
return require database_path('migrations/2026_09_30_000000_add_admin_scope_to_users.php');
}
private function login(array $extra = []): TestResponse
{
return $this->postJson('/api/v1/adminapp/login', [
'email' => ' ADMIN@EXAMPLE.TEST ', 'password' => 'secret123', ...$extra,
]);
}
public function test_existing_admin_keeps_general_access_after_migration(): void
{
$this->assertTrue($this->user->isTenantAdministrator());
$token = $this->login()->assertOk()->assertJsonPath('user.admin_scope', 'tenant')
->assertJsonPath('user.event_id', null)->json('token');
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertOk()
->assertJsonPath('data.event', null)->assertJsonCount(1, 'data.tenant.menues.0.submenues');
}
public function test_event_admin_logs_in_and_restores_only_its_assigned_context(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$this->assertSame(1, $this->user->event->id);
// Scope cannot be chosen by the caller during login.
$token = $this->login(['admin_scope' => 'tenant', 'event_id' => 2])->assertOk()
->assertJsonPath('user.admin_scope', 'event')->assertJsonPath('user.event_id', 1)->json('token');
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertOk()
->assertJsonPath('data.event.id', 1)->assertJsonPath('data.event.title', 'Evento A')
->assertJsonPath('data.tenant.codigo', 'onticket')
->assertJsonCount(1, 'data.tenant.menues.0.submenues');
$this->assertSame(['adminapp'], $this->user->tokens()->sole()->abilities);
}
public function test_event_admins_of_the_same_tenant_receive_the_same_assigned_menus(): void
{
DB::table('menues')->insert([
'code' => 'onticket.adminapp.event',
'label' => 'Eventos',
'route' => '/admin/event',
'parent_menu_code' => 'main.adminapp',
]);
DB::table('roles_menues')->insert([
'rol_codigo' => 'adminapp',
'menu_codigo' => 'onticket.adminapp.event',
]);
DB::table('tenants_menues')->insert([
'tenant_code' => 'onticket',
'menu_code' => 'onticket.adminapp.event',
]);
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$token = $this->login()->assertOk()->json('token');
$firstMenus = $this->withToken($token)->getJson('/api/v1/adminapp/me')
->assertOk()->json('data.tenant.menues');
$this->user->update(['event_id' => 2]);
$secondMenus = $this->withToken($token)->getJson('/api/v1/adminapp/me')
->assertOk()->json('data.tenant.menues');
$this->assertSame($firstMenus, $secondMenus);
$this->assertSame(
['adminapp.ventas', 'onticket.adminapp.event'],
collect($firstMenus[0]['submenues'])->pluck('code')->sort()->values()->all(),
);
}
public function test_invalid_scopes_never_issue_tokens_or_increment_password_failure_counts(): void
{
foreach ([
['admin_scope' => 'event', 'event_id' => null],
['admin_scope' => 'event', 'event_id' => 3],
['admin_scope' => 'tenant', 'event_id' => 1],
['admin_scope' => 'unknown', 'event_id' => null],
['admin_scope' => 'event', 'event_id' => 1, 'tenant_codigo' => null],
] as $attributes) {
$this->user->update($attributes);
$this->login()->assertUnprocessable()->assertJsonValidationErrors('email');
}
$this->assertDatabaseCount('personal_access_tokens', 0);
$this->assertSame(0, $this->user->refresh()->failed_login_attempts);
}
public function test_event_admin_cannot_access_tenant_operations_but_can_logout(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$token = $this->login()->assertOk()->json('token');
foreach (['tenant/tickets', 'tenant/administrators', 'tenant/website-extras', 'forms/tickets-filter'] as $path) {
$this->withToken($token)->getJson('/api/v1/adminapp/'.$path)->assertForbidden();
}
$this->withToken($token)->postJson('/api/v1/adminapp/tenant/administrators', [])->assertForbidden();
$this->withToken($token)->postJson('/api/logout')->assertOk();
$this->assertDatabaseCount('personal_access_tokens', 0);
}
public function test_deleting_the_event_invalidates_an_existing_token_without_promoting_the_user(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$token = $this->login()->assertOk()->json('token');
DB::table('events')->where('id', 1)->delete();
$this->assertNull($this->user->refresh()->event_id);
$this->assertSame('event', $this->user->admin_scope);
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertForbidden();
$this->withToken($token)->getJson('/api/v1/adminapp/tenant/administrators')->assertForbidden();
}
public function test_event_reassignment_and_tenant_changes_apply_to_existing_tokens(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$token = $this->login()->assertOk()->json('token');
$this->user->update(['event_id' => 2]);
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertOk()->assertJsonPath('data.event.id', 2);
DB::table('events')->where('id', 2)->update(['tenant_code' => 'other']);
$this->withToken($token)->getJson('/api/v1/adminapp/me')->assertForbidden();
}
public function test_wrong_password_still_counts_as_a_failed_attempt(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$this->login(['password' => 'wrong'])->assertUnprocessable()->assertJsonValidationErrors('email');
$this->assertSame(1, $this->user->refresh()->failed_login_attempts);
$this->assertDatabaseCount('personal_access_tokens', 0);
}
public function test_scope_migration_can_be_rolled_back_without_removing_users(): void
{
$this->scopeMigration()->down();
$this->assertFalse(Schema::hasColumn('users', 'admin_scope'));
$this->assertFalse(Schema::hasColumn('users', 'event_id'));
$this->assertDatabaseHas('users', ['id' => 1, 'email' => 'admin@example.test']);
}
}

View File

@@ -1,485 +0,0 @@
<?php
namespace Tests\Feature\Auth;
use App\Domains\Commerce\Purchase\Models\Purchase;
use App\Domains\Commerce\Sale\Services\AdminAppSaleService;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\ResetPasswordAttemptService;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Services\AdminAppTicketService;
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Facades\Schema;
use Illuminate\Testing\TestResponse;
use Laravel\Sanctum\Sanctum;
use Tests\TestCase;
class EventScopedOperationsTest extends TestCase
{
private User $user;
protected function setUp(): void
{
parent::setUp();
// Focused pre-migration schema: do not replay unrelated provisioning migrations.
// Tests\TestCase and tests/bootstrap.php enforce SQLite :memory:.
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->string('codigo')->unique();
$table->string('nombre');
$table->string('dominio');
$table->string('search_product_layout')->default('column_with_image');
$table->string('search_group_layout')->default('paginated');
});
Schema::create('events', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->string('title');
$table->timestamps();
});
Schema::create('users', function (Blueprint $table): void {
$table->id();
$table->string('nombre_apellido');
$table->string('email');
$table->string('active_email')->virtualAs('CASE WHEN deleted_at IS NULL THEN lower(email) ELSE NULL END');
$table->string('password');
$table->string('rol_codigo')->default('user');
$table->string('tenant_codigo')->nullable();
$table->softDeletes();
$table->timestamps();
$table->unique(['active_email', 'rol_codigo']);
});
Schema::create('menues', function (Blueprint $table): void {
$table->id();
$table->string('code')->unique();
$table->string('label');
$table->string('route');
$table->string('parent_menu_code')->nullable();
$table->string('content_type')->default('dynamic');
});
Schema::create('roles_menues', function (Blueprint $table): void {
$table->string('rol_codigo');
$table->string('menu_codigo');
});
Schema::create('tenants_menues', function (Blueprint $table): void {
$table->string('tenant_code');
$table->string('menu_code');
$table->json('static_content')->nullable();
$table->timestamps();
});
foreach ([
'2026_06_18_130006_create_personal_access_tokens_table.php',
'2026_07_28_000000_create_roles_and_permissions_tables.php',
'2026_07_29_000000_add_login_security_fields_to_users_table.php',
'2026_07_29_000100_create_login_attempts_table.php',
] as $file) {
(require database_path('migrations/'.$file))->up();
}
DB::table('roles')->insert(['codigo' => 'adminapp', 'nombre' => 'AdminApp']);
DB::table('tenants')->insert([
['codigo' => 'onticket', 'nombre' => 'OnTicket', 'dominio' => 'onticket.test'],
['codigo' => 'other', 'nombre' => 'Other', 'dominio' => 'other.test'],
]);
DB::table('events')->insert([
['id' => 1, 'tenant_code' => 'onticket', 'title' => 'Evento A'],
['id' => 2, 'tenant_code' => 'onticket', 'title' => 'Evento B'],
['id' => 3, 'tenant_code' => 'other', 'title' => 'Evento ajeno'],
]);
// An existing administrator must remain general after applying the new migration.
DB::table('users')->insert([
'id' => 1, 'nombre_apellido' => 'Admin', 'email' => 'admin@example.test',
'password' => Hash::make('secret123'), 'rol_codigo' => 'adminapp', 'tenant_codigo' => 'onticket',
]);
$this->scopeMigration()->up();
$this->user = User::query()->findOrFail(1);
$this->createOperationsSchema();
DB::table('menues')->insert([
['code' => 'main.adminapp', 'label' => 'Administración', 'route' => '/', 'parent_menu_code' => null],
['code' => 'adminapp.ventas', 'label' => 'Ventas', 'route' => '/admin/ventas', 'parent_menu_code' => 'main.adminapp'],
]);
foreach (['main.adminapp', 'adminapp.ventas'] as $code) {
DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]);
DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]);
}
}
private function scopeMigration(): Migration
{
return require database_path('migrations/2026_09_30_000000_add_admin_scope_to_users.php');
}
private function login(array $extra = []): TestResponse
{
return $this->postJson('/api/v1/adminapp/login', [
'email' => ' ADMIN@EXAMPLE.TEST ', 'password' => 'secret123', ...$extra,
]);
}
private function createOperationsSchema(): void
{
Schema::table('tenants', function (Blueprint $table): void {
$table->unsignedBigInteger('active_event_id')->nullable();
$table->boolean('scanner_category_validation_enabled')->default(false);
$table->boolean('allow_ticket_refund')->default(true);
$table->boolean('allow_ticket_total_refund')->default(true);
$table->boolean('allow_ticket_partial_refund')->default(true);
$table->decimal('ticket_partial_refund_percentage')->default(25);
});
Schema::table('users', fn (Blueprint $table) => $table->string('dni')->nullable());
Schema::table('events', function (Blueprint $table): void {
$table->string('location')->nullable();
$table->string('date_text')->nullable();
});
(require database_path('migrations/2026_09_30_000200_add_refund_configuration_to_events.php'))->up();
DB::table('tenants')->where('codigo', 'onticket')->update(['active_event_id' => 2]);
Schema::create('social_media', function (Blueprint $table): void {
$table->id();
$table->string('code')->unique();
$table->string('nombre');
});
Schema::create('event_social_media', function (Blueprint $table): void {
$table->unsignedBigInteger('event_id');
$table->string('social_media_code');
$table->string('url');
$table->integer('orden');
$table->timestamps();
});
Schema::create('event_dates', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->unsignedBigInteger('event_id');
$table->date('date');
$table->time('time_start');
$table->time('time_end');
$table->unsignedBigInteger('validity_time_id')->nullable();
$table->unsignedBigInteger('rescheduled_to_event_date_id')->nullable();
$table->timestamp('suspended_at')->nullable();
});
Schema::create('validity_times', function (Blueprint $table): void {
$table->id();
$table->string('type');
$table->time('start_time')->nullable();
$table->time('end_time')->nullable();
$table->timestamp('fixed_starts_at')->nullable();
$table->timestamp('fixed_expires_at')->nullable();
$table->timestamps();
});
Schema::create('categorias', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code')->nullable();
$table->unsignedBigInteger('categoria_id')->nullable();
$table->string('nombre');
});
Schema::create('category_scanners', function (Blueprint $table): void {
$table->unsignedBigInteger('user_id');
$table->unsignedBigInteger('categoria_id');
$table->timestamps();
});
Schema::create('catalog_items', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->unsignedBigInteger('event_id');
$table->unsignedBigInteger('category_id')->nullable();
$table->string('nombre');
$table->string('slug');
$table->text('descripcion')->nullable();
$table->decimal('precio')->default(0);
$table->string('type')->default('standard');
$table->string('inventory_policy')->default('tracked');
$table->string('inventory_subject')->default('product');
$table->integer('group_order')->default(0);
$table->boolean('has_tickets')->default(false);
$table->softDeletes();
});
Schema::create('compras', function (Blueprint $table): void {
$table->id();
$table->string('tenant_codigo');
$table->unsignedBigInteger('event_id');
$table->string('status');
$table->decimal('total');
$table->string('nombre_apellido');
$table->timestamps();
});
Schema::create('compra_items', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('compra_id');
$table->integer('cantidad');
$table->string('item_nombre')->nullable();
$table->decimal('precio_unitario')->default(10);
$table->decimal('total')->default(10);
});
Schema::create('tickets', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->unsignedBigInteger('event_id')->nullable();
$table->uuid('ticket');
foreach (['source_purchase_item_id', 'source_catalog_item_id', 'source_variant_id', 'scanner_user_id', 'user_id'] as $column) {
$table->unsignedBigInteger($column)->nullable();
}
foreach (['used_at', 'disabled_at', 'cancelled_at', 'refunded_at'] as $column) {
$table->timestamp($column)->nullable();
}
});
Schema::create('ticket_refunds', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('purchase_item_id');
$table->decimal('amount');
});
Schema::create('scan_attempts', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->unsignedBigInteger('scanner_user_id');
$table->unsignedBigInteger('ticket_id')->nullable();
$table->text('data')->nullable();
$table->string('result');
$table->timestamp('created_at')->nullable();
$table->timestamp('resolved_at')->nullable();
});
(require database_path('migrations/2026_09_30_000400_add_event_id_to_scan_attempts.php'))->up();
Schema::create('value_changes', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->string('trackable_type');
$table->unsignedBigInteger('trackable_id');
$table->string('attribute');
$table->string('old_value')->nullable();
$table->string('new_value')->nullable();
$table->string('actor_type')->default('user');
$table->unsignedBigInteger('user_id')->nullable();
$table->timestamp('changed_at')->nullable();
});
DB::table('roles')->insert(['codigo' => 'scanner', 'nombre' => 'Scanner']);
DB::table('permisos')->insert(['codigo' => 'tickets.escanear', 'nombre' => 'Escanear']);
DB::table('roles_permisos')->insert(['rol_codigo' => 'scanner', 'codigo_permiso' => 'tickets.escanear']);
foreach (['adminapp.catalog', 'adminapp.event', 'adminapp.staff', 'adminapp.inicio'] as $code) {
DB::table('menues')->insert(['code' => $code, 'label' => $code, 'route' => '/admin/test', 'parent_menu_code' => 'main.adminapp']);
DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]);
DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]);
}
}
private function actingEventAdmin(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
Sanctum::actingAs($this->user);
}
public function test_event_and_refund_settings_use_user_event_even_when_tenant_active_event_changes(): void
{
$this->actingEventAdmin();
$this->getJson('/api/v1/adminapp/tenant/event')->assertOk()->assertJsonPath('data.id', 1)
->assertJsonPath('data.allow_ticket_refund', true);
$this->putJson('/api/v1/adminapp/tenant/event', [
'title' => 'Solo A', 'location' => 'Predio A', 'social_media' => [], 'allow_ticket_refund' => false,
'allow_ticket_total_refund' => true, 'allow_ticket_partial_refund' => true,
'ticket_partial_refund_percentage' => 30,
])->assertOk()->assertJsonPath('data.id', 1)->assertJsonPath('data.allow_ticket_refund', false);
$this->assertDatabaseHas('events', ['id' => 1, 'title' => 'Solo A', 'allow_ticket_refund' => false]);
$this->assertDatabaseHas('events', ['id' => 2, 'title' => 'Evento B', 'allow_ticket_refund' => true]);
$this->assertDatabaseHas('tenants', ['codigo' => 'onticket', 'allow_ticket_refund' => true]);
$this->getJson('/api/v1/adminapp/forms/event')->assertOk();
$this->getJson('/api/v1/adminapp/tenant/website-extras')->assertForbidden();
}
public function test_dates_are_created_on_user_event_and_other_event_dates_cannot_be_changed(): void
{
$this->actingEventAdmin();
$this->postJson('/api/v1/adminapp/tenant/event-dates', [
'date' => '2027-01-20', 'start_time' => '10:00', 'end_time' => '12:00',
])->assertSuccessful();
$this->assertDatabaseHas('event_dates', ['event_id' => 1, 'date' => '2027-01-20']);
DB::table('event_dates')->insert(['id' => 20, 'event_id' => 2, 'tenant_code' => 'onticket',
'date' => '2027-01-20', 'time_start' => '10:00', 'time_end' => '12:00']);
$this->postJson('/api/v1/adminapp/tenant/event-dates/20/suspend')->assertNotFound();
$this->postJson('/api/v1/adminapp/tenant/event-dates/20/reschedule', ['date' => '2027-01-21'])->assertNotFound();
$this->assertDatabaseHas('event_dates', ['id' => 20, 'suspended_at' => null]);
}
public function test_sales_totals_details_exports_and_history_are_scoped_to_user_event(): void
{
$this->actingEventAdmin();
foreach ([1, 2] as $id) {
DB::table('compras')->insert(['id' => $id, 'tenant_codigo' => 'onticket', 'event_id' => $id,
'status' => 'paid', 'total' => $id * 100, 'nombre_apellido' => 'Cliente', 'created_at' => now()]);
DB::table('compra_items')->insert(['id' => $id, 'compra_id' => $id, 'cantidad' => 1]);
DB::table('ticket_refunds')->insert(['purchase_item_id' => $id, 'amount' => $id * 10]);
DB::table('value_changes')->insert(['tenant_code' => 'onticket',
'trackable_type' => (new Purchase)->getMorphClass(),
'trackable_id' => $id, 'attribute' => 'status', 'new_value' => 'paid', 'changed_at' => now()]);
}
$this->getJson('/api/v1/adminapp/tenant/sales')->assertOk()->assertJsonCount(1, 'data')
->assertJsonPath('confirmed_sales_total', '100.00')->assertJsonPath('refunded_total', '10.00');
$this->getJson('/api/v1/adminapp/tenant/sales/1')->assertOk();
foreach (['', '/tickets'] as $suffix) {
$this->getJson('/api/v1/adminapp/tenant/sales/2'.$suffix)->assertNotFound();
}
foreach (['confirm', 'cancel'] as $action) {
$this->postJson('/api/v1/adminapp/tenant/sales/2/'.$action)->assertNotFound();
}
$this->getJson('/api/v1/adminapp/tenant/sales/modifications')->assertOk()->assertJsonCount(1, 'data');
$service = app(AdminAppSaleService::class);
$tenant = $this->user->tenant;
$this->assertSame([1], $service->salesForExport($tenant, [], 1)->pluck('id')->all());
$this->assertSame([1], $service->modificationsForExport($tenant, [], 1)->pluck('trackable_id')->all());
}
private function scanner(int $eventId, int $id = 10): User
{
return User::query()->create(['id' => $id, 'nombre_apellido' => 'Scanner',
'email' => "scanner{$id}@example.test", 'password' => 'password', 'dni' => '123',
'tenant_codigo' => 'onticket', 'rol_codigo' => 'scanner', 'admin_scope' => 'event', 'event_id' => $eventId]);
}
public function test_staff_is_created_on_admin_event_and_other_staff_cannot_be_managed(): void
{
$this->actingEventAdmin();
$scanner = $this->scanner(2);
$this->getJson('/api/v1/adminapp/tenant/staff')->assertOk()->assertJsonCount(0, 'data');
$payload = ['nombre_apellido' => 'Nuevo', 'email' => 'nuevo@example.test', 'dni' => '123'];
$this->putJson('/api/v1/adminapp/tenant/staff/'.$scanner->id, $payload)->assertNotFound();
$this->deleteJson('/api/v1/adminapp/tenant/staff/'.$scanner->id)->assertNotFound();
$this->getJson('/api/v1/adminapp/tenant/staff/'.$scanner->id.'/scan-attempts')->assertNotFound();
$this->mock(ResetPasswordAttemptService::class,
fn ($mock) => $mock->shouldReceive('createForScannerEmail')->once());
$this->postJson('/api/v1/adminapp/tenant/staff', [...$payload, 'event_id' => 2])
->assertSuccessful()->assertJsonPath('data.event_id', 1);
$this->assertDatabaseHas('users', ['email' => 'nuevo@example.test', 'event_id' => 1, 'admin_scope' => 'event']);
}
public function test_scanner_rejects_foreign_event_qr_without_consuming_or_disclosing_ticket(): void
{
$scanner = $this->scanner(1);
Sanctum::actingAs($scanner);
$uuid = '11111111-1111-4111-8111-111111111111';
DB::table('tickets')->insert(['id' => 20, 'tenant_code' => 'onticket', 'event_id' => 2, 'ticket' => $uuid]);
$this->getJson('/api/v1/scanner/tickets/'.$uuid)->assertNotFound();
$this->postJson('/api/v1/scanner/tickets/scan', ['data' => $uuid])->assertOk()
->assertJsonPath('data.scan_attempt.result', 'ticket_not_found')->assertJsonPath('data.ticket', null);
$this->assertDatabaseHas('tickets', ['id' => 20, 'used_at' => null, 'scanner_user_id' => null]);
$this->assertDatabaseHas('scan_attempts', ['scanner_user_id' => $scanner->id, 'event_id' => 1, 'ticket_id' => null]);
}
public function test_scanner_history_and_detail_follow_assignment_changes_and_invalid_event_is_denied(): void
{
$scanner = $this->scanner(1);
Sanctum::actingAs($scanner);
$response = $this->postJson('/api/v1/scanner/tickets/scan', ['data' => 'invalid'])->assertOk();
$id = $response->json('data.scan_attempt.id');
$this->getJson('/api/v1/scanner/attempts')->assertOk()->assertJsonCount(1, 'data');
$scanner->update(['event_id' => 2]);
$this->getJson('/api/v1/scanner/attempts')->assertOk()->assertJsonCount(0, 'data');
$this->getJson('/api/v1/scanner/attempts/'.$id)->assertNotFound();
$scanner->update(['event_id' => null]);
$this->getJson('/api/v1/scanner/attempts')->assertForbidden();
}
public function test_initial_assignment_migration_preserves_existing_scopes_and_ignores_missing_events(): void
{
$this->user->update(['admin_scope' => 'event', 'event_id' => 1]);
$scanner = $this->scanner(1);
$scanner->update(['event_id' => null, 'admin_scope' => 'tenant']);
$migration = require database_path('migrations/2026_09_30_000100_assign_active_event_to_staff_users.php');
$migration->up();
$migration->up();
$this->assertDatabaseHas('users', ['id' => 1, 'event_id' => 1]);
$this->assertDatabaseHas('users', ['id' => $scanner->id, 'event_id' => 2, 'admin_scope' => 'event']);
DB::table('tenants')->where('codigo', 'onticket')->update(['active_event_id' => 3]);
$scanner->refresh()->update(['event_id' => null, 'admin_scope' => 'tenant']);
$migration->up();
$this->assertDatabaseHas('users', ['id' => $scanner->id, 'event_id' => null, 'admin_scope' => 'event']);
}
public function test_deprecated_menus_are_removed_with_their_role_and_tenant_assignments(): void
{
foreach (['adminapp.categories', 'adminapp.combos'] as $code) {
DB::table('menues')->insert(['code' => $code, 'label' => $code, 'route' => '/admin/old']);
DB::table('roles_menues')->insert(['rol_codigo' => 'adminapp', 'menu_codigo' => $code]);
DB::table('tenants_menues')->insert(['tenant_code' => 'onticket', 'menu_code' => $code]);
}
(require database_path('migrations/2026_09_30_000300_remove_deprecated_admin_menus.php'))->up();
foreach (['adminapp.categories', 'adminapp.combos'] as $code) {
$this->assertDatabaseMissing('menues', ['code' => $code]);
$this->assertDatabaseMissing('roles_menues', ['menu_codigo' => $code]);
$this->assertDatabaseMissing('tenants_menues', ['menu_code' => $code]);
}
}
public function test_scanner_accepts_ticket_from_its_event_and_cannot_consume_it_twice(): void
{
$scanner = $this->scanner(1);
Sanctum::actingAs($scanner);
$uuid = '11111111-1111-4111-8111-111111111111';
DB::table('tickets')->insert(['id' => 20, 'tenant_code' => 'onticket', 'event_id' => 1, 'ticket' => $uuid]);
$this->postJson('/api/v1/scanner/tickets/scan', ['data' => $uuid])->assertOk()
->assertJsonPath('data.scan_attempt.result', 'accepted')->assertJsonPath('data.ticket.id', 20);
$this->assertNotNull(DB::table('tickets')->where('id', 20)->value('used_at'));
$this->postJson('/api/v1/scanner/tickets/scan', ['data' => $uuid])->assertOk()
->assertJsonPath('data.scan_attempt.result', 'already_scanned');
$this->getJson('/api/v1/scanner/tickets/'.$uuid)->assertOk();
}
public function test_refund_calculation_uses_ticket_event_configuration_instead_of_tenant_defaults(): void
{
Schema::create('desfile_entry_reservations', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('ticket_id');
$table->softDeletes();
});
DB::table('ticket_refunds')->delete();
DB::table('compra_items')->insert(['id' => 1, 'compra_id' => 1, 'cantidad' => 1,
'precio_unitario' => 100, 'total' => 100]);
DB::table('tickets')->insert(['id' => 20, 'tenant_code' => 'onticket', 'event_id' => 1,
'ticket' => '11111111-1111-4111-8111-111111111111', 'source_purchase_item_id' => 1]);
DB::table('events')->where('id', 1)->update(['ticket_partial_refund_percentage' => 75]);
$calculation = app(AdminAppTicketService::class)
->calculateRefund($this->user->tenant, 20);
$this->assertSame(['total' => '100.00', 'partial' => '75.00'], $calculation);
DB::table('events')->where('id', 1)->update(['allow_ticket_refund' => false]);
$this->assertFalse(Ticket::query()->findOrFail(20)->allow_refund());
}
public function test_staff_category_options_and_assignments_exclude_other_event_products(): void
{
$this->actingEventAdmin();
DB::table('tenants')->where('codigo', 'onticket')->update(['scanner_category_validation_enabled' => true]);
foreach ([1, 2] as $id) {
DB::table('categorias')->insert(['id' => $id, 'nombre' => "Categoria {$id}", 'tenant_code' => 'onticket']);
DB::table('catalog_items')->insert(['id' => $id, 'tenant_code' => 'onticket', 'event_id' => $id,
'nombre' => "Producto {$id}", 'slug' => "producto-{$id}", 'category_id' => $id]);
}
$this->getJson('/api/v1/adminapp/forms/staff')->assertOk()->assertJsonCount(1, 'data.categories')
->assertJsonPath('data.categories.0.id', 1);
$this->postJson('/api/v1/adminapp/tenant/staff', ['nombre_apellido' => 'Nuevo', 'dni' => '123',
'email' => 'nuevo@example.test', 'category_ids' => [2]])->assertUnprocessable()->assertJsonValidationErrors('category_ids');
$this->assertDatabaseMissing('users', ['email' => 'nuevo@example.test']);
}
public function test_initial_migration_assigns_existing_tenant_admin_and_blocks_staff_without_active_event(): void
{
$unassigned = $this->scanner(1);
$unassigned->update(['tenant_codigo' => 'other', 'admin_scope' => 'tenant', 'event_id' => null]);
(require database_path('migrations/2026_09_30_000100_assign_active_event_to_staff_users.php'))->up();
$this->assertDatabaseHas('users', ['id' => 1, 'admin_scope' => 'event', 'event_id' => 2]);
$this->assertDatabaseHas('users', ['id' => $unassigned->id, 'admin_scope' => 'event', 'event_id' => null]);
$this->user->refresh();
$this->assertFalse($this->user->isTenantAdministrator());
$this->login()->assertOk()->assertJsonPath('user.event_id', 2);
}
public function test_scanner_login_validates_event_before_issuing_a_token(): void
{
$scanner = $this->scanner(1);
$this->postJson('/api/v1/scanner/login', ['email' => $scanner->email, 'password' => 'password'])
->assertOk()->assertJsonPath('user.event_id', 1);
$scanner->update(['event_id' => null]);
$this->postJson('/api/v1/scanner/login', ['email' => $scanner->email, 'password' => 'password'])
->assertUnprocessable()->assertJsonValidationErrors('email');
$this->assertDatabaseCount('personal_access_tokens', 1);
$this->assertSame(0, $scanner->refresh()->failed_login_attempts);
}
}

View File

@@ -17,6 +17,7 @@ class UserAuthorizationRelationsTest extends TestCase
$this->assertTrue(Schema::hasColumns('users', [
'rol_codigo',
'tenant_codigo',
'event_id',
]));
}
@@ -28,5 +29,7 @@ class UserAuthorizationRelationsTest extends TestCase
$this->assertNull($user->tenant_codigo);
$this->assertSame(RoleCode::User->value, $user->role->codigo);
$this->assertNull($user->tenant);
$this->assertNull($user->event_id);
$this->assertNull($user->event);
}
}

View File

@@ -9,15 +9,18 @@ use App\Domains\Ticketing\Desfile\Requests\ExportEntryReservationsRequest;
use App\Domains\Ticketing\Desfile\Requests\IndexEntryReservationsRequest;
use App\Domains\Ticketing\Desfile\Requests\StoreEntryReservationsRequest;
use App\Domains\Ticketing\Desfile\Resources\EntryReservationResource;
use App\Domains\Ticketing\Desfile\Services\DesfileEntryReservationPolicy;
use App\Domains\Ticketing\Desfile\Services\DesfileEntryReservationService;
use App\Domains\Ticketing\Desfile\Services\EntryReservationExcelService;
use App\Domains\Ticketing\Desfile\Services\EntryReservationPdfService;
use App\Domains\Ticketing\Desfile\Services\EntryReservationReportService;
use App\Domains\Ticketing\Desfile\Services\EntryReservationService;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Services\EntryReservationService as TicketEntryReservationService;
use App\Domains\Ticketing\Ticket\Services\ResolvedTicketValidity;
use App\Domains\Ticketing\Ticket\Services\TicketGeneratorService;
use App\Domains\Ticketing\Ticket\Services\TicketValidityResolver;
use Barryvdh\DomPDF\ServiceProvider as DomPdfServiceProvider;
use Illuminate\Database\Eloquent\ModelNotFoundException;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\DB;
@@ -136,6 +139,7 @@ class EntryReservationServiceTest extends TestCase
(require database_path('migrations/2026_09_23_010000_create_desfile_entry_reservations_table.php'))->up();
(require database_path('migrations/2026_09_24_000000_add_administrative_entry_reservation_stock.php'))->up();
(require database_path('migrations/2026_09_24_010000_add_soft_deletes_to_desfile_entry_reservations_table.php'))->up();
(require database_path('migrations/2026_10_02_000000_generalize_ticket_reservations.php'))->up();
DB::table('tenants')->insert(['codigo' => 'desfile_pura_tendencia']);
DB::table('users')->insert(['id' => 1, 'tenant_codigo' => 'desfile_pura_tendencia']);
DB::table('catalog_items')->insert([
@@ -165,7 +169,12 @@ class EntryReservationServiceTest extends TestCase
}
}
private function service(bool $failSecond = false): EntryReservationService
private function service(bool $failSecond = false): DesfileEntryReservationService
{
return new DesfileEntryReservationService($this->ticketService($failSecond), new DesfileEntryReservationPolicy);
}
private function ticketService(bool $failSecond = false): TicketEntryReservationService
{
$generator = Mockery::mock(TicketGeneratorService::class);
$generator->shouldReceive('generate')->andReturnUsing(function ($entry, $user, $quantity, $variantId) use ($failSecond) {
@@ -182,7 +191,7 @@ class EntryReservationServiceTest extends TestCase
return collect([Ticket::query()->findOrFail($id)]);
});
return new EntryReservationService($generator);
return new TicketEntryReservationService($generator);
}
private function rows(): array
@@ -200,8 +209,8 @@ class EntryReservationServiceTest extends TestCase
$replayed = $service->reserve($user, $key, $this->rows());
$this->assertSame($result->pluck('id')->all(), $replayed->pluck('id')->all());
$this->assertDatabaseCount('tickets', 2);
$this->assertDatabaseCount('desfile_entry_reservations', 2);
$this->assertDatabaseCount('desfile_reservation_batches', 1);
$this->assertDatabaseCount('entry_reservations', 2);
$this->assertDatabaseCount('reservation_batches', 1);
foreach (Inventory::all() as $inventory) {
$this->assertSame(1, $inventory->entry_reserved_stock);
$this->assertSame(1, $inventory->real_stock);
@@ -223,7 +232,7 @@ class EntryReservationServiceTest extends TestCase
$this->assertStringContainsString('Tipo: NORMAL, Sector: A, Fila: 3, Asiento: 17', $error->errors()['rows.1.variant_id'][0]);
}
$this->assertDatabaseCount('tickets', 0);
$this->assertDatabaseCount('desfile_entry_reservations', 0);
$this->assertDatabaseCount('entry_reservations', 0);
$this->assertSame(0, (int) Inventory::sum('entry_reserved_stock'));
}
@@ -236,8 +245,8 @@ class EntryReservationServiceTest extends TestCase
$this->assertSame('Ticket generation failed', $error->getMessage());
}
$this->assertDatabaseCount('tickets', 0);
$this->assertDatabaseCount('desfile_entry_reservations', 0);
$this->assertDatabaseCount('desfile_reservation_batches', 0);
$this->assertDatabaseCount('entry_reservations', 0);
$this->assertDatabaseCount('reservation_batches', 0);
$this->assertSame(0, (int) Inventory::sum('entry_reserved_stock'));
}
@@ -250,6 +259,120 @@ class EntryReservationServiceTest extends TestCase
$service->reserve($user, (string) Str::uuid(), $this->rows());
}
public function test_a_seat_cannot_be_reserved_twice_even_when_inventory_has_more_stock(): void
{
DB::table('inventories')->where('id', 1)->update(['real_stock' => 3]);
$service = $this->service();
$user = User::findOrFail(1);
$row = $this->rows()[0];
$reservation = $service->reserve($user, (string) Str::uuid(), [$row])->sole();
try {
$service->reserve($user, (string) Str::uuid(), [$row]);
$this->fail('Expected a unique seat despite remaining stock');
} catch (ValidationException $error) {
$this->assertArrayHasKey('rows.0.variant_id', $error->errors());
$this->assertStringContainsString('Asiento: 17', $error->errors()['rows.0.variant_id'][0]);
}
$this->assertDatabaseCount('tickets', 1);
$this->assertDatabaseCount('reservation_batches', 1);
$this->assertSame(1, Inventory::findOrFail(1)->entry_reserved_stock);
$service->cancel($user, $reservation->id);
$replacement = $service->reserve($user, (string) Str::uuid(), [$row])->sole();
$this->assertNotSame($reservation->id, $replacement->id);
$this->assertSame(1, Inventory::findOrFail(1)->entry_reserved_stock);
}
public function test_duplicate_seats_in_one_batch_are_rejected_without_changing_stock(): void
{
DB::table('inventories')->where('id', 1)->update(['real_stock' => 3]);
$row = $this->rows()[0];
try {
$this->service()->reserve(User::findOrFail(1), (string) Str::uuid(), [$row, $row]);
$this->fail('Expected duplicate seat validation');
} catch (ValidationException $error) {
$this->assertArrayHasKey('rows.1.variant_id', $error->errors());
}
$this->assertDatabaseCount('tickets', 0);
$this->assertDatabaseCount('reservation_batches', 0);
$this->assertSame(0, Inventory::findOrFail(1)->entry_reserved_stock);
}
public function test_legacy_batches_replay_after_cancellation_and_an_active_event_change(): void
{
$service = $this->service();
$user = User::findOrFail(1);
$key = (string) Str::uuid();
$result = $service->reserve($user, $key, $this->rows());
DB::table('reservation_batches')->update([
'request_hash' => hash('sha256', json_encode($this->rows(), JSON_THROW_ON_ERROR)),
]);
$service->cancel($user, $result->first()->id);
DB::table('tenants')->update(['active_event_id' => 20]);
$replay = $service->reserve($user, $key, array_reverse($this->rows()));
$this->assertSame($result->last()->id, $replay->sole()->id);
$this->assertSame($result->last()->id, $service->reservations($user)->sole()->id);
$this->assertSame($result->last()->ticket_id, $service->reservationTicket($user, $result->last()->id)->id);
$this->assertSame('NORMAL', $replay->sole()->variant->selectionValues()->get('tipo'));
$this->assertDatabaseCount('tickets', 2);
$this->assertDatabaseCount('reservation_batches', 1);
}
public function test_desfile_cannot_list_export_download_or_cancel_other_catalog_item_reservations(): void
{
DB::table('catalog_items')->insert([
'id' => 2, 'tenant_code' => 'desfile_pura_tendencia', 'slug' => 'other-ticket',
'inventory_policy' => 'tracked', 'precio' => 100,
]);
DB::table('inventories')->insert(['id' => 3, 'real_stock' => 1]);
DB::table('variantes')->insert(['id' => 3, 'catalog_item_id' => 2, 'inventory_id' => 3, 'precio' => 100]);
$user = User::findOrFail(1);
$other = $this->ticketService()->reserve($user, (string) Str::uuid(), [
['catalog_item_id' => 2, 'variant_id' => 3, 'tipo_pago' => 'sin_cargo'],
])->sole();
$service = $this->service();
$own = $service->reserve($user, (string) Str::uuid(), [$this->rows()[0]])->sole();
$this->assertSame([$own->id], $service->reservations($user)->pluck('id')->all());
$this->assertSame([$own->id], $service->reservationsForExport($user)->pluck('id')->all());
foreach (['reservationTicket', 'cancel'] as $method) {
try {
$service->$method($user, $other->id);
$this->fail('Expected the Desfile catalog scope');
} catch (ModelNotFoundException) {
$this->assertNull(Ticket::findOrFail($other->ticket_id)->cancelled_at);
}
}
DB::table('catalog_items')->where('id', 1)->update(['deleted_at' => now()]);
$this->assertSame(0, $service->reservations($user)->total());
$this->assertCount(0, $service->reservationsForExport($user));
}
public function test_desfile_service_rejects_other_tenants_for_every_operation(): void
{
$user = new User(['tenant_codigo' => 'other']);
$service = $this->service();
$operations = [
fn () => $service->reservations($user),
fn () => $service->reservationsForExport($user),
fn () => $service->reservationTicket($user, 1),
fn () => $service->cancel($user, 1),
fn () => $service->reserve($user, (string) Str::uuid(), $this->rows()),
];
foreach ($operations as $operation) {
try {
$operation();
$this->fail('Expected the Desfile tenant restriction');
} catch (HttpException $error) {
$this->assertSame(403, $error->getStatusCode());
}
}
}
public function test_it_cancels_the_ticket_releases_stock_and_soft_deletes_the_reservation(): void
{
$service = $this->service();
@@ -258,7 +381,7 @@ class EntryReservationServiceTest extends TestCase
$service->cancel($user, $reservation->id);
$this->assertSoftDeleted('desfile_entry_reservations', ['id' => $reservation->id]);
$this->assertSoftDeleted('entry_reservations', ['id' => $reservation->id]);
$this->assertNotNull(Ticket::findOrFail($reservation->ticket_id)->cancelled_at);
$this->assertSame(0, Inventory::findOrFail(1)->entry_reserved_stock);
$this->assertSame(1, Inventory::findOrFail(1)->availableStock());
@@ -280,7 +403,7 @@ class EntryReservationServiceTest extends TestCase
$this->assertArrayHasKey('status', $error->errors());
}
$this->assertDatabaseHas('desfile_entry_reservations', [
$this->assertDatabaseHas('entry_reservations', [
'id' => $reservation->id,
'deleted_at' => null,
]);
@@ -440,9 +563,13 @@ class EntryReservationServiceTest extends TestCase
$validity->shouldReceive('resolveVariant')->andReturn(
ResolvedTicketValidity::unrestricted(),
);
$service = new EntryReservationService(new TicketGeneratorService($validity));
$service = new DesfileEntryReservationService(
new TicketEntryReservationService(new TicketGeneratorService($validity)),
new DesfileEntryReservationPolicy,
);
$result = $service->reserve(User::findOrFail(1), (string) Str::uuid(), $this->rows());
foreach ($result as $reservation) {
$this->assertSame(1, $reservation->catalog_item_id);
$this->assertDatabaseHas('tickets', [
'id' => $reservation->ticket_id, 'user_id' => 1,
'source_variant_id' => $reservation->variant_id,

View File

@@ -99,7 +99,7 @@ class AdminAppDesfileEntryReservationFormControllerTest extends TestCase
]);
}
if ($state === 'administrative') {
$variant->desfileEntryReservations()->create([
$variant->entryReservations()->create([
'fecha_reserva' => now(), 'importe' => 0, 'tipo_pago' => 'sin_cargo',
]);
}
@@ -111,7 +111,7 @@ class AdminAppDesfileEntryReservationFormControllerTest extends TestCase
->assertOk()->assertJsonCount(1, 'data.variants')
->assertJsonPath('data.variants.0.id', $availableId)
->assertJsonPath('data.fields.3.options', [['value' => '1', 'label' => '1']]);
$this->assertDatabaseCount('desfile_entry_reservations', 1);
$this->assertDatabaseCount('entry_reservations', 1);
$this->assertSame(1, (int) Inventory::query()->sum('reserved_stock'));
}

View File

@@ -0,0 +1,76 @@
<?php
namespace Tests\Feature\Menu;
use App\Domains\Core\Auth\Models\User;
use App\Http\Middleware\EnsureTenantHasMenu;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Route;
use Illuminate\Support\Facades\Schema;
use PHPUnit\Framework\Attributes\DataProvider;
use Symfony\Component\HttpKernel\Exception\HttpException;
use Tests\TestCase;
class TicketMenuAccessTest extends TestCase
{
public static function menuAssignments(): array
{
return [
'new code' => ['onticket.adminapp.tickets', 'current', false],
'old code' => ['adminapp.tickets', 'current', true],
'another tenant' => ['adminapp.tickets', 'other', false],
'unrelated menu' => ['adminapp.ventas', 'current', false],
];
}
#[DataProvider('menuAssignments')]
public function test_ticket_menu_requires_an_association_with_the_authenticated_tenant(string $menuCode, string $assignedTenant, bool $allowed): void
{
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->string('codigo');
});
Schema::create('menues', function (Blueprint $table): void {
$table->id();
$table->string('code');
});
Schema::create('tenants_menues', function (Blueprint $table): void {
$table->string('tenant_code');
$table->string('menu_code');
});
DB::table('tenants')->insert(['codigo' => 'current']);
DB::table('menues')->insert(['code' => $menuCode]);
DB::table('tenants_menues')->insert(['tenant_code' => $assignedTenant, 'menu_code' => $menuCode]);
$user = new User(['tenant_codigo' => 'current']);
$request = Request::create('/api/v1/adminapp/tenant/tickets');
$request->setUserResolver(fn () => $user);
if (! $allowed) {
$this->expectException(HttpException::class);
$this->expectExceptionCode(0);
}
try {
$response = (new EnsureTenantHasMenu)->handle($request, fn () => response('allowed'), 'adminapp.tickets');
$this->assertSame('allowed', $response->getContent());
} catch (HttpException $exception) {
$this->assertSame(404, $exception->getStatusCode());
throw $exception;
}
}
public function test_all_ticket_routes_and_filter_form_use_the_updated_menu_codes(): void
{
foreach ([
'adminapp.tickets.index', 'adminapp.tickets.cancel',
'adminapp.tickets.calculate-refund', 'adminapp.tickets.refund',
'adminapp.tickets.pdf', 'adminapp.tickets.excel', 'adminapp.forms.tickets-filter',
] as $name) {
$route = Route::getRoutes()->getByName($name);
$this->assertNotNull($route);
$this->assertContains('tenant.menu:adminapp.tickets', $route->gatherMiddleware());
}
}
}

View File

@@ -0,0 +1,57 @@
<?php
namespace Tests\Feature\Migrations;
use App\Domains\Core\Administrator\Resources\AdministratorResource;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Resources\UserResource;
use Illuminate\Database\QueryException;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use Tests\TestCase;
class AddEventIdToUsersTest extends TestCase
{
public function test_event_assignment_preserves_existing_users_and_restricts_event_deletion(): void
{
Schema::create('events', function (Blueprint $table): void {
$table->id();
});
Schema::create('users', function (Blueprint $table): void {
$table->id();
$table->string('tenant_codigo')->nullable();
$table->softDeletes();
$table->timestamps();
});
DB::table('users')->insert(['id' => 1, 'tenant_codigo' => 'legacy']);
DB::table('events')->insert(['id' => 42]);
$migration = require database_path('migrations/2026_10_01_000000_add_event_id_to_users_table.php');
$migration->up();
$legacy = User::query()->findOrFail(1);
$this->assertNull($legacy->event_id);
$this->assertNull($legacy->event);
$this->assertSame('legacy', $legacy->tenant_codigo);
$legacy->update(['event_id' => '42']);
$user = $legacy->fresh();
$this->assertSame(42, $user->event_id);
$this->assertSame(42, $user->event->id);
$this->assertSame(42, UserResource::make($user)->resolve(new Request)['event_id']);
$this->assertSame(42, AdministratorResource::make($user)->resolve(new Request)['event_id']);
try {
DB::table('events')->where('id', 42)->delete();
$this->fail('An assigned event must not be deleted.');
} catch (QueryException $exception) {
$this->assertStringContainsString('FOREIGN KEY', $exception->getMessage());
}
$migration->down();
$this->assertFalse(Schema::hasColumn('users', 'event_id'));
$this->assertSame('legacy', DB::table('users')->where('id', 1)->value('tenant_codigo'));
}
}

View File

@@ -0,0 +1,206 @@
<?php
namespace Tests\Feature\Migrations;
use App\Domains\Ticketing\Ticket\Models\EntryReservation;
use App\Domains\Ticketing\Ticket\Models\ReservationBatch;
use Illuminate\Database\Migrations\Migration;
use Illuminate\Database\QueryException;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use Illuminate\Validation\ValidationException;
use Tests\TestCase;
/** Tests the upgrade on the guarded SQLite :memory: connection. */
class GeneralizeTicketReservationsTest extends TestCase
{
protected function setUp(): void
{
parent::setUp();
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->string('codigo');
});
Schema::create('users', function (Blueprint $table): void {
$table->id();
$table->softDeletes();
});
Schema::create('catalog_items', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->softDeletes();
});
Schema::create('variantes', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('catalog_item_id');
$table->softDeletes();
});
Schema::create('tickets', fn (Blueprint $table) => $table->id());
Schema::create('inventories', fn (Blueprint $table) => $table->id());
(require database_path('migrations/2026_09_23_010000_create_desfile_entry_reservations_table.php'))->up();
(require database_path('migrations/2026_09_24_000000_add_administrative_entry_reservation_stock.php'))->up();
(require database_path('migrations/2026_09_24_010000_add_soft_deletes_to_desfile_entry_reservations_table.php'))->up();
DB::table('users')->insert(['id' => 1]);
DB::table('tenants')->insert([
['codigo' => 'desfile_pura_tendencia'], ['codigo' => 'other'],
]);
DB::table('catalog_items')->insert([
['id' => 1, 'tenant_code' => 'desfile_pura_tendencia'],
['id' => 2, 'tenant_code' => 'other'],
]);
DB::table('variantes')->insert([
['id' => 1, 'catalog_item_id' => 1, 'deleted_at' => null],
['id' => 2, 'catalog_item_id' => 2, 'deleted_at' => now()],
]);
DB::table('tickets')->insert(['id' => 10]);
DB::table('inventories')->insert(['id' => 20, 'entry_reserved_stock' => 1]);
DB::table('desfile_reservation_batches')->insert([
'id' => 30, 'user_id' => 1, 'tenant_code' => 'desfile_pura_tendencia',
'idempotency_key' => 'aab7c678-7f4d-486a-87ec-7f613ad6f58d',
'request_hash' => str_repeat('a', 64),
'created_at' => now(), 'updated_at' => now(),
]);
DB::table('desfile_entry_reservations')->insert([
['id' => 40, 'variant_id' => 1, 'ticket_id' => 10, 'inventory_id' => 20,
'batch_id' => 30, 'fecha_reserva' => now(), 'importe' => 250,
'tipo_pago' => 'otro_metodo', 'deleted_at' => null],
['id' => 41, 'variant_id' => 2, 'ticket_id' => null, 'inventory_id' => null,
'batch_id' => null, 'fecha_reserva' => now(), 'importe' => 0,
'tipo_pago' => 'sin_cargo', 'deleted_at' => now()],
]);
}
private function migration(): Migration
{
return require database_path('migrations/2026_10_02_000000_generalize_ticket_reservations.php');
}
public function test_upgrade_preserves_reservations_batches_stock_and_deleted_history(): void
{
$this->migration()->up();
$this->assertFalse(Schema::hasTable('desfile_entry_reservations'));
$this->assertFalse(Schema::hasTable('desfile_reservation_batches'));
$this->assertDatabaseCount('entry_reservations', 2);
$this->assertDatabaseCount('reservation_batches', 1);
$reservation = EntryReservation::findOrFail(40);
$this->assertSame(1, $reservation->catalog_item_id);
$this->assertSame(1, $reservation->catalogItem->id);
$this->assertSame(30, $reservation->batch->id);
$this->assertSame(40, $reservation->batch->reservations->sole()->id);
$this->assertSame(10, $reservation->ticket->id);
$this->assertSame('250.00', $reservation->importe);
$this->assertSame(str_repeat('a', 64), $reservation->batch->request_hash);
$this->assertSame(1, $reservation->inventory->entry_reserved_stock);
$historical = EntryReservation::withTrashed()->findOrFail(41);
$this->assertTrue($historical->trashed());
$this->assertTrue($historical->variant->trashed());
$this->assertSame(2, $historical->catalog_item_id);
}
public function test_reservations_can_belong_to_other_tenants_and_have_no_variant(): void
{
$this->migration()->up();
$batch = ReservationBatch::create([
'user_id' => 1, 'tenant_code' => 'other',
'idempotency_key' => '9495eb8e-a424-4f1b-8911-e05c51e1caf7',
'request_hash' => str_repeat('b', 64),
]);
$reservation = $batch->reservations()->create([
'catalog_item_id' => 2, 'fecha_reserva' => now(),
'tipo_pago' => 'sin_cargo', 'importe' => 0,
]);
$this->assertNull($reservation->variant_id);
$this->assertSame('other', $reservation->catalogItem->tenant_code);
$this->assertSame('other', $reservation->batch->tenant->codigo);
$this->assertSame(1, $reservation->batch->user->id);
}
public function test_variant_based_callers_infer_the_catalog_item(): void
{
$this->migration()->up();
$reservation = EntryReservation::create([
'variant_id' => 1, 'fecha_reserva' => now(), 'tipo_pago' => 'sin_cargo',
]);
$this->assertSame(1, $reservation->fresh()->catalog_item_id);
}
public function test_a_variant_from_another_catalog_item_is_rejected(): void
{
$this->migration()->up();
$this->expectException(ValidationException::class);
EntryReservation::create([
'catalog_item_id' => 2, 'variant_id' => 1,
'fecha_reserva' => now(), 'tipo_pago' => 'sin_cargo',
]);
}
public function test_the_catalog_item_is_required_at_the_database_level(): void
{
$this->migration()->up();
$this->expectException(QueryException::class);
DB::table('entry_reservations')->insert([
'fecha_reserva' => now(), 'tipo_pago' => 'sin_cargo',
]);
}
public function test_upgrade_preserves_foreign_keys_and_batch_idempotency(): void
{
$this->migration()->up();
$this->assertSame([], DB::select('PRAGMA foreign_key_check'));
foreach (['catalog_items' => 1, 'variantes' => 1, 'tickets' => 10, 'inventories' => 20, 'reservation_batches' => 30] as $table => $id) {
try {
DB::table($table)->where('id', $id)->delete();
$this->fail("Expected {$table} to remain referenced");
} catch (QueryException) {
$this->assertDatabaseHas($table, ['id' => $id]);
}
}
$batch = ReservationBatch::findOrFail(30);
$this->expectException(QueryException::class);
ReservationBatch::create($batch->only(['user_id', 'tenant_code', 'idempotency_key', 'request_hash']));
}
public function test_rollback_restores_the_original_schema_and_keeps_data(): void
{
$migration = $this->migration();
$migration->up();
$migration->down();
$this->assertFalse(Schema::hasTable('entry_reservations'));
$this->assertFalse(Schema::hasTable('reservation_batches'));
$this->assertDatabaseCount('desfile_entry_reservations', 2);
$this->assertDatabaseCount('desfile_reservation_batches', 1);
$this->assertFalse(Schema::hasColumn('desfile_entry_reservations', 'catalog_item_id'));
$this->assertSame([], DB::select('PRAGMA foreign_key_check'));
$migration->up();
$this->assertSame(1, EntryReservation::findOrFail(40)->catalog_item_id);
}
public function test_rollback_does_not_discard_reservations_without_variants(): void
{
$migration = $this->migration();
$migration->up();
EntryReservation::create([
'catalog_item_id' => 2, 'fecha_reserva' => now(), 'tipo_pago' => 'sin_cargo',
]);
try {
$migration->down();
$this->fail('Expected incompatible rollback to be rejected');
} catch (\LogicException) {
$this->assertDatabaseCount('entry_reservations', 3);
$this->assertTrue(Schema::hasTable('reservation_batches'));
}
}
public function test_an_orphaned_catalog_is_rejected_before_renaming_tables(): void
{
DB::table('variantes')->where('id', 2)->update(['catalog_item_id' => 999]);
try {
$this->migration()->up();
$this->fail('Expected orphaned catalog to be rejected');
} catch (\LogicException) {
$this->assertDatabaseCount('desfile_entry_reservations', 2);
$this->assertFalse(Schema::hasTable('entry_reservations'));
}
}
}

View File

@@ -0,0 +1,183 @@
<?php
namespace Tests\Feature\Sale;
use App\Domains\Commerce\Purchase\Models\Purchase;
use App\Domains\Commerce\Purchase\Services\CheckoutService;
use App\Domains\Commerce\Sale\Services\AdminAppSaleExcelService;
use App\Domains\Commerce\Sale\Services\AdminAppSalePdfService;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Authorization\Enums\RoleCode;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use Laravel\Sanctum\Sanctum;
use Mockery\MockInterface;
use Symfony\Component\HttpFoundation\StreamedResponse;
use Tests\TestCase;
class AdminAppSaleEventScopeTest extends TestCase
{
protected function setUp(): void
{
parent::setUp();
// Isolated schema: the full legacy migration chain cannot run on SQLite.
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->string('codigo');
});
Schema::create('users', function (Blueprint $table): void {
$table->id();
$table->softDeletes();
});
Schema::create('compras', function (Blueprint $table): void {
$table->id();
$table->string('tenant_codigo');
$table->unsignedBigInteger('event_id')->nullable();
$table->string('nombre_apellido');
$table->string('status');
$table->decimal('total', 12, 2);
$table->timestamps();
});
Schema::create('compra_items', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('compra_id');
$table->integer('cantidad');
});
Schema::create('tickets', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('source_purchase_item_id');
});
Schema::create('ticket_refunds', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('purchase_item_id');
$table->decimal('amount', 12, 2);
});
Schema::create('value_changes', function (Blueprint $table): void {
$table->id();
$table->string('tenant_code');
$table->string('trackable_type');
$table->unsignedBigInteger('trackable_id');
$table->string('attribute');
$table->string('old_value');
$table->string('new_value');
$table->timestamp('changed_at');
$table->string('actor_type');
$table->unsignedBigInteger('user_id')->nullable();
});
DB::table('tenants')->insert(['codigo' => 'onticket']);
foreach ([1 => ['onticket', 10], 2 => ['onticket', 20], 3 => ['onticket', null], 4 => ['other', 10]] as $id => [$tenant, $event]) {
DB::table('compras')->insert([
'id' => $id,
'tenant_codigo' => $tenant,
'event_id' => $event,
'nombre_apellido' => 'Cliente',
'status' => Purchase::STATUS_PAID,
'total' => $id * 100,
'created_at' => now(),
'updated_at' => now(),
]);
DB::table('compra_items')->insert(['id' => $id, 'compra_id' => $id, 'cantidad' => 1]);
DB::table('ticket_refunds')->insert(['purchase_item_id' => $id, 'amount' => $id * 10]);
DB::table('value_changes')->insert([
'id' => $id,
'tenant_code' => $tenant,
'trackable_type' => (new Purchase)->getMorphClass(),
'trackable_id' => $id,
'attribute' => 'status',
'old_value' => Purchase::STATUS_PENDING_PAYMENT,
'new_value' => Purchase::STATUS_PAID,
'changed_at' => now(),
'actor_type' => 'system',
]);
}
$this->actingAsAdministrator(10);
}
public function test_list_totals_and_filters_cannot_escape_the_authenticated_event(): void
{
$this->getJson('/api/v1/adminapp/tenant/sales?event_id=20&q=Cliente')
->assertOk()
->assertJsonCount(1, 'data')
->assertJsonPath('data.0.id', 1)
->assertJsonPath('confirmed_sales_total', '100.00')
->assertJsonPath('refunded_total', '10.00');
$this->getJson('/api/v1/adminapp/tenant/sales?id=2')->assertOk()->assertJsonCount(0, 'data');
$this->getJson('/api/v1/adminapp/tenant/sales/modifications?q=Cliente')
->assertOk()->assertJsonCount(1, 'data')->assertJsonPath('data.0.sale_id', 1);
}
public function test_unscoped_administrators_keep_access_to_all_sales_in_their_tenant(): void
{
$this->actingAsAdministrator(null);
$this->getJson('/api/v1/adminapp/tenant/sales')->assertOk()->assertJsonCount(3, 'data')
->assertJsonPath('confirmed_sales_total', '600.00')->assertJsonPath('refunded_total', '60.00');
$this->getJson('/api/v1/adminapp/tenant/sales/modifications')->assertOk()->assertJsonCount(3, 'data');
$this->getJson('/api/v1/adminapp/tenant/sales/2')->assertOk();
$this->getJson('/api/v1/adminapp/tenant/sales/3')->assertOk();
}
public function test_foreign_and_unassigned_sales_are_inaccessible_before_any_checkout_action(): void
{
$this->mock(CheckoutService::class, function (MockInterface $mock): void {
$mock->shouldNotReceive('confirmPaidPurchase');
$mock->shouldNotReceive('cancelPurchaseFromAdmin');
});
foreach ([2, 3, 4] as $id) {
$this->getJson("/api/v1/adminapp/tenant/sales/{$id}")->assertNotFound();
$this->getJson("/api/v1/adminapp/tenant/sales/{$id}/tickets")->assertNotFound();
$this->postJson("/api/v1/adminapp/tenant/sales/{$id}/confirm", ['event_id' => 20])->assertNotFound();
$this->postJson("/api/v1/adminapp/tenant/sales/{$id}/cancel", ['event_id' => 20])->assertNotFound();
}
$this->assertSame(Purchase::STATUS_PAID, DB::table('compras')->where('id', 2)->value('status'));
}
public function test_own_event_allows_detail_tickets_and_checkout_actions(): void
{
// Empty snapshots keep this fixture focused on authorization.
DB::table('compra_items')->where('compra_id', 1)->delete();
$this->mock(CheckoutService::class, function (MockInterface $mock): void {
foreach (['confirmPaidPurchase', 'cancelPurchaseFromAdmin'] as $method) {
$mock->shouldReceive($method)->once()->withArgs(fn (Purchase $sale): bool => $sale->id === 1)
->andReturnUsing(fn (Purchase $sale): Purchase => $sale);
}
});
$this->getJson('/api/v1/adminapp/tenant/sales/1')->assertOk()->assertJsonPath('data.id', 1);
$this->getJson('/api/v1/adminapp/tenant/sales/1/tickets')->assertOk();
$this->postJson('/api/v1/adminapp/tenant/sales/1/confirm')->assertOk()->assertJsonPath('data.id', 1);
$this->postJson('/api/v1/adminapp/tenant/sales/1/cancel')->assertOk()->assertJsonPath('data.id', 1);
}
public function test_pdf_and_excel_exports_only_receive_sales_and_history_for_the_own_event(): void
{
foreach ([AdminAppSalePdfService::class, AdminAppSaleExcelService::class] as $class) {
$this->mock($class, function (MockInterface $mock) use ($class): void {
foreach (['downloadSales', 'downloadModifications'] as $method) {
$mock->shouldReceive($method)->once()->withArgs(
fn ($tenant, Collection $rows, $timezone): bool => $tenant->codigo === 'onticket'
&& $rows->pluck('id')->all() === [1] && $timezone === 'UTC'
)->andReturn($class === AdminAppSalePdfService::class
? response('pdf') : new StreamedResponse(fn () => print ('excel')));
}
});
}
foreach (['pdf', 'excel', 'modifications/pdf', 'modifications/excel'] as $path) {
$this->getJson("/api/v1/adminapp/tenant/sales/{$path}?timezone=UTC&event_id=20")->assertOk();
}
}
private function actingAsAdministrator(?int $eventId): void
{
$user = new User;
$user->setRawAttributes([
'id' => 1,
'rol_codigo' => RoleCode::AdminApp->value,
'tenant_codigo' => 'onticket',
'event_id' => $eventId,
]);
Sanctum::actingAs($user);
}
}

View File

@@ -27,6 +27,8 @@ class MenuSeederTest extends TestCase
$expectedMenus = [
'adminapp.inicio' => ['Inicio', '/admin/inicio'],
'adminapp.catalog' => ['Catálogo', '/admin/catalog'],
'adminapp.categories' => ['Categorías', '/admin/categories'],
'adminapp.combos' => ['Combos', '/admin/combos'],
'adminapp.event' => ['Eventos', '/admin/event'],
'adminapp.staff' => ['Staff', '/admin/staff'],
'adminapp.ventas' => ['Ventas', '/admin/ventas'],
@@ -52,6 +54,8 @@ class MenuSeederTest extends TestCase
...$expectedMenus,
...$fiestaCategoryMenus,
'adminapp.desfile.entradas' => ['Entradas', '/admin/desfile/entradas'],
'adminapp.desfile.reservas' => ['Reserva de Tickets', '/admin/desfile/reservas'],
'adminapp.ticket-reservations' => ['Reserva de Tickets', '/admin/ticket-reservations'],
]))->sort()->values()->all(),
$adminApp->children->pluck('code')->sort()->values()->all()
);
@@ -98,8 +102,6 @@ class MenuSeederTest extends TestCase
$this->assertFalse(
Menu::query()->whereIn('code', [
'adminapp.categories',
'adminapp.combos',
'admin.event',
'admin.catalog',
'admin.combos',

View File

@@ -0,0 +1,158 @@
<?php
namespace Tests\Feature\Staff;
use App\Domains\Core\Auth\Models\User;
use App\Domains\Core\Auth\Services\ResetPasswordAttemptService;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Schema;
use Laravel\Sanctum\Sanctum;
use Mockery\MockInterface;
use Tests\TestCase;
class StaffEventScopeTest extends TestCase
{
protected function setUp(): void
{
parent::setUp();
// Exercise HTTP authorization on SQLite without the incompatible legacy migrations.
Schema::create('tenants', function (Blueprint $table): void {
$table->id();
$table->string('codigo');
$table->boolean('scanner_category_validation_enabled')->default(false);
});
Schema::create('roles', function (Blueprint $table): void {
$table->id();
$table->string('codigo');
$table->string('nombre');
});
Schema::create('users', function (Blueprint $table): void {
$table->id();
$table->string('rol_codigo');
$table->string('tenant_codigo');
$table->unsignedBigInteger('event_id')->nullable();
$table->string('nombre_apellido');
$table->string('dni');
$table->string('email');
$table->string('active_email')->nullable();
$table->string('password')->nullable();
$table->timestamps();
$table->softDeletes();
});
Schema::create('categorias', function (Blueprint $table): void {
$table->id();
$table->string('nombre');
$table->string('tenant_code')->nullable();
$table->unsignedBigInteger('categoria_id')->nullable();
});
Schema::create('catalog_items', function (Blueprint $table): void {
$table->id();
$table->unsignedBigInteger('category_id');
$table->string('tenant_code');
$table->softDeletes();
});
Schema::create('category_scanners', function (Blueprint $table): void {
$table->unsignedBigInteger('user_id');
$table->unsignedBigInteger('categoria_id');
$table->timestamps();
});
Schema::create('personal_access_tokens', function (Blueprint $table): void {
$table->id();
$table->string('tokenable_type');
$table->unsignedBigInteger('tokenable_id');
});
DB::table('tenants')->insert(['codigo' => 'onticket']);
foreach (['adminapp', 'scanner'] as $role) {
DB::table('roles')->insert(['codigo' => $role, 'nombre' => $role]);
foreach ([10, 20, null] as $eventId) {
$this->insertUser($role, 'onticket', $eventId);
}
$this->insertUser($role, 'other', 10);
}
Sanctum::actingAs(User::query()->findOrFail(1));
}
public function test_lists_and_searches_are_restricted_to_the_authenticated_event(): void
{
foreach (['administrators' => 1, 'staff' => 5] as $path => $id) {
foreach (['', '?search=Persona&event_id=20'] as $query) {
$this->getJson("/api/v1/adminapp/tenant/{$path}{$query}")
->assertOk()->assertJsonCount(1, 'data')
->assertJsonPath('data.0.id', $id)->assertJsonPath('data.0.event_id', 10);
}
}
}
public function test_creation_inherits_the_actor_event_even_if_the_client_supplies_another(): void
{
$this->mock(ResetPasswordAttemptService::class, function (MockInterface $mock): void {
$mock->shouldReceive('createForAdminAppEmail')->once();
$mock->shouldReceive('createForScannerEmail')->once();
});
foreach (['administrators' => 'adminapp', 'staff' => 'scanner'] as $path => $role) {
$this->postJson("/api/v1/adminapp/tenant/{$path}", [
...$this->payload("new-{$role}@example.com"), 'event_id' => 20,
])->assertSuccessful()->assertJsonPath('data.event_id', 10);
$this->assertDatabaseHas('users', ['email' => "new-{$role}@example.com", 'event_id' => 10, 'rol_codigo' => $role]);
}
}
public function test_foreign_and_unassigned_staff_cannot_be_edited_deleted_or_inspected(): void
{
foreach (['administrators' => [2, 3, 4], 'staff' => [6, 7, 8]] as $path => $ids) {
foreach ($ids as $id) {
$this->putJson("/api/v1/adminapp/tenant/{$path}/{$id}", $this->payload("update-{$id}@example.com"))->assertNotFound();
$this->deleteJson("/api/v1/adminapp/tenant/{$path}/{$id}")->assertNotFound();
$this->assertDatabaseHas('users', ['id' => $id, 'deleted_at' => null, 'email' => "person-{$id}@example.com"]);
if ($path === 'staff') {
$this->getJson("/api/v1/adminapp/tenant/staff/{$id}/scan-attempts")->assertNotFound();
}
}
}
}
public function test_own_staff_can_be_edited_and_deleted_without_changing_its_event(): void
{
$adminId = $this->insertUser('adminapp', 'onticket', 10);
foreach (['administrators' => $adminId, 'staff' => 5] as $path => $id) {
$this->putJson("/api/v1/adminapp/tenant/{$path}/{$id}", [
...$this->payload("updated-{$id}@example.com"), 'event_id' => 20,
])->assertOk()->assertJsonPath('data.event_id', 10);
$this->deleteJson("/api/v1/adminapp/tenant/{$path}/{$id}")->assertNoContent();
$this->assertSoftDeleted('users', ['id' => $id]);
}
}
public function test_unscoped_actor_keeps_tenant_lists_and_creates_without_an_event(): void
{
Sanctum::actingAs(User::query()->findOrFail(3));
$this->mock(ResetPasswordAttemptService::class, function (MockInterface $mock): void {
$mock->shouldReceive('createForAdminAppEmail')->once();
$mock->shouldReceive('createForScannerEmail')->once();
});
foreach (['administrators', 'staff'] as $path) {
$this->getJson("/api/v1/adminapp/tenant/{$path}")->assertOk()->assertJsonCount(3, 'data');
$this->postJson("/api/v1/adminapp/tenant/{$path}", $this->payload("legacy-{$path}@example.com"))
->assertSuccessful()->assertJsonPath('data.event_id', null);
}
}
private function insertUser(string $role, string $tenant, ?int $eventId): int
{
$id = DB::table('users')->count() + 1;
return DB::table('users')->insertGetId([
'id' => $id, 'rol_codigo' => $role, 'tenant_codigo' => $tenant,
'event_id' => $eventId, 'nombre_apellido' => 'Persona', 'dni' => '12345678',
'email' => "person-{$id}@example.com", 'active_email' => "person-{$id}@example.com",
]);
}
private function payload(string $email): array
{
return ['nombre_apellido' => 'Persona editada', 'dni' => '87654321', 'email' => $email];
}
}

View File

@@ -13,8 +13,8 @@ use App\Domains\Core\Authorization\Enums\RoleCode;
use App\Domains\Core\Menu\Models\Menu;
use App\Domains\Core\Tenant\Models\AdminWebsiteType;
use App\Domains\Core\Tenant\Models\Tenant;
use App\Domains\Ticketing\Desfile\Enums\EntryReservationPaymentType;
use App\Domains\Ticketing\Desfile\Models\EntryReservation;
use App\Domains\Ticketing\Ticket\Enums\EntryReservationPaymentType;
use App\Domains\Ticketing\Ticket\Models\EntryReservation;
use App\Domains\Ticketing\Ticket\Models\Ticket;
use App\Domains\Ticketing\Ticket\Models\TicketRefund;
use App\Shared\Attachable\Enums\AttachmentType;

Some files were not shown because too many files have changed in this diff Show More